Aller au contenu

jhohwald

Membres
  • Compteur de contenus

    18
  • Inscription

  • Dernière visite

jhohwald's Achievements

Junior Member

Junior Member (3/12)

0

Réputation sur la communauté

  1. Bonjour, Merci d'avance du temps qui pourra m'être consacré. Depuis peu, mon PC a des accès de lenteur et de bugs de façon assez irrégulière et aléatoire. En regardant un peu dans le gestionnaire des taches, j'ai remarqué que dans ces moments dans le gestionnaire des taches que wuauclt.exe me prend d'un coup presque toute la mémoire. Voila ce que je sais. Je vous poste un log Hijackthis, si vous pouviez me dire ce que vous en pensez, merci. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:32, on 2008-11-11 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\USB Storage RW\DskWatch.exe C:\WINDOWS\system32\carpserv.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HK\HOHWALD'S.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [uSB Storage RW] C:\Program Files\USB Storage RW\DskWatch.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [CamserviceDeluxe2] C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe /startup O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.targa.co.uk O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1108507380937 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CA9FCA32-5396-4737-A69D-188CA85B3056}: NameServer = 84.103.237.140 86.64.145.140 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe -- End of file - 9058 bytes
  2. Oui, j'ai pu envoyer tous les fichiers avec les remerciements qui se devaient de les accompagner. Pour le moment la machine semble aller bien mieux déjà au niveau de la vitesse, et des fenetres IE qui ne s'ouvrent plus. Mais je verrai dans les prochains jours. En tout cas merci pour tout. A bientot, bonne soirée
  3. Salut, je ne sais pas si je peux etre fier de moi, c'est toi qui m'a quand meme pas mal aiguillé jusque la... Voila, donc VMN toolbar est desinstallé, et apres avoir fait un scan avec MBAM voici le log : Malwarebytes' Anti-Malware 1.26 Version de la base de données: 1122 Windows 5.1.2600 Service Pack 2 2008-09-07 17:46:33 mbam-log-2008-09-07 (17-46-33).txt Type de recherche: Examen complet (C:\|D:\|) Eléments examinés: 133321 Temps écoulé: 2 hour(s), 31 minute(s), 8 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 9 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\star1 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\star2 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\star3 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\star4 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\star6 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\star7 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\star8 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msn_livers (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msne (Spyware.Banker) -> Quarantined and deleted successfully. Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté) A bientot
  4. Salut, Alors, en réponse à tes questions : Je n'ai pas installé VMN toolbare volontairement, et pas non plus PSEXESVC, je ne sais pas ce que c'est. Ok pour les P2P, je vais voir ce que je peux faire si je peux les enlever (le PC n'est pas seulement à moi...). Enfin, voila le log de avenger : Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Driver "vspf" disabled successfully. Driver "vspf_hk" disabled successfully. Driver "vspf" deleted successfully. Driver "vspf_hk" deleted successfully. Error: file "C:\WINDOWS\system32\drivers\vspf_hk5.sys" not found! Deletion of file "C:\WINDOWS\system32\drivers\vspf_hk5.sys" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\drivers\vspf5.sys" not found! Deletion of file "C:\WINDOWS\system32\drivers\vspf5.sys" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\inglog.exe" deleted successfully. File "C:\WINDOWS\system32\msnnet.exe" deleted successfully. Error: file "C:\windows\temp\msnmsgr.exe" not found! Deletion of file "C:\windows\temp\msnmsgr.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\Winrun.exe" not found! Deletion of file "C:\WINDOWS\system32\Winrun.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\ischot.exe" not found! Deletion of file "C:\WINDOWS\system32\ischot.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\Xred1.exe" not found! Deletion of file "C:\WINDOWS\system32\Xred1.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\Zred2.exe" not found! Deletion of file "C:\WINDOWS\system32\Zred2.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\MscheldB.exe" not found! Deletion of file "C:\WINDOWS\system32\MscheldB.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\Mscheldncx.exe" not found! Deletion of file "C:\WINDOWS\system32\Mscheldncx.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\svscheld.exe" not found! Deletion of file "C:\WINDOWS\system32\svscheld.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Completed script processing. ******************* Finished! Terminate.
  5. Salut Wawaseb, tout d'abord merci pour ton aide et pour le temps consacré... Après avoir suivi tes instructions je t'envoie le rapport de SDfix dans ce post, et les 2 autres rapports dans le post suivant. Bon week end à toi aussi. SDFix: Version 1.221 Run by HOHWALD'S on 2008-09-06 at 16:58 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\ponto.DLL - Deleted C:\WINDOWS\system32\MEGATRON.ini - Deleted C:\WINDOWS\system32\msn.exe - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-06 17:08:00 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000000 "khjeh"=hex:2b,9b,92,32,31,32,be,1b,9b,58,eb,ca,3f,70,48,d6,04,ba,58,f1,50,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000000 "khjeh"=hex:2b,9b,92,32,31,32,be,1b,9b,58,eb,ca,3f,70,48,d6,04,ba,58,f1,50,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:fd3f4193 "s2"=dword:dc998b90 "h0"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000000 "khjeh"=hex:2b,9b,92,32,31,32,be,1b,9b,58,eb,ca,3f,70,48,d6,04,ba,58,f1,50,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000000 "khjeh"=hex:2b,9b,92,32,31,32,be,1b,9b,58,eb,ca,3f,70,48,d6,04,ba,58,f1,50,.. scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="990" "USERProcessHandleQuota"=dword:00002710 scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\CA\\Etrust Antivirus\\Realmon.exe"="C:\\Program Files\\CA\\Etrust Antivirus\\Realmon.exe:*:Enabled:Realmon" "C:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"="C:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe:*:Enabled:PowerCinema" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Program Files\\Microsoft Games\\Age of Empires II\\empires2.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\empires2.exe:*:Enabled:Age of Empires II" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe:*:Disabled:AOL" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe:*:Disabled:AOL" "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Disabled:AOL 9.0" "C:\\Program Files\\CA\\Etrust Antivirus\\InoRpc.exe"="C:\\Program Files\\CA\\Etrust Antivirus\\InoRpc.exe:*:Enabled:eTrust Antivirus - RPC Server" "C:\\Program Files\\CA\\Etrust Antivirus\\InocIT.exe"="C:\\Program Files\\CA\\Etrust Antivirus\\InocIT.exe:*:Enabled:eTrust Antivirus - Local Scanner" "C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III" "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent" "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus" "C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp"="C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp:*:Disabled:KazaaLite" "C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exmodul32d.1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exmodul32d.1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exmodul32d.1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exmodul32d.1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\55exmodul32d.1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\55exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exmodul32d.1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\48exmodul32d.1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\48exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\51exmodul32d.2.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\51exmodul32d.2.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exmodul32d.3.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exmodul32d.3.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\6exmodul32d.4.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\6exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\77exmodul32d.4.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\77exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\69exmodul32d.4.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\69exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\9exmodul32d.4.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\9exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32d.4.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exmodul32d.4.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exmodul32d.4.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\13exmodul32d.4.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\13exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exmodul32d.4.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exmodul32d.4.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exmodul32d.5.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exmodul32d.5.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exmodul32d.5.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32d.5.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exmodul32d.6.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exmodul32d.6.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exmodul32d.6.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exmodul32d.6.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exmodul32d.6.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exmodul32d.6.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exmodul32d.a.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exmodul32d.a.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exmodul32d.a.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exmodul32d.a.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\80exmodul32d.a.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\80exmodul32d.a.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\86exinjs.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\86exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\20exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\20exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\27exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\27exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\79exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\79exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\4exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\4exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\74exinjs.p.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\74exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\44exinjs.p.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\44exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\24exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\24exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\37exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\37exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exinjs.p.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exinjs.p.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\96exinjs.q.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\96exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\22exinjs.q.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\22exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\23exinjs.q.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\23exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.q.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\92exinjs.q.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\92exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.q.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\58exinjs.q.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\58exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\38exinjs.q.exe"="C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\38exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\69exinjs.q.exe"="C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\69exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\78exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\78exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\18exinjs.q.exe"="C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\18exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\8exinjs.q.exe"="C:\\DOCUME~1\\FRANOI~1\\LOCALS~1\\Temp\\8exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.q.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.q.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\47exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\47exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\65exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\65exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\36exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\36exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\73exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\73exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\48exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\48exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\66exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\66exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\90exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\90exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\25exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\25exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\44exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\44exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\68exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\68exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\49exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\49exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\9exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\9exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\29exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\29exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\37exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\37exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\7exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\7exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\97exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\97exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\87exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\87exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\85exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\85exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\71exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\71exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\13exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\13exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\0exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\0exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\75exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\75exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\74exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\74exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\14exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\14exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.r.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\58exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\58exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\61exinjs.r.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\61exinjs.r.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\27exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\27exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\97exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\97exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\50exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\50exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\30exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\30exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\14exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\14exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.s.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\67exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\67exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\63exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\63exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\64exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\64exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\10exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\10exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\25exmodul32f.f.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\25exmodul32f.f.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\31exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\31exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\49exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\49exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\94exmodul32f.f.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\94exmodul32f.f.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.s.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.s.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32f.f.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32f.f.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\71exmodul32f.f.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\71exmodul32f.f.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\4exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\4exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\96exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\96exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\51exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\51exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.t.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\6exinjs.t.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\6exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\73exinjs.t.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\73exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\42exmodul32f.i.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\42exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\5exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\41exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\41exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\71exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\71exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\96exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\96exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\10exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\10exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\74exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\74exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\37exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\37exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exmodul32f.i.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exmodul32f.i.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.t.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.t.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\88exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\88exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\97exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\97exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\61exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\61exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\92exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\92exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\28exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\28exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\3exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\3exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\39exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\39exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\89exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\89exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\50exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\50exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\76exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\76exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\49exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\49exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\38exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\38exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\98exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\98exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\81exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\81exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\55exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\55exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\71exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\71exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\0exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\0exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\60exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\60exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\10exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\10exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\44exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\44exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\33exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\33exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\61exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\61exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\98exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\98exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\24exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\24exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\68exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\68exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\82exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\82exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\51exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\51exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\62exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\62exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\59exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\59exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\38exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\38exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\99exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\99exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\36exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\36exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\6exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\6exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\69exinjs.u.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\69exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\80exmodul32f.k.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\80exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\80exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\80exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\58exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\58exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exmodul32f.k.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exmodul32f.k.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\20exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\20exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\75exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\75exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\70exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\70exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\65exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\65exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.u.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.u.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\88exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\37exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\37exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\65exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\65exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\39exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\39exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\81exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\81exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\47exmodul32f.l.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\47exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\94exmodul32f.l.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\94exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\95exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\62exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\62exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exmodul32f.l.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exmodul32f.l.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\54exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exmodul32f.m.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exmodul32f.m.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exmodul32f.m.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exmodul32f.m.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exmodul32f.m.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exmodul32f.m.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exmodul32f.m.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exmodul32f.m.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\62exmodul32f.m.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\62exmodul32f.m.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\8exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\8exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\83exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\83exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\73exml32.7.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\73exml32.7.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\29exed32_2.a.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\29exed32_2.a.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\37exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\37exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\5exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\5exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\12exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\12exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\88exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\88exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\79exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\79exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\93exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\93exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\9exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\9exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\79exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\79exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\53exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\53exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exmodul32f.n.exe:*:Enabled:Microsoft Update" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\4exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\4exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\97exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\97exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\66exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\66exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\70exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\70exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\86exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\41exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\41exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exed32_2.a.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exed32_2.a.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\68exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\68exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\12exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\58exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\58exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\30exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\30exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exmodul32f.n.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\78exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\78exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\96exmodul32f.n.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\96exmodul32f.n.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\15exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\15exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exmodul32f.o.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\72exmodul32f.o.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\72exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\18exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\18exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\0exmodul32f.o.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\0exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\96exmodul32f.o.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\96exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\53exmodul32f.o.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\53exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\65exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\65exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\30exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\30exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\58exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\58exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\43exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\43exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\69exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exmodul32f.o.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\34exinjs.v.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\34exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exmodul32f.o.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exmodul32f.o.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exinjs.v.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exinjs.v.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\25exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\25exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\24exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\14exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\14exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\30exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\30exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\92exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\92exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\60exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\80exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\80exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\82exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\82exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\58exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\58exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\47exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\49exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\49exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\83exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exml32.7.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exml32.7.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\75exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\75exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\77exinjs.w.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\77exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exml32.7.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\63exml32.7.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\1exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\1exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exml32.7.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exml32.7.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\59exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exinjs.w.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exinjs.w.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\51exinjs.x.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\51exinjs.x.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\56exinjs.x.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\56exinjs.x.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\76exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\76exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\67exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\67exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\94exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\94exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\41exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\41exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\43exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\43exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\45exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\45exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\49exml32.7.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\49exml32.7.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\14exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\14exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\4exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\4exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\17exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\22exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\98exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\36exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\43exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\43exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\91exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\91exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\42exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\42exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\7exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\70exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\70exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\26exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\1exinjs.y.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\1exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\38exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\0exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\0exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\Documents and Settings\\HOHWALD'S\\Bureau\\Jeux\\Warcraft III\\Warcraft III.exe"="C:\\Documents and Settings\\HOHWALD'S\\Bureau\\Jeux\\Warcraft III\\Warcraft III.exe:*:Disabled:Warcraft III" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\24exinjs.y.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\24exinjs.y.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exed32_2.a.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\6exed32_2.a.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\91exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\99exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\57exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\93exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\27exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\27exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\41exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\41exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.z.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\57exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.z.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\33exinjs.z.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\33exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\55exinjs.z.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\55exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.z.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\99exinjs.z.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\99exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\19exinjs.z.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\19exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\82exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\77exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\15exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\96exinjs.z.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\96exinjs.z.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\67exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\87exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\87exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\21exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\85exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\28exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\29exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\23exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\25exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\40exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\62exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\56exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\56exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\92exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\19exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\49exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\49exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\46exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\3exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\39exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\39exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\11exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\89exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\32exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\0exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\0exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\21exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\27exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\27exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\81exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\26exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\16exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\13exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\13exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\78exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\78exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\34exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\34exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\53exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\75exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\20exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\20exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\17exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\17exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\71exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\71exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\95exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\33exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\28exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\28exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\48exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\48exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\52exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\76exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\76exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\8exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\8exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\8exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\9exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\53exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\53exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\55exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\55exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\54exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\80exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\80exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\2exinjs.a1.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\2exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\73exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\27exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\27exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\45exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\34exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\84exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\72exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\31exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\52exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\42exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\35exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\79exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\79exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\90exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\94exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\76exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\66exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\18exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\50exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\64exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\2exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exinjs.a1.exe"="C:\\DOCUME~1\\HOHWAL~1\\LOCALS~1\\Temp\\44exinjs.a1.exe:*:Enabled:Microsoft Update" "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule" "C:\\Documents and Settings\\Samuel\\Bureau\\Jeux\\Blobby\\volley.exe"="C:\\Documents and Settings\\Samuel\\Bureau\\Jeux\\Blobby\\volley.exe:*:Disabled:volley" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\22exinjs.aa.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\22exinjs.aa.exe:*:Enabled:Microsoft Update" "C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\61exinjs.aa.exe"="C:\\DOCUME~1\\Samuel\\LOCALS~1\\Temp\\61exinjs.aa.exe:*:Enabled:Microsoft Update" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Documents and Settings\\HOHWALD'S\\Local Settings\\Temp\\WZSE0.TMP\\symnrt.exe"="C:\\Documents and Settings\\HOHWALD'S\\Local Settings\\Temp\\WZSE0.TMP\\symnrt.exe:*:Enabled:Symantec Removal Utility" "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL" "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Mon 23 Jun 2008 625,664 A.SH. --- "C:\Program Files\Internet Explorer\iexplore.exe" Thu 5 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe" Thu 5 Aug 2004 4,639 A.SH. --- "C:\Program Files\Windows Media Player\mplayer2.exe" Wed 11 Aug 2004 73,728 A.SH. --- "C:\Program Files\Windows Media Player\wmplayer.exe" Sat 6 Sep 2008 1,539,584 ..SH. --- "C:\WINDOWS\system32\inglog.exe" Fri 13 May 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Fri 22 Jun 2007 1,094,656 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL0710.tmp" Fri 22 Jun 2007 1,094,656 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL1233.tmp" Fri 22 Jun 2007 1,094,656 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL1540.tmp" Sat 15 Mar 2008 1,276,928 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL2504.tmp" Sat 15 Mar 2008 1,275,392 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL2762.tmp" Tue 17 Jun 2008 1,389,568 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL3108.tmp" Fri 22 Jun 2007 1,094,656 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL3350.tmp" Fri 22 Jun 2007 1,094,656 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\~WRL4095.tmp" Fri 13 Aug 2004 1,953,792 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\launcher.exe" Fri 13 Aug 2004 53,760 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\mnyinsta.dll" Fri 13 Aug 2004 94,208 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\RmvSuite.exe" Mon 16 Aug 2004 35,328 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\setuplng.dll" Fri 13 Aug 2004 20,480 A..HR --- "C:\Program Files\Microsoft Works Suite 2005\Setup\unregwtr.exe" Sun 5 Nov 2006 970,752 A.SH. --- "C:\Documents and Settings\All Users\Documents\101MSDCF\SIV2.tmp" Tue 28 Sep 2004 13,739 A..H. --- "C:\Documents and Settings\Fran‡ois\Bureau\CCN Stg\~WRL3969.tmp" Mon 13 Jun 2005 208,896 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL0678.tmp" Mon 13 Jun 2005 195,072 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL0761.tmp" Wed 13 Jul 2005 608,768 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL0789.tmp" Tue 12 Jul 2005 593,920 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL1194.tmp" Thu 23 Jun 2005 364,032 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL2097.tmp" Thu 23 Jun 2005 366,080 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL2301.tmp" Mon 13 Jun 2005 205,312 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL2373.tmp" Mon 13 Jun 2005 202,752 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL2718.tmp" Mon 13 Jun 2005 205,312 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL2849.tmp" Mon 27 Jun 2005 412,672 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL2879.tmp" Sun 12 Jun 2005 186,880 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL3076.tmp" Wed 13 Jul 2005 622,592 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL3297.tmp" Mon 13 Jun 2005 204,800 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL3658.tmp" Wed 13 Jul 2005 623,104 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL3809.tmp" Mon 13 Jun 2005 205,824 ...H. --- "C:\Documents and Settings\Fran‡ois\Bureau\ThŠse\~WRL3824.tmp" Sun 5 Nov 2006 970,752 A.SH. --- "C:\Documents and Settings\Fran‡ois\Bureau\Br‚sil\101MSDCF\SIV2.tmp" Tue 9 Jan 2007 864,256 A.SH. --- "C:\Documents and Settings\Fran‡ois\Bureau\Prague\100_PANA\SIV50.tmp" Sun 5 Nov 2006 970,752 A.SH. --- "C:\Documents and Settings\HOHWALD'S\Bureau\SAUVEGARDES\photos\Photos Brasil\101MSDCF\SIV2.tmp" Finished! et voila le log.txt : Logfile of random's system information tool (written by random/random) Run by HOHWALD'S at 2008-09-06 17:14:10 Microsoft Windows XP Édition familiale Service Pack 2 System drive C: has 98 GB (66%) free of 148 GB Total RAM: 511 MB (15% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:14, on 2008-09-06 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\USB Storage RW\DskWatch.exe C:\WINDOWS\system32\carpserv.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\WINDOWS\system32\msnnet.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Documents and Settings\HOHWALD'S\Bureau\RSIT.exe C:\HK\HOHWALD'S.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [uSB Storage RW] C:\Program Files\USB Storage RW\DskWatch.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [msn_livers] C:\windows\temp\msnmsgr.exe O4 - HKLM\..\Run: [msne] C:\WINDOWS\system32\msnnet.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [star1] C:\WINDOWS\system32\Winrun.exe O4 - HKCU\..\Run: [star2] C:\WINDOWS\system32\ischot.exe O4 - HKCU\..\Run: [star3] C:\WINDOWS\system32\Xred1.exe O4 - HKCU\..\Run: [star4] C:\WINDOWS\system32\Zred2.exe O4 - HKCU\..\Run: [star6] C:\WINDOWS\system32\MscheldB.exe O4 - HKCU\..\Run: [star7] C:\WINDOWS\system32\Mscheldncx.exe O4 - HKCU\..\Run: [star8] C:\WINDOWS\system32\svscheld.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.targa.co.uk O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1108507380937 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CA9FCA32-5396-4737-A69D-188CA85B3056}: NameServer = 86.64.145.142 84.103.237.142 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe -- End of file - 9879 bytes Registry dump [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}] HP Print Enhancer - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}] HP Print Clips - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}] Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-04-23 1377576] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}] VMN Toolbar - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL [2007-08-21 1895896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - VMN Toolbar - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL [2007-08-21 1895896] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2005-03-08 53248] "SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-02-09 65024] "USB Storage RW"=C:\Program Files\USB Storage RW\DskWatch.exe [2004-12-23 208896] "CARPService"=C:\WINDOWS\system32\carpserv.exe [2003-03-19 4608] "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648] "AntivirusRegistration"=C:\Program Files\CA\Etrust Antivirus\Register.exe [2005-01-31 458752] "Realtime Monitor"=C:\PROGRA~1\CA\ETRUST~1\realmon.exe [2004-06-26 504080] "PCMService"=C:\Program Files\CyberLink\PowerCinema\PCMService.exe [2005-02-18 110744] "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2005-02-21 98304] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784] "VTTrayp"=C:\WINDOWS\system32\VTtrayp.exe [2005-03-11 147456] "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2003-04-28 323584] "ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [2006-09-25 90112] "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152] "msn_livers"=C:\windows\temp\msnmsgr.exe [] "msne"=C:\WINDOWS\system32\msnnet.exe [2008-09-06 443904] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360] "star1"=C:\WINDOWS\system32\Winrun.exe [] "star2"=C:\WINDOWS\system32\ischot.exe [] "star3"=C:\WINDOWS\system32\Xred1.exe [] "star4"=C:\WINDOWS\system32\Zred2.exe [] "star6"=C:\WINDOWS\system32\MscheldB.exe [] "star7"=C:\WINDOWS\system32\Mscheldncx.exe [] "star8"=C:\WINDOWS\system32\svscheld.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\meqoi] c:\documents and settings\hohwald's\local settings\application data\meqoi.exe meqoi [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM-Reset] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "Windows Log"=2 C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] C:\WINDOWS\system32\Ati2evxx.dll [2006-12-17 110592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-05 240128] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=msapsspc.dll schannel.dll digest.dll msnsspc.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\CA\Etrust Antivirus\Realmon.exe"="C:\Program Files\CA\Etrust Antivirus\Realmon.exe:*:Enabled:Realmon" "C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe"="C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe:*:Enabled:PowerCinema" "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger" "C:\Program Files\Microsoft Games\Age of Empires II\empires2.exe"="C:\Program Files\Microsoft Games\Age of Empires II\empires2.exe:*:Enabled:Age of Empires II" "C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe:*:Disabled:AOL" "C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe:*:Disabled:AOL" "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Disabled:AOL 9.0" "C:\Program Files\CA\Etrust Antivirus\InoRpc.exe"="C:\Program Files\CA\Etrust Antivirus\InoRpc.exe:*:Enabled:eTrust Antivirus - RPC Server" "C:\Program Files\CA\Etrust Antivirus\InocIT.exe"="C:\Program Files\CA\Etrust Antivirus\InocIT.exe:*:Enabled:eTrust Antivirus - Local Scanner" "C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III" "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent" "C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus" "C:\Program Files\Kazaa Lite K++\KazaaLite.kpp"="C:\Program Files\Kazaa Lite K++\KazaaLite.kpp:*:Disabled:KazaaLite" "C:\WINDOWS\system32\svchost.exe"="C:\WINDOWS\system32\svchost.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\45exmodul32d.1.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\45exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\29exmodul32d.1.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\29exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\66exmodul32d.1.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\66exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\15exmodul32d.1.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\15exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\55exmodul32d.1.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\55exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\59exmodul32d.1.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\59exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\48exmodul32d.1.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\48exmodul32d.1.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\51exmodul32d.2.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\51exmodul32d.2.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\50exmodul32d.3.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\50exmodul32d.3.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\6exmodul32d.4.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\6exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\77exmodul32d.4.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\77exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\69exmodul32d.4.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\69exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\9exmodul32d.4.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\9exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\21exmodul32d.4.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\21exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\95exmodul32d.4.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\95exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\88exmodul32d.4.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\88exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\13exmodul32d.4.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\13exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\25exmodul32d.4.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\25exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\44exmodul32d.4.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\44exmodul32d.4.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\45exmodul32d.5.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\45exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\67exmodul32d.5.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\67exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\92exmodul32d.5.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\92exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\2exmodul32d.5.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\2exmodul32d.5.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\73exmodul32d.6.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\73exmodul32d.6.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\90exmodul32d.6.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\90exmodul32d.6.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\93exmodul32d.6.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\93exmodul32d.6.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\85exmodul32d.a.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\85exmodul32d.a.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\28exmodul32d.a.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\28exmodul32d.a.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\80exmodul32d.a.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\80exmodul32d.a.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\86exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\86exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\69exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\69exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\86exinjs.n.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\86exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\77exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\77exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\20exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\20exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\50exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\50exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\23exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\23exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\95exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\95exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\35exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\35exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\64exinjs.n.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\64exinjs.n.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\88exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\88exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\52exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\52exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\46exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\46exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\86exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\86exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\84exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\84exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\35exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\35exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\27exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\27exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\16exinjs.o.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\16exinjs.o.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\32exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\32exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\84exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\84exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\59exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\59exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\6exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\6exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\98exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\98exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\79exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\79exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\4exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\4exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\69exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\69exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\91exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\91exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\74exinjs.p.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\74exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\Samuel\LOCALS~1\Temp\44exinjs.p.exe"="C:\DOCUME~1\Samuel\LOCALS~1\Temp\44exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\24exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\24exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\37exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\37exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\82exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\82exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\53exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\53exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\25exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\25exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\34exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\34exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\38exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\38exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\95exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\95exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\54exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\54exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\7exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\7exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\62exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\62exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\77exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\77exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\72exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\72exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\92exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\92exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\17exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\17exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\11exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\11exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\46exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\46exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\15exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\15exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\90exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\90exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\28exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\28exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\64exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\64exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\60exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\60exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\57exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\57exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\36exinjs.p.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\36exinjs.p.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\40exinjs.q.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\40exinjs.q.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\94exinjs.q.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\94exinjs.q.exe:*:Enabled:Microsoft Update" "C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\35exinjs.q.exe"="C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\35exinjs.q.exe:*:Enabled:Microsoft Update" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe:*:Enabled:AOL" "C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLacsd.exe:*:Enabled:AOL" "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL 9.0" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9958706-7f1a-11d9-acd4-806d6172696f}] shell\AutoRun\command - I:\Autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f995870c-7f1a-11d9-acd4-806d6172696f}] shell\AutoRun\command - D:\Autorun.exe File associations .scr - open - "%1" %* List of files/folders created in the last three months 2008-09-06 17:14:10 ----D---- C:\rsit 2008-09-06 16:45:10 ----D---- C:\SDFix 2008-09-06 10:53:56 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe 2008-09-06 10:40:51 ----A---- C:\WINDOWS\system32\msnnet.exe 2008-09-06 10:40:38 ----SH---- C:\WINDOWS\system32\inglog.exe 2008-08-31 11:41:38 ----A---- C:\WINDOWS\ntbtlog.txt 2008-08-31 11:34:26 ----D---- C:\Program Files\CCleaner 2008-08-27 11:00:12 ----D---- C:\_OTMoveIt 2008-08-24 19:24:22 ----D---- C:\Program Files\Navilog1 2008-08-24 17:43:14 ----D---- C:\WINDOWS\ERUNT 2008-08-24 16:48:09 ----D---- C:\Documents and Settings\HOHWALD'S\Application Data\Malwarebytes 2008-08-24 16:47:23 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-08-24 14:09:08 ----D---- C:\Documents and Settings\All Users\Application Data\Avira 2008-08-23 22:42:43 ----A---- C:\WINDOWS\Nircmd.exe 2008-08-23 22:42:37 ----A---- C:\WINDOWS\system32\CF26673.exe 2008-08-23 22:25:25 ----A---- C:\WINDOWS\system32\CF23296.exe 2008-08-23 20:48:07 ----A---- C:\Boot.bak 2008-08-23 20:47:46 ----D---- C:\cmdcons 2008-08-23 20:43:01 ----A---- C:\WINDOWS\system32\CF3223.exe 2008-08-23 20:35:52 ----D---- C:\WINDOWS\erdnt 2008-08-23 20:35:24 ----D---- C:\QooBox 2008-08-23 20:35:20 ----A---- C:\WINDOWS\zip.exe 2008-08-23 20:35:20 ----A---- C:\WINDOWS\VFind.exe 2008-08-23 20:35:20 ----A---- C:\WINDOWS\swxcacls.exe 2008-08-23 20:35:20 ----A---- C:\WINDOWS\swsc.exe 2008-08-23 20:35:20 ----A---- C:\WINDOWS\swreg.exe 2008-08-23 20:35:20 ----A---- C:\WINDOWS\sed.exe 2008-08-23 20:35:20 ----A---- C:\WINDOWS\grep.exe 2008-08-23 20:35:20 ----A---- C:\WINDOWS\fdsv.exe 2008-08-23 20:35:11 ----A---- C:\WINDOWS\system32\CF1684.exe 2008-08-23 20:05:53 ----D---- C:\HK 2008-08-23 19:56:42 ----D---- C:\backups 2008-08-23 19:30:00 ----D---- C:\WINDOWS\pss 2008-08-23 19:03:05 ----D---- C:\Documents and Settings\HOHWALD'S\Application Data\WinRAR 2008-08-23 19:02:39 ----D---- C:\Program Files\WinRAR 2008-08-23 18:58:36 ----A---- C:\WINDOWS\system32\javaws.exe 2008-08-23 18:58:36 ----A---- C:\WINDOWS\system32\javaw.exe 2008-08-23 18:58:36 ----A---- C:\WINDOWS\system32\java.exe 2008-08-22 20:24:31 ----D---- C:\WINDOWS\system32\CatRoot_bak 2008-08-19 00:59:51 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$ 2008-08-19 00:59:44 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$ 2008-08-19 00:59:37 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$ 2008-08-19 00:59:30 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$ 2008-08-19 00:59:22 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$ 2008-08-19 00:58:07 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$ 2008-07-09 22:43:36 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$ 2008-06-23 16:25:25 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$ 2008-06-14 09:27:44 ----D---- C:\WINDOWS\NTX16AFJOUY27BGK 2008-06-11 18:05:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$ 2008-06-11 18:05:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$ 2008-06-11 18:05:27 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$ 2008-06-11 18:05:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$ List of drivers R1 AmdK8;Pilote de processeur AMD Athlon64; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2003-11-07 38400] R1 oreans32;oreans32; \??\C:\WINDOWS\system32\drivers\oreans32.sys [] R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\system32\System32\drivers\prodrv06.sys [] R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936] R2 enodpl;enodpl; C:\WINDOWS\System32\drivers\enodpl.sys [2003-03-02 7552] R2 INO_FLTR;INO_FLTR; \??\C:\WINDOWS\system32\Drivers\ino_fltr.sys [] R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-03-19 11044] R2 ONSIO;ONSIO; \??\C:\WINDOWS\SYSTEM32\DRIVERS\ONSIO.SYS [] R2 StreamDispatcher;StreamDispatcher; C:\WINDOWS\system32\DRIVERS\strmdisp.sys [2003-03-19 22400] R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys [] R2 tandpl;tandpl; C:\WINDOWS\System32\drivers\tandpl.sys [2003-04-19 4736] R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776] R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-12 391424] R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-02-19 610988] R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800] R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-12-17 1918464] R3 BridgeMP;Miniport de pont MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2004-08-05 71552] R3 catchme;catchme; \??\C:\DOCUME~1\HOHWAL~1\LOCALS~1\Temp\catchme.sys [] R3 dskwatch;Disk Watch Filter; C:\WINDOWS\system32\drivers\dskwatch.sys [2004-11-30 15232] R3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496] R3 fhlppppoe;PPPOE/ADSL miniport; C:\WINDOWS\system32\DRIVERS\fhlpppoe.sys [2004-06-04 49200] R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-08 49920] R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496] R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-08 21568] R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-03-19 1107072] R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2003-03-19 177024] R3 MODEMCSA;Périphérique de filtrage de flux Unimodem; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128] R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824] R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-05 5888] R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616] R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-05 26624] R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600] R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856] R3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104] R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 26496] R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-05 20480] R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-03-19 622592] S1 vspf;vspf; \??\C:\WINDOWS\system32\drivers\vspf5.sys [] S1 vspf_hk;vspf_hk; \??\C:\WINDOWS\system32\drivers\vspf_hk5.sys [] S3 Bridge;Pont MAC; C:\WINDOWS\system32\DRIVERS\bridge.sys [2004-08-05 71552] S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024] S3 dtscsi;dtscsi; C:\WINDOWS\system32\System32\Drivers\dtscsi.sys [] S3 FETNDIS;Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165] S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504] S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376] S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880] S3 NTSIM;NTSIM; \??\C:\WINDOWS\system32\ntsim.sys [] S3 ovt530;Webcam Deluxe; C:\WINDOWS\System32\Drivers\ov530vid.sys [2005-03-15 161792] S3 scsiscan;Pilote de scanneur SCSI; C:\WINDOWS\system32\DRIVERS\scsiscan.sys [2001-08-17 10880] S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136] S3 SQTECH905C;DaulCamera; C:\WINDOWS\System32\Drivers\Capt905c.sys [2004-02-13 27148] S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360] S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264] S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2005-04-06 173696] S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [] S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] List of services R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-12-17 434176] R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe [2005-02-18 172153] R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe [2005-02-18 110711] R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe [2005-02-18 24576] R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336] R2 InoRPC;eTrust Antivirus RPC Server; C:\Program Files\CA\eTrust Antivirus\InoRpc.exe [2004-06-26 139536] R2 InoRT;eTrust Antivirus Realtime Server; C:\Program Files\CA\eTrust Antivirus\InoRT.exe [2004-06-26 241936] R2 InoTask;eTrust Antivirus Job Server; C:\Program Files\CA\eTrust Antivirus\InoTask.exe [2004-06-26 254224] R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-05 14336] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-05 14336] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-10-11 38912] R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336] R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328] S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-12-20 520192] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240] S3 WmcCds;Windows Media Connect (WMC); c:\program files\windows media connect\mswmccds.exe [2004-08-11 483328] S3 WmcCdsLs;Aide de Windows Media Connect (WMC); C:\Program Files\Windows Media Connect\mswmcls.exe [2004-08-10 28160] -----------------EOF----------------- Et maintenant le info.txt : info.txt logfile of random's system information tool 2008-09-06 17:14:24 Uninstall list -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL -->C:\WINDOWS\UNNVEContent.exe /UNINSTALL -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf -->VTUninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Timer' 32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7} Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002} Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe ArtRage 2.2 Free-->"C:\Program Files\Ambient Design\ArtRage 2 Free\unins000.exe" Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986} ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe ATI Catalyst Control Center-->MsiExec.exe /I{B7777E08-1344-42E8-975B-6F541F9ADBD8} ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe" ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean AVI Info-->C:\WINDOWS\st6unst.exe -n "C:\AVI Info\ST6UNST.LOG" Beyond Good & Evil-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6BF81CE7-3D5A-497F-8912-2A65A0253E1B}\setup.exe" -l0x40c BSPlayer-->"C:\Program Files\Webteh\BSplayer\uninstall.exe" c:\documents and settings\hohwald's\bureau\jeux-->C:\WINDOWS\IsUn040c.exe -f"c:\documents and settings\hohwald's\bureau\jeux\Uninst.isu" CA eTrust Antivirus-->MsiExec.exe /X{6A120E99-3123-4CB2-9A02-D24784F4BC8C} CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe" CDex 1.40 Fr [Extraction Audio]-->"C:\Program Files\CDex\uninstall.exe" Complément Microsoft Word pour Microsoft Works Suite-->MsiExec.exe /I{17E57E89-DDB3-4f76-9AF1-A8E01CC633E4} Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe" Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe" Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe" Correctif Windows XP - KB867282-->C:\WINDOWS\$NtUninstallKB867282$\spuninst\spuninst.exe Correctif Windows XP - KB873333-->C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe Correctif Windows XP - KB885250-->C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe Correctif Windows XP - KB885884-->C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe Correctif Windows XP - KB887742-->C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe Correctif Windows XP - KB887797-->C:\WINDOWS\$NtUninstallKB887797$\spuninst\spuninst.exe Correctif Windows XP - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe Correctif Windows XP - KB890047-->C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe Correctif Windows XP - KB890175-->C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe" Correctif Windows XP - KB890923-->"C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe" Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe Correctif Windows XP - KB893066-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe" Correctif Windows XP - KB893086-->"C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe" DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC EA SPORTS online 2004-->C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe EAX Unified-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Creative\EAX Unified\Uninst.isu" Emergency 2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{874F0C23-7CA8-4639-9D77-E032E272A3FD}\setup.exe" -l0x40c -uninst Encyclopédie Microsoft Encarta 2005-->MsiExec.exe /I{05460044-64A6-4248-A026-9745C1E9E159} Enjoy 6e-->C:\WINDOWS\Enjoy 6e Uninstaller.exe eTrust Registration-->MsiExec.exe /X{6BFF4534-7608-41F0-85F7-31A0569D8960} Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F} Fable - The Lost Chapters-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{C3C9EB3D-24FA-4462-B784-0EC6AAFCD2DD} ffdshow (remove only)-->"C:\Program Files\ffdshow\uninstall.exe" Fire Department 2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1DA8594C-2F14-4491-B155-2BF3A999622D}\setup.exe" -l0x40c Uninstall FM-56PCI-HSFi-AB-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F00\HXFSETUP.EXE -U -IVEN_14F1&DEV_2F02&SUBSYS_000B1767 Google Earth-->MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90} GTA2-->C:\WINDOWS\IsUn040c.exe -fc:\hohwald's\bureau\jeux\Uninst.isu Haali Matroska Splitter-->"C:\Program Files\Mirage-Team Decoder Pack\filtres\haali\uninstall.exe" Hercules Webcam-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A250D351-A07F-4D5D-AB6C-693C69B9BFAF}\Setup.exe" -l0x40c HijackThis 2.0.2-->"C:\HK\HijackThis.exe" /uninstall Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe" HP Customer Participation Program 9.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat HP Imaging Device Functions 9.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat HP OCR Software 9.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat HP Photosmart All-In-One Software 9.0-->C:\Program Files\HP\Digital Imaging\{B22C19AE-6A67-4f28-B541-5AE72FB17A25}\setup\hpzscr01.exe -datfile hposcr15.dat HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7} HP Solution Center 9.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134} HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3} J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060} Java 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060} Java 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} Java SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} Le Fabuleux Voyage de l'Oncle Ernest-->C:\emme\Voyage\Desinst.exe Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Les départements français-->"C:\Program Files\GEOGRAPHIE\FRANCE\uninstall.exe" Les pays d'Europe-->"C:\Program Files\GEOGRAPHIE\EUROPE\uninstall.exe" Les Sims-->C:\WINDOWS\IsUn040c.exe -f"c:\program files\les Sims\Uninst.isu" Macromedia Dreamweaver 2-->C:\WINDOWS\IsUn040c.exe -f"c:\hohwald's\bureau\Dreamweaver 2\Uninst.isu" Micromega Software System EasyScan-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\EasyScan\Uninst.isu" Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700} Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp" Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28} Microsoft Age of Empires II-->"C:\Program Files\Microsoft Games\Age of Empires II\UNINSTAL.EXE" /runtemp /uninstall Microsoft Age of Empires-->C:\HOHWALD'S\Bureau\jeux\Desinstallation.exe /uninstall Microsoft AutoRoute 2005-->MsiExec.exe /I{67E4EE98-59F4-4220-89A6-A20AF5BEC689} Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe" Microsoft Money-->C:\Program Files\Microsoft Money 2005\MNYCoreFiles\Setup\uninst.exe /s:120 Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe" Microsoft Office Excel Viewer 2003-->MsiExec.exe /I{9084040C-6000-11D3-8CFE-0150048383C9} Microsoft Office Visio Professional 2003-->MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9} Microsoft Photo Premium 10-->"C:\Program Files\Fichiers communs\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=PREM Microsoft Word 2002-->MsiExec.exe /I{911B040C-6000-11D3-8CFE-0050048383C9} Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04} Microtek ScanWizard-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17A7779A-D23F-11D3-8753-0050BABE1202}\setup.exe" Mirage-Team Decoder Pack-->C:\Program Files\Mirage-Team Decoder Pack\Uninstall.exe Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe" Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe" Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe" Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe" Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe" Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe" Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB883939)-->"C:\WINDOWS\$NtUninstallKB883939$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB896422)-->"C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB896688)-->"C:\WINDOWS\$NtUninstallKB896688$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB899588)-->"C:\WINDOWS\$NtUninstallKB899588$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB903235)-->"C:\WINDOWS\$NtUninstallKB903235$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB905915)-->"C:\WINDOWS\$NtUninstallKB905915$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB911567)-->"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB912812)-->"C:\WINDOWS\$NtUninstallKB912812$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB913446)-->"C:\WINDOWS\$NtUninstallKB913446$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB916281)-->"C:\WINDOWS\$NtUninstallKB916281$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB917159)-->"C:\WINDOWS\$NtUninstallKB917159$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB925454)-->"C:\WINDOWS\$NtUninstallKB925454$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB925486)-->"C:\WINDOWS\$NtUninstallKB925486$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe" Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB896727)-->"C:\WINDOWS\$NtUninstallKB896727$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe" Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe" Mozilla Firefox (3.0.1)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} Mulan FTH-->C:\WINDOWS\unin040c.exe -fC:\PROGRA~1\DISNEY~1\MULANF~1\DeIsL1.isu My Pictures And Sounds 7.04-->C:\Program Files\SAGEM\My Pictures And Sounds\Uninstall.exe MyDsc2-->C:\Program Files\InstallShield Installation Information\{83d96ed0-98aa-4515-8ddc-816f3efdd104}\setup.exe Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID="" PowerCinema 4.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall PPP over Ethernet-->rundll32.exe pppoe32.dll,Uninstall QuickTime for Windows (32-bit)-->C:\WINDOWS\QTW32DEL.EXE QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE RollerCoaster Tycoon® 3 Demo-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{990036E7-D647-45A4-8F7F-1CB277EF0ABD}\Setup.exe" -l0x40c S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display' S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2' S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2' S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay' S3 S3TrayPlus-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3TrayPlus' Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Sélecteur d'installation de Microsoft Works 2005-->C:\Program Files\Microsoft Works Suite 2005\Setup\Launcher.exe /ARP e:\ Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82} Syberia-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Documents and Settings\HOHWALD'S\Bureau\Jeux\Uninstall\setup.exe" -l0x40c UniChrome Pro IGP Display Driver and Utilities-->C:\PROGRA~1\S3Inc\S3\s3setvga.exe -s -fC:\PROGRA~1\S3Inc\S3\S3.uns Uninstall USB Storage RW 3.00.06.b03-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{30A3EE3C-D860-4A6C-BB6B-E6B92C927703}\setup.exe" -l0x40c UNINST VIA Gestionnaire de périphériques de plate-forme-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169} VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA VIA/S3G Display Driver-->C:\PROGRA~1\VIA\UChromeP\s3minset.exe /u C:\PROGRA~1\VIA\UChromeP\UChromeP.uns VideoLAN VLC media player 0.8.6b-->C:\Program Files\VideoLAN\VLC\uninstall.exe VMN Toolbar-->C:\Program Files\vmntoolbar\uninstall.exe Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe" Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe" Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390} Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65} Windows Media Connect-->msiexec.exe /I {F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B} Windows Media Connect-->MsiExec.exe /I{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B} Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Hosts File 127.0.0.1 localhost Environment variables "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\PROGRA~1\CA\SHARED~1\SCANEN~1;C:\PROGRA~1\CA\ETRUST~1;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\ATI Technologies\ATI.ACE;C:\Program Files\Smart Projects\IsoBuster "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 28 Stepping 0, AuthenticAMD "PROCESSOR_REVISION"=1c00 "NUMBER_OF_PROCESSORS"=1 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "AVENGINE"=C:\PROGRA~1\CA\SHARED~1\SCANEN~1 "INOCULAN"=C:\PROGRA~1\CA\ETRUST~1 -----------------EOF----------------- Bon courage pour déchiffrer tout ça!!
  6. Bonjour à tous, et merci d'avance à celui ou celle qui aura la possibilité de me consacrer un petit peu de temps. J'ai reçu il y a peu un mail qui proposait un lien vers une e-card. Je l'ai helas ouvert et me retrouve maintenant avec un PC lent, et qui ouvre des pages d'IE sans arret (j'utilise mozilla). Je vous poste le log hijackthis que je viens de faire. Je sais que vous n'avez pas que ça à faire d'aider de pauvres internautes, je serai donc patient. Merci Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:58, on 2008-09-06 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\USB Storage RW\DskWatch.exe C:\WINDOWS\system32\carpserv.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\inglog.exe C:\WINDOWS\system32\msn.exe C:\WINDOWS\system32\msnnet.exe C:\WINDOWS\system32\inglog.exe C:\WINDOWS\system32\msnnet.exe C:\WINDOWS\system32\inglog.exe C:\WINDOWS\system32\msnnet.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\inglog.exe C:\WINDOWS\system32\msnnet.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\HK\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [uSB Storage RW] C:\Program Files\USB Storage RW\DskWatch.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [GlobalFlagimglog] C:\WINDOWS\system32\imglog.exe O4 - HKLM\..\Run: [msn_livers] C:\windows\temp\msnmsgr.exe O4 - HKLM\..\Run: [msne] C:\WINDOWS\system32\msnnet.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [star1] C:\WINDOWS\system32\Winrun.exe O4 - HKCU\..\Run: [star2] C:\WINDOWS\system32\ischot.exe O4 - HKCU\..\Run: [star3] C:\WINDOWS\system32\Xred1.exe O4 - HKCU\..\Run: [star4] C:\WINDOWS\system32\Zred2.exe O4 - HKCU\..\Run: [star6] C:\WINDOWS\system32\MscheldB.exe O4 - HKCU\..\Run: [star7] C:\WINDOWS\system32\Mscheldncx.exe O4 - HKCU\..\Run: [star8] C:\WINDOWS\system32\svscheld.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.targa.co.uk O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1108507380937 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CA9FCA32-5396-4737-A69D-188CA85B3056}: NameServer = 84.103.237.142 86.64.145.142 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe -- End of file - 10282 bytes
  7. Salut Apollo, j'ai donc refait une analyse complete avec MBAM, il n'a rien trouvé. Je n'ai pas le log pour te le confirmer car je ne sais pas ou il est enregistrer. Y a t-il d'autres démarches à faire?
  8. me revoila... Alors le rapport de OTmovit2 : File/Folder c:\documents and settings\hohwald's\local settings\application data\meqoi.exe not found. OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08272008_110012 Et je me relance donc de suite dans un scan complet de MBAM a bientot
  9. Merci pour ton aide jusqu'à maintenant, par contre je dois partir et ne serai pas de retour avant mercredi soir. Je me chargerai donc de tout cela à ce moment la. J'espère que tu seras disponible à ce moment, ou plus tard si jamais. A bientot
  10. Voila le rapport généré apres l'étape 2 : Clean Navipromo version 3.6.5 commencé le 2008-08-24 à 19:49:06.45 Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "HOHWALD'S" Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 7.0.5730.11 Système de fichiers : NTFS Mode suppression automatique avec prise en charge résultats Catchme et GNS Nettoyage exécuté au redémarrage de l'ordinateur *** fsbl1.txt non trouvé *** (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche) *** Suppression avec sauvegardes résultats GenericNaviSearch *** * Suppression dans "C:\WINDOWS\System32" * * Suppression dans "C:\Documents and Settings\HOHWALD'S\locals~1\applic~1" * * Suppression dans "C:\DOCUME~1\FRANOI~1\locals~1\applic~1" * * Suppression dans "C:\DOCUME~1\NOLLE~1\locals~1\applic~1" * *** Suppression dossiers dans "C:\WINDOWS" *** *** Suppression dossiers dans "C:\Program Files" *** *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" *** *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" *** *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" *** *** Suppression dossiers dans "C:\Documents and Settings\HOHWALD'S\applic~1" *** *** Suppression dossiers dans "C:\DOCUME~1\FRANOI~1\applic~1" *** *** Suppression dossiers dans "C:\DOCUME~1\NOLLE~1\applic~1" *** *** Suppression dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" *** *** Suppression dossiers dans "C:\Documents and Settings\HOHWALD'S\locals~1\applic~1" *** *** Suppression dossiers dans "C:\DOCUME~1\FRANOI~1\locals~1\applic~1" *** *** Suppression dossiers dans "C:\DOCUME~1\NOLLE~1\locals~1\applic~1" *** *** Suppression dossiers dans "C:\Documents and Settings\HOHWALD'S\menudm~1\progra~1" *** *** Suppression dossiers dans "C:\DOCUME~1\FRANOI~1\menudm~1\progra~1" *** *** Suppression dossiers dans "C:\DOCUME~1\NOLLE~1\menudm~1\progra~1" *** *** Suppression fichiers *** *** Suppression fichiers temporaires *** Nettoyage contenu C:\WINDOWS\Temp effectué ! Nettoyage contenu C:\Documents and Settings\HOHWALD'S\locals~1\Temp effectué ! *** Traitement Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Suppression avec sauvegardes nouveaux fichiers Instant Access : 2)Recherche, création sauvegardes et suppression Heuristique : * Dans "C:\WINDOWS\system32" * * Dans "C:\Documents and Settings\HOHWALD'S\locals~1\applic~1" * * Dans "C:\DOCUME~1\FRANOI~1\locals~1\applic~1" * * Dans "C:\DOCUME~1\NOLLE~1\locals~1\applic~1" * *** Sauvegarde du Registre vers dossier Safebackup *** sauvegarde du Registre réalisée avec succès ! *** Nettoyage Registre *** Nettoyage Registre Ok *** Certificats *** Certificat Egroup supprimé ! Certificat Electronic-Group supprimé ! Certificat Montorgueil absent ! Certificat OOO-Favorit supprimé ! Certificat Sunny-Day-Design-Ltdt absent ! *** Nettoyage terminé le 2008-08-24 à 19:53:35.46 *** et le log Hijackthis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:04, on 2008-08-24 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\USB Storage RW\DskWatch.exe C:\WINDOWS\system32\carpserv.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HK\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [uSB Storage RW] C:\Program Files\USB Storage RW\DskWatch.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [meqoi] "c:\documents and settings\hohwald's\local settings\application data\meqoi.exe" meqoi O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.targa.co.uk O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1108507380937 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CA9FCA32-5396-4737-A69D-188CA85B3056}: NameServer = 86.64.145.143 84.103.237.143 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe -- End of file - 9121 bytes a +
  11. Voila le log navilog : Search Navipromo version 3.6.5 commencé le 2008-08-24 à 19:25:41.29 !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!! !!! Postez ce rapport sur le forum pour le faire analyser !!! !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!! Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "HOHWALD'S" Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 7.0.5730.11 Système de fichiers : NTFS Recherche executé en mode normal *** Recherche Programmes installés *** *** Recherche dossiers dans "C:\WINDOWS" *** *** Recherche dossiers dans "C:\Program Files" *** *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" *** *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" *** *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\HOHWALD'S\applic~1" *** *** Recherche dossiers dans "C:\DOCUME~1\FRANOI~1\applic~1" *** *** Recherche dossiers dans "C:\DOCUME~1\NOLLE~1\applic~1" *** *** Recherche dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\HOHWALD'S\locals~1\applic~1" *** *** Recherche dossiers dans "C:\DOCUME~1\FRANOI~1\locals~1\applic~1" *** *** Recherche dossiers dans "C:\DOCUME~1\NOLLE~1\locals~1\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\HOHWALD'S\menudm~1\progra~1" *** *** Recherche dossiers dans "C:\DOCUME~1\FRANOI~1\menudm~1\progra~1" *** *** Recherche dossiers dans "C:\DOCUME~1\NOLLE~1\menudm~1\progra~1" *** *** Recherche avec Catchme-rootkit/stealth malware detector par gmer *** pour + d'infos : http://www.gmer.net *** Recherche avec GenericNaviSearch *** !!! Tous ces résultats peuvent révéler des fichiers légitimes !!! !!! A vérifier impérativement avant toute suppression manuelle !!! * Recherche dans "C:\WINDOWS\system32" * * Recherche dans "C:\Documents and Settings\HOHWALD'S\locals~1\applic~1" * * Recherche dans "C:\DOCUME~1\FRANOI~1\locals~1\applic~1" * * Recherche dans "C:\DOCUME~1\NOLLE~1\locals~1\applic~1" * *** Recherche fichiers *** *** Recherche clés spécifiques dans le Registre *** *** Module de Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Recherche nouveaux fichiers Instant Access : 2)Recherche Heuristique : * Dans "C:\WINDOWS\system32" : * Dans "C:\Documents and Settings\HOHWALD'S\locals~1\applic~1" : * Dans "C:\DOCUME~1\FRANOI~1\locals~1\applic~1" : * Dans "C:\DOCUME~1\NOLLE~1\locals~1\applic~1" : 3)Recherche Certificats : Certificat Egroup trouvé ! Certificat Electronic-Group trouvé ! Certificat Montorgueil absent ! Certificat OOO-Favorit trouvé ! Certificat Sunny-Day-Design-Ltd absent ! 4)Recherche fichiers connus : *** Analyse terminée le 2008-08-24 à 19:36:04.20 *** A plus
  12. Pardon, j'ai oublié de préciser que oui, l'antivirus est activé avec protection residente. Apres reboot, voila le log Hijackthis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:14, on 2008-08-24 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\USB Storage RW\DskWatch.exe C:\WINDOWS\system32\carpserv.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\wuauclt.exe C:\HK\HiJackThis.exe C:\WINDOWS\system32\msiexec.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [uSB Storage RW] C:\Program Files\USB Storage RW\DskWatch.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [meqoi] "c:\documents and settings\hohwald's\local settings\application data\meqoi.exe" meqoi O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.targa.co.uk O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1108507380937 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CA9FCA32-5396-4737-A69D-188CA85B3056}: NameServer = 86.64.145.140 84.103.237.140 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe -- End of file - 9220 bytes Merci encore pour tout
  13. Le scan rapide a fonctionné, voila le log : Malwarebytes' Anti-Malware 1.25 Version de la base de données: 1081 Windows 5.1.2600 Service Pack 2 19:02:19 2008-08-24 mbam-log-08-24-2008 (19-02-19).txt Type de recherche: Examen rapide Eléments examinés: 69878 Temps écoulé: 20 minute(s), 48 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 5 Valeur(s) du Registre infectée(s): 1 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 2 Fichier(s) infecté(s): 5 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\Interface\{2b0eceac-f597-4858-a542-d966b49055b9} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{ddea2e1d-8555-45e5-af09-ec9aa4ea27ad} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{5b6689b5-c2d4-4dc7-bfd1-24ac17e5fcda} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e} (Adware.Hotbar) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\sau (Adware.180Solutions) -> Quarantined and deleted successfully. Valeur(s) du Registre infectée(s): HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootStera (Rogue.WinAntivirus) -> Quarantined and deleted successfully. Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Program Files\WinFixer 2005 (Rogue.WinFixer) -> Quarantined and deleted successfully. Fichier(s) infecté(s): C:\Documents and Settings\HOHWALD'S\Local Settings\Application Data\meqoi_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\HOHWALD'S\Local Settings\Application Data\meqoi_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\HOHWALD'S\Local Settings\Application Data\meqoi.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\HOHWALD'S\Local Settings\Application Data\meqoi.exe (Adware.Navipromo.H) -> Delete on reboot. Je dois rebooter, je refais un hijackthis apres
  14. Voila, j'ai fait ce que tu m'avais dit. Je te poste le rapport de SDfix : SDFix: Version 1.219 Run by HOHWALD'S on 2008-08-24 at 17:46 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Checking Services : Name : Windows Log Path : C:\WINDOWS\system32\nvsvcd.exe Windows Log - Deleted Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Et le nouveau log de hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:12, on 2008-08-24 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\CA\eTrust Antivirus\InoRpc.exe C:\Program Files\CA\eTrust Antivirus\InoRT.exe C:\Program Files\CA\eTrust Antivirus\InoTask.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\USB Storage RW\DskWatch.exe C:\WINDOWS\system32\carpserv.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\HK\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [uSB Storage RW] C:\Program Files\USB Storage RW\DskWatch.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.targa.co.uk O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1108507380937 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CA9FCA32-5396-4737-A69D-188CA85B3056}: NameServer = 86.64.145.142 84.103.237.142 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe -- End of file - 9126 bytes Il a quoi le PC en fait? beaucoup d'infections? Pas beaucoup? Encore merci pour la disponibilité
  15. Re La fenetre Malewarebytes s'est fermée pendant l'analyse? Normal? Il me dit qu'il est pourtant en cours d'execution...
×
×
  • Créer...