Bonjour NickW, du nouveau..
re-essais sur le CD de transfert : tourne toujours , impossible d'ouvrir. ( sur PC-malade )
Aller voir sur mon PC : je peux ouvrir et oh! stupéfaction tous les logs et logociels enrgistrés disparus sauf HJT. Que signifie ? Est-ce possible ?
L'idée de reprendre un autre CD neuf, et là pas de pb je peux enregistrer tout. Heureux !!
BILAN
a - nette amélioration des réactions. Ne nous avançons pas trop, pour l'instant j'etais cantonné dans les même fonctions..
Cependant l'installation du bureau est lente encore.Peut-on améliorer ?
zffequpjy.exe m'a copieusement embêté avec sa fenêtre toujours.
b -HJT Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:52, on 04/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\zffequpjy.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\HJT\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {733E9132-53CA-4C97-9AC9-145C4502FA20} - C:\WINDOWS\system32\tuvutqo.dll
O2 - BHO: (no name) - {AA41A037-3359-4556-A257-8183E6DD5CBE} - C:\WINDOWS\System32\ssqnl.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [china] C:\nasajplview.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Log System] C:\WINDOWS\System32\zffequpjy.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/206f8060b82 ... 601_fr.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: tuvutqo - C:\WINDOWS\SYSTEM32\tuvutqo.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 6979 bytes
AVG ---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 11:40:56 04/10/2006
+ Résultat de l'analyse:
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061616.exe -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061617.exe -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061610.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061612.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061613.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061614.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061615.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061627.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061637.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061650.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061660.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061673.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061682.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP4\A0061691.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\zffequpjy.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
C:\gmafrufwh.exe -> Heuristic.Win32.Exploit : Nettoyé et sauvegardé (mise en quarantaine).
SDFIX
SDFix: Version 1.112
Run by Cecile Roumy on 02/10/2006 at 18:30
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
Microsoft Agent
ImagePath:
"C:\WINDOWS\System32\dllcache\frehost.exe"
Microsoft Agent - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\27031_~1.EXE - Deleted
C:\WINDOWS\system\NOTEPAD.exe - Deleted
C:\WINDOWS\system32\firewall.exe - Deleted
Folder C:\Program Files\Network Monitor - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\System32\\zffequpjy.exe"="C:\\WINDOWS\\System32\\zffequpjy.exe:*:Enabled:Log System"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Tue 28 Aug 2001 80,384 A.SHR --- "C:\imfkznebe.exe"
Tue 28 Aug 2001 80,384 ...H. --- "C:\jpbmknecb.exe"
Tue 28 Aug 2001 80,384 A.SHR --- "C:\vvqtuvfds.exe"
Wed 12 Sep 2007 4,380 A..H. --- "C:\WINDOWS\system32\corqhnit.exe"
Thu 13 Sep 2007 24,024 A..H. --- "C:\WINDOWS\system32\daqqvzye.exe"
Wed 12 Sep 2007 69,860 A..H. --- "C:\WINDOWS\system32\degqeik.exe"
Thu 13 Sep 2007 10,884 A..H. --- "C:\WINDOWS\system32\ifysqr.exe"
Tue 28 Aug 2001 80,384 ..SHR --- "C:\WINDOWS\system32\kbqozasnt.exe"
Sun 2 Sep 2007 80,384 A.SH. --- "C:\WINDOWS\system32\mftrmrnjl.exe"
Thu 13 Sep 2007 43,916 A..H. --- "C:\WINDOWS\system32\onsmkfy.exe"
Thu 13 Sep 2007 50,324 A..H. --- "C:\WINDOWS\system32\prevsa.exe"
Sat 15 Sep 2007 69,860 A..H. --- "C:\WINDOWS\system32\qojhh.exe"
Wed 12 Sep 2007 69,860 A..H. --- "C:\WINDOWS\system32\rgnxccx.exe"
Mon 3 Sep 2007 69,860 A..H. --- "C:\WINDOWS\system32\yjdtxf.exe"
Tue 28 Aug 2001 80,384 A.SHR --- "C:\WINDOWS\system32\zffequpjy.exe"
Mon 25 Jun 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Mon 25 Jun 2007 401 ..SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv18.bak"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP0\A0000042.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0000044.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0001071.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0002008.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0003008.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0004008.exe"
Tue 28 Aug 2001 511,488 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0004010.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0004024.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0005021.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP1\A0005038.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0005043.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0005061.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0005080.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0005091.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0006094.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0007092.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0007109.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0008109.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0009108.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0009120.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0009131.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0009142.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0009153.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0012155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0013156.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0014157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0017154.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0018155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0019157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0022155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0023157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0024157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0025155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0026155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0027157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0028155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0029155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0030157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0031155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0033155.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0034157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0035157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0036157.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0036166.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP2\A0037168.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0037172.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0037183.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0037200.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0037211.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0037224.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0038224.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0039224.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0039237.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0039246.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0039259.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0040261.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0043259.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0044259.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0050259.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0055259.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0058259.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059259.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059271.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059284.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059301.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059315.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059331.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059346.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059360.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059378.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059391.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059407.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0059422.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060422.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060438.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060453.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060464.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060479.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060494.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060538.exe"
Tue 28 Aug 2001 80,384 A..H. --- "C:\System Volume Information\_restore{84EB1796-A022-436F-BFCA-BED09733F54C}\RP3\A0060550.exe"
Thu 5 Aug 2004 32,840 ...H. --- "C:\Documents and Settings\Cecile Roumy\Mes documents\Ma musique\Finale 2005 (D_)\AUTORUN.EXE"
Thu 5 Aug 2004 32,840 A..H. --- "C:\Documents and Settings\roumy c‚cile\Mes documents\Finale 2005\Finale 2005 (D_)\AUTORUN.EXE"
Finished!
Je t'envois navi1, log de OTMovelt et Vundofix demain. J'espère pas de problème.