Accueil Forum Tutoriaux Contactez nous
Forum informatique
Aidoforum.com  •  RSS  •  Chat  •  Annuaire  •  Demander de l'aide  •  Tutoriaux  •  Rechercher   •  S'inscrire  •  Profil  •  Non identifié  •  Connexion

Soutenez Aidoforum

Inscrivez vous pour découvrir les nombreux avantages des membres ! La publicité disparaîtra, et l'inscription est gratuite !
 

probleme de trojans proxu.horst

    ( Recommander ce sujet )

Créer un nouveau fil de discussion dans la même catégorie
Répondre au sujet
Auteur Message

dark vador69

Disquette
Disquette


Avatar non sélectionné


Messages: 40
Tutoriaux : 0

MessagePosté le: Mer 16 Mai 2007 07:14    Sujet : probleme de trojans proxu.horst Répondre en citantRevenir en haut Alerter les modérateurs

bonjour tout le monde au comble du desespoir je solicite votre aide pour mon probleme de malware .le probleme est le suivant ,premierement mon pare feu (zonealarme) me previent constament qu'un programme du type 70exnijs.exe veut demarer , je bloque l'acces mais peu de temps apres il revient sous un autre nom du type 39exnijs et ainsi de suite .deuxiemement mes cessions internet sont tres souvent envahient par des fenetre pub qui s'ouvrent toutes seule du types winsftware ,voyance betclic,systeme doctor etc et cela malgres mon bloqueur de popup.j'ai suivie votre procedure de nettoyage a la lettre et vous envoie les rapports obtenus.merci par avance de votre aide.Logfile of HijackThis v1.99.1
Scan saved at 07:54:21, on 16/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\71exinjs.a9.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\christophe\Mes documents\mes logiciels\securité\Nouveau dossier\aidoroforum.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pornkingmovies.com/%20to%20verify%20your%20age,%20REQUIRED!%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20WARNING!%20Adult%20pictures%20are%20featured%20in%20this%20site.% 20Only%20adults%20permitted%20beyond%20this%20point!%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Are%20you%20at%20least %2018%20years%20old
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [fenaffiche] C:\Program Files\FenAffiche\FenUnika.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [vrdaszi] c:\windows\system32\vrdaszi.exe vrdaszi
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab ?1121096465890
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Systems Internals - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

16/05/2007 a 7:55:30,46

*** Recherche des fichiers dans C:
C:\StubInstaller.exe FOUND

*** Recherche des fichiers dans C:\WINDOWS\

*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system\smss.exe FOUND
C:\WINDOWS\system32\winspool.dll FOUND
"C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\??exinjs.??.exe" FOUND

*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\mailskinner\" FOUND
"C:\Program Files\MessengerSkinner\" FOUND
*** Fin du rapport !

16/05/2007 a 7:55:30,46

*** Recherche des fichiers dans C:
C:\StubInstaller.exe FOUND

*** Recherche des fichiers dans C:\WINDOWS\

*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system\smss.exe FOUND
C:\WINDOWS\system32\winspool.dll FOUND
"C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\??exinjs.??.exe" FOUND

*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\mailskinner\" FOUND
"C:\Program Files\MessengerSkinner\" FOUND
*** Fin du rapport !




et enfin ---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 07:24:26 16/05/2007

+ Résultat de l'analyse:



C:\Program Files\MessengerSkinner\uninst.exe -> Adware.NaviPromo : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\stbwjedzip.exe -> Adware.NaviPromo : Nettoyé et sauvegardé (mise en quarantaine).
HKU\S-1-5-21-1943756527-1774892174-1014270077-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Sta ts\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP4\A0000629.exe -> Backdoor.Skinymes.a : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP3\A0000350.exe -> Downloader.Agent.aii : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\christophe\Local Settings\Temp\39exinjs.a9.exe -> Proxy.Horst.sv : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\christophe\Local Settings\Temp\86exinjs.a9.exe -> Proxy.Horst.sv : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\isabel\Local Settings\Temp\59exinjs.a9.exe -> Proxy.Horst.sv : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP3\A0000389.exe -> Proxy.Horst.sv : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP3\A0000390.exe -> Proxy.Horst.wo : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.6:C:\Documents and Settings\christophe\Application Data\Mozilla\Firefox\Profiles\tmc24sy0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.7:C:\Documents and Settings\christophe\Application Data\Mozilla\Firefox\Profiles\tmc24sy0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.9:C:\Documents and Settings\christophe\Application Data\Mozilla\Firefox\Profiles\tmc24sy0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
C:\Documents and Settings\mathilde\Cookies\mathilde@search.msn[2].txt -> TrackingCookie.Msn : Nettoyé.
C:\Documents and Settings\christophe\Mes documents\mes jeux\Zoo_Tycoon_Complete_Collection_No-CD_Patch.rar/Nur Cd 2\Zoo_Patch.exe -> Trojan.Feutel.av : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\christophe\Mes documents\mes jeux\patch jeux\patch zoo3\Zoo_Patch.exe -> Trojan.Feutel.av : Nettoyé et sauvegardé (mise en quarantaine).


Fin du rapport
Configuration système deVoir le profil de l'utilisateurEnvoyer un message privé

synthexe

Geek
Geek

AidoAntivirus
AidoAntivirus


Messages: 2470
Tutoriaux : 0

MessagePosté le: Mer 16 Mai 2007 10:30    Sujet : probleme de trojans proxu.horst Répondre en citantRevenir en haut Alerter les modérateurs

Bonjour dark vador69 et bienvenue sur AidoForum Clin
d'oeil

Tu es effectivement bien infecté, je vais t'aider a supprimer tout ca ...

Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.
Déroule la liste des instructions ci-dessous :

  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
N.B.:
- Le fichier SDFIX_README.htm (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.

  • Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd, une fenêtre noire va apparaître.
  • Choisis l'option 2 et appuie sur Entrée pour valider.
  • Copie/colle moi le rapport qui apparait dans ta prochaine réponse.



  • Télécharge Navilog1 de Il-Mafioso.
  • Ensuite double clique sur navilog1.exe pour lancer l'installation.
  • Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

  • Laisse-toi guider. Au menu principal, choisis 1 et valide.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

  • Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
  • Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
  • Copie-colle l'intégralité dans une réponse. Referme le bloc-note.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)




Poste moi les rapports SDFix, Clean option2, Navilog option1 et un nouveau rapport hijackthis.

Bonne journée Clin d'oeil

_________________
Anti-Malware Powa
Configuration système deVoir le profil de l'utilisateurEnvoyer un message privéVisiter le site web du posteur

dark vador69

Disquette
Disquette


Avatar non sélectionné


Messages: 40
Tutoriaux : 0

MessagePosté le: Mer 16 Mai 2007 11:28    Sujet : probleme de trojans proxu.horst Répondre en citantRevenir en haut Alerter les modérateurs

merci pour ton aide s"est tres sympa voici les differents rapport


SDFix: Version 1.84

Run by christophe - 16/05/2007 - 11:57:51,37

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing Security Center Service
Restoring Missing SharedAccess Service

Rebooting...


Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\injs.a9.exe.conf - Deleted
C:\WINDOWS\system\smss.exe - Deleted



Removing Temp Files...

ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.



Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Standar dProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re s.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\41exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\41exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\94exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\94exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\70exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\70exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\14exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\14exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\75exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\75exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\59exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS ~1\\Temp\\59exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\39exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\39exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\86exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\86exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\60exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\60exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\68exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS ~1\\Temp\\68exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\71exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\71exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\26exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\26exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\0exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS~ 1\\Temp\\0exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\87exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\87exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\93exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\93exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\53exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\53exinjs.a9.exe:*:Enabled:Microsoft Update"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainP rofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re s.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes:

C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\Sharing Folders\cstromano@hotmail.com\Thumbs.db
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\Sharing Folders\petitepuuce@hotmail.com\Thumbs.db
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\Sharing Folders\vania_valadeiro@hotmail.com\Thumbs.db
C:\Program Files\Canon\Canon Setup Utility 2.3\uinstrsc.dll
C:\Program Files\Canon\Canon Setup Utility 2.3\Maint.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\isabel\Bureau\ACTION 1\~WRL0001.tmp
C:\Documents and Settings\isabel\Bureau\info Mr Bloch\Exo\~WRL3828.tmp

Finished
le rappoort clean
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 16/05/2007 a 12:13:29,43

Microsoft Windows XP [version 5.1.2600]

*** Suppression des fichiers dans C:
tentative de suppression de C:\StubInstaller.exe

*** Suppression des fichiers dans C:\WINDOWS\

*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\system32\winspool.dll

*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\MessengerSkinner\"

*** Suppression des clefs du registre effectuee..
*** Fin du rapport !


le rapport navilog

Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 16/05/2007 a 12:13:29,43

Microsoft Windows XP [version 5.1.2600]

*** Suppression des fichiers dans C:
tentative de suppression de C:\StubInstaller.exe

*** Suppression des fichiers dans C:\WINDOWS\

*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\system32\winspool.dll

*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\MessengerSkinner\"

*** Suppression des clefs du registre effectuee..
*** Fin du rapport

enfin le rapport hijack

Logfile of HijackThis v1.99.1
Scan saved at 12:26:54, on 16/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
C:\Documents and Settings\christophe\Mes documents\mes logiciels\securité\Nouveau dossier\aidoroforum.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pornkingmovies.com/%20to%20verify%20your%20age,%20REQUIRED!%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20WARNING!%20Adult%20pictures%20are%20featured%20in%20this%20site.% 20Only%20adults%20permitted%20beyond%20this%20point!%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Are%20you%20at%20least %2018%20years%20old
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [fenaffiche] C:\Program Files\FenAffiche\FenUnika.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [kipejnp] c:\windows\system32\kipejnp.exe kipejnp
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab ?1121096465890
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Systems Internals - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

encore merci pour ton aide
Configuration système deVoir le profil de l'utilisateurEnvoyer un message privé

synthexe

Geek
Geek

AidoAntivirus
AidoAntivirus


Messages: 2470
Tutoriaux : 0

MessagePosté le: Jeu 17 Mai 2007 11:36    Sujet : probleme de trojans proxu.horst Répondre en citantRevenir en haut Alerter les modérateurs

Bonjour Clin d'oeil

Merci pour les rapports Sourire , mais tu as oublié navilog ... passe-le stp, et poste le rapport.

Fais aussi ceci :

Lance hijackthis et clique sur Do a System Scan Only.
Coche les lignes suivantes, si présentes :
Citation:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pornkingmovies.com/%20to%20verify%20your%20age,%20REQUIRED!%20%20%20% 20%20%20%20%20%20%20%20%20%20%20%20WARNING!%20Adult%20pictures%20are%20featured%20in%20this%20site.% 20Only%20adults%20permitted%20beyond%20this%20point!%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20 %20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Are%20you%20at%20least %2018%20years%20old
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [kipejnp] c:\windows\system32\kipejnp.exe kipejnp

Ferme tous les programmes, sauf hijackthis et clique sur Fix Checked.

Clique sur Démarrer --> Exécuter --> Saisie :
Code:
SC delete NipSvc

Clique sur Ok pour valider.

  • Télécharge DiagHelp de Malekal_morte sur ton bureau :
  • Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout.
  • Un nouveau dossier chercher va être créé DiagHelp.
  • Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître).
  • Une fenêtre va s'ouvrir, choisis l'option 1.
  • L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.
  • Copie/colle le rapport ici


Poste moi le rapport de navilog, celui de diaghelp et un nouveau hijackthis.

Bonne journée Clin d'oeil
Configuration système deVoir le profil de l'utilisateurEnvoyer un message privéVisiter le site web du posteur

dark vador69

Disquette
Disquette


Avatar non sélectionné


Messages: 40
Tutoriaux : 0

MessagePosté le: Jeu 17 Mai 2007 14:27    Sujet : probleme de trojans proxu.horst Répondre en citantRevenir en haut Alerter les modérateurs

voila deja le rapport navilog je fait le resteSearch Navipromo version 2.0.1 commencé le 17/05/2007 à 15:18:23,23

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

Fix lancé depuis C:\Program Files\navilog1
Mise a jour le 10.05.2007 a 22h00 by IL-MAFIOSO

Executé en mode normal

*** Recherche Programmes installes ***




*** Recherche dossiers dans C:\WINDOWS ***


C:\WINDOWS\msskinner trouvé !


*** Recherche dossiers dans C:\Program Files ***




*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***




*** Recherche dossiers dans C:\Documents and Settings\christophe\Application Data ***



*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
http://www.f-secure.com/blacklight/blacklight_help.html

Fichier(s) caché(s) dans C:\WINDOWS\system32 :

c:\WINDOWS\system32\vrdaszi.dat
C:\windows\system32\vrdaszi.exe
c:\WINDOWS\system32\vrdaszi_nav.dat
c:\WINDOWS\system32\vrdaszi_navps.dat

Processus caché(s) dans C:\WINDOWS\system32 :

C:\windows\system32\vrdaszi.exe


*** Recherche fichiers ***


C:\WINDOWS\pack.epk trouvé !
C:\WINDOWS\system32\nvs2.inf trouvé !


*** Recherche cles registre ***


Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]



Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]



Recherche Clé Magic Control

HKEY_CURRENT_USER\Software\Lanconfig trouvé !


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche fichiers connus:


2)Recherche Heuristique :
*
C:\WINDOWS\system32\kipejnp.dat trouvé !
C:\WINDOWS\system32\vrdaszi.dat trouvé !
**
C:\WINDOWS\system32\kipejnp.dat trouvé !
C:\WINDOWS\system32\vrdaszi.dat trouvé !
***
****
C:\WINDOWS\system32\kipejnp_navps.dat trouvé !
C:\WINDOWS\system32\vrdaszi_navps.dat trouvé !
*****
C:\WINDOWS\system32\kipejnp_nav.dat trouvé !
C:\WINDOWS\system32\vrdaszi_nav.dat trouvé !
C:\WINDOWS\system32\kipejnp_navup.dat trouvé !
C:\WINDOWS\system32\boxqdwuc_navtmp.dat trouvé !
C:\WINDOWS\system32\dqpmfwoyce_navtmp.dat trouvé !
C:\WINDOWS\system32\vsthecbjaq_navtmp.dat trouvé !
******
*******
C:\WINDOWS\system32\miimrp.exe trouvé !
********
C:\WINDOWS\system32\kipejnp.exe trouvé !
C:\WINDOWS\system32\mauagafaf.exe trouvé !
C:\WINDOWS\system32\miimrp.exe trouvé !
C:\WINDOWS\system32\vrdaszi.exe trouvé !


*** Analyse Terminé le 17/05/2007 à 15:23:14,87 ***
Configuration système deVoir le profil de l'utilisateurEnvoyer un message privé

dark vador69

Disquette
Disquette


Avatar non sélectionné


Messages: 40
Tutoriaux : 0

MessagePosté le: Jeu 17 Mai 2007 15:16    Sujet : probleme de trojans proxu.horst Répondre en citantRevenir en haut Alerter les modérateurs

voila les deux autres rapports .on dirait que zone alarme ne me previent plus toutes les 5 minutes pour des programme xnijs mais les pubs intempestives type adultfriender betclic navisearh ou winsoftware sont toujours presentent. merci pour ta patience !!

le rapport dighelpDiagHelp version v1.08.1 - http://www.malekal.com
excute le 17/05/2007 à 16:04:54,32


Liste des fichiers modifies/crees dans les 24 dernieres heures...
C:\WINDOWS
C:\WINDOWS\0.log
C:\WINDOWS\bootstat.dat
C:\WINDOWS\Debug\PASSWD.LOG
C:\WINDOWS\Internet Logs
C:\WINDOWS\Internet Logs\BACKUP.RDB
C:\WINDOWS\Internet Logs\fwdbglog.txt
C:\WINDOWS\Internet Logs\fwpktlog.txt
C:\WINDOWS\Internet Logs\JOSHUA.ldb
C:\WINDOWS\Internet Logs\tvDebug.log
C:\WINDOWS\Internet Logs\ZALog.txt
C:\WINDOWS\SchedLgU.Txt
C:\WINDOWS\system32
C:\WINDOWS\system32\kipejnp.dat
C:\WINDOWS\system32\nvapps.xml
C:\WINDOWS\system32\Restore
C:\WINDOWS\system32\Restore\MachineGuid.txt
C:\WINDOWS\system32\spool\PRINTERS
C:\WINDOWS\system32\vrdaszi.dat
C:\WINDOWS\system32\vrdaszi_navps.dat
C:\WINDOWS\system32\vsconfig.xml
C:\WINDOWS\system32\wpa.dbl
C:\WINDOWS\system32\ZoneLabs\Updates
C:\WINDOWS\system32\ZoneLabs\Updates\LocalCatalog.xml
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Temp
C:\WINDOWS\Temp\Perflib_Perfdata_5a4.dat
C:\WINDOWS\Temp\WGANotify.settings
C:\WINDOWS\Temp\ZLT00724.TMP
C:\WINDOWS\Temp\ZLT00727.TMP
C:\WINDOWS\Temp\_avast4_
C:\WINDOWS\Temp\_avast4_\Webshlock.txt
C:\WINDOWS\wiadebug.log
C:\WINDOWS\wiaservc.log
C:\WINDOWS\WindowsUpdate.log


Liste des derniers fichies modifies/crees dans windir\system32
C:\WINDOWS\System32/drivers\aswmon.sys -->30/04/2007 17:41:55
C:\WINDOWS\System32/drivers\aswmon2.sys -->30/04/2007 17:41:42
C:\WINDOWS\System32/drivers\aswRdr.sys -->30/04/2007 17:39:41
C:\WINDOWS\System32/drivers\aswTdi.sys -->30/04/2007 17:38:51
C:\WINDOWS\System32/drivers\aavmker4.sys -->30/04/2007 17:37:23
C:\WINDOWS\System32/drivers\ntfs.sys -->09/02/2007 13:10:35
C:\WINDOWS\System32/drivers\vaxscsi.sys -->26/10/2006 01:42:21

C:\WINDOWS\System32\vrdaszi_navps.dat -->17/05/2007 16:05:04
C:\WINDOWS\System32\vrdaszi.dat -->17/05/2007 16:04:30
C:\WINDOWS\System32\vsconfig.xml -->17/05/2007 15:40:23
C:\WINDOWS\System32\wpa.dbl -->17/05/2007 15:12:53
C:\WINDOWS\System32\nvapps.xml -->17/05/2007 15:10:49
C:\WINDOWS\System32\kipejnp.dat -->17/05/2007 00:59:56
C:\WINDOWS\System32\perfh00C.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\perfh009.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\perfc00C.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\perfc009.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\PerfStringBackup.INI -->16/05/2007 12:08:46
C:\WINDOWS\System32\perfh040.dat -->16/05/2007 12:08:45
C:\WINDOWS\System32\perfc040.dat -->16/05/2007 12:08:45
C:\WINDOWS\System32\CONFIG.NT -->13/05/2007 23:25:16
C:\WINDOWS\System32\vrdaszi_nav.dat -->12/05/2007 09:14:51
C:\WINDOWS\System32\kipejnp_navup.dat -->11/05/2007 07:06:11
C:\WINDOWS\System32\d3d9caps.dat -->09/05/2007 12:38:55
C:\WINDOWS\System32\SIntfNT.dll -->08/05/2007 09:58:11
C:\WINDOWS\System32\SIntf32.dll -->08/05/2007 09:58:11
C:\WINDOWS\System32\SIntf16.dll -->08/05/2007 09:58:11
C:\WINDOWS\System32\kipejnp.exe -->02/05/2007 16:28:31
C:\WINDOWS\System32\aswBoot.exe -->30/04/2007 17:46:10
C:\WINDOWS\System32\AVASTSS.scr -->30/04/2007 17:35:28
C:\WINDOWS\System32\MRT.exe -->27/04/2007 22:45:12
C:\WINDOWS\System32\vrdaszi.exe -->26/04/2007 19:02:10

C:\WINDOWS\0.log -->17/05/2007 15:12:01
C:\WINDOWS\WindowsUpdate.log -->17/05/2007 15:11:37
C:\WINDOWS\wiadebug.log -->17/05/2007 15:11:01
C:\WINDOWS\wiaservc.log -->17/05/2007 15:10:59
C:\WINDOWS\bootstat.dat -->17/05/2007 15:10:27
C:\WINDOWS\SchedLgU.Txt -->17/05/2007 12:05:03
C:\WINDOWS\Sti_Trace.log -->16/05/2007 07:48:52
C:\WINDOWS\NeroDigital.ini -->14/05/2007 18:01:56
C:\WINDOWS\win.ini -->23/04/2007 21:43:11
C:\WINDOWS\system.ini -->09/04/2007 10:32:04
C:\WINDOWS\PhotoSnapViewer.INI -->09/03/2007 10:40:46
C:\WINDOWS\zllsputility_loc040c.dll -->09/03/2007 00:03:06
C:\WINDOWS\zllsputility.exe -->09/03/2007 00:02:00
C:\WINDOWS\pack.epk -->14/02/2007 21:20:29
C:\WINDOWS\PowerReg.dat -->10/01/2007 21:41:45


Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 8873-867D

Répertoire de C:\WINDOWS\system32

05/08/2004 14:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 121 246 957 568 octets libres

Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 8873-867D

Répertoire de C:\WINDOWS\Downloaded Program Files

08/04/2007 19:53 <REP> .
08/04/2007 19:53 <REP> ..
11/07/2005 15:23 65 desktop.ini
11/12/2006 17:44 367 LegitCheckControl.inf
20/01/2000 15:25 1 162 Microsoft XML Parser for Java.osd
29/06/2005 17:17 227 opuc.inf
09/11/2006 15:36 5 019 swflash.inf
26/05/2005 04:19 291 wuweb.inf
6 fichier(s) 7 131 octets

Total des fichiers listés :
6 fichier(s) 7 131 octets
2 Rép(s) 121 246 957 568 octets libres

Recherche de rootkit! (Merci S!Ri)
infection possible Magic.Control : un scan F-Secure BlackLight est recommandé

Recherche d'infections connues

Export des clefs sensibles..

Liste des fichiers en exception sur le pare-feu XP SP2

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re s.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\41exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\41exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\94exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\94exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\70exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\70exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\14exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\14exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\75exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\75exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\59exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS ~1\\Temp\\59exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\39exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\39exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\86exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\86exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\60exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\60exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\68exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS ~1\\Temp\\68exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\71exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\71exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\26exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\26exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\0exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS~ 1\\Temp\\0exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\87exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\87exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\93exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\93exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\53exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO CALS~1\\Temp\\53exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re s.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Export de la clef SharedTaskScheduler

[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

Rechercher adresses sensibles dans le fichier HOSTS...



catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-17 16:05:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\01\27-{C7288C60-5584-BBE3-125E-E007FE577B73}-v1-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\89\235-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v89-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4044 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\89\235-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v89-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\90\236-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v90-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3864 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\90\236-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v90-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\culture-club@hotmail.fr\DFSR\Stag ing\CS{EEB87E84-22B3-9CE0-21D7-CE775441081C}\01\10-{EEB87E84-22B3-9CE0-21D7-CE775441081C}-v1-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\01\22-{4D946FF6-8632-DF97-193D-312C18EC36EB}-v1-{B3A57E0D-5 A94-4085-A9BA-13A5DDECC4B9}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\11\285-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v11-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5268 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\11\285-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v11-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 592 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\14\279-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v14-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3810 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\14\279-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v14-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\17\280-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v17-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4764 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\17\280-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v17-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 544 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\20\286-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v20-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4314 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\20\286-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v20-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 488 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\23\283-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v23-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4098 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\23\283-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v23-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 464 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\287-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v24-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6456 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\287-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v24-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 728 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\288-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v24-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3450 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\288-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v24-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 384 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\25\281-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v25-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6060 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\25\281-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v25-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\26\282-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v26-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6222 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\26\282-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v26-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 688 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\27\299-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1527-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 43176 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\27\299-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1527-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 4832 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\284-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v28-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4962 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\284-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v28-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 552 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\295-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1528-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 57252 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\295-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1528-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 6456 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\291-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v29-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7482 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\291-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v29-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\300-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1529-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 14178 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\300-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1529-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 1544 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\34\289-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v34-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5376 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\34\289-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v34-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 592 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\37\290-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v37-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4008 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\37\290-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v37-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 448 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\41\272-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v141-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 19902 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\41\272-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v141-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1488 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\41\272-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v141-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\42\142-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v142-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1380 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\42\142-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v142-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 152 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\49\294-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v149-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 20100 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\49\294-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v149-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2160 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\57\298-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1257-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 21684 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\57\298-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1257-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 2408 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\88\293-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v988-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3612 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\88\293-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v988-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 416 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\91\296-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v91-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5412 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\91\296-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v91-{B3A57E0D -5A94-4085-A9BA-13A5DDECC4B9}-v296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 616 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\92\297-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v992-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3774 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\ CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\92\297-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v992-{B3A57E0 D-5A94-4085-A9BA-13A5DDECC4B9}-v297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 416 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\01\85-{000328E1-717F-0640-4E54-0927C781472A}-v1-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v85-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\06\32-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v106-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4152 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\06\32-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v106-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\07\11-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v107-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4764 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\07\11-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v107-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 536 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\08\12-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v108-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3234 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\08\12-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v108-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\09\19-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v109-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\09\19-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v109-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 368 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\10\20-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v110-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2802 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\10\20-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v110-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 312 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\11\21-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v111-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2532 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\11\21-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v111-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 280 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\12\22-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v112-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3990 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\12\22-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v112-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 456 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\13\13-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v113-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3810 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\13\13-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v113-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 432 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\14\23-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v114-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3306 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\14\23-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v114-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 368 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\15\24-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v115-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6618 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\15\24-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v115-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 728 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\16\25-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v116-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4728 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\16\25-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v116-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 528 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\17\33-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v117-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5664 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\17\33-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v117-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 624 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\18\26-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v118-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6690 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\18\26-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v118-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\19\14-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v119-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5286 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\19\14-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v119-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 600 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\20\28-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v120-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6492 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\20\28-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v120-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 736 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\21\27-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v121-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7968 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\21\27-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v121-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\22\15-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v122-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5412 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\22\15-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v122-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 616 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\23\29-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v123-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 8832 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\23\29-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v123-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 976 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\24\31-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v124-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4260 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\24\31-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v124-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 464 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\25\16-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v125-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6636 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\25\16-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v125-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 752 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\26\17-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v126-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5718 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\26\17-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v126-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\27\34-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v127-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5394 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\27\34-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v127-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 592 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\28\35-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v128-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7194 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\28\35-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v128-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 800 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\29\18-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v129-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4206 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\29\18-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v129-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 472 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\30\36-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v130-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7950 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\30\36-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v130-{8F4D 6544-DDCA-41AB-A35C-6CA4AFC94F15}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 872 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\86\30-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v86-{8F4D6 544-DDCA-41AB-A35C-6CA4AFC94F15}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6492 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag ing\CS{000328E1-717F-0640-4E54-0927C781472A}\86\30-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v86-{8F4D6 544-DDCA-41AB-A35C-6CA4AFC94F15}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 696 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\01\11-{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}-v1-{B3A57E 0D-5A94-4085-A9BA-13A5DDECC4B9}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\54\54-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4152 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\54\54-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\55\55-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4764 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\55\55-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 536 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\56\56-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3234 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\56\56-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\57\57-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\57\57-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 368 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\58\58-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v58-{B3A57 E0D-5A94-4085-A9BA-13A5DDECC4B9}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 2802 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\58\58-{