

yugm
Membres-
Compteur de contenus
61 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par yugm
-
Bjr A priori l'adresse du site est bonne car ds mes favoris depuis longtemps et je suis inscrit à ce site pour consultations journalières de portefeuilles virtuels en bourse.Mon principal souci est de retrouver ces portefeuilles avec la même adresse sans avoir cette erreur 404 qui me bloque tout . Pas de problèmes pour l'instant avec d'autres sites par Google chrome Merci pour une solution guy
-
Bonjour, Je voudrais savoir comment me débarrasser de ce message « erreur 404 » quand je demande à consulter un site. Ex.: les échos Merci de la réponse. Guy
-
Bjr vieu bison boiteu Si possible une précision concernant ce retroéclairage défectueux :Dans la mesure où l'ecran s'éclaire quand même normalement qques 10emes de secondes au départ et ensuite par appui sur Fn+F6 ,est-ce hard ou soft ??? et l'inverter va t-il me dépanner ?Merci encore de ton attention
-
Bjr à tous .Depuis qques jours je n'ai plus d'écran lisible sur mon portable (acer aspire 8920g ,winsow 7, 64 bits)et suis donc sur écran complementaire de télé par liaison HDMI .Impossible pour moi de rétablir cet écran (seulement en 10eme de seconde au démarrage et par appui sur touche Fn+F6) .Pas de résultat non plus avec restauration sur date antérieure .Merci pour le conseil
-
Merci Tonton de ta réponse mais elle ne correspond pas à mon problème car c'est ce que je fais à chaque fois et j'ai bien la confirmation d'une installation réussie .Aprés arrêt de mon pc ,je dois recommencer le téléchargement;as-tu d'autres propositions ?(serai absent ce soir pour 8 jours)
-
BJR Je suis en I E 64 bits en Windows 7 avec Orange et à chaque jour pour une demande d'infos vidéo il me faut recharger le flash player.j'arrête le pc tous les soirs et le lendemain au démarrage il a disparu .Pourquoi ?????.Merci d'une réponse (PC portable =ACER type Aspire 8920G)
-
Sauvegarde sur DD externe non reconnue par Vista
yugm a répondu à un(e) sujet de yugm dans Optimisation, Trucs & Astuces
merci Tonton de la réponse mais le nti ne reconnait pas mes sauvegardes ou trouve fichiers endommagés Je crois que je vais en faire mon deuil Merci encore et peut-être à + tard Salut -
Sauvegarde sur DD externe non reconnue par Vista
yugm a posté un sujet dans Optimisation, Trucs & Astuces
Bonjour j'ai donc ce disque dur externe Memup (MEDIADISK LX SERIES)qui me sauvegarde journellement et après un gros probleme du DD de mon PC ,voulant lire cette sauvegarde Vista ne reconnait pas ces fichiers type NBF.Merci de m'indiquer comment m'en sortir -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bonjour lance_yien Depuis maintenant 3 jours ,je suis sur Avast à nouveau et je n'ai plus de messages me coupant la liaison Internet (raison de mon 1er problème),ni les avertissements de chez Avira.Donc tout va bien et on en reste là. Merci encore -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bonjour Ce que je voulais dire ,c'est que j'ai l'impression de tourner en rond depuis que j'ai pris l'AV d'Avira en place d'Avast Sur le dernier point,chaque ligne est un fichier vide et donc pas de scan par Jotti (no file uploaded)et il m'a fallu désactiver Avira pour y accéder Quel est ton avis sur retour à Avast? A+ -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bjr A priori ,rien de changer. Vu pour Reader .Voici le rapport Je reviendrai sans doute sur AV d'Avast en espérant mieux Merci quand même pour ta disponibilité OTL logfile created on: 10/05/2011 12:11:59 - Run 2 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\guy\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19048) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 77,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,44 Gb Total Space | 62,13 Gb Free Space | 55,75% Space Free | Partition Type: NTFS Drive D: | 104,90 Gb Total Space | 76,34 Gb Free Space | 72,77% Space Free | Partition Type: NTFS Drive F: | 465,76 Gb Total Space | 269,61 Gb Free Space | 57,89% Space Free | Partition Type: NTFS Drive G: | 3,76 Gb Total Space | 3,76 Gb Free Space | 100,00% Space Free | Partition Type: FAT32 Computer Name: PC-DE-GUY | User Name: YUG | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011/05/09 10:24:56 | 000,204,800 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\guy\AppData\Local\Temp\RtkBtMnt.exe PRC - [2011/05/08 12:03:03 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\guy\Desktop\OTL.exe PRC - [2011/04/29 13:05:06 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2011/04/29 13:05:05 | 000,442,024 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avscan.exe PRC - [2011/04/07 09:00:03 | 000,235,168 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10o_ActiveX.exe PRC - [2011/03/04 14:38:18 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2011/03/04 14:38:17 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2010/08/24 11:38:18 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe PRC - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe PRC - [2010/01/14 21:11:14 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2009/11/18 20:41:12 | 000,206,120 | ---- | M] (CyberLink) -- C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe PRC - [2009/09/21 15:02:04 | 003,786,472 | ---- | M] () -- C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe PRC - [2009/09/21 15:02:00 | 003,451,904 | ---- | M] (Arachnoid Biometrics Identification Group Corp.) -- C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe PRC - [2009/09/21 15:01:50 | 003,488,768 | ---- | M] () -- C:\Program Files\Acer\Acer Bio Protection\BASVC.exe PRC - [2009/09/21 15:01:41 | 003,673,600 | ---- | M] (Arachnoid Biometrics Identification Group Corp.) -- C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe PRC - [2009/05/20 20:18:32 | 000,075,048 | ---- | M] () -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe PRC - [2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009/04/11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2008/04/28 13:18:26 | 000,809,480 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe PRC - [2008/04/27 22:26:44 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) -- C:\Windows\System32\vfsFPService.exe PRC - [2008/03/21 13:22:52 | 000,024,576 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe PRC - [2008/03/11 11:53:54 | 005,296,128 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2008/03/07 04:36:12 | 000,544,768 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe PRC - [2008/03/05 11:56:30 | 001,216,512 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\AcerVCM.exe PRC - [2008/03/05 00:38:34 | 000,500,784 | ---- | M] (Egis Incorporated) -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe PRC - [2008/01/21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2008/01/10 17:03:00 | 000,233,472 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\RS_Service.exe PRC - [2007/12/11 05:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe PRC - [2007/12/06 17:15:28 | 000,110,592 | ---- | M] () -- C:\ACER\Mobility Center\MobilityService.exe PRC - [2007/10/03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe PRC - [2007/10/03 14:44:58 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe PRC - [2007/03/27 12:00:32 | 000,196,608 | ---- | M] (Acer Inc.) -- C:\Program Files\Acer\Acer VCM\acp2HID.exe ========== Modules (SafeList) ========== MOD - [2011/05/08 12:03:03 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\guy\Desktop\OTL.exe MOD - [2010/08/31 17:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - [2011/04/29 13:05:06 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011/03/29 15:41:46 | 000,053,248 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus® SRV - [2011/03/04 14:38:18 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010/08/24 11:38:18 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2010/06/14 14:39:26 | 001,053,424 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Orange\OrangeUpdate\Service\OUCore.exe -- (Orange update Core Service) SRV - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess) SRV - [2009/09/21 15:01:50 | 003,488,768 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Acer Bio Protection\BASVC.exe -- (IGBASVC) SRV - [2009/05/20 20:18:32 | 000,075,048 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe -- (CLHNService) SRV - [2008/04/27 22:26:44 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) [Auto | Running] -- C:\Windows\System32\vfsFPService.exe -- (vfsFPService) SRV - [2008/03/21 13:22:52 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -- (ETService) SRV - [2008/03/05 00:38:34 | 000,500,784 | ---- | M] (Egis Incorporated) [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service) SRV - [2008/01/21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2008/01/10 17:03:00 | 000,233,472 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer VCM\RS_Service.exe -- (RS_Service) SRV - [2007/12/11 05:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio) SRV - [2007/12/06 17:15:28 | 000,110,592 | ---- | M] () [Auto | Running] -- C:\Acer\Mobility Center\MobilityService.exe -- (MobilityService) SRV - [2007/10/03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON) Intel® ========== Driver Services (SafeList) ========== DRV - [2011/03/04 16:11:12 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011/03/04 14:38:47 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2010/06/17 14:28:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009/12/24 16:19:56 | 000,087,536 | ---- | M] (CyberLink Corp.) [2010/04/01 12:12:30] [Kernel | Auto | Running] -- C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl -- ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) DRV - [2009/11/12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2009/09/21 15:01:45 | 000,043,184 | ---- | M] (Alfa Corporation) [File_System | Boot | Running] -- C:\Windows\system32\Drivers\AlfaFF.sys -- (AlfaFF) DRV - [2009/05/25 12:12:28 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lgvmodem.sys -- (LGVMODEM) DRV - [2009/05/25 12:12:28 | 000,012,032 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lgbtport.sys -- (LgBttPort) DRV - [2009/05/25 12:12:26 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lgbtbus.sys -- (lgbusenum) DRV - [2008/07/08 14:55:56 | 000,121,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdmdm.sys -- (lgmdmdm) DRV - [2008/07/08 14:55:56 | 000,114,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdmgmt.sys -- (lgmdmgmt) LG Mobile USB WMC Device Management Drivers (WDM) DRV - [2008/07/08 14:55:56 | 000,111,232 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdobex.sys -- (lgmdobex) DRV - [2008/07/08 14:55:56 | 000,089,600 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdbus.sys -- (lgmdbus) LG Mobile driver (WDM) DRV - [2008/07/08 14:55:56 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdmdfl.sys -- (lgmdmdfl) DRV - [2008/05/08 19:01:44 | 003,552,256 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2008/04/27 22:27:10 | 000,040,752 | ---- | M] (Validity Sensors, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vfs101x.sys -- (vfs101x) DRV - [2008/03/21 10:48:24 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\int15.sys -- (int15) DRV - [2008/03/11 13:38:00 | 000,048,128 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1E60x86.sys -- (L1E) DRV - [2008/02/29 09:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2008/01/08 21:10:32 | 002,554,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Pilote de carte Intel® DRV - [2007/12/18 18:12:12 | 000,054,784 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\itecir.sys -- (itecir) DRV - [2007/12/16 17:57:20 | 000,075,776 | ---- | M] (Wasay) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSVD.sys -- (WSVD) DRV - [2006/11/02 15:27:34 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\PROGRA~1\LAUNCH~1\DPortIO.sys -- (DritekPortIO) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo! France IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Yahoo! France IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Acer.com Worldwide - Select your local country or region [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data over 100 bytes] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Portail Orange : Actu, Sport, Assistance Internet, Web Mail Orange IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN : Hotmail, Messenger, Bing, Actualité et Sport IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CD 97 04 A8 DC 6A CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: MapShare-status@tomtom.com:1.7 FF - prefs.js..extensions.enabledItems: baseTheme@tomtom.com:1.0.2 [2011/02/28 19:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\YUG\AppData\Roaming\mozilla\Extensions [2011/02/28 19:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\YUG\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2010/12/18 18:47:43 | 000,000,000 | ---D | M] (Map status indicator) -- C:\PROGRAM FILES\TOMTOM HOME 2\XUL\EXTENSIONS\MAPSHARE-STATUS@TOMTOM.COM O1 HOSTS File: ([2011/05/08 19:22:14 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.) O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D3028143-6145-4318-99D3-3EDCE54A95A9} - No CLSID value found. O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [eAudio] C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (Acer Incorporated) O4 - HKLM..\Run: [eRecoveryService] File not found O4 - HKLM..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) O4 - HKLM..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [ZPdtWzdVitaKey MC3000] C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.) O4 - HKCU..\Run: [orangeinside] C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe (Orange) O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\RunOnce: [uninstall Adobe Download Manager] C:\Program Files\NOS\bin\getPlusUninst_Adobe.exe (NOS Microsystems Ltd.) O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\addfavorites_html\addfavorites.html () O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: envoyer le texte sélectionné par sms - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\sendsmsselectedtext_html\sendsmsselectedtext.html () O8 - Extra context menu item: envoyer par sms - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\sendsms_html\sendsms.html () O8 - Extra context menu item: envoyer un mail - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\sendmail_html\sendmail.html () O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.) O8 - Extra context menu item: orange.fr - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\orange_html\orange.html () O8 - Extra context menu item: rechercher le texte sélectionné - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\selectedsearch_html\selectedsearch.html () O8 - Extra context menu item: traduire la page - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\translate_html\translate.html () O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\translateSelectedText_html\translateSelectedText.html () O9 - Extra Button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe () O9 - Extra 'Tools' menuitem : Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe () O9 - Extra Button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2011/04/14 22:23:37 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011/04/14 22:24:01 | 000,000,000 | ---D | M] - D:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011/04/14 22:24:02 | 000,000,000 | ---D | M] - F:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk /p \??\F:) - File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011/05/10 11:16:09 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe [2011/05/10 11:02:57 | 000,000,000 | ---D | C] -- C:\ProgramData\NOS [2011/05/10 11:02:57 | 000,000,000 | ---D | C] -- C:\Program Files\NOS [2011/05/08 19:19:52 | 000,000,000 | ---D | C] -- C:\_OTL [2011/05/02 10:20:08 | 000,000,000 | ---D | C] -- C:\Users\YUG\AppData\Roaming\Malwarebytes [2011/05/02 10:19:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011/05/02 10:19:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/05/02 10:19:48 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011/05/02 10:19:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011/04/29 13:21:34 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll [2011/04/29 13:21:34 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll [2011/04/29 13:17:37 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2011/04/15 12:22:43 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll [2011/04/15 12:22:43 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll [2011/04/15 12:22:37 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2011/04/15 12:22:37 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2011/04/15 12:22:37 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011/04/15 12:22:37 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011/04/15 12:22:37 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011/04/15 12:22:37 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011/04/15 12:22:36 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011/04/15 12:22:36 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011/04/15 12:22:36 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011/04/15 12:22:36 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011/04/15 12:22:36 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011/04/15 12:22:36 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011/04/15 12:22:36 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011/04/15 12:22:36 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011/04/15 12:22:36 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011/04/15 12:22:36 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011/04/15 12:22:36 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011/04/15 12:22:27 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll [2011/04/15 12:22:26 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll [2011/04/15 12:17:23 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe [2011/04/15 12:12:22 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011/04/15 12:12:15 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2011/04/15 12:12:15 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2011/04/15 00:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2011/04/15 00:05:11 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll [2011/04/15 00:05:11 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe [2011/04/15 00:05:11 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe [2011/04/15 00:05:11 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe [2011/04/14 22:21:57 | 000,000,000 | ---D | C] -- C:\UsbFix [2011/04/12 00:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2011/04/12 00:06:26 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2011/04/12 00:06:25 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011/04/12 00:06:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2011/04/12 00:06:24 | 000,000,000 | ---D | C] -- C:\Program Files\Avira ========== Files - Modified Within 30 Days ========== [2011/05/10 12:11:51 | 000,000,398 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E6E841DC-A458-4EE4-8C13-43F9E7FCE5F6}.job [2011/05/10 12:09:55 | 000,679,042 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2011/05/10 12:09:55 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011/05/10 12:09:55 | 000,126,626 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2011/05/10 12:09:55 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011/05/10 12:09:11 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011/05/10 12:09:11 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011/05/10 11:16:43 | 000,001,896 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2011/05/10 08:09:28 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml [2011/05/10 08:09:27 | 000,000,374 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics [2011/05/10 08:09:09 | 000,067,584 | ---- | M] () -- C:\Windows\bootstat.dat [2011/05/09 21:13:04 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2011/05/08 19:22:14 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts [2011/05/08 12:08:35 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin [2011/05/07 18:48:00 | 000,001,975 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2011/05/02 10:19:52 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/16 08:16:36 | 000,316,264 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011/04/12 00:06:38 | 000,001,851 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2011/04/11 21:25:51 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt ========== Files Created - No Company Name ========== [2011/05/10 11:16:43 | 000,001,896 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2011/05/10 11:16:42 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2011/05/09 10:22:38 | 000,000,398 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{E6E841DC-A458-4EE4-8C13-43F9E7FCE5F6}.job [2011/05/08 12:08:35 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin [2011/05/02 10:19:52 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/12 00:06:38 | 000,001,851 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2010/10/18 11:35:32 | 000,005,056 | ---- | C] () -- C:\ProgramData\drctchbl.xvi [2010/10/18 11:35:32 | 000,004,110 | ---- | C] () -- C:\ProgramData\xqkcebzs.dik [2010/10/08 10:57:42 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010/06/02 02:42:42 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2010/04/29 16:12:32 | 000,000,031 | ---- | C] () -- C:\Windows\yesmessenger.ini [2010/04/22 14:56:51 | 000,000,338 | ---- | C] () -- C:\Windows\yes_messenger.ini [2009/10/22 00:57:28 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2009/09/24 10:14:18 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat [2009/09/24 10:14:18 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat [2009/09/24 10:14:18 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat [2009/09/24 10:14:18 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat [2009/09/24 10:14:18 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat [2009/09/24 10:14:18 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat [2009/09/24 10:14:18 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat [2009/09/24 10:14:18 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat [2009/09/24 10:14:18 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat [2009/09/24 10:14:18 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat [2009/09/24 10:14:18 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat [2009/09/24 10:14:18 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat [2009/09/24 10:14:18 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat [2009/09/24 10:14:18 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat [2009/09/24 10:14:18 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat [2009/09/24 10:14:18 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat [2009/09/24 10:14:18 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat [2009/09/24 10:14:18 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat [2009/09/24 10:14:18 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini [2009/09/24 10:09:09 | 000,000,027 | ---- | C] () -- C:\Windows\CDE DX4000EFDG.ini [2009/09/24 09:25:31 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009/09/24 09:25:31 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009/09/21 17:12:20 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2009/09/21 15:47:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2009/09/21 15:05:51 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll [2009/09/21 15:05:51 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe [2009/09/21 15:05:51 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini [2009/09/21 15:02:13 | 001,548,099 | ---- | C] () -- C:\Windows\System32\VMC3KAPI.dll [2008/05/16 07:50:46 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat [2008/05/16 07:50:46 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll [2008/05/16 07:50:44 | 000,168,883 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat [2008/05/16 07:50:43 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe [2008/03/21 13:20:46 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIOFM4.dll [2008/03/21 13:20:46 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN5.dll [2008/03/21 12:41:33 | 000,204,800 | ---- | C] () -- C:\Windows\System32\SysHook.dll [2008/03/21 12:37:44 | 000,487,424 | ---- | C] () -- C:\Windows\System32\INT15.dll [2008/03/21 12:33:29 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini [2008/03/21 12:33:29 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat [2008/03/21 12:32:04 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\RtkHDAud.dat [2008/01/21 10:40:50 | 000,679,042 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2008/01/21 10:40:50 | 000,340,236 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2008/01/21 10:40:50 | 000,126,626 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2008/01/21 10:40:50 | 000,037,390 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2007/11/14 16:17:34 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CogentBioSDK.dll [2007/04/24 18:32:56 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll [2006/11/02 14:57:28 | 000,067,584 | ---- | C] () -- C:\Windows\bootstat.dat [2006/11/02 14:47:37 | 000,316,264 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 12:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 12:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2005/12/15 06:17:00 | 000,159,744 | ---- | C] () -- C:\Windows\System32\EPSPTDV.DLL [2001/12/26 16:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll [2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll [2001/09/03 23:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll [2001/07/30 16:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll [2001/07/23 22:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll < End of report > -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Encore moi,Bonjour Cette fois ça marche ,mais j'ai encore eu l'avertissement d'Avira après le redémarrage Pour le rapport ,en fait en ouvrant OTL ce matin il me donne un rapport du 8/05.Je te poste donc les 2 au cas ou... Merci et A+ Rapport du8/05 All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ deleted successfully. C:\Program Files\Avanquest_FR\prxtbAva0.dll moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{AEEC3B59-CA98-4EBA-A140-57B94E283583} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEEC3B59-CA98-4EBA-A140-57B94E283583}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. File C:\Program Files\ConduitEngine\prxConduitEngine.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Program Files\ConduitEngine\prxConduitEngine.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{6EC85FCF-87AD-41D7-AE1F-F116F8AD4848} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6EC85FCF-87AD-41D7-AE1F-F116F8AD4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\avast5 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\orange.fr\logicielsgratuits\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ not found. File E:\Viewer.exe not found. C:\Windows\Tasks\Registry Winner Schedule.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Windows\Tasks\Registry Reviver-YUG-Startup.job moved successfully. C:\Windows\Tasks\Registry_Doktor.job moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== < ipconfig /flushdns /c > Configuration IP de Windows Cache de r‚solution DNS vid‚. C:\Users\guy\Desktop\cmd.bat deleted successfully. C:\Users\guy\Desktop\cmd.txt deleted successfully. C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\WINDOWS\tasks\SyncBack GUY.job moved successfully. C:\WINDOWS\tasks\User_Feed_Synchronization-{29B4A4A2-E71F-4BB3-91D7-16A36EE731FF}.job moved successfully. C:\WINDOWS\tasks\User_Feed_Synchronization-{E6E841DC-A458-4EE4-8C13-43F9E7FCE5F6}.job moved successfully. File\Folder C:\*.sqm not found. File\Folder C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. File\Folder C:\Program Files\ConduitEngine not found. File\Folder C:\Windows\tasks\Registry Winner Schedule.job not found. File\Folder C:\Windows\tasks\GoogleUpdateTaskMachineCore.job not found. File\Folder C:\Windows\tasks\Registry Reviver-YUG-Startup.job not found. File\Folder C:\Windows\tasks\Registry_Doktor.job not found. ========== COMMANDS ========== [EMPTYTEMP] User: admin User: Administrator User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: guy ->Temp folder emptied: 2899966 bytes ->Temporary Internet Files folder emptied: 45739941 bytes ->Java cache emptied: 73183770 bytes ->Google Chrome cache emptied: 6116979 bytes ->Flash cache emptied: 9700 bytes User: Public User: YUG ->Temp folder emptied: 75461022 bytes ->Temporary Internet Files folder emptied: 24907649 bytes ->Java cache emptied: 73470106 bytes ->Flash cache emptied: 635 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 42652886 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 8393932 bytes Total Files Cleaned = 337,00 mb [EMPTYFLASH] User: admin User: Administrator User: All Users User: Default User: Default User User: guy ->Flash cache emptied: 0 bytes User: Public User: YUG ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.22.3 log created on 05082011_191952 Files\Folders moved on Reboot... File\Folder C:\Users\guy\AppData\Local\Temp\~DF3FCB.tmp not found! File\Folder C:\Users\guy\AppData\Local\Temp\~DF3FDB.tmp not found! File\Folder C:\Users\guy\AppData\Local\Temp\~DFAD2F.tmp not found! File\Folder C:\Users\guy\AppData\Local\Temp\~DFAD4A.tmp not found! File\Folder C:\Users\guy\AppData\Local\Temp\~DFAD8A.tmp not found! File\Folder C:\Users\guy\AppData\Local\Temp\~DFAE12.tmp not found! File\Folder C:\Users\guy\AppData\Local\Temp\~DFB475.tmp not found! File\Folder C:\Users\guy\AppData\Local\Temp\~DFB56F.tmp not found! C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KVRUY0XL\read[1].html moved successfully. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KVRUY0XL\st[1] moved successfully. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G4TIYV7H\ban_home_728x90[1].htm moved successfully. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9VLK57V7\AP_ADV_728x90[1].htm moved successfully. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4H3SATYI\sendConfirmationReading_frame[1].html moved successfully. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\23VLMH18\read_unread_iframe[1].htm moved successfully. File move failed. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\07GBO19P\=;var41;u=id=4TNIUGYJhkmWVL4VM_6uqg%7C1=5%7C2=1%7C3=86400%7C4=9%7C21=5%7C22=1%7C23=1%7C24=1%7C25=2%7C26=86078%7C8=0%7C9=0%7C10=0%7C%7C;;ord=7636669132966258[1].htm scheduled to be moved on reboot. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\07GBO19P\afr[3].htm moved successfully. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\07GBO19P\logiciel-malveillant-bloque-par-avast-t184609[1].htm moved successfully. File move failed. C:\Users\guy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be moved on reboot. Registry entries deleted on Reboot... Rapport du 9/05 All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{AEEC3B59-CA98-4EBA-A140-57B94E283583} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEEC3B59-CA98-4EBA-A140-57B94E283583}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Program Files\ConduitEngine\prxConduitEngine.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Program Files\ConduitEngine\prxConduitEngine.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6ec85fcf-87ad-41d7-ae1f-f116f8ad4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{6EC85FCF-87AD-41D7-AE1F-F116F8AD4848} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6EC85FCF-87AD-41D7-AE1F-F116F8AD4848}\ not found. File C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\avast5 not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ not found. Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\orange.fr\logicielsgratuits\ not found. File not found. File not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\ not found. File E:\Viewer.exe not found. File C:\Windows\tasks\Registry Winner Schedule.job not found. File C:\Windows\tasks\GoogleUpdateTaskMachineCore.job not found. File C:\Windows\tasks\Registry Reviver-YUG-Startup.job not found. File C:\Windows\tasks\Registry_Doktor.job not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\tasks\User_Feed_Synchronization-{E6E841DC-A458-4EE4-8C13-43F9E7FCE5F6}.job moved successfully. File\Folder C:\*.sqm not found. File\Folder C:\Program Files\Avanquest_FR\prxtbAva0.dll not found. File\Folder C:\Program Files\ConduitEngine not found. File\Folder C:\Windows\tasks\Registry Winner Schedule.job not found. File\Folder C:\Windows\tasks\GoogleUpdateTaskMachineCore.job not found. File\Folder C:\Windows\tasks\Registry Reviver-YUG-Startup.job not found. File\Folder C:\Windows\tasks\Registry_Doktor.job not found. Folder move failed. C:\autorun.inf scheduled to be moved on reboot. Folder move failed. D:\autorun.inf scheduled to be moved on reboot. Folder move failed. F:\autorun.inf scheduled to be moved on reboot. ========== COMMANDS ========== [EMPTYTEMP] User: admin User: Administrator User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: guy ->Temp folder emptied: 911366 bytes ->Temporary Internet Files folder emptied: 21425924 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 750 bytes User: Public User: YUG ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 108 bytes Total Files Cleaned = 21,00 mb [EMPTYFLASH] User: admin User: Administrator User: All Users User: Default User: Default User User: guy ->Flash cache emptied: 0 bytes User: Public User: YUG ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 05092011_102054 -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bonsoir lance_yien Problèmes:en 1 suppression de conduitengine:vu en partie car impossible de le supprimer en F mon disque externe de sauvegarde en 2-plantage au redémarrage après la correction faite (conseillé :avec démarrage système=arrêt après 2 à 3 mn sur 2 tentatives (grrrr)puis démarrage normal= ouf!ça marche)par contre je n'ai pas de rapport et j'hésite de reprendre le processus Et j'ai tjrs par moment l'avertissement d'Avira :Autorun.inf bloqué pour sécurité soit sur C ou F..... Merci de me donner la marche à suivre sans me planter A + -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
et le 2éme Merci encore OTL Extras logfile created on: 08/05/2011 12:05:06 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\guy\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19048) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 39,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 73,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,44 Gb Total Space | 61,34 Gb Free Space | 55,04% Space Free | Partition Type: NTFS Drive D: | 104,90 Gb Total Space | 76,98 Gb Free Space | 73,38% Space Free | Partition Type: NTFS Drive F: | 465,76 Gb Total Space | 273,37 Gb Free Space | 58,69% Space Free | Partition Type: NTFS Drive G: | 3,76 Gb Total Space | 3,76 Gb Free Space | 100,00% Space Free | Partition Type: FAT32 Computer Name: PC-DE-GUY | User Name: YUG | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" () Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 "VistaSp1" = Reg Error: Unknown registry data type -- File not found "VistaSp2" = Reg Error: Unknown registry data type -- File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe:*:Enabled:eDSfsu -- (Egis Incorporated.) "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\encryption.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\encryption.exe:*:Enabled:encryption -- ( Egis Incorporated.) "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\decryption.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\decryption.exe:*:Enabled:decryption -- ( Egis Incorporated.) "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe:*:Enabled:eDSMgr "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe:*:Enabled:eDStbmngr -- (Egis Incorporated.) "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe:*:Enabled:eDSfsu -- (Egis Incorporated.) "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\encryption.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\encryption.exe:*:Enabled:encryption "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\decryption.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\decryption.exe:*:Enabled:decryption "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe:*:Enabled:eDSMgr "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe" = C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe:*:Enabled:eDStbmngr -- (Egis Incorporated.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{06291F09-D425-424F-AD68-0115C6175234}" = lport=10243 | protocol=6 | dir=in | app=system | "{07F0F635-A5F7-42AA-BAEE-AEE194356750}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{09077A62-5D1F-4535-84E9-F23F17D14F4E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{15C41F86-12B3-47DD-AA1C-70ECE54601A3}" = lport=445 | protocol=6 | dir=in | app=system | "{160CB322-9922-44D9-99B2-07A2EC128EEB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{1EACBE9B-4FCB-45C9-B524-805163347ABE}" = rport=139 | protocol=6 | dir=out | app=system | "{1FCA295C-9058-4BAE-BEAC-EB279E4DFD4C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{22295743-653A-4C6A-A574-3950B73E15CE}" = rport=2869 | protocol=6 | dir=out | app=system | "{226801C5-CF4C-467E-9C6E-4CE332353902}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{2E666031-E16E-401F-8EB1-9CCA40B5C696}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2EEEA81E-6A1C-4096-8FAC-5E76E5C9B756}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{33420BE6-7469-46E1-BA1C-23BF6557497E}" = lport=445 | protocol=6 | dir=in | app=system | "{350D0667-E6A4-4A44-A683-E0CC186E4047}" = lport=2869 | protocol=6 | dir=in | app=system | "{3A2DFB28-5786-4C1C-9963-F8944A6BE23D}" = rport=138 | protocol=17 | dir=out | app=system | "{42160FD8-393F-4C08-B299-A8A6640E6298}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{45414DAC-67F8-49BB-89B6-BAF942390688}" = lport=3390 | protocol=6 | dir=in | app=system | "{45C0E7D4-B839-442A-B872-B66D6AF52557}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{47194D16-7474-49A4-9CCB-5854174B9A18}" = rport=10243 | protocol=6 | dir=out | app=system | "{56D9CDF5-AEE7-41BE-B7BA-3FE0DD614B4B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{58160860-0702-41D3-A527-388226CABEF3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5D630B31-6414-4A20-98F4-C098B0CBD64F}" = lport=137 | protocol=17 | dir=in | app=system | "{61FC7F18-37B0-4C22-8B17-57F0452C5720}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{65F169CD-41D6-407B-9BA0-432388EB07A9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{6FF6A7FB-B43C-411F-8C8F-CCE9C1B98EE4}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{786EB93B-F57E-4934-A1A2-70341D7B1D60}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{78BFDD3A-1FC3-41B4-9A32-8A8B165E38DB}" = rport=10244 | protocol=6 | dir=out | app=system | "{7A4DD3C6-10AE-445F-90D7-AF0490CD9DDA}" = lport=138 | protocol=17 | dir=in | app=system | "{7FC25EC1-80F3-498E-AEFB-615E2E04B70F}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=c:\windows\system32\dfsr.exe | "{84975B36-9040-4290-ABFD-61A6D4345BAF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe | "{8B9D35F9-73A1-4B71-A5B8-F76E19D31B34}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{9010076C-2663-4562-BD9D-BD7F66D4A35A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{92E1A326-E442-4199-BCDD-8A8A0323DC81}" = lport=139 | protocol=6 | dir=in | app=system | "{93F5E78E-DA61-4C1E-8295-025C5F5FF366}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{94A14E1E-CADF-4FC0-8800-4970A5A780F4}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{9F82DED6-2FD7-4218-92F2-AB8248E110EB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{9FED5E8A-56CE-47E3-A4D4-4955887A8EF2}" = lport=554 | protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe | "{A0CD45B5-5039-4453-B6DA-1E17C56525C9}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{A4631AD5-C8C2-4552-B19F-9D704F961743}" = lport=rpc | protocol=6 | dir=in | svc=* | app=c:\windows\system32\svchost.exe | "{A4AA5BCE-6580-44F3-AD57-6C38188337C0}" = rport=137 | protocol=17 | dir=out | app=system | "{A9B35ECB-9E8D-41DA-BA70-AFC30103EC44}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe | "{AA5C105C-C542-4F5C-8A51-7DBC9A8AC022}" = lport=2869 | protocol=6 | dir=in | app=system | "{AC0F92F3-2177-4679-89A4-12EA0A8C1946}" = lport=10244 | protocol=6 | dir=in | app=system | "{AE1C84F5-EB32-4A87-8F1A-2BCEA0A439A2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{B88FCAD9-BA68-4C6A-B2FD-C8F7510FF29C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{BFBE1358-1D0E-4522-B1BB-4541DFCB0E30}" = lport=445 | protocol=6 | dir=in | app=system | "{C2FBC7DB-F52E-4D00-A6EE-3BC685C72B42}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=c:\windows\system32\dfsr.exe | "{C7CF4DA9-8029-4695-9095-73A13FBEC617}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{C83DF4B2-EDC8-4FD1-84E4-E367A1FF04F7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{CA6E7BD0-6985-41E5-8F73-47B6FED652BD}" = lport=5985 | protocol=6 | dir=in | app=system | "{DBBC8AC2-EDF3-41AC-8CAE-665963E3E744}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe | "{E50A982D-0696-4CD8-8949-89F44793E7AC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | "{E5A5B9D1-A109-4B79-BD7E-D12EF7D84F42}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=c:\windows\system32\svchost.exe | "{E73E95B1-935A-4761-B297-DF8D378D0B09}" = rport=445 | protocol=6 | dir=out | app=system | "{E772BAE5-7D6C-41D2-8D53-D5FC0F847E61}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{EAA90862-B5F6-4F7F-94D4-13F7802DA836}" = lport=7777 | protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe | "{F012488C-5D7D-48B8-8E54-9CE5321B0D85}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{F317F26B-B183-4F3D-B30D-5A5399A95A61}" = lport=80 | protocol=6 | dir=in | name=@wsmres.dll,-50 | "{FBA5A2D9-020D-4693-8950-E7DA569501B0}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{FC73AFF0-3005-45BD-A7BD-D97EBE165161}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=c:\windows\system32\svchost.exe | "{FD2A158A-F0B4-4FA7-904C-CD3C6A22415B}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{FD47ACAD-686C-4308-91FB-501926699E47}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe | "{FE98DB72-C91F-4C1C-84CD-EDD390393199}" = lport=2869 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0316ECE0-8979-471B-B681-8F812151A41A}" = protocol=6 | dir=out | app=system | "{0532BA36-B605-4087-BEC0-7CABBAD9810F}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\playmovie.exe | "{0561FF07-60F9-412E-9804-A89F454622AD}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{06C2FCFC-DE5D-423D-A253-17F8F234A43A}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | "{0BDB4EFA-D7E1-4205-B95E-2094C77804F4}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe | "{0C44DDF6-5CBA-462B-980C-92EA32E88C16}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{1285865A-F82F-47E8-AC5F-DFB1BF1A4F4E}" = protocol=17 | dir=in | app=c:\program files\windows collaboration\wincollab.exe | "{12D2DCD0-6D87-4AFE-A0A8-96C7090CB98E}" = protocol=6 | dir=in | app=c:\program files\orange\orangeupdate\service\oucore.exe | "{169FAD64-6C6C-42C4-9B6F-2D1753F471DF}" = protocol=6 | dir=out | svc=mcx2svc | app=c:\windows\system32\svchost.exe | "{17BB2075-0344-4064-8EC0-90F3D2BAACDA}" = protocol=6 | dir=out | app=system | "{17CD2994-6FBC-4BA5-9036-42C9DDE86993}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{19B74D63-7980-458C-B2F1-04E30F0DB515}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{1E886B77-0757-47A0-9AEB-B6671BC7E17A}" = dir=in | app=c:\program files\acer arcade deluxe\playmovie\pmvservice.exe | "{22CA5593-AA1A-4E4C-BD54-1EF276B23D2B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{237BEDA4-D306-4DFF-9CEB-D5FC2775ACEA}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe | "{24398DC6-2730-49BF-9658-86FF293D787F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{281681F8-07D3-4362-A8BC-30A45B40D85B}" = protocol=6 | dir=out | app=c:\windows\ehome\mcx2prov.exe | "{2894340D-95A6-4216-9561-E44710AF5772}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe | "{351D3FE6-4025-4B8B-BBD7-8C489F430654}" = dir=in | app=c:\program files\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe | "{37F3F3FA-D7D5-4D15-9ED0-36003DFF4DC2}" = protocol=6 | dir=in | app=c:\windows\system32\msra.exe | "{417C682D-E65A-4FE5-960B-7EE60ADC0C46}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe | "{47BF15BC-29DF-4BE5-A1D6-7D52783DBEE8}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe | "{4954DC36-416E-416E-90D7-290BC6881B56}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{4EE59E44-DEF4-4DF4-B6D0-8F43AD2A7930}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | "{508AA1EB-3DF5-489C-9C21-B84987DCC58D}" = dir=in | app=c:\program files\acer arcade deluxe\homemedia\homemedia.exe | "{55628189-9484-4DA9-8DCB-C5E528FDE4EE}" = protocol=6 | dir=in | app=c:\windows\system32\wbem\unsecapp.exe | "{562161D5-6ADE-44C2-BF3F-E68B1BB48BB5}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | "{5E38C0A7-7502-4D39-B1CA-BC4B35A3AC38}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe | "{62B21C4E-EF6B-4839-93CF-F820AF071C44}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | "{6C3511D7-6B18-400B-A2DF-80AE98E7EC05}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{7761C3C4-D541-4278-BF2F-B7F17733E222}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{79917CB4-A3DC-4145-9B30-B2EEFBCFA4B4}" = protocol=6 | dir=out | app=c:\program files\windows collaboration\wincollab.exe | "{7BD48571-1985-4162-804A-70344C44FE82}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 | "{7BDD7D71-A30C-4688-B4E6-F0E820DDE2FA}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{8046314B-E16E-434A-9543-74D2569D908F}" = protocol=6 | dir=out | app=c:\windows\system32\msra.exe | "{8DA87909-1116-4839-8426-963F226C5569}" = protocol=17 | dir=in | app=c:\program files\orange\orangeupdate\service\oucore.exe | "{90333D8B-5613-4799-8711-0A6C6EE7D7BA}" = protocol=6 | dir=in | app=c:\program files\windows collaboration\wincollab.exe | "{95039699-F173-4BD4-8E0F-6EC17142C8B4}" = protocol=6 | dir=out | app=c:\windows\ehome\ehshell.exe | "{A111E818-2932-45CF-9513-5F8E30BA71E0}" = protocol=17 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\client\agentsvc.exe | "{A465919E-5CB5-4168-976A-BC2A1C89271A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{BDDE3185-4301-4BC7-84A3-E3F720F83226}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | "{BFD9C540-A9E9-41C3-8CBF-2DB2E6D7B843}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{D00D0839-8061-4669-889D-EA886FCEC735}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe | "{D02C830D-A5A3-42CA-AB0C-64574576A721}" = protocol=6 | dir=in | app=c:\program files\microsoft works\wksss.exe | "{D6459749-6CF2-4A77-86C7-93C2A113CC75}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe | "{DA51C2EB-E87D-49AA-A70B-EA1ABEA2048E}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe | "{E1AC2556-362D-476A-954A-9D1A9ED428E1}" = protocol=6 | dir=out | svc=winmgmt | app=c:\windows\system32\svchost.exe | "{E702CAD2-48EF-464C-8344-A624A885A95D}" = protocol=17 | dir=out | app=c:\program files\windows collaboration\wincollab.exe | "{E9EA1E12-86FE-4769-B649-C29C542E2737}" = dir=in | app=c:\program files\acer\acer vcm\vc.exe | "{EDF0518D-9E51-442A-916B-51E85D5BE5CC}" = protocol=17 | dir=in | app=c:\program files\microsoft works\wksss.exe | "{EE5CDDDD-2660-49AD-807E-17179F331E5A}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\backupsvc.exe | "{EFE4943A-A44D-4155-9C86-0659C9066805}" = protocol=6 | dir=in | svc=winmgmt | app=c:\windows\system32\svchost.exe | "{F00E00D7-6611-4B86-BA3E-352C76FD90D8}" = protocol=6 | dir=in | app=c:\program files\newtech infosystems\nti backup now 5\schedulersvc.exe | "{F36D27AD-D586-4554-8C09-1864607257EA}" = protocol=17 | dir=out | app=c:\windows\ehome\ehshell.exe | "{FCCF3647-3FCB-44C8-BAE8-FF9F7D14C3E9}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "TCP Query User{13D7F936-6699-4059-BC56-8BADA2E4CC91}C:\program files\windows sidebar\sidebar.exe" = protocol=6 | dir=in | app=c:\program files\windows sidebar\sidebar.exe | "TCP Query User{3DA929C9-52E5-4524-BD4F-F5B07396B472}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "TCP Query User{646C4F52-3D95-4463-8751-8B67074FD9B0}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "TCP Query User{E8EBBDC4-514F-405C-9F09-85F9E13BBA4B}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe | "UDP Query User{0E3551A1-C681-40F4-812C-9F9CE4004C79}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{2E1AA533-41E3-499A-8EFA-63F5AA2DADE4}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe | "UDP Query User{4B745E1F-3EDF-43B3-91AC-F97776C2B390}C:\program files\windows sidebar\sidebar.exe" = protocol=17 | dir=in | app=c:\program files\windows sidebar\sidebar.exe | "UDP Query User{D27D7894-AE05-4ACA-90A9-FB5AFE97864F}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{01C08A7D-4CCD-41F8-B020-4B4BB8C08C68}" = Catalyst Control Center - Branding "{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5000 "{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM "{0A1984C3-5036-5B5F-F18E-16453EF5A6E1}" = Catalyst Control Center Localization Swedish "{0F5B4A82-9DAF-3D13-8CB8-AEB25E4A614E}" = Microsoft .NET Framework 4 Client Profile FRA Language Pack "{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In "{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard "{13A5E785-5197-4EAD-8EE3-D660271E49BC}" = Feedback Tool "{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management "{155BBB23-C7A5-223C-3B33-289089D6E0A2}" = Catalyst Control Center Localization Finnish "{16E79B1D-D1C2-4CA6-8B23-F4D890E0DCB9}" = Orange Plug-in messagerie vocale 888 "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{19B4BDE9-0F2B-44FF-FDC4-987E1B33D03C}" = CCC Help English "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "{24F149E4-D897-9046-48A5-87CD67F81865}" = CCC Help Polish "{25C1AF96-1F59-A1CE-3135-B38AFAA5C614}" = CCC Help Czech "{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller "{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java 6 Update 24 "{26E2E4FB-F26A-549E-5496-14BAE4E2BA67}" = Catalyst Control Center Graphics Full Existing "{27B7371A-7AA2-CC5B-6377-72161660F0BE}" = CCC Help Chinese Traditional "{29F3D466-E05F-CBB6-63E9-01C85C083FCD}" = CCC Help French "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant "{2CB2E1AE-B62A-3F43-9DD0-EF73467977AC}" = Catalyst Control Center Localization Hungarian "{30BDD0BE-6A51-6DDD-197D-EFCE3B0EF79D}" = CCC Help German "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver "{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0 "{358C26F2-5B99-A7E9-18CF-2AE6BC97289B}" = Catalyst Control Center Localization Czech "{3C277F75-605E-BFFE-4F87-27709C92370C}" = Catalyst Control Center Localization Portuguese "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile "{3E31821C-7917-367E-938E-E65FC413EA31}" = Microsoft .NET Framework 3.5 Language Pack SP1 - fra "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4BD4AA8B-3C63-26AB-1CA3-010475A9EA72}" = CCC Help Portuguese "{5262BAD6-5AB7-1490-A65C-D06368F07FF1}" = Catalyst Control Center Localization Italian "{53F44183-B716-8D7D-053E-CB8039B38E74}" = CCC Help Hungarian "{5539EBB1-4BB9-21E5-921B-16E8886639D3}" = Catalyst Control Center Localization Chinese Traditional "{567E8236-C414-4888-8211-3D61608D57AE}" = Validity Sensors software "{57265292-228A-41FA-9AEC-4620CBCC2739}" = Acer eAudio Management "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management "{59996900-0E6C-45B7-8C39-C64CB98462E4}" = Microsoft Web Platform Installer 2.0 "{5A89D38C-B9FE-ECFF-B90E-B9DEC8C8F2D8}" = Catalyst Control Center Localization Greek "{5B1519C1-265C-C636-C414-F1E150B4F0AA}" = CCC Help Turkish "{6184B5A4-1355-A8D6-CE24-8F7EE887CBF3}" = CCC Help Norwegian "{650BDC60-79C7-383B-2E9C-B8FF3909A127}" = Catalyst Control Center Localization Spanish "{653F6FEA-643C-457F-774A-64D4DAAE1028}" = Catalyst Control Center Graphics Previews Vista "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites "{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3 "{6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C}" = Microsoft Works "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{790DA23A-126B-91A9-FAB7-13EF66724253}" = CCC Help Swedish "{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver "{7DBDAAAB-8639-B59D-798A-32458B7380F9}" = Catalyst Control Center Localization Norwegian "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP "{7E96828D-B970-B1A9-3D9F-7EC3624785D0}" = Catalyst Control Center Localization German "{7ECBF19A-78EC-1665-7E1C-B3E92B07F7CC}" = CCC Help Japanese "{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management "{80C1F369-F876-3D19-7816-B7800E7A6961}" = CCC Help Greek "{827CFE4D-8687-9E1E-0A72-587BFF0B0D3A}" = CCC Help Thai "{8969CD6F-5B75-40B9-8701-86ECA4C1F263}_is1" = VSO Image Resizer 4.0.0.42 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology "{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules "{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007 "{90120000-0016-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007 "{90120000-0018-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007 "{90120000-001B-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007 "{90120000-001F-0401-0000-0000000FF1CE}_HOMESTUDENTR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007 "{90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007 "{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007 "{90120000-006E-040C-0000-0000000FF1CE}_HOMESTUDENTR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-040C-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (French) 2007 "{90120000-00A1-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2) "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer "{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 4.1.2 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9AF60AF6-B109-D3A4-4367-B3620CBA37A7}" = CCC Help Finnish "{9ED61802-0F47-F846-FA23-67CE3E4BD427}" = CCC Help Italian "{A047FE02-C91C-41CB-898C-4ED21B86025A}" = ToolbarFR "{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management "{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}" = Acer Crystal Eye Webcam 2.0.5 "{A79CB508-2DD7-F717-8787-C6382C274082}" = Catalyst Control Center Graphics Light "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AACF5D06-EF3A-1941-3492-1E60589CA444}" = ccc-utility "{ABD7DBE3-E344-4BCA-B8AD-4360494DD1D9}" = LG MC USB U330 driver "{AC76BA86-7AD7-1036-7B44-A94000000001}" = Adobe Reader 9.4.3 - Français "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint "{AE2C968B-8A14-ABA2-D742-14E575104BCD}" = Catalyst Control Center Localization Korean "{B6988D5B-4325-F1F7-B0E5-C4CCCD01E6B8}" = Catalyst Control Center Localization Thai "{B734B040-25BB-02CA-39BD-FD6D070EDDAB}" = Catalyst Control Center Localization Danish "{B86EE516-7CB4-E4C3-8382-010D4F2807F5}" = CCC Help Korean "{B90450DF-E781-46FD-B1F1-0C86DA40E443}" = PIF DESIGNER "{BB01F512-272A-3C70-DA60-884C8BBC39DD}" = Catalyst Control Center Localization Chinese Standard "{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}" = EPSON Easy Photo Print "{BCB0CE1E-7510-3948-4834-99BBA689CF62}" = Catalyst Control Center Core Implementation "{BD5106DF-C061-5736-F1A5-F114BAA63759}" = CCC Help Russian "{C03A43DF-CEE0-6D82-D2D3-781CCE1FC24E}" = Catalyst Control Center Localization Japanese "{C0E18DC4-C74A-4889-AE3A-933471023787}" = LG PC Suite III "{C2EBC2F1-B766-4AE3-A10C-6EBBC1EE3B02}" = Logiciel de Synchronisation Orange "{C6754E95-9700-45AB-A6C5-668F5F449E27}" = LG Bluetooth Driver "{C76DAFAE-5E59-44AB-2764-70BC79E0D4B2}" = Skins "{C8256DAF-828E-7E91-FB83-D900AA8E3C86}" = CCC Help Danish "{C9429012-1CBE-E0CA-0955-CC53E0F2115F}" = CCC Help Chinese Standard "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "{CB9B619A-EEA1-BFAB-6CA5-1FC655E2A0DA}" = Catalyst Control Center Localization Turkish "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1 "{D013644E-F890-49A4-0DE9-8E4BBD18A406}" = ATI Catalyst Install Manager "{D13FE823-C575-4451-AC37-E645A67AA581}_1.2.2.0" = Orange Installeur version 1.2.2.0 "{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! "{D7C49EC6-4DEA-7A7A-860D-78D613C68B8C}" = ccc-core-static "{E08C03D7-AE05-0458-2D14-78F219316933}" = Catalyst Control Center Localization Dutch "{E4FD0200-A7DB-2D5A-B5B1-DBC0A184C9B2}" = Catalyst Control Center Localization Russian "{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 "{E86BC406-944E-41F6-ADE6-2C136734C96B}" = EPSON File Manager "{E9BA4A79-BD4C-52E3-F34F-85B1CC62EE15}" = Catalyst Control Center Localization Polish "{E9D20FA4-7CA6-F243-A503-CA961CCD2277}" = CCC Help Spanish "{EF9E54C1-2D5F-DDA8-8E7B-0CD3EF89C8E4}" = Catalyst Control Center Localization French "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F5A630D4-3D7D-6EEC-5DAE-41835DC0A1DA}" = Catalyst Control Center Graphics Full New "{FA02ACAC-9E14-4878-A257-92A22A647C2C}" = LG USB Modem Drivers "{FB1AC1F1-8F47-4DCE-A1ED-0DFBA0F455B4}" = Driver Mender "{FCED9B62-34FF-4C15-8A23-F65221F7874D}" = ITECIR Driver "{FD2B6E20-5344-07B4-C210-B57611E02906}" = CCC Help Dutch "Acer Acer Bio Protection 6.0.00.13" = Acer Bio Protection AAV 6.0.00.13 "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Agere Systems Soft Modem" = Agere Systems HDA Modem "Avanquest_FR Toolbar" = Avanquest FR Toolbar "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CCleaner" = CCleaner "conduitEngine" = Conduit Engine "EPSON Printer and Utilities" = EPSON Logiciel imprimante "EPSON Scanner" = EPSON Scan "ESDX4000_4050_CX3900" = ESDX4000_4050_CX3900 "Google Chrome" = Google Chrome "GridVista" = Acer GridVista "HOMESTUDENTR" = Version d'évaluation de Microsoft Office Home and Student 2007 "InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5 "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email "InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8 "InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector "LManager" = Launch Manager "MailNotifier" = Notification Mail "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 Language Pack SP1 - fra" = Module linguistique Microsoft .NET Framework 3.5 SP1- fra "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile FRA Language Pack" = Module linguistique Microsoft .NET Framework 4 Client Profile FRA "OrangeToolbar" = barre d'outils Orange "OrangeUpdateManager" = Orange update "Picasa 3" = Picasa 3 "TomTom HOME" = TomTom HOME 2.7.6.2056 "Usbfix" = UsbFix By TeamXscript "VLC media player" = VLC media player 1.1.5 "Yahoo! Toolbar" = Yahoo! Toolbar "YesMessenger_is1" = YesMessenger 2.4.14 "ZHPDiag_is1" = ZHPDiag 1.24 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Orange Inside" = Orange Inside ========== Last 10 Event Log Errors ========== Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt! < End of report > -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bjr Je te joins le 1er rapport OTL logfile created on: 08/05/2011 12:05:05 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\guy\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19048) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 39,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 73,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,44 Gb Total Space | 61,34 Gb Free Space | 55,04% Space Free | Partition Type: NTFS Drive D: | 104,90 Gb Total Space | 76,98 Gb Free Space | 73,38% Space Free | Partition Type: NTFS Drive F: | 465,76 Gb Total Space | 273,37 Gb Free Space | 58,69% Space Free | Partition Type: NTFS Drive G: | 3,76 Gb Total Space | 3,76 Gb Free Space | 100,00% Space Free | Partition Type: FAT32 Computer Name: PC-DE-GUY | User Name: YUG | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011/05/08 12:03:03 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\guy\Desktop\OTL.exe PRC - [2011/04/29 13:05:06 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2011/04/29 13:05:05 | 000,442,024 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avscan.exe PRC - [2011/04/07 09:00:03 | 000,235,168 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10o_ActiveX.exe PRC - [2011/03/04 14:38:18 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2011/03/04 14:38:17 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2010/08/24 11:38:18 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe PRC - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () -- C:\Program Files\CDBurnerXP\NMSAccessU.exe PRC - [2010/01/14 21:11:14 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe PRC - [2009/11/18 20:41:12 | 000,206,120 | ---- | M] (CyberLink) -- C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe PRC - [2009/09/21 15:02:04 | 003,786,472 | ---- | M] () -- C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe PRC - [2009/09/21 15:02:00 | 003,451,904 | ---- | M] (Arachnoid Biometrics Identification Group Corp.) -- C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe PRC - [2009/09/21 15:01:50 | 003,488,768 | ---- | M] () -- C:\Program Files\Acer\Acer Bio Protection\BASVC.exe PRC - [2009/09/21 15:01:41 | 003,673,600 | ---- | M] (Arachnoid Biometrics Identification Group Corp.) -- C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe PRC - [2009/09/21 14:58:44 | 000,204,800 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\guy\AppData\Local\Temp\RtkBtMnt.exe PRC - [2009/05/20 20:18:32 | 000,075,048 | ---- | M] () -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe PRC - [2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009/04/11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2008/04/28 13:18:26 | 000,809,480 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe PRC - [2008/04/27 22:26:44 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) -- C:\Windows\System32\vfsFPService.exe PRC - [2008/03/21 13:22:52 | 000,024,576 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe PRC - [2008/03/11 11:53:54 | 005,296,128 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2008/03/07 04:36:12 | 000,544,768 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe PRC - [2008/03/05 11:56:30 | 001,216,512 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\AcerVCM.exe PRC - [2008/03/05 00:38:34 | 000,500,784 | ---- | M] (Egis Incorporated) -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe PRC - [2008/01/21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe PRC - [2008/01/10 17:03:00 | 000,233,472 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\RS_Service.exe PRC - [2007/12/11 05:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe PRC - [2007/12/06 17:15:28 | 000,110,592 | ---- | M] () -- C:\ACER\Mobility Center\MobilityService.exe PRC - [2007/10/03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe PRC - [2007/10/03 14:44:58 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe PRC - [2007/03/27 12:00:32 | 000,196,608 | ---- | M] (Acer Inc.) -- C:\Program Files\Acer\Acer VCM\acp2HID.exe ========== Modules (SafeList) ========== MOD - [2011/05/08 12:03:03 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\guy\Desktop\OTL.exe MOD - [2010/08/31 17:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - [2011/04/29 13:05:06 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService) SRV - [2011/03/04 14:38:18 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService) SRV - [2010/08/24 11:38:18 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2010/06/14 14:39:26 | 001,053,424 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Orange\OrangeUpdate\Service\OUCore.exe -- (Orange update Core Service) SRV - [2010/03/04 23:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess) SRV - [2009/09/21 15:01:50 | 003,488,768 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Acer Bio Protection\BASVC.exe -- (IGBASVC) SRV - [2009/05/20 20:18:32 | 000,075,048 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe -- (CLHNService) SRV - [2008/04/27 22:26:44 | 000,599,344 | ---- | M] (Validity Sensors, Inc.) [Auto | Running] -- C:\Windows\System32\vfsFPService.exe -- (vfsFPService) SRV - [2008/03/21 13:22:52 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -- (ETService) SRV - [2008/03/05 00:38:34 | 000,500,784 | ---- | M] (Egis Incorporated) [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service) SRV - [2008/01/21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend) SRV - [2008/01/10 17:03:00 | 000,233,472 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer VCM\RS_Service.exe -- (RS_Service) SRV - [2007/12/11 05:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio) SRV - [2007/12/06 17:15:28 | 000,110,592 | ---- | M] () [Auto | Running] -- C:\Acer\Mobility Center\MobilityService.exe -- (MobilityService) SRV - [2007/10/03 14:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON) Intel® ========== Driver Services (SafeList) ========== DRV - [2011/03/04 16:11:12 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb) DRV - [2011/03/04 14:38:47 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt) DRV - [2010/06/17 14:28:02 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv) DRV - [2009/12/24 16:19:56 | 000,087,536 | ---- | M] (CyberLink Corp.) [2010/04/01 12:12:30] [Kernel | Auto | Running] -- C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl -- ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) DRV - [2009/11/12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2009/09/21 15:01:45 | 000,043,184 | ---- | M] (Alfa Corporation) [File_System | Boot | Running] -- C:\Windows\system32\Drivers\AlfaFF.sys -- (AlfaFF) DRV - [2009/05/25 12:12:28 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lgvmodem.sys -- (LGVMODEM) DRV - [2009/05/25 12:12:28 | 000,012,032 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lgbtport.sys -- (LgBttPort) DRV - [2009/05/25 12:12:26 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lgbtbus.sys -- (lgbusenum) DRV - [2008/07/08 14:55:56 | 000,121,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdmdm.sys -- (lgmdmdm) DRV - [2008/07/08 14:55:56 | 000,114,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdmgmt.sys -- (lgmdmgmt) LG Mobile USB WMC Device Management Drivers (WDM) DRV - [2008/07/08 14:55:56 | 000,111,232 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdobex.sys -- (lgmdobex) DRV - [2008/07/08 14:55:56 | 000,089,600 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdbus.sys -- (lgmdbus) LG Mobile driver (WDM) DRV - [2008/07/08 14:55:56 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgmdmdfl.sys -- (lgmdmdfl) DRV - [2008/05/08 19:01:44 | 003,552,256 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2008/04/27 22:27:10 | 000,040,752 | ---- | M] (Validity Sensors, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vfs101x.sys -- (vfs101x) DRV - [2008/03/21 10:48:24 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\int15.sys -- (int15) DRV - [2008/03/11 13:38:00 | 000,048,128 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1E60x86.sys -- (L1E) DRV - [2008/02/29 09:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2008/01/08 21:10:32 | 002,554,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Pilote de carte Intel® DRV - [2007/12/18 18:12:12 | 000,054,784 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\itecir.sys -- (itecir) DRV - [2007/12/16 17:57:20 | 000,075,776 | ---- | M] (Wasay) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSVD.sys -- (WSVD) DRV - [2006/11/02 15:27:34 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\PROGRA~1\LAUNCH~1\DPortIO.sys -- (DritekPortIO) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo! France IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Yahoo! France IE - HKLM\..\URLSearchHook: {6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll (Conduit Ltd.) IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Acer.com Worldwide - Select your local country or region [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data over 100 bytes] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Portail Orange : Actu, Sport, Assistance Internet, Web Mail Orange IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN : Hotmail, Messenger, Bing, Actualité et Sport IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = CD 97 04 A8 DC 6A CA 01 [binary data] IE - HKCU\..\URLSearchHook: {6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {AEEC3B59-CA98-4EBA-A140-57B94E283583} - Reg Error: Key error. File not found IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..extensions.enabledItems: MapShare-status@tomtom.com:1.7 FF - prefs.js..extensions.enabledItems: baseTheme@tomtom.com:1.0.2 [2011/02/28 19:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\YUG\AppData\Roaming\mozilla\Extensions [2011/02/28 19:08:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\YUG\AppData\Roaming\mozilla\Extensions\home2@tomtom.com [2010/12/18 18:47:43 | 000,000,000 | ---D | M] (Map status indicator) -- C:\PROGRAM FILES\TOMTOM HOME 2\XUL\EXTENSIONS\MAPSHARE-STATUS@TOMTOM.COM O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Value error. File not found O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Avanquest FR Toolbar) - {6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll (Conduit Ltd.) O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.) O3 - HKLM\..\Toolbar: (Avanquest FR Toolbar) - {6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Value error. File not found O3 - HKCU\..\Toolbar\WebBrowser: (Avanquest FR Toolbar) - {6EC85FCF-87AD-41D7-AE1F-F116F8AD4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll (Conduit Ltd.) O4 - HKLM..\Run: [avast5] File not found O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [eAudio] C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (Acer Incorporated) O4 - HKLM..\Run: [eRecoveryService] File not found O4 - HKLM..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation) O4 - HKLM..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKLM..\Run: [ZPdtWzdVitaKey MC3000] C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe (Arachnoid Biometrics Identification Group Corp.) O4 - HKCU..\Run: [orangeinside] C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe (Orange) O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKLM..\RunOnce: [] File not found O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\addfavorites_html\addfavorites.html () O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: envoyer le texte sélectionné par sms - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\sendsmsselectedtext_html\sendsmsselectedtext.html () O8 - Extra context menu item: envoyer par sms - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\sendsms_html\sendsms.html () O8 - Extra context menu item: envoyer un mail - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\sendmail_html\sendmail.html () O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.) O8 - Extra context menu item: orange.fr - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\orange_html\orange.html () O8 - Extra context menu item: rechercher le texte sélectionné - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\selectedsearch_html\selectedsearch.html () O8 - Extra context menu item: traduire la page - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\translate_html\translate.html () O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\YUG\AppData\Roaming\Orange\OrangeInside\src\translateSelectedText_html\translateSelectedText.html () O9 - Extra Button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe () O9 - Extra 'Tools' menuitem : Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe () O9 - Extra Button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: orange.fr ([logicielsgratuits] http in Trusted sites) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AWinNotifyVitaKey MC3000: DllName - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2011/04/14 22:23:37 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011/04/14 22:24:01 | 000,000,000 | ---D | M] - D:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011/04/14 22:24:02 | 000,000,000 | ---D | M] - F:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{60d8493a-a6b4-11de-9bf5-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Viewer.exe O34 - HKLM BootExecute: (autocheck autochk /p \??\F:) - File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - File not found NetSvcs: Nla - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.dvsd - pdvcodec.dll File not found CREATERESTOREPOINT Restore point Set: OTL Restore Point PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin ========== Files/Folders - Created Within 30 Days ========== [2011/05/02 10:20:08 | 000,000,000 | ---D | C] -- C:\Users\YUG\AppData\Roaming\Malwarebytes [2011/05/02 10:19:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2011/05/02 10:19:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/05/02 10:19:48 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011/05/02 10:19:48 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011/04/29 13:21:34 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll [2011/04/29 13:21:34 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll [2011/04/29 13:17:37 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll [2011/04/15 12:22:43 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll [2011/04/15 12:22:43 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll [2011/04/15 12:22:37 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2011/04/15 12:22:37 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2011/04/15 12:22:37 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2011/04/15 12:22:37 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2011/04/15 12:22:37 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2011/04/15 12:22:37 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2011/04/15 12:22:36 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2011/04/15 12:22:36 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2011/04/15 12:22:36 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2011/04/15 12:22:36 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2011/04/15 12:22:36 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2011/04/15 12:22:36 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2011/04/15 12:22:36 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2011/04/15 12:22:36 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2011/04/15 12:22:36 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2011/04/15 12:22:36 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2011/04/15 12:22:36 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2011/04/15 12:22:27 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll [2011/04/15 12:22:26 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll [2011/04/15 12:17:23 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe [2011/04/15 12:12:22 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2011/04/15 12:12:15 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll [2011/04/15 12:12:15 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll [2011/04/15 00:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun [2011/04/15 00:05:11 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll [2011/04/15 00:05:11 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe [2011/04/15 00:05:11 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe [2011/04/15 00:05:11 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe [2011/04/14 22:21:57 | 000,000,000 | ---D | C] -- C:\UsbFix [2011/04/12 00:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira [2011/04/12 00:06:26 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys [2011/04/12 00:06:25 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011/04/12 00:06:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira [2011/04/12 00:06:24 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/05/08 12:08:35 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin [2011/05/08 12:06:59 | 000,000,428 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{29B4A4A2-E71F-4BB3-91D7-16A36EE731FF}.job [2011/05/08 12:03:52 | 000,679,042 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2011/05/08 12:03:52 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011/05/08 12:03:52 | 000,126,626 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2011/05/08 12:03:52 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011/05/08 12:02:12 | 000,000,398 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{E6E841DC-A458-4EE4-8C13-43F9E7FCE5F6}.job [2011/05/08 11:47:00 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/05/08 11:27:32 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011/05/08 11:27:32 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011/05/08 08:17:00 | 000,067,584 | ---- | M] () -- C:\Windows\bootstat.dat [2011/05/07 20:00:00 | 000,000,400 | ---- | M] () -- C:\Windows\tasks\Registry Winner Schedule.job [2011/05/07 18:48:00 | 000,001,975 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2011/05/07 13:47:00 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/05/06 08:20:01 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\Registry Reviver-YUG-Startup.job [2011/05/06 08:20:01 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\Registry_Doktor.job [2011/05/06 08:00:07 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml [2011/05/05 19:59:37 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2011/05/02 10:19:52 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/16 08:16:36 | 000,316,264 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011/04/12 00:06:38 | 000,001,851 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2011/04/11 21:25:51 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/05/08 12:08:35 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin [2011/05/02 10:19:52 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/04/15 00:07:12 | 000,000,428 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{29B4A4A2-E71F-4BB3-91D7-16A36EE731FF}.job [2011/04/12 00:06:38 | 000,001,851 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk [2011/04/08 21:21:13 | 000,000,398 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{E6E841DC-A458-4EE4-8C13-43F9E7FCE5F6}.job [2010/10/18 11:35:32 | 000,005,056 | ---- | C] () -- C:\ProgramData\drctchbl.xvi [2010/10/18 11:35:32 | 000,004,110 | ---- | C] () -- C:\ProgramData\xqkcebzs.dik [2010/10/08 10:57:42 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010/06/02 02:42:42 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2010/04/29 16:12:32 | 000,000,031 | ---- | C] () -- C:\Windows\yesmessenger.ini [2010/04/22 14:56:51 | 000,000,338 | ---- | C] () -- C:\Windows\yes_messenger.ini [2009/10/22 00:57:28 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat [2009/09/24 10:14:18 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat [2009/09/24 10:14:18 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat [2009/09/24 10:14:18 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat [2009/09/24 10:14:18 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat [2009/09/24 10:14:18 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat [2009/09/24 10:14:18 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat [2009/09/24 10:14:18 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat [2009/09/24 10:14:18 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat [2009/09/24 10:14:18 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat [2009/09/24 10:14:18 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat [2009/09/24 10:14:18 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat [2009/09/24 10:14:18 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat [2009/09/24 10:14:18 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat [2009/09/24 10:14:18 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat [2009/09/24 10:14:18 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat [2009/09/24 10:14:18 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat [2009/09/24 10:14:18 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat [2009/09/24 10:14:18 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat [2009/09/24 10:14:18 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini [2009/09/24 10:09:09 | 000,000,027 | ---- | C] () -- C:\Windows\CDE DX4000EFDG.ini [2009/09/24 09:25:31 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009/09/24 09:25:31 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009/09/21 17:12:20 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2009/09/21 15:47:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2009/09/21 15:05:51 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll [2009/09/21 15:05:51 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe [2009/09/21 15:05:51 | 000,000,036 | ---- | C] () -- C:\Windows\PidList.ini [2009/09/21 15:02:13 | 001,548,099 | ---- | C] () -- C:\Windows\System32\VMC3KAPI.dll [2008/05/16 07:50:46 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat [2008/05/16 07:50:46 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll [2008/05/16 07:50:44 | 000,168,883 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat [2008/05/16 07:50:43 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe [2008/03/21 13:20:46 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIOFM4.dll [2008/03/21 13:20:46 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN5.dll [2008/03/21 12:41:33 | 000,204,800 | ---- | C] () -- C:\Windows\System32\SysHook.dll [2008/03/21 12:37:44 | 000,487,424 | ---- | C] () -- C:\Windows\System32\INT15.dll [2008/03/21 12:33:29 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini [2008/03/21 12:33:29 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat [2008/03/21 12:32:04 | 000,000,008 | ---- | C] () -- C:\Windows\System32\drivers\RtkHDAud.dat [2008/01/21 10:40:50 | 000,679,042 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2008/01/21 10:40:50 | 000,340,236 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2008/01/21 10:40:50 | 000,126,626 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2008/01/21 10:40:50 | 000,037,390 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [2007/11/14 16:17:34 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CogentBioSDK.dll [2007/04/24 18:32:56 | 000,389,120 | ---- | C] () -- C:\Windows\System32\btwhidcs.dll [2006/11/02 14:57:28 | 000,067,584 | ---- | C] () -- C:\Windows\bootstat.dat [2006/11/02 14:47:37 | 000,316,264 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 12:33:01 | 000,595,996 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 12:33:01 | 000,104,070 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2005/12/15 06:17:00 | 000,159,744 | ---- | C] () -- C:\Windows\System32\EPSPTDV.DLL [2001/12/26 16:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll [2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll [2001/09/03 23:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll [2001/07/30 16:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll [2001/07/23 22:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2006/09/18 23:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat [2009/04/11 08:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr [2008/03/21 05:12:07 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK [2006/09/18 23:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys [2009/09/21 15:15:37 | 000,000,020 | ---- | M] () -- C:\Medion.ini [2004/02/29 17:44:34 | 000,052,576 | ---- | M] () -- C:\orange.bmp [2011/05/06 07:59:25 | 3533,369,344 | -HS- | M] () -- C:\pagefile.sys [2009/09/21 15:08:45 | 000,000,058 | ---- | M] () -- C:\Partition.txt [2011/05/08 12:08:35 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin [2008/03/21 12:33:43 | 000,000,477 | ---- | M] () -- C:\RHDSetup.log [2011/04/14 22:24:05 | 000,000,000 | ---- | M] () -- C:\UsbFix.txt < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2009/03/08 13:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtmsft.dll [2009/03/08 13:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtrans.dll [2011/02/22 08:16:39 | 000,184,320 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\iepeers.dll [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav > [2008/01/21 05:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV [2008/01/21 05:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV [2008/01/21 05:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV [2006/11/02 12:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV [2006/11/02 12:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV < %systemroot%\system32\drivers\*.sys /90 > [2011/03/04 14:38:47 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys [2011/03/04 16:11:12 | 000,137,656 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys [2011/02/22 15:23:55 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\bowser.sys [2011/02/22 15:23:59 | 000,106,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb.sys [2011/02/22 15:24:10 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys [2011/02/22 15:24:02 | 000,079,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb20.sys [2011/02/18 16:03:32 | 000,305,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv.sys [2011/02/18 16:03:10 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srv2.sys [2011/02/18 16:03:06 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\srvnet.sys < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-06 06:06:20 < > < End of report > -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bjr à "lance-yien" voici donc le rapport Eset Mon seul problème actuel est d'avoir 1 à 2 fois par jour à l'écran un avertissement du guard avira avec blocage pour ma sécurité de l'accès au fichier autorun du C: ou du D: ou F:........que je supprime à chaque fois Merci et à + C:\Program Files\LG Electronics\LG PC Suite III\USB Setup\Silent_Uninstall.exe une variante probable de Win32/Agent.GNAJRYT cheval de troie C:\Program Files\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application C:\ProgramData\ReviverSoft\RegistryReviver\InstallCache\{E31E4E05-4B6B-42A5-8623-EB530F8147F5}\RegistryReviver.msi une variante de Win32/SlowPCfighter application C:\Users\All Users\ReviverSoft\RegistryReviver\InstallCache\{E31E4E05-4B6B-42A5-8623-EB530F8147F5}\RegistryReviver.msi une variante de Win32/SlowPCfighter application -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bjr.Comme me demandait Bleuet je suis à priori dans la partie "analyses et éradication malwares"pour nettoyer mon PC selon le rapport.Et j'attends la réponse d' un bienveillant .Merci pour lui -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a répondu à un(e) sujet de yugm dans Analyses et éradication malwares
Bonsoir Bleuet et merci de ta bienveillance Ci- joint rapport ZHPDiag et observations:pour accéder à des adresses internet j'ai finalement supprimer l'AV Avast et plus de problème.Par précaution j'ai repris l'AV Avira qui lui maintenant me bloque l'accès au fichier C ou D ou F:\autorun (à priori pas méchant mais emm....). Comment supprimer ce message de guard Pour info concernant une précédente question concernant superposition de lignes à l'écran jusqu'au blocage ,il m'a suffit de revenir à l'ancienne version d'IE Pour USBFIX j'ai vacciné mais je n'ai rien ds le rapport A +Bleuet et merci Rapport de ZHPDiag v1.24.37 par Nicolas Coolman Run by guy at 14/04/2011 19:55:26 Web site : ZHPDiag Outil de diagnostic Platform : Windows Vista Home Premium (6.0.6002) Service Pack 2 MSIE: Internet Explorer v8.0.6001.19019 Boot mode: Normal (Normal boot) Total RAM: 3069 MB (50% free) System drive C: has 64 GB (57%) free of 111 GB ---\\ Processus lancés [MD5.0D392EDE3B97E0B3131B2F63EF1DB94E] - C:\Program Files\Windows Defender\MSASCui.exe [MD5.250EF6EE2EEFE202E0B35B6EC583E8BF] - C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [MD5.EC9B27B37D8E9D361C38E8D364F09611] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [MD5.27FF6EFE1FDBC90F547F0A2E7CF7EE26] - C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe [MD5.E7E9B7FBE002E3CEA5CE4DF4C3084816] - C:\PROGRA~1\LAUNCH~1\LManager.exe [MD5.6B9CF3583B248D1C8215CFE6FF847F0E] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [MD5.9D5E8B45BD348DF0882C69EED0E83111] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [MD5.5D61BE7DB55B026A5D61A3EED09D0EAD] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [MD5.BF08674925F151BD4537B89A493E3E0C] - C:\Windows\ehome\ehTray.exe [MD5.2BAD84B393AF47006D80BA2F03B18029] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [MD5.35937EAD711207544E219C2A19A78A7D] - C:\Program Files\Windows Media Player\WMPNSCFG.exe ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2) F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=explorer.exe ---\\ Pages de démarrage d'Internet Explorer (R0) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Portail Orange : Actu, Sport, Assistance Internet, Web Mail Orange R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo! France ---\\ Pages de recherche d'Internet Explorer (R1) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local> R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6092 ---\\ Internet Explorer URLSearchHook (R3) R3 - URLSearchHook: Avanquest FR Toolbar - {6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\system32\ieframe.dll ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (not file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: ToolbarOrange.InitToolbarBHO - {1d970ed5-3eda-438d-bffd-715931e2775b} - mscoree.dll O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll O2 - BHO: Avanquest FR - {6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Avanquest FR Toolbar - {6ec85fcf-87ad-41d7-ae1f-f116f8ad4848} - C:\Program Files\Avanquest_FR\prxtbAva0.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll O3 - Toolbar: barre d'outils Orange - {c9a6357b-25cc-4bcf-96c1-78736985d412} - mscoree.dll ---\\ Applications démarrées automatiquement par le registre (O4) O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [eAudio] C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe O4 - HKLM\..\Run: [CLMLServer] C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe O4 - HKLM\..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui O4 - HKLM\..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [iSUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKLM\..\policies\Explorer: [bindDirectlyToPropertySetStorage] Data=0 O4 - Global Startup: Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8) O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\IETag.ico O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll,103 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO O9 - Extra button: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico ---\\ Objets ActiveX (Downloaded Program Files)(O16) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab ---\\ Protocole additionnel et piratage de protocole (O18) O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\system32\urlmon.dll O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22) O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Registry Reviver-YUG-Startup.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Registry Winner Schedule.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\RegistryBooster.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Registry_Doktor.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\User_Feed_Synchronization-{E6E841DC-A458-4EE4-8C13-43F9E7FCE5F6}.job ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP O40 - ASIC: Personnalisation du navigateur - >{8540E99C-8242-4725-A6D7-59D4F8A613C2} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - (not file) O40 - ASIC: Microsoft Windows Media Player 11.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\System32\wmpdxm.dll O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - C:\Windows\system32\regsvr32.exe /s /n /i:/UserInstall C:\Windows\system32\themeui.dll O40 - ASIC: Offline Browsing Pack - {3af36230-a269-11d1-b5bf-0000f8051515} - (not file) O40 - ASIC: .NET Framework - {3C3901C5-3455-3E0A-A214-0B093A5070A6} - (not file) O40 - ASIC: Microsoft Windows Mail 7 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE O40 - ASIC: DirectDrawEx - {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - (not file) O40 - ASIC: Internet Explorer Help - {45ea75a0-a269-11d1-b5bf-0000f8051515} - (not file) O40 - ASIC: Microsoft Windows Script 5.6 - {4f645220-306d-11d2-995d-00c04f98bbc9} - (not file) O40 - ASIC: Internet Explorer Setup Tools - {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - (not file) O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} - (not file) O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\Windows\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI O40 - ASIC: MSN Site Access - {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - (not file) O40 - ASIC: Address Book 7 - {7790769C-0471-11d2-AF11-00C04FA35D02} - (not file) O40 - ASIC: .NET Framework - {7C028AF8-F614-47B3-82DA-BA94E41B1089} - (not file) O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install O40 - ASIC: Dynamic HTML Data Binding - {9381D8F2-0288-11D0-9501-00AA00B911A5} - (not file) O40 - ASIC: Package Orange - {9858455C-0B8A-477C-A6AB-FB1E3267E8BF} - (not file) O40 - ASIC: .NET Framework - {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - (not file) O40 - ASIC: Internet Explorer Core Fonts - {C9E9A340-D1F1-11D0-821E-444553540600} - (not file) O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\Windows\system32\Macromed\Flash\Flash10o.ocx O40 - ASIC: HTML Help - {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - (not file) O40 - ASIC: Active Directory Service Interface - {E92B03AB-B707-11d2-9CBD-0000F87A369E} - (not file) ---\\ Logiciels installés (O42) O42 - Logiciel: ABBYY FineReader 6.0 Sprint O42 - Logiciel: Acer Arcade Deluxe O42 - Logiciel: Acer Bio Protection AAV 6.0.00.13 O42 - Logiciel: Acer Crystal Eye Webcam 2.0.5 O42 - Logiciel: Acer Empowering Technology O42 - Logiciel: Acer GridVista O42 - Logiciel: Acer Mobility Center Plug-In O42 - Logiciel: Acer ScreenSaver O42 - Logiciel: Acer VCM O42 - Logiciel: Acer eAudio Management O42 - Logiciel: Acer eDataSecurity Management O42 - Logiciel: Acer ePower Management O42 - Logiciel: Acer eRecovery Management O42 - Logiciel: Acer eSettings Management O42 - Logiciel: Activation Assistant for the 2007 Microsoft Office suites O42 - Logiciel: Adobe Flash Player 10 ActiveX O42 - Logiciel: Adobe Flash Player 10 Plugin O42 - Logiciel: Adobe Reader 9.4.3 - Français O42 - Logiciel: Agere Systems HDA Modem O42 - Logiciel: Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver O42 - Logiciel: Avanquest FR Toolbar O42 - Logiciel: Avira AntiVir Personal - Free Antivirus O42 - Logiciel: CCleaner O42 - Logiciel: CDBurnerXP O42 - Logiciel: Catalyst Control Center - Branding O42 - Logiciel: EPSON Attach To Email O42 - Logiciel: EPSON Copy Utility 3 O42 - Logiciel: EPSON Easy Photo Print O42 - Logiciel: EPSON File Manager O42 - Logiciel: EPSON Logiciel imprimante O42 - Logiciel: EPSON Scan O42 - Logiciel: EPSON Scan Assistant O42 - Logiciel: EPSON Web-To-Page O42 - Logiciel: ESDX4000_4050_CX3900 O42 - Logiciel: Feedback Tool O42 - Logiciel: Google Chrome O42 - Logiciel: Google Toolbar for Internet Explorer O42 - Logiciel: Google Update Helper O42 - Logiciel: Google Earth O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) O42 - Logiciel: ITECIR Driver O42 - Logiciel: IZArc 4.1.2 O42 - Logiciel: Intel® Matrix Storage Manager O42 - Logiciel: J2SE Runtime Environment 5.0 O42 - Logiciel: JMicron JMB38X Flash Media Controller O42 - Logiciel: Java 6 Update 17 O42 - Logiciel: LG Bluetooth Driver O42 - Logiciel: LG MC USB U330 driver O42 - Logiciel: LG PC Suite III O42 - Logiciel: LG USB Modem Drivers O42 - Logiciel: Launch Manager O42 - Logiciel: Logiciel de Synchronisation Orange O42 - Logiciel: MSXML 4.0 SP2 (KB954430) O42 - Logiciel: MSXML 4.0 SP2 (KB973688) O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 O42 - Logiciel: Microsoft .NET Framework 4 Client Profile O42 - Logiciel: Microsoft .NET Framework 4 Client Profile FRA Language Pack O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 O42 - Logiciel: Microsoft Office Excel Viewer O42 - Logiciel: Microsoft Office Home and Student 2007 O42 - Logiciel: Microsoft Office OneNote MUI (French) 2007 O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 O42 - Logiciel: Microsoft Office Proof (English) 2007 O42 - Logiciel: Microsoft Office Proof (French) 2007 O42 - Logiciel: Microsoft Office Proof (German) 2007 O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 O42 - Logiciel: Microsoft Office Proofing (French) 2007 O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 O42 - Logiciel: Microsoft Office Word MUI (French) 2007 O42 - Logiciel: Microsoft Silverlight O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 O42 - Logiciel: Microsoft Web Platform Installer 2.0 O42 - Logiciel: Microsoft Works O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra O42 - Logiciel: Module linguistique Microsoft .NET Framework 4 Client Profile FRA O42 - Logiciel: NTI Backup Now 5 O42 - Logiciel: NTI Media Maker 8 O42 - Logiciel: Notification Mail O42 - Logiciel: Orange Installeur version 1.2.2.0 O42 - Logiciel: Orange Plug-in messagerie vocale 888 O42 - Logiciel: Orange update O42 - Logiciel: PIF DESIGNER O42 - Logiciel: PhotoNow! O42 - Logiciel: Picasa 3 O42 - Logiciel: PowerDirector O42 - Logiciel: Realtek High Definition Audio Driver O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2289158) O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2344875) O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2345035) O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB982158) O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer (KB2413381) O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) O42 - Logiciel: TomTom HOME 2.7.6.2056 O42 - Logiciel: TomTom HOME Visual Studio Merge Modules O42 - Logiciel: ToolbarFR O42 - Logiciel: Uniblue RegistryBooster O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) O42 - Logiciel: Update for Microsoft Office OneNote 2007 (KB980729) O42 - Logiciel: VLC media player 1.1.5 O42 - Logiciel: VSO Image Resizer 4.0.0.42 O42 - Logiciel: Validity Sensors software O42 - Logiciel: Version d'évaluation de Microsoft Office Home and Student 2007 O42 - Logiciel: WIDCOMM Bluetooth Software 6.0.1.5000 O42 - Logiciel: YesMessenger 2.4.14 O42 - Logiciel: barre d'outils Orange ---\\ Contenu des dossiers Fichiers Communs (O43) O43 - CFD:Common File Directory ----D- C:\Program Files\ABBYY FineReader 6.0 Sprint O43 - CFD:Common File Directory ----D- C:\Program Files\Acer O43 - CFD:Common File Directory ----D- C:\Program Files\Acer Arcade Deluxe O43 - CFD:Common File Directory ----D- C:\Program Files\Acer GameZone O43 - CFD:Common File Directory ----D- C:\Program Files\Acer Inc O43 - CFD:Common File Directory ----D- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites O43 - CFD:Common File Directory ----D- C:\Program Files\Adobe O43 - CFD:Common File Directory ----D- C:\Program Files\Alwil Software O43 - CFD:Common File Directory ----D- C:\Program Files\ATI O43 - CFD:Common File Directory ----D- C:\Program Files\ATI Technologies O43 - CFD:Common File Directory ----D- C:\Program Files\Avanquest_FR O43 - CFD:Common File Directory ----D- C:\Program Files\Avira O43 - CFD:Common File Directory ----D- C:\Program Files\Big Kahuna Reef O43 - CFD:Common File Directory ----D- C:\Program Files\CCleaner O43 - CFD:Common File Directory ----D- C:\Program Files\CDBurnerXP O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files O43 - CFD:Common File Directory ----D- C:\Program Files\Conduit O43 - CFD:Common File Directory ----D- C:\Program Files\ConduitEngine O43 - CFD:Common File Directory ----D- C:\Program Files\Cyberlink O43 - CFD:Common File Directory ----D- C:\Program Files\Driver Mender O43 - CFD:Common File Directory ----D- C:\Program Files\epson O43 - CFD:Common File Directory ----D- C:\Program Files\eSobi O43 - CFD:Common File Directory ----D- C:\Program Files\Feedback Tool O43 - CFD:Common File Directory -SH-D- C:\Program Files\Fichiers communs O43 - CFD:Common File Directory ----D- C:\Program Files\Google O43 - CFD:Common File Directory --H-D- C:\Program Files\InstallShield Installation Information O43 - CFD:Common File Directory ----D- C:\Program Files\Intel O43 - CFD:Common File Directory ----D- C:\Program Files\Internet Explorer O43 - CFD:Common File Directory ----D- C:\Program Files\IZArc O43 - CFD:Common File Directory ----D- C:\Program Files\Java O43 - CFD:Common File Directory ----D- C:\Program Files\Launch Manager O43 - CFD:Common File Directory ----D- C:\Program Files\LG Electronics O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Games O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Office O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Silverlight O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Works O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft.NET O43 - CFD:Common File Directory ----D- C:\Program Files\Movie Maker O43 - CFD:Common File Directory ----D- C:\Program Files\Mozilla Firefox O43 - CFD:Common File Directory ----D- C:\Program Files\MSBuild O43 - CFD:Common File Directory ----D- C:\Program Files\MSECache O43 - CFD:Common File Directory ----D- C:\Program Files\MSXML 4.0 O43 - CFD:Common File Directory ----D- C:\Program Files\Need4 Video Converter 7 O43 - CFD:Common File Directory ----D- C:\Program Files\NewTech Infosystems O43 - CFD:Common File Directory ----D- C:\Program Files\Orange O43 - CFD:Common File Directory ----D- C:\Program Files\Realtek O43 - CFD:Common File Directory ----D- C:\Program Files\Reference Assemblies O43 - CFD:Common File Directory ----D- C:\Program Files\Registry Winner O43 - CFD:Common File Directory ----D- C:\Program Files\Synaptics O43 - CFD:Common File Directory ----D- C:\Program Files\TomTom HOME 2 O43 - CFD:Common File Directory ----D- C:\Program Files\TomTom International B.V O43 - CFD:Common File Directory ----D- C:\Program Files\Uniblue O43 - CFD:Common File Directory --H-D- C:\Program Files\Uninstall Information O43 - CFD:Common File Directory ----D- C:\Program Files\USB-set O43 - CFD:Common File Directory ----D- C:\Program Files\Validity Sensors, Inc O43 - CFD:Common File Directory ----D- C:\Program Files\VideoLAN O43 - CFD:Common File Directory ----D- C:\Program Files\VSO O43 - CFD:Common File Directory ----D- C:\Program Files\WIDCOMM O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Calendar O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Collaboration O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Defender O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Journal O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Mail O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Player O43 - CFD:Common File Directory ----D- C:\Program Files\Windows NT O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Photo Gallery O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Portable Devices O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Sidebar O43 - CFD:Common File Directory ----D- C:\Program Files\YesMessenger O43 - CFD:Common File Directory ----D- C:\Program Files\ZHPDiag O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Adobe O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\DESIGNER O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\InstallShield O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Java O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\LightScribe O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\microsoft shared O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\PX Storage Engine O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Services O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\SpeechEngines O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\System ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:Last File Created 11/04/2011 - 20:25:51 ---A- C:\Windows\System32\config.nt O44 - LFC:Last File Created 14/04/2011 - 07:30:13 ---A- C:\Windows\PFRO.log O44 - LFC:Last File Created 14/04/2011 - 07:30:26 ---A- C:\Windows\bootstat.dat O44 - LFC:Last File Created 14/04/2011 - 07:30:36 ---A- C:\Windows\System32\agent.log O44 - LFC:Last File Created 14/04/2011 - 07:30:53 ---A- C:\Windows\System32\LogConfigTemp.xml O44 - LFC:Last File Created 14/04/2011 - 07:36:41 ---A- C:\Windows\System32\PerfStringBackup.INI O44 - LFC:Last File Created 14/04/2011 - 07:36:41 ---A- C:\Windows\System32\perfc009.dat O44 - LFC:Last File Created 14/04/2011 - 07:36:41 ---A- C:\Windows\System32\perfc00C.dat O44 - LFC:Last File Created 14/04/2011 - 07:36:41 ---A- C:\Windows\System32\perfh009.dat O44 - LFC:Last File Created 14/04/2011 - 07:36:41 ---A- C:\Windows\System32\perfh00C.dat O44 - LFC:Last File Created 14/04/2011 - 12:00:24 ---A- C:\Windows\WindowsUpdate.log O44 - LFC:Last File Created 20/03/2011 - 08:25:51 ---A- C:\Windows\System32\FNTCACHE.DAT ---\\ MountPoints2 Shell Key (MPSK) (O51) O51 - MPSK:{f467d428-0987-11df-9c31-00a0d1a862d6}\Shell\AutoRun\command - G:\InstallTomTomHOME.exe ---\\ Trojan Driver Search Data (TDSD) (O52) O52 - TDSD:HKLM\...\Drivers\"timer"="timer.drv" O52 - TDSD:HKLM\...\Drivers32\"vidc.mrle"="msrle32.dll" O52 - TDSD:HKLM\...\Drivers32\"vidc.msvc"="msvidc32.dll" O52 - TDSD:HKLM\...\Drivers32\"msacm.imaadpcm"="imaadp32.acm" O52 - TDSD:HKLM\...\Drivers32\"msacm.msg711"="msg711.acm" O52 - TDSD:HKLM\...\Drivers32\"msacm.msgsm610"="msgsm32.acm" O52 - TDSD:HKLM\...\Drivers32\"msacm.msadpcm"="msadp32.acm" O52 - TDSD:HKLM\...\Drivers32\"midimapper"="midimap.dll" O52 - TDSD:HKLM\...\Drivers32\"wavemapper"="msacm32.drv" O52 - TDSD:HKLM\...\Drivers32\"VIDC.UYVY"="msyuv.dll" O52 - TDSD:HKLM\...\Drivers32\"VIDC.YUY2"="msyuv.dll" O52 - TDSD:HKLM\...\Drivers32\"VIDC.YVYU"="msyuv.dll" O52 - TDSD:HKLM\...\Drivers32\"VIDC.IYUV"="iyuv_32.dll" O52 - TDSD:HKLM\...\Drivers32\"vidc.i420"="iyuv_32.dll" O52 - TDSD:HKLM\...\Drivers32\"VIDC.YVU9"="tsbyuv.dll" O52 - TDSD:HKLM\...\Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" O52 - TDSD:HKLM\...\Drivers32\"vidc.cvid"="iccvid.dll" O52 - TDSD:HKLM\...\Drivers32\"MSVideo8"="VfWWDM32.dll" O52 - TDSD:HKLM\...\Drivers32\"wave1"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"midi1"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"mixer1"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"aux1"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"wave"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"midi"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"mixer"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"aux"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"wave2"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"midi2"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"mixer2"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"wave3"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"midi3"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"mixer3"="wdmaud.drv" O52 - TDSD:HKLM\...\Drivers32\"vidc.dvsd"="pdvcodec.dll" O52 - TDSD:HKLM\...\drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" O52 - TDSD:HKLM\...\drivers.desc\"wdmaud.drv"="Audio Bluetooth" O52 - TDSD:HKLM\...\drivers.desc\"vfwwdm32.dll"="WDM Video For Windows Capture Driver (Win32)" O52 - TDSD:HKLM\...\drivers.desc\"pdvcodec.dll"="DV Video Codec" ---\\ Microsoft Windows Policies System (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=2 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"= O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"= O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 ---\\ Microsoft Windows Policies Explorer (MWPE) (O56) O56 - MWPE:[HKLM\...\Policies\Explorer] - "BindDirectlyToPropertySetStorage"=0 ---\\ Liste des Drivers Système (SDL) (O58) O58 - SDL:System Drivers List - C:\Windows\system32\drivers\1394bus.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\acpi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adp94xx.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adpahci.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adpu160m.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adpu320.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\afd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\AGP440.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\AGRSM.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\aliide.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\AMDAGP.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\amdide.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\amdk7.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\amdk8.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\arc.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\arcsas.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\asyncmac.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\atapi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ataport.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\atikmdag.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\avgntflt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\avipbb.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\battc.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bdasup.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\beep.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\blbdrive.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bowser.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrFiltLo.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrFiltUp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bridge.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrSerId.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrSerWdm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrUsbMdm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrUsbSer.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bthenum.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bthmodem.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bthpan.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bthport.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BTHUSB.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\btwaudio.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\btwavdt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\btwrchid.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\cdfs.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\cdrom.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\circlass.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Classpnp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\CmBatt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\cmdide.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\compbatt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\crashdmp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\crcdisk.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\crusoe.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dfsc.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\disk.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Diskdump.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\djsvs.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\DKbFltr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\drmk.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\drmkaud.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Dumpata.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dxapi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dxg.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dxgkrnl.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\E1G60I32.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ecache.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\elxstor.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\errdev.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\exfat.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fastfat.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fdc.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fileinfo.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\filetrace.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\flpydisk.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fltMgr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fs_rec.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\FWPKCLNT.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\GAGP30KX.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hdaudbus.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\HdAudio.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidbth.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidclass.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidir.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidparse.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidusb.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\HpCISSs.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\http.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\i2omgmt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\i2omp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\i8042prt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iaStor.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iaStorV.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iirsp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\int15.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\int15_64.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\intelide.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\intelppm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ipfltdrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\IPMIDrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ipnat.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\irda.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\irenum.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\isapnp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iteatapi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\itecir.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iteraid.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\kbdclass.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\kbdhid.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ks.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ksecdd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\L1E60x86.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgbtbus.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgbtport.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdbus.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdcm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdcmnt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdmdfl.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdmdm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdmgmt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdobex.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdwh.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgmdwhnt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lgvmodem.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lltdio.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lsi_fc.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lsi_sas.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lsi_scsi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\luafv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mcd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\megasas.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\MegaSR.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\modem.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\monitor.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mouclass.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mouhid.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mountmgr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mpio.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mpsdrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Mraid35x.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxdav.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxsmb.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxsmb10.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxsmb20.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msahci.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msdsm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msfs.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msisadrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msiscsi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mskssrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mspclock.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mspqm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msrpc.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mssmbios.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mstee.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mup.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndis.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndistapi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndisuio.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndiswan.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndproxy.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\netbios.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\netbt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\netio.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\NETw4v32.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nfrd960.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\npfs.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nsiproxy.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ntfs.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\NTIDrvr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ntrigdigi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\null.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nvraid.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nvstor.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\NV_AGP.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nwifi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ohci1394.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pacer.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\parport.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\partmgr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\parvdm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pci.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pciide.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pciidex.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pcmcia.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\PEAuth.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\portcls.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\processr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\psdfilter.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\PSDNServ.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\PSDVdisk.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pxhelp20.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ql2300.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ql40xx.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\qwavedrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rasacd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rasl2tp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\raspppoe.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\raspptp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rassstp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rdbss.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RDPCDD.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rdpdr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RDPENCDD.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rdpwd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rfcomm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rmcast.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RNDISMP.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rootmdm.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rspndr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RTKVHDA.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sbp2port.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\scsiport.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\secdrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\serenum.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\serial.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sermouse.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sffdisk.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sffp_mmc.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sffp_sd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sfloppy.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\SISAGP.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sisraid2.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sisraid4.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\smb.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\smclib.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\spldr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\spsys.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\srv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\srv2.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\srvnet.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ssmdrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\StarOpen.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Storport.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\stream.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\swenum.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\symc8xx.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sym_hi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sym_u3.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tape.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tcpip.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tcpipreg.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdpipe.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdtcp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdx.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\termdd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tssecsrv.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\TUNMP.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tunnel.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\TVicPort.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\UAGP35.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\UBHelper.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\udfs.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ULIAGPKX.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\uliahci.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ulsata.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ulsata2.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\umbus.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\umpass.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usb8023.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\USBCAMD.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\USBCAMD2.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbccgp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbcir.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbehci.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbhub.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbohci.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbport.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbprint.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbscan.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\USBSTOR.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbuhci.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbvideo.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\vfs101x.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\vga.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\vgapnp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\VIAAGP.SYS O58 - SDL:System Drivers List - C:\Windows\system32\drivers\viac7.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\viaide.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\videoprt.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\volmgr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\volmgrx.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\volsnap.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\vsmraid.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wacompen.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wanarp.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\watchdog.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Wdf01000.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WdfLdr.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wmiacpi.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wmilib.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ws2ifsl.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WSVD.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WUDFPf.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WUDFRd.sys O58 - SDL:System Drivers List - C:\Windows\system32\drivers\zntport.sys ---\\ Liste des outils de nettoyage (LATC) (O63) O63 - Logiciel: ZHPDiag 1.24 End of the scan: 742 lines -
"logiciel malveillant bloqué" par avast - RESOLU-
yugm a posté un sujet dans Analyses et éradication malwares
Bonsoir à tous Impossible de me connecter sur certains cites ce soir car l'antivirus Avast m'annonce un logiciel malveillant ou cheval de troie et me coupe la liaison .Avatar ou réelle infection ??? Comment le savoir ?Suppression des soi-disants fichiers infectés après le scan mais rien n'y fait .Un passage de CCleaner ne me rétablit pas non plus .Merci de m'en sortir -
Bonjour Me revoila ,et tjrs le même problème d'écran saturé et bloqué.Cela m'est apparu depuis le update en internet explorer 9.Ceci explique-t-il cela?Par contre ,merci de m'indiquer comment changer de pilotes graphiques dans la mesure ou l état du pilote actuel est correct -
-
Bonjour Ticlou Pas de "jaunes "en gestionniaire de periphérques ni à priori de problémes de la carte graphique ATI Mobility Radeon HD 3650.Peut-être une autre proposition ? Dans l'attente de ta réponse .Merci
-
Bonjour Depuis qques temps sur mon portable Acer Aspire8920G ,en changement de page sur internet ,des lignes se superposent durant 3 à 4 sec puis l'écran se rétablit tout seul.Mais le plus inquietant ,qui m'est arrivé 2 à 3 fois depuis 1 mois ,c'est l'écran qui subitement se bloque avec plein de lignes et plus rien ne répond:le processeur se met à 100% ,la souris est bloquée,"alt ctrl sup" ne réagit pas, il me faut alors débrancher la prise de courant et la batterie et ensuite je redémarre normalement Merci de me trouver la solution
-
Bonjour à tous 2 problèmes à résoudre.En 1:apparition de cette alerte :"GAME/Download.Gen" par Antivir avira 3 à 4 fois de suite puis plus rien durant 3 à 4 heures et ça reprend qque soit les cases cochées lors de l'alerte.Comment la faire disparaitre définitivement ?Je vous joins le rapport HJT En 2:problème de transfert d'1fichier ods (open office) en fichier xls (excel de microsoft office) Etant en open office,avec un nouveau portable(Acer type Aspire 8920) je dois le réinitialiser suite à une erreur Windows (alt F10),donc suppression de l'open et je me remets à la version essai de Microsoft restée sur le Pc.Dans l'ensemble le tranfert se passe bien sauf pour 2 fichiers dont 1 ci-joint transformé en ...chinois? Comment le récupèrer?Merci de la réponse Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:12:41, on 28/09/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.18813) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe C:\Windows\PLFSetI.exe C:\Users\guy\AppData\Local\Temp\RtkBtMnt.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Acer\Acer VCM\AcerVCM.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Acer\Acer VCM\acp2HID.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe C:\Users\guy\AppData\Local\Temp\Temp1_HiJackThis.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [bkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [skytel] Skytel.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKCU\..\RunOnce: [uninstall mes données] cmd /c rd /s /q "C:\Users\guy\AppData\Local\Temp\OnlineStorage" O4 - Global Startup: Acer VCM.lnk = ? O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O13 - Gopher Prefix: O16 - DPF: {6EBC6744-5383-4213-AD5E-66434ECA1812} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/nordne.../fslauncher.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jin...indows-i586.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe -- End of file - 11311 bytes En 2: PKÑz‘:…l9Š..mimetypeapplication/vnd.oasis.opendocument.spreadsheetPKÑz‘:Configurations2/statusbar/PKÑz‘:'Configurations2/accelerator/current.xmlPKPKÑz‘:Configurations2/floater/PKÑz‘:Configurations2/popupmenu/PKÑz‘:Configurations2/progressbar/PKÑz‘:Configurations2/menubar/PKÑz‘:Configurations2/toolbar/PKÑz‘:Configurations2/images/Bitmaps/PKÑz‘:content.xmlí}ÙnI–èûý ^7¦áª"“±äêj×À°$WU{iXp†QH“)‰mŠÈ¤—yœ/™×ææÑ2_r#2I*’Ê”â$OnT3¥Î…'"ÎgýÛ¿½žö>G‹åd>{þ„ZäI/šæãÉìòù“ó³“ÿäßù?›_\LFѳñ|´ºŽfñ`4ŸÅâoOüz¶|–>}þdµ˜=›‡ËÉòÙ,¼Ž–ÏâѳùM4Ûüê™úö³d¬ôÎ2þ6Õþyò²úë8úëþX¾›ùmøQääeõ×ãEøE÷Çò]±¨êÏ/æº?þºœ.æbÕ¯oÂx²Å×édöéù“«8¾y6~ùòÅúÂùârHƒ &O·¶ïݬÓäñhM#9ØrH-:ܼ{Å¡.|ò]¤Ùêúc´Ð^š0ïìêÍ"ZŠWÄt%bê}HýM¿>_jc×çË‚e]…m<K^΢ ë£ «¿½ã«‚ýõ‡oÄÃä?o^ßâÕâZw,ùnf©F‹Éö4Ó·ÕßÏçó-¨ò)±'à2Bìaz¼ýåÞ׿,&q´P^Ýûú(œŽ¶+>¿Î[4ñŠ7Ñg‰ò["’±,ø¦·//Ç…Ÿþo^ŸŽ®¢ëðöåÉÃ/&³eÎnWf!7¡p¦ÎpÝÌñva.ô™¯Ø-¶e|n‡o.äùÃd,õCIåCù“¿<陸"9Ø“_6b"E‹åp{ãBˆ‹ÁE8Šãh4]þò·”Ü··{éµüù“‹I8¥Oz‚7o\O¦ßÖž5~Í ÝËüV>\F³h1ˆµü2Y.µ¾¿ÇçÕ7n&ñHPöçPüVp¡{糉ÏQïÍi oæËŸw_LïÞÜ·e]ïÝYx5—X¦íƒ}GaÓú~¸ŠÅ@ñd4H¾³E³ä¿XGsºl e"Ü럮®gO6¿Ton‚ñ$Zö.æÏ>.¢ðÓàc$ƒø zóÅõë_&cɶ©åy|tÀ¯€sl¬.ؘEl¯6Ç¡0Øìú`ã܃ÁæÔu6·.؈å0›W#-P l~}<Äe@Ô·n`°QR#1iÖ& €Õ&l‹QèŽÖ(¸Y´6¹¤QZ£Pà`B¨M*IÏA’~Q¤½-æ_vwT¨ÒGòæU4¹¼Š¥Hâ®Döû^-#q&Š'×át þ:^¬"Ü4\ nÛáµÁ]@Þåàfµ]@øåÀÜÚà.à¥àv¿4Üát ¼€g”\p».Àã0Ÿ¡ln^‡âxºÜ„—Ñ ýÅ?Äÿ<•Ïþp.þx-W‹h¹3Eez©áx<YÞLÃoktXZ¸&³ËÁµ8©?2]â¸óŠ&ÜÇG'ƒWG'Ä'A°ç3 ìñ›€=Ÿ³Ã~]„«i¬ jŠÀXS“ûÚò>¸ó[údç¥Þúj#¢¥ ½'›'דÙ`2‹£KñÅñär‹§4:g4 ˜.lOÆaåÀoçvk,š/ÆÒW‘bÇú©4÷†ñ`9_-¤ckÎ.Wb7Ÿ(#|n/¤Wé—á¤äróìz>‹¯ô^ý…ef·“xx^îóRáÞ¼™|AÌm>»|˜KùŸËùüºÌœ½®Ì¹`~…ºwTt¦[óM¸~Øäâ^#´«˜'«4ø8cé#!ñ…ŽÐ[Χ“qï/$ù·g< /ç3Aš§ƒX¬ìl>‹î<‹Åãí³Û¦ÑE\øùÛשÌÞýu<¿)úñÖ-—ú®!µ‚/“ÙX(‰©X7æ‹,ûO~8_ÅÓÉ,Úá¶É#y_-æ«Ë«Áz×Õ©'ßÍ:äÉÝåä?Ä]JnbåÞæ‚«L“ÛÉ(Ë«p,`ê—“«™X†ÌØ›Ï}Y«9çÓq"9ö \NÂÙõa‚+ë§P”çéW7/Üù¶œmâF_7ËÎàÛ †ß>/`ûJ‚þ‘5*²`ÍÞÔ`pÙà2—‹jÕˆ€\<n†ã'7;@~ 4‘ƒW*Uø{EÎ@²ÈBëWtQdË5tñˆèâ^Y±Uì+*ö§ ¨¤(r"Šh Eõ©~õ©ÈyeNÐ9uAR3Í…Ú´äø¼a÷ºÓ)ŠÎ©Œp§½, 6ÃÌ+ŸrŠbÇÚªQ†£O—Éfã[$ gËÄGªsÊi„r #ÛJ:Ž0rc“8œNF8Œm@iì0V@iŲ0¦öñÆ:M&ÆfQéù«0»22!¬åd¢½t]v—íÞ}à(—³i•ª×R1/.]7 a†7À‹»ìU1Ta¨¢ª¨×ÒBªÐ^©ŽÓÛNåÆ T7‰ïç6Ùà_‡™ç2Z»u"Z¯¡»º°v¨m½†ÎнkÀ¥Ëw¦i/]•Ö°G$Œ%·~K.«ÝDÕŽ •-¬^‹TÅÆ¼JWj?‹T¡ÆÁºuÞØÏ¬Çö³W«m¤y§džä¿³¬¾g"aÌ9BP]6uàM§Bc¬–Lª´su“L´—®*K‹Ù`G&¯‘<ÖµèU#¸q)%Y“‚WÖçÔR;o¬ç»FO¾?O}?Cp¡£Ü9HZÔ^×ý¬ÄµŠ4¼ªûÙ/Ùª¹aäFerc?û8"%6ãdx0<ÖDg[¤*r¤<hPØ›TÌ)¿<ž?:ÁQ‘§Ë¨p†|ù¿–¡C#÷ÓÈ~NÒ"&}v9ývs5˜/&›N–ƒÏòù(œ&¥¹ËÒ’‚átr9ÛÖ¶¾˜|Ý<]D7Q¸mîºEf,_áMRižlù@^ï*p÷¢Ñ(ýí4^lG›¯çÎ.%f’»$ Ù ,¯“Ù'AÀƒ‹I¼Cn›uÚün[ú–ÊŶ…—ö«¶u».fIÏIqû:\\Nfî3Úv¨ËVd—uÞ»ÀH(mš“¤4ÆJ †¯”—Täå5¼ä1òñ™5ãøËÅ…º*†w"ï¨Ò•½N®Yp©;*¶É%¨?—Àî| ¬îX™úNÒ1óW*ìŠ"ÌЬº.ݧeÿé4MsOÝUoR›!C4@4]«¸eˆÆD¨WA8%ZØT§ÑLȬ¡+CW-¡«Š1Te¨ª%Tµ_ÀÈ=ÒÊ5tuxte¢èk=…u-ýÚП±¡·Á†^es¨}èãü¦w«ÅÝý¢ ²þŸ.”el; ËuÍôã ÅŒ2µÆ¨zû™œŠnЈ1&Ý¥”Šê/jµCF†ŒòȨ5Å"ê*ÕÛ ÍPJGÂô •=õ÷§„PýÄRo?´–6´¡½RùK ÏnOå6§¢œlú¸Wµ¡ìTãZì fi\ûû(¨`£bEnsÆkæj¥•R[{‚i÷êHj¯e{’ۚȻg;í0ÙjÕéîÉj:<Ùkì«ØWÝ®ÙW -µƒ–Ì1P¥¢†’šöV[»ƒÓælÖÀÙì1”¡…ªj/]eÕI‡÷‹2·¢ÝRÔ¦’»XYG¤êjÚ<@ìÐò¾”êU.{q[É0ZÓÏaRXè}+GÈÅÅ®\×l;Òá~‹\yÏRsÌÒ«½}•¶ÔÃÜ¢®·÷Hõ4EjpGê ši3}«Ô±ÍYð~2©÷,XqlÙ¾tÉblµ|áT:ôÞàºÕÛQ¼™8‚Na²ßùÒá5¥¹7¸EÕ÷¯nÏ\;n®@ôcv?»éÑ”ï¹Á-:¨:©pÿ¨ç#ܽÚOåÝ‹žÍß³ô®±f=Nk–ß„e$×ÂñÎGâ_{L[DD¦7(áLDUšªºAD‡7jˆ¨"ª×nY3~ö®©vÑTµ‹ ^û²¡œ.RŽ‘6Yš©ºf…´Ñ^+LÐeׂ1º£K=F— öðÔŽ:„[N&F»C»ír ðãL»5 m mEîËÇå~~d4dN%UTó1:2tT–ùmèè@éÈètY ª×¯ü ¥ë€“ƒ&¼us¤NeMPrPiºGõök‘%³½[R¯æ@ë›¶o[»–bêç[o”tÍ¡Ð^Jj’v¹ZI¡MîQ—Ë&îµGí%›®U¨iKŒNð¸u‚ê,e(ÆPL Óš†OmÎÅ5$„å%¡íÁ½¤”îgæ.MH{Ó‡ z6„èµû :*<ÒýœÝ‘ꀼf#æ ßÛ‹ïuÍsSi½µŽ˜.iל º6 Ž*>ffÎ,¹ÔÑeçK¢¿IVQ;wjÿÌÖèr¢êšû¬šBò]gy{Z‘+÷(6°kÑÚí%C#е@cMÔŽj'·ëŽq‚UÔàÀTûÖŠ/V‘•½ý£½²É-î¸Ñ×èFÿ¨Eÿ¨¨kFgDYnr™1JÐÐáv.9¼¶†”Ud—§f·ªØÃ-bRÕniô¸¥QkR)ZBf4<CSûÒTk’-ºkhhP‰à …øÒöø¨9 oEòÀ.$`HüL\å˜3’†uq0¤¢B힤±Ùã!k“ÌØ”¥¬´,%厯Sçl«ªD¼ÙѦv´¡Rå{0FÂÜ‹ØHqÖíÆ"sh¬øÐØD_ævJµnŸ>»îÝ"íÄð·Ãåovǃ·›IR><º0IʹÔd2.'÷ã]ð¦–wÆR{ ùbG}²þâ„q9,ç«ÅHÒéäëæé"º‰B9ÕY, Ù’°¦¡Ew^.›«IÞ.×TÀ·H¾|..'³ ]·ÒciWi /¿¯‡½æMXU/ò8önUŽH¹UFÙT†EéÝÖ:«õªZë•]uy”‡(ÖðÖÝi²ŠÙ-ènU]e£›;Òr©b¬=[{ª¶f·Sܵí$Ãk0¾·›¼°ÁÍrŒæíæfÁõ¨—Seìn›ñþàìÂN•vá–ïä†áFäþÎ#¶ùÞn.!‡¸¹õ—‰Å\{tÝÏWâ».WJÒ/“q|uÇ´ó·ÈN}q!kN#Û›agÔ¹pëØ©aƒfŒÛ»c‚f‡‹ØÐË]z©·Âõ=^ŽÃÅúúÎõ:èZ×鱉ž¨‡G úçÛ„XM”¦>lÄzœª¢ú¥+²;<k" ÛàQ5x¤¼hL·fºu›ˆ0×!Ô†cÒ7((ÜŠ*—¯”m¤Èá!Ykšž;TÛÏ·bP¬#(ftáÖ…›«zcH±½á`ns½P Z<¶· ï‘A6#´Á¿zLèa$•M„Ç•ë-Ô݈(X‘Û¦™ÁHP¯W¬é˜#^µ‹ïÕ„^[/ °á#ð¡êèUìû£Û¤Šœ %žÙÂz¶°ê:ð³IÊ‹ÆÜ}`æn¯jsw;C<«®Ù`уa‡Mî_C•àjÿŒ8;`qVQ#×’ :J!Mr¸ŠòôBÍ"ì`ÝöÍö:ºkûì´Ïǯעzp>è„vÊ,ßãô4Þ£}¹«ßš™Œ¡íâÅuaV½ÕàÛᇪœÕ–À¬&:®8f=NÕžÚù‘̹ãzv<Füа1¶ÕñpîG‡ÝæBMT2Øf²¶ØñkƒËF¥Ûâr+‚µÓ<ê]e*˜¦wMAúGÔí2´kºIâE"Þê»I4yj(ÊPTÕ„¯ëÒ¯¦£Ô##MÓÉ>—@›p“5jd烤Yw_ƒ<JæL˯‘®uH׿œóµSìp•xΖéìŒü5$ÜUn.Ž¢»BרüÂ$“µBAÞ€Ò˜‚\À rÝÒ×bhÕfk8ÌÖŸƒJ«š!6e|™- ö‹;Ù¬àÝ<vR³”ÃóL9!R¼§cQ0ŒÏ0¾[¢bd¿€CT†¨ÌѼ€´êMKn3ùd•øGC-É¢¼’D1?®âyÁë¸]#Í$¹–õ33Ôh¨ñScEßÔ-÷&;£ð™SÓ÷‹…(-wÒg—Óo7Wƒùb"¾Æ“ùlðY>…SÇMY€¿,›ÁüF‚#?8×!¿[ˆÑ(ýí4^lG›¯çÎ.%r’»R°:åÕb2û$$ßàbïÜf6¿“üÿZ|i„gq^ôe1‰'³ËÁõ|,¿ /£6ÌD‹™4TØ0“Cd&·©²:ËN}Ã<yTT ›ë´àÀ>ƒc¶´Énf#‘ Q©DÕ\ùC8]"ãÉ%ŸFë—Ú2´uÀ´UQPLCY†²ÚCY´¢ÈªÕ7ÅÐV×h˸k>•Ñýâk0MÈÉ©{ÆóÇ¥±lèÒP— ˜¨£6«VÐÒŒ!Ã’!¥æH©¡ˆCH†‹*Š¡ˆòYËöHj¼\Ü9Â&Ñ!“Ñvñ××*´ãEøE|l1ÿ¤X>_®oml b]˜›„ŒÜ>RK“ËEJ¾t.>‰eŠfãçO®—/‹ù—ãÙøFþpî¼qûqFå·w§±+[£@šð˜Í'b ¯'I|Kòðb2n0`{cp°"ÿŸÈMx®æ‹Éˆ¥¿´ù×jO.¾í¾¸#0aýŠ4Ä.ÅLWkærktŽÇ2¸fsšvÜu9ùÍåÐçÙwï<¹E×í£LTSÒ”®ØšQ^MÆãh¦Nÿ¸ƒMÛx£->A"Ò_dƒ¦‚ >êR³ó¨a8¿¸˜Œ¢gÛø¨”ñ,ùÛúÁÇùøÛöby#¶r¼¼Š¢ø—¿%¬è™ØÒÑjšÆh-£XB·ìm i¸ŒfKóç[Y—>¼ðBÈËÁ4üM—;ïHiºˆ.ÅçFc/—b˜í[à É׿IWÿM´\‰×7R™iÒÍí›Åä6´m;ÉÁ÷åâ-®U ç£ÕRÁLùðæfúm0Ž–2‚.Ý<¸$®g9Œæ[Hf«ë‚lÓW—ƒ4ø.KÆìÍKãTL¤Ü?O~ì,H*gÔÅ\J“€â{ÁáÜ™•üÑzÅ>‡Ó•ÐY¾ÝH‹E½”#l|vóËëùìr½Ñõ߆ë{âì|©Ü·û“~º‡þí×áâR|öÝ7“º îìÒÛ¦1“ñäZÒ œ^zKЧü3zþÄÐ|'ÑæÁð—éüòrönæbYM-&ã(\¡.‚‹IÓy(Ä»úDp1ŸÜÎL\ì½ïù£P¦ŒB6x¸XP’4§â“S±Éç¡ÈD=!:â46·÷y/¢^Ѝ“çûí¾î‹ ÜÝQ¼Û1¼–ï¼–øh®-C‰i㿆7óåÏ‚¥ÜrœáLò˜Þ•`æ§aŠ}¨+¯-¾òÑŽY¶‚w¬o·\,ì+«…ꇳ¸÷ý¿zâ4%>± ØJ¹€íÞ‚l»Ø[áï³Ùï‹÷Ô»ŽÃ‚VqùÕ;Åê÷ñÑÉàÕÑ ñeDÔ] âuHgeõï{F⛼‚o–>{ÜóM§‚oê¤e#¤X1ieÀ‹èöûòÝÛÓwoÞ¼8ûíÝÛ[ùøâ¼÷’qÖ{ý¢÷þÝË__¿>¾}Èñâ?A.¸£ýàæ³íÜÚ¯ºäžW+bÔ€Óž±ƒ¹|®Wjïª1-tk]=ÒšGR¹ÍgŸ£…<÷ÄðÏè5NiŸÛ½O_®žR>$¾ø¿~Nnò§46$Á8p>°9ùãŠMð¹Ö*ŸNâUb ¼ePB±gCJĪž6ýxºøÌfž{Ç,²Ö}öw†Ð4 Û{ì84ƒ²ãTË)hÏù=ç({ÎõåÞÃèÑf¯/Ëö›çRÞ§+d_u–Ç ¬/2Ã=0I±vŽâU9“IYËœ\Ç¢íy1ØØP¤¦JÉ€(‡wâJÑ Ÿì¹¯c?_ÇR†Â¸œ|µä>h‚aÜB³Ñ>š‚ÆÛ¥@#d¸]𿙕1½‘nìÔèu~‹J¹~JSSþ8',¢š#iŸ”²GîÐO¾Òž%žås7¼¾Ï÷‡² œø–£P‹¸î;´ÚÜR‘âºß2ƒdâ\§õ_µõÇg%õ msDuz™S«Ë—Êwô†ïÆádZ+‡k6äo½[rc«qê•‘aÿøþçb2á‹óÙ,ºŽfq›ìkA)χá*ÀR¶l½µL2 I ±bz‡N©;±dزT¹aÅxɨn»ô6Ž‹ó/çßÿ'î]Å¥\”{°3ýxËU¼¾[*žDçÆçêðŠ`ö®(ÚªÛ”UØêûêìKñ›nBü¹T¬N$@,5r‡ô¡¡;û’Q8H¹ø}fÏU+CŸ#=àêóÌôK±€ŽA<ª•¶2 a5 Ÿ?™_<{þOë%e~’øýò3'{å`_áQ áBÏR£ãú¥âã4á;Ná;ÂÇ3²–#0šBORO€{̸ºÇ¬MĈ|y9¿¾‰KFQï#–rvK:úô7)y{; yU¯¼²m¢Ø^åU½Ãö<…É«šÇlu|qÕ""A–XÛ3ûËùl9o—\GsãŽëÑJ V†+êÕm$ð÷5tC&ÌW½hO®“°Goì‹J8S/šõÞ ª9a*:Œ6/Tš©Ö;•2E˜‰ž’ßq ß>® {Ž%ësá;Iá;†Ÿ§:¢½RºPÇíï_®Z 4KD÷?üH©ÅóãÁòÑɶˆrãvŸÔlî¡6QŽ©ò !ˆ¢˜äÖKÑï÷2&1y£BOJÀHæZTGamòmWåE~ª—ô8òˆ8ª)O^£nÊ63e‡úôeVêNx@›}ÄÚѲùŽÚ#ˆÂÅògr ý°Nûá,}‡?¡l;‹På¬Í#2ë\Î'µû_9-TX‚?Š?ŒL&[½d8*‹SxŠH€<ésË£®ÂÓ|Þ÷*JgSE¿¸ìÓÊNO©Ë\±'b9~â„$ÿ“~ø ªPnWUù(ï—Súº¡,¾ÿy¹š!¥cûÇ£ÛLôÝ«•ib|™eS'ÃQ|önGdLP,@Âo ±(³®ZWéS† è9~Ñq¯¤œPË¡Tq)‰;}¥‚yRfA¹c1æSÕ…*îµËEyO(,Bæ ‹ÙoÃÊ]m‰’È’a¸ í…«ž3$¶GòÚøÞeÈfðTšJìC—üÈ€2°-ŸŸoÿÝ.ìÀnUÌ™!Ÿ²Ë³snÓ’÷gïÎ^¼ÞŸËÊ)ð"ÏÅK×2 ‰ÙË;±lGU()™á²³ù-H6jA®Q¡ì¶Ó¸¢ôs!;Æ}Ëu<ø®ü§ž‰¸ßwÛdÁÕ¦µý2éw8”¿×ÇZĕ﫞s›Y^9‘c¬r"L:¿”\¥+UY™Ž6UçÈç¼CUϾ¼Äµ…,@{“¡•9Ä&“Uä(Øg[õñ'—}Ÿ1Kl´™ié増º`úN§‚à‡k]¨¬‹rÄZAxØ€ªÞ|Š–~ ‡¦ÂZ.¼HZëB5"ÚÝÂÔ Œ¢Vàie•qÅ}Šác†˜kËSµ§ï!h.ÄúîZ®b-fn»NnÚ^‘|ÖP”&Ò[DÓèó÷?{›áv„Àq‰¥¬Dcuò¹Z®¯†ßÉ˺!hF›—ô‰¯#ÄQxäe‹è§LMfýã~;=©ª„‰£_8¶»õ8sœ8–1¤€[îŽÊ“'´ªsšs•ãa&8(6w–ØKœÜnèÖåq½ N†?e÷l”ä]´€/åk3ŠBY®vÃ]î”ÞßÂá^’Ý$þ<N®zw‘2&sá;Ná;ÁǘR|C\TßI ß1lý²%Û¤§¢SY7r,|’)—"¯ˆpü¯ †6¬ƒ„!Ÿ¸mH <ðœÊ¥ƒø÷èëSMTYÿÒfI?!¸e¯Û+u뾑sTÂ/€“!ü6Ä8D¹åx™ÔDÞwòþ ¡<N¡<†Aé[œøª=Üïs„XÕB(OR(O`PRËcj]-JÁé• ÏF‹ïr}ßÑŸßçGFš_qÑ¢¡bªú–éã—…Rj3\M•R p+©jš.‚GVIõ©Ýwìáõ|²Dh}`Z Úë–ŸÉñïû¸ù^‰ÐKí.ô1l|®](ê!‡NÐ0Šn—•{TSÇ7‰;WÒÞ÷TœCˆíô†²£X½Ä“¯]‰s’€çÇT©†¯hÀ3ùóXNøû`„iÓÄò\’£Lˆ Yê”ö1ÎÇ.¨Ò‚%@Ú$€¬Åá×hÙ›ÎGá4Z¶V*©åQ)FyTÈèÌ¢Êð¬OkßåêønÍä 6‡o!t»Ì7ÔÆDe¶Aa[–KUû‹a³€µ\E§²û.’º§?5ì§ß&Ðo¸«•Ë@>Lmkˆ~œ ÀÆÒ„5¤U™ÀÞº<5IG®…è8?ÈŒaHë°mQ‡/?a˜âÖôjsnš´1¼à±$ipº³¦;MþøéŸ ù《C µ–ºªbÃPZø‚~”‚~”‚~”‚~”‚~]†ÒSU-F ¦/ý8ý8ý8ý8ýºŒÁgª ) ¿ô“ô“ô“ô“ôzòbžxãPæ1×ÝÍÄT®öKÓ\“Ûé‹·Æhk+¬z“„3Þi:.%ÛñÑIï•øÿgj ôaa¶ƒã¤e"|±r‹xj[^¶üš&”G)”G ()÷,Âh¦¸‘‡Rè¯ÎãÎcØjÚ¶Åi†÷Ù6J'›B8OR8O`ëéR‹z„0gW…OJŸ*"g@ÎÚƒRz)/p+éeÁÞ„ß¾ÿ‰À(´«$g°&½œê³BÆÛ¨™ëÏPb³x.}xÙÉ®Ï~_¼§~Üulï^pPlP½2é^Å#ªw2ßÝ|2U¨¡Vø$Èã9q¸ÝÀA÷±`òát P׬AŠˆeOþ÷Y¸Šç2Ÿa4¸˜VËÍ«ë‡77Óoƒq´œ\Î×óq´y¼»ùÉópi¾uŽ£‹p5“ìh>àƒ»hpw}}ì!=ìê@(K5ê1ÐùbNÉÖ{Ö™àòá½cøƒVðItœæè_´Ñ¿è ±Þ@ )·ÖEÀÍÚrV/tëÝÛÓwoÞ¼8ûíÝÛÛ Ã/Î{/g½×/zïß½üõøõëã#Äû§ }XŸÐWN‚‡‹”éGŸR€ŸÚ¥ÇÑ«¾”lGï÷óßÄŠŸ ^¼;?CXí,/|××÷£Q_³Jƒ6Šm&…gd…•Æqí>Zß#’l?ÂÖÇPD½Ý¿¯Jná÷e¿™ºú–~ê, ¿shˆ¥wº…Q/ÑÓd‡óèBïÍgŸ£ÅRV¥Ã?£×ü9¥}Nd°äSÊ“Xrÿ‡^rÓÞÜóå=PØ2}“4%¹H®ýsV¦¢q™TV_Æ£#Iò‚Æ`»y9aE7ôéP¿|·l¨Ï7â=ÐÓ¶ZD;v/C'?'7ùÓMAµz§¤‡¾)ééqÈÛš[…&\õd…oˆáÝðôõ9OÏ<,ƒ;¾sÇÑ´¶¨í0ž¾O €Þ©¾NáAL˜¹_ŸcAŠ¡´°ŠÁ>¸ŒWü·T¶™çÞAe•ËbIõßör,—Š8–¯—UøâíÛó×ÇÇûèŸgkÙ^VYp\ÕÓlÐV½ŒZ|=£T`Õç¶õ±Ê1b~‡B9 …òû(¦ŒÂ˜Àl£·[ËÕ$Žzñ÷?§ßÿ¼A¨±#À¦¤Õ5–0jµ‚5„¦ö}èÒNrÖª6Š]} ý}=·âd,Ä M{OÓ7 Æ$nRcL=I:^‰9bԼЯ·1QbðUÿ˾ÀZh¨ZÇ—53p¬…•1ÙRótÅÿ)IÐ.¢UÄÉóÉôàý&ƒPÖà@½B“L¥z^]Ü@ëÁÁHd¥l ÖÝ h¥846á(`XJÕx)À*(Lx« Œ~¥‰’ÀHÇRë–:N¡øF(PI×bj•ºÀí3„”sP§€AmN)®qšSB’î™kjÃæöŒˆ‹®Ñ•i@,ÇQq‡ô„r‘0ÐЂ’ À"™>çAŸ {zBgx£™5eeIAxXUs[PsúŠºÛ‚ª¹q+[›—ì3ÜNÑ_S@¸¾¾WÂ8«À¾»&AÚÈWb1R¦¿zICt]w£"ÃoÀvG¶;7ƒÑ´TS§´ŸZ…ªÉºb4ŠÍ^Ï/‘xÒ*Õµù šS6ø¦i]ìºþšUÊɶ„6nj× wÃ'(c„…ž³>´Æ·KS»ËB/Nç–pºxRMŒN¢ÛÃE±GëZ.šæ¤ŒäÛ?ó»h}‰67Tö_¢ fÝýÞ •Õýo¹R±íÐU¢¨Œj¥åfÔŠÜñËS¬fNßCÀKÈü›ßµTߪÛG‘²ªG°ÔV¥ÈRáQsý [qÔþ%VÁÑ®`Þj—·d“Œýη`Ì&9-up´Ÿ7z–«”9óPêUi pu|—Œ5D 0Ü Ùûêìq{«´^uÀ)P_ aL‹‚Ò¢¢4‹3u|Œª~°ù7>~fý9ÂúW¦4`í°-Wóò3óªÝðP °™7Cͬ@)h7׳3To×+CH'5ÓAÇwˆ: fŸazåz¸wX!ˆG% ʲ=¼J/ˆJ ަ4s4Eh[S–›Ÿêø¼öØEÁöU`mÑÉòür¬¤¯@Z2‹©MˆXŸaø¬§çožþÓzMÙ3ñþáÈaŠ9êiŠÕ§Iï™Ñ[9£·°‰ãiætÚR…¦f®ÍHþ:ÿÓzO™ ¬NþžBúÁû™ØN%´³ÄÓÄSˆžÚ-ÐÃèÈ‚øÎRøÎ€ðñŒ ã°Xáy á9p“Õ®~Ÿ=2Íêåüú&ŽVõ†XW]V…~ǵ󊼪[»ÌmªžuåÕþÀB†gj¶¼ª_w¨*Ȱ.QÁÅ zÈáz²®ÆàŸÖïÔôR; a`³¶×£^S°pÆœòmeK1ÚDƒÌ¶MTœWõ lÏSt!yUóøŽ/®—˜ÞƽœÏ–s#¬s–(©W®d|‚–‰!¡ï@È·1H(nÍF»¡ÆzEqÁb#¸u#è°æ nˆV,nH0Ã!Q޼ºƒý}ƒ»+!ç«^´Œ'×Ii¼VÒ@*Ÿp‚ Ù-cB?{sÌΫ=e h“^†Èšµ¤Ízo£prÉ73úŠ¥\\4p„IìXգ·Á?W uÕªP.‚ä±ø~Oáû _¦NJV·ïPV¨¸÷T+ª‹bDmƒa”Š«E\´ÓkÙ ·Òg «@:NåâîiJ\ïaÄ•©©…QP«À†+½‘ |§ ø¸jÊäX–Ì\øÎSøÎ`ëç©ÌÉ+Åœ@Yøû„êÓÑã¡åU½_\–þºÅaqUoÄÕ@ð}%H(¹¬›SÕ##®ZóEƒŒ¾ (Ì-T8ü?R*CÏ!<Û³²l%ì«H«|E«ñ[úçwñTb{\…U^ãhHúôïSÕ‡*®ˆ(Óf\ q‘W-W¼šàü¹Xú¾%qÛ"êIÎîc¸£@Îbj;å…ijÍ"A¸7ã^&£@Þ@ˆT)ÖÃà0 ´u-ª²mv@õõr¥:üT7EŽXÄ!Ê>‘¾¼®W˃‚6¬B‘Y㣆© BéØÜq|ßÉ”2—×®Åå×Ù)žñ,À²T“Óá~–œ|ùú ö¢¸‡e‘)”QŒc•ZÏz'»²A)ÆwG¤@.˜Y 8À¤[ÃRµ^ŸXÎ'í.zAÉÖHg%ë¢JPÇ·U}wü~P]O¤|óŽïZêB\÷+ìËTPZÝÏœÄ5JÖqeFž °|Åë}#¬ µòcªüØ^ò?z¦ä{˜|q¨Uss\¥8F¢ŸÃ-îü$–³ —zÙp‹eÚ‰ð~¹óÚž H΄|ÏrÄ„¨å„õ‚Lj’¸.™œTV[9Š.ÂÕ4Ư¾ùðCM_‚JbÛÎJâÇNžÖ ¶?¾¦ù¸Œçy,®QäqÃÕ* Èá™2¤ƒQ€ia°#X¸‚Ó]3Šp‘÷= >ü(þ0É!³³ÕÞoÉÎ]”Ý{šBy ‚Òç–G]åØåó¾S{E¦š‹ÅeÁþVZð”ºÌËq.–ã'©ÊÿI!%(åQ3[Å’J~wå`n»¨Ó ïþ[{Ϧ6·œŒ[‡÷êúó6=ËxDŠÃË”f”7Pª3‚ΦŒ¨Å%FëÂêÂh`ÙJú(îý‚³é?ß/ú‘Z4I}jyÜ·]O9•ú´ŸStŠ$Ðë“ÚƒÅ_·ú#¤eåï”,?#fõ“üÃ>ü]`•‹¸ 9vk•®&Ï<ø'^羡»+ÏÞ½x]«.£$qĸ¤Œ#jC‚7+ëj›äq ä1HÙø6#ÈÝ>ÃPV×ò$óf•½qóÁ|•‚ù f;ÚçBÔ8æXª/J\÷1üa´0ú÷t]«o[D—¬B`÷1¢@ “O|R!HfõH{Ärì¬FÐHïà¢ðÑ·é¬ÞŠYÁ'—4Îhx}†!Ax®¥ÃpkôëÞísªÔÏ=̧À^cS'c®A)áK‹hãTè“`e™ˆã%³žAqÆÄ(Ø(¦‚øÅrB-‡ªèâNßAÀ±B0ÏË,(w,Æ|ª:úĽƒ*rðN=k¢û±@?5u\Z˜©uÄv}’þyÅ@ ŒïXj}+qÝǨpuànœäx„³ ÈAw÷ÂÆv²™ü>9ý'çþ^¸êɲ,Câ=ï z̹NBŒý«7þkx3_þâvï{hõ8JòÕ¶ , ²£&ï+fÔ O1¢j%ùvSv®HÛP• êð%Ö:Câ`öÑß›ÙÓþ2x*³6ì²|9w~mù„ø|ûOArûp)éK/ÀT@ôýÛѬ7›Ç‹¨w~ŽVyý¿ÿùß,F_úû4¼§Bû¯Ìy&þãBÜ«Ìu3¢Ä5J«¨¢2¿4¾ê,@EÇ—ßAðUjú)2|üʼ$'5ýó»øHhó\Ëñw 7ûŒ[wP¢¡é6÷ 6ò`}F„z´þØ}aHž‹}ÝA^iËÓk”䢾GЧ#'‡û÷0VO,ÛQ-”ô1* l”x?ޏÆñã@v¾¥.‚¸†²f8>Oí0çéŽÝbµó-×ñXà»òŸ¸Áý¾{0IÈz9…/ß½=}÷æÍ‹³ßÞ½½µª¿8ï½dœõ^¿è½÷ò×ãׯ1ü'˜&BT†^Ê‚ñqµÊô¥¸ÆÒuÌž¥gÎ:>:A°LÙ¨–)À»Œ`žIy®lm7îïªz뺶9 Fá>i!%jZ–O'ñjkW¦öøCŒ\I@“H+ã¾£zç“ËZlÜÕrÆä$73ëÇ(d°0UH8ª³"¹¬ØCÓ2Êð6²všµM|GÍK. o;$Þ¦× ‹µ4ÁZæfëc bn¶Zð5¹4Ì=QA0ç¼!î=Ä]øGýó#w¹ä‘€³7–îÙQ¼ZDtDß1«g|ßšûÆâd•*©Ú‡¦Q†”¢Œ9ñõ|ʘ´ Nøî IÏ´š zÓvnÈ‹ÁƱNˆ? ö€ªù+Tv¼’Oê`Ú›íæ« Ìݽ3wkî^~Véùõt&‘ÈÇ$@òÚÄ÷Éç=÷/0%»,8!Î3Z†ü(ÛEA¤{v~Ó}Ð" Qý›V×=¾6AšÔüû°šñé5"|3ŸÅ!Rð,$P÷Ìåd*;;.Fƒö“¤ÈÜL¡Aq’$YF-_WBû>FxU‡+XK Ïd}Œäª²&™cÙj•Ó·1’<ëT7 F²•09N!LÙ¶DÁmKm2Âì>F“‘"•BŸ«õ¾ÿWï&üÁúØkŽ™¿2/NY ™[ í‘+SÔ)èS$çÔ:ÇÊô¶qúÝ=\Hª¤k¹j6”{@17zâûåüú&–1Û‹h}þþgoÓ‹³Vëžøj6¦¼DHÆ„¤ûžÀȲA@µóˆ¼Ä§ E¼ì6 äVU‰Ù^y‰!Ò!r6àvÆú/.1‚Ü÷Ó\@=U°ÀWg .14Ú6Ëì£Rúd|ÐŒfl gMïïFsHÉÍjÜòŒBâz7Ó7W^"ð}Hw ÓÜ-¹DÐW Í”qÔ^xò²åúʃ#\_] ]=¼vàz,ðèûŸq8™ÖÍð´'H/ä˜.\ã<®>2¤å¸Ç|ïð؇fLÚ?¾ÿ¹˜ÌÇQ/éÙ†é.„Ip/\I¿‚.Pp ½3ª-\yCZ]MÞÝ1å`é<+<iæM”‰QYýÎê‚Ãå%háŠQl¦uZˆõæ''®‚!J»>Í®mr´tÓ‘ŒÀ:ƒ2?ŨšÝ'ÖC¢7RÔxщï.ÚIçc9›™²û)·ñмÊz“MWîa¹õæ¾1Š´º59(tò p@hŽ;9JºÊ·AŠtBÏtAÇ0^‚âPT烼ªÙe•q™a8Ì@îªAÆý3ÀñþTÖÅCÝ*Šâ%¢…ý;¸ûAvà⺌)#âÇu/€Gœô%ÞÉVëÝ÷UÐDÌ‹áº(:N”óÕC+ÖÁ*gÇ’¬¦AºoJ(*Ê£4MÑ”ÿm—ŠÛÍÆò¹åÚiJhïaûæªñ¸.F¢ºÇg)|§@N¥Æ•a à}!|ç)|g°õSÅ"-'»¬±}ÿŸ¤=âðÓ—«zI ;‹x¾R›‰ôåõþàTÃ=‡‚Ö®,ÍTPÀ\û†ô‹Êæ© P˜:Ãú|Â3+*®1´€ TÀVâ•Á¯íØóxÝU&֖륥¢cõ‘M?ü¸æGú6n1ª¦”qŽÒ¬-(ªƒ|\Êõ-ß÷UkŠÒ ²p1OÊ€É<‹q¢æRx%»á”?¼ vZ/ u^€º´#ÔRŒR”Fß”µYý]î«üauÔ³\¦¢õPÊï-«ß¤³|›¥mq–éŽe÷9ŠÑ¨ˆÈÞ¦`¾…)©’«GXR²³xõWòÁ)Bý÷éj¿6·l‡©e¯ú6F»´"Op?Ê?Hq*{—“L%c”æå¼oÏR(Ï`Pú'¾J^~Ÿ#HÚB(ÏS(ÏaPRËcÜÏpd¯h§V(PÈt_ ô¥(à«ÆeÜûûqýfñ‡ÚÓpÀgï[ÛvÒ1(ÔínÃ5äx·`H‰¬% ŇôàcI<fQ¸Ažà„¸Vƒ`ƨêé 4ágÔj’8óÆ)‘Y”µ™3¦/ÇÄïF,o»œ\<§Ï¤‘¼)çBÙÍÞ[ÞUgDï-Gzt½/7~§¶8¯ç“åm ƒüæs–ršöû²¿Ä¯ PPô\ÃW;W¨öK1’lYZPÕ²À€#ÏqŠý%™ªšL ºVÅVÁð S¡¦r¡rUÇn€«BÊÍQÛR½ðÔîc8á!Q¬fACá…T¶ªb|·(@ö̆œá€Ö]ýd4Ÿ‰;Wõg{<ä*&6ÄUgùyÙªK?.ðgi@Q©¥ÖB¡ýr¥PöÉ) –£¸K¤ï´$K¹ FÄÍDˆ 8Mt£”y€ý$*FQ¤Ðõ)GÄRcüI¿ö ¾ €S{]n8~JúUzÃÞ§/Wõê4ŽÏ5î¦>ZÈâÓ€;êòcÔÓdù¡;[aÎYby.ÉÀˆQ´¢ "çǨø hT~’ª÷©Gzqø5Zö¦óQ8–µËØ™ŠÄ6JAb r£ÌàÌ¥KZ™|I”>ÞPåF¥T¡Ü`ju)“V@3ê0†î‰c™ZÆ¥”qʳÔôdÖÇÈO†e(f´'Š£=U ¼4ÇAA6KµÀôk¶¿0‹z*2QŒ0Ðøn†1Ž:-C¥¤G¦_|[«Uø–ªûú}‚< ©¶¥Ö.Ø}ŒÚÅpU®àbp`†¬Á„¶Û`Â3ÇQ€ :…m¹Žª»[§NÁ-O-Þ÷PâN:Ëö½Ái{S…NQ3ׄÉrµÖG¿æÖEÜr©ŠB.F6`|A‚~†‘<9úóWkž÷E› zkï¿ÿy¹š×ýûz˜í9™~XrE•âŠüAÇĤ—ôSsvŒá—gÓÉ,ZÍÆ Pƒp<^DËåó' oæËŸN¯ŽNˆG|¤·¬Yÿög_å£kõî7y—É{ÉPÿ1˜ÌÆ‘|u}Cöå‚®ïJð꣈'ËϗϾÒ$•Ùò‹òƷ䆰ͯL#y#¹Á\OÜØ¬ƒDëíÔ÷Ò®L8ÿŽø&œ_ñ']®ÀFóŸÍã°ÞÚê…YjG6ÿð“ü㦼ôŸþ" ¬T¶Š$ªáYv‹Dp«EƒŽSÐSÐSÐSÐA ?(ГORØORØORØORØOìòC •š¤Í=cƒÄ±ºÎàU:ƒWé^¥3x•Îàpõw›[b»}â Òl±šî–•,NÏß<•)Þî3ñŸàÃ?ÉÁ™CŸé‰”E¿oÎE~ù»t¾oä|ßü—ó}šoÒŽ“WÑ3ß•œüVüv ð[ØÉæj8ZûÎüˆ7Æ,'‹*‰ß0ÕÀêjEájkÉËErIJÃm~ˆÌÃp†ÄÁIˆè–V”·³ƒ§2CÚýð#µˆãüDWÎêˆ%ßüËØZi)ãY;U4@âëCótœ ~‘ &N¬‰¼Oþ¼_=Çr©j÷#9aat.»UžY-ñ÷·[ri™³6$^ïyoÐcŽUëEqï§÷þÕ§Æ’7ío]‰ç+ËRÁu~r,ÒîÔ²U%¦o#5ÈyäD}×Á€(ô>Ĉ @B-v”Ô.Šf½Ù<^D½‹ð³l,+®ÿ÷?ÿªFkˆ‰³¨´á¯“z¯ä”áB'Ìè Š¿¨j×o -¦¢3uáþƒ®²#tQaÁß[nñoéŸ_Å@èç–ë©ÂCÜé»0ŸO·˜¸ž7ììÝÙ‹×»è–xaûèÔxö>5ž½OgïSãÙ{ñLÍ]êfúIô]„°BÐOSÐOSÐOSÐOSÐOa º (ËÒÝ‚~–‚~–‚~–‚~–‚~eŽ©Ð¸ƒ²Zúy úy úy úy úyj/>‡15f9”yÌMÿyvüh±ZPÉ>«NÀëµòÀh奵r”Ca‹ÚÃë/¤O1‘PO-O$r/½Zö’?£t˜ã£“Þ«£SÀ~˜Ýiå«»RGc\Uã¶c¹>ËtörPb¤ ÕòÌß`¥C3ÆqdŽ(ÔÏS0‡I¹ÐÓÅrz™"̼OQléê¿:nº¤n 2¤š€KeÜ ñ3 ‹›ÐÈææ¹{Qu…w,9¼é&ŽŸÉ¦q|œtš@¯æÕƒ\©÷…/i{{HÑâ¾Oχï™a:Ü"S#³9JÍéb0OS0OA`RîY„©§q¥ :/ì•Ây[NÛ¶8ÍlœZã…pž§pžÃÖÓ¥õaήsO<)™aÔ"EÀ×èÃ=†K¹…zD•lXƒÃ¥Ísn¢FÓtÉVg¬»Ý¯]†“Ÿ²;Û›ðÛ÷?QT*Á¾ÿWOŒ-˜œ û$[²Ô¸O²ûë^Iûyµî€½·ea4Ó‰Ãgþ¤tÃc{iÚB9”(Ť‹{@ÂKàY”©G:q§dB‹-({–Ì+±¾iæLLO-"n”Tváy“Âó6=0¼åºÄâQÛ*‹[}ŽRá°AkãY2×dæïSë?w n=B-ÇÉL\Üê;¥<{»p½Oá:€Ï}Ëñ¨j/·Jö0¹™9õ23 Pï!bI‚J–dÇò‰i&wóbvåÁëù(ŒÃÉ"BHÄ´ºE±ñ‹M8sisF«íÀú÷éÎdø1Èw!±$€ïºú†©B´zÚªªR…àÁZu†( ^T™œÛ9—D¦îé…c¼ ¯0Ž{¨ S"å!ø®_d÷{ÂÛŠŒè€™hl %išVÕøý°s€ßzÎÍ—+±w=$£ê¨9@BL•ú²ƒúEÙOu’w.¤µ£ëú–íïŠ{×ïÛ™T€õXk½"M盇¹ Dä$ÈifÊŸ5A}Ÿ‚z 5="Ú<jùC"˜RöªÙï‹÷Ô»ŽN+Ø{€bvÍ'ÚÂÕ;™ïn>™Œšæm\LÄápxôlx4dÇr¸.†ñÇë¼÷ò×ãׯ?ʺÖ|¼Lö—M½ÿ6gBRn W7‚¯Æ•Âé2Ú™ær¾ZŒ¢Þ×édöéÙÕ"ºxþIJî}óÑô÷éX9 ˆYÅbÑÖHNG[nu=Ë[ó›ob)—«i¼ÌgÓow¨>Yî<ëڬߧæÞd;3Õ>ŠìÀÅ£VñM^Á7uÈ—‘²ÑÍ£ !ÿÛµ@æåD’Æ&i¯Âéd-zâætÍzÿÙôÅö°ã—èÉdt5s†>h|Ì@°W“5°šÑj2迚 /kÕ:Ý+3ÓÜZ¦Sûˆ¬Ðüúõ†\FÒ†kt]Þ,¢p¼¼Š¢øöæÇùøÛíÕxMøÙÚ@üýåÿPKøÙ^¢>÷iPKÑz‘: styles.xmlí][Û¸~ï¯t±TÖÅwoì`‹Ý´Í"ÈfŸŽDÛl$Q ¨ñLû{ú«úKJRwYÒЖ4¶g2A&yxx.ß9¤hùèí»ÏUî! öת92Tú6v¿[«~~¯-Ôw›¿¼ÅÛ-²áÊÁväAŸj!}ta¨°Á~¸Š;×jDü! W>ð`¸¢ö ÐOŠÔ+1UÜ"˜ÉÄÅÑ>PÙÁœ¶4ÜÉÏ,ˆ‹£²ƒ9-³iqøË~]m‹5{ ¨"Ń‹ü¯kuOi°ÒõÃá0:ŒG˜ìts¹\ê¢7ØÎ肈¸‚ʱuèB>Y¨›#SOi=H¬|œ¶(’ywH›PpäÕ€À‘0u9.åÇ”ðu¿“F×ý®ÁÌöiœ â2TÆŽ<TÆNq¬è¾Á¿ýë¿>ü+Çñdçâ´%SÙÒjÆÔÅñãLT> v!®e=¾.PZÉQH äv+¹ \;³8öêŒÆèLQhðžC>¥&\éFÎSÀ𠲕OvÌ:V6‹³Ù4Œ2 (æ*rÐyTé|ÈUI’f!Q[ê&ÍÊ[Ì2òØPs 톛·q4eÍJ|Íå\«¿\SUÒS ¹I‡ªKŒ¶G+¥±¼GÛAÄüPJñïÀ¾H j³À¹l,f©©•?}ÄV?¨|ø£FŠ@€ÃŸ«„qk»p!…^é>ƒ=ö@LYG×Ùõ&4%íñ’ŸJéÀ-ˆÜd#rND¥fC×USò¼IC9¡ˆmRV6òëpÙ¤áZµr[€€ÁþxãÈ&Çæ Ÿï?XPLm/ÍWûãB¿Ú¶xåkÛÑ`ãȧ„)óþ“Z¨± ~-baÊ,¥ûöðv%lÓûð˜=_€\øPõmÆ6ë¯aœõ ÖÜ5þ’q¢0;²3&×E{ò=Í*Ü4’RMlŒÆÌ ui§”¹ó@Dqî\ä@“7ØgF ߦ‘XòµëfhGܙѵ;Û…”…M{øÚÂvdšÇœ·VfØ’'ï@žùnW0árˆ]ñ¸!,"[à0Ìm]§U;&£jl{Èm%&·±‹Ùþ‰’ 4Öd¡Ïˆ:Êïð |bñ%’átY ›*Dßx<Y•ŽR¶Tk_!ñ…•bÙ“qž)îI@{ˆÁ2C|-Ób%ÞÍ&›ÚR¬ÄYäwC)É•‡|†# wlœƒvˆ²ìfЉjxf<ìˆvöX7•i,>©÷ØeÀç70ÂØ B§×vñÒÞÁQ»RÏØso”Lqy,û£w‡Ý”W@)mD›ÿýç¿Ç “MMÇ)S›bOYÚ›íÖ`?U%µz%_œ}cóx ÈÄwP|çuÜþøÓ;úó:7±¶V¦ÞÑW³ïà>Ñ`ßÁý,àžI»y‰0M£+´~L_´UlýÖŨU%µD ¦V~^{j½n3‘ùò¼n>sʹn€˜2¾’¯G€ŒûHƒ©Õ‹×ǽ>yy^ŸÜæNd €L:Dâ.¯m'õ,•ýôžÅGSJÝK. ½ªkÉyW;uV{õs–ykÖ”ÊÐŽ'¹`h…äÆP‚•û4+SŽÕáÉPÏÜj2N–×ú‚+Ó÷ú£³_}¥ÃóÔiãÓ².ŸÎýħ@Jñ)<p~|Jœ"Ÿ=í;ú[M˜º†ç5ª+ý§££koë³5»XüÏú‹ÿYOñ?ëÿc‰£¶‹ÇëÓ÷ú@¿ú^Sèm06.•ÆFo)@€±‡ œÜž(ò`½!ÍÜ̇…aêRA¸V]ì搜\Õƒ%„\ô&ú‘,âå!Å@ëÛ€B û¾‡dëòâÒ¢=ŽH('ì5j;~g4…³ù„àm‰f’‹Úˆ…"Ú"[kOfkú—záC€}þ€‰üÃmâNeO'Oäô.BÌd…(Ä\VˆÙ€B,d…˜(ÄRVˆÅpBL© 1PSVˆöî&„u}ÅáëO°Sþtügð9»G‰üÞ°3óØŽg¯z"àÖo(<B@ çºÉ¨;¿.uÏSbq†Ï`ö¦ý“xy†Äƒì‰î§Þy»Ÿ)HâJ´;kÇ×yšájšƒÅœ.s§çH?ßV±çûªÝÙ-Ñ×¼$MÛA8Ý5í+YoŸÄõs’Àu?CÇ‹Öq¤¿Ü@ë ÷´ëC Ó¶§^>&§è¾©Ç§Â\·ç$ƒæÏzúÆ\oŸ„ô†¹s¶ç?H³®@š¿b tãóœÉëº17å-˜½=/È•¿Å× &Hè%«ù3Ï—%ë¤{ìÜ| „:«Û·¦mOÂ]é¢Ù'ê¬[Ü~ %«+”žïâ ¡tÒ1Ä nÀ†B]×#ëYX'Y\ËR8ÌVÞêzaM_1¦×š½®sÓ®˜{Åg_Ö÷³¯2:éŸ}YßϾÎÂ\׳/«ùŽWº`ö¹ß?ç!‹/ƒCmâ]¡ôšQ“ŽQopó5꺞¸¶|ËäJÍQ7>穦‹/…AiÜõuÜ\%æ@é¤'Ànp6êZ+ÏÄ þk\Ú0«¢x^ÅV‚ã"ÛpÑÎÏë'Ö{'™ªRvÕ¬V›\äÕêEVûÊeR³’Æ•Á®gåŸ0Ñ'¶[(é É*ákeë¶à4–Ž÷®UD™ý씟 Ž|’¸ÜhLb9 $äðÊà¼HjEyMÑÜèˆv{ºVï°ëœjë,ë” Ë«¾W¾óe,rOýOø[ úqL¸… °µG„מݢ¬v(ÙWóÒïjeb×´e&Ï™®U› „¤9^*EXgIÖ:ätsfbQó,“¦î8-_ø;.þÒ8RÔöùʲø<þB>üæ;_,ãË4©+ì eéGJ£Lã Ù÷þŽy1bÅP,Sü{FnSÖÌ³æ½Æ~}òT ]'—<¼<&¾¥©MvPcBàˆ–¬ú!ðòi¢š”ˆHÈš9Iœ½6˜7‘ŸWÎ-)v‰Fïrà왪)?iÛbÌ«ñ–QÅ—±}‚c4Ÿš¼N3odǺ\¸ååF’—[ï0¥¼¾¾‘UÜÖ›EJd¹€˜52–åÑ%á`KÎÁ·á=Þs‡‰ÃñgŒŒÅÂö±ì(oñ#(àÄ/…a$æ"ì¯|ûã;éRóÆ6øŸÌ> ¶¹ÚÁ#¨ézXºV‹õ€ìñSÈ®XÄM–ËzxÕtÅö6GËZ‹'í/&9^}fì;-NäÒ"ó§Æ_<¨¸JFv‡¥a‚ò·þðW®€è‘à—]h¶Ï¡˜4Œ¿~‡â•BqzÅP4F‹ñ¢Þ4£¹iÇ¢rŒCUü F*;ÂV/|÷oh³Öo`ME„£Ø3«!.ÍEƒa/„æ“d=Õzã-GÒá0c‘݈$œSÛYO1jîTbólÞò»ÑUüî!Œ©7ïÞ½{«W“– ⌊ɹùÒ»þøÆíè¾9¶M6ûG®Kr‘£c¦óÚŽDHY•ŒÞ*‚~dǧLû)yX‹e#˦;~'Ì:ÑØÊ1EÔ-’Ä×?¢4S©IÀ¶2;ÿÖhãÑŒ¥*QœXz3Œ¥fL4s®n̹nLø›Ò–‰œpó7%˜IoÎW–µO2¡ëàS–ïb˜Rô"¡8Þ,—E¸í"ØãzüÁ¯¿L·_>À0"0{ïYù\$§¬Õv\ìÖ=ÕRDƒÚê·_ßkÿøõ½±àÚíUCZk³Ék±Ùœ×•³Y´ÖfÓ›´™^¿ëõ/ÆÝüPKÆcr¤XwPKÑz‘:6.•Àƒƒmeta.xml<?xml version="1.0" encoding="UTF-8"?> <office:document-meta xmlns:office="urn:oasis:names:tc:opendocument:xmlns:office:1.0" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:meta="urn:oasis:names:tc:opendocument:xmlns:meta:1.0" xmlns:ooo="http://openoffice.org/2004/office" office:version="1.2"><office:meta><meta:creation-date>2009-04-17T17:22:34.84</meta:creation-date><meta:editing-duration>PT00H00M00S</meta:editing-duration><meta:editing-cycles>1</meta:editing-cycles><meta:generator>OpenOffice.org/3.0$Win32 OpenOffice.org_project/300m15$Build-9379</meta:generator><meta:document-statistic meta:table-count="4" meta:cell-count="660" meta:object-count="1"/><meta:user-defined meta:name="Info 1"/><meta:user-defined meta:name="Info 2"/><meta:user-defined meta:name="Info 3"/><meta:user-defined meta:name="Info 4"/></office:meta></office:document-meta>PKÑz‘:Thumbnails/thumbnail.pngm»ePQÓ5ŠN‚; îN€`ÁÝ]îppw8¸Kp .'¸»»œƒ»Üäy¾÷¾ßºóg¦jOõìÚ{º{Õ½#å%Q?|„‚‚B•–ú®ü÷Þ …ÿ÷i\ÆÅó$ý]DÕ#ëLOÎ’PòÝG_J,¯Èï-3Ow –x¸îN"öP‚4n‚Z÷T «®Øt?Þî= ˜¥@xY4xR"=bϪBT©dßã?s%¥*kÐäŸsAÙëéËz• Ó³±ëβƶúúúßÙÕë9›a(]<<ï.½Å'ÐC|ÒRì!JÃû¸t"lÐ(Ôt·Â<ÆÒð¯6<7â¥ÃŸVÉSÆ’\§\J_¤%b3y5MS´†Ä^‡|à¥^FS.ÇÔ\·Ÿs©ŽªC†ì~(MZ |j£1+“ògªz¿æzÏkIâeviÚÛµ‰¹ÙjSëÇfà+]+VÁÒ)è<Žéþ&¼[áq›fˆ<«|p¬iï†Rà&.àùﻢ$õLÒ•G_½FœÇ:ùÖéí[˜ÍbBšGÍ ¶\“7‘çÎl²çÂRü(»ÙÑQ0÷šÚ¢6̽õŸÀ]s”0•I'1làgª›!ÔÖœi¶y4FZºÏA9ßo’dT]ŽÂAnaªOn/&V7ŽsÐr«—´×l7tB®îiD´áÑ#’6Ÿ_1‘ï]E óœa-‡WÇSUìò|hC®`ûjÁÓk‹“šâ9xo%JvEwTÙ(…;þ¢:eŽŠ~¹†·þQb7Žo•'Û¦ŽõKŒmöš¸ÚÎ=³jŸD¥Qr–·§±bº=ú+ÖLǰ<ô›Ò—ñcÕí?õ/äKË@zØhE—L7ifÕþi;‡œ3J{3Å|Æ™_ŽO°W4 o·«>ob¢7o±«ç•y9[OO˜±»±ÕùÛÖ3¡júØÛ'Ñm5~Þýê§p.Ãï–èþ»Ô§ÆÓÇ39 ž|+ϸó»—áíE=Ù6憶3 ò_šz¨›ì>òJfDœ[ðu¢£ Óüª˜¶ç^ãàú쪢5“ÌÔq š3r~…up¼Œ¡ížÉ=å>®Æ:8ÓK“’ÒÞå¦~˜vð:•<ÜÈ!óåUj”>¡Ís¯{ ÍØ `¤ôŒ¤†\ O¥Aš¢`b2ÁçU7ÅAsµˆÓ Õ¡Ï7ÃâdïC%ʺvÿôˆ¨q+5?g~û±`XµJJììÝšìáJøÅéb³z¸³w§Bî_qÑ.ôÞæxD &¿+Áë4}ÐBCâÐAðZù¯TGô'å û;LY3o XÞ¾öø|à=xø&FþËÂ݉Uܦãjþ=Wµ<gÐX†I“êîüwì!ö›Î ëJŠåËyš¸>l=…8îÁ-Ý…2å—á W¤|ߣšK&•-Â{)*yC.!Àýð Èv¦wBÌcÂ7k̾“Qh,žÌýmÍõw[€!÷Ìg‰uRÿF¤Æ÷—ižx«T8ŠØ=j¹@:VçØ Äà¹8¿nR!žBeE Ö1h»heohÂþ’•?"U<ç厦”ó³ÁŒ¨¾(«ž|ãö&W”ˆüñwujlâ×DzÖ³oà hÕ_•í‘˨Wå¦@\C»;ˆ×›“>ÿ(!¥²h»;l– ÇÐUOò¾£ï,œ—ìF/–íh®¾ås¶ÝÅŒ––±ûxúé'1U½Û/ûâá ¸¼·¡Kåˆ)ùtùó4r™èh£°nè¨íéÒœ=?k›mŒxuÔƒJhæo2AWÇû»N²šN®96œE?š×²Àœ+ _°±ý”šÔM°A€Äö¸,> ûÛ˜?稛 G|˜M¬ _—Ï|¹*5K«8†Ñ,OJH;£JÝÂ.§“>Æ-+ÆÂbÈ‚ÚÝULŽ‡Ç’jh5‹‚‚Wl`„UXÆðð=„N…Ø8¥Š¥ÞÆÐ_fŒ¡$¾ˆ£Ù;À|y–æyEU–áNüXö L¢Ûé±È”ÑeÇ¥ÓÔ{¼Ö8-d§g1µa@‰+÷†W(e·vmtgE> vR?F»iŽ7©T¶º´<4[ðX©®8©xú7iãý”8¡×ÐåÏ?Í–èO p…¬äŸ²[§´å0üPâà”ˆdXë~uüþ£%¾ÅÖ{OǵU†ãðý®îßÕÒU¾¢ùòºá“úŒéñH[ê K»Y<ú.ksÙŽ‘[3;J™kÿ˜AmôY|¶ªúÏרÇÅ gjì<‘sþ oEse¤§¼{óÏq„D•´ü‚š´öËï½*dÛÚ€6và%Ÿódk—W¡zÛØï?J‹¼“6±$ð9IÐk¸\¦©&CÙµôËzV†[ƤÅn÷Íq\‹…«¾ëy·×ó³ýGm¹¿Ù8`Üôl_3ú‰åŒ|Öƒ“óøžÞ’r†Ç¯BnÙJIRâÎ|J7ž¯ô;ÛK±ó.–—Oçà'Æ<Úcõb3[Ä=ñÕESDGˆí§D·cŠ3$.ªy\Nv’[]V‚–lOÒ+Α–öÍÃrIü™âã=DÝÍçÀTRWÙ°¥^‚èRq/Åîõ~ÂH#aÐÇùÌp}ÐÍ™4u¤1ðŽÈsiLS•"V¼ÏÍG½DÞA§ö!?Lßýü"ü¶´J‡|‘+12'96-04Æ08þZé Åpœ€^:·þC]½)ð‡ÙÛûTµÖÍ:yËÙšZfG.[©/‹_€]èjá,„RÆ~D½š¸Õ¼$FH:íañÏ|1@nãp<¡N™®"ö›ÅÓ¹D0ø°¬ÈŸ$Jà«ÂƒŸÇ ›ð'ðHÛ"g£7ÌÖ³LÞ[L}g6Ú~n«Ú¯ÙØßL–†¨ä®sqì¨T/Å µq —{, k³¡ÍI¬CàòµîÄCÍâíãMWáL!7Ä+Ò1VâÎm [OÛ|&GI“&{ŠÀäªÿU. ¸ÇV«Ññ‡6u7[’¿Ü…"CÜ ›=5\\¼3ÝÁÓB¬œþcg-ÝM±†áœÎdÉŒ{¬i[‚Ü]ª×`ÕhEåçW›‚<óuÙþ0ñǪæføæ;§`U_–°¾Ëy*õâºmÛ{RqW¿|xìö~}ÉÜû¸Ó)¾Büû䃆담ñ. ³Ò:ƽqkËÚœ3Œöõ«Ÿ9ôÕµ}%·â9_•œ$˜˜-.áH©ô±ãî[Ç÷ÚJÔAR“‘ΰJúµ/÷z:Îý@ÌÊ£M̽³uìÈs×iKH9ìWšùQ’TõTD+>’£#_bbNRÉaÐ"ÊQ~HÎ’ôÐ"3°pç…(Êhõåü×0DR7La1 ã9±aÄJè BtÒq¶cêÆÄ•YaG`£Ë´yá:Jž™¤w• ”ØÚ€TE¼\Ýñ¯ÎlªH‘áœ3é6Vr©ˆX™–%ËuÿÒEwZ1qxt JÛoÀ°$ˆcêããð¤ÒòÈ=‚gk>Þaà r°É_Y´Ê÷šõ£Làzµƒ5e³n:¬7‡hähô8úp˜G:ëjZïÓv!QÄ¿ûÒ¶M?NKZžÚÌLº UÝ®CýƇV•HÒâìMcð2ëiy÷dÅIßnk`ù¶s•îHuæl1~ WYÔ3 7*|ÎÌAà’ß®·?úTŒŒÑÿà´àâ´ÐTÌžH©pÞxR?ⓚæF9ˆÊ‹®ºÇ ï@ŽËrVUºŽeã½kLQ_'ẙY›€’)”8àeøªbÂJ‰'‘»þ%¹:– £¢¼1#nìMã£`îc;}xX¶@}½8<ËËéï„È ôØÖ³Êi#Ù$3 Þ5Üä{˜Ï”=ßìÑß¿ÝËiQŒgô¡j‹Q¡#ƱðF¡J5™ Fêí Ž‰Å‰ñCu‰4†>Ts€HȶwÛìôÝP©_¢(å®ñÇM Ycð{—"K®2Wœ,P“¹©52†SŸ• Çoâ™h\¬±2µÚ·ÉɉòÅ(ÑZ0umÚ_UG_ŸIɆ=ì‘%¸ÐSà„nôUTOô„.é_cFyy,€u‰êÙGÁ†ß3…é‰Ú'Üà˜ =S‘Y»åÎ<Ù`T;%XnÜÈÈÌOÉ>Ž/¹äa…âo9QæÜ2ZqÍ⛌8)°q O›,‡gAÝþAYùÅrEŠ3òkm…8P?«*Ã0³1ØpërÅÞv½ÓÿÌ JýúõÔ^û”£Íœ÷l¬îKeáæÂ× x¶Øv² ,~Ä· #5¯Ëöý»cý¾c‹|´ìûj ÷›Q¸7=ebé¥y8,ë„ l=?{\Ÿ!¯ÑgíÞÛ?@&sª·ª½\HÇÓ!Â~TU7œ-b/„+M®—±féûß´—E ¦¡Ì—g"ŸÕÐ5_EþL£+âš%¸2jIèÄÅŠR—³í‚¦ß?fAvohs7I¶7·‹˜Þø>¼u«´û:€^À—Ëêsì/·ÇÖÞô/ø5›_²ÅÞžn3 ¸¨Ñ£*÷E¸)ZÅ|ª¬ÝãæÏ–Ϥô°)îÉðÆ7+øGñ™‰l&,~æ-²§Ë½%N&:RÂ’wÔ‹§#]\ÁGüu1zȤÆTxÀàytïž“´*ù6£ÒgÌ]‰½Ô: q ¿ÅFÓºSÞÅ+QW6ÏŒ±}ÊØÅËS3‹ÓÜiÄq̹ Æ?pL®0ÅöË<Ê鈗1Ù½ý í[ øºýñì·°>µŒü%ÈÝ`㙀9{ÐôÏLWcýAísU<ûÆÛ˧Ç×Ê:ÐvôžøÌÆ2ýÜS‰SÖ*†z"ÚøòZ$š(ãtгlùàÁNZœ# Hœe4áO†B¾D‡¨²ÿÐV×¾½+µAÞt{ÿš½jvyß"·MbGº3Þ³‘óŠ·‚põ>9Ü6/³P;[†&ÝôNéàqy~9dÚOÅÓ´CÔ#Wû’ÍRzk½_Q>§h ¹³ ð"!¦ˆ=éº9´SëtU‡0®ýFnîwcØø‰RÞ–ö •»ß iÚì ¢i¾þ¶Q¢óäå° ‡:€C§Æœñ?˜nì*+^}‘â+£Tf6g}–5·í>æoÔz"TÊ n–8C‚ôV¯0šæŸß;(îŸ?è35T„Â>!/‰m:{µ_ ~¨3g1„0¦\Å{ÅžCóL^âëÝ_‡WáR¬VÛx»Ý!2'ld&à¶»JWÏAÞ×ÉÆK,„=sãF6ú 3Â,?̼üÊËô‘º‰=fYaT…W_ æõr£‹‹|È÷_,Ìs{þê-âyð[²Éñuÿp”ê#÷%ï«Lº¡ò¶Â%¬´Ÿý•ÐN{N‡¨¤åž¨Äbæ2sK†éæúðMƒòe³ÞBóéÍëeãu„y’ Íà £‘áØ§ëßGÜ¥ö}Zv¶vW›ªÏwV'>¥«®ÿö·^/)\ì¯_LÂ&‰¹˜Ñ);V°oÔʘÌV%ÂC%êØ K<œØ_RáÓù–äf?í™ 6&qÀügujèbÂüH6i’±m1+Û!@ç”^ÒËç^;´ßë%HúÛM¯aßõ$g^Vb_Pcwoâö/‡õnÛßs:)ŽÚ÷ñ÷´Ógý_íöë]ÌDè‹Å?“{“…¿{?õèPwˆÏ„û _ìG!l†£î7‰ :ƒ7fØß`g¶§ž½[»Ò<g»8>ÁTix^u"³²2 Ög×)V À„jÅ"0Ž™§ÌÂ4,I&Ñ0V°…ýÅöÊÑøÁ¼¬¢Žä Ÿ/i>4F!£üàÞ¾ÝÀ¥FÚ(A8\§‹AK"ŸYw| X{´½#úm®'èî›d¡ôžAx¾2 rÔŽ#Ö±{‹øÎ*¼·=ÇÛVUKí =Ó ˆû C•œF̓¥ŽHAGº» Ìc—ûmÖc>@ºõ@ˆk‚ZþøÕ¥m}¢º^ú ÙQ8t4Õ<·èÆ Ëèä7>äÓŽŽÔ^yU¨K8±ß ÂÚ/x÷·ñ«9ÖOù8²^X÷)Õ+Ÿõ©›3NA³^͵âÃ>º^[ñfªk~OŒ”ëš&¼˜ûá[“~®¤ƒæ·^±—×ñÃQ¾˜ù’m2q® ’mÎͳ>mÑ›92FQ>JX*”+é+¡|ÞRGÕ«b®˜Æìг 1ÐO¥DŒ¤•á]ë‰ð`F¯Þ³Ä]|åK³Ú7ËŸðoàúiyXÚ…»¿\ö{²É4â¦Ã Ôúø@‘Œhˆy¾£kõ’ŽœÂ7£RM´³±äŠõsd¿`qt‹<¹(™l*é’äÎÝ•Ê#˜.Ƚ¼#z %ÙYÀÂÿ‘ÓÞ%Ù€Y«TÔ50½y°}$ïü‚z¬‘¦p)1zEY ˜žàXàúÔ|³x–ÇcX•ÓIîscÔAL9A 1±˜ÚÜí{g¨{RD~9‹x€U@†îÃØš¿’û¸™÷ q¸ên#gå!ZýûÛ®7È9Ö¯f¿„^b…¼°U›p„ø¾½‚Þ…%%«I ¡AhI û#ëˆRæB•”ó³ÎRÛ8…’¹1‰o<Ö%Éœ»ü1²”ÚYÂ_Tn·Î‡a½‘ƒûž<· ?f¡ _pƒ.|äw:…P†9;|Ctב½^½Ÿ&_±¸ý6Õ»õÚÚ¢…—}é§îéx¨<2›Ë'ÔêPÇ좞×åº4É·ëó>„Té=-Ì †]ñn–Œ¾ÝZgôqÕÞ—‰¸-*Ù«á~95Ç…„é& ì¼ÐŠ<öAwš„œrÝtmþݺ—ÒÙˆž;qC¾ûÛm[iü?E.A´ƒ°kb<"Ò¿ë‡1ó}èΙãâ„™~S]é_A„½„h½z˜e~H}û‘Á:A@üèmeèÿµ‹¡P¯°¢iÙ°<Ä2êl”’h”fôÙä8ôRë©Ü¶¹1˜7«J…±9h¥²GN¢jŸåÔ\©éG´Ì¶Agh)ýª[—”ÌÞ¶FsläIç•uz†—~…éúÅ‘÷œ 7‚í3ïN@LmŽ)²ä&° dz”]Æ8W"J-BVǪZ7Ó¸ðá.hvIÕë’9jm¨Ø3—áÈM z¦ ^:*oóêŽä*ø¸¬ÖÂbsÈŠÙÌZwc‘ÝHÁœX>k˜Ï²¹´¼·®F†Ï²ðñÞ‡ë-‚ú~æ &y;§ÍnMf¹êvÚZ´÷Xmë¢Ã>üí‘tÓöª:"ój¿Ï«Ÿz1ü(äk¤mQÊ©Õ$á;Ky?EÞÓU„èyÛp‘£‹UÔ¿šþ”ƒžñøÙ¹‚ц¹2uÄ6hZÜ™ãpšø]Gˆ:G=ŽoÕ]˜ÚüÑgD܇àÚ2ïã6‹ãÿ´¸*ÉÉ-Ž%|)]´Äüd4›¼¼oâ°À[ãèë{63aFŒ‡æÙ`0¿c·m½>$}ý„™–¥ŠEHƒ´ˆ‡þô˜¤ª«œ®e|mæ-À×»zN }ôìòu ß1i< 9X_º‚‰Œ‹ßűUÜ„}=çzkÕê" ÛâåLFMúñ¢_«DΩÜá}œ¬Œo35m”^§p+*ÎýdÏhê<;²e05þ,®×7X2I™ŠŸX%õQÃÖ+¿ÿשSÉŠ[=ÝÌ(µÑ7zžL˜iNž34zŦLeG¿`wóß5DW0Âq9¯‹õ¹¯{ý"ø¿iƒYí?øùR埯 ’š~þùîàå÷‡ÂqǶMp~®Hø,yß—ëH•]ÀyÝ (Ûpx}u[=ü¬¼»<¸Œ@43š«QÐɶÌiä|}Ù˜.ëUPÿä1€—¹²×$¢£Li©¨Ýbœ½îm^SP4ZÔY^XÞ·ÕeJ²nã2ÕüºÁCÊWEXõ3øuƆ£~j߈Å&ß³À@©ø^$ËzôZ/ø¬û,«×ÙîÛ'&íãHöçù®ÕF©zÉ%C\犄U(ð–tÁΦí”yÖï é”+Œ§që‘Pá6_4j”¿L"q*’'×mC/#ÕNÉ›òÅ›u…gì šÕßõoðÌDO¶…ÿx¥˜²êu@|€ãËáŸY"–å–k¼”KЉ^>¢’Ë}ÙµÕõCÔýúuÜ%ƒó`ñ‰½ÑĦ¦jhRGŽ{uîP°×€»bÝÅY€>cÙ°Ÿ•ÏzÌçb»‚‰ãzÆ3çÅOÍÐ’ÿuÔ4Ì2:Ì2VðáŸàfH@üGDº»ü»9>ÀÂþSãºþ3Põ/ƒ#Vʆjɇ¥ ö2Ð욤ðÛÄçÑç©®Uˆ`ýÙEÍäû@2ç}vZZ{*b@N’Å\äbÑd)¾s¤g»•×rB.‘Ÿ+Xs%ö .ú”•U¡²_ÞÖBH:Ðv z4:.‹Ïß-ü^Bzen›¼¨¾ÄÉFÁ#v#-†È1Ôws®/XñǪS=ɳPSRBz¶,åÛ¼:“¿£ýc5QÄyHû«04™'–öùâ±·ê‚ßñÚ½ÆÎQÛðîL¬cÔ˜'õ\Š8®EÌYøÿi‹ÿǰ¢àÈlÍØdËR5QÍ#ÄÙªæ°ë î* O²¬"Dû}½‡ÍjÖ¼“é‹¥Óa±×oÞ)òÇó:àÁ—q˾›J—ºÑ]¦ÜdOPí;–†²Žô+hbrHzøÁ)ÄØö¢\T)NY1mÈcóá¡w§Pé¸6¥¯%€m %çQ=¡’šÁA-œ’ó8þ‰¯FF«jÈTÇ/nî¸ãß’Jly…ê¥Ä;6M˜ÞÝ܇9¹tÖRÍ•öoké'±¾yC.~ðúKkFØsâªz2—Dú!áâ²°µ¤^h©Ëì–lwP˜\)žf[³¹4¹(/ûÀÁ?د(¿…`ì"<Æçø¹Fï©Ñ%‘WJ{.S¼ª©›¦—4GB`j{#ÍHI,ã¹fΘX®Ã§ÊR1ŽS\ªÌËóVÉçÒ;õ«nGÊ1HÂ+œu4©]Çm.þBª}‰QÞåzð9À+X^§CžwQŒ¹ Áݣϓh±2λG¶%âIÚÒÑ¥ãN´vÎÅ„…ž~Þ”M Xc¸_ÖæN ÆwPžÓk7@ë=43”?¾¤93÷)—¿Äêe·í9±_¸eÍb¿ðž•ÊÐi~iÒ¡XoÑÜ)»Ë»Jw^r ߩݾµd©Ë`vZiDéŒÕf•§itËaJ¹~Ã~˜}JxðäõñŒfóÝëÿ®(\ú°–.âs®œgPyTöæ gÞE _ƽɻ/QÞËðʼnRîÚÝ›ÌjöYB»ÛÚ×î>,õB{„tHÀFÉ\‚Þù_LÏ÷î'z}^žØË., wF/3RívžÖèXˆY7„|ðíñïý.5G¿˜qM5à )¸ÜpÓ¯ %€epšÕ—A-’–74NaÑS®«¾cÓŒ9þš èßFlsì .ýÁ†ê‘gdÓùði"úãD0[à‡MæHŽ$Ç@;V<ÚU3“†¤ ´´Ôû±}iˆ{ïa0F…í5Ì÷êŠys€t"—'Xõ¢>×á\m‡söÅØí³»fçcR»…ø€‰DCÀ˜.õt2ÙuHÈ:n“ãïTím¯Ú-0wäp37˜'i™œU‰LW>k¬Šÿ:jFÓw ¢Ú¬±°uÕù-ï… AGA_U °˜>ºëß!¿†%#ÅþÍÇ”JÉtW#ÌUGðþ8Ä¡t™Øx·hý×ó6›E/S(Gð-(×4Gž>"¸ò/œ§.‚ºÛþ'’IŽýciHŒ‡ŸJ}Ê.ÎF×·ï¾g‚& ³ÌOÖ|XZ¼=éTFïéÔÚïŒÖÛky±6î—Ý…/þ»§³‡8ï0â&ô›~Ñ~šG”…»K„d˜qBÓöq»i4Ü ìŠPG!]7Á-já÷TH¶#o´«"»ß)äjä[ (y(†šEðn2›Û]D7SX¬æèÞßÐ(Ârv!³áþ»;ÎG¼Tç;ðR½q)ú/õ¥;(Ï[:~_„Z®ÐšÃå;*™:.X^ç†Üž|:UÎÚVW”Ãü_ǃß»{اEP)~2g‡ëüá+á³ZšXÜÉ›¸øsÁ:~ë¿ûùàá •î¢ëµŒ¡Cósiè2Ïy(ÎÐ 0£% WÕ~#jøº…:^+úÙ*–f–ÜÍ‹&e¶´7}¸9пͨ§x w×*»Þ!ÞMŠ¿qž¨~áeϼ®–¢¿5o㘲‹1ÔÑÿSÃu£’QÛö(DSž÷/ Ú±üÉWf›|¼æ,Ãg‡X[¸þ%Û*Ù5¢H6Ô݈panÇÜ ëWûŽø{s½'†ŠÏL{ $Pö\5E_@“ò1Š]4 äåìç—þŽ»È¤¥åiTÀ1Š…¼?›Šsˆïöa¾ò&.kBAP4aŸˆ¹ýA’xÉ&ò ¾Ëþ–#ü!Êî|›låŠÄ .¤ÂöüyGþ9Ë7͹E®aŸ/jÏ<¢^dŸÐÿ5û§¢â"c‡½îujŽ–¼ŠÖ‡uê¿™±÷ÿ«{9‚GýÛZ7MT”Ä/Ä÷ˆÙF;?A¡éÝ0Û3£8r)wb Ëc5(¶B¤tYóLnufÐŽ Üÿhë•oT†Ó´ºá›‡PBpÏ/ã[kRáWwTÁƒÎÝÜÝIàz ¹b¯ó£Ãx•‘‡ÂúÜ®B9!Qm•8öÍ Šå—ǦÄtùÏãïuXÅ£Ÿ_ò™V"u?+^ÇóCGÈ©˜ƒk¢/õž;toÆ—Þi¹Álù±2n 1ùêµ s<Ì+|¡šÎØ’i'Ù¯‚?µáñ@ ͰýReO< ˆý87Üç–¾bŽ•µªŽt_=ƒ?1§ÍéLô:=†¹¼“ÅÞ÷+#*"êeéܤ¶§—‡Òg WŒÇ#,S6a Aé y¥¿™¥ëN6ŽZÚ’ø·ÒÐKS8=Ša7ñC[ðÎÎ`´µJ™k}Ú¯?š^gô+*Óþؤ4¥ŠÍŠyW_£®ƒ…Bî–éIR¡L룕ŒìGý·µf"'†¥Úýþ‡"ÝL/É/‘}”|ú7¸£“|@ÂMÉ$+sŽY½ÐˆRï Œ‡§Ö 3JÙdžQÅ hHþ/Dº"2JÛ7ýWÈ$ëOë$Ç«¼Ü!wn„¦XÏ;±±:xgM"ô8" M3‹lJð½ŒðØ|a:î“r$Ïã§ Ýz÷1˜8Óð˜´Ã6¥d²åÆ“6ÉëeMHy²ˆž~µ)SÆéN G裸¤dû¬š"PÏz)<>γÎôRbUoIhý»uÉŽÌܵú™Kÿhë›(áFž;mÒe=_bx˜ü5ÁÒ4‰«œ†˜¢—í¸×ÝÄ\ bÑDäàšûù›fFz ¼«°Ö‡êZ²§/dåµn´Ìì”nf`+’Ûð=*{Î^öûEÐòÏú¼9nt‹5®[=¶QÚ5Ø4s-–¡,-sdÈ—û+”§;Å9Í»aÑD¸´-&xí]j=k9 x$ŒVÓdTqŒq~HœÖç(wˆ9~¤×ãЙø·&qI˺£Þ±ƒÙQÄÿz„ð5ñ?³ÏÛóp©Hd-†ýÒ§n–Yxº˜v#I„« 1âÆbK•vÃç1‡NÏlÈÄÔ! V ”ýÒt@{üu»!.¿ŽG7É#c—ûƒ2ƒà<rß_˜ÄCüÈn²þö“™ný††5<cë„nÞ[’ûÔm…âñ´£m}´§.GA‡†€nþ®—#þ¿v “¢Ò̃Ðì•B<Èé5`m£‹Ì‡åÀ³áÿ€Mø/§ô2ââ±{s&4ä)±ú%.ÑTá–\²o¡…Z˜Ö¢¢`±ôjP*À%ã?Œ9¨»Ôÿå´pÝ[QåA<cªu">âê=ƒA]{'‡ömºñØÝƳ³:ŒòýÓðZß…oì=¯MÕ"ŸÍI0ùnzPf‡£‘HÔEðC¾©ÊáïÓá¤Ä£Ê«VL¿Îq'_gS¿ó(aæ¦ShžªQ`¯Ý¦»°^'ÍàÛsÈõ‰yŒQº¬V Ø©®2™~"Ú¶púµQ}@¿3–H³f¯«¬ym\j ãˆ2ºÈ¢Ó R¨*iMBoGˆÐ‹%RÔœ444DÝYÀõaºªÇXZ6\W¬€¹ˆ0)ª‘´æ«]†(æïVŸ¯DOY»û‹ïe,rÔôl=âjÅ=´’.8«ü¹!Ó® µxÁFB¹x[YFßWNMþã–ÀX–1'¶à=θ=7”ìf¤—ži'ÆæøzƒÓ´Xâ;dÚÝÌPodõ ‘ÚåÆÁ”|tÖÑp–§‡o"âQø¶#õWofm#_&àž4óŒ8b ¿ãwzëð ¹îˆ‹¹yŽˆ*@ ”“.Å^£õqTñèYXÚ±Ñ3÷¡ê¸×HÏÇÌðº×»NŽû€°NìErÀ•{BȲ¶ðEcØî;Ú:´Ô×Òê¯Ï™r‹N™k8’ûù7d ¯sð•e‰›&!F[b@7…vÁ»”~O×κïÛäooæTÚÄ‘ký™ÏhodaâÂ½Õ ŽŸ<®^¸úO™*†§’{^ЄG÷…_?+òñ:œö6ž7ÇÅ™ú8Ý8&3Új˜øH»Zä4œå9HU:“Ä#+‚ý¨ïw޲ހ•ãNûº9MÞæáÿ&~¦üÎÈøwc|Á6ÂL,GߎK•&y¹›ïãÞ¬0†“bIä˜'y%²vbˆHÏ…Þš¿{:,G¹j€ t»$ `ýˆ`þbðøPÑ7Æú‡ºœ Mv]ƒNiðäEèçûÙëCïîSi›Ï¹dÄW@›¬¬ï+aùšF×ï¶¹eñ%Ìh?ÑõLù(k;íÄ'É´*î•ZnX³Ô@ó"±ÌÄ€0AÙ}Údê!cHöŠgŒÞ9L'Kܲ¾Qõô·meï½w!ŸØI0 - ôDB0öÊ´r«Ú‹Ùá`[È÷5]õ]ùÂTkHî—ðÑÏ䈺êÝ%W|¼r`µDòß0PhÝøPŠ ÕÆM׸ ¦nœNR) ^x^éu+ìÔ4‹Õº)Ž=}ìpâõÿ«g¯dÌsÿzÍåæ¼”.õõÕ7oàq·4¾¨/7d%ãWœ¹Ð›³¯{þf£uK-šõuŸÉæ/ZŽä1¡“÷ÞÝ[úÖÆ•vå R'ØÐç«Õ p@+¼½ó|˜$Ô©©ñÙó1~ü£r%„‘ ±á ^?¯"Ø\]h<›sb#”ãå<¾B±Õ38%ß+Ò²ð¡RX9E+p¸©þ&s0ý[¾A½õqÉlxµÎ<*ñÓxÏÖ ¹|fyÀÉØds›%ðåô(½û^ªr@òíjcÒíÃ0œm&G)?3ø¥Rç*Oêo¬^¢%ÏfzrKˆ;Pù!E“ PÒ2ŽG©ï3ŽeùǪ‹R4Çú ï’GÀ(-Çj\OQƒ®’»3Q™Bá<zÕñ7"ûXWÌßréôÅí¿Yãß—¢ï rY%)™ °”æw#Äþ}1c¸±¯Õ7‡nÂV¢ÅÌÙú0j§}¯^ ù"”q—B{¯z s(¥þ›‰?ô#lºZ’ amg7\¡ýR¢u„ëÙÕF3L\wžÔœT~ç"†(k(* “ˆgog\ è3QÿgÜL9·3ãÔû‡Í´N–4¢PEvÿ‚ J¨–>ÔŒ9éÿü‹þ!¿_¡2M}4Â0΄¹ œVç3ûë+¯î;|wPÒwì7哟_çÈ5½0kY=^-ázÅ®vOàÏm°—„¶ñ¶Æ}^œÞYߌ¼Êä‘„< ¿HB¹ É!õàIBäÀ lá:µq0æCuìÌ•šVJ›9QÊ%‡þø¹FÑï®Ý3þÉ…+(ÂX%æïÜ7¤“&/8ócäÅHP6%g½~>ÜÙÜ·0mmüNÐGÙ> ÷ò•Vѱã&KEú@oMóxÇÎ'Ðþ0*¨Š:®ï¡Ÿ–qÆq3gîÓš¡?XLµPÚ™šzØ¢v«#ù4é„ÿôÒ ÚéKÀ#tÿ¼F=Z×ÂrËx¢fÆvÓ Ûéc]B(ÂHД)E¡¹I\.OF|~^ÒMÅ‹¿£ü—’à¬×nolÁÅw3…ê•kŸ~ÃÜ•‘ÇH‹TÆ:Y•Y„‹ÿb?a<à|ßÜg¼Û<*™" ›^µ«‚q™ifQ´/0ä„#;ø>v…z]ÿ¤ûü¦Œu1€47:tw>…Ê—’ç¯Ãœ³}ÿÊô(]"QÎó~&€Coú",¥üÔB¶G¦]öµîÓâìc¾Is,Óï´loÀTç88³ü&éI)‚Þ_§xYÐ9DÅE2=ãÎX¸Ás–&X?:$|ÌÒ(Ÿ7›+oÂ+÷`¸±ïƒ—\̃ܿTÏÌû‰Œúu÷1U:äøƒˆd¨„Ò(ÿaBšLï÷"c¯Þâ›UÜë(*\cÉò¾—Y±1`‘`¤ì`<šÕd~ÑmÒu§^ŸB^øõ°ªå‰ˆÍ“3L^n4N1®¾€Í„'K³(Ëÿª¡Z9”ÿ‹URSÑ@,„\]º-Ï—‰œÍž‹x†Ç=^SÊU¢I}Axú_~_jÛÚm¾Ãù`ì¬ œ<oûñ>y>EÉ™†tÛ„°ŒÎëìkïv9ïo¸ê®~õîzøQµQ´Ë‘Æëº]iúg€ÿÍŒH ä †¿WcíÂïé ´L2QÒ ÛÉ󪻬÷0C‘7]vÅ•¾îuiýöè!M>BlœöÆj ¯5"Ù4`˜ó’Õ±9uÿpÿes¼EÞ>oN(tuŸñžž}ˆ|ñõY2ˆD;3åtã$w”¥ÙtÜ•~Î%d÷ŽÿÆçí|en”ÀmB×Ù)ÈåvoºsRóV¼ø2ÀíÝ9¿FP/S"¤‘)‚ÖZ<$ÌÅZkQ9Uà;NìäµÅ¼³™¿³¡â\ýcÂÓðŸÓ}+§ûÏz—o›¯UDzµÐÚ"ïu[¾ªâ?]ÆËPŒ…¸#Ý3xôÛ[QêŽ Ö‘Ô—ž±iàÛxuGóÚí.sž§»½ÁùÙ{Ôצþ<ß=ZüuTº_vÊ~Z_Ãóg’!L·¡j èd™>ùP>ˆÏ~8þ¬(ü×pŠSšÖd‹M!rË’,˜?/ŒpÇwcj}`³=´”Ïo+¬cqÓãþé}°a1sFhú+~´ÎÃhP¾‰^¹›mtDx=ÔØ²ÐÿƸ]eöÑYrÈÿŽ:QEÚ‡Mø¸ƒ$Á\¡"8Gb6_ÕìçãÏ&bmU¡œîÄóh¦ƒ›:¨œ»vÝýÔ9ƜŰ t£Áñ$Kz†Ç“%ñO&¾fK;¦\°’Yà…óŸ†ÉÔ&jÃoJ±°N6nvZ•ߢíßYûPðª-y–ú£ê&¼IK þ“l涘~&?sÔ™·¾î ±-DpÛ¼!èWE%W÷Û¡Y&åãPY ?àæ¢6VQwç7È($Û??ÄßB¹Ìöš®í3zP¼~W„Õ„>‚Ò?[Õ©k-$N4U7f¾Á]¬[`ý¹ù!ýdB¬òêÓ„¡½¿‹¤5?= mú±Ÿ¿EQõžŽŽlog1PÄÒñQ¡ÆEIÀU‰àÓ2ùˆï×7/Yá2“HýUÐgv¡š¶.UÔ€ñÞü›A±<NÚL›Ÿbô©êµ|fl˜™UÙ1—k¥ÀÆ 7—°ô5}Ô{¡²õk}Gübþx ÀðxÖ )±L;€ÓóÒe°ö<Ã#ìdX˜¦ôV°ù‰·ý5Ù…É’cTY§®¶·Ãz•¦V_a¯ÊÓ~Æ:*cµå¨×+Àm¹²«¨wÚ·,…zÊd(”«/Qïê»8æ„ÅdY 3ÉPRÆó_²æX–¾ßÐýÿ²5V±4UÒ¯šPñÆ!|š1Œ1v*™ök¬Q¶q^xx’b+DbzL<¸Š\'äþ8&õƳkEÖyKG‚ý$w¸ah£¥Ê°°ÞuÙÜ'`ÛA¬\»*Ø$«‚–™É¨˜·n³î" Û¦ØhDòÇ Y/›”éÐÐ(sbƒì¾y-…MÏRüÊ©&\š0O¤‡°ýJH<[›{)§¦]¿–ª‡á%;ŸÒ7ÐÝÀS©™“Wžù²!so¶ÀEÈÃ.³¢ß=ã/k—¼ ‡&×DdïªÁbúƒ8æ†Ìjd«n°Æþ!äÀ<)6‚–¹qªªÔLá$tVF(:äåj·~=&›1$¡?˨MÖ0Tº¿¶µfRAœDæ5FÍÂ>i¢kæ$hÚ¾õ«óÁæ¬ßI˼Ooît€ÅâæÂ𤑍á®dÍg J rÄ™›P½O#f™ÔË 0w»Œ °ËedÍÞÌ€ngl ÉŒäsÄQP˜°ÿu\üß*§9PࢼTZ'¹îwwö)ŠÂÏ„<ŸõS®‘$§€ Sqº'剆äų¤öQ#Žû´Z ~…t®Çnå w›Çötj}§ sÞºÎ×uÎ`L×QÚ´5Áæ}h¼Ý“%+³ù†æl®¤¥.-5g>›éV[Jø=>W9ÝúO!S¤ÕfK#¨ZÞœª‚‡?@ü¤–æz™²Ùú’ÀA4@nI°>ˆƒÑ ÞJÀê2„¼Sü¨µÄ ‘ëõGÃø²‘Zât¼\”ñ£¶¯Í– D…F µ,c–`I{,öÉG!ÍÉVà |^¤µ@ºÊõ²4ÒûSrJP˜}õû¡ã¬\¯w q·ÝÄú@!m«Ùc¤G$ɈQnÏÚzÞÒI¹ÎÖ•©ï‡ÇyÒ!à€Œd¨´I›…õa0À‹¢©’¯«7”j¶¾-ÙF.tÓZääFØôãå+˜ÉeŽuKz¢e»“GG•å‰/ì*©XÞÚº4|*;Éq²ú°xç:ˆ}#UoIÎ]*°—\š"¼ÙHe[VÌkùgíÔüо¥ÆÁ•òÁHÎ:!´ƒï5&ÍwG6s1L<̇.“ÚʹW€[p^Gm*/¾úÅ+@çÀsbä™úŠ76ÛcµîæŽËºŠ|ÌPc$V¢ÌâK4³›MÖjí“y2p©³ÑPüdbe.É5·:Ɖ)B¦ âç"øX,—ÒaâÞæÑñÙyC6î´`1•ÚOøjßãöGµ½¾|FÕó«Ÿ\Á×™TÛøÌOƒ‰¿4ü"ow†¹Vê¿jh}¾yD?‘QŠæ—ÝŒµ4¿´ýoQv4òmÃ˃²ï£%OMY°èÂŒRCçk|÷muL2ú5 —/Ÿ¦?úê± £DȲ ZH)“–éÀQ嶈XDçñ¢Ujb<óçœ @–þŘ6Â6ÚÙêO10Ç«Lïv_w˜±.ü²`Ù,ð,è)vËwÀ–<9@×û»QŸ¼ ½ o,eÞ8ÖËÚ*Ãæ“¼~Ê^oüôw¥—ÌFÒ{iÝ©I³ÈåNúC™µZh,íûúÇ¢½9ë8x7ñü¯u?øéЍºÉÿw¡÷[z*L¶[sÑ7l8§j³Ò{¦¥Ì8ò…å76·)ÊÕÁW”•l|ÂÀ®8ÒHΦѡÚ<%íx/‡À$R*¾ñüˇ4¨•t€=XþTວ"e°Õz5ЖôNáì,}DLb°u4‚ëÑ””Ù[´ÛñÁ胇KhÓºŠrYêeÿ2Ýð?E%ëK;£ôÿzR."’&çº?p~þJH›üÐa\ j•ã ׇ5ŠÂãÈ;“äÉH& Ñlh_?xÿØOp¹‹u˜š”ˆræs½éˆºua€ybÐx«a!Ã^»_›>ÿ ãÚFW{–ŸZøl1ðˆ¿±FœóV,Ðþü°ÿFŽNä{§‚¸Wæ„eýÁÏ·¿D!ÏÛüÍWMÛêµm—:íÍükýíçÓ¯óh±JNîNbÍØÆmV]ª“s–Ö£J¤·TŽ©½?;OœK9ûyW‡tN,¨FP䇤üºh-öQNî¸c‡½4Íqùg¸NtkÂìlSk+ý¬ÄÝ› —eèé.K}¤ø3ϔɄ÷XÈǨ™°SHY>“ø÷—Èídì”ÞC¦ {\ÛÑŽŽ…möŸ{áuzÖ8æË>ý¢FLæéÆn§r‹i,Öâ1Ã((3…wýdWÛ¥è5½€âÚÊJ-Üu¥»f²×X“„#Ú‹ÿS¸è&ÎO¹NÇu1_Ž•\<m‘A™~ºômûÜÚã"QÙ娔ùŸc0½Ìþ“hƒ¼þáôu’ÚÅ ¬£€ºxLÈßHþÿwnæ_óåYé¿®¿|TreD,žËœ7†ëI!CS6è>ä`Ÿ#ë}Â0êï%-.ÿ½JÔ0ðÿPK®[#Ä839PKÑz‘:settings.xmlíš]sÚ:†ïû+ß$œà t9iègHzN€&²Ö#Éúë+ÛÐI\›8þèœéñƒe=»^IïJk_¼}tYcBRä£}b à6:”¯ÆÝüºyn¼¾¹Àå’Ú`9hû.pÕ” ”¾E6tw.¨y`ø‚[H$•'.HKÙzÀݬ§w[¡±èÊ#£üa`¬•ò¬Vk»Ýžl»'(Vv¿ßo…‡[mäKºÊj*ºû©)Düi(è9ë˜æi+úo4öN> MÇâpxüáÅÞ@ôÓ¤ Ü 6ýåÀµ¡MZ ÛŸQ3’ú=ïsO%]0 sôŒC£Úyº‘re͋֯W?ÂR%‘Ï:íÂì¯ÔQë$øi§ßéÆß]ïšýþyV~Ó%^“rÁ‰Û‚mò8…}ô»,ÃvâÄÜ”JèI`ƒÆÌИŸs¢#ò’£Ï»ü}uÝ|wumþež›ýSqì‰â%Uz%ü“ôvæˆCÿ›8ž|èô;rEØÌcT}Bâã°FQ`PÔ®Šóþ¡2uà©ÿðG¶¢éSÂW)áÉ9¸Ó¬];MS—œÁ8pË•òõ•B7qñäòoˆî\cJÓôž0?N ==?˲‚@HÂ{)'\<®î/Iji‚š3ô´WËi-§¯”Ó‚ú”ª¦y×üq5-*þérZ@ø~¯š¶Í¼CöŸÓO }‘²«¥´–ÒZJËæþîi¤E”49¬d]aå ¥4ñ¬DPX'lŒ-ˆH u{9WÛÿäœò|¶Æm`àRy¸cü"Âá’0 ùÍ|¡ÿ2Í€~þgTU¡ß /Å•@¨cd(bh†ÁBjwzÝNç,çNáÙ¸V•"µë¾Ë§¸½â€¨ÆÈl ´ÞT@ŸÈ/¾b”Ãlç.ÉÄÓc)Ffœxsœ© >Ðe¬¬<‘û we¦ õx§—qͼÙ.ŽOÜ/ÅÏü…C7T¦º_<Ùù¼S'©œí¸½ÈéwÈ!D9÷û·É7HPÙ_aE|A‚~Í»¬üayã#åwžC¤/»uJªSR’þè”ô’¥‘¯pL˜í3-åãoõaU?Çgý'ùÛÊÌÐkÔW@DBïô’r"vYP#Ïc»; âŠ(RþÓŽ×D[û:F× ƒiQúÙw"?€à#I ¿õ¹|’P|+å,I6p}[ó…Ê*&ÊQ×Ý9¸^5“pĘN¶Á,z‹1á6° .gª³!r¶« Nyµÿlj¦'Yº1‘º»lýòÉT+íc²áPK¨$õÿŽ&PKÑz‘:META-INF/manifest.xmlµ•Anà E÷9…Åަͪ²âDj¥ž =À$ˆ¢äöÅ‘’¸mT5•Ù…ßûŒ=°ÚS0v¶ÏÕ“(Ð*×jÛ7âcû^¾ˆÍz±Àê‰ëË HïYºNƒ¦Ú€T³ªGÛ: ´\]_¦õ¢¸;m°Lé¸É°ÕPòÉc#À{£pÊ)¶Î®jª¨È„–öˆ,nÉæ–“Ç]4¦ôÀûFH!ŠrŸòæl§ûÎi)‰#í äÁƒRh0M]*†0 Õ8»+‹ 33Á½óѧ$fÂפ|_zŒž ÎΙlp=@$_5à)«ãAö÷Ó„¢»§ŠºRSÁß2<(g<²{õ.<ùùÍü;—ødfÇÈ0ÛÁ³ÝÇagA’|VÞösÃç-,2§ëòZÚ•üq[®?PKATûCIhPKÑz‘:…l9Š..mimetypePKÑz‘:TConfigurations2/statusbar/PKÑz‘:'ŒConfigurations2/accelerator/current.xmlPKÑz‘:ãConfigurations2/floater/PKÑz‘:Configurations2/popupmenu/PKÑz‘:QConfigurations2/progressbar/PKÑz‘:‹Configurations2/menubar/PKÑz‘:ÁConfigurations2/toolbar/PKÑz‘:÷Configurations2/images/Bitmaps/PKÑz‘:øÙ^¢>÷i4content.xmlPKÑz‘:Æcr¤Xw Astyles.xmlPKÑz‘:6.•ÀƒƒëLmeta.xmlPKÑz‘:®[#Ä839”PThumbnails/thumbnail.pngPKÑz‘:¨$õÿŽ&ž‰settings.xmlPKÑz‘:ATûCIh×META-INF/manifest.xmlPKîc
-
Bonjour Notpa01 Ma carte son est effectivement Realtek High definition Audio en mode activé ,par Acer Arcade Deluxe.Dès l'introduction du dvd le système Arcade le prend en charge avec vision du contenu mais en muet .Lors du passage du dispositif de pointage Synaptics sur l'image,apparait au niveau bas une ligne de réglage:arrêt ,avant, arrière ,son + ou -,ect....Hélas les paramètres du son sont en grisé c-à-d en muet et non modifiafles.J'ai essayé avec Media Player et même problème.A priori je n'ai rien en Bluetooth et je ne vois pas ce qui cloche Merci de ton intervention