| Auteur |
Message |
Disquette
Messages: 39
Tutoriaux : 0
|
Posté le:
Mer 16 Mai 2007 08:14 Sujet : probleme de trojans proxu.horst |
  |
bonjour tout le monde au comble du desespoir je solicite votre aide pour mon probleme de malware .le
probleme est le suivant ,premierement mon pare feu (zonealarme) me previent constament qu'un
programme du type 70exnijs.exe veut demarer , je bloque l'acces mais peu de temps apres il revient
sous un autre nom du type 39exnijs et ainsi de suite .deuxiemement mes cessions internet sont tres
souvent envahient par des fenetre pub qui s'ouvrent toutes seule du types winsftware ,voyance
betclic,systeme doctor etc et cela malgres mon bloqueur de popup.j'ai suivie votre procedure de
nettoyage a la lettre et vous envoie les rapports obtenus.merci par avance de votre aide.Logfile of
HijackThis v1.99.1
Scan saved at 07:54:21, on 16/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\71exinjs.a9.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\christophe\Mes documents\mes logiciels\securité\Nouveau
dossier\aidoroforum.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pornkingmovies.com/%20to%20verify%20your%20age,%20REQUIRED!%20%20%20%
20%20%20%20%20%20%20%20%20%20%20%20WARNING!%20Adult%20pictures%20are%20featured%20in%20this%20site.%
20Only%20adults%20permitted%20beyond%20this%20point!%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20
%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Are%20you%20at%20least
%2018%20years%20old
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program
Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program
Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN
Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN
Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN
Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program
Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [fenaffiche] C:\Program Files\FenAffiche\FenUnika.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"
-osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [vrdaszi] c:\windows\system32\vrdaszi.exe vrdaszi
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe"
/minimized
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe"
AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat
7.0\Reader\reader_sl.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab
?1121096465890
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program
Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
(file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Systems Internals - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program
Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
16/05/2007 a 7:55:30,46
*** Recherche des fichiers dans C:
C:\StubInstaller.exe FOUND
*** Recherche des fichiers dans C:\WINDOWS\
*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system\smss.exe FOUND
C:\WINDOWS\system32\winspool.dll FOUND
"C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\??exinjs.??.exe" FOUND
*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\mailskinner\" FOUND
"C:\Program Files\MessengerSkinner\" FOUND
*** Fin du rapport !
16/05/2007 a 7:55:30,46
*** Recherche des fichiers dans C:
C:\StubInstaller.exe FOUND
*** Recherche des fichiers dans C:\WINDOWS\
*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system\smss.exe FOUND
C:\WINDOWS\system32\winspool.dll FOUND
"C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\??exinjs.??.exe" FOUND
*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\mailskinner\" FOUND
"C:\Program Files\MessengerSkinner\" FOUND
*** Fin du rapport !
et enfin ---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 07:24:26 16/05/2007
+ Résultat de l'analyse:
C:\Program Files\MessengerSkinner\uninst.exe -> Adware.NaviPromo : Nettoyé et sauvegardé (mise en
quarantaine).
C:\WINDOWS\system32\stbwjedzip.exe -> Adware.NaviPromo : Nettoyé et sauvegardé (mise en
quarantaine).
HKU\S-1-5-21-1943756527-1774892174-1014270077-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Sta
ts\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Nettoyé et sauvegardé (mise en
quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP4\A0000629.exe ->
Backdoor.Skinymes.a : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP3\A0000350.exe ->
Downloader.Agent.aii : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\christophe\Local Settings\Temp\39exinjs.a9.exe -> Proxy.Horst.sv :
Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\christophe\Local Settings\Temp\86exinjs.a9.exe -> Proxy.Horst.sv :
Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\isabel\Local Settings\Temp\59exinjs.a9.exe -> Proxy.Horst.sv : Nettoyé
et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP3\A0000389.exe ->
Proxy.Horst.sv : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{8B26E68C-EAC6-4030-A534-10211A3E8170}\RP3\A0000390.exe ->
Proxy.Horst.wo : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.6:C:\Documents and Settings\christophe\Application
Data\Mozilla\Firefox\Profiles\tmc24sy0.default\cookies.txt -> TrackingCookie.Advertising :
Nettoyé.
:mozilla.7:C:\Documents and Settings\christophe\Application
Data\Mozilla\Firefox\Profiles\tmc24sy0.default\cookies.txt -> TrackingCookie.Advertising :
Nettoyé.
:mozilla.9:C:\Documents and Settings\christophe\Application
Data\Mozilla\Firefox\Profiles\tmc24sy0.default\cookies.txt -> TrackingCookie.Advertising :
Nettoyé.
C:\Documents and Settings\mathilde\Cookies\mathilde@search.msn[2].txt -> TrackingCookie.Msn :
Nettoyé.
C:\Documents and Settings\christophe\Mes documents\mes
jeux\Zoo_Tycoon_Complete_Collection_No-CD_Patch.rar/Nur Cd 2\Zoo_Patch.exe -> Trojan.Feutel.av :
Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\christophe\Mes documents\mes jeux\patch jeux\patch zoo3\Zoo_Patch.exe
-> Trojan.Feutel.av : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport |
|
|
   |
 |
Geek
AidoAntivirus
Messages: 2383
Tutoriaux : 0
|
Posté le:
Mer 16 Mai 2007 11:30 Sujet : probleme de trojans proxu.horst |
  |
Bonjour dark vador69 et bienvenue sur AidoForum
Tu es effectivement bien infecté, je vais t'aider a supprimer tout ca ...
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
Redémarre ton ordinateur en mode sans échec en suivant la
procédure que voici :
- Redémarre ton ordinateur
- Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows
apparaisse, tapote la touche F8 (une pression par seconde).
- A la place du chargement normal de Windows, un menu avec différentes options devrait
apparaître.
- Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur
"Entrée".
- Choisis ton compte.
Déroule la liste des instructions ci-dessous :
- Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
- Appuie sur Y pour commencer le processus de nettoyage.
- Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te
demandera d'appuyer sur une touche pour redémarrer.
- Appuie sur une touche pour redémarrer le PC.
- Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à
s'exécuter et supprimer des fichiers.
- Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi
dans le dossier SDFix sous le nom Report.txt.
- Enfin, copie/colle le contenu du fichier Report.txt dans
ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
N.B.:
- Le fichier SDFIX_README.htm (dans le dossier SDFix)
contient la liste des malwares pris en compte par l'outil.
- Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd, une fenêtre noire va apparaître.
- Choisis l'option 2 et appuie sur Entrée pour valider.
- Copie/colle moi le rapport qui apparait dans ta prochaine réponse.
- Télécharge Navilog1 de Il-Mafioso.
- Ensuite double clique sur navilog1.exe pour lancer
l'installation.
- Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
- Laisse-toi guider. Au menu principal, choisis 1 et
valide.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
- Patiente jusqu'au message :
*** Analyse Termine le ..... ***
- Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
- Copie-colle l'intégralité dans une réponse. Referme le bloc-note.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
Poste moi les rapports SDFix, Clean option2, Navilog option1 et un nouveau rapport hijackthis.
Bonne journée  |
_________________ Anti-Malware Powa
 |
|
    |
 |
Disquette
Messages: 39
Tutoriaux : 0
|
Posté le:
Mer 16 Mai 2007 12:28 Sujet : probleme de trojans proxu.horst |
  |
merci pour ton aide s"est tres sympa voici les differents rapport
SDFix: Version 1.84
Run by christophe - 16/05/2007 - 11:57:51,37
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing Security Center Service
Restoring Missing SharedAccess Service
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\injs.a9.exe.conf - Deleted
C:\WINDOWS\system\smss.exe - Deleted
Removing Temp Files...
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\Standar
dProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re
s.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program
Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program
Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program
Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network
Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN
Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN
Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN
Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\41exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\41exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\94exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\94exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\70exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\70exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\14exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\14exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\75exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\75exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\59exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS
~1\\Temp\\59exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\39exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\39exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\86exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\86exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\60exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\60exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\68exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS
~1\\Temp\\68exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\71exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\71exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\26exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\26exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\0exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS~
1\\Temp\\0exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\87exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\87exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\93exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\93exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\53exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\53exinjs.a9.exe:*:Enabled:Microsoft Update"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainP
rofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re
s.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network
Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN
Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN
Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN
Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes:
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\Sharing Folders\cstromano@hotmail.com\Thumbs.db
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\Sharing
Folders\petitepuuce@hotmail.com\Thumbs.db
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\Sharing
Folders\vania_valadeiro@hotmail.com\Thumbs.db
C:\Program Files\Canon\Canon Setup Utility 2.3\uinstrsc.dll
C:\Program Files\Canon\Canon Setup Utility 2.3\Maint.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\isabel\Bureau\ACTION 1\~WRL0001.tmp
C:\Documents and Settings\isabel\Bureau\info Mr Bloch\Exo\~WRL3828.tmp
Finished
le rappoort clean
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 16/05/2007 a 12:13:29,43
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
tentative de suppression de C:\StubInstaller.exe
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\system32\winspool.dll
*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\MessengerSkinner\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
le rapport navilog
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 16/05/2007 a 12:13:29,43
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
tentative de suppression de C:\StubInstaller.exe
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de C:\WINDOWS\system32\winspool.dll
*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\MessengerSkinner\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport
enfin le rapport hijack
Logfile of HijackThis v1.99.1
Scan saved at 12:26:54, on 16/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
C:\Documents and Settings\christophe\Mes documents\mes logiciels\securité\Nouveau
dossier\aidoroforum.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pornkingmovies.com/%20to%20verify%20your%20age,%20REQUIRED!%20%20%20%
20%20%20%20%20%20%20%20%20%20%20%20WARNING!%20Adult%20pictures%20are%20featured%20in%20this%20site.%
20Only%20adults%20permitted%20beyond%20this%20point!%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20
%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Are%20you%20at%20least
%2018%20years%20old
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program
Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program
Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN
Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN
Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN
Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program
Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [fenaffiche] C:\Program Files\FenAffiche\FenUnika.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers
communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [kipejnp] c:\windows\system32\kipejnp.exe kipejnp
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware
7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat
7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat
7.0\Reader\reader_sl.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab
?1121096465890
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program
Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
(file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PsShutdown (PsShutdownSvc) - Systems Internals - C:\WINDOWS\System32\PSSDNSVC.EXE
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program
Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
encore merci pour ton aide |
|
|
   |
 |
Geek
AidoAntivirus
Messages: 2383
Tutoriaux : 0
|
Posté le:
Jeu 17 Mai 2007 12:36 Sujet : probleme de trojans proxu.horst |
  |
Bonjour
Merci pour les rapports , mais
tu as oublié navilog ... passe-le stp, et poste le rapport.
Fais aussi ceci :
Lance hijackthis et clique sur Do a System Scan Only.
Coche les lignes suivantes, si présentes :
| Citation: | R0 -
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pornkingmovies.com/%20to%20verify%20your%20age,%20REQUIRED!%20%20%20%
20%20%20%20%20%20%20%20%20%20%20%20WARNING!%20Adult%20pictures%20are%20featured%20in%20this%20site.%
20Only%20adults%20permitted%20beyond%20this%20point!%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20
%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Are%20you%20at%20least
%2018%20years%20old
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [kipejnp] c:\windows\system32\kipejnp.exe kipejnp |
Ferme tous les programmes, sauf hijackthis et clique sur Fix
Checked.
Clique sur Démarrer --> Exécuter --> Saisie :
Clique sur Ok pour valider.
- Télécharge DiagHelp de Malekal_morte sur ton bureau :
- Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout.
- Un nouveau dossier chercher va être créé DiagHelp.
- Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître).
- Une fenêtre va s'ouvrir, choisis l'option 1.
- L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche
quand on te le demande.
- Copie/colle le rapport ici
Poste moi le rapport de navilog, celui de diaghelp et un nouveau hijackthis.
Bonne journée  |
|
|
    |
 |
Disquette
Messages: 39
Tutoriaux : 0
|
Posté le:
Jeu 17 Mai 2007 15:27 Sujet : probleme de trojans proxu.horst |
  |
voila deja le rapport navilog je fait le resteSearch Navipromo version 2.0.1 commencé le 17/05/2007
à 15:18:23,23
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
Fix lancé depuis C:\Program Files\navilog1
Mise a jour le 10.05.2007 a 22h00 by IL-MAFIOSO
Executé en mode normal
*** Recherche Programmes installes ***
*** Recherche dossiers dans C:\WINDOWS ***
C:\WINDOWS\msskinner trouvé !
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Recherche dossiers dans C:\Documents and Settings\christophe\Application Data ***
*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
http://www.f-secure.com/blacklight/blacklight_help.html
Fichier(s) caché(s) dans C:\WINDOWS\system32 :
c:\WINDOWS\system32\vrdaszi.dat
C:\windows\system32\vrdaszi.exe
c:\WINDOWS\system32\vrdaszi_nav.dat
c:\WINDOWS\system32\vrdaszi_navps.dat
Processus caché(s) dans C:\WINDOWS\system32 :
C:\windows\system32\vrdaszi.exe
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
C:\WINDOWS\system32\nvs2.inf trouvé !
*** Recherche cles registre ***
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]
Recherche Clé Magic Control
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
*
C:\WINDOWS\system32\kipejnp.dat trouvé !
C:\WINDOWS\system32\vrdaszi.dat trouvé !
**
C:\WINDOWS\system32\kipejnp.dat trouvé !
C:\WINDOWS\system32\vrdaszi.dat trouvé !
***
****
C:\WINDOWS\system32\kipejnp_navps.dat trouvé !
C:\WINDOWS\system32\vrdaszi_navps.dat trouvé !
*****
C:\WINDOWS\system32\kipejnp_nav.dat trouvé !
C:\WINDOWS\system32\vrdaszi_nav.dat trouvé !
C:\WINDOWS\system32\kipejnp_navup.dat trouvé !
C:\WINDOWS\system32\boxqdwuc_navtmp.dat trouvé !
C:\WINDOWS\system32\dqpmfwoyce_navtmp.dat trouvé !
C:\WINDOWS\system32\vsthecbjaq_navtmp.dat trouvé !
******
*******
C:\WINDOWS\system32\miimrp.exe trouvé !
********
C:\WINDOWS\system32\kipejnp.exe trouvé !
C:\WINDOWS\system32\mauagafaf.exe trouvé !
C:\WINDOWS\system32\miimrp.exe trouvé !
C:\WINDOWS\system32\vrdaszi.exe trouvé !
*** Analyse Terminé le 17/05/2007 à 15:23:14,87 *** |
|
|
   |
 |
Disquette
Messages: 39
Tutoriaux : 0
|
Posté le:
Jeu 17 Mai 2007 16:16 Sujet : probleme de trojans proxu.horst |
  |
voila les deux autres rapports .on dirait que zone alarme ne me previent plus toutes les 5 minutes
pour des programme xnijs mais les pubs intempestives type adultfriender betclic navisearh ou
winsoftware sont toujours presentent. merci pour ta patience !!
le rapport dighelpDiagHelp version v1.08.1 - http://www.malekal.com
excute le 17/05/2007 à 16:04:54,32
Liste des fichiers modifies/crees dans les 24 dernieres heures...
C:\WINDOWS
C:\WINDOWS\0.log
C:\WINDOWS\bootstat.dat
C:\WINDOWS\Debug\PASSWD.LOG
C:\WINDOWS\Internet Logs
C:\WINDOWS\Internet Logs\BACKUP.RDB
C:\WINDOWS\Internet Logs\fwdbglog.txt
C:\WINDOWS\Internet Logs\fwpktlog.txt
C:\WINDOWS\Internet Logs\JOSHUA.ldb
C:\WINDOWS\Internet Logs\tvDebug.log
C:\WINDOWS\Internet Logs\ZALog.txt
C:\WINDOWS\SchedLgU.Txt
C:\WINDOWS\system32
C:\WINDOWS\system32\kipejnp.dat
C:\WINDOWS\system32\nvapps.xml
C:\WINDOWS\system32\Restore
C:\WINDOWS\system32\Restore\MachineGuid.txt
C:\WINDOWS\system32\spool\PRINTERS
C:\WINDOWS\system32\vrdaszi.dat
C:\WINDOWS\system32\vrdaszi_navps.dat
C:\WINDOWS\system32\vsconfig.xml
C:\WINDOWS\system32\wpa.dbl
C:\WINDOWS\system32\ZoneLabs\Updates
C:\WINDOWS\system32\ZoneLabs\Updates\LocalCatalog.xml
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Temp
C:\WINDOWS\Temp\Perflib_Perfdata_5a4.dat
C:\WINDOWS\Temp\WGANotify.settings
C:\WINDOWS\Temp\ZLT00724.TMP
C:\WINDOWS\Temp\ZLT00727.TMP
C:\WINDOWS\Temp\_avast4_
C:\WINDOWS\Temp\_avast4_\Webshlock.txt
C:\WINDOWS\wiadebug.log
C:\WINDOWS\wiaservc.log
C:\WINDOWS\WindowsUpdate.log
Liste des derniers fichies modifies/crees dans windir\system32
C:\WINDOWS\System32/drivers\aswmon.sys -->30/04/2007 17:41:55
C:\WINDOWS\System32/drivers\aswmon2.sys -->30/04/2007 17:41:42
C:\WINDOWS\System32/drivers\aswRdr.sys -->30/04/2007 17:39:41
C:\WINDOWS\System32/drivers\aswTdi.sys -->30/04/2007 17:38:51
C:\WINDOWS\System32/drivers\aavmker4.sys -->30/04/2007 17:37:23
C:\WINDOWS\System32/drivers\ntfs.sys -->09/02/2007 13:10:35
C:\WINDOWS\System32/drivers\vaxscsi.sys -->26/10/2006 01:42:21
C:\WINDOWS\System32\vrdaszi_navps.dat -->17/05/2007 16:05:04
C:\WINDOWS\System32\vrdaszi.dat -->17/05/2007 16:04:30
C:\WINDOWS\System32\vsconfig.xml -->17/05/2007 15:40:23
C:\WINDOWS\System32\wpa.dbl -->17/05/2007 15:12:53
C:\WINDOWS\System32\nvapps.xml -->17/05/2007 15:10:49
C:\WINDOWS\System32\kipejnp.dat -->17/05/2007 00:59:56
C:\WINDOWS\System32\perfh00C.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\perfh009.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\perfc00C.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\perfc009.dat -->16/05/2007 12:08:49
C:\WINDOWS\System32\PerfStringBackup.INI -->16/05/2007 12:08:46
C:\WINDOWS\System32\perfh040.dat -->16/05/2007 12:08:45
C:\WINDOWS\System32\perfc040.dat -->16/05/2007 12:08:45
C:\WINDOWS\System32\CONFIG.NT -->13/05/2007 23:25:16
C:\WINDOWS\System32\vrdaszi_nav.dat -->12/05/2007 09:14:51
C:\WINDOWS\System32\kipejnp_navup.dat -->11/05/2007 07:06:11
C:\WINDOWS\System32\d3d9caps.dat -->09/05/2007 12:38:55
C:\WINDOWS\System32\SIntfNT.dll -->08/05/2007 09:58:11
C:\WINDOWS\System32\SIntf32.dll -->08/05/2007 09:58:11
C:\WINDOWS\System32\SIntf16.dll -->08/05/2007 09:58:11
C:\WINDOWS\System32\kipejnp.exe -->02/05/2007 16:28:31
C:\WINDOWS\System32\aswBoot.exe -->30/04/2007 17:46:10
C:\WINDOWS\System32\AVASTSS.scr -->30/04/2007 17:35:28
C:\WINDOWS\System32\MRT.exe -->27/04/2007 22:45:12
C:\WINDOWS\System32\vrdaszi.exe -->26/04/2007 19:02:10
C:\WINDOWS\0.log -->17/05/2007 15:12:01
C:\WINDOWS\WindowsUpdate.log -->17/05/2007 15:11:37
C:\WINDOWS\wiadebug.log -->17/05/2007 15:11:01
C:\WINDOWS\wiaservc.log -->17/05/2007 15:10:59
C:\WINDOWS\bootstat.dat -->17/05/2007 15:10:27
C:\WINDOWS\SchedLgU.Txt -->17/05/2007 12:05:03
C:\WINDOWS\Sti_Trace.log -->16/05/2007 07:48:52
C:\WINDOWS\NeroDigital.ini -->14/05/2007 18:01:56
C:\WINDOWS\win.ini -->23/04/2007 21:43:11
C:\WINDOWS\system.ini -->09/04/2007 10:32:04
C:\WINDOWS\PhotoSnapViewer.INI -->09/03/2007 10:40:46
C:\WINDOWS\zllsputility_loc040c.dll -->09/03/2007 00:03:06
C:\WINDOWS\zllsputility.exe -->09/03/2007 00:02:00
C:\WINDOWS\pack.epk -->14/02/2007 21:20:29
C:\WINDOWS\PowerReg.dat -->10/01/2007 21:41:45
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 8873-867D
Répertoire de C:\WINDOWS\system32
05/08/2004 14:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 121 246 957 568 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 8873-867D
Répertoire de C:\WINDOWS\Downloaded Program Files
08/04/2007 19:53 <REP> .
08/04/2007 19:53 <REP> ..
11/07/2005 15:23 65 desktop.ini
11/12/2006 17:44 367 LegitCheckControl.inf
20/01/2000 15:25 1 162 Microsoft XML Parser for Java.osd
29/06/2005 17:17 227 opuc.inf
09/11/2006 15:36 5 019 swflash.inf
26/05/2005 04:19 291 wuweb.inf
6 fichier(s) 7 131 octets
Total des fichiers listés :
6 fichier(s) 7 131 octets
2 Rép(s) 121 246 957 568 octets libres
Recherche de rootkit! (Merci S!Ri)
infection possible Magic.Control : un scan F-Secure
BlackLight est recommandé
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re
s.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program
Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program
Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program
Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network
Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN
Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN
Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN
Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\41exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\41exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\94exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\94exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\70exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\70exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\14exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\14exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\75exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\75exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\59exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS
~1\\Temp\\59exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\39exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\39exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\86exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\86exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\60exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\60exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\68exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS
~1\\Temp\\68exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\71exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\71exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\26exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\26exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\isabel\\LOCALS~1\\Temp\\0exinjs.a9.exe"="C:\\DOCUME~1\\isabel\\LOCALS~
1\\Temp\\0exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\87exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\87exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\93exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\93exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\53exinjs.a9.exe"="C:\\DOCUME~1\\CHRIST~1\\LO
CALS~1\\Temp\\53exinjs.a9.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program
Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2re
s.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network
Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN
Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN
Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN
Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de
composant"
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-17 16:05:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin
g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\01\27-{C7288C60-5584-BBE3-125E-E007FE577B73}-v1-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin
g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\89\235-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v89-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4044 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin
g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\89\235-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v89-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v235-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin
g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\90\236-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v90-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3864 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\cstromano@hotmail.com\DFSR\Stagin
g\CS{C7288C60-5584-BBE3-125E-E007FE577B73}\90\236-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v90-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v236-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\culture-club@hotmail.fr\DFSR\Stag
ing\CS{EEB87E84-22B3-9CE0-21D7-CE775441081C}\01\10-{EEB87E84-22B3-9CE0-21D7-CE775441081C}-v1-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\01\22-{4D946FF6-8632-DF97-193D-312C18EC36EB}-v1-{B3A57E0D-5
A94-4085-A9BA-13A5DDECC4B9}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8 bytes
hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\11\285-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v11-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5268
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\11\285-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v11-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v285-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 592
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\14\279-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v14-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3810
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\14\279-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v14-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v279-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 440
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\17\280-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v17-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4764
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\17\280-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v17-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v280-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 544
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\20\286-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v20-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4314
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\20\286-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v20-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v286-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 488
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\23\283-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v23-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4098
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\23\283-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v23-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v283-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 464
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\287-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v24-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6456
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\287-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v24-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v287-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 728
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\288-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v24-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3450
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\24\288-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v24-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v288-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 384
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\25\281-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v25-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6060
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\25\281-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v25-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v281-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 648
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\26\282-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v26-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 6222
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\26\282-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v26-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v282-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 688
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\27\299-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1527-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
43176 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\27\299-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1527-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v299-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
4832 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\284-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v28-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4962
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\284-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v28-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v284-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 552
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\295-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1528-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
57252 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\28\295-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1528-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v295-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
6456 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\291-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v29-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 7482
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\291-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v29-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v291-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 816
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\300-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1529-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
14178 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\29\300-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1529-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v300-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
1544 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\34\289-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v34-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5376
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\34\289-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v34-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v289-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 592
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\37\290-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v37-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 4008
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\37\290-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v37-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v290-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 448
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\41\272-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v141-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
19902 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\41\272-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v141-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.2 1488
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\41\272-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v141-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v272-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
2360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\42\142-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v142-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 1380
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\42\142-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v142-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v142-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 152
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\49\294-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v149-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
20100 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\49\294-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v149-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v294-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
2160 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\57\298-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1257-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
21684 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\57\298-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v1257-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v298-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
2408 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\88\293-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v988-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3612
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\88\293-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v988-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v293-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 416
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\91\296-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v91-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 5412
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\91\296-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v91-{B3A57E0D
-5A94-4085-A9BA-13A5DDECC4B9}-v296-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 616
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\92\297-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v992-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1 3774
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\jedelion@hotmail.fr\DFSR\Staging\
CS{4D946FF6-8632-DF97-193D-312C18EC36EB}\92\297-{D8FC3D3D-CD4F-4608-B6A0-BC4BED5EAD00}-v992-{B3A57E0
D-5A94-4085-A9BA-13A5DDECC4B9}-v297-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 416
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\01\85-{000328E1-717F-0640-4E54-0927C781472A}-v1-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v85-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\06\32-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v106-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4152 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\06\32-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v106-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v32-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\07\11-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v107-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4764 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\07\11-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v107-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
536 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\08\12-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v108-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3234 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\08\12-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v108-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\09\19-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v109-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\09\19-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v109-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v19-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
368 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\10\20-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v110-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
2802 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\10\20-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v110-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v20-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
312 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\11\21-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v111-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
2532 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\11\21-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v111-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v21-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
280 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\12\22-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v112-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3990 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\12\22-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v112-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v22-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
456 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\13\13-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v113-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3810 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\13\13-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v113-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v13-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
432 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\14\23-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v114-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3306 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\14\23-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v114-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v23-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
368 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\15\24-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v115-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
6618 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\15\24-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v115-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v24-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
728 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\16\25-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v116-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4728 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\16\25-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v116-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v25-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
528 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\17\33-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v117-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
5664 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\17\33-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v117-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v33-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
624 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\18\26-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v118-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
6690 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\18\26-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v118-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v26-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
752 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\19\14-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v119-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
5286 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\19\14-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v119-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v14-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
600 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\20\28-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v120-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
6492 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\20\28-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v120-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v28-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
736 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\21\27-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v121-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
7968 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\21\27-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v121-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v27-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
872 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\22\15-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v122-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
5412 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\22\15-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v122-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v15-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
616 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\23\29-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v123-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
8832 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\23\29-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v123-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v29-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
976 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\24\31-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v124-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4260 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\24\31-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v124-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v31-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
464 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\25\16-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v125-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
6636 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\25\16-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v125-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v16-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
752 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\26\17-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v126-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
5718 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\26\17-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v126-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v17-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
648 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\27\34-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v127-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
5394 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\27\34-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v127-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v34-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
592 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\28\35-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v128-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
7194 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\28\35-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v128-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v35-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
800 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\29\18-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v129-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4206 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\29\18-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v129-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v18-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
472 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\30\36-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v130-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
7950 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\30\36-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v130-{8F4D
6544-DDCA-41AB-A35C-6CA4AFC94F15}-v36-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
872 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\86\30-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v86-{8F4D6
544-DDCA-41AB-A35C-6CA4AFC94F15}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
6492 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\petitepuuce@hotmail.com\DFSR\Stag
ing\CS{000328E1-717F-0640-4E54-0927C781472A}\86\30-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v86-{8F4D6
544-DDCA-41AB-A35C-6CA4AFC94F15}-v30-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
696 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\01\11-{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}-v1-{B3A57E
0D-5A94-4085-A9BA-13A5DDECC4B9}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS 8
bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\54\54-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4152 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\54\54-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
440 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\55\55-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
4764 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\55\55-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
536 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\56\56-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3234 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\56\56-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\57\57-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
3360 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\57\57-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
368 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\58\58-{B3A57E0D-5A94-4085-A9BA-13A5DDECC4B9}-v58-{B3A57
E0D-5A94-4085-A9BA-13A5DDECC4B9}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.rdc.1
2802 bytes hidden from API
C:\Documents and Settings\isabel\Local Settings\Application
Data\Microsoft\Messenger\isabel.cerrino@hotmail.fr\SharingMetadata\rodrigo.roda@hotmail.fr\DFSR\Stag
ing\CS{AF0B5E1A-22E0-40D3-5C43-4046B469B7A5}\58\58-{B3A57E0D | | | |