suite....c:\program files\Zylom Games\Rainbow Web 2 Deluxe\zylom.ico
c:\program files\Zylom Games\Rainbow Web 2 Deluxe\ZylomCrashReport.dmp
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\bird.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\BLUEJAY2.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\CAVEWIND.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\chain.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\clockchime1.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\clocktick2.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\cock.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\creakslam.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\crickets.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\CRK_SQK1.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\crow.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\darkevil.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\earthquake.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\frog3.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\gravelwalk.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\harp.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Insect_Alien01.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Insect04.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Insect06.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\mice.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\mouse.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\nitepond.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\owl.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\owl2.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\sparrow3.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Step_Foliage01.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Step_Grass_B_01.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Step_Heavy_A_02.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Stream_Splash.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\thunder.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\thunderrumble2.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\treeSnoreIn.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\treeSnoreOut.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\Wind_Light_Loop.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\wolf2.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\ambient\write.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\bigbong01.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\gdchimes.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\goodmorning.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\IncDec1.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\IncDec4.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\IncDec5a.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\magicgenie.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\magicwand.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\MaxedOut4.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\mudfart.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\Music_Stinger04.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\newsalert.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\nicechime.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\PageChange1.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\PageChange2Hi.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\PageChange3.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\rollover3.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\rollover5.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\Select3.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\Select9.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\whoosh01.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\whoosh11.wav
c:\program files\Zylom Games\The Magician's Handbook Deluxe\cached\sounds\Wind_Gust11.wav
c:\program files\Zylom Games\Zylom puzzles Deluxe\players\players.plrs
c:\program files\Zylom Games\Zylom puzzles Deluxe\players\roger.plr
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-19 au 2008-11-19 ))))))))))))))))))))))))))))))))))))
.
2008-11-16 19:01 . 2008-11-16 19:01 <REP> d-------- c:\program files\JRE
2008-11-15 15:03 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-15 15:03 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-10 09:14 . 2008-11-17 14:26 <REP> d-------- c:\program files\Navilog1
2008-11-10 00:34 . 2008-11-10 00:34 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\OpenOffice.org
2008-11-09 14:03 . 2008-11-09 15:30 <REP> d--h----- C:\$AVG8.VAULT$
2008-11-09 10:57 . 2008-11-09 10:57 <REP> d-------- c:\documents and settings\Thomas\Application Data\Malwarebytes
2008-11-09 02:29 . 2008-11-16 19:01 <REP> d-------- c:\program files\OpenOffice.org 3
2008-11-09 01:45 . 2008-11-09 14:56 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-09 01:45 . 2008-11-09 01:45 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\Malwarebytes
2008-11-09 01:45 . 2008-11-09 01:45 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-09 01:45 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-09 01:45 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-08 22:09 . 2008-06-10 02:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-08 09:29 . 2008-11-08 09:29 <REP> d-------- c:\program files\AVG
2008-11-08 09:29 . 2008-11-19 09:50 <REP> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-11-01 16:07 . 2008-11-01 16:07 <REP> d-------- c:\documents and settings\All Users\Application Data\wmp
2008-10-29 21:49 . 2008-11-17 18:57 1,426 --a------ c:\windows\
0
2008-10-29 21:49 . 2008-11-17 18:57 190 --a------ c:\windows\Faux
2008-10-29 21:49 . 2008-11-17 18:57 87 --a------ c:\windows\Times New Roman
2008-10-29 21:44 . 2008-10-29 21:44 <REP> d-------- c:\program files\Mindscape
2008-10-24 12:38 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 23:03 . 2008-10-23 23:03 <REP> d-------- c:\program files\Fichiers communs\xing shared
2008-10-23 18:18 . 2008-10-26 07:14 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\U3
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 18:25 17,408 ----a-w c:\windows\system32\drivers\USBCRFT.SYS
2008-11-19 17:58 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Skype
2008-11-19 15:42 --------- d-----w c:\program files\VoipCheapCom
2008-11-19 15:42 --------- d-----w c:\documents and settings\Propriétaire\Application Data\skypePM
2008-11-19 12:16 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Apple Computer
2008-11-15 18:06 1,838 ----a-w c:\documents and settings\TEMP\Application Data\wklnhst.dat
2008-11-09 09:02 --------- d-----w c:\documents and settings\Thomas\Application Data\Apple Computer
2008-11-08 21:42 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2008-11-08 21:09 --------- d-----w c:\program files\Java
2008-11-05 17:57 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-03 21:19 --------- d-----w c:\program files\a-squared Anti-Malware
2008-11-02 19:00 --------- d-----w c:\documents and settings\Propriétaire\Application Data\LimeWire
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 22:02 --------- d-----w c:\program files\Fichiers communs\Real
2008-10-16 13:14 --------- d--h--w c:\documents and settings\Propriétaire\Application Data\yahoo!
2008-10-16 07:56 262,144 ----a-w C:\ntuser.dat
2008-10-14 16:24 --------- d-----w c:\documents and settings\TEMP\Application Data\Apple Computer
2008-10-07 20:12 --------- d-----w c:\program files\eBay
2008-10-07 17:26 --------- d-----w c:\documents and settings\All Users\Application Data\WholeSecurity
2008-10-05 16:15 --------- d-----w c:\program files\Google
2008-10-04 16:31 --------- d-----w c:\program files\AAALOGO2008
2008-10-04 16:11 --------- d-----w c:\program files\iTunes
2008-10-04 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 16:10 --------- d-----w c:\program files\iPod
2008-10-04 15:56 --------- d-----w c:\program files\Safari
2008-10-04 14:24 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-04 14:21 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-10-04 14:17 --------- d-----w c:\program files\Microsoft Silverlight
2008-09-27 10:27 --------- d-----w c:\program files\Bonjour
2008-09-27 10:26 --------- d-----w c:\program files\QuickTime
2008-09-27 10:26 --------- d-----w c:\program files\Fichiers communs\Apple
2008-09-27 10:26 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-09-27 10:23 --------- d-----w c:\program files\Apple Software Update
2008-09-27 10:22 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-09-21 14:55 --------- d-----w c:\program files\MSN Messenger
2008-09-21 12:35 --------- d-----w c:\program files\LimeWire
2008-02-13 21:22 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-11-18 16:18 774,144 ----a-w c:\program files\RngInterstitial.dll
2007-07-17 16:37 23,572 ----a-w c:\documents and settings\Propriétaire\Application Data\wklnhst.dat
2006-11-09 07:10 20,822 ----a-w c:\documents and settings\Titou\Application Data\wklnhst.dat
2006-01-26 13:08 444 ----a-w c:\documents and settings\Thomas\Application Data\wklnhst.dat
2006-09-14 12:01 1,160 --sha-w c:\windows\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of :\documents and settings\All Users\Application Data\wmp ----
:\documents and settings\All Users\Application Data\wmp\
---- Directory of c:\program files\AAALOGO2008 ----
2008-10-04 17:31 71 --a------ c:\program files\AAALOGO2008\get_last.url
2008-10-04 17:31 71 --a------ c:\program files\AAALOGO2008\aaa_logo.url
2008-10-04 17:31 66652 --a------ c:\program files\AAALOGO2008\unins000.dat
2008-10-04 17:30 678682 --a------ c:\program files\AAALOGO2008\unins000.exe
2008-09-26 20:23 132 --a------ c:\program files\AAALOGO2008\styles\LOGO SOCOMIA.dta
2008-09-04 19:28 4071424 --a------ c:\program files\AAALOGO2008\alogo.exe
2008-09-02 03:05 548 --a------ c:\program files\AAALOGO2008\templates\3b4.dta
2008-09-02 03:00 3767 --a------ c:\program files\AAALOGO2008\templates\9c3.dta
2008-09-02 02:59 3427 --a------ c:\program files\AAALOGO2008\templates\9c2.dta
2008-09-02 02:58 1341 --a------ c:\program files\AAALOGO2008\templates\9c4.dta
2008-09-02 02:23 1054 --a------ c:\program files\AAALOGO2008\templates\9c1.dta
2008-09-02 01:58 2250 --a------ c:\program files\AAALOGO2008\templates\9a3.dta
2008-09-02 01:49 633 --a------ c:\program files\AAALOGO2008\templates\8c4.dta
2008-09-02 01:37 1779 --a------ c:\program files\AAALOGO2008\templates\5c4.dta
2008-09-02 01:25 1654 --a------ c:\program files\AAALOGO2008\templates\3b2.dta
2008-09-02 01:18 852 --a------ c:\program files\AAALOGO2008\templates\3c4.dta
2008-09-02 01:11 934 --a------ c:\program files\AAALOGO2008\templates\3c3.dta
2008-09-02 00:52 1028 --a------ c:\program files\AAALOGO2008\templates\2a4.dta
2008-09-02 00:25 3649 --a------ c:\program files\AAALOGO2008\templates\2a2.dta
2008-09-01 23:23 1539 --a------ c:\program files\AAALOGO2008\templates\1c3.dta
2008-09-01 23:09 1496 --a------ c:\program files\AAALOGO2008\templates\9b3.dta
2008-09-01 22:55 3410 --a------ c:\program files\AAALOGO2008\templates\2a3.dta
2008-09-01 22:34 3479 --a------ c:\program files\AAALOGO2008\templates\9b4.dta
2008-09-01 22:20 762 --a------ c:\program files\AAALOGO2008\templates\1b1.dta
2008-09-01 21:52 1052 --a------ c:\program files\AAALOGO2008\templates\1b4.dta
2008-09-01 21:48 1714 --a------ c:\program files\AAALOGO2008\templates\1b3.dta
2008-09-01 20:25 856 --a------ c:\program files\AAALOGO2008\templates\
0c2.dta
2008-09-01 20:03 766 --a------ c:\program files\AAALOGO2008\templates\
0c4.dta
2008-09-01 19:59 1266 --a------ c:\program files\AAALOGO2008\templates\
0c1.dta
2008-09-01 19:51 961 --a------ c:\program files\AAALOGO2008\templates\
0c3.dta
2008-09-01 19:33 2353 --a------ c:\program files\AAALOGO2008\templates\
0b4.dta
2008-08-30 23:26 758 --a------ c:\program files\AAALOGO2008\templates\
0b3.dta
2008-08-30 22:04 578 --a------ c:\program files\AAALOGO2008\templates\
0b2.dta
2008-08-30 21:25 734 --a------ c:\program files\AAALOGO2008\templates\
0b1.dta
2008-08-27 21:50 842 --a------ c:\program files\AAALOGO2008\templates\8c3.dta
2008-08-27 21:23 433 --a------ c:\program files\AAALOGO2008\templates\8c1.dta
2008-08-27 20:17 1416 --a------ c:\program files\AAALOGO2008\templates\8c2.dta
2008-08-27 18:44 1695 --a------ c:\program files\AAALOGO2008\templates\7c4.dta
2008-08-27 17:19 667 --a------ c:\program files\AAALOGO2008\templates\7c3.dta
2008-08-26 21:27 1319 --a------ c:\program files\AAALOGO2008\templates\7b4.dta
2008-08-26 21:24 776 --a------ c:\program files\AAALOGO2008\templates\7c1.dta
2008-08-26 21:03 1030 --a------ c:\program files\AAALOGO2008\templates\7c2.dta
2008-08-26 20:41 587 --a------ c:\program files\AAALOGO2008\templates\6c3.dta
2008-08-26 20:03 771 --a------ c:\program files\AAALOGO2008\templates\6c4.dta
2008-08-26 18:52 1365 --a------ c:\program files\AAALOGO2008\templates\6c2.dta
2008-08-26 18:06 1470 --a------ c:\program files\AAALOGO2008\templates\6c1.dta
2008-08-26 16:01 1957 --a------ c:\program files\AAALOGO2008\templates\5c3.dta
2008-08-26 15:47 639 --a------ c:\program files\AAALOGO2008\templates\1c1.dta
2008-08-25 22:41 1256 --a------ c:\program files\AAALOGO2008\templates\5c1.dta
2008-08-25 22:36 941 --a------ c:\program files\AAALOGO2008\templates\5c2.dta
2008-08-24 13:28 153 --a------ c:\program files\AAALOGO2008\fonts\fonts.txt
2008-08-19 20:00 1522781 --a------ c:\program files\AAALOGO2008\latfn.dta
2008-06-24 17:19 3456082 --a------ c:\program files\AAALOGO2008\ollib.dta
2008-06-16 15:22 1172 --a------ c:\program files\AAALOGO2008\templates\6b4.dta
2008-06-16 15:21 2316 --a------ c:\program files\AAALOGO2008\templates\5a4.dta
2008-06-16 15:15 656 --a------ c:\program files\AAALOGO2008\templates\6b3.dta
2008-06-16 15:02 1455 --a------ c:\program files\AAALOGO2008\templates\9a1.dta
2008-06-16 14:49 1832 --a------ c:\program files\AAALOGO2008\templates\8b1.dta
2008-06-16 14:40 1686 --a------ c:\program files\AAALOGO2008\templates\8a1.dta
2008-06-16 14:34 1553 --a------ c:\program files\AAALOGO2008\templates\6a2.dta
2008-06-16 14:31 571 --a------ c:\program files\AAALOGO2008\templates\6a4.dta
2008-06-16 14:24 1398 --a------ c:\program files\AAALOGO2008\templates\6a3.dta
2008-06-16 14:06 839 --a------ c:\program files\AAALOGO2008\templates\3a4.dta
2008-06-16 13:57 1435 --a------ c:\program files\AAALOGO2008\templates\1c2.dta
2008-06-16 13:37 1047 --a------ c:\program files\AAALOGO2008\templates\2b3.dta
2008-06-16 13:30 1645 --a------ c:\program files\AAALOGO2008\templates\2b4.dta
2008-06-15 21:06 1273 --a------ c:\program files\AAALOGO2008\templates\2b2.dta
2008-06-15 20:59 680 --a------ c:\program files\AAALOGO2008\templates\2b1.dta
2008-06-15 20:53 160 --a------ c:\program files\AAALOGO2008\styles\b1.dta
2008-06-15 19:03 1016 --a------ c:\program files\AAALOGO2008\templates\2a1.dta
2008-06-15 18:47 1287 --a------ c:\program files\AAALOGO2008\templates\1c4.dta
2008-06-15 16:44 1362 --a------ c:\program files\AAALOGO2008\templates\7b3.dta
2008-06-15 16:39 363 --a------ c:\program files\AAALOGO2008\templates\7b2.dta
2008-06-15 16:22 1532 --a------ c:\program files\AAALOGO2008\templates\7b1.dta
2008-06-14 22:30 4852 --a------ c:\program files\AAALOGO2008\templates\3b1.dta
2008-06-14 22:16 3061 --a------ c:\program files\AAALOGO2008\templates\4c2.dta
2008-06-14 22:12 548 --a------ c:\program files\AAALOGO2008\templates\4c4.dta
2008-06-14 21:39 449 --a------ c:\program files\AAALOGO2008\templates\4c3.dta
2008-06-14 21:16 1156 --a------ c:\program files\AAALOGO2008\templates\4c1.dta
2008-06-14 18:25 517 --a------ c:\program files\AAALOGO2008\templates\4b2.dta
2008-06-14 16:47 714 --a------ c:\program files\AAALOGO2008\templates\3c1.dta
2008-06-14 15:22 4104 --a------ c:\program files\AAALOGO2008\templates\3c2.dta
2008-06-14 14:14 1966 --a------ c:\program files\AAALOGO2008\templates\2c2.dta
2008-06-14 14:12 1006 --a------ c:\program files\AAALOGO2008\templates\2c4.dta
2008-06-13 23:34 455 --a------ c:\program files\AAALOGO2008\templates\2c3.dta
2008-06-13 22:41 1961 --a------ c:\program files\AAALOGO2008\templates\
0a1.dta
2008-06-13 20:51 374 --a------ c:\program files\AAALOGO2008\templates\1a4.dta
2008-06-13 20:24 3325 --a------ c:\program files\AAALOGO2008\templates\1a2.dta
2008-06-13 20:00 503 --a------ c:\program files\AAALOGO2008\templates\1a3.dta
2008-06-13 18:05 1462 --a------ c:\program files\AAALOGO2008\templates\1a1.dta
2008-06-12 15:04 426 --a------ c:\program files\AAALOGO2008\templates\9b2.dta
2008-06-12 14:40 1487 --a------ c:\program files\AAALOGO2008\templates\9b1.dta
2008-06-11 21:36 3236 --a------ c:\program files\AAALOGO2008\templates\8b4.dta
2008-06-11 21:25 1115 --a------ c:\program files\AAALOGO2008\templates\8b3.dta
2008-06-11 21:01 640 --a------ c:\program files\AAALOGO2008\templates\8b2.dta
2008-06-11 20:02 600 --a------ c:\program files\AAALOGO2008\templates\
0a4.dta
2008-06-11 19:46 403 --a------ c:\program files\AAALOGO2008\templates\6b2.dta
2008-06-11 18:54 1056 --a------ c:\program files\AAALOGO2008\templates\
0a2.dta
2008-06-11 18:37 422 --a------ c:\program files\AAALOGO2008\templates\2c1.dta
2008-06-09 20:20 722 --a------ c:\program files\AAALOGO2008\templates\
0a3.dta
2008-06-09 20:08 764 --a------ c:\program files\AAALOGO2008\templates\6b1.dta
2008-03-29 20:46 4610 --a------ c:\program files\AAALOGO2008\license.txt
2008-03-29 20:43 984 --a------ c:\program files\AAALOGO2008\templates\5b4.dta
2008-03-29 19:31 1139 --a------ c:\program files\AAALOGO2008\templates\9a4.dta
2008-03-29 19:03 925 --a------ c:\program files\AAALOGO2008\templates\8a2.dta
2008-03-29 18:12 1054 --a------ c:\program files\AAALOGO2008\templates\7a4.dta
2008-03-29 18:01 1211 --a------ c:\program files\AAALOGO2008\templates\7a3.dta
2008-03-29 17:55 731 --a------ c:\program files\AAALOGO2008\templates\7a2.dta
2008-03-29 16:39 2056 --a------ c:\program files\AAALOGO2008\templates\5a1.dta
2008-03-29 16:33 1370 --a------ c:\program files\AAALOGO2008\templates\4a4.dta
2008-03-29 16:18 4596 --a------ c:\program files\AAALOGO2008\templates\3a1.dta
2008-03-29 16:02 699 --a------ c:\program files\AAALOGO2008\templates\5b3.dta
2008-03-29 15:33 721 --a------ c:\program files\AAALOGO2008\templates\5b1.dta
2008-03-29 15:24 719 --a------ c:\program files\AAALOGO2008\templates\4b3.dta
2008-03-29 15:15 5514 --a------ c:\program files\AAALOGO2008\templates\4b1.dta
2008-03-29 13:35 877 --a------ c:\program files\AAALOGO2008\templates\1b2.dta
2008-03-29 12:51 135 --a------ c:\program files\AAALOGO2008\styles\a6.dta
2008-03-28 20:33 711 --a------ c:\program files\AAALOGO2008\templates\9a2.dta
2008-03-28 20:18 1396 --a------ c:\program files\AAALOGO2008\templates\8a4.dta
2008-03-28 19:52 1069 --a------ c:\program files\AAALOGO2008\templates\7a1.dta
2008-03-28 19:32 149 --a------ c:\program files\AAALOGO2008\styles\a5.dta
2008-03-28 18:56 624 --a------ c:\program files\AAALOGO2008\templates\6a1.dta
2008-03-28 18:34 898 --a------ c:\program files\AAALOGO2008\templates\5a3.dta
2008-03-28 17:52 1665 --a------ c:\program files\AAALOGO2008\templates\5a2.dta
2008-03-28 17:27 634 --a------ c:\program files\AAALOGO2008\templates\4a3.dta
2008-03-28 15:20 1490 --a------ c:\program files\AAALOGO2008\templates\4a2.dta
2008-03-28 14:44 399 --a------ c:\program files\AAALOGO2008\templates\3a3.dta
2008-03-28 13:55 806 --a------ c:\program files\AAALOGO2008\templates\3a2.dta
2008-03-28 12:37 913 --a------ c:\program files\AAALOGO2008\templates\5b2.dta
2008-03-26 20:21 1156 --a------ c:\program files\AAALOGO2008\templates\4b4.dta
2008-03-26 19:29 790 --a------ c:\program files\AAALOGO2008\templates\3b3.dta
2008-03-26 18:42 129 --a------ c:\program files\AAALOGO2008\styles\a4.dta
2008-03-26 15:08 4437 --a------ c:\program files\AAALOGO2008\templates\8a3.dta
2008-03-25 21:05 782 --a------ c:\program files\AAALOGO2008\templates\4a1.dta
2008-03-23 21:55 137 --a------ c:\program files\AAALOGO2008\styles\a3.dta
2008-03-23 21:53 140 --a------ c:\program files\AAALOGO2008\styles\a2.dta
2008-03-23 21:51 129 --a------ c:\program files\AAALOGO2008\styles\a1.dta
2008-03-23 21:47 137 --a------ c:\program files\AAALOGO2008\styles\t3.dta
2008-03-23 21:46 136 --a------ c:\program files\AAALOGO2008\styles\t2.dta
2008-03-23 21:42 132 --a------ c:\program files\AAALOGO2008\styles\t1.dta
2008-03-22 12:56 498891 --a------ c:\program files\AAALOGO2008\basgl.dta
2004-04-08 19:42 624 --a------ c:\program files\AAALOGO2008\alogo.exe.manifest
2004-02-20 09:49 232 --a------ c:\program files\AAALOGO2008\styles\8.dta
2004-02-20 09:47 243 --a------ c:\program files\AAALOGO2008\styles\5.dta
2004-02-20 09:45 245 --a------ c:\program files\AAALOGO2008\styles\13.dta
2004-02-20 09:42 243 --a------ c:\program files\AAALOGO2008\styles\1.dta
2004-02-20 09:40 237 --a------ c:\program files\AAALOGO2008\styles\14.dta
2004-02-19 13:44 244 --a------ c:\program files\AAALOGO2008\styles\10.dta
2004-02-19 13:41 232 --a------ c:\program files\AAALOGO2008\styles\11.dta
2004-02-19 13:29 238 --a------ c:\program files\AAALOGO2008\styles\12.dta
2004-02-19 13:29 237 --a------ c:\program files\AAALOGO2008\styles\9.dta
2004-02-19 13:28 255 --a------ c:\program files\AAALOGO2008\styles\15.dta
2004-02-19 13:28 252 --a------ c:\program files\AAALOGO2008\styles\2.dta
2004-02-19 13:28 243 --a------ c:\program files\AAALOGO2008\styles\6.dta
2004-02-19 13:28 237 --a------ c:\program files\AAALOGO2008\styles\7.dta
2004-02-19 13:28 237 --a------ c:\program files\AAALOGO2008\styles\4.dta
2004-02-19 13:28 237 --a------ c:\program files\AAALOGO2008\styles\3.dta
---- Directory of c:\windows\
0 ----
c:\windows\
0\
---- Directory of c:\windows\Faux ----
c:\windows\Faux\
---- Directory of c:\windows\Times New Roman ----
c:\windows\Times New Roman\
(((((((((((((((((((((((((((((
snapshot@2008-11-18_21.38.40.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-19 15:43:08 1,163,960 ----a-w c:\windows\system32\aswBoot.exe
+ 2008-07-19 15:30:53 94,392 ----a-w c:\windows\system32\AvastSS.scr
+ 2008-07-19 15:32:15 26,944 ----a-w c:\windows\system32\drivers\aavmker4.sys
+ 2008-07-19 15:37:42 20,560 ----a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-01-17 17:34:01 93,264 ----a-w c:\windows\system32\drivers\aswmon.sys
+ 2008-07-19 15:37:21 94,416 ----a-w c:\windows\system32\drivers\aswmon2.sys
+ 2008-07-19 15:33:42 23,152 ----a-w c:\windows\system32\drivers\aswRdr.sys
+ 2008-07-19 15:35:18 78,416 ----a-w c:\windows\system32\drivers\aswSP.sys
+ 2008-07-19 15:32:36 42,912 ----a-w c:\windows\system32\drivers\aswTdi.sys
+ 2008-11-19 18:23:32 16,384 ----atw c:\windows\temp\Perflib_Perfdata_524.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VoipCheapCom"="c:\program files\VoipCheapCom\VoipCheapCom.exe" [2008-09-13 9218872]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-01 21898024]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2006-06-18 311340]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 1211176]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"Ashampoo PopUpBlocker"="c:\progra~1\Ashampoo\ASHAMP~1\PopUpKiller.exe" [2004-02-03 1216000]
"LDM"="\Program\BackWeb-8876480.exe" [BU]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-10-23 185896]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"SetDefPrt"="c:\program files\Brother\Brmfl04b\BrStDvPt.exe" [2004-05-25 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"Keyboard Status"="c:\progra~1\Medion\KeyStat\KeyStat.exe" [2005-01-25 411648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-03-10 40960]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-01-12 344064]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"Dit"="Dit.exe" [2004-07-20 c:\windows\Dit.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
eBayCenter.lnk - c:\program files\eBayCenter\eBayCenter.exe [2006-07-15 1011712]
eBayer 3.lnk - c:\program files\eBayer 3\ebayer3d.exe [2006-02-11 397312]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-09-03 450560]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2006-11-09 819200]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\eBayCenter\\eBayCenter.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VoipCheapCom\\VoipCheapCom.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-19 20560]
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2005-09-18 802048]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;c:\windows\system32\Drivers\BrSerIf.sys [2004-06-12 51712]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\system32\Drivers\BrUsbSer.sys [2004-01-10 11648]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2005-09-09 1272000]
S1 ensqio;ensqio;c:\windows\system32\DRIVERS\ensqio.sys []
S1 sbpcint4;SB AudioPCI 128;c:\windows\system32\DRIVERS\sbpcint4.sys []
S3 CardReaderFilter;Card Reader Filter;\??\c:\windows\system32\Drivers\USBCRFT.SYS [2005-09-01 17408]
S3 wbscr;Winbond Smartcard Reader for I/O;c:\windows\system32\drivers\wbscr.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f343358-a126-11dd-96e2-001109e2e899}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2008-09-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-19 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-07-07 17:26]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-19 19:24:03
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\scardsvr.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Brmfrmps.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\Magentic\bin\MgApp.exe
c:\program files\IncrediMail\bin\IMApp.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\YesMessenger\YesMessenger.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2008-11-19 19:32:40 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-19 18:32:34
ComboFix2.txt 2008-11-18 20:39:55
Avant-CF: 39 424 397 312 octets libres
Après-CF: 38,916,505,600 octets libres
2834 --- E O F --- 2008-11-15 14:16:42