ComboFix 08-07-26.1 - saad 2008-07-27 19:01:49.1 - [color=red][b]FAT32
/b/colorx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.171 [GMT 2:00]
Endroit: D:\down\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Reset Cursor.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Weather.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Zango Customer Support Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Zango Games!.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Zango Library.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Zango Screensavers!.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Zango Uninstall Instructions.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Zango\Zango Videos!.lnk
C:\Documents and Settings\saad\Application Data\WeatherDPA
C:\Documents and Settings\saad\Application Data\WeatherDPA\Weather\WeatherStartup.xml
C:\Documents and Settings\saad\Application Data\Zango
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte10_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte11_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte12_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte13_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte14_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte19_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte20_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte21_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30104_emte9_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u30203lib_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102angel_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102bigluf_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102bigsmile_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102birthday_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102cheers_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102flo_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102good_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102jump_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102king_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102lough_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102luf_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102smile_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102smiled_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102sor_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102thanx_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u33102uhu_1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u40103ahh_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u40103wow_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u40104_emi2_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u42102_1134_112_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u50103big_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u50103gig_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u50103hm_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u50103nomail_emoti_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u50103norm_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema15_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema16_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema17_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema18_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema19_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema20_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema21_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema24_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema25_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema26_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema30_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema33_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u60104_ema34_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u62802hippi_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u62802jumpie_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u80402argh_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u80402oops_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u80402ouch_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u82502no_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\[u]0
/u82502yes_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_boring1_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_confused_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_crying_ugly_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_fantastic_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_feel_better_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_gimme_break_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_heehee_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_hlopaet_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_ign_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_lol_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_no_comment_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_peace_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_smashing_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\110103_talk2thehand_prv.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\avatar.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\block_sm.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\block_sm2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\block_smli.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\block_smli2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\blocked.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\blocked2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_add-but.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_back-but.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_left_cut_enabled_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_left_enabled_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_left_pressed_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_middle_enabled_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_middle_pressed_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_right_cut_enabled_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_right_enabled_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\btn_right_pressed_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\business_promo.htm
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\buttondir.txt
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\components.cdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\css_cattree.css
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\css_flashpreview.css
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\css2_main.css
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\css2_pagingmodule.css
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\css2_topbuttons.css
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\cursors.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\delete.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\edit_clear_sound.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\edit_fs.htm
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\edit_select.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-543450.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-589306.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-591943.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-592579.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-598579.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-603763.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-9696.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-511745-514279.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-backgrounds.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-bcards.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-ecards.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-emoticons.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-estationery.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-funny.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-help.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-images.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-info.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-more.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-my.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-new.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-new2.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-options.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-people.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-photo.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-tell.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-temp.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-text.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-voice.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-def.cdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-premium-email-premium.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-t1-bg.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\email-temp-bg.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\estatationery.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\flashpatch.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\flashpreview.htm
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\fs3.htm
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\hotbar_promo.htm
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_checked_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_close_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_close_pressed_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_edit_preview.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_edit_send.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_flash_preview.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_recently_used.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_remove_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_remove_pressed_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_sand-clock2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_tell_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_tell_pressed_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_tree_null.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_unchecked_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\icon_unchecked_pressed_1.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout4.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\img_corner_left.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\img_local_logo.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_basetemplate.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_hbgroups.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_hbobject3.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_hbobjectset3.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_hotbarwrapper.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_iteratorsandreaders3nf.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_pagingmoduleobj3.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_texts3.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\js2_xmltree3nf.js
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\layout.cdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\linkpathlegal.txt
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\n.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\nav_b_2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\nav_bb_2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\nav_f_2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\nav_ff_2.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\progress.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\sales_buttons.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\searchbtn.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\submit.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_bg.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_bga.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_bgia.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_l.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_la.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_lia.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_r.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_ra.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tab_ria.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tree_dots.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tree_minus.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\tree_plus.gif
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\treedata_animations.xml
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\treedata_backgrounds.xml
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\treedata_ecards.xml
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\treedata_emoticons.xml
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\treedata_notifiers.xml
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\treedata_text.xml
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\1\zango_btn.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\avatar.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\business_promo.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\buttondir.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\code.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\cursors.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-def.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-temp-bg.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\hotbar_promo.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\images.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\layout.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\localcontent.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\progress.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\treexml.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\HostWD\static\DownLoad\zango_btn.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\1383356.sdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\2884334.sdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\3340762.sdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\3786291.sdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\877979.sdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\domains.txt
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\141199
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\27503
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\34123
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\427075
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\52335
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\63492
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\65770
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\738022
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\753300
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\753309
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\753363
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\82292
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\93899
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\dynamic\ustat\3705.dat
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\avatar.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\btntrans.idx
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\btntrans1.dat
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\buttondir.txt
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\components.cdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\cursors.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_1000.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_2000.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_3000.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_bar.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_bbar1.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_logos.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_other.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\d_icons_weather.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\default.cdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_511745-514279.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-ca.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-us.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_categorize.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_comparison.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_explorer-Mails.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_explorer-people.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_favorites.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_Games.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_Hide.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_hotbarcom.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_Hotmail.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_hsskin.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_jemster.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_jemsterie.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_jemsteruk.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_jobsearch.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_Mails.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_MobileSidewalk.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_new.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_premium.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_reun.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_ringtones.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_searchfor.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_searchgo.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_weather.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Default_yellowpages.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\editblbuttons.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\email-def-511724-548964.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\email-def-511724-9595.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\email-t1-bg.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\icons2.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\ie_games_icon.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\ie_video.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\keywords.idx
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\keywords1.dat
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\layout.cdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\linkpathlegal.txt
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\progress.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\s_icons_buttons.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\sales_buttons.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\sdfmodifier.xml
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\t2_bg.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\theweb.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\top7.cdf
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\Top7_theweb.mnu
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\tsd_bg.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\zango_btn.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\2\zango_ie_menu.res
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\avatar.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\buttondir.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\cursors.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\default.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\icons2.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_video.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords1.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\layout.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\progress.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\top7.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip
C:\Documents and Settings\saad\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip
C:\Program Files\newdotnet
C:\Program Files\newdotnet\readme.html
C:\Program Files\newdotnet\uninstall.exe
C:\Program Files\zango
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NNSERV
-------\Service_NNServ
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-27 to 2008-07-27 ))))))))))))))))))))))))))))))))))))
.
2008-07-27 16:57 . 2008-07-27 16:57 <REP> d-------- C:\Documents and Settings\saad\Application Data\Malwarebytes
2008-07-27 16:56 . 2008-07-27 16:56 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-27 16:56 . 2008-07-27 16:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-27 16:56 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-27 16:56 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-27 13:18 . 2008-07-27 13:18 <REP> d-------- C:\Program Files\Alwil Software
2008-07-27 00:45 . 2008-07-27 00:45 <REP> d-------- C:\Documents and Settings\saad\Application Data\Grisoft
2008-07-27 00:45 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-07-27 00:34 . 2008-07-27 00:34 <REP> dr-h----- C:\$VAULT$.AVG
2008-07-26 03:22 . 2008-07-26 03:22 <REP> d-------- C:\Program Files\Zealot Software
2008-07-26 03:22 . 2003-05-22 13:27 620,094 --a------ C:\WINDOWS\system32\divx.dll
2008-07-26 03:22 . 2001-08-18 20:00 262,144 --a------ C:\WINDOWS\system32\mpg4ds32.axu
2008-07-26 03:22 . 2004-02-26 02:08 236,544 --a------ C:\WINDOWS\system32\divxdec.ax
2008-07-26 03:22 . 2004-04-05 13:36 217,088 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-07-26 03:22 . 2003-08-19 15:20 180,224 --a------ C:\WINDOWS\system32\ac3filter.ax
2008-07-26 03:22 . 2000-06-30 17:40 139,264 --a------ C:\WINDOWS\system32\Mpeg2Decoder.ax
2008-07-26 03:22 . 2004-02-10 19:15 128,512 --a------ C:\WINDOWS\system32\xvid.dll
2008-07-26 03:22 . 2000-06-26 13:13 94,208 --a------ C:\WINDOWS\system32\Mpeg2Parser.ax
2008-07-26 03:22 . 2004-04-05 13:46 61,440 --a------ C:\WINDOWS\system32\xvid.ax
2008-07-26 02:37 . 2008-07-26 02:38 <REP> d-------- C:\Program Files\MKVTOAVI
2008-07-24 09:49 . 2008-07-24 09:49 <REP> d--hs---- C:\FOUND.020
2008-07-24 00:31 . 2008-07-24 00:31 <REP> d--hs---- C:\FOUND.019
2008-07-23 11:46 . 2008-07-23 11:46 <REP> d-------- C:\Program Files\Matroska Pack
2008-07-23 03:56 . 2008-07-23 03:57 <REP> d-------- C:\Program Files\Haali
2008-07-20 15:52 . 2008-07-20 15:52 <REP> d--hs---- C:\FOUND.018
2008-07-20 01:21 . 2008-07-20 01:21 <REP> d-------- C:\WINDOWS\Sun
2008-07-19 21:48 . 2008-07-19 21:48 <REP> d--hs---- C:\FOUND.017
2008-07-19 15:01 . 2008-07-19 15:01 <REP> d-------- C:\Program Files\uTorrent
2008-07-19 15:01 . 2008-07-19 15:01 <REP> d-------- C:\Documents and Settings\saad\Application Data\uTorrent
2008-07-18 13:02 . 2008-07-18 13:03 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-07-17 20:48 . 2008-07-17 20:48 <REP> d--hs---- C:\FOUND.016
2008-07-17 20:46 . 2008-07-17 20:46 268 --ah----- C:\sqmdata18.sqm
2008-07-17 20:46 . 2008-07-17 20:46 244 --ah----- C:\sqmnoopt18.sqm
2008-07-17 20:09 . 2008-07-17 20:09 <REP> d--hs---- C:\FOUND.015
2008-07-17 12:51 . 2008-07-17 12:51 <REP> d--hs---- C:\FOUND.013
2008-07-17 12:46 . 2008-07-17 12:46 <REP> d--hs---- C:\FOUND.012
2008-07-17 12:00 . 2008-07-17 12:00 <REP> d--hs---- C:\Documents and Settings\LocalService
2008-07-17 11:59 . 2008-07-17 11:59 <REP> d--hs---- C:\FOUND.011
2008-07-17 09:37 . 2008-07-17 09:37 <REP> d--hs---- C:\FOUND.010
2008-07-14 13:53 . 2008-07-14 13:53 <REP> d--hs---- C:\FOUND.009
2008-07-13 15:22 . 2008-07-13 15:22 <REP> d--hs---- C:\FOUND.008
2008-07-11 17:30 . 2008-07-11 17:30 <REP> d-------- C:\Documents and Settings\saad\Application Data\dvdcss
2008-07-10 21:46 . 2008-07-10 21:46 <REP> d--hs---- C:\FOUND.007
2008-07-10 13:21 . 2008-07-10 13:21 <REP> d-------- C:\Documents and Settings\saad\Application Data\Nokia Multimedia Player
2008-07-10 00:17 . 2008-07-10 00:17 <REP> d--hs---- C:\FOUND.006
2008-07-09 19:04 . 2008-07-09 19:04 <REP> d--hs---- C:\FOUND.005
2008-07-08 19:21 . 2008-07-08 19:21 <REP> d--hs---- C:\FOUND.004
2008-07-06 19:12 . 2008-07-06 19:12 <REP> d-------- C:\Program Files\RelevantKnowledge
2008-07-06 19:11 . 2008-07-06 19:11 <REP> d-------- C:\temp\rk
2008-07-06 19:11 . 2008-07-06 19:11 <REP> d-------- C:\temp
2008-07-05 20:00 . 2008-07-05 20:00 <REP> d--hs---- C:\FOUND.003
2008-07-03 20:34 . 2008-07-03 20:34 268 --ah----- C:\sqmdata15.sqm
2008-07-03 20:34 . 2008-07-03 20:34 244 --ah----- C:\sqmnoopt15.sqm
2008-07-02 03:02 . 2008-07-02 03:02 268 --ah----- C:\sqmdata14.sqm
2008-07-02 03:02 . 2008-07-02 03:02 244 --ah----- C:\sqmnoopt14.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 19:51 --------- d-----w C:\Program Files\iTunes
2008-06-25 19:51 --------- d-----w C:\Program Files\iPod
2008-06-25 19:46 --------- d-----w C:\Program Files\Apple Software Update
2008-06-25 19:45 --------- d-----w C:\Program Files\Fichiers communs\Apple
2008-06-25 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-17 15:44 --------- d-----w C:\Program Files\Real
2008-06-17 15:44 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-01 07:29 --------- d-----w C:\Program Files\Sun
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:15 1,293,824 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-05 03:26 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2008-04-30 18:00 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2008-04-30 17:51 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-04-30 17:51 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
.
------- Sigcheck -------
2006-03-09 08:25 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:09 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-21 22:57 171448]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-07-19 15:01 219952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-05-01 14:40 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-07-18 13:01 185896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-30 20:20 219136]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoStrCmpLogical"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"DisablePagingExecutive"=dword:00000001
"SecondLevelDataCache"=dword:00000200
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Emule Lite\\Emule.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\DAP\\DAP.EXE"=
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 19:20]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 19:55]
S3 USBSER34;USBSER34;C:\WINDOWS\system32\Drivers\USBSER34.SYS [2005-12-27 18:00]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-07-25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - s!N:C:\Program Files\Apple Software Update\SoftwareUpdate.exe-taskSYSTEM0 []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-saap - c:\program files\emule lite\saap.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.menara.ma/
O8 -: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 -: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 -: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O18 -: Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~1\DAP\dapie.dll
O18 -: Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~1\DAP\dapie.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-27 19:13:54
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\FICHIERS COMMUNS\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGUPSVC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE
C:\PROGRAM FILES\FICHIERS COMMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Menara\dslmon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-27 19:18:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-27 17:17:54
Pre-Run: 1,013,923,840 octets libres
Post-Run: 1,195,638,784 octets libres
562 --- E O F --- 2008-07-27 13:47:06