S'abonner :  Newsletters    Magazines
Avis sur les produits Avis sur les logiciels Avis sur les jeux Actualités A propos de 01net
334 utilisateurs connectés

Services.exe 60 secondes

theredeagle le 25 mai 2007 à 19h37
Bonjour voici mon problème depuis quelques temps cette fenêtre s'affiche eb me disant que le PC va redémarrer dans 60 secondes à cause services.exe . J'ai vu ne pas être le seul ayant ce problème mais je ne comprends pas vos démarche... .
Est qu'on pourrait m'aider à résoudre mon problème en détaillant S.V.P

Merci d'avance !
Malekal_morte le 25 mai 2007 à 19h38
Bonjour,


Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :[list]
  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.
  • [/list]Déroule la liste des instructions ci-dessous :[list]
  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
  • [/list]
    theredeagle le 25 mai 2007 à 20h10

    SDFix: Version 1.85

    Run by Jimmy - 25/05/2007 - 19:59:08,04

    Microsoft Windows XP [version 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:

    Name:
    lzx32

    ImagePath:
    \??\C:\WINDOWS\system32\lzx32.sys

    lzx32 - Deleted



    Restoring Windows Registry Values
    Restoring Windows Default Hosts File
    Restoring Missing Security Center Service
    Restoring Missing SharedAccess Service

    Rebooting...


    Normal Mode:
    Checking Files:

    Below files will be copied to Backups folder then removed:

    C:\546841~1 - Deleted



    Removing Temp Files...

    ADS Check:

    Checking if ADS is attached to system32 Folder
    C:\WINDOWS\system32
    :lzx32.sys 69670
    Total size: 69670 bytes.

    system32: deleted 69670 bytes in 1 streams.

    Checking for remaining Streams

    C:\WINDOWS\system32
    No streams found.

    Checking if ADS is attached to svchost.exe
    C:\WINDOWS\system32\svchost.exe
    No streams found.



    Final Check:

    Remaining Services:
    ------------------


    [B]Rootkit PE386 Found, Use a Rootkit scanner ![/B]

    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\PMS\\Inquiero\\externeinquiero.exe"="C:\\PMS\\Inquiero\\externeinquiero.exe:*:Enabled:externeinquiero"
    "C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire"
    "C:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
    "C:\\Program Files\\Fichiers communs\\AOL\\1156967821\\ee\\aolsoftware.exe"="C:\\Program Files\\Fichiers communs\\AOL\\1156967821\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
    "C:\\Program Files\\Fichiers communs\\AOL\\1156967821\\ee\\aim6.exe"="C:\\Program Files\\Fichiers communs\\AOL\\1156967821\\ee\\aim6.exe:*:Enabled:AIM"
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\theredeagle\\counter-strike source\\hl2.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\theredeagle\\counter-strike source\\hl2.exe:*:Enabled:hl2"
    "C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"="C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe:*:Enabled:BearShare"
    "C:\\Program Files\\SightSpeed\\SightSpeed.exe"="C:\\Program Files\\SightSpeed\\SightSpeed.exe:*:Enabled:SightSpeed"
    "C:\\Program Files\\Mozilla Firefox 2 Beta 1\\firefox.exe"="C:\\Program Files\\Mozilla Firefox 2 Beta 1\\firefox.exe:*:Enabled:Firefox"
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
    "c:\\windows\\system32\\kernelex1.exe"="c:\\windows\\system32\\kernelex1.exe:*:Enabled:kernelex1"
    "C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe"="C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe:*:Enabled:P2P Networking"
    "C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\theredeagle\\counter-strike\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\theredeagle\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    Remaining Files:
    ---------------

    Backups Folder: - C:\SDFix\backups\backups.zip

    Checking For Files with Hidden Attributes:

    C:\WINDOWS\system32\wxmmin.dll
    C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
    C:\WINDOWS\Temp\6334.tmp.LOG

    Finished
    Hijackthis c quoi ?
    Malekal_morte le 25 mai 2007 à 20h12
    - Télécharge HiJackThis de Merijn sur ton bureau.
    - Renomme le fichier HiJackThis.exe en Scanner.exe pour cela, fais un clic droit sur le fichier HiJackThis.exe et choisis renommer dans la liste
    - Tape Scanner.exe et Appuye sur la touche Entrée.
    - Génère un rapport en suivant ces indications :
    - Double-clic sur Scanner.exe
    - Exécute le et clique sur Do a scan and save log file.
    - Le rapport s'ouvre sur le Bloc-Note
    - Colle le rapport ici, pour cela :
    - Menu Edition / Selectionner Tout
    - Menu Edition / copier
    - Ici dans un nouveau message : clic droit / coller
    Aide : N'hésite pas à consulter l'aide HiJackThis -
    theredeagle le 25 mai 2007 à 20h12
    Logfile of HijackThis v1.99.1
    Scan saved at 20:12:42, on 25/05/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\RunDLL32.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Razer\Copperhead\razerhid.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\program files\valve\steam\steam.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Razer\Copperhead\razerofa.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Jimmy\Bureau\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video ActiveX Object\isaddon.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [PD0870 STISvc] RunDLL32.exe P0870Pin.dll,RunDLL32EP 513
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
    O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\Jimmy\OctoshapeClient.exe" -inv:bootrun
    O4 - HKCU\..\Run: [SFS6] "C:\Program Files\Steganos Secure FileSharing 6\sfs.exe" /booting
    O4 - Startup: Product Registration.lnk = C:\Documents and Settings\Jimmy\Bureau\Civilization 3\ATR1.EXE
    O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b53358fdd328415bbd23256367c1faf8
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b53358fdd328415bbd23256367c1faf8
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator2_8_1\Ghost (file missing)
    O9 - Extra 'Tools' menuitem: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator2_8_1\Ghost (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_s(...)
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Serveur lanmanserverlanmanserver (lanmanserverlanmanserver) - Unknown owner - C:\WINDOWS\system32\32405.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    Malekal_morte le 26 mai 2007 à 01h09

    Merci de bien lire et suivre attentivement ce qui est écrit car tu dois appuyer sur une touche lors du scan.. si tu ne le fais pas le rapport ne sera pas entier et tu devras recommencer donc :

    - Télécharge DiagHelp.zip sur ton bureau - Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
    - Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout
    - Un nouveau dossier chercher va être créé DiagHelp
    - Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
    - Une fenêtre va s'ouvrir, choisis l'option 1
    - L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.

    ATTENTION : pendant l'analyse, après le rapport catchme, il te sera demandé d'appuyer sur une touche afin de poursuivre le scan, suis bien les instructions à l'écran !

    - A la fin de l'analyse, il peut-être (pas obligatoire) demandé de redemanderl'ordinateur... Une fois l'ordinateur redémarré le rapport va apparaître sur le bloc-note.. Ce dernier se trouve sur C:\resultat.txt
    - Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :
    -- Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout
    -- A nouveau menu Edition / copier
    -- Dans un nouveau message ici, faire un clic droit / coller

    theredeagle le 26 mai 2007 à 18h19
    DiagHelp version v1.08.1 - http://www.malekal.com
    excute le 26/05/2007 à 18:12:50,92


    Liste des fichiers modifies/crees dans les 24 dernieres heures...
    \boot.ini
    \Config.Msi
    \Documents and Settings\All Users\Bureau\iTunes.lnk
    \Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    \Documents and Settings\Jimmy
    \Documents and Settings\Jimmy\Bureau
    \Documents and Settings\Jimmy\Bureau\cssconfig.zip
    \Documents and Settings\Jimmy\Bureau\DiagHelp
    \Documents and Settings\Jimmy\Bureau\DiagHelp.zip
    \Documents and Settings\Jimmy\Bureau\hijackthis.log
    \Documents and Settings\Jimmy\Bureau\legitcheck.hta
    \Documents and Settings\Jimmy\Bureau\THE Bloc Notes.txt
    \Documents and Settings\Jimmy\Local Settings\desktop.ini
    \Documents and Settings\Jimmy\Local Settings\Temp
    \Documents and Settings\Jimmy\Local Settings\Temp\BitTorrent-5.0.7.exe
    \Documents and Settings\Jimmy\Local Settings\Temp\byeDC.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeDD.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeDE.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeDF.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeE0.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeE1.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeE2.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeE3.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\byeE4.tmp\Disk1
    \Documents and Settings\Jimmy\Local Settings\Temp\DIO6.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\DIO8.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\DIO9.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\DIOA.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\DIOB.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\DIOC.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\DIOD.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\fla30.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\fla36.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\fla40.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\fla46.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\fla4F.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\hpodvd09.log
    \Documents and Settings\Jimmy\Local Settings\Temp\iPod Temporary Files
    \Documents and Settings\Jimmy\Local Settings\Temp\java_install_reg.log
    \Documents and Settings\Jimmy\Local Settings\Temp\MAR3.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\MAR4.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\MAR5.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\MAR6.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\MAR7.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\MAR8.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\STS7.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\STSB.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\STSC.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\vlt3\default
    \Documents and Settings\Jimmy\Local Settings\Temp\vlt3\default\main
    \Documents and Settings\Jimmy\Local Settings\Temp\vlt3\default\playlist
    \Documents and Settings\Jimmy\Local Settings\Temp\WPDNSE
    \Documents and Settings\Jimmy\Local Settings\Temp\_hphtra07.log
    \Documents and Settings\Jimmy\Local Settings\Temp\~DF6023.tmp
    \Documents and Settings\Jimmy\Local Settings\Temp\~DFD5D.tmp
    \Documents and Settings\Jimmy\Mes documents\Ma musique\iTunes
    \Documents and Settings\Jimmy\Mes documents\Ma musique\iTunes\iTunes Library.itl
    \Documents and Settings\Jimmy\Mes documents\Ma musique\iTunes\iTunes Music Library.xml
    \Documents and Settings\Jimmy\Mes documents\Mes dossiers de partage.lnk
    \Documents and Settings\Jimmy\Mes documents\setup
    \Documents and Settings\Jimmy\Mes documents\setup\SDFix.exe
    \Documents and Settings\Jimmy\NTUSER.DAT
    \Documents and Settings\Jimmy\ntuser.dat.LOG
    \Documents and Settings\Jimmy\ntuser.ini
    \Documents and Settings\LocalService\Local Settings\desktop.ini
    \Documents and Settings\LocalService\NTUSER.DAT
    \Documents and Settings\LocalService\ntuser.dat.LOG
    \Documents and Settings\NetworkService\Local Settings\desktop.ini
    \Documents and Settings\NetworkService\NTUSER.DAT
    \Documents and Settings\NetworkService\ntuser.dat.LOG
    \hiberfil.sys
    \pagefile.sys
    \SDFix
    \SDFix\backups
    \SDFix\backups\backupreg.zip
    \SDFix\backups\backups.zip
    \SDFix\catchme.log
    \SDFix\Report.txt
    \WINDOWS
    \WINDOWS\$hf_mig$
    \WINDOWS\$hf_mig$\KB925902
    \WINDOWS\$hf_mig$\KB925902\SP2QFE
    \WINDOWS\$hf_mig$\KB925902\update
    \WINDOWS\$hf_mig$\KB927891
    \WINDOWS\$hf_mig$\KB927891\SP2QFE
    \WINDOWS\$hf_mig$\KB927891\update
    \WINDOWS\$hf_mig$\KB930178
    \WINDOWS\$hf_mig$\KB930178\SP2QFE
    \WINDOWS\$hf_mig$\KB930178\update
    \WINDOWS\$hf_mig$\KB930916
    \WINDOWS\$hf_mig$\KB930916\SP2QFE
    \WINDOWS\$hf_mig$\KB930916\update
    \WINDOWS\$hf_mig$\KB931261
    \WINDOWS\$hf_mig$\KB931261\SP2QFE
    \WINDOWS\$hf_mig$\KB931261\update
    \WINDOWS\$hf_mig$\KB931768
    \WINDOWS\$hf_mig$\KB931768\SP2QFE
    \WINDOWS\$hf_mig$\KB931768\update
    \WINDOWS\$hf_mig$\KB931784
    \WINDOWS\$hf_mig$\KB931784\SP2QFE
    \WINDOWS\$hf_mig$\KB931784\update
    \WINDOWS\$hf_mig$\KB932168
    \WINDOWS\$hf_mig$\KB932168\SP2QFE
    \WINDOWS\$hf_mig$\KB932168\update
    \WINDOWS\$NtUninstallKB925902$
    \WINDOWS\$NtUninstallKB925902$\spuninst
    \WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB927891$
    \WINDOWS\$NtUninstallKB927891$\spuninst
    \WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB929399$
    \WINDOWS\$NtUninstallKB929399$\spuninst
    \WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB930178$
    \WINDOWS\$NtUninstallKB930178$\spuninst
    \WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB930916$
    \WINDOWS\$NtUninstallKB930916$\spuninst
    \WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB931261$
    \WINDOWS\$NtUninstallKB931261$\spuninst
    \WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB931768$
    \WINDOWS\$NtUninstallKB931768$\reg00001
    \WINDOWS\$NtUninstallKB931768$\reg00002
    \WINDOWS\$NtUninstallKB931768$\reg00003
    \WINDOWS\$NtUninstallKB931768$\reg00004
    \WINDOWS\$NtUninstallKB931768$\reg00005
    \WINDOWS\$NtUninstallKB931768$\reg00006
    \WINDOWS\$NtUninstallKB931768$\reg00007
    \WINDOWS\$NtUninstallKB931768$\reg00008
    \WINDOWS\$NtUninstallKB931768$\reg00009
    \WINDOWS\$NtUninstallKB931768$\reg00010
    \WINDOWS\$NtUninstallKB931768$\reg00011
    \WINDOWS\$NtUninstallKB931768$\reg00012
    \WINDOWS\$NtUninstallKB931768$\reg00013
    \WINDOWS\$NtUninstallKB931768$\reg00014
    \WINDOWS\$NtUninstallKB931768$\reg00015
    \WINDOWS\$NtUninstallKB931768$\reg00016
    \WINDOWS\$NtUninstallKB931768$\reg00017
    \WINDOWS\$NtUninstallKB931768$\reg00018
    \WINDOWS\$NtUninstallKB931768$\reg00019
    \WINDOWS\$NtUninstallKB931768$\reg00020
    \WINDOWS\$NtUninstallKB931768$\reg00021
    \WINDOWS\$NtUninstallKB931768$\reg00022
    \WINDOWS\$NtUninstallKB931768$\spuninst
    \WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB931784$
    \WINDOWS\$NtUninstallKB931784$\spuninst
    \WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.txt
    \WINDOWS\$NtUninstallKB932168$
    \WINDOWS\$NtUninstallKB932168$\spuninst
    \WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.inf
    \WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.txt
    \WINDOWS\0.log
    \WINDOWS\assembly
    \WINDOWS\assembly\GAC_32
    \WINDOWS\assembly\GAC_32\CustomMarshalers
    \WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    \WINDOWS\assembly\GAC_32\ISymWrapper
    \WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    \WINDOWS\assembly\GAC_32\mscorlib
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\big5.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bopomofo.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\ksc.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normidna.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfc.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfd.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkc.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkd.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prc.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prcp.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
    \WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\xjis.nlp
    \WINDOWS\assembly\GAC_32\System.Data
    \WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    \WINDOWS\assembly\GAC_32\System.Data.OracleClient
    \WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    \WINDOWS\assembly\GAC_32\System.EnterpriseServices
    \WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    \WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    \WINDOWS\assembly\GAC_32\System.Transactions
    \WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    \WINDOWS\assembly\GAC_32\System.Web
    \WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    \WINDOWS\assembly\GAC_MSIL
    \WINDOWS\assembly\GAC_MSIL\Accessibility
    \WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    \WINDOWS\assembly\GAC_MSIL\AspNetMMCExt
    \WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    \WINDOWS\assembly\GAC_MSIL\cscompmgd
    \WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    \WINDOWS\assembly\GAC_MSIL\IEExecRemote
    \WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    \WINDOWS\assembly\GAC_MSIL\IEHost
    \WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    \WINDOWS\assembly\GAC_MSIL\IIEHost
    \WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    \WINDOWS\assembly\GAC_MSIL\sysglobl
    \WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    \WINDOWS\assembly\GAC_MSIL\System
    \WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    \WINDOWS\assembly\GAC_MSIL\System.Configuration
    \WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    \WINDOWS\assembly\GAC_MSIL\System.Configuration.Install
    \WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    \WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml
    \WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    \WINDOWS\assembly\GAC_MSIL\System.Deployment
    \WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    \WINDOWS\assembly\GAC_MSIL\System.Design
    \WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    \WINDOWS\assembly\GAC_MSIL\System.DirectoryServices
    \WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    \WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols
    \WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    \WINDOWS\assembly\GAC_MSIL\System.Drawing
    \WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    \WINDOWS\assembly\GAC_MSIL\System.Drawing.Design
    \WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    \WINDOWS\assembly\GAC_MSIL\System.Management
    \WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    \WINDOWS\assembly\GAC_MSIL\System.Messaging
    \WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    \WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting
    \WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap
    \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    \WINDOWS\assembly\GAC_MSIL\System.Security
    \WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    \WINDOWS\assembly\GAC_MSIL\System.ServiceProcess
    \WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    \WINDOWS\assembly\GAC_MSIL\System.Web.Mobile
    \WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    \WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions
    \WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    \WINDOWS\assembly\GAC_MSIL\System.Web.Services
    \WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a
    \WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    \WINDOWS\assembly\GAC_MSIL\System.Windows.Forms
    \WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    \WINDOWS\assembly\GAC_MSIL\System.Xml
    \WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089
    \WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    \WINDOWS\assembly\NativeImages_v2.0.50727_32
    \WINDOWS\assembly\NativeImages_v2.0.50727_32\index2b.dat
    \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design
    \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\34d2a1daa3ba59449539d01f575436a5
    \WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\34d2a1daa3ba59449539d01f575436a5\System.Design.ni.dll
    \WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp
    \WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP172.tmp
    \WINDOWS\assembly\temp
    \WINDOWS\assembly\tmp
    \WINDOWS\bootstat.dat
    \WINDOWS\comsetup.log
    \WINDOWS\Debug
    \WINDOWS\Debug\mrt.log
    \WINDOWS\Debug\mrteng.log
    \WINDOWS\Debug\PASSWD.LOG
    \WINDOWS\FaxSetup.log
    \WINDOWS\iis6.log
    \WINDOWS\imsins.BAK
    \WINDOWS\imsins.log
    \WINDOWS\inf
    \WINDOWS\inf\branches.PNF
    \WINDOWS\inf\swflash.PNF
    \WINDOWS\KB925902.log
    \WINDOWS\KB927891.log
    \WINDOWS\KB929399.log
    \WINDOWS\KB930178.log
    \WINDOWS\KB930916.log
    \WINDOWS\KB931261.log
    \WINDOWS\KB931768.log
    \WINDOWS\KB931784.log
    \WINDOWS\KB932168.log
    \WINDOWS\Minidump
    \WINDOWS\Minidump\Mini052507-01.dmp
    \WINDOWS\msagent
    \WINDOWS\msgsocm.log
    \WINDOWS\ntdtcsetup.log
    \WINDOWS\ocgen.log
    \WINDOWS\ocmsn.log
    \WINDOWS\pss
    \WINDOWS\pss\boot.ini.backup
    \WINDOWS\QTFont.for
    \WINDOWS\QTFont.qfn
    \WINDOWS\SchedLgU.Txt
    \WINDOWS\setupapi.log
    \WINDOWS\spupdsvc.log
    \WINDOWS\system.ini
    \WINDOWS\system32
    \WINDOWS\system32\546841067.dll
    \WINDOWS\system32\drivers
    \WINDOWS\system32\drivers\etc
    \WINDOWS\system32\drivers\etc\HOSTS
    \WINDOWS\system32\perfc009.dat
    \WINDOWS\system32\perfc00C.dat
    \WINDOWS\system32\perfh009.dat
    \WINDOWS\system32\perfh00C.dat
    \WINDOWS\system32\PerfStringBackup.INI
    \WINDOWS\system32\spool\drivers\w32x86
    \WINDOWS\system32\wpa.dbl
    \WINDOWS\Tasks\SA.DAT
    \WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
    \WINDOWS\Temp
    \WINDOWS\Temp\100203
    \WINDOWS\Temp\104046
    \WINDOWS\Temp\104687
    \WINDOWS\Temp\6334.tmp
    \WINDOWS\Temp\6334.tmp.LOG
    \WINDOWS\Temp\99281
    \WINDOWS\Temp\Perflib_Perfdata_748.dat
    \WINDOWS\Temp\Perflib_Perfdata_750.dat
    \WINDOWS\Temp\Perflib_Perfdata_758.dat
    \WINDOWS\Temp\Perflib_Perfdata_75c.dat
    \WINDOWS\Temp\Perflib_Perfdata_76c.dat
    \WINDOWS\Temp\WGAErrLog.txt
    \WINDOWS\Temp\WGANotify.settings
    \WINDOWS\Temp\_avast4_
    \WINDOWS\Temp\_avast4_\Webshlock.txt
    \WINDOWS\tsoc.log
    \WINDOWS\updspapi.log
    \WINDOWS\WgaNotify.log
    \WINDOWS\wiadebug.log
    \WINDOWS\wiaservc.log
    \WINDOWS\win.ini
    \WINDOWS\WindowsUpdate.log
    \WINDOWS\WinSxS
    \WINDOWS\WinSxS\Manifests
    \WINDOWS\WinSxS\Manifests\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790.manifest
    \WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
    \WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    \WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll


    Liste des derniers fichies modifies/crees dans windir\system32
    C:\WINDOWS\System32/drivers\secdrv.sys -->06/05/2007 16:36:28
    C:\WINDOWS\System32/drivers\aswRdr.sys -->30/04/2007 17:39:41
    C:\WINDOWS\System32/drivers\aavmker4.sys -->30/04/2007 17:37:23
    C:\WINDOWS\System32/drivers\scdemu.sys -->09/04/2007 14:27:07
    C:\WINDOWS\System32/drivers\ntfs.sys -->09/02/2007 13:10:35
    C:\WINDOWS\System32/drivers\aswmon.sys -->21/12/2006 01:56:13
    C:\WINDOWS\System32/drivers\aswmon2.sys -->21/12/2006 01:56:00

    C:\WINDOWS\System32\wpa.dbl -->26/05/2007 15:08:01
    C:\WINDOWS\System32\PerfStringBackup.INI -->25/05/2007 19:32:36
    C:\WINDOWS\System32\perfh00C.dat -->25/05/2007 19:32:36
    C:\WINDOWS\System32\perfh009.dat -->25/05/2007 19:32:36
    C:\WINDOWS\System32\perfc00C.dat -->25/05/2007 19:32:36
    C:\WINDOWS\System32\perfc009.dat -->25/05/2007 19:32:36
    C:\WINDOWS\System32\FNTCACHE.DAT -->25/05/2007 18:38:37
    C:\WINDOWS\System32\546841067.dll -->25/05/2007 18:15:06
    C:\WINDOWS\System32\aswBoot.exe -->30/04/2007 17:46:10
    C:\WINDOWS\System32\AVASTSS.scr -->30/04/2007 17:35:28
    C:\WINDOWS\System32\CmdLineExt.dll -->30/04/2007 14:17:59
    C:\WINDOWS\System32\SI.bin -->30/04/2007 14:13:03
    C:\WINDOWS\System32\MRT.exe -->27/04/2007 13:45:14
    C:\WINDOWS\System32\libeay32.dll -->19/04/2007 17:31:16
    C:\WINDOWS\System32\ssleay32.dll -->19/04/2007 17:30:48
    C:\WINDOWS\System32\msi.dll -->18/04/2007 18:14:18
    C:\WINDOWS\System32\winsrv.dll -->17/03/2007 15:44:47
    C:\WINDOWS\System32\LegitCheckControl.dll -->15/03/2007 18:19:28
    C:\WINDOWS\System32\WgaTray.exe -->15/03/2007 18:17:20
    C:\WINDOWS\System32\WgaLogon.dll -->15/03/2007 18:16:48
    C:\WINDOWS\System32\xpsp3res.dll -->09/03/2007 12:24:03
    C:\WINDOWS\System32\user32.dll -->08/03/2007 17:37:50
    C:\WINDOWS\System32\mf3216.dll -->08/03/2007 17:37:50
    C:\WINDOWS\System32\gdi32.dll -->08/03/2007 17:37:50
    C:\WINDOWS\System32\win32k.sys -->08/03/2007 17:33:58

    C:\WINDOWS\uncsetup.exe -->23/04/2087 08:15:02
    C:\WINDOWS\QTFont.qfn -->26/05/2007 17:59:48
    C:\WINDOWS\QTFont.for -->26/05/2007 17:59:48
    C:\WINDOWS\0.log -->26/05/2007 15:07:14
    C:\WINDOWS\wiadebug.log -->26/05/2007 15:07:11
    C:\WINDOWS\WindowsUpdate.log -->26/05/2007 15:07:07
    C:\WINDOWS\wiaservc.log -->26/05/2007 15:07:06
    C:\WINDOWS\bootstat.dat -->26/05/2007 15:05:51
    C:\WINDOWS\setupapi.log -->26/05/2007 13:05:40
    C:\WINDOWS\SchedLgU.Txt -->25/05/2007 22:16:03
    C:\WINDOWS\win.ini -->25/05/2007 20:59:27
    C:\WINDOWS\system.ini -->25/05/2007 20:59:27
    C:\WINDOWS\spupdsvc.log -->25/05/2007 19:52:05
    C:\WINDOWS\tsoc.log -->25/05/2007 19:33:11
    C:\WINDOWS\ocmsn.log -->25/05/2007 19:33:11


    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 2098-21EB

    Répertoire de C:\WINDOWS\system32

    05/08/2004 14:00 6 144 csrss.exe
    1 fichier(s) 6 144 octets
    0 Rép(s) 109 109 813 248 octets libres

    Contenu de Downloaded Program Files
    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 2098-21EB

    Répertoire de C:\WINDOWS\Downloaded Program Files

    23/04/2007 20:45 <REP> .
    23/04/2007 20:45 <REP> ..
    24/01/2007 03:41 841 304 ampAx3.0.84.2.dll
    05/08/2004 14:41 288 296 Chess.ocx
    09/03/2007 17:18 <REP> CONFLICT.1
    21/08/2006 17:10 65 desktop.ini
    23/11/2006 00:22 372 736 GAME_UNO1.dll
    22/11/2006 21:50 316 GAME_UNO1.INF
    23/04/2007 20:45 2 849 install.log
    29/05/2003 16:00 160 864 messengerstatsclient.dll
    06/04/2004 20:03 172 072 MessengerStatsPAClient.dll
    29/05/2003 16:00 77 408 msgrchkr.dll
    26/03/2007 16:46 5 085 swflash.inf
    23/04/2007 20:45 38 428 unagiuninst.exe
    30/06/2003 23:41 1 689 WMV9VCM.inf
    26/05/2005 04:19 291 wuweb.inf
    18/07/2006 15:35 151 080 ZIntro.ocx
    14 fichier(s) 2 112 483 octets

    Répertoire de C:\WINDOWS\Downloaded Program Files\CONFLICT.1

    09/03/2007 17:18 <REP> .
    09/03/2007 17:18 <REP> ..
    23/02/2007 00:41 304 544 MessengerStatsPAClient.dll
    1 fichier(s) 304 544 octets

    Total des fichiers listés :
    15 fichier(s) 2 417 027 octets
    5 Rép(s) 109 109 813 248 octets libres

    Recherche de rootkit! (Merci S!Ri)
    pe386 présent!

    Recherche d'infections connues

    Export des clefs sensibles..

    Liste des fichiers en exception sur le pare-feu XP SP2

    Export de la clef SharedTaskScheduler

    [SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
    "{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

    Rechercher adresses sensibles dans le fichier HOSTS...



    catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-05-26 18:14:35
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\deaglecss@hotmail.fr\SharingMetadata\deltarouge@hotmail.com\DFSR\Staging\CS{15EE2819-73AF-8D02-9DAE-0B99A9120A98}\01\11-{15EE2819-73AF-8D02-9DAE-0B99A9120A98}-v1-{B4E32502-DA18-4FBE-9744-EE48B2FF2548}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\deaglecss@hotmail.fr\SharingMetadata\dremcatcher@hotmail.fr\DFSR\Staging\CS{2E487352-62CE-FD23-9A5E-8485C740488A}\01\12-{2E487352-62CE-FD23-9A5E-8485C740488A}-v1-{B4E32502-DA18-4FBE-9744-EE48B2FF2548}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\deaglecss@hotmail.fr\SharingMetadata\j.jonathan@hotmail.fr\DFSR\Staging\CS{C5D23AD9-5B72-7A4C-64C9-53431A8D1DE9}\01\10-{C5D23AD9-5B72-7A4C-64C9-53431A8D1DE9}-v1-{B4E32502-DA18-4FBE-9744-EE48B2FF2548}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\deltarouge@hotmail.com\DFSR\Staging\CS{A2D71CF6-FE3B-3EF1-CF2B-DD208BD568B9}\01\10-{A2D71CF6-FE3B-3EF1-CF2B-DD208BD568B9}-v1-{86D3C07A-2586-4039-B5CF-9CCEFD113234}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\deltarouge@hotmail.com\DFSR\Staging\CS{A2D71CF6-FE3B-3EF1-CF2B-DD208BD568B9}\11\13-{700BB7DD-8857-40C6-85B9-5F691EF6ADCD}-v11-{700BB7DD-8857-40C6-85B9-5F691EF6ADCD}-v13-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2232 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\deltarouge@hotmail.com\DFSR\Staging\CS{A2D71CF6-FE3B-3EF1-CF2B-DD208BD568B9}\15\15-{700BB7DD-8857-40C6-85B9-5F691EF6ADCD}-v15-{700BB7DD-8857-40C6-85B9-5F691EF6ADCD}-v15-Partial.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2296 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\33\33-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v33-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\56\56-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v56-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2752 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\00\100-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v100-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2376 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\01\101-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v101-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2368 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\01\11-{8CD92633-C08F-0341-8712-88AB570F1018}-v1-{86D3C07A-2586-4039-B5CF-9CCEFD113234}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\02\102-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v102-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v102-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2800 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\03\103-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v103-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2112 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\04\104-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v104-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\05\105-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v105-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v105-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1648 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\06\106-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v106-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v106-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1296 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\07\107-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v107-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v107-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1800 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\08\108-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v108-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v108-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1760 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\09\109-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v109-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v109-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1752 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\10\110-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v110-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1992 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\11\111-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v111-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v111-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2168 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\12\112-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v112-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v112-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1752 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\12\12-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v12-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 832 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\13\113-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v113-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v113-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1784 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\13\13-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v13-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\14\114-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v114-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v114-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 720 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\14\14-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v14-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 896 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\15\115-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v115-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v115-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 328 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\15\15-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v15-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\16\116-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v116-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v116-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 608 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\16\16-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v16-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\17\117-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v117-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v117-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 216 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\17\17-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v17-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 792 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\18\118-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v118-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 200 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\18\18-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v18-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\19\119-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v119-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v119-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 296 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\19\19-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v19-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 832 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\20\120-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v120-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v120-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 688 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\20\20-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v20-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 904 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\21\121-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v121-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v121-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 416 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\21\21-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v21-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\22\122-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v122-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v122-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 512 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\22\22-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v22-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 768 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\23\123-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v123-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v123-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 192 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\23\23-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v23-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\24\124-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v124-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v124-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 104 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\24\24-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v24-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\25\125-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v125-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v125-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 264 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\25\25-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v25-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 856 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\26\126-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v126-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v126-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\26\26-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v26-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 776 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\27\127-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v127-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v127-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 760 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\27\27-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v27-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\28\128-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v128-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v128-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 520 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\28\28-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v28-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\29\129-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v129-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v129-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1384 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\29\29-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v29-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\30\130-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v130-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v130-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 9016 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\30\30-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v30-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 888 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\31\131-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v131-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v131-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4360 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\31\31-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v31-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 840 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\32\132-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v132-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v132-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 9152 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\32\32-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v32-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 832 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\34\134-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v134-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v134-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 136 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\34\34-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v34-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 880 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\35\135-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v135-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v135-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 128 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\35\35-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v35-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 656 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\36\136-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v136-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v136-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 296 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\36\36-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v36-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 640 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\37\37-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v37-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v37-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 848 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\38\38-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v38-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v38-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 808 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\39\39-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v39-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v39-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2080 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\40\40-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v40-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v40-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2400 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\41\41-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v41-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v41-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2472 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\42\42-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v42-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v42-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2592 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\43\43-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v43-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v43-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1912 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\44\44-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v44-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v44-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1712 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\45\45-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v45-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v45-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2152 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\46\137-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v46-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21360 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\46\137-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v46-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v137-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2352 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\47\47-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v47-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v47-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2440 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\48\48-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v48-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v48-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2544 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\49\49-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v49-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v49-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1112 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\50\50-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v50-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2696 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\51\51-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v51-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3040 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\52\52-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v52-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3128 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\53\53-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v53-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3104 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\54\54-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v54-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3296 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\55\55-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v55-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2928 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\57\57-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v57-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3208 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\58\58-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v58-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2768 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\59\59-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v59-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2984 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\60\60-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v60-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3128 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\61\61-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v61-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3216 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\62\62-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v62-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3112 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\63\63-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v63-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3136 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\64\64-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v64-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2800 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\65\65-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v65-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v65-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2864 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\66\66-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v66-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2656 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\67\67-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v67-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v67-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2904 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\68\68-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v68-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2672 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\69\69-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v69-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v69-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1928 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\70\70-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v70-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v70-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1672 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\71\71-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v71-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2048 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\72\72-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v72-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 3624 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\73\73-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v73-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2208 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyjim@hotmail.com\SharingMetadata\immortal00@hotmail.fr\DFSR\Staging\CS{8CD92633-C08F-0341-8712-88AB570F1018}\74\74-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v74-{C918DB8A-F47E-4AB7-90CE-B4D06199B195}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2096 bytes hidden from API
    C:\Documents and Settings\Jimmy\Local Settings\Application Data\Microsoft\Messenger\lyj
    Malekal_morte le 26 mai 2007 à 21h49
    Télécharge ce fichier (par ejvindh)
    http://www.uploads.ejvindh.net/rustbfix.exe
    ...et sauvegarde-le sur ton Bureau.

    Double clique rustbfix.exe afin de lancer l'outil.
    Si une infection Rustock.b est détectée, une invite t'indiquera qu'il est nécessaire de redémarrer l'ordi. Ce redémarrage pourrait être plus long que d'habitude, et il est possible que deux redémarrages soient requis. Tout cela se fera automatiquement.
    Suite au(x) redémarrage(s), deux rapports s'ouvriront : (%root%\avenger.txt & %root%\rustbfix\pelog.txt).
    Poste (Copie/Colle) le contenu de ces deux rapports, ainsi qu'un nouveau log HijackThis dans ta prochaine réponse.
    theredeagle le 26 mai 2007 à 23h43
    ************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************
    26/05/2007 23:38:31,17

    ******************* Pre-run Status of system *******************

    Rootkit driver PE386 is found. Starting the unload-procedure....

    Rustock.b-ADS attached to the System32-folder:
    No streams found.

    Looking for Rustock.b-files in the System32-folder:
    system32\lzx32.sys FOUND!
    attempting to delete lzx32.sys from system32-folder


    ******************* Post-run Status of system *******************

    Rustock.b-driver on the system: NONE!

    Rustock.b-ADS attached to the System32-folder:
    No System32-ADS found.

    Looking for Rustock.b-files in the System32-folder:
    No Rustock.b-files found in system32


    ******************************* End of Logfile ********************************
    theredeagle le 26 mai 2007 à 23h44
    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\vrfstnlc

    *******************

    Script file located at: \??\C:\cwvuumpa.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Driver PE386 unloaded successfully.
    Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.

    Completed script processing.

    *******************

    Finished! Terminate.
    theredeagle le 26 mai 2007 à 23h44
    Logfile of HijackThis v1.99.1
    Scan saved at 23:44:32, on 26/05/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\RunDLL32.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Razer\Copperhead\razerhid.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Razer\Copperhead\razerofa.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    C:\Documents and Settings\Jimmy\Bureau\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video ActiveX Object\isaddon.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [PD0870 STISvc] RunDLL32.exe P0870Pin.dll,RunDLL32EP 513
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
    O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\Jimmy\OctoshapeClient.exe" -inv:bootrun
    O4 - HKCU\..\Run: [SFS6] "C:\Program Files\Steganos Secure FileSharing 6\sfs.exe" /booting
    O4 - Startup: Product Registration.lnk = C:\Documents and Settings\Jimmy\Bureau\Civilization 3\ATR1.EXE
    O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?b53358fdd328415bbd23256367c1faf8
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?b53358fdd328415bbd23256367c1faf8
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator2_8_1\Ghost (file missing)
    O9 - Extra 'Tools' menuitem: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator2_8_1\Ghost (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_s(...)
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Serveur lanmanserverlanmanserver (lanmanserverlanmanserver) - Unknown owner - C:\WINDOWS\system32\32405.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    Malekal_morte le 27 mai 2007 à 02h23
    Désinstalle : My Global Search

    Avast! est loin de ce que l'on a fait de mieux en matière de protection, voir ce lien pour plus d'informations : http://forum.malekal.com/ftopic3123.php

    Clairement, Antivir est beaucoup plus performant, c'est pourquoi, je te conseille TRES VIVEMENT de désinstaller Avast! et installer Antivir à la place : http://www.malekal.com/tutorial_antivir.php
    - Après l'installation, mets le à jour - si ton firewall fait une alerte.. accepte la connexion.

    -- Redémarre en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier.

    - Cliquez sur l'onglet Scanner.
    - Sélectionne Manual Selection
    - Sélectionne le disque C
    - Lance le scan - Mets en quarantaine tous les éléments détectés.
    - Une fois le scan terminé Enregistre le rapport.

    Redémarre en mode normal.

    Poste le rapport ici.

    theredeagle le 27 mai 2007 à 11h35


    AntiVir PersonalEdition Classic
    Report file date: dimanche 27 mai 2007 10:18

    Scanning for 792110 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: Jimmy
    Computer name: 483F1E95867045D

    Version information:
    BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00
    AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
    AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
    LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
    LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
    ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
    ANTIVIR1.VDF : 6.38.1.170 5569024 Bytes 21/05/2007 08:08:58
    ANTIVIR2.VDF : 6.38.1.171 2048 Bytes 21/05/2007 08:08:58
    ANTIVIR3.VDF : 6.38.1.193 123904 Bytes 25/05/2007 08:08:58
    AVEWIN32.DLL : 7.4.0.27 2478592 Bytes 27/05/2007 08:08:58
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
    AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
    AVPACK32.DLL : 7.3.0.9 360488 Bytes 27/05/2007 08:08:58
    AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
    AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
    AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
    RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
    RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42

    Configuration settings for the scan:
    Jobname..........................: Local Drives
    Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Boot sectors.....................: D:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: on
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: dimanche 27 mai 2007 10:18

    Starting search for hidden objects.
    The driver could not be initialized.

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    11 processes with 11 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [NOTE] No virus was found!
    Master boot sector HD1
    [NOTE] No virus was found!
    [WARNING] The boot sector file could not be read!
    [WARNING] Error code: 0x0015

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Boot sector 'A:\'
    [NOTE] In the drive 'A:\' no data medium is inserted!
    Boot sector 'E:\'
    [NOTE] In the drive 'E:\' no data medium is inserted!

    Starting to scan the registry.
    The registry was scanned ( '25' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Documents and Settings\Jimmy\Mes documents\GTA San Andreas User Files\GTA\HOODLUM\HLM-INTR.EXE
    [DETECTION] Is the Trojan horse TR/Hupigon.KG.2
    [INFO] The file was moved to '46a6423a.qua'!
    C:\WINDOWS\system32\32405.exe
    [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
    [INFO] The file was moved to '468d489f.qua'!
    C:\WINDOWS\system32\546841067.dll
    [DETECTION] Is the Trojan horse TR/PSW.Ceda.B
    [INFO] The file was moved to '468f48a4.qua'!
    Begin scan in 'A:\'
    Search path A:\ could not be opened!
    Le périphérique n'est pas prêt.

    Begin scan in 'E:\'
    Search path E:\ could not be opened!
    Le périphérique n'est pas prêt.

    Begin scan in 'D:\'
    Search path D:\ could not be opened!
    Le périphérique n'est pas prêt.



    End of the scan: dimanche 27 mai 2007 11:01
    Used time: 42:41 min

    The scan has been done completely.

    5862 Scanning directories
    246754 Files were scanned
    3 viruses and/or unwanted programs were found
    0 classified as suspicious:
    0 files were deleted
    0 files were repaired
    3 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    246751 Files not concerned
    3030 Archives were scanned
    1 Warnings
    129 Notes
    0 Hidden objects were found

    Malekal_morte le 27 mai 2007 à 11h51

    C'est OK en suivant les dernières manipulations ci-dessous :)

    Essaye de rapporter ton infection sur le site que je te donne ci-dessous, ce serait super cool ;)

    Ton infection : rustock


    Finir le nettoyage :
    - Nettoye ton ordinateur avec CCleaner : http://www.malekal.com/tutorial_CCleaner.html
    - Désactive puis réactive la restauration du système :
    - Mode d'emploi Windows XP
    - Tu peux ensuite désinstaller tous les programmes que l'on a utilisé.



    je t'invite à jeter un coup d'oeil à ces liens dans la mesure du possible, essaye de rapporter ton infection :

    Pour les utilisateurs d'Avast! Vous n'êtes pas protégé en utilisant Avast!. Antivir est vraiment très performant, c'est pourquoi, je te conseille d'opter pour cet antivirus qui est gratuit (surtout si tu as Avast!), voici le tutorial d'Antivir : http://www.malekal.com/tutorial_antivir.php
    Pour plus d'informations, voici un petit comparatif : http://forum.malekal.com/ftopic3123.php

    Comment se protéger des virus : - Tout ceci est résume sur cette page : Sécuriser son ordinateur et connaître les menaces
    Je t'invite aussi à mettre à jour tous les composants de ton système - Garde l'habitude de les maintenir à jour, un ordinateur avec des logiciels non à jour = infection ! tu peux scanner ton ordinateur pour vérifier quels sont les progammes non à jour en suivant les directives de cette page : http://www.malekal.com/scan_vulnerabilite.php

    Faire bouger les choses :

    Rapporte ton infection pour faire condamner les auteurs sur Malware-Complaints. Pour faire entendre notre voix, nous devons être le plus nombreux possibles, alors rapport ton infection :
    - Voir les règles de Malware-Complaints
    - Enregistre sur le forum à partir du bouton register en haut :
    Si tu as plus de 13 ans, choisir : I Agree to these terms and am over or exactly 13 years of age
    Si tu as moins, clic sur : I Agree to these terms and am under 13 years of age

    Après t'être enregistré, tu as sous forme de liste les types d'infection (Look2Me, Smitfraud, SpywareQuake etc..) : http://www.malwarecomplaints.info/viewforum.php?f=10&sid=0ea0981a2025873f(...)

    Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas quelle infection tu as eu, créé un message dans le sujet "Autres infections" conforme au règle du forum (age, ville, département etc..) : http://www.malwarecomplaints.info/viewforum.php?f=10

    Pour poster un message, clics sur le bouton "post reply" et remplir les informations - NE PAS CREER UN SUJET avec le bouton New Topic.

    Pour toutes aides pour poster ton message, tu peux consulter ce lien : http://www.malekal.com/malwarecomplaints.html
    Si tu as des questions ou des problèmes, n'hésites pas à me demander ici ou à contacter un des modérateurs du forum : Kimberly, AgnesD ou ipl_001.


    PRODUITS

    TÉLÉCHARGER - LOGICIELS

    JEUX VIDÉOS

    LOISIRS

    01NET PRO

    AVIS ET COMMENTAIRES

    A PROPOS DE 01NET

    publicité
    Photos
    720 corps nus pour sauver la feuille de vigne.

    Service 01net
    Newsletters 01net
    abonnez vous gratuitement !
      
    01Informatique
    01 INFORMATIQUE
    L'hebdo de référence des décideurs informatiques.
    Micro Hebdo
    MICRO HEBDO
    L'hebdo qui vous simplifie la micro
    et Internet.
    L'Ordinateur Individuel
    L'ORDINATEUR INDIVIDUEL
    Le mensuel informatique qui vous informe et vous conseille.
    Nous contacter  |  Charte de confiance  |  Voir notice légale

    01net.  -  01men  -  RMC  -  BFM Radio  -  BFM TV  -  TousLesPodcasts  -  01informatique.fr  -  Association RMC-BFM
    Tous droits réservés © 1999 - 2009 Internext - 01net.