bonjour,
suite infection zango, je sollicite votre aide pour voir si j'ai tout éradiquer
un grand merci
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:15:12, on 24/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
C:\Program Files\Fichiers communs\SystemDoctor\USDR6cw.exe
C:\Program Files\Fichiers communs\SystemDoctor\usdrmdr.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Hotbar\bin\10.0.356.0\Weather.exe
C:\Program Files\MessengerSkinner\MessengerSkinner.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Documents and Settings\bigeon sophie\Local Settings\Application Data\eugfqsfr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: {bc979c65-1af3-5a39-b504-c5a31e59f7d4} - {4d7f95e1-3a5c-405b-93a5-3fa156c979cb} - C:\WINDOWS\system32\jxlglcyx.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [USDR6cw] C:\Program Files\Fichiers communs\SystemDoctor\USDR6cw.exe -c
O4 - HKLM\..\Run: [MDRV_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrmdr.exe"
O4 - HKLM\..\Run: [DC6V_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrdc.exe"
O4 - HKLM\..\Run: [ConducteurPrive] C:\Program Files\ConducteurPrive\GDC.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Hotbar\bin\10.0.356.0\Weather.exe" -auto
O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [laxbute] c:\documents and settings\bigeon sophie\local settings\application data\laxbute.exe laxbute
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [eugfqsfr] c:\documents and settings\bigeon sophie\local settings\application data\eugfqsfr.exe eugfqsfr
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
O4 - Global Startup: DSLMON.lnk = ?
O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 2137206531
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0024E3.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ddcdaay - ddcdaay.dll (file missing)
O20 - Winlogon Notify: nnnljhh - nnnljhh.dll (file missing)
O20 - Winlogon Notify: urqQiHxw - urqQiHxw.dll (file missing)
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 13492 bytes
Bonjour,
Télécharge Navilog1.exe (IL-MAFIOSO)
Enregistre-le sur ton Bureau.
Lance l'installation en double cliquant sur navilog.exe.
Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
(Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)
Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
! N'utilise pas l'option 2, 3 et 4 sans notre accord !
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste-nous son contenu de cette manière :
-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse
NOTE : Le rapport se trouve également ici : C:\fixnavi.txt
Répondre à Angeldark
ok merci
Search Navipromo version 3.5.7 commencé le 24/05/2008 à 21:54:44,48
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "bigeon sophie"
Mise à jour le 11.05.2008 à 18h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS
Recherche executé en mode normal
*** Recherche Programmes installés ***
MessengerSkinner
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
C:\Program Files\MessengerSkinner trouvé !
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\menudm~1\progra~1" ***
...\MessengerSkinner trouvé !
*** Recherche dossiers dans "C:\Documents and Settings\bigeon sophie\applic~1" ***
...\MessengerSkinner trouvé !
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\CARREF~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\bigeon sophie\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\CARREF~1\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\bigeon sophie\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\CARREF~1\menudm~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
Aucun Fichier trouvé
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\bigeon sophie\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\CARREF~1\locals~1\applic~1" *
*** Recherche fichiers ***
C:\WINDOWS\system32\nvs2.inf trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
* Dans "C:\Documents and Settings\bigeon sophie\locals~1\applic~1" :
eugfqsfr.dat trouvé !
eugfqsfr_nav.dat trouvé !
eugfqsfr_navps.dat trouvé !
laxbute.dat trouvé !
laxbute_nav.dat trouvé !
laxbute_navps.dat trouvé !
* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :
* Dans "C:\DOCUME~1\CARREF~1\locals~1\applic~1" :
3)Recherche Certificats :
Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
C:\WINDOWS\system32\CfiPAcfe.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ddLoqtwa.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\dgiOnUvw.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\lmWvyyxx.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\QAJmUvut.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\SrXyxyay.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\UwFNpXbc.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\wFiPonmp.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ddeeg.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ihkmp.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\knnmp.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\lnnmp.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\qtutv.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\rqtwa.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\ddeeg.bak2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\lnnmp.bak2 trouvé ! infection Vundo possible non traitée par cet outil !
C:\WINDOWS\system32\rqtwa.bak2 trouvé ! infection Vundo possible non traitée par cet outil !
*** Analyse terminée le 24/05/2008 à 22:22:00,48 ***
Re,
Double clique sur le raccourci de Navilog1 présent sur ton Bureau.
Suis les instructions. Choisis ensuite l'option 2 puis valide.
Laisse toi guider et réponds aux questions éventuelles.
L'utilitaire va t'informer qu'il va redémarrer l'ordinateur.
**Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts**
Appuie maintenant sur une touche, comme demandé.
(si ton PC ne redémarre pas automatiquement, fais-le manuellement)
Patiente jusqu'à l'apparition de ce message :
"*** Nettoyage Termine le ..... ***"
Le Bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver.
Referme le Bloc-notes. Ton bureau va maintenant réapparaître.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
Poste le rapport sauvegardé auparavant (C:\cleannavi.txt)
Ainsi qu'un nouveau rapport Hijackthis.
&
Désactive tes protections résidentes (antivirus, Spybot-S&D, etc.) !
- Télécharge ComboFix (sUBs) sur ton Bureau.
- Double clique sur ComboFix.exe (le .exe n'est pas forcément visible) afin de le lancer.
- Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\combofix.txt*) dans ta prochaine réponse.
AIDE : Un guide et un tutoriel sur l'utilisation de ComboFix
* le nom de la partition peut changer
Répondre à Angeldark
merci Angeldark pour ton aide
Clean Navipromo version 3.5.7 commencé le 25/05/2008 à 18:42:17,43
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "bigeon sophie"
Mise à jour le 11.05.2008 à 18h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.13
Système de fichiers : NTFS
Mode suppression automatique
avec prise en charge résultats Catchme et GNS
Nettoyage exécuté au redémarrage de l'ordinateur
*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)
*** Suppression avec sauvegardes résultats GenericNaviSearch ***
* Suppression dans "C:\WINDOWS\System32" *
* Suppression dans "C:\Documents and Settings\bigeon sophie\locals~1\applic~1" *
* Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *
* Suppression dans "C:\DOCUME~1\CARREF~1\locals~1\applic~1" *
*** Suppression dossiers dans "C:\WINDOWS" ***
*** Suppression dossiers dans "C:\Program Files" ***
C:\Program Files\MessengerSkinner ...suppression...
C:\Program Files\MessengerSkinner supprimé !
*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Suppression dossiers dans "c:\docume~1\alluse~1\menudm~1\progra~1" ***
...\MessengerSkinner ...suppression...
...\MessengerSkinner supprimé !
*** Suppression dossiers dans "C:\Documents and Settings\bigeon sophie\applic~1" ***
...\MessengerSkinner ...suppression...
...\MessengerSkinner supprimé !
*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\CARREF~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\bigeon sophie\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\CARREF~1\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\bigeon sophie\menudm~1\progra~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***
*** Suppression dossiers dans "C:\DOCUME~1\CARREF~1\menudm~1\progra~1" ***
*** Suppression fichiers ***
C:\WINDOWS\system32\nvs2.inf supprimé !
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\bigeon sophie\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans "C:\WINDOWS\system32" *
* Dans "C:\Documents and Settings\bigeon sophie\locals~1\applic~1" *
laxbute.dat trouvé !
Copie laxbute.dat réalisée avec succès !
laxbute.dat supprimé !
laxbute_nav.dat trouvé !
Copie laxbute_nav.dat réalisée avec succès !
laxbute_nav.dat supprimé !
laxbute_navps.dat trouvé !
Copie laxbute_navps.dat réalisée avec succès !
laxbute_navps.dat supprimé !
* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *
* Dans "C:\DOCUME~1\CARREF~1\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat OOO-Favorit supprimé !
Certificat Sunny-Day-Design-Ltdt absent !
*** Nettoyage terminé le 25/05/2008 à 19:15:19,10 ***
combofix
long tre long
ComboFix 08-05-24.1 - bigeon sophie 2008-05-25 20:49:16.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.354 [GMT 2:00]
Endroit: C:\Documents and Settings\bigeon sophie\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
* Resident AV is active
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
C:\Documents and Settings\All Users\Application Data\HotbarSA
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSA.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSA_gdf.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSA_kyf.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAAbout.mht
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAau.dat
C:\Documents and Settings\All Users\Application Data\HotbarSA\HotbarSAEula.mht
C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\Abbr
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ActivationCode
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\HOURS
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ProductCode
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Hotbar
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Hotbar\About Hotbar.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Hotbar\Hotbar Customer Support Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Hotbar\Reset Cursor.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Hotbar\Uninstall Hotbar.lnk
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\eskin\010108lo32_arrow.ani
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\eskin\010108lo32_cr.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\eskin\010108lo32_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\eskin\FileManager.txt
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\HbTools.log
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\HbTools_1180460804.log
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\HbTools_1184003975.log
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte10_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte11_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte12_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte13_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte14_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte19_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte20_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte21_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030104_emte9_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\030203lib_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102angel_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102bigluf_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102bigsmile_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102birthday_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102cheers_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102flo_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102good_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102jump_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102king_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102lough_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102luf_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102smile_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102smiled_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102sor_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102thanx_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\033102uhu_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\040103ahh_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\040103wow_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\040104_emi2_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\042102_1134_112_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\050103big_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\050103gig_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\050103hm_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\050103nomail_emoti_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\050103norm_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema15_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema16_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema17_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema18_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema19_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema20_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema21_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema24_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema25_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema26_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema30_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema33_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\060104_ema34_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\062802hippi_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\062802jumpie_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\080402argh_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\080402oops_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\080402ouch_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\082502no_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\082502yes_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_boring1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_confused_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_crying_ugly_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_fantastic_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_feel_better_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_gimme_break_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_heehee_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_hlopaet_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_ign_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_lol_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_no_comment_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_peace_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_smashing_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\110103_talk2thehand_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\block_sm.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\block_sm2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\block_smli.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\block_smli2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\blocked.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\blocked2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_add-but.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_back-but.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_left_cut_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_left_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_left_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_middle_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_middle_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_right_cut_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_right_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\btn_right_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\business_promo.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\buttondir.txt
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\components.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\css_cattree.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\css_flashpreview.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\css2_main.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\css2_pagingmodule.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\css2_topbuttons.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\delete.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\edit_clear_sound.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\edit_fs.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\edit_select.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-511745-514279.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-backgrounds.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-bcards.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-ecards.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-edit.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-emoticons.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-estationery.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-funny.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-help.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-images.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-info.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-more.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-my.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-people.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-photo.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-tell.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-temp.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-temp_OI.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-text.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-voice.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-def.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-premium-email-premium.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-premium-email-premium_OI.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-t1-bg.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\email-temp-bg.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\estatationery.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\flashpatch.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\flashpreview.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\fs3.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\hotbar_promo.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_checked_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_close_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_close_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_edit_preview.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_edit_send.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_flash_preview.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_recently_used.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_remove_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_remove_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_sand-clock2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_tell_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_tell_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_tree_null.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_unchecked_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\icon_unchecked_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\img_barlayout.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\img_barlayout2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\img_barlayout4.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\img_corner_left.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\img_local_logo.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_basetemplate.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_hbgroups.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_hbobject3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_hbobjectset3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_hotbarwrapper.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_iteratorsandreaders3nf.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_pagingmoduleobj3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_texts3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\js2_xmltree3nf.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\layout.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\linkpathlegal.txt
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\more.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\n.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\nav_b_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\nav_bb_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\nav_f_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\nav_ff_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\progress.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\searchbtn.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\submit.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_bg.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_bga.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_bgia.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_l.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_la.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_lia.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_r.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_ra.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tab_ria.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tree_dots.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tree_minus.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\tree_plus.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_animations.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_backgrounds.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_ecards.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_emoticons.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_notifiers.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_text.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte10_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte11_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte12_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte13_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte14_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte19_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte20_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte21_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030104_emte9_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\030203lib_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102angel_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102bigluf_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102bigsmile_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102birthday_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102cheers_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102flo_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102good_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102jump_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102king_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102lough_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102luf_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102smile_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102smiled_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102sor_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102thanx_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\033102uhu_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\040103ahh_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\040103wow_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\040104_emi2_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\042102_1134_112_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\050103big_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\050103gig_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\050103hm_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\050103nomail_emoti_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\050103norm_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema15_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema16_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema17_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema18_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema19_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema20_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema21_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema24_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema25_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema26_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema30_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema33_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\060104_ema34_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\062802hippi_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\062802jumpie_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\080402argh_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\080402oops_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\080402ouch_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\082502no_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\082502yes_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_boring1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_confused_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_crying_ugly_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_fantastic_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_feel_better_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_gimme_break_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_heehee_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_hlopaet_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_ign_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_lol_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_no_comment_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_peace_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_smashing_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\110103_talk2thehand_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\block_sm.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\block_sm2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\block_smli.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\block_smli2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\blocked.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\blocked2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_add-but.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_back-but.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_left_cut_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_left_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_left_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_middle_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_middle_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_right_cut_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_right_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\btn_right_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\business_promo.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\buttondir.txt
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\components.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\css_cattree.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\css_flashpreview.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\css2_main.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\css2_pagingmodule.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\css2_topbuttons.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\delete.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\edit_clear_sound.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\edit_fs.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\edit_select.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-511745-514279.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-backgrounds.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-bcards.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-ecards.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-edit.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-emoticons.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-estationery.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-funny.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-help.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-images.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-info.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-more.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-my.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-people.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-photo.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-tell.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-temp.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-temp_OI.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-text.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-voice.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-def.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-premium-email-premium.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-premium-email-premium_OI.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-t1-bg.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\email-temp-bg.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\estatationery.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\flashpatch.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\flashpreview.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\fs3.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\hotbar_promo.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_checked_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_close_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_close_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_edit_preview.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_edit_send.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_flash_preview.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_recently_used.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_remove_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_remove_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_sand-clock2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_tell_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_tell_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_tree_null.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_unchecked_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\icon_unchecked_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\img_barlayout.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\img_barlayout2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\img_barlayout4.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\img_corner_left.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\img_local_logo.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_basetemplate.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_hbgroups.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_hbobject3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_hbobjectset3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_hotbarwrapper.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_iteratorsandreaders3nf.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_pagingmoduleobj3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_texts3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\js2_xmltree3nf.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\layout.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\linkpathlegal.txt
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\more.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\n.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\nav_b_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\nav_bb_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\nav_f_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\nav_ff_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\progress.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\searchbtn.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\submit.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_bg.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_bga.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_bgia.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_l.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_la.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_lia.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_r.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_ra.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tab_ria.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tree_dots.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tree_minus.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\tree_plus.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_animations.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_backgrounds.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_ecards.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_emoticons.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_notifiers.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_text.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\business_promo.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\buttondir.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\code.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\email-def.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\email-temp-bg.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\hotbar_promo.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\images.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\layout.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\localcontent.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\more.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\progress.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\treexml.xip
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte10_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte11_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte12_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte13_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte14_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte19_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte20_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte21_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030104_emte9_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\030203lib_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102angel_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102bigluf_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102bigsmile_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102birthday_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102cheers_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102flo_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102good_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102jump_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102king_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102lough_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102luf_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102smile_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102smiled_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102sor_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102thanx_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\033102uhu_1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\040103ahh_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\040103wow_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\040104_emi2_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\042102_1134_112_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\050103big_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\050103gig_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\050103hm_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\050103nomail_emoti_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\050103norm_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema15_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema16_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema17_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema18_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema19_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema20_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema21_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema24_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema25_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema26_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema30_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema33_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\060104_ema34_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\062802hippi_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\062802jumpie_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\080402argh_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\080402oops_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\080402ouch_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\082502no_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\082502yes_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_boring1_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_confused_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_crying_ugly_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_fantastic_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_feel_better_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_gimme_break_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_heehee_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_hlopaet_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_ign_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_lol_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_no_comment_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_peace_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_smashing_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\110103_talk2thehand_prv.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\avatar.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\block_sm.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\block_sm2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\block_smli.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\block_smli2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\blocked.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\blocked2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_add-but.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_back-but.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_left_cut_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_left_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_left_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_middle_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_middle_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_right_cut_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_right_enabled_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\btn_right_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\business_promo.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\buttondir.txt
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\components.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\css_cattree.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\css_flashpreview.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\css2_main.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\css2_pagingmodule.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\css2_topbuttons.css
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\delete.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\edit_clear_sound.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\edit_fs.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\edit_select.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-543450.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-589306.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-591943.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-592579.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-598579.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-603763.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511724-9696.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-511745-514279.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-backgrounds.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-bcards.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-ecards.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-emoticons.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-estationery.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-funny.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-help.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-images.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-info.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-more.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-my.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-new.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-new2.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-options.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-people.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-photo.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-tell.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-temp.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-text.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def-email-voice.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-def.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-premium-email-premium.mnu
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-t1-bg.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\email-temp-bg.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\estatationery.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\flashpatch.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\flashpreview.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\fs3.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\hotbar_promo.htm
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_checked_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_close_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_close_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_edit_preview.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_edit_send.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_flash_preview.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_recently_used.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_remove_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_remove_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_sand-clock2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_tell_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_tell_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_tree_null.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_unchecked_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\icon_unchecked_pressed_1.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\img_barlayout.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\img_barlayout2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\img_barlayout4.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\img_corner_left.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\img_local_logo.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_basetemplate.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_hbgroups.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_hbobject3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_hbobjectset3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_hotbarwrapper.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_iteratorsandreaders3nf.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_pagingmoduleobj3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_texts3.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\js2_xmltree3nf.js
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\layout.cdf
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\linkpathlegal.txt
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\more.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\n.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\nav_b_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\nav_bb_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\nav_f_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\nav_ff_2.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\pro_hb_fo_word.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\progress.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\sales_buttons.res
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\searchbtn.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\submit.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_bg.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_bga.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_bgia.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_l.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_la.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_lia.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_r.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_ra.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tab_ria.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tree_dots.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tree_minus.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\tree_plus.gif
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\treedata_animations.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\treedata_backgrounds.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\treedata_ecards.xml
C:\Documents and Settings\bigeon sophie\Application Data\Hotbar\v3.0\HostOL\static\1\treedata_emoticons.xml
C:\Documents and Settings\bigeon sophie
suite
C:\Program Files\Fichiers communs\SystemDoctor
C:\Program Files\Fichiers communs\SystemDoctor\err.log
C:\Program Files\Fichiers communs\SystemDoctor\up.dat
C:\Program Files\Fichiers communs\SystemDoctor\USDR6cw.exe
C:\Program Files\Fichiers communs\SystemDoctor\usdrmdr.exe
C:\Program Files\Hotbar
C:\Program Files\Hotbar\bin\10.0.356.0\arrow.ico
C:\Program Files\Hotbar\bin\10.0.356.0\copyright.txt
C:\Program Files\Hotbar\bin\10.0.356.0\CoreSrv.dll
C:\Program Files\Hotbar\bin\10.0.356.0\dBenderC.dll
C:\Program Files\Hotbar\bin\10.0.356.0\firefox\extensions\chrome.manifest
C:\Program Files\Hotbar\bin\10.0.356.0\firefox\extensions\components\npclntax.xpt
C:\Program Files\Hotbar\bin\10.0.356.0\firefox\extensions\install.rdf
C:\Program Files\Hotbar\bin\10.0.356.0\firefox\extensions\plugins\npclntax_HotbarSA.dll
C:\Program Files\Hotbar\bin\10.0.356.0\HostOE.dll
C:\Program Files\Hotbar\bin\10.0.356.0\HostOL.dll
C:\Program Files\Hotbar\bin\10.0.356.0\HotbarSADF.exe
C:\Program Files\Hotbar\bin\10.0.356.0\HotbarSAHook.dll
C:\Program Files\Hotbar\bin\10.0.356.0\HotbarUnInstaller.exe
C:\Program Files\Hotbar\bin\10.0.356.0\link.ico
C:\Program Files\Hotbar\bin\10.0.356.0\Srv.exe
C:\Program Files\Hotbar\bin\10.0.356.0\Toolbar.dll
C:\Program Files\Hotbar\bin\10.0.356.0\Wallpaper.dll
C:\WINDOWS\BM03c5ff94.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aqnlkewf.ini
C:\WINDOWS\system32\aruqahsw.ini
C:\WINDOWS\system32\aukuesqy.ini
C:\WINDOWS\system32\aydoayfq.exe
C:\WINDOWS\system32\bhwcykvr.ini
C:\WINDOWS\system32\bnhkvjnh.ini
C:\WINDOWS\system32\CfiPAcfe.ini
C:\WINDOWS\system32\CfiPAcfe.ini2
C:\WINDOWS\system32\cmrvemtu.ini
C:\WINDOWS\system32\ddeeg.bak1
C:\WINDOWS\system32\ddeeg.bak2
C:\WINDOWS\system32\ddeeg.ini
C:\WINDOWS\system32\ddLoqtwa.ini
C:\WINDOWS\system32\ddLoqtwa.ini2
C:\WINDOWS\system32\dgiOnUvw.ini
C:\WINDOWS\system32\dgiOnUvw.ini2
C:\WINDOWS\system32\dqudilyv.ini
C:\WINDOWS\system32\ejdlipjo.ini
C:\WINDOWS\system32\eltgdxxu.ini
C:\WINDOWS\system32\eodocjsm.ini
C:\WINDOWS\system32\etonvssb.ini
C:\WINDOWS\system32\fahsujjn.ini
C:\WINDOWS\system32\fqltbvtr.ini
C:\WINDOWS\system32\fruyijct.ini
C:\WINDOWS\system32\ftiexbbh.ini
C:\WINDOWS\system32\ftqwftyr.ini
C:\WINDOWS\system32\geyxfuto.ini
C:\WINDOWS\system32\gtipcfob.ini
C:\WINDOWS\system32\gvasmseg.ini
C:\WINDOWS\system32\hgkqhhnh.ini
C:\WINDOWS\system32\hkfmcbnm.ini
C:\WINDOWS\system32\hpyolekt.ini
C:\WINDOWS\system32\hqlvkodp.ini
C:\WINDOWS\system32\htsptxvd.ini
C:\WINDOWS\system32\ihkmp.bak1
C:\WINDOWS\system32\imymshpo.ini
C:\WINDOWS\system32\iqbufrph.ini
C:\WINDOWS\system32\irypbhks.ini
C:\WINDOWS\system32\iwgckdod.ini
C:\WINDOWS\system32\jfchqvtb.ini
C:\WINDOWS\system32\jhddymci.ini
C:\WINDOWS\system32\jlyucmql.ini
C:\WINDOWS\system32\jnftmyxi.ini
C:\WINDOWS\system32\jpdtsbbu.ini
C:\WINDOWS\system32\jujtmjfb.ini
C:\WINDOWS\system32\jwwvkywi.ini
C:\WINDOWS\system32\jytvvmdy.ini
C:\WINDOWS\system32\kcdhgtyg.ini
C:\WINDOWS\system32\kctpgocd.ini
C:\WINDOWS\system32\kcvivemr.ini
C:\WINDOWS\system32\kehsxwlj.ini
C:\WINDOWS\system32\kknrlkvl.ini
C:\WINDOWS\system32\knnmp.bak1
C:\WINDOWS\system32\ksuiinns.ini
C:\WINDOWS\system32\lmWvyyxx.ini
C:\WINDOWS\system32\lmWvyyxx.ini2
C:\WINDOWS\system32\lnnmp.bak1
C:\WINDOWS\system32\lnnmp.bak2
C:\WINDOWS\system32\lnnmp.ini
C:\WINDOWS\system32\lxapxhsp.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mqvxjidy.ini
C:\WINDOWS\system32\nkmadwif.ini
C:\WINDOWS\system32\pdesbmbd.ini
C:\WINDOWS\system32\pkdeaejq.ini
C:\WINDOWS\system32\pkhgotdb.ini
C:\WINDOWS\system32\QAJmUvut.ini
C:\WINDOWS\system32\QAJmUvut.ini2
C:\WINDOWS\system32\qfgxtgml.ini
C:\WINDOWS\system32\qtutv.bak1
C:\WINDOWS\system32\rapatpru.ini
C:\WINDOWS\system32\rqtwa.bak1
C:\WINDOWS\system32\rqtwa.bak2
C:\WINDOWS\system32\rqtwa.ini
C:\WINDOWS\system32\rujbcdbb.ini
C:\WINDOWS\system32\scasmoop.ini
C:\WINDOWS\system32\scgjoslb.ini
C:\WINDOWS\system32\srgvqutc.ini
C:\WINDOWS\system32\SrXyxyay.ini
C:\WINDOWS\system32\SrXyxyay.ini2
C:\WINDOWS\system32\suyxdaeq.ini
C:\WINDOWS\system32\svibbwhg.ini
C:\WINDOWS\system32\tflnbqvh.ini
C:\WINDOWS\system32\torxfkqt.ini
C:\WINDOWS\system32\udftwiav.ini
C:\WINDOWS\system32\ugjncvon.ini
C:\WINDOWS\system32\usgpnefn.ini
C:\WINDOWS\system32\usptmabn.ini
C:\WINDOWS\system32\UwFNpXbc.ini
C:\WINDOWS\system32\UwFNpXbc.ini2
C:\WINDOWS\system32\uypjyvjr.ini
C:\WINDOWS\system32\vigbyeur.ini
C:\WINDOWS\system32\wavfphbq.ini
C:\WINDOWS\system32\wchwxdqi.ini
C:\WINDOWS\system32\wFiPonmp.ini
C:\WINDOWS\system32\wFiPonmp.ini2
C:\WINDOWS\system32\wqutlacd.ini
C:\WINDOWS\system32\xdgsvmor.ini
C:\WINDOWS\system32\xkbpulsp.ini
C:\WINDOWS\system32\xljuhxsm.ini
C:\WINDOWS\system32\xshitoku.ini
C:\WINDOWS\system32\ylugrhfj.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-25 to 2008-05-25 ))))))))))))))))))))))))))))))))))))
.
2008-05-25 14:47 . 2008-05-25 14:47 <REP> d-------- C:\WINDOWS\system32\fr
2008-05-25 14:47 . 2008-05-25 14:47 <REP> d-------- C:\WINDOWS\system32\bits
2008-05-25 14:47 . 2008-05-25 14:47 <REP> d-------- C:\WINDOWS\l2schemas
2008-05-25 14:43 . 2008-05-25 14:47 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-05-25 14:32 . 2008-05-25 14:32 <REP> d-------- C:\WINDOWS\EHome
2008-05-25 12:17 . 2004-08-04 00:38 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-25 09:17 . 2008-05-25 09:17 <REP> d-------- C:\VundoFix Backups
2008-05-24 21:19 . 2008-05-25 19:15 <REP> d-------- C:\Program Files\Navilog1
2008-05-24 20:57 . 2008-05-24 20:57 <REP> d-------- C:\Program Files\XnView
2008-05-24 20:54 . 2008-05-24 20:54 <REP> d-------- C:\Documents and Settings\bigeon sophie\Application Data\vlc
2008-05-24 20:52 . 2008-05-24 20:52 <REP> d-------- C:\Program Files\VideoLAN
2008-05-24 19:14 . 2008-05-24 19:14 <REP> d-------- C:\Program Files\Trend Micro
2008-05-24 18:33 . 2008-05-24 18:33 <REP> d-------- C:\Program Files\microsoft frontpage
2008-05-24 13:45 . 2008-05-24 13:45 <REP> d-------- C:\Program Files\Avira
2008-05-24 13:45 . 2008-05-24 13:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-24 12:01 . 2008-05-24 12:01 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SUPERAntiSpyware.com
2008-05-24 11:59 . 2005-11-16 12:46 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-05-24 11:59 . 2005-11-16 12:46 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-05-24 11:59 . 2005-11-16 12:33 <REP> d---s---- C:\Documents and Settings\Administrateur\UserData
2008-05-24 11:59 . 2006-03-14 16:16 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-05-24 11:59 . 2005-11-17 11:55 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-05-24 11:59 . 2005-11-16 12:46 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-05-24 11:59 . 2005-11-17 10:57 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-05-24 11:59 . 2008-05-24 18:21 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-05-24 11:59 . 2005-11-17 10:58 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
2008-05-24 11:59 . 2005-11-17 11:55 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\CyberLink
2008-05-24 11:59 . 2008-05-24 18:24 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\AOL
2008-05-24 11:59 . 2008-05-24 11:59 <REP> d-------- C:\Documents and Settings\Administrateur
2008-05-24 11:51 . 2008-05-24 11:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-24 11:50 . 2008-05-24 11:50 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-24 11:50 . 2008-05-24 11:50 <REP> d-------- C:\Documents and Settings\bigeon sophie\Application Data\SUPERAntiSpyware.com
2008-05-24 11:49 . 2008-05-24 11:49 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-05-24 09:34 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-05-24 09:34 . 2001-08-23 17:04 12,288 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-05-24 09:30 . 2008-05-24 09:30 0 --a------ C:\WINDOWS\system32\drivers\SET3.tmp
2008-05-24 09:26 . 2008-04-13 20:45 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-05-23 22:12 . 2008-05-23 22:12 268 --ah----- C:\sqmdata00.sqm
2008-05-23 22:12 . 2008-05-23 22:12 244 --ah----- C:\sqmnoopt00.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-25 19:04 --------- d-----w C:\Program Files\Wanadoo
2008-05-25 16:33 --------- d-----w C:\Program Files\MSN Messenger
2008-05-24 16:30 --------- d-----w C:\Program Files\Fichiers communs\aolshare
2008-05-24 16:30 --------- d-----w C:\Program Files\DivX
2008-05-24 16:30 --------- d-----w C:\Program Files\AOL Compagnon
2008-05-24 16:30 --------- d-----w C:\Program Files\AOL 9.0
2008-05-24 16:24 --------- d-----w C:\Program Files\Fichiers communs\AOL
2008-05-24 16:24 --------- d-----w C:\Documents and Settings\carrefour\Application Data\AOL
2008-05-24 16:24 --------- d-----w C:\Documents and Settings\bigeon sophie\Application Data\AOL
2008-05-24 16:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-05-24 12:17 --------- d-----w C:\Program Files\ConducteurPrive
2008-04-20 19:18 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-14 02:33 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-14 02:10 73,600 ----a-w C:\WINDOWS\system32\drivers\sr.sys
2008-04-14 02:09 80,384 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-04-14 02:09 68,608 ----a-w C:\WINDOWS\system32\drivers\pci.sys
2008-04-14 02:09 46,848 ----a-w C:\WINDOWS\system32\drivers\p3.sys
2008-04-14 02:09 120,576 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys
2008-04-14 02:05 800,256 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-14 02:05 25,216 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-14 02:05 154,496 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-14 02:04 37,632 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
2008-04-14 02:03 5,504 ----a-w C:\WINDOWS\system32\drivers\intelide.sys
2008-04-14 02:03 40,576 ----a-w C:\WINDOWS\system32\drivers\intelppm.sys
2008-04-14 02:02 40,960 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
2008-04-14 02:00 66,048 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-14 02:00 54,144 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-14 01:59 25,856 ------w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-14 01:58 273,664 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-14 01:57 58,752 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
2008-04-14 01:57 44,672 ----a-w C:\WINDOWS\system32\drivers\fips.sys
2008-04-14 01:56 53,376 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-14 01:55 40,064 ----a-w C:\WINDOWS\system32\drivers\processr.sys
2008-04-14 01:54 41,856 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
2008-04-14 01:54 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
2008-04-14 01:53 30,336 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-14 01:53 23,680 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-14 01:52 188,672 ----a-w C:\WINDOWS\system32\drivers\acpi.sys
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 30,592 ------w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,800 ------w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:55 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:54 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 ----a-w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 18:51 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 18:51 55,808 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 18:51 101,120 ------w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 18:47 25,856 ----a-w C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-13 18:45 60,160 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
2008-04-13 18:44 81,664 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 18:44 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys
2008-04-13 18:43 14,208 ------w C:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 18:43 12,672 ------w C:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 18:39 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 18:39 5,504 ----a-w C:\WINDOWS\system32\drivers\mstee.sys
2008-04-13 18:39 5,376 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 18:39 42,368 ----a-w C:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 18:39 4,992 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys
2008-04-13 18:39 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
2005-11-18 08:02 8 --sha-r C:\WINDOWS\system32\EFF80A778C.sys
2005-11-18 08:02 4,704 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4d7f95e1-3a5c-405b-93a5-3fa156c979cb}]
C:\WINDOWS\system32\jxlglcyx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
"WOOKIT"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 17:55 32768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-30 09:06 68856]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2008-01-02 21:15 103712]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-13 12:43 1510640]
"msnmsgr"="~C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-08 11:02 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-08 10:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-08 11:03 114688]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-07-08 11:05 729178]
"RemoteControl"="C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-17 10:58 98304]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 04:52 36975]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-09 15:17 14743552 C:\WINDOWS\RTHDCPL.EXE]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-11-17 10:57 26112]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"autoclk"="autoclk.exe" []
"adiras"="adiras.exe" []
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 15:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 17:55 32768]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2006-12-22 13:27 497176]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2006-12-22 13:28 756248]
"F-Secure Manager"="C:\Program Files\AntivirusFirewall\Common\FSM32.exe" [2005-10-26 03:51 122929]
"F-Secure TNB"="C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" [2005-07-18 16:51 700416]
"F-Secure Startup Wizard"="C:\Program Files\AntivirusFirewall\FSGUI\FSSW.exe" [2005-10-18 10:29 372736]
"News Service"="C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe" [2005-05-31 14:45 356352]
"ConducteurPrive"="C:\Program Files\ConducteurPrive\GDC.exe" [ ]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2008-01-02 21:15 103712]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [ ]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:33 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcdaay]
ddcdaay.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnljhh]
nnnljhh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqQiHxw]
urqQiHxw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\AntivirusFirewall\\backweb\\6588780\\Program\\fspex.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-11-18 17:04]
R2 BackWeb Plug-in - 6588780;Antivirus Firewall;C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE [2007-02-14 09:51]
R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\AntivirusFirewall\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 17:14]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\AntivirusFirewall\Anti-Virus\Win2K\FSgk.sys [2008-03-21 13:08]
R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\AntivirusFirewall\Anti-Virus\Win2K\FSrec.sys [2004-06-01 11:03]
R2 OPTENET_FILTER;Control Parental;C:\Program Files\Controle Parental\bin\optproxy.exe [2006-03-02 18:10]
R3 W33ND;W89C33 mPCI 802.11 Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\W33ND.SYS [2005-03-25 17:33]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 20:25]
S3 CBEN5;Pilote de la famille de carte CardBus Ethernet 10/100 Xircom;C:\WINDOWS\system32\DRIVERS\cben5.sys []
S3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 19:50]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-25 07:10:41 C:\WINDOWS\Tasks\Scheduled scanning task.job"
- C:\PROGRA~1\ANTIVI~1\ANTI-V~1\fsav.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-25 21:02:36
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fsbwsys.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32.exe
C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\FTRTSVC.exe
C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\FSRW.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\FSAV32.exe
C:\Program Files\AntivirusFirewall\FWES\program\fsdfwd.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\PROGRA~1\ANTIVI~1\ANTI-S~1\FSAW.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\system32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Fichiers communs\LogiShrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-25 21:07:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-25 19:07:14
Pre-Run: 15,815,593,984 octets libres
Post-Run: 15,638,032,384 octets libres
1725 --- E O F --- 2008-05-24 09:57:14
Reposte un rapport Hijackthis.
Répondre à Angeldark
ok
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:27:33, on 25/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: {bc979c65-1af3-5a39-b504-c5a31e59f7d4} - {4d7f95e1-3a5c-405b-93a5-3fa156c979cb} - C:\WINDOWS\system32\jxlglcyx.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [ConducteurPrive] C:\Program Files\ConducteurPrive\GDC.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
O4 - Global Startup: DSLMON.lnk = ?
O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 2137206531
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ddcdaay - ddcdaay.dll (file missing)
O20 - Winlogon Notify: nnnljhh - nnnljhh.dll (file missing)
O20 - Winlogon Notify: urqQiHxw - urqQiHxw.dll (file missing)
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 12480 bytes
Désinstalle SweetIM puis reposte un rapport Hijackthis.
Répondre à Angeldark
bonjour Angeldark
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:05:04, on 26/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: {bc979c65-1af3-5a39-b504-c5a31e59f7d4} - {4d7f95e1-3a5c-405b-93a5-3fa156c979cb} - C:\WINDOWS\system32\jxlglcyx.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [ConducteurPrive] C:\Program Files\ConducteurPrive\GDC.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
O4 - Global Startup: DSLMON.lnk = ?
O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra button: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 2137206531
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ddcdaay - ddcdaay.dll (file missing)
O20 - Winlogon Notify: nnnljhh - nnnljhh.dll (file missing)
O20 - Winlogon Notify: urqQiHxw - urqQiHxw.dll (file missing)
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 12377 bytes
Re,
Fix les lignes dans le cadre ci-dessous avec HijackThis : AIDE EN IMAGES
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
|
Répondre à Angeldark
ok
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:34, on 26/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
O4 - Global Startup: DSLMON.lnk = ?
O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
O9 - Extra button: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/window [...] 2137206531
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 11382 bytes
nouvelle alerte antivir
c:\System Volume Information\...\A0044168.dll is the Trojan horse TR/Vundo.Gen
Il te suffit de désactiver puis réactiver la restauration du système.
Répondre à Angeldark
bonjour Angeldark
opération effectuée
Ça devrait être ok.
Répondre à Angeldark
bonjour Angeldark
tout est ok
un grand merci à toi
le sujet peut être clôturé
On peut laisser ouvert, bon surf
Répondre à Angeldark
Il y a 1033 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
