Bonjour,
Je viens de faire un scan complet avec Malwarebytes' Anti-Malware. Il y avait 10 infections... Quelqu'un peut-il me dire ce que je dois faire maintenant ?
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3668
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
31/01/2010 18:17:43
mbam-log-2010-01-31 (18-17-43).txt
Type de recherche: Examen complet (C:\|D:\|F:\|G:\|H:\|I:\|)
Eléments examinés: 389195
Temps écoulé: 1 hour(s), 0 minute(s), 53 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 7
Processus mémoire infecté(s):
C:\Users\Croûtons\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe (Rogue.Eorezo) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\softwarehelper (Rogue.Eorezo) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Users\Croûtons\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
C:\32788R22FWJFW\pv.com (Adware.Swizzor) -> Quarantined and deleted successfully.
C:\Program Files (x86)\EduCle-Eleve\Apps\Bureautique\OOoP\OpenOfficePortable\App\openoffice\URE\bin\unicows.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files (x86)\EduCle-Eleve\Apps\Developper\KompoZerPortable\App\kompozer\msvcr70.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files (x86)\EduCle-Eleve\Apps\Image\BlenderPortable\App\Blender\msvcp90.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Program Files (x86)\EduCle-Eleve\Apps\Son\PortableCDex\CDex\unicows.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Croûtons\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdate.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.


Bien : je suis sous Windows 7, 64 bits et mon pc est infecté par EOREZO.
Je suis en train de faire le scan avec List_Kill'em.
User : Croûtons (Administrateurs)
Update on 29/01/2010 by g3n-h@ckm@n ::::: 11:50
Start at: 18:55:21 | 31/01/2010
Contact : g3n-h@ckm@n sur CCM
Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz
Microsoft Windows 7 Édition Familiale Premium (6.1.7600 64-bit) #
Internet Explorer 8.0.7600.16385
Windows Firewall Status : Disabled
C:\ -> Disque fixe local | 455,92 Go (398,03 Go free) [ACER] | NTFS
D:\ -> Disque fixe local | 457,09 Go (449,19 Go free) [DATA] | NTFS
F:\ -> Disque CD-ROM
G:\ -> Disque amovible
H:\ -> Disque amovible
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files (x86)\a-squared Free\a2service.exe
C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\IncrediMail\bin\IncMail.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Users\Croûtons\AppData\Local\Clavier+\Clavier.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Creative\Shared Files\CamTray.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\PC Tools Firewall Plus\FWService.exe
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
C:\Program Files (x86)\Seagate\Sync\SeaSyncServices.exe
C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe
C:\PROGRA~2\Bandoo\Bandoo.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files (x86)\IncrediMail\bin\IMApp.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\List_Kill'em\List_Kill'em.scr
C:\Windows\SysWOW64\cmd.exe
C:\Users\Croûtons\AppData\Local\Temp\DA28.tmp\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
IncrediMail REG_SZ C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
Clavier+ REG_SZ C:\Users\Croûtons\AppData\Local\Clavier+\Clavier.exe
SpywareTerminatorUpdate REG_SZ "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
Creative WebCam Tray REG_SZ "C:\Program Files (x86)\Creative\Shared Files\CamTray.exe"
Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
SUPERAntiSpyware REG_SZ C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
swg REG_SZ "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Babylon Client REG_SZ "C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe" -AutoStart
PCMMediaSharing REG_SZ "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
SiteVacuum REG_SZ "C:\Program Files (x86)\EasySearch\SiteVacuumClient.exe"
Creative WebCam Tray REG_SZ C:\Program Files (x86)\Creative\Shared Files\CAMTRAY.EXE
avgnt REG_SZ "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
SunJavaUpdateSched REG_SZ "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
00PCTFW REG_SZ "C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe" -s
Adobe Reader Speed Launcher REG_SZ "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
ConsentPromptBehaviorAdmin REG_DWORD 0 (0x0)
ConsentPromptBehaviorUser REG_DWORD 3 (0x3)
EnableInstallerDetection REG_DWORD 1 (0x1)
EnableLUA REG_DWORD 0 (0x0)
EnableSecureUIAPaths REG_DWORD 1 (0x1)
EnableUIADesktopToggle REG_DWORD 0 (0x0)
EnableVirtualization REG_DWORD 1 (0x1)
PromptOnSecureDesktop REG_DWORD 0 (0x0)
ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
scforceoption REG_DWORD 0 (0x0)
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
FilterAdministratorToken REG_DWORD 0 (0x0)
legalnoticetext REG_SZ
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoActiveDesktop REG_DWORD 1 (0x1)
ForceActiveDesktopOn REG_DWORD 0 (0x0)
BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ c:\progra~2\google\google~1\go36f4~1.dll c:\progra~2\bandoo\bndhook.dll
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
===============
ActivX controls
===============
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
===============
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
==============
BHO :
======
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}]
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ http://www.google.fr/
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3
EapHost : 0x3
Wlansvc : 0x3
SharedAccess : 0x4
windefend : 0x2
wuauserv : 0x2
wscsvc : 0x2
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Users\Croûtons\AppData\Local\Temp\DA28.tmp
## C:\> hashdeep C:\Windows\Sysnative\Drivers\atapi.sys
##
24128,02062c0b390b7729edc9e69c680a6f3c,0261683c6dc2706dce491a1cdc954ac9c9e649376ec30760bb4e225e18dc5273,C:\Windows\Sysnative\Drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Users\Croûtons\AppData\Local\Temp\DA28.tmp
## C:\> hashdeep C:\Windows\Sysnative\Drivers\atapi.sys
##
24128,02062c0b390b7729edc9e69c680a6f3c,0261683c6dc2706dce491a1cdc954ac9c9e649376ec30760bb4e225e18dc5273,C:\Windows\Sysnative\Drivers\atapi.sys
Sources
=======
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
Référence :
==========
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
=======
Drive :
=======
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\Windows\system32\XInput9_1_0.dll
Present !! : C:\Windows\SysWow64\XInput9_1_0.dll
Present !! : C:\Windows\Sysnative\XInput9_1_0.dll
Present !! : C:\Windows\winstart.bat
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKCU\SOFTWARE\EoRezo
Present !! : HKCU\SOFTWARE\FunkyEmoticons
Present !! : HKLM\SOFTWARE\FunkyEmoticons
Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
============
driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-31 19:04:52
Windows 6.1.7600 WOW64 NTFS
detected NTDLL code modification:
ZwEnumerateKey 0 != 47, ZwQueryKey 0 != 19, ZwOpenKey 0 != 15, ZwClose 0 != 12, ZwEnumerateValueKey 0 != 16, ZwQueryValueKey 0 != 20, ZwOpenFile 0 != 48, ZwQueryDirectoryFile 0 != 50, ZwQuerySystemInformation 0 != 51Initialization error
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: error reading MBR
==========
Programs
==========
2BrightSparks
7-Zip
7x8
A Note
a-squared Free
Acer
Acer Arcade Live
Acer GameZone
Acer Incorporated
Adobe
adslTV
Agfa
AGFAnet
Ahead
Aide mémoire
Apollo DVD Copy
Apple Software Update
Aspell
ATI Technologies
ATnotes
Avira
AXPDF
Babylon
Bandoo
Bonjour
Brother
Brownie
Calme 2010
Capturino V2
Capturino V21
Carambis
CCleaner
Cobian Backup 9
CodeStuff
Common Files
Creative
CyberLink
DAEMON Tools Lite
desktop.ini
DICCIONARIO CLAVE
directx
DRAE
Driver-Soft
DUE
DVD Shrink
DVDFab 6
EasyPHP 3.0
EasySearch
EduCle-Eleve
Emoticon
eMule
ESET
eSobi
ESTsoft
ExperimentalScene
FileHippo.com
Files-Destructor
FileZilla FTP Client
Folding@home
Foreignword
Free Download Manager
Free PDF to Word Doc Converter
GIMP-2.0
Glary Undelete
Glary Utilities
Google
GooglePlusVideos
GraphCalc
greenstreet
Groobax
Hercules
ICEOWS
iKoneStudio
Iminent
IncrediMail
InstallShield Installation Information
Internet Explorer
Intuisphere
IZArc
Java
JCA2000
JRE
Kalender
KaraFun
KC Softwares
Kellogg's Arctique
KirysTech2k
Kyodai Mahjongg
Kyodai Mahjongg 2006
La Science Interactive
Larousse
Lavasoft
Le Robert
Linguae
List_Kill'em
Macromedia
Malwarebytes' Anti-Malware
Microsoft
Microsoft AntiSpyware
Microsoft Office
Microsoft Office XP
Microsoft SQL Server Compact Edition
Microsoft Visual Studio
Microsoft Works
Mozilla Firefox
Mozilla Firefox 3.6 Beta 1
Mozilla Thunderbird
MSBuild
MSECache
MSXML 4.0
Nero
NewTech Infosystems
OpenOffice.org 3
Opera
Panda Security
PC Drivers HeadQuarters
PC Tools Firewall Plus
PDFCreator
Photo to Sketch Pro
PhotoFiltre
PhotoMail Maker
Pixia
Planeta DeAgostini Interactive
Power Soft
Q-Dir
QuickTime
RapidTyping
ratDVD
Realtek
Reference Assemblies
Registry Mechanic
RogueRemover FREE
Roxio
SafeSoft
Seagate
sgel
Smallvideosoft
SnapScan
Spybot - Search & Destroy
Spyware Doctor
Spyware Terminator
SUPERAntiSpyware
Supercow
Supercow Deluxe
ToupicLabels
Traduce Gratis
trend micro
TuneUp Utilities 2007
UltimateZip
Ultralingua
Uninstall Information
Universal Extractor
Unlocker
uTorrent
VideoLAN
VirusTotalUploader2
Visicom Media
VS Revo Group
VSO
WinAVI Video Capture
Windows Calendar
Windows Collaboration
Windows Defender
Windows Live
Windows Live SkyDrive
Windows Mail
Windows Media Player
Windows NT
Windows Photo Gallery
Windows Photo Viewer
Windows Portable Devices
Windows Sidebar
WinRAR
XDTK
Xenocode
XnView
Yahoo!
zabkat
Zero G Registry
ZikiTranslator
============
Drive C:
============
!conMania Collection
$INPLACE.~TR
$RECYCLE.BIN
$WINDOWS.~Q
32788R22FWJFW
32788R22FWJFW(0)
aaw7boot.log
ACER
ACERSW
Book
Boot
bootmgr
BOOTSECT.BAK
Bug.txt
CtDrvIns.log
CtDrvStp.log
DICT31S
Documents and Settings
Erunt
FyK
hiberfil.sys
Kill'em
List'em.txt
Media
OEM
orange.bmp
pagefile.sys
PCStreet
PerfLogs
Player.ini
Program Files
Program Files (x86)
ProgramData
Recovery
RHDSetup.log
ST_Fix
System Volume Information
tmp
Transfert de fichiers et paramètres Windows - Éléments de l’ancien ordinateur.MIG
UAC
Users
VueScan
Wamp
WCThumb.tmb
WebCam
WebCamNX
Windows
ZHPExportRegistry-02-01-2010-20-31-19.txt
ZHPExportRegistry-03-01-2010-22-24-03.txt
¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials
C:\ACER\Preload\PatchLog
C:\ACER\Preload\PatchLog\CodeTracer
C:\ACER\Preload\PatchLog\DecompressFM2009-04-16 08-31-52.log
C:\ACER\Preload\PatchLog\PAP01I4164000004.csv
C:\ACER\Preload\PatchLog\CodeTracer\CodeTracer2009-04-16 08-31-19.log
C:\Program Files (x86)\EduCle-Eleve\Apps\Image\GIMPPortable\App\gimp\share\gimp\2.0\gimpressionist\Presets\Patchwork
C:\Program Files (x86)\EduCle-Eleve\Apps\Image\GIMPPortable\App\gimp\share\gimp\2.0\patterns\cracked.pat
C:\Program Files (x86)\EduCle-Eleve\Apps\Image\PortableInkScape\inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.py
C:\Program Files (x86)\EduCle-Eleve\Apps\Image\PortableInkScape\inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.pyc
C:\Program Files (x86)\EduCle-Eleve\Apps\Image\PortableInkScape\inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.pyo
C:\Program Files (x86)\GIMP-2.0\share\gimp\2.0\gimpressionist\Presets\Patchwork
C:\Program Files (x86)\GIMP-2.0\share\gimp\2.0\patterns\cracked.pat
C:\Users\Croûtons\Documents\MegaMario_v1.6c_full\data\gfx\bonus\cracked.PNG
C:\Users\Croûtons\Documents\MegaMario_v1.6c_full\data\gfx\bonus\cracked2.PNG
C:\Users\Croûtons\Documents\MegaMario_v1.6c_full\data\gfx\bonus\crackedlong.PNG
C:\Users\Croûtons\Documents\MegaMario_v1.6c_full\data\gfx\bonus\crackstone.png
C:\Users\Croûtons\Documents\MegaMario_v1.6c_full\data\gfx\bonus\crackstone2.png
C:\Users\Croûtons\Documents\MegaMario_v1.6c_full\data\sfx\crack.wav
C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\Install.exe
C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\Install.exe.manifest
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤