verification apres probleme iexplorer.exe [résolu] - Sécurité - Virus
TomsGuide.com : 700 000 inscrits répondent à toutes vos questions high-tech et informatique.
Pour obtenir de l'aide, inscrivez-vous gratuitement !
 




Mot :   Pseudo :  
 
Bas de page
Auteur
 Sujet : verification apres probleme iexplorer.exe [résolu]
 
Profil : IDNaute
Plus d'informations

Bonjour à tous,
J'avais un probleme avec iexplorer.exe. Est ce que vous pouvez analyser les logs HIJACKTHIS pour voir si c'est OK???
Merci de votre aide

les logs :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:11:00, on 29/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\program files\lotus\notes\ntmulti.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\TPHDEXLG.EXE
C:\WINNT\system32\TpKmpSVC.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\lotus\organize\easyclip.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Internet Explorer\iehook.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\explorer.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ABB
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [884d88f4] rundll32.exe "C:\WINNT\system32\ubflmqxy.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Babylon Translator] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINNT\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Lotus Organizer EasyClip.lnk = ?
O4 - Global Startup: Lotus QuickStart.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - c:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://inside.abb.com
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activ [...] stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mi [...] 7006427421
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - McAfee, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\system32\ibmpmsvc.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\program files\lotus\notes\ntmulti.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINNT\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exe

--
End of file - 8899 bytes


Message édité par elg_49 le 10-09-2008 Ã  00:27:56
Liens sponsorisés


Inscrivez-vous ou connectez-vous pour masquer ceci.

Profil : Helper
Plus d'informations

Bonjour,

Apparemment Vundo.

Télécharge ComboFix (de sUBs) sur ton Bureau.

  • Désactive temporairement toute protection résidente ! (Antivirus, antispywares..)
  • Double clique sur ComboFix.exe.
  • Accepte la licence en cliquant sur Oui.
  • Lorsque l'opération sera terminée, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.


Le rapport se trouve ici : %systemdrive%\ComboFix.txt (%systemdrive% étant la partition où est installée Windows; C:\ en général)

Aide : Comment utiliser ComboFix.


---------------
Prière de signaler si vous vous faites déjà aider sur un autre forum ou dans un autre topic.

Sécurité/Prévention
Profil : IDNaute
Plus d'informations

Bonjour,
Voici le rapport conbofix. Au moment du scan, j'ai eu plusieurs fois le message suivant "The application or DLL c:\WINNT\System32\clbdll.dll i snot a valid windows image. Please check this against your installation diskette"

Les logs:
ComboFix 08-07-29.1 - A ELLOUGANI 2008-07-30 15:35:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.517 [GMT 0:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\system32\clbdll.dll
C:\WINNT\system32\clbdll.old
C:\WINNT\system32\clbinit.dll
C:\WINNT\system32\drivers\clbdriver.sys
C:\WINNT\system32\drivers\Winxf75.sys
C:\WINNT\system32\ehilRXbc.ini
C:\WINNT\system32\ehilRXbc.ini2
C:\WINNT\system32\fijflgei.dll
C:\WINNT\system32\jshfjhqr.ini
C:\WINNT\system32\llalfeky.dll
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\nnnlkHyv.dll
C:\WINNT\system32\rwnekgkg.ini
C:\WINNT\system32\smnqnmag.ini
C:\WINNT\system32\urqOFuRl.dll
C:\WINNT\system32\vav.cpl
C:\WINNT\system32\WinCtrl32.dll
C:\WINNT\system32\ydboxvoi.ini
C:\WINNT\system32\yxqmlfbu.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CLBDRIVER
-------\Legacy_WINXF75
-------\Service_Winxf75


((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-30 )))))))))))))))))))))))))))))))
.

2008-07-30 15:50 . 2008-07-30 15:50 53,248 --a------ C:\temp\catchme.dll
2008-07-30 14:23 . 2008-07-30 14:23 <DIR> d-------- C:\temp\72DF
2008-07-30 14:13 . 2008-07-30 14:13 <DIR> d-------- C:\temp\6B62
2008-07-30 13:52 . 2008-07-30 13:52 <DIR> d-------- C:\temp\BTN%Copy%1
2008-07-30 11:44 . 2008-07-30 11:53 <DIR> d-------- C:\temp\hsperfdata_A ELLOUGANI
2008-07-30 11:08 . 2008-07-30 11:08 99,456 --a------ C:\WINNT\system32\rqhjfhsj.dll
2008-07-29 19:59 . 2008-07-29 19:59 <DIR> d-------- C:\temp\smkits
2008-07-29 19:28 . 2008-07-29 19:29 <DIR> d-------- C:\Program Files\Software by Design
2008-07-29 19:28 . 2005-05-25 05:00 90,112 --------- C:\WINNT\SDUnInst.exe
2008-07-29 17:56 . 2008-07-29 17:56 <DIR> d-------- C:\temp\VBE
2008-07-29 15:01 . 2008-07-29 15:01 <DIR> d-------- C:\temp\41FA
2008-07-29 14:47 . 2008-07-29 14:47 <DIR> d-------- C:\temp\Google Toolbar
2008-07-29 14:47 . 2008-07-29 14:47 <DIR> d-------- C:\temp\BabylonData
2008-07-29 14:44 . 2008-07-30 15:50 <DIR> d-------- C:\temp\WERdf6a.dir00
2008-07-29 14:44 . 2008-07-30 15:50 <DIR> d-------- C:\temp\WERcd0a.dir00
2008-07-29 14:44 . 2008-07-30 15:50 <DIR> d-------- C:\temp\WERc8c6.dir00
2008-07-29 14:23 . 2008-07-29 20:04 <DIR> d-------- C:\temp\notesAE2D45
2008-07-29 14:10 . 2008-07-29 14:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-29 14:05 . 2008-07-29 14:05 <DIR> d-------- C:\Program Files\Panda Security
2008-07-29 14:05 . 2008-06-19 17:24 28,544 --a------ C:\WINNT\system32\drivers\pavboot.sys
2008-07-29 13:15 . 2008-07-30 15:50 <DIR> d-------- C:\temp\Word8.0
2008-07-29 12:22 . 2008-07-30 15:50 <DIR> d-------- C:\temp\a2temp
2008-07-29 12:21 . 2008-07-29 13:21 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2008-07-29 00:51 . 2008-07-30 15:50 <DIR> d-------- C:\temp\jkos-A ELLOUGANI
2008-07-29 00:50 . 2008-06-10 02:32 73,728 --a------ C:\WINNT\system32\javacpl.cpl
2008-07-28 23:54 . 2008-07-28 23:54 <DIR> d---s---- C:\temp\Temporary Internet Files
2008-07-28 23:54 . 2008-07-28 23:54 <DIR> d---s---- C:\temp\History
2008-07-28 23:54 . 2008-07-30 15:50 <DIR> d---s---- C:\temp\Cookies
2008-07-28 23:35 . 2008-07-30 15:50 <DIR> d-------- C:\temp\WER2cc4.dir00
2008-07-26 06:36 . 2008-07-26 06:36 94,848 --a------ C:\WINNT\system32\gamnqnms.dll
2008-07-25 19:45 . 1996-08-20 20:37 15,840 --a------ C:\WINNT\system32\Machnm1.exe
2008-07-25 19:45 . 2005-09-25 16:37 5,632 --a------ C:\WINNT\system32\Machnm64.sys
2008-07-25 19:45 . 2008-07-25 19:45 3,120 --a------ C:\WINNT\system32\118290.54
2008-07-25 19:45 . 2008-07-25 19:45 3,120 --a------ C:\WINNT\118294.78
2008-07-25 19:45 . 2003-08-13 00:27 2,304 --a------ C:\WINNT\system32\Machnm32.sys
2008-07-25 17:10 . 2008-07-27 23:17 <DIR> d-------- C:\Program Files\AVM
2008-07-25 17:10 . 2008-07-25 08:17 120,320 --a------ C:\WINNT\system32\avm.cpl
2008-07-25 16:50 . 2008-07-25 16:51 30,672 --a------ C:\a
2008-07-25 15:01 . 2008-07-25 15:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-25 14:19 . 2008-07-30 15:50 <DIR> d-------- C:\temp\NSU_b77b2a565b734e3913dbdc
2008-07-25 11:59 . 2004-08-03 23:08 25,600 --a------ C:\WINNT\system32\drivers\usbser.sys
2008-07-25 11:59 . 2004-08-03 23:08 25,600 --a--c--- C:\WINNT\system32\dllcache\usbser.sys
2008-07-25 11:59 . 2008-07-25 11:59 0 --ah----- C:\WINNT\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-07-25 11:59 . 2008-07-25 11:59 0 --ah----- C:\WINNT\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-07-25 00:32 . 2008-07-25 00:32 323,584 --a------ C:\WINNT\system32\cbXRlihe.dll
2008-07-25 00:27 . 2008-07-30 14:27 <DIR> d-------- C:\temp\__SkypeIEToolbar_Cache
2008-07-25 00:27 . 2008-07-25 00:27 34,816 --a------ C:\WINNT\system32\clbdll.dll.vir
2008-07-25 00:27 . 2004-08-04 08:00 4,224 --a------ C:\WINNT\system32\beep.sys
2008-07-25 00:08 . 2008-05-07 07:39 1,419,232 --a------ C:\WINNT\system32\wdfcoinstaller01005.dll
2008-07-25 00:08 . 2008-05-07 07:38 659,968 --a------ C:\WINNT\system32\nmwcdcocls.dll
2008-07-25 00:08 . 2008-05-07 07:38 20,864 --a------ C:\WINNT\system32\drivers\ccdcmbo.sys
2008-07-25 00:08 . 2008-05-07 07:38 17,536 --a------ C:\WINNT\system32\drivers\ccdcmb.sys
2008-07-25 00:08 . 2008-05-07 07:38 8,064 --a------ C:\WINNT\system32\drivers\usbser_lowerfltj.sys
2008-07-25 00:08 . 2008-06-06 09:24 8,064 --a------ C:\WINNT\system32\drivers\usbser_lowerflt.sys
2008-07-25 00:07 . 2008-07-25 00:07 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-07-24 16:41 . 2008-07-24 16:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\NSeries
2008-07-18 22:01 . 2008-07-18 22:01 <DIR> d-------- C:\Program Files\HSDPA USB MODEM
2008-07-18 22:01 . 2007-11-01 15:35 103,424 --a------ C:\WINNT\system32\MyDIT_GenClassCoInst.dll
2008-07-18 22:01 . 2007-10-16 11:40 97,408 --a------ C:\WINNT\system32\drivers\cmusbser.sys
2008-07-13 11:22 . 2007-08-24 19:45 101,120 -ra------ C:\WINNT\system32\drivers\ewusbmdm.sys
2008-07-13 11:22 . 2007-08-24 19:45 24,448 -ra------ C:\WINNT\system32\drivers\ewdcsc.sys
2008-07-13 11:21 . 2008-07-13 11:23 <DIR> d-------- C:\Program Files\Internet Mobile
2008-07-13 11:20 . 2004-08-03 23:08 17,024 --a------ C:\WINNT\system32\drivers\usbohci.sys
2008-07-13 11:20 . 2004-08-03 23:08 17,024 --a--c--- C:\WINNT\system32\dllcache\usbohci.sys
2008-07-10 19:58 . 2008-07-13 12:15 <DIR> d-------- C:\LOGIAPRO
2008-07-10 19:31 . 2008-07-10 19:58 <DIR> d-------- C:\Program Files\Common Files\PC SOFT
2008-07-10 19:31 . 2008-07-13 12:16 <DIR> d-------- C:\logiasyndic
2008-06-11 23:56 . 2008-06-12 00:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\U3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-30 15:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-07-30 14:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-07-29 00:50 --------- d-----w C:\Program Files\Java
2008-07-25 19:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-25 00:08 --------- d-----w C:\Program Files\Nokia
2008-07-25 00:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-07-25 00:06 --------- d-----w C:\Program Files\Common Files\Nokia
2008-07-24 16:42 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-07-24 16:29 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-06-27 19:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Babylon
2008-03-28 21:52 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-09 22:19 2,293,848 -c--a-w C:\Program Files\FLV PlayerFCSetup.exe
2008-02-09 22:17 3,955,352 -c--a-w C:\Program Files\FLV PlayerRCATSetup.exe
2008-02-09 21:34 411,248 -c--a-w C:\Program Files\FLV PlayerRCSetup.exe
2007-03-09 08:12 27,648 -csha-w C:\WINNT\system32\AVSredirect.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A32C803-1CB0-495A-8381-928837187B2E}]
2008-07-25 00:32 323584 --a------ C:\WINNT\system32\cbXRlihe.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-17 09:57 68856]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024]
"Babylon Translator"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2004-04-01 11:43 2400323]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12 695808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 10:18 49152]
"NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-08-02 14:30 3096576]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-23 16:37 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"884d88f4"="C:\WINNT\system32\rqhjfhsj.dll" [2008-07-30 11:08 99456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\system32\CTFMON.EXE" [2004-08-04 08:00 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-05-04 19:39:42 2913840]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe [2005-11-01 14:10:32 581693]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-05-16 09:54:22 24576]
Lotus Organizer EasyClip.lnk - C:\lotus\organize\easyclip.exe [2002-08-08 20:49:20 87040]
Lotus QuickStart.lnk - C:\lotus\wordpro\ltsstart.exe [2002-08-08 08:23:48 32768]
VPN Client.lnk - C:\WINNT\Installer\{24C67B54-0718-445E-B663-3138D9246BD1}\Icon3E5562ED7.ico [2006-05-16 10:40:19 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoSMMyPictures"= 1 (0x1)
"NoSimpleStartMenu"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"= 0 (0x0)
"Btn_Forward"= 0 (0x0)
"Btn_Stop"= 0 (0x0)
"Btn_Refresh"= 0 (0x0)
"Btn_Home"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"Btn_History"= 0 (0x0)
"Btn_Favorites"= 0 (0x0)
"Btn_Media"= 2 (0x2)
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Folders"= 0 (0x0)
"Btn_Fullscreen"= 0 (0x0)
"Btn_Tools"= 0 (0x0)
"Btn_MailNews"= 0 (0x0)
"Btn_Size"= 0 (0x0)
"Btn_Print"= 0 (0x0)
"Btn_Edit"= 0 (0x0)
"Btn_Discussions"= 0 (0x0)
"Btn_Cut"= 0 (0x0)
"Btn_Copy"= 0 (0x0)
"Btn_Paste"= 0 (0x0)
"Btn_Encoding"= 0 (0x0)
"Btn_PrintPreview"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoSimpleStartMenu"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2006-04-17 12:01 32768 C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 22:45 28672 C:\WINNT\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 19:16 24576 C:\WINNT\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= C:\PROGRA~1\REPLAY~1\iac25_32.ax
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 TivoliAP

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINNT\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 16:25 94208 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sametime Connect]
--a------ 2005-05-04 13:56 1310720 C:\Program Files\lotus\Sametime Client\connect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShStatEXE]
--a------ 2004-08-18 08:00 94208 C:\Program Files\Network Associates\VirusScan\shstat.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-02-23 16:37 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 pavboot;pavboot;C:\WINNT\system32\drivers\pavboot.sys [2008-06-19 17:24]
R0 Shockprf;Shockprf;C:\WINNT\system32\drivers\Shockprf.sys [2005-11-30 14:58]
R1 ANC;ANC;C:\WINNT\system32\drivers\ANC.SYS [2005-11-08 08:27]
R1 IBMTPCHK;IBMTPCHK;C:\WINNT\system32\Drivers\IBMBLDID.sys [2006-01-12 23:33]
R1 ShockMgr;ShockMgr;C:\WINNT\system32\drivers\ShockMgr.sys [2005-06-20 11:18]
R1 TPPWRIF;TPPWRIF;C:\WINNT\system32\drivers\Tppwrif.sys [2005-12-07 00:12]
S3 lcfd;Tivoli Endpoint;C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe [2005-05-22 01:15]
S3 qcusbser;Mobile Connector USB Device for Legacy Serial Communication;C:\WINNT\system32\DRIVERS\cmusbser.sys [2007-10-16 11:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\aamsstp\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53632f97-3285-11dd-9c78-0015587fd50b}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa86e88e-50cd-11dd-9c83-0019d22a4f22}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aa86e891-50cd-11dd-9c83-0019d22a4f22}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb79fa6e-5259-11dd-9c86-0015587fd50b}]
\Shell\AutoRun\command - E:\.\ShowModem.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
rundll32.exe advpack.dll,LaunchINFSectionEx C:\WINNT\INF\wmactedp.inf,PerUserStub,,4
.
Contents of the 'Scheduled Tasks' folder

2008-03-04 C:\WINNT\Tasks\PMTask.job
- C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2005-12-07 00:12]

2008-07-30 C:\WINNT\Tasks\SDMsgUpdate (TE).job
- C:\PROGRA~1\SMARTD~2\Messages\SDNotify.exe [2007-09-26 08:53]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R1 -: HKCU-Internet Settings,ProxyOverride = <local>
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Send To &Bluetooth - c:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: Translate with &Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm

O16 -: Microsoft XML Parser for Java - file://C:\WINNT\Java\classes\xmldso.cab
C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-30 15:50:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINNT\system32\winlogon.exe
-> C:\Program Files\ThinkPad\ConnectUtilities\AcSvcStub.dll
-> C:\Program Files\ThinkPad\ConnectUtilities\AcLocSettings.dll
-> C:\Program Files\ThinkPad\ConnectUtilities\ACHelper.dll
-> C:\WINNT\system32\tphklock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINNT\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINNT\system32\TPHDEXLG.exe
C:\WINNT\system32\TpKmpSvc.exe
C:\WINNT\system32\wdfmgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\system32\ati2evxx.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
.
**************************************************************************
.
Completion time: 2008-07-30 15:54:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-30 15:54:05

Pre-Run: 15,542,071,296 bytes free
Post-Run: 15,547,318,272 bytes free

330

Profil : Helper
Plus d'informations

Re,

Télécharge ZebRestore

Dézippe-le. Ouvre le dossier, lance le en double cliquant sur l’exécutable.

Coche :
- RegEdit
- Clés RUN
- Bouton Arrêter
- Windows Update
- Gestionnaire des tâches
- Panneau de configuration
- Ajout/Suppression de programmes
- Policies

Clique sur Restaurer. Ferme le programme.

-------------

Sélectionne l'intégralité du cadre ci-dessous :

Collect::
C:\WINNT\system32\cbXRlihe.dll
C:\WINNT\system32\rqhjfhsj.dll
C:\WINNT\system32\gamnqnms.dll

File::
C:\WINNT\system32\clbdll.dll.vir

Folder::
C:\temp

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A32C803-1CB0-495A-8381-928837187B2E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"=-
"884d88f4"=-



  • Copie/colle le dans le Bloc Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
  • Enregistre le sous sur ton bureau sous le nom de CFScript.txt
  • Glisse maintenant le fichier CFScript.txt dans ComboFix.exe comme ci-dessous :

http://i266.photobucket.com/albums/ii277/sUBs_/CFScript.gif

  • Cela va relancer Combofix.
  • ComboFix créera ces fichiers sur ton Bureau :

- Un fichier zippé nommé Submit [Date Time].zip
- Un second fichier nommé - CF-Submit.htm

  • ComboFix peut exiger un redémarrage pour compléter son travail. Accepte.
  • Lorsque l'outil aura terminé, un rapport ComboFix.log apparaîtra à l'écran.
  • Une nouvelle fenêtre avec invite "Submit Files for further analysis" s'ouvrira. Clique "OK"
  • Ton navigateur se lancera automatiquement avec le fichier CF-Submit.htm et une fenêtre s'ouvrira :

- Clique sur le bouton "Browse"("Parcourir" ) et navigue vers le fichier
Submit [Date Time].zip qui est sur ton Bureau.
- Clique sur le fichier afin de le sélectionner.

  • Soumets le fichier en cliquant "OK"
  • Lorsque cette opération sera complétée, tu peux supprimer ces deux fichiers qui se trouvent sur ton Bureau.

Poste le contenu du rapport ComboFix.txt après redémarrage s'il y en a un.


---------------
Prière de signaler si vous vous faites déjà aider sur un autre forum ou dans un autre topic.

Sécurité/Prévention
Profil : IDNaute
Plus d'informations

Bonjour XmichouX,
J'ai suivi la procédure. Au moment de l'envoi du fichier zip, j'ai eu le message suivant "improper usage" donc je ne sais pas si l'envoi est bon.

Les logs combofix:

ComboFix 08-07-29.1 - A ELLOUGANI 2008-07-31 13:11:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.487 [GMT 0:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINNT\system32\clbdll.dll.vir
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.external.css
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.external.html
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.external.js
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.graph.compat.css
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.graph.compat.js
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.graph.modern.css
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.graph.modern.js
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.text.css
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\session\menu.text.js
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_a.compat.flex.w11.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_a.compat.flex.w16.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_a.compat.stat.w11.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_a.compat.stat.w16.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_a.modern.flex.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_a.modern.stat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_m.compat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_m.modern.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_r.compat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_r.modern.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_ra.compat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_ra.modern.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s.compat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s.modern.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s_noflag.compat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s_noflag.modern.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s_stat.compat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s_stat.modern.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s_stat_noflag.compat.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\active_s_stat_noflag.modern.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AC.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AD.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AF.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AL.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AS.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AW.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\AZ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BB.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BD.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BF.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BH.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BJ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BS.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BW.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BY.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\BZ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CD.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CF.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CH.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CK.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CL.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CV.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CY.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\CZ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\DE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\DG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\DJ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\DK.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\DM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\DO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\DZ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\EC.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\EE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\EG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\ER.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\ES.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\ET.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\FI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\FJ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\FK.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\FM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\FO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\FR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GB.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GD.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GF.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GH.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GL.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GP.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GQ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GW.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\GY.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\HK.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\HN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\HR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\HT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\HU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\ID.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\IE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\IL.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\IN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\IQ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\IR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\IS.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\IT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\JM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\JO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\JP.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KH.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KP.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KW.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KY.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\KZ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LB.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LC.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LK.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LS.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LV.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LY.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MC.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MD.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\ME.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MH.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MK.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\ML.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MN.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MP.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MQ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MS.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MV.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MW.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MX.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MY.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\MZ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NC.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NI.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NL.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NP.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\NZ.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\OM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PF.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PG.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PH.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PK.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PL.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PM.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PR.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PS.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PT.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PW.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\PY.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\QA.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\RE.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\RO.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\RS.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\RU.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\RW.gif
C:\temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\SA.gif
C:\temp\__SkypeIEToolbar