Rundll erreur entrée manquante [resolu]

Discussions gérénales sur Microsoft Windows Vista, des différentes versions.
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Rundll erreur entrée manquante [resolu]

Message par da-flute »

Bonjour,
quand je suis sous windows vista, quand j'allume mon ordi, j'ai plein de fenêtres qui se mettent, voilà ce qui est écrit dessus: Rundll Erreur dans C:\user\daflute\AppData\Roaming\c00b1EC8.mat entrée manquante: B.
Je ne sais pas du tout ce que c'est, j'ai fait un hitjacksthis, voilà le rapport :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:06:09, on 19/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\da flute\AppData\Roaming\Microsoft\Windows\lsass.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\da flute\Desktop\test.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
O4 - HKLM\..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [igcqc] "c:\users\da flute\appdata\local\igcqc.exe" igcqc
O4 - HKCU\..\Run: [Lsass Service] C:\Users\da flute\AppData\Roaming\Microsoft\Windows\lsass.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\DAFLUT~1\AppData\Local\Temp\fccbYrOi.dll,c
O4 - HKCU\..\Run: [c00DCE03] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00DCE03.mat", sh
O4 - HKCU\..\Run: [c0089564] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0089564.mat", sh
O4 - HKCU\..\Run: [c0046745] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0046745.mat", sh
O4 - HKCU\..\Run: [c00BDB3A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00BDB3A.mat", sh
O4 - HKCU\..\Run: [c00A7982] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00A7982.mat", sh
O4 - HKCU\..\Run: [c001FEA7] rundll32.exe "C:\Users\da flute\AppData\Roaming\c001FEA7.mat", sh
O4 - HKCU\..\Run: [c008C347] rundll32.exe "C:\Users\da flute\AppData\Roaming\c008C347.mat", sh
O4 - HKCU\..\Run: [c00BDC7C] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00BDC7C.mat", sh
O4 - HKCU\..\Run: [c0049789] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0049789.mat", sh
O4 - HKCU\..\Run: [c00C0090] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C0090.mat", sh
O4 - HKCU\..\Run: [c0021100] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0021100.mat", sh
O4 - HKCU\..\Run: [c003A91E] rundll32.exe "C:\Users\da flute\AppData\Roaming\c003A91E.mat", sh
O4 - HKCU\..\Run: [c00A3B32] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00A3B32.mat", sh
O4 - HKCU\..\Run: [c0090691] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0090691.mat", sh
O4 - HKCU\..\Run: [c0095EE4] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0095EE4.mat", sh
O4 - HKCU\..\Run: [c004B1D1] rundll32.exe "C:\Users\da flute\AppData\Roaming\c004B1D1.mat", sh
O4 - HKCU\..\Run: [c004A821] rundll32.exe "C:\Users\da flute\AppData\Roaming\c004A821.mat", sh
O4 - HKCU\..\Run: [c0051284] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0051284.mat", sh
O4 - HKCU\..\Run: [c00F846] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F846.mat", sh
O4 - HKCU\..\Run: [c00AFC72] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00AFC72.mat", sh
O4 - HKCU\..\Run: [c00817D8] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00817D8.mat", sh
O4 - HKCU\..\Run: [c0087A24] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0087A24.mat", sh
O4 - HKCU\..\Run: [c0064A9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0064A9.mat", sh
O4 - HKCU\..\Run: [c00F2AAF] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F2AAF.mat", sh
O4 - HKCU\..\Run: [c0049F3F] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0049F3F.mat", sh
O4 - HKCU\..\Run: [c00C2652] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C2652.mat", sh
O4 - HKCU\..\Run: [c0082E96] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0082E96.mat", sh
O4 - HKCU\..\Run: [c00DBA84] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00DBA84.mat", sh
O4 - HKCU\..\Run: [c008441D] rundll32.exe "C:\Users\da flute\AppData\Roaming\c008441D.mat", sh
O4 - HKCU\..\Run: [c00C2D10] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C2D10.mat", sh
O4 - HKCU\..\Run: [c00F29D2] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F29D2.mat", sh
O4 - HKCU\..\Run: [c00BEE09] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00BEE09.mat", sh
O4 - HKCU\..\Run: [c004B80C] rundll32.exe "C:\Users\da flute\AppData\Roaming\c004B80C.mat", sh
O4 - HKCU\..\Run: [c0098C20] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0098C20.mat", sh
O4 - HKCU\..\Run: [c00E66A0] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00E66A0.mat", sh
O4 - HKCU\..\Run: [c00B97AD] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00B97AD.mat", sh
O4 - HKCU\..\Run: [c00BB63A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00BB63A.mat", sh
O4 - HKCU\..\Run: [c00A7BE0] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00A7BE0.mat", sh
O4 - HKCU\..\Run: [c00F6464] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F6464.mat", sh
O4 - HKCU\..\Run: [c00EBBE3] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00EBBE3.mat", sh
O4 - HKCU\..\Run: [c00C67A1] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C67A1.mat", sh
O4 - HKCU\..\Run: [c007F28E] rundll32.exe "C:\Users\da flute\AppData\Roaming\c007F28E.mat", sh
O4 - HKCU\..\Run: [c00F7FF3] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F7FF3.mat", sh
O4 - HKCU\..\Run: [c00614E4] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00614E4.mat", sh
O4 - HKCU\..\Run: [c0032D1A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0032D1A.mat", sh
O4 - HKCU\..\Run: [c0049628] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0049628.mat", sh
O4 - HKCU\..\Run: [c002A068] rundll32.exe "C:\Users\da flute\AppData\Roaming\c002A068.mat", sh
O4 - HKCU\..\Run: [c00234A6] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00234A6.mat", sh
O4 - HKCU\..\Run: [c0017D86] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0017D86.mat", sh
O4 - HKCU\..\Run: [c00C7B88] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C7B88.mat", sh
O4 - HKCU\..\Run: [c0045122] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0045122.mat", sh
O4 - HKCU\..\Run: [c00A4986] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00A4986.mat", sh
O4 - HKCU\..\Run: [c00991D4] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00991D4.mat", sh
O4 - HKCU\..\Run: [c00F4126] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F4126.mat", sh
O4 - HKCU\..\Run: [c006C032] rundll32.exe "C:\Users\da flute\AppData\Roaming\c006C032.mat", sh
O4 - HKCU\..\Run: [c00B5024] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00B5024.mat", sh
O4 - HKCU\..\Run: [c00D0876] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00D0876.mat", sh
O4 - HKCU\..\Run: [c00FDD6C] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00FDD6C.mat", sh
O4 - HKCU\..\Run: [c003A264] rundll32.exe "C:\Users\da flute\AppData\Roaming\c003A264.mat", sh
O4 - HKCU\..\Run: [c0051BE7] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0051BE7.mat", sh
O4 - HKCU\..\Run: [c006A704] rundll32.exe "C:\Users\da flute\AppData\Roaming\c006A704.mat", sh
O4 - HKCU\..\Run: [c001B840] rundll32.exe "C:\Users\da flute\AppData\Roaming\c001B840.mat", sh
O4 - HKCU\..\Run: [c00D766B] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00D766B.mat", sh
O4 - HKCU\..\Run: [c00CA532] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00CA532.mat", sh
O4 - HKCU\..\Run: [c001EB90] rundll32.exe "C:\Users\da flute\AppData\Roaming\c001EB90.mat", sh
O4 - HKCU\..\Run: [c009D1DC] rundll32.exe "C:\Users\da flute\AppData\Roaming\c009D1DC.mat", sh
O4 - HKCU\..\Run: [c004C024] rundll32.exe "C:\Users\da flute\AppData\Roaming\c004C024.mat", sh
O4 - HKCU\..\Run: [c004C09] rundll32.exe "C:\Users\da flute\AppData\Roaming\c004C09.mat", sh
O4 - HKCU\..\Run: [c00D4F96] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00D4F96.mat", sh
O4 - HKCU\..\Run: [c00A646F] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00A646F.mat", sh
O4 - HKCU\..\Run: [c00EE456] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00EE456.mat", sh
O4 - HKCU\..\Run: [c00BCC22] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00BCC22.mat", sh
O4 - HKCU\..\Run: [c0027E24] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0027E24.mat", sh
O4 - HKCU\..\Run: [c007FBCD] rundll32.exe "C:\Users\da flute\AppData\Roaming\c007FBCD.mat", sh
O4 - HKCU\..\Run: [c00A108B] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00A108B.mat", sh
O4 - HKCU\..\Run: [c005ACF8] rundll32.exe "C:\Users\da flute\AppData\Roaming\c005ACF8.mat", sh
O4 - HKCU\..\Run: [c00CCD31] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00CCD31.mat", sh
O4 - HKCU\..\Run: [c008B69D] rundll32.exe "C:\Users\da flute\AppData\Roaming\c008B69D.mat", sh
O4 - HKCU\..\Run: [c00CB9CD] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00CB9CD.mat", sh
O4 - HKCU\..\Run: [c00CDE41] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00CDE41.mat", sh
O4 - HKCU\..\Run: [c0026D40] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0026D40.mat", sh
O4 - HKCU\..\Run: [c00CF735] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00CF735.mat", sh
O4 - HKCU\..\Run: [c00E7A78] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00E7A78.mat", sh
O4 - HKCU\..\Run: [c00EF46A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00EF46A.mat", sh
O4 - HKCU\..\Run: [c0067853] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0067853.mat", sh
O4 - HKCU\..\Run: [c0026F08] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0026F08.mat", sh
O4 - HKCU\..\Run: [c00B236] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00B236.mat", sh
O4 - HKCU\..\Run: [c00DDC81] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00DDC81.mat", sh
O4 - HKCU\..\Run: [c00AA5AE] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00AA5AE.mat", sh
O4 - HKCU\..\Run: [c0089246] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0089246.mat", sh
O4 - HKCU\..\Run: [c00C4DA9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C4DA9.mat", sh
O4 - HKCU\..\Run: [c00E7136] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00E7136.mat", sh
O4 - HKCU\..\Run: [c0096F5A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0096F5A.mat", sh
O4 - HKCU\..\Run: [c00C9A91] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C9A91.mat", sh
O4 - HKCU\..\Run: [c009A4DA] rundll32.exe "C:\Users\da flute\AppData\Roaming\c009A4DA.mat", sh
O4 - HKCU\..\Run: [c0016973] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0016973.mat", sh
O4 - HKCU\..\Run: [c005C0CC] rundll32.exe "C:\Users\da flute\AppData\Roaming\c005C0CC.mat", sh
O4 - HKCU\..\Run: [c00458C9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00458C9.mat", sh
O4 - HKCU\..\Run: [c00AC40] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00AC40.mat", sh
O4 - HKCU\..\Run: [c002FA5E] rundll32.exe "C:\Users\da flute\AppData\Roaming\c002FA5E.mat", sh
O4 - HKCU\..\Run: [c00DD308] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00DD308.mat", sh
O4 - HKCU\..\Run: [c005E518] rundll32.exe "C:\Users\da flute\AppData\Roaming\c005E518.mat", sh
O4 - HKCU\..\Run: [c00A6900] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00A6900.mat", sh
O4 - HKCU\..\Run: [c0054874] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0054874.mat", sh
O4 - HKCU\..\Run: [c0029614] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0029614.mat", sh
O4 - HKCU\..\Run: [c00F6C3A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F6C3A.mat", sh
O4 - HKCU\..\Run: [c003C6F4] rundll32.exe "C:\Users\da flute\AppData\Roaming\c003C6F4.mat", sh
O4 - HKCU\..\Run: [c00C3DC9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C3DC9.mat", sh
O4 - HKCU\..\Run: [c0076600] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0076600.mat", sh
O4 - HKCU\..\Run: [c009EC32] rundll32.exe "C:\Users\da flute\AppData\Roaming\c009EC32.mat", sh
O4 - HKCU\..\Run: [c0075413] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0075413.mat", sh
O4 - HKCU\..\Run: [c009EDC4] rundll32.exe "C:\Users\da flute\AppData\Roaming\c009EDC4.mat", sh
O4 - HKCU\..\Run: [c0013E64] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0013E64.mat", sh
O4 - HKCU\..\Run: [c00FCFDC] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00FCFDC.mat", sh
O4 - HKCU\..\Run: [c002EF10] rundll32.exe "C:\Users\da flute\AppData\Roaming\c002EF10.mat", sh
O4 - HKCU\..\Run: [c003A7A9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c003A7A9.mat", sh
O4 - HKCU\..\Run: [c002D5B9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c002D5B9.mat", sh
O4 - HKCU\..\Run: [c00D8B63] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00D8B63.mat", sh
O4 - HKCU\..\Run: [c0020A78] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0020A78.mat", sh
O4 - HKCU\..\Run: [c00BF021] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00BF021.mat", sh
O4 - HKCU\..\Run: [c00D9108] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00D9108.mat", sh
O4 - HKCU\..\Run: [c0025244] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0025244.mat", sh
O4 - HKCU\..\Run: [c00924B6] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00924B6.mat", sh
O4 - HKCU\..\Run: [c007A30A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c007A30A.mat", sh
O4 - HKCU\..\Run: [c001EF0A] rundll32.exe "C:\Users\da flute\AppData\Roaming\c001EF0A.mat", sh
O4 - HKCU\..\Run: [c003F686] rundll32.exe "C:\Users\da flute\AppData\Roaming\c003F686.mat", sh
O4 - HKCU\..\Run: [c003F622] rundll32.exe "C:\Users\da flute\AppData\Roaming\c003F622.mat", sh
O4 - HKCU\..\Run: [c005D10B] rundll32.exe "C:\Users\da flute\AppData\Roaming\c005D10B.mat", sh
O4 - HKCU\..\Run: [c00CACA9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00CACA9.mat", sh
O4 - HKCU\..\Run: [c00541F8] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00541F8.mat", sh
O4 - HKCU\..\Run: [c005AEE4] rundll32.exe "C:\Users\da flute\AppData\Roaming\c005AEE4.mat", sh
O4 - HKCU\..\Run: [c0038867] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0038867.mat", sh
O4 - HKCU\..\Run: [c0048661] rundll32.exe "C:\Users\da flute\AppData\Roaming\c0048661.mat", sh
O4 - HKCU\..\Run: [c002C6D3] rundll32.exe "C:\Users\da flute\AppData\Roaming\c002C6D3.mat", sh
O4 - HKCU\..\Run: [c00FA3E4] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00FA3E4.mat", sh
O4 - HKCU\..\Run: [c009948D] rundll32.exe "C:\Users\da flute\AppData\Roaming\c009948D.mat", sh
O4 - HKCU\..\Run: [c003D4F1] rundll32.exe "C:\Users\da flute\AppData\Roaming\c003D4F1.mat", sh
O4 - HKCU\..\Run: [c00F10B9] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00F10B9.mat", sh
O4 - HKCU\..\Run: [c00BEC31] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00BEC31.mat", sh
O4 - HKCU\..\Run: [c006C225] rundll32.exe "C:\Users\da flute\AppData\Roaming\c006C225.mat", sh
O4 - HKCU\..\Run: [c00C66F6] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C66F6.mat", sh
O4 - HKCU\..\Run: [c00C9788] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00C9788.mat", sh
O4 - HKCU\..\Run: [c005692] rundll32.exe "C:\Users\da flute\AppData\Roaming\c005692.mat", sh
O4 - HKCU\..\Run: [c004EC38] rundll32.exe "C:\Users\da flute\AppData\Roaming\c004EC38.mat", sh
O4 - HKCU\..\Run: [c005CCE0] rundll32.exe "C:\Users\da flute\AppData\Roaming\c005CCE0.mat", sh
O4 - HKCU\..\Run: [c00499FE] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00499FE.mat", sh
O4 - HKCU\..\Run: [c00EA89E] rundll32.exe "C:\Users\da flute\AppData\Roaming\c00EA89E.mat", sh
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/709-44555-9400-3/4 (file missing)
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.fr/exec/obidos/redire ... &site=home (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resourc ... dfr-fr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F87F05D-C810-4664-A5DD-D04689177032}: NameServer = 89.2.0.1,89.2.0.2
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 24069 bytes


Pourriez vous m'aider svp? Merci !!
Avatar du membre
bernard53
Support
Support
Messages : 3516
Enregistré le : 25 avr. 2008, 22:05
Configuration matérielle : Processeur intel 2 duo CPU E6750 2.66GHz
3GO mémoire vive

disque dur samsung 160Go

Re: Rundll erreur entrée manquante

Message par bernard53 »

Bonsoir

Je regarde cela de suite et te mets la suite.
:coucou:
Bonne visite sur: http://tuto-b.comli.com/
Avatar du membre
nardino
Modérateurs
Modérateurs
Messages : 11993
Enregistré le : 05 févr. 2007, 17:38
Localisation : Reims
Contact :

Re: Rundll erreur entrée manquante

Message par nardino »

Salut.

Au minimum un Navipromo et un Vundo et peut-être un Mydoom ou un Purity ce que je ne souhaite pas.
bernard va s'occuper de ton cas.
@+

EDIT.
Avec son accord je vais prendre en charge cette désinfection.

La première opération à effectuer est celle-ci :

1°- Télécharge Navilog1 depuis-ce lien : http://pagesperso-orange.fr/il.mafioso/ ... vilog1.exe
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.

2°- Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):
  • Vas dans "Démarrer" puis "Panneau de configuration".
    Double Clique sur l'icône "Comptes d'utilisateurs" et sur "Activer ou désactiver le contrôle des comptes d'utilisateurs".
    Clique sur "Continuer".
    Décoche la case "Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur".
    Valide par "OK" et redémarre.
3°- Une fois redémarré, double clique sur "navilog1.exe" pour lancer l'installation.
L'installation terminée, fais un clic-droit sur le raccourci "Navilog1" présent sur ton bureau et choisis :
"Exécuter en tant qu'administrateur". C'est impératif.
  • Au menu principal, Fais le choix "1"
    Laisse toi guider et patiente.
    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche le blocnote va s'ouvrir.
    Copie-colle l'intégralité du rapport dans ta réponse.
    Referme le blocnote.
Il y aura une suite.
@+
Image
Clic sur l'image pour ouvrir le site.
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

Merci de vous occuper de moi si rapidement c'est trés gentil !
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

Voilà j'ai suivi tous tes conseils voilà le rapport de navilog 1


Search Navipromo version 3.6.9 commencé le 19/11/2008 à 22:48:30,25

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "da flute"

Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

Microsoft Windows Vista 6.0.6001
Internet Explorer : 7.0.6001.18000
Système de fichiers : NTFS

Recherche executé en mode normal

*** Recherche Programmes installés ***


*** Recherche dossiers dans "C:\Windows" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***


*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***


*** Recherche dossiers dans "C:\ProgramData" ***


*** Recherche dossiers dans "c:\users\daflut~1\appdata\roaming\micros~1\windows\startm~1\programs" ***


*** Recherche dossiers dans "C:\Users\da flute\AppData\Local\virtualstore\Program Files" ***

...\InternetGameBox trouvé !

*** Recherche dossiers dans "C:\Users\da flute\AppData\Roaming" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\Windows\system32" *

* Recherche dans "C:\Users\da flute\AppData\Local\Microsoft" *

* Recherche dans "C:\Users\da flute\AppData\Local\virtualstore\windows\system32" *

* Recherche dans "C:\Users\da flute\AppData\Local" *



*** Recherche fichiers ***


C:\Windows\system32\nvs2.inf trouvé !

*** Recherche clés spécifiques dans le Registre ***

HKEY_CURRENT_USER\Software\Lanconfig trouvé !

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\Windows\system32" :


* Dans "C:\Users\da flute\AppData\Local\Microsoft" :


* Dans "C:\Users\da flute\AppData\Local\virtualstore\windows\system32" :


* Dans "C:\Users\da flute\AppData\Local" :

igcqc.exe trouvé !
igcqc.dat trouvé !
igcqc_nav.dat trouvé !
igcqc_navps.dat trouvé !

3)Recherche Certificats :

Certificat Egroup trouvé !
Certificat Electronic-Group trouvé !
Certificat Montorgueil absent !
Certificat OOO-Favorit trouvé !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche fichiers connus :



*** Analyse terminée le 19/11/2008 à 23:16:13,89 ***
Avatar du membre
nardino
Modérateurs
Modérateurs
Messages : 11993
Enregistré le : 05 févr. 2007, 17:38
Localisation : Reims
Contact :

Re: Rundll erreur entrée manquante

Message par nardino »

Bonsoir.

Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts.
Veille à ce que le le contrôle des comptes utilisateurs (UAC) soit toujours désactivé.
Fais un Clic-droit sur le raccourci "Navilog1" présent sur ton bureau et choisis "Exécuter en tant qu'administrateur". Impératif.

Au menu principal, Fais le choix "2"
Laisse toi guider et patiente.
Le fix va t'informer qu'il va alors redémarrer ton PC
Appuie sur une touche comme demandé, si ton Pc ne redémarre pas automatiquement, fais le toi même.
Au redémarrage de ton PC, choisis ta session habituelle, celle qui est infectée.
Patiente jusqu'au message :
*** Nettoyage Termine le ..... ***
Le blocnote va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver et à le poster dans ta réponse.
Referme le blocnote. Ton bureau va réapparaitre
Réactive le contrôle des comptes utilisateurs (UAC)

PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Cela fera réapparaitre ton bureau.


Télécharge et installe Malwarebyte's Anti-Malware de RubbeR DuckY
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
  • A la fin de l'installation, veille à ce que l'option Mettre à jour Malwarebytes' Anti-Malware soit cochée. Clique sur "Terminer"
    Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur le bureau.
    Au premier lancement, une fenêtre t'annonce que la version est Free, clique sur OK.
    Laisse les Mises à jour se télécharger et referme le programme.
Redémarre en "Mode sans échec"
  • Lance Malwarebyte's Anti-Malware par clic droit sur l'icône du bureau et "Exécuter en tant qu'administrateur"
    Onglet "Recherche", coche Exécuter un examen complet et Rechercher
    Sélectionne ton disque dur et clique sur Lancer l'examen
A la fin du scan, sélectionne tout et clique sur Supprimer la sélection
Redémarre en mode normal et poste le rapport avec un nouveau Hijackthis.
Il se trouve dans l'onglet Rapports/Logs avec la date et l'heure d'exécution
Un tutoriel pour ce programme
http://forum.pcastuces.com/malwarebytes ... -f31s3.htm

@+
Image
Clic sur l'image pour ouvrir le site.
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

OK, l'analyse de malwarebytes' anti-malware est en cours là, elle a déja trouvé 21 éléments infectés. Je poste le rapport dés que c'est finit!
Encore une fois merci de prendre ma désinfection en charge.
da-flute
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

il y avait 21 fichiers infectés, dont vundo comme tu le pensais. J'ai fait tout supprimer et l'opération s'est bien dérouleé. Mon ordinateur est réparée maintenant?

voilà le rapport:

Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1412
Windows 6.0.6001 Service Pack 1

20/11/2008 07:56:51
mbam-log-2008-11-20 (07-56-45).txt

Type de recherche: Examen complet (C:\|E:\|)
Eléments examinés: 200675
Temps écoulé: 1 hour(s), 41 minute(s), 14 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 34
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 3
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1133

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
C:\Users\da flute\AppData\Local\Temp\fccbYrOi.dll (Trojan.Vundo.H) -> No action taken.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4bb0b49c-ed1e-4e3e-9a3f-17dbe8fc74b5} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4bb0b49c-ed1e-4e3e-9a3f-17dbe8fc74b5} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\dc_ads.ads (Adware.Fotomoto) -> No action taken.
HKEY_CLASSES_ROOT\dc_ads.ads.1 (Adware.Fotomoto) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c001b6e6 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c0021100 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c0026753 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c002b02e (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c003b69 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00593d2 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c005e1ac (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00629cb (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c006a10 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c006a900 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c008400 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c0086286 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c0098e40 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c009edb0 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00a7982 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00b38aa (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00b5024 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00bdc7c (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00c78e9 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00d88fe (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00dcbc3 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00f228f (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00f7fb4 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00fa7a1 (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00fb85a (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\c00fda2c (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmds (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lsass service (Trojan.Agent) -> No action taken.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\users\daflut~1\appdata\local\temp\fccbyroi -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: c:\windows\system32\c00dcbc3.mat -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Agent) -> Data: system32\c00dcbc3.mat -> No action taken.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Users\da flute\AppData\Local\Temp\fccbYrOi.dll (Trojan.Vundo.H) -> No action taken.
C:\Users\da flute\AppData\Local\Temp\iOrYbccf.ini (Trojan.Vundo.H) -> No action taken.
C:\Users\da flute\AppData\Local\Temp\iOrYbccf.ini2 (Trojan.Vundo.H) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\363P1GFA\awgqdrropy[1].htm (Trojan.TinyDownloader705) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\363P1GFA\djgqnnokhr[1].htm (Trojan.TinyDownloader705) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\363P1GFA\tzvjt[1].htm (Trojan.Clicker) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\924THW85\upd[1] (Trojan.Vundo) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X31QRMZL\ioyiffggd[1].htm (Trojan.TinyDownloader705) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X31QRMZL\kakzjg[1].htm (Trojan.TinyDownloader705) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X31QRMZL\tzwtg[1].htm (Trojan.TinyDownloader705) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y521JU6L\index[1] (Trojan.Vundo) -> No action taken.
C:\Users\da flute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y521JU6L\tzvjt[1].htm (Trojan.Clicker) -> No action taken.
C:\Windows\System32\WhoisCL.exe (Adware.BHO) -> No action taken.
C:\Users\da flute\AppData\Roaming\Microsoft\Windows\lsass.exe (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0010570.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0010B01.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0010D09.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0010E50.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0010F34.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0010FBC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00110F7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0011211.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0011944.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0011CC9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00125C9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0012790.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0012934.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0012BCE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0012D41.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0012DBA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0012E74.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001339.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00135D6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0013A4A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0013AB2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0013BA4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0013DF1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0014739.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0014ADC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0014B8E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0014D4C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0016024.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001612C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0016368.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00163BA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0016843.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00169E6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0016D65.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00174A2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00174B8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00175EC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0017748.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0017B56.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0017B7C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0017BB4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0017BC6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0017FD1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0018286.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00189BC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00193C6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001A9A9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001AC19.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001B464.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001B64.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001B685.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001B6E6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001BA4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001C241.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001C258.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001C2C7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001C71C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001C844.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001CA78.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001CB1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001CD21.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001D3C3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001D415.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001D641.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001D6BA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001D810.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001EAFC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001F1E2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001F884.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001F982.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001FA40.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c001FC01.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0020070.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00202A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00208F9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0020962.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0020FDA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00210F2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0021100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00213B8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0021A0C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0022001.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00225B8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0022FA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00236DE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0024025.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0024813.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0024A52.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0024C71.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0024EF1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002509B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002533.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0025382.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0025440.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0025641.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0025906.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0025A11.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0025ED1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0025FFD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0026591.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0026753.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0026ABF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0026D27.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0026D4B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0026FC7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002707C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0027188.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00274BE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00276CB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0027B64.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0027DC9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002850E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00286E9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00289E9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0028E22.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002958.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0029623.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002A009.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002A144.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002AC3F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002AC4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002ACB9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002B02E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002B08C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002B2F9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002B3F6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002B6C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002B6DE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002BBA4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002C4E1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002C639.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002C648.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002C6C3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002C9EC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002CD9E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002CE0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002D540.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002D710.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002D806.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002DAAD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002DD23.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002E0B6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002E0FD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002E261.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002E470.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002E786.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002F13A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002F7E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002FB9E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c002FEE8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00300B1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00301D6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0030310.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0030553.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00306AC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0031325.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0031585.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0031611.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0031692.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0031944.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00320C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0032631.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0032804.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0032A68.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0032C91.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0033A2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0033E40.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0034364.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0034900.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0034D28.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003590.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003664.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003731E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00374E8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00376F9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003786.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0037CE6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00381FD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00384C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0038AE3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0038C02.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00392BD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00394B3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00397B2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003990.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0039E2C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0039F26.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003AB06.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003AE30.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003B34E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003B4C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003B50C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003B69.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003BC2C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003BD3A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003C019.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003C099.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003C1A0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003C861.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003CDCA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003D07E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003D1A1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003D20E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003D5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003D723.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003E1C8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003E821.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003E988.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003EC97.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003EE17.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003F3C6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003F9A0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003FA9D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c003FD4E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00407BE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0040AEA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0040DBE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0040DF9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0040FB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00410E5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004140D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0041464.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004162E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00419F8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0041AE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0041B89.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004230A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0042836.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00429BB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0042BD2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0042DD8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0043021.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0043B51.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0043B9A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0044781.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0044B49.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00450C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0045280.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004541.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0045B13.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0045EA1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00460D4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0046109.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0046298.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00463D6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0046545.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0046984.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0046C9B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0046FEA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00470DC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0047749.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004778.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00479C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004871C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0048A1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0048E0E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0048F19.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00490D0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00492E1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0049464.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0049A72.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0049C3B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0049F59.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004A6A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004ABD4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004ADC2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004B0BC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004B0C1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004B34.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004B889.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004B969.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004B979.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004BAC4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004BBF9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004C642.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004C68E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004CBCF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004D0B2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004D0C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004D2A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004D37.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004D4F6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004D734.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004DDE9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004DFE8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004E0C6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004E100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004EA5C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004EF7E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004F8F0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004FDAC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004FE0A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c004FF10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0050378.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005046F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0050644.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005085F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005088.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0050AB7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0050ECE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00512C9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00515B9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0051890.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00518C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0051961.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0052532.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00527B0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0052B80.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0052EAB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00531AF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00536F9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0053910.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0053DD2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0054347.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0054A71.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0054B5B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0054BBC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0054F52.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055064.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055648.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055716.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055924.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055A26.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055AC3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055C5E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055CCD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0055FA5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0056058.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00560B6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00563DA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0056E01.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0057079.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0057290.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005747C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00575A1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0057D3A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0057F09.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00584.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00588E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0058BC4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0058DA6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0058FC4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005905.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0059100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00593D2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005988E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00598C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005A08F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005A68E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005A7F8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005AAD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005AF60.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B02B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B136.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B490.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B513.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B679.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B686.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005B7FC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005BE05.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005BF60.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005C100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005C1FD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005CD34.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005D044.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005D590.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005D7CE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005D80C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005E1AC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005E225.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005E4DA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005EA7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005F39C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005F69C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005F823.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005FA10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c005FA40.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0060069.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0060240.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0060619.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00607A6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0060989.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00609E1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0061554.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006191A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0062325.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006299C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00629CB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0062C1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0062F32.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00636EB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0063FB4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0064090.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0064547.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00645AD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0064640.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0064CBC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0064D84.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0064DFB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00650.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0065558.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006560C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0065816.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0065C3B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0065EC5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0065F06.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0066220.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0066690.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0066A49.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0066C71.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00673C0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0067590.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0067DC4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00682E9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00682F1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0068440.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006873A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00697D8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0069920.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006A10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006A2A6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006A479.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006A900.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006B2E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006BC4C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006C34D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006CA38.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006CC49.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006CD38.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006D269.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006D6C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006D86E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006DC5B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006DFBC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E0A2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E0B4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E1EA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E2D6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E3C1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E6EC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E835.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006E9D9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006ED37.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006F075.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006F4FF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006FD50.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c006FF9E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00702B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00703A1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00704C9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00704DA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070642.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070689.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00708C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070A16.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070A35.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070A7A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070BF8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070C08.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070D64.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0070E0A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0071000.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007167F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0071744.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007186E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0071BAB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0071CCD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0072168.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00727FB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007310.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0073490.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00738BE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0073F14.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00745FF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00747CA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0074C99.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0075929.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0075DA4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007613E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0076240.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0076378.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00766C9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00767A2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0076C44.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0076D4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0076DA1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0076F9E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0077838.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0077A4A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0077F07.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00781F1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00783E2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0078BE4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0078D94.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0079157.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007A4CC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007AFAE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007B061.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007B3C6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007B400.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007B41.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007B629.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007B817.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007B823.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007BCFE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007C10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007C25A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007C3AC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007C64.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007C723.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007CED4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007CF00.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007D169.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007D293.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007D34D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007D39D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007D515.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007DC21.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007E00E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007E0A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007E104.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007E533.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007E73C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007E9EB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c007EC2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00809DA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0080F10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008135E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00813A9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008158E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0081E98.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0082522.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00825C2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008283E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00829A9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0082CCA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0082DAF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0082E6D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0082FE1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0082FFA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00834D0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00837AC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008393.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0083D10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0083D9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008400.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0084149.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00848ED.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0084EB2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0085010.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008506C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008519C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008536F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00854FF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008558C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0085869.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0085CC6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0086286.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0086678.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0086845.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0086854.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0086910.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008691E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0086BA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0086CB6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008720F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00876FA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0087849.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0087D50.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0087DD2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0087FD1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00881CE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008850C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00891D9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00898E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0089944.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0089D71.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008A040.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008A400.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008B770.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008B840.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008BE64.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008BE9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008C0F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008C6F6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008C790.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008CC68.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008D07E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008D0DE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008D213.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008D6D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008DA6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008ED5C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008F088.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008F138.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008F764.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008F9A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008FC7C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c008FE61.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009057F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00909E0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0091324.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0091A35.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0091C81.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0091E98.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0092842.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0092A1C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0092FE4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0093329.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009399B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0093D54.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0093E0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0094234.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009450.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0094B34.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0094CD8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0094E2A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0094E3C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0095244.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0095F05.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00969B1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0096C78.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0096DFA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00979C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00979D6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0097E20.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0098478.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00987EB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0098802.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0098B90.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0098E40.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00990C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0099209.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0099361.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00993C1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00996C1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00998C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0099A91.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c0099B51.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009A079.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009A0F6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009A100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009AC39.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009ACD8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009AED2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009B018.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009B3FB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009B529.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009B5C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009B7FA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009C286.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009C640.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009CE16.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009D065.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009D21B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009D331.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009D51E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009D571.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009DBF9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009DCB3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009E24E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009EDB0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009F411.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009F5B9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009F6EA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009FD83.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009FE6C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c009FFA5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A0391.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A0559.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A0590.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A0681.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A07E9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A089E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A0B28.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A0FAF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A1100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A118D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A11B1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A1457.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A1A40.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A1F56.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A1F80.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A1FE4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A2262.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A285D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A2AE8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A2B80.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A2C72.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A3070.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A334E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A3AD9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A47A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A49A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A4FC2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A5264.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A5DFF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A61C8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A64A9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A65C2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A6691.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A6FC1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A7199.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A7982.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A7C7E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A7F6E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A82E2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A84DA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A8DEE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A94B8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A9574.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A96CB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A9799.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A9898.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A9997.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A9A42.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00A9C8D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AA27C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AA2CA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AA530.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AAA10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AAB04.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AAB09.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AB040.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AB50C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ABB1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ABBE1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ABC05.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ABCA5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AC424.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AC426.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AC8E6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ACE04.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AD104.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE282.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE431.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE450.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE569.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE828.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE86E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE904.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AE956.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AEA49.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AEB48.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AF47E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AF61.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AFB95.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00AFBC6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B00ED.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B0E62.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B0E6B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B120D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B166.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B17E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B1A70.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B1AD1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B1D19.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B1DA2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B2CD7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B38AA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B38FC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B3916.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B3E20.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B3E40.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B40F8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B451.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B46D9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B4910.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B49BB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B4A16.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B5024.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B50A1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B5169.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B53CA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B5411.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B577D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B5A42.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B5BF1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B66F6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B6E5F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B7644.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B7A66.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B7E95.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B80F8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B816E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B86A6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B86E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B895C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B8F87.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B9604.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00B9D49.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BA368.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BAF24.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BBA60.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BBC18.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BBD1D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BBE08.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BBFC1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BC039.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BC8A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BCC00.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BCC41.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BCD27.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BCF27.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BD076.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BD334.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BD942.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BD99B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BDC7C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BE4AA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BE828.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00BF2D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C00AE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C02E2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C08C2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C08F9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C0C39.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C0FA4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C1000.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C11DE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C194C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C1978.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C1C0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C1C0E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C1F10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C1F59.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C2336.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C2530.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C2824.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C28BE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C2C69.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C32BF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C333E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C33FE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C3435.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C348D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C3719.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C3FF1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C3FF5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C42C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C4691.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C46ED.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C49D8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C4A00.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C4A65.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C4C09.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C5048.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C50D0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C549F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C5585.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C5939.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C6638.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C680B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C7499.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C76E1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C7764.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C78E9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C7C49.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C7C63.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C7EA7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C8490.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C84B2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C9344.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C975A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C9B51.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C9C51.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00C9EC8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CA9B0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CAD91.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CB1E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CB439.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CB452.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CB6A8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CB6D0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CB860.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CBAE4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CBC2C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CBCF2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CBFFC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CC0D1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CC277.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CC544.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CCC62.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CCCD7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CCD2F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CD0C0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CD1E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CD601.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CD710.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CE00F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CE428.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CE6F4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CEB31.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CECDC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CF10F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CF6F4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CF984.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00CFF54.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D002C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D018E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D09DF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D0B76.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D10E8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D1270.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D12E1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D1860.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D1890.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D1944.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D1A92.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D1D7D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D2428.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D2599.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D27EC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D2896.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D29C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D2D3B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D2D7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D2E19.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D3002.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D3199.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D3376.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D37D1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D3808.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D3901.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D3C64.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D3D03.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D4069.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D4298.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D435A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D4390.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D446A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D4AEE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D5090.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D5148.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D5511.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D5C7C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D5D28.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D5E48.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D609.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D6138.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D65B8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D66F3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D6A10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D7ACD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D87F8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D88FE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D8998.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D9010.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D9364.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D94E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D98B1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00D9978.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DA01C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DA510.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DA8E4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DACB7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DAE3C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DAEB4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DB804.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DBDED.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DCBC3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DCD4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DD0CC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DD181.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DD280.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DD758.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DDB22.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DDCCB.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DDCE2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DDD19.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DE399.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DE9DA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DEA23.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DF280.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00DF689.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E026C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E0570.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E06A6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E0A46.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E0D41.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E105F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E13A6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E14D6.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E1515.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E1B71.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E1DE3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E2400.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E259.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E261A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E2769.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E2A04.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E2A68.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E2E00.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E3457.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E38F0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E38FC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E400.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E4A6D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E4D5A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E4FA0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E5010.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E5100.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E5164.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E54.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E5B43.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E6976.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E6992.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E6A5B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E6AE1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E6CD9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E7021.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E75A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E7723.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E7910.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E7BD1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E7BDC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E7C84.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E7CA5.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E8124.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E83B9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E8989.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E8C08.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E8CD0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E8FC4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E8FE7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E9B48.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E9DE2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00E9F59.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EA431.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EAEAA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EB411.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EB729.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EBF91.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ECB6A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ECCAC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ECCEC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ECE4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ED162.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00ED640.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EDE08.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EDE10.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EDEBC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EE4DD.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EEC04.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EEF61.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EF146.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EF19C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EF28B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EF3E3.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EF72B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00EFEAC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F0081.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F023E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F0C38.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F0D1F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F114.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F13A4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F1596.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F16BA.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F1942.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F1C27.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F1C4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F1D24.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F228F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F3003.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F37E8.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F3DD1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F43C7.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F4C66.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F5192.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F54D2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F5840.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F5A79.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F5B0E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F6422.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F6449.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F6BAE.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F705F.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F734E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F73E9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F7589.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F7638.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F7D64.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F7F4E.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F7F6A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F7FB4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F91FC.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F9376.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F9614.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F984.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F9AF9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00F9BF9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FA44D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FA7A1.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FB1A2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FB56B.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FB85A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FC0DF.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FC68.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FC9A2.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FCD36.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FD044.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FD310.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FD5D0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FD8B0.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FD8E9.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FD90A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FD99.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FDA2C.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FDB46.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FDE3D.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FE12A.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FE336.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FF110.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FFAA4.mat (Trojan.Agent) -> No action taken.
C:\Windows\System32\c00FFBFC.mat (Trojan.Agent) -> No action taken.
C:\Users\da flute\AppData\Roaming\Microsoft\Windows\sys32.dll (Trojan.Agent) -> No action taken.
Avatar du membre
nardino
Modérateurs
Modérateurs
Messages : 11993
Enregistré le : 05 févr. 2007, 17:38
Localisation : Reims
Contact :

Re: Rundll erreur entrée manquante

Message par nardino »

Bonjour.

As-tu supprimé la sélection comme précisé dans le tuto et dans mon dernier post ?
@+
Image
Clic sur l'image pour ouvrir le site.
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

juste pour préciser je me suis trompé ceci est le rapport de la premiére analyse que j'vaais faite et je m'étais trompé j'avais pas fait supprimer, j'en ai fefais une, dont le rappor est semblable mais au lieu de "no action taken" c'est escrit "quarantined and deleted succesfuly"
Désolé pour la petit erreur.
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

en fait j'avais analysé une première fois sans supprimer (je suis allé trop vite) puis j'ai recommencé en supprimant et dans le rapport c'est écrit "quaratined and deleted succesfuly"
Avatar du membre
nardino
Modérateurs
Modérateurs
Messages : 11993
Enregistré le : 05 févr. 2007, 17:38
Localisation : Reims
Contact :

Re: Rundll erreur entrée manquante

Message par nardino »

Bonjour.

OK, merci.

Enchaînons
Désactive à nouveau le contrôle des comptes d'utilisateur.


Télécharge Combofix de Subs depuis l'un des liens ci-dessous :

Lien 1
Lien 2
Lien 3


IMPORTANT !!! Enregistre ComboFix.exe sur le Bureau.
Dans le cas d'une infection avérée par Bagle, le renommer Combo-fix.exe avant de l'enregistrer.

Désactive les applications antivirus et anti-malware, en général via un clic droit sur l'icône de la Zone de notification.
Sinon, elles risquent d'interférer avec nos outils.

Fais un double clic sur combofix.exe et suis les invites.

Image

Lors de son exécution, ComboFix va vérifier si la Console de récupération Microsoft Windows est installée.
Avec des infections comme celles d'aujourd'hui, il est fortement conseillé de l'avoir pré-installée sur votre PC avant toute suppression de nuisibles.
Elle permettra de démarrer dans un mode spécial, de récupération (réparation), qui nous permet de vous aider plus facilement si jamais votre ordinateur rencontre un problème après une tentative de nettoyage.

Suis les invites pour permettre à ComboFix de télécharger et installer la Console de récupération Microsoft Windows, et lorsque cela est demandé, accepte le Contrat de Licence Utilisateur Final pour l'installer.

Note importante : Si la Console de récupération Microsoft Windows est déjà installée, ComboFix continuera ses procédures de suppression de nuisibles.

Image

Une fois que la Console de récupération Microsoft Windows est installée via ComboFix, le message suivant apparaitra :

Image

Clique sur Oui/Yes, pour poursuivre avec la recherche de nuisibles.

Lorsque l'outil aura terminé, il vous affichera un rapport.
Copie le contenu de C:\ComboFix.txt dans ta prochaine réponse.

@+
Image
Clic sur l'image pour ouvrir le site.
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

Bonsoir,
j'ai eu du mal à utiliser combo fix car au moment de redémarrer mon pc ça buguait mais j'y suis finalement arrivé, voici le rapport:

ComboFix 08-11-19.08 - da flute 2008-11-20 21:50:49.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1384 [GMT 1:00]
Lancé depuis: c:\users\da flute\Desktop\Combo-Fix.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\dcads-remove.exe
.
---- Previous Run -------
.
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\dcads-remove.exe

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-21 au 2008-11-21 ))))))))))))))))))))))))))))))))))))
.

2008-11-20 21:50 . 2008-11-20 21:50 <REP> d-------- C:\32788R22FWJFW
2008-11-20 13:12 . 2008-11-21 15:48 252,475,789 --a------ c:\windows\MEMORY.DMP
2008-11-20 13:04 . 2008-11-20 13:08 <REP> d-------- C:\ComboFix(0)
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\users\da flute\AppData\Roaming\Malwarebytes
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\users\All Users\Malwarebytes
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\programdata\Malwarebytes
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-20 00:34 . 2008-10-22 16:10 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-20 00:34 . 2008-10-22 16:10 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-11-20 00:20 . 2008-11-20 00:20 0 --ahs---- c:\windows\System32\c00AFD49.mat
2008-11-19 22:21 . 2008-11-20 00:05 <REP> d-------- c:\program files\Navilog1
2008-11-19 22:16 . 2008-11-19 22:16 0 --ahs---- c:\windows\System32\c00C5C3C.mat
2008-11-19 22:16 . 2008-11-19 22:16 0 --ahs---- c:\windows\System32\c002B4E8.mat
2008-11-19 21:51 . 2008-11-19 21:51 0 --ahs---- c:\windows\System32\c00D992A.mat
2008-11-19 21:44 . 2008-11-19 21:44 0 --ahs---- c:\windows\System32\c00E657E.mat
2008-11-15 15:56 . 2008-11-16 12:05 <REP> d-------- c:\users\All Users\Sports Interactive
2008-11-15 15:56 . 2008-11-16 12:05 <REP> d-------- c:\programdata\Sports Interactive
2008-11-15 15:12 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\System32\d3dx9_32.dll
2008-11-12 18:06 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 18:06 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 18:06 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-12 15:36 . 2008-11-14 16:36 <REP> d-------- c:\users\da flute\AppData\Roaming\gtk-2.0
2008-11-11 17:09 . 2008-11-19 19:34 <REP> d-------- c:\users\da flute\AppData\Roaming\Azureus
2008-11-11 17:09 . 2008-11-11 17:09 <REP> d-------- c:\users\All Users\Azureus
2008-11-11 17:09 . 2008-11-11 17:09 <REP> d-------- c:\programdata\Azureus
2008-11-11 17:08 . 2008-11-11 19:41 <REP> d-------- c:\program files\Vuze
2008-11-11 17:08 . 2008-11-11 17:08 <REP> d-------- c:\program files\AskSBar
2008-11-09 18:49 . 2008-11-09 18:50 <REP> d-------- c:\program files\Gimp-2.0
2008-11-09 17:29 . 2008-11-10 11:17 <REP> d-------- c:\users\da flute\.gimp-2.6
2008-11-09 17:29 . 2008-11-09 17:29 <REP> d-------- c:\users\da flute\.gegl-0.0
2008-11-06 18:19 . 2008-11-06 18:19 0 --a------ c:\windows\nsreg.dat
2008-11-06 10:48 . 2008-11-06 10:48 <REP> d-------- c:\users\da flute\AppData\Roaming\Inkscape
2008-11-02 18:48 . 2008-08-05 10:49 428,544 --a------ c:\windows\System32\EncDec.dll
2008-11-02 18:48 . 2008-08-05 10:49 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-11-02 18:48 . 2008-08-05 10:48 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-11-02 18:48 . 2008-08-05 10:48 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-11-02 18:48 . 2008-08-05 10:48 80,896 --a------ c:\windows\System32\MSNP.ax
2008-10-28 22:54 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-28 22:54 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-10-28 22:54 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-10-27 21:36 . 2008-10-27 21:50 <REP> d-------- c:\program files\Inkscape

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 14:58 21,014 ----a-w c:\users\da flute\AppData\Roaming\wklnhst.dat
2008-11-19 18:34 --------- d-----w c:\program files\Microsoft Works
2008-11-19 18:34 --------- d-----w c:\program files\Microsoft Picture It! 9
2008-11-18 08:12 --------- d-----w c:\programdata\Microsoft Help
2008-11-15 15:16 --------- d-----w c:\users\da flute\AppData\Roaming\Sports Interactive
2008-11-13 22:35 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-13 22:33 --------- d-----w c:\users\da flute\AppData\Roaming\Sony
2008-11-11 15:53 --------- d-----w c:\program files\eMule
2008-11-06 21:48 --------- d-----w c:\program files\Google
2008-11-06 17:33 --------- d-----w c:\users\da flute\AppData\Roaming\Samsung
2008-11-01 13:47 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-10-21 08:37 --------- d-----w c:\program files\Common Files\Adobe
2008-10-18 16:09 --------- d-----w c:\users\da flute\AppData\Roaming\Toshiba
2008-10-18 12:05 --------- d-----w c:\programdata\FLEXnet
2008-10-18 11:58 --------- d-----w c:\program files\Bonjour
2008-10-18 11:39 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-10-17 09:57 --------- d-----w c:\program files\PDFCreator Toolbar
2008-10-17 09:39 --------- d-----w c:\program files\Windows Mail
2008-10-16 17:45 --------- d-----w c:\program files\DsNET Corp
2008-10-11 15:49 --------- d-----w c:\programdata\Symantec
2008-10-11 10:33 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-05 13:35 --------- d-----w c:\program files\Java
2008-10-05 09:00 --------- d-----w c:\users\da flute\AppData\Roaming\OpenOffice.org2
2008-10-03 22:01 --------- d-----w c:\program files\PDFCreator
2008-10-03 22:00 253,139 ----a-w c:\windows\PDFCreator_Toolbar_Uninstaller_8304.exe
2008-10-03 21:45 --------- d-----w c:\users\da flute\AppData\Roaming\PPTminimizer
2008-10-03 21:27 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-10-03 18:05 --------- d-----w c:\program files\MSBuild
2008-10-03 18:02 --------- d-----w c:\program files\Microsoft.NET
2008-10-03 17:50 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-29 18:38 --------- d-----w c:\program files\Messenger Plus! Live
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-08-31 14:47 174 --sha-w c:\program files\desktop.ini
2008-08-31 13:28 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-08-31 13:28 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-01-01 21:10 102,768 ----a-w c:\users\da flute\AppData\Roaming\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-11-11 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-11-11 17:08 66912 --a------ c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-06-27 436088]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-05-22 413696]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-04-03 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"Desktop SMS"="c:\program files\IDM\Desktop SMS\DesktopSMS.exe" [2007-06-18 1507328]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-08 894512]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-07 c:\windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\c002B4E8]
2008-11-19 22:16 0 c:\windows\System32\c002B4E8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0010]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0010.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0010000]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0010000.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0012289]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0012289.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0013E64]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0013E64.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00147E2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00147E2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0014A2C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0014A2C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0014E0E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0014E0E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001640]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001640.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0016973]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0016973.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0017300]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0017300.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00178A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00178A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0017D86]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0017D86.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0018526]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0018526.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001AC62]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001AC62.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001ADAA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001ADAA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001B31E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001B31E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001B6E6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001B6E6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001B840]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001B840.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001CEC1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001CEC1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001D3A8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001D3A8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001E161]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001E161.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001E60E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001E60E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001EB90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001EB90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001EF0A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001EF0A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001FEA7]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c001FEA7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0020A78]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0020A78.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0021000]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0021000.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0021100]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0021100.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00234A6]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00234A6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0024524]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0024524.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0025244]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0025244.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00257E0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00257E0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026753]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026753.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026BEE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026BEE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026C40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026C40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026D40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026D40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026F08]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026F08.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00271A4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00271A4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0027E24]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0027E24.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0028E01]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0028E01.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0029614]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0029614.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002A068]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c002A068.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002B02E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002B02E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002B4E8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002B4E8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002B97E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002B97E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002C6D3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002C6D3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002D09]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002D09.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002D5B9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002D5B9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002D905]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002D905.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002E172]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002E172.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002E46C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002E46C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002E992]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002E992.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002ECDE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002ECDE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002EF10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002EF10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002F5B0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002F5B0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002FA5E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002FA5E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002FB22]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002FB22.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002FF10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002FF10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00306EC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00306EC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0031D4E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0031D4E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003201]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003201.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0032290]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0032290.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0032638]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0032638.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0032D1A]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0032D1A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0034066]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0034066.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0034545]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0034545.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0034D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0034D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0035FE8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0035FE8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003664E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003664E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003678C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003678C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003686C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003686C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0037729]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0037729.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0038867]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0038867.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0038CD8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0038CD8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003A264]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003A264.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003A7A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003A7A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003A91E]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c003A91E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003B3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003B3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003B69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003B69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003B70]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003B70.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003BD69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003BD69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003C6F4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003C6F4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003D4F1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003D4F1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003F622]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003F622.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003F686]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003F686.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003FF90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003FF90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0040]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0040.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00402B1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00402B1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00404DA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00404DA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0041272]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0041272.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0043F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0043F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00448C8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00448C8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00448C9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00448C9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0045122]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0045122.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0045734]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0045734.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00458C9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00458C9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00461C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00461C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0046745]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0046745.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0046A18]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0046A18.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004742E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004742E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004785A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004785A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00481BF]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00481BF.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00485CE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00485CE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004861E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004861E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0048661]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0048661.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0048B90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0048B90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0049628]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0049628.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0049789]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0049789.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00499FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00499FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0049F3F]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0049F3F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004A821]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c004A821.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004B1D1]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c004B1D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004B80C]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c004B80C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004C024]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004C024.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004C09]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004C09.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004C470]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004C470.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004CB82]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004CB82.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004EC38]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004EC38.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004F23F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004F23F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005012D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005012D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0050714]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0050714.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0051284]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0051284.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0051BE7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0051BE7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0052536]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0052536.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00527C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00527C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0053900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0053900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0053DE4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0053DE4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00541F8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00541F8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0054804]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0054804.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0054874]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0054874.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00556FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00556FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005692]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005692.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00570D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00570D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0058119]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0058119.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0059211]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0059211.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00593D2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00593D2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005ACF8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005ACF8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005AEE4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005AEE4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005B7C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005B7C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005C0CC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005C0CC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005C6E3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005C6E3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005CA38]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005CA38.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005CCE0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005CCE0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005CE0C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005CE0C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005D10B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005D10B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005D19D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005D19D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005D5E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005D5E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E0F4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E0F4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E1AC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E1AC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E518]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E518.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E845]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E845.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005EE1E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005EE1E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005F5C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005F5C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005FC90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005FC90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00614E4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00614E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00616C6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00616C6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0061C3E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0061C3E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0062524]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0062524.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00629CB]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00629CB.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064100]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0064100.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064474]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0064474.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006455C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006455C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064A9]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0064A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064FBA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0064FBA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0065D9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0065D9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0065FE1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0065FE1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006623E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006623E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0066DFA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0066DFA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006776C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006776C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0067853]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0067853.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0067F03]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0067F03.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00684A8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00684A8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0068790]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0068790.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00690B1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00690B1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00696F2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00696F2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0069A40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0069A40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0069A79]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0069A79.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0069BA5]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0069BA5.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006A10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006A10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006A704]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006A704.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006A900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006A900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006AF7E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006AF7E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C032]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C032.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C225]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C225.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C27C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C27C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C29C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C29C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006D885]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006D885.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006DCEA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006DCEA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006EB82]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006EB82.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006FB10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006FB10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006FBC2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006FBC2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006FEC2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006FEC2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0071E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0071E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0074069]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0074069.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0075413]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0075413.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0076600]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0076600.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00769C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00769C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0076EA4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0076EA4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0076F90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0076F90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0077DF6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0077DF6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0078ADC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0078ADC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0079040]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0079040.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007959E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007959E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A30A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A30A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A62E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A62E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A813]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A813.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A841]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A841.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007D69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007D69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007EB24]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007EB24.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007F28E]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c007F28E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007FBCD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007FBCD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0080FC0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0080FC0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00817D8]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00817D8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0082896]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0082896.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0082E96]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0082E96.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00838B9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00838B9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0083F05]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0083F05.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008400]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008400.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008441D]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c008441D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0084721]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0084721.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0084D29]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0084D29.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0087A24]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0087A24.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0088108]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0088108.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0088840]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0088840.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0088F00]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0088F00.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0089246]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0089246.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0089564]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0089564.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008AEBC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008AEBC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008B39C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008B39C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008B69D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008B69D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008BC34]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008BC34.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008C347]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c008C347.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008CFBD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008CFBD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008D190]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008D190.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008FE9E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008FE9E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090691]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0090691.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0090900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090CBC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0090CBC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090FA4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0090FA4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0091529]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0091529.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00924B6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00924B6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0093B7A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0093B7A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0094570]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0094570.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00959BA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00959BA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0095C7B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0095C7B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0095EE4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0095EE4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0096316]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0096316.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0096F5A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0096F5A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009776E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009776E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009799]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009799.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009831B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009831B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0098C20]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0098C20.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0098E40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0098E40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0098F64]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0098F64.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00991D4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00991D4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009948D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009948D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0099E06]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0099E06.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009A4DA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009A4DA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009BAC4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009BAC4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009BCF2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009BCF2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009CE90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009CE90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009D1DC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009D1DC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009D9A3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009D9A3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009EC32]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009EC32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009EDB0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009EDB0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009EDC4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009EDC4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009FDA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009FDA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A108B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A108B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A20E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A20E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A2E1A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A2E1A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A3590]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A3590.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A3B32]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00A3B32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A4142]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A4142.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A45AE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A45AE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A4706]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A4706.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A4986]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A4986.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A646F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A646F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A6900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A6900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A71E2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A71E2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A7982]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00A7982.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A7BE0]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00A7BE0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A7F02]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A7F02.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A92CE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A92CE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A9E2C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A9E2C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AA4DA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AA4DA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AA5AE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AA5AE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AB240]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AB240.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AC40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AC40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AD511]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AD511.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AE259]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AE259.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AFC72]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00AFC72.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B0C22]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B0C22.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B0F41]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B0F41.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B1EC8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B1EC8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B2195]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B2195.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B236]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B236.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B31E2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B31E2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B4450]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B4450.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B45A4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B45A4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B4D98]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B4D98.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B5024]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B5024.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B5840]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B5840.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B5C69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B5C69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B707C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B707C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B70FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B70FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B97AD]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00B97AD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BAB8E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BAB8E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BB3A0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BB3A0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BB63A]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BB63A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BBB32]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BBB32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC0B4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC0B4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC18B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC18B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC3C7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC3C7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC867]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC867.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BCC22]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BCC22.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BDB3A]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BDB3A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BDC7C]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BDC7C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BDDB]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BDDB.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BEC31]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BEC31.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BEE09]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BEE09.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BEE94]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BEE94.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BF021]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BF021.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BF8D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BF8D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C0090]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C0090.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C00B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C00B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C0386]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C0386.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C2652]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C2652.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C2D10]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C2D10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C39E7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C39E7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C3DC9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C3DC9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C4DA9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C4DA9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C66F6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C66F6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C67A1]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C67A1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C7440]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C7440.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C781E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C781E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C78E9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C78E9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C7B88]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C7B88.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C7D52]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C7D52.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C9788]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C9788.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C9A91]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C9A91.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CA532]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CA532.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CA5AC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CA5AC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CA8E7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CA8E7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CACA9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CACA9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB0B4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB0B4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB411]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB411.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB729]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB729.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB9CD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB9CD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CBACC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CBACC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CBC8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CBC8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CCD31]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CCD31.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CDE41]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CDE41.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CF735]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CF735.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D0876]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D0876.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D16D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D16D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D29B0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D29B0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D2FD6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D2FD6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D37D5]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D37D5.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D3CBA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D3CBA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D4F96]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D4F96.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D766B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D766B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D7AB8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D7AB8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D88FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D88FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D8B63]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D8B63.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D9108]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D9108.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D9280]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D9280.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DBA84]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00DBA84.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DBE2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DBE2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DC04]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DC04.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DC571]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DC571.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DCE03]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00DCE03.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD072]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD072.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD308]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD308.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD413]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD413.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD8FA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD8FA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD9A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD9A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DDC81]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DDC81.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DE588]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DE588.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DE9A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DE9A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E0C10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E0C10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E0F32]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E0F32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E1690]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E1690.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E216E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E216E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E401A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E401A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E64D0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E64D0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E6536]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E6536.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E66A0]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00E66A0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E7136]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E7136.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E75C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E75C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E7A78]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E7A78.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E7CC6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E7CC6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EA144]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EA144.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EA445]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EA445.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EA89E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EA89E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EAD80]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EAD80.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EBBE3]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00EBBE3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EBFBE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EBFBE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00ED939]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00ED939.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EE456]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EE456.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EF0D2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EF0D2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EF46A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EF46A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F05B3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F05B3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F0874]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F0874.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F10B9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F10B9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F165A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F165A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F228F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F228F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F2400]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F2400.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F28E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F28E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F29D2]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F29D2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F2AAF]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F2AAF.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F3A56]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F3A56.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F4126]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F4126.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F63B1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F63B1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F6464]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F6464.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F6C3A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F6C3A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F7FB4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F7FB4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F7FF3]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F7FF3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F846]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F846.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F91AD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F91AD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F990F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F990F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FA3E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FA3E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FA7A1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FA7A1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FB852]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FB852.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FB85A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FB85A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FC583]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FC583.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FCFDC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FCFDC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FDA2C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FDA2C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FDD6C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FDD6C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E13B20E4-803B-491E-8A42-379E05A6D7BD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5AC6B7EB-6F12-4ED5-9867-48FF05758BB0}"= UDP:c:\program files\eMule\emule.exe:eMule
"{21446F4E-2F39-494C-B98A-741B0EB42815}"= TCP:c:\program files\eMule\emule.exe:eMule
"{3705BCE4-12D2-42CA-B40E-1CB8A80163DB}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{CDF77771-6C11-4F4D-A848-ECEDA7422CAE}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C0EB7E8D-57D8-412F-9D9C-5E9E4D7BB7BC}"= UDP:c:\program files\Codemasters\Le Seigneur des anneaux Online\lotroclient.exe:lotroclient
"{ACE42427-6AB7-44C2-AB45-A563B21B627C}"= TCP:c:\program files\Codemasters\Le Seigneur des anneaux Online\lotroclient.exe:lotroclient
"{09D1076A-1F05-4974-97EA-662312D682D0}"= UDP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineInvoker.exe:TurbineInvoker
"{D9EDD5D7-CC67-4D6E-9CEE-23F1E345A5C8}"= TCP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineInvoker.exe:TurbineInvoker
"{A362C5A7-6413-447E-90EA-38A7E7C3C059}"= Disabled:UDP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineLauncher.exe:TurbineLauncher
"{9BE5508B-0878-4FDC-9387-58DFEACAFFF6}"= Disabled:TCP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineLauncher.exe:TurbineLauncher
"{15E0727D-4C7E-41E9-9693-C3A972701D85}"= UDP:4662:emule
"{94B89F3E-D61B-42EE-AF6E-1084A6A12664}"= TCP:4672:emule
"TCP Query User{469E37F9-F0B4-4CEA-894D-02B64C5C439B}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{1FA9A288-68EF-4217-A184-F0AD2195A825}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{8D99EFC1-401E-43FA-910E-AEC4CC8B0F7B}c:\\users\\da flute\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\da flute\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{7DC14EDD-7E89-4453-9B61-939C4BCF0171}c:\\users\\da flute\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\da flute\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"{72BB0C5A-4B62-44AC-B448-E0858DFCF1E6}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{A527629A-444D-4CA1-968B-EB1DE172D405}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{03170058-34B5-40C8-802E-D02D9A0447D8}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
"{F140E44E-F93F-4C97-BEFE-94E43026DE3A}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
"{D84327D3-3DDF-48B3-93F3-7F973AEC82FE}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{E8BCF5F6-2ADC-450E-88ED-E66FC9918CCC}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{225D501F-332A-422C-8F78-B9C48E5E12EB}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{4320DF04-CD75-45B6-A37B-F5DDD56F8C78}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{EAAD8D78-4407-4849-8F4F-3BC859A7875E}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{5A439AB8-2812-47E2-985F-F6081D48A8A0}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{53777DB8-90AB-4A2C-9E12-0F3B196F0617}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 AtiPcie;ATI PCI Express (3GIO) Filter;c:\windows\system32\DRIVERS\AtiPcie.sys [2007-08-29 7680]
R0 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
R1 IDSvix86;Symantec Intrusion Prevention Driver;\??\c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20081118.001\IDSvix86.sys [2008-11-19 270384]
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-02-08 149352]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2007-08-29 2600960]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 41008]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2007-05-29 23888]
.
Contenu du dossier 'Tâches planifiées'

2008-11-17 c:\windows\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - da flute.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-26 18:19]
.
- - - - ORPHELINS SUPPRIMES - - - -

HKLM-Run-HWSetup - \HWSetup.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
Notify-c0010000 - c0010000.mat
Notify-c0012289 - c0012289.mat
Notify-c0013E64 - c0013E64.mat
Notify-c00147E2 - c00147E2.mat
Notify-c0014A2C - c0014A2C.mat
Notify-c0014E0E - c0014E0E.mat
Notify-c001640 - c001640.mat
Notify-c0017300 - c0017300.mat
Notify-c00178A9 - c00178A9.mat
Notify-c0017D86 - c0017D86.mat
Notify-c0018526 - c0018526.mat
Notify-c001AC62 - c001AC62.mat
Notify-c001ADAA - c001ADAA.mat
Notify-c001B31E - c001B31E.mat
Notify-c001B840 - c001B840.mat
Notify-c001D3A8 - c001D3A8.mat
Notify-c001E161 - c001E161.mat
Notify-c001E60E - c001E60E.mat
Notify-c001EF0A - c001EF0A.mat
Notify-c001FEA7 - c001FEA7.mat
Notify-c0020A78 - c0020A78.mat
Notify-c0021000 - c0021000.mat
Notify-c00234A6 - c00234A6.mat
Notify-c0024524 - c0024524.mat
Notify-c0025244 - c0025244.mat
Notify-c0026BEE - c0026BEE.mat
Notify-c0026C40 - c0026C40.mat
Notify-c0026D40 - c0026D40.mat
Notify-c0026F08 - c0026F08.mat
Notify-c00271A4 - c00271A4.mat
Notify-c0027E24 - c0027E24.mat
Notify-c0028E01 - c0028E01.mat
Notify-c0029614 - c0029614.mat
Notify-c002A068 - c002A068.mat
Notify-c002B97E - c002B97E.mat
Notify-c002C6D3 - c002C6D3.mat
Notify-c002D5B9 - c002D5B9.mat
Notify-c002D905 - c002D905.mat
Notify-c002E46C - c002E46C.mat
Notify-c002E992 - c002E992.mat
Notify-c002EF10 - c002EF10.mat
Notify-c002F5B0 - c002F5B0.mat
Notify-c002FA5E - c002FA5E.mat
Notify-c002FB22 - c002FB22.mat
Notify-c002FF10 - c002FF10.mat
Notify-c00306EC - c00306EC.mat
Notify-c0031D4E - c0031D4E.mat
Notify-c0032290 - c0032290.mat
Notify-c0032638 - c0032638.mat
Notify-c0032D1A - c0032D1A.mat
Notify-c0034066 - c0034066.mat
Notify-c0034545 - c0034545.mat
Notify-c0035FE8 - c0035FE8.mat
Notify-c003664E - c003664E.mat
Notify-c003686C - c003686C.mat
Notify-c0037729 - c0037729.mat
Notify-c0038867 - c0038867.mat
Notify-c003A264 - c003A264.mat
Notify-c003A7A9 - c003A7A9.mat
Notify-c003A91E - c003A91E.mat
Notify-c003B70 - c003B70.mat
Notify-c003C6F4 - c003C6F4.mat
Notify-c003D4F1 - c003D4F1.mat
Notify-c003F622 - c003F622.mat
Notify-c003F686 - c003F686.mat
Notify-c003FF90 - c003FF90.mat
Notify-c0040 - c0040.mat
Notify-c00404DA - c00404DA.mat
Notify-c0041272 - c0041272.mat
Notify-c0043F - c0043F.mat
Notify-c00448C9 - c00448C9.mat
Notify-c0045122 - c0045122.mat
Notify-c0045734 - c0045734.mat
Notify-c00461C4 - c00461C4.mat
Notify-c0046745 - c0046745.mat
Notify-c0046A18 - c0046A18.mat
Notify-c004742E - c004742E.mat
Notify-c00481BF - c00481BF.mat
Notify-c00485CE - c00485CE.mat
Notify-c004861E - c004861E.mat
Notify-c0048661 - c0048661.mat
Notify-c0048B90 - c0048B90.mat
Notify-c0049789 - c0049789.mat
Notify-c00499FE - c00499FE.mat
Notify-c0049F3F - c0049F3F.mat
Notify-c004A821 - c004A821.mat
Notify-c004B80C - c004B80C.mat
Notify-c004C024 - c004C024.mat
Notify-c004C470 - c004C470.mat
Notify-c004CB82 - c004CB82.mat
Notify-c004EC38 - c004EC38.mat
Notify-c004F23F - c004F23F.mat
Notify-c005012D - c005012D.mat
Notify-c0051284 - c0051284.mat
Notify-c0051BE7 - c0051BE7.mat
Notify-c00527C4 - c00527C4.mat
Notify-c0053DE4 - c0053DE4.mat
Notify-c00541F8 - c00541F8.mat
Notify-c0054874 - c0054874.mat
Notify-c00556FE - c00556FE.mat
Notify-c005692 - c005692.mat
Notify-c00570D1 - c00570D1.mat
Notify-c0058119 - c0058119.mat
Notify-c0059211 - c0059211.mat
Notify-c005ACF8 - c005ACF8.mat
Notify-c005AEE4 - c005AEE4.mat
Notify-c005B7C4 - c005B7C4.mat
Notify-c005C0CC - c005C0CC.mat
Notify-c005C6E3 - c005C6E3.mat
Notify-c005CA38 - c005CA38.mat
Notify-c005CCE0 - c005CCE0.mat
Notify-c005CE0C - c005CE0C.mat
Notify-c005D10B - c005D10B.mat
Notify-c005E0F4 - c005E0F4.mat
Notify-c005E518 - c005E518.mat
Notify-c005E845 - c005E845.mat
Notify-c005EE1E - c005EE1E.mat
Notify-c005F5C4 - c005F5C4.mat
Notify-c005FC90 - c005FC90.mat
Notify-c00616C6 - c00616C6.mat
Notify-c0061C3E - c0061C3E.mat
Notify-c0062524 - c0062524.mat
Notify-c0064100 - c0064100.mat
Notify-c0064474 - c0064474.mat
Notify-c006455C - c006455C.mat
Notify-c0064A9 - c0064A9.mat
Notify-c0064FBA - c0064FBA.mat
Notify-c0065D9 - c0065D9.mat
Notify-c0065FE1 - c0065FE1.mat
Notify-c006623E - c006623E.mat
Notify-c0066DFA - c0066DFA.mat
Notify-c006776C - c006776C.mat
Notify-c0067853 - c0067853.mat
Notify-c00684A8 - c00684A8.mat
Notify-c0068790 - c0068790.mat
Notify-c00690B1 - c00690B1.mat
Notify-c0069A40 - c0069A40.mat
Notify-c0069A79 - c0069A79.mat
Notify-c0069BA5 - c0069BA5.mat
Notify-c006A704 - c006A704.mat
Notify-c006AF7E - c006AF7E.mat
Notify-c006C032 - c006C032.mat
Notify-c006C225 - c006C225.mat
Notify-c006C29C - c006C29C.mat
Notify-c006D885 - c006D885.mat
Notify-c006EB82 - c006EB82.mat
Notify-c006FB10 - c006FB10.mat
Notify-c006FBC2 - c006FBC2.mat
Notify-c006FEC2 - c006FEC2.mat
Notify-c0074069 - c0074069.mat
Notify-c0075413 - c0075413.mat
Notify-c0076600 - c0076600.mat
Notify-c00769C4 - c00769C4.mat
Notify-c0076EA4 - c0076EA4.mat
Notify-c0076F90 - c0076F90.mat
Notify-c0077DF6 - c0077DF6.mat
Notify-c0078ADC - c0078ADC.mat
Notify-c0079040 - c0079040.mat
Notify-c007959E - c007959E.mat
Notify-c007A30A - c007A30A.mat
Notify-c007A62E - c007A62E.mat
Notify-c007A813 - c007A813.mat
Notify-c007A841 - c007A841.mat
Notify-c007EB24 - c007EB24.mat
Notify-c007F28E - c007F28E.mat
Notify-c0080FC0 - c0080FC0.mat
Notify-c00817D8 - c00817D8.mat
Notify-c0082896 - c0082896.mat
Notify-c0082E96 - c0082E96.mat
Notify-c00838B9 - c00838B9.mat
Notify-c008441D - c008441D.mat
Notify-c0084721 - c0084721.mat
Notify-c0084D29 - c0084D29.mat
Notify-c0087A24 - c0087A24.mat
Notify-c0088840 - c0088840.mat
Notify-c0088F00 - c0088F00.mat
Notify-c0089246 - c0089246.mat
Notify-c0089564 - c0089564.mat
Notify-c008AEBC - c008AEBC.mat
Notify-c008B39C - c008B39C.mat
Notify-c008B69D - c008B69D.mat
Notify-c008BC34 - c008BC34.mat
Notify-c008C347 - c008C347.mat
Notify-c008CFBD - c008CFBD.mat
Notify-c008FE9E - c008FE9E.mat
Notify-c0090691 - c0090691.mat
Notify-c0090CBC - c0090CBC.mat
Notify-c0090FA4 - c0090FA4.mat
Notify-c0091529 - c0091529.mat
Notify-c00924B6 - c00924B6.mat
Notify-c0094570 - c0094570.mat
Notify-c00959BA - c00959BA.mat
Notify-c0095C7B - c0095C7B.mat
Notify-c0095EE4 - c0095EE4.mat
Notify-c009776E - c009776E.mat
Notify-c009799 - c009799.mat
Notify-c0098C20 - c0098C20.mat
Notify-c0098F64 - c0098F64.mat
Notify-c00991D4 - c00991D4.mat
Notify-c009948D - c009948D.mat
Notify-c0099E06 - c0099E06.mat
Notify-c009A4DA - c009A4DA.mat
Notify-c009BAC4 - c009BAC4.mat
Notify-c009BCF2 - c009BCF2.mat
Notify-c009CE90 - c009CE90.mat
Notify-c009D1DC - c009D1DC.mat
Notify-c009D9A3 - c009D9A3.mat
Notify-c009EC32 - c009EC32.mat
Notify-c009EDC4 - c009EDC4.mat
Notify-c009FDA - c009FDA.mat
Notify-c00A108B - c00A108B.mat
Notify-c00A2E1A - c00A2E1A.mat
Notify-c00A3B32 - c00A3B32.mat
Notify-c00A4142 - c00A4142.mat
Notify-c00A45AE - c00A45AE.mat
Notify-c00A646F - c00A646F.mat
Notify-c00A6900 - c00A6900.mat
Notify-c00A7BE0 - c00A7BE0.mat
Notify-c00A92CE - c00A92CE.mat
Notify-c00A9E2C - c00A9E2C.mat
Notify-c00AA5AE - c00AA5AE.mat
Notify-c00AB240 - c00AB240.mat
Notify-c00AC40 - c00AC40.mat
Notify-c00AD511 - c00AD511.mat
Notify-c00AE259 - c00AE259.mat
Notify-c00AFC72 - c00AFC72.mat
Notify-c00B0C22 - c00B0C22.mat
Notify-c00B1EC8 - c00B1EC8.mat
Notify-c00B2195 - c00B2195.mat
Notify-c00B236 - c00B236.mat
Notify-c00B4450 - c00B4450.mat
Notify-c00B45A4 - c00B45A4.mat
Notify-c00B4D98 - c00B4D98.mat
Notify-c00B5840 - c00B5840.mat
Notify-c00B5C69 - c00B5C69.mat
Notify-c00B707C - c00B707C.mat
Notify-c00B70FE - c00B70FE.mat
Notify-c00B97AD - c00B97AD.mat
Notify-c00BAB8E - c00BAB8E.mat
Notify-c00BB3A0 - c00BB3A0.mat
Notify-c00BB63A - c00BB63A.mat
Notify-c00BBB32 - c00BBB32.mat
Notify-c00BC0B4 - c00BC0B4.mat
Notify-c00BC18B - c00BC18B.mat
Notify-c00BC3C7 - c00BC3C7.mat
Notify-c00BC867 - c00BC867.mat
Notify-c00BCC22 - c00BCC22.mat
Notify-c00BDDB - c00BDDB.mat
Notify-c00BEC31 - c00BEC31.mat
Notify-c00BEE09 - c00BEE09.mat
Notify-c00BEE94 - c00BEE94.mat
Notify-c00BF021 - c00BF021.mat
Notify-c00BF8D1 - c00BF8D1.mat
Notify-c00C0090 - c00C0090.mat
Notify-c00C00B - c00C00B.mat
Notify-c00C0386 - c00C0386.mat
Notify-c00C2652 - c00C2652.mat
Notify-c00C2D10 - c00C2D10.mat
Notify-c00C3DC9 - c00C3DC9.mat
Notify-c00C4DA9 - c00C4DA9.mat
Notify-c00C66F6 - c00C66F6.mat
Notify-c00C67A1 - c00C67A1.mat
Notify-c00C781E - c00C781E.mat
Notify-c00C7B88 - c00C7B88.mat
Notify-c00C7D52 - c00C7D52.mat
Notify-c00C9788 - c00C9788.mat
Notify-c00C9A91 - c00C9A91.mat
Notify-c00CA532 - c00CA532.mat
Notify-c00CA5AC - c00CA5AC.mat
Notify-c00CA8E7 - c00CA8E7.mat
Notify-c00CACA9 - c00CACA9.mat
Notify-c00CB411 - c00CB411.mat
Notify-c00CB729 - c00CB729.mat
Notify-c00CB9CD - c00CB9CD.mat
Notify-c00CBACC - c00CBACC.mat
Notify-c00CCD31 - c00CCD31.mat
Notify-c00CDE41 - c00CDE41.mat
Notify-c00CF735 - c00CF735.mat
Notify-c00D0876 - c00D0876.mat
Notify-c00D16D1 - c00D16D1.mat
Notify-c00D29B0 - c00D29B0.mat
Notify-c00D37D5 - c00D37D5.mat
Notify-c00D3CBA - c00D3CBA.mat
Notify-c00D4F96 - c00D4F96.mat
Notify-c00D766B - c00D766B.mat
Notify-c00D8B63 - c00D8B63.mat
Notify-c00D9108 - c00D9108.mat
Notify-c00DBA84 - c00DBA84.mat
Notify-c00DBE2 - c00DBE2.mat
Notify-c00DC04 - c00DC04.mat
Notify-c00DC571 - c00DC571.mat
Notify-c00DCE03 - c00DCE03.mat
Notify-c00DD308 - c00DD308.mat
Notify-c00DD413 - c00DD413.mat
Notify-c00DD8FA - c00DD8FA.mat
Notify-c00DD9A9 - c00DD9A9.mat
Notify-c00DDC81 - c00DDC81.mat
Notify-c00DE588 - c00DE588.mat
Notify-c00E0C10 - c00E0C10.mat
Notify-c00E1690 - c00E1690.mat
Notify-c00E216E - c00E216E.mat
Notify-c00E401A - c00E401A.mat
Notify-c00E64D0 - c00E64D0.mat
Notify-c00E66A0 - c00E66A0.mat
Notify-c00E75C4 - c00E75C4.mat
Notify-c00E7A78 - c00E7A78.mat
Notify-c00E7CC6 - c00E7CC6.mat
Notify-c00EA144 - c00EA144.mat
Notify-c00EA445 - c00EA445.mat
Notify-c00EA89E - c00EA89E.mat
Notify-c00EBBE3 - c00EBBE3.mat
Notify-c00ED939 - c00ED939.mat
Notify-c00EE456 - c00EE456.mat
Notify-c00EF0D2 - c00EF0D2.mat
Notify-c00EF46A - c00EF46A.mat
Notify-c00F05B3 - c00F05B3.mat
Notify-c00F0874 - c00F0874.mat
Notify-c00F10B9 - c00F10B9.mat
Notify-c00F28E4 - c00F28E4.mat
Notify-c00F29D2 - c00F29D2.mat
Notify-c00F2AAF - c00F2AAF.mat
Notify-c00F3A56 - c00F3A56.mat
Notify-c00F4126 - c00F4126.mat
Notify-c00F63B1 - c00F63B1.mat
Notify-c00F6464 - c00F6464.mat
Notify-c00F6C3A - c00F6C3A.mat
Notify-c00F7FF3 - c00F7FF3.mat
Notify-c00F846 - c00F846.mat
Notify-c00F91AD - c00F91AD.mat
Notify-c00FA3E4 - c00FA3E4.mat
Notify-c00FB852 - c00FB852.mat
Notify-c00FC583 - c00FC583.mat
Notify-c00FCFDC - c00FCFDC.mat
Notify-c00FDD6C - c00FDD6C.mat
MSConfigStartUp-cmds - c:\users\DAFLUT~1\AppData\Local\Temp\fccbYrOi.dll


.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\users\da flute\AppData\Roaming\Mozilla\Firefox\Profiles\wk42f29s.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.fr/
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-21 15:51:12
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\conime.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\TOSHIBA\ConfigFree\CFSwMgr.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\System32\msiexec.exe
c:\progra~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2008-11-21 15:59:40 - La machine a redémarré [da flute]
ComboFix-quarantined-files.txt 2008-11-21 14:59:29

Avant-CF: 44,916,899,840 octets libres
Après-CF: 44,693,114,880 octets libres

1440 --- E O F --- 2008-11-18 08:12:53
Avatar du membre
nardino
Modérateurs
Modérateurs
Messages : 11993
Enregistré le : 05 févr. 2007, 17:38
Localisation : Reims
Contact :

Re: Rundll erreur entrée manquante

Message par nardino »

Bonsoir.

Suite des opérations.

**Création d'un Script Combofix**

ATTENTION : Cette procédure a été rédigée pour le cas présent, toute copie sur sur un autre système peut entrainer des dysfonctionnements graves.

Ouvre le bloc-notes : Tous les programmes - Accessoire - Bloc-notes
Colles-y les lignes écrites ci-dessous :
Veille à ce que Retour à la ligne ne soit pas coché dans Format.

File::
c:\windows\System32\c00*.mat

Folder::
c:\program files\AskSBar

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"=-
[-HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\c002B4E8]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00*]
Enregistre-le sous CFScript.txt, sur le bureau
Comme sur l'image présentée ici, fais glisser CFScript.txt dans Combofix.exe
Image
Combofix va se lancer et faire redémarrer l'ordinateur.
Poste le rapport C:\Combofix et un nouveau rapport HijackThis.

La source de tes problèmes se situe ici:
c:\program files\eMule\emule.exe
c:\program files\LimeWire\LimeWire.exe
c:\program files\vuze\azureus.exe


Voici quelques lectures à ce sujet:
http://www.speedweb1.org/forum-tesgaz/v ... php?t=1793
http://forum.zebulon.fr/index.php?showtopic=85544
http://www.libellules.ch/phpBB2/les-ris ... 28947.html

@+
Image
Clic sur l'image pour ouvrir le site.
da-flute
Novice
Novice
Messages : 33
Enregistré le : 19 nov. 2008, 20:36

Re: Rundll erreur entrée manquante

Message par da-flute »

Voilà le nouveau rapport combofix:

ComboFix 08-11-20.02 - da flute 2008-11-21 18:30:47.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1276 [GMT 1:00]
Lancé depuis: c:\users\da flute\Desktop\Combo-Fix.exe
Commutateurs utilisés :: c:\users\da flute\Desktop\CFScript.txt
* Un nouveau point de restauration a été créé
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AskSBar
c:\program files\AskSBar\bar\1.bin\A2FFXTBR.JAR
c:\program files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
c:\program files\AskSBar\bar\1.bin\A2HIGHIN.EXE
c:\program files\AskSBar\bar\1.bin\A2NTSTBR.JAR
c:\program files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
c:\program files\AskSBar\bar\1.bin\A2PLUGIN.DLL
c:\program files\AskSBar\bar\1.bin\ASKSBAR.DLL
c:\program files\AskSBar\bar\1.bin\NPASKSBR.DLL
c:\program files\AskSBar\bar\1.bin\V2RSSMNU.DLL
c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-21 au 2008-11-21 ))))))))))))))))))))))))))))))))))))
.

2008-11-20 13:12 . 2008-11-21 15:48 252,475,789 --a------ c:\windows\MEMORY.DMP
2008-11-20 13:04 . 2008-11-20 13:08 <REP> d-------- C:\ComboFix(0)
2008-11-20 12:47 . 2008-11-20 21:50 <REP> d-------- C:\ComboFix
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\users\da flute\AppData\Roaming\Malwarebytes
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\users\All Users\Malwarebytes
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\programdata\Malwarebytes
2008-11-20 00:34 . 2008-11-20 00:34 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-20 00:34 . 2008-10-22 16:10 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-20 00:34 . 2008-10-22 16:10 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-11-20 00:20 . 2008-11-20 00:20 0 --ahs---- c:\windows\System32\c00AFD49.mat
2008-11-19 22:21 . 2008-11-20 00:05 <REP> d-------- c:\program files\Navilog1
2008-11-19 22:16 . 2008-11-19 22:16 0 --ahs---- c:\windows\System32\c00C5C3C.mat
2008-11-19 22:16 . 2008-11-19 22:16 0 --ahs---- c:\windows\System32\c002B4E8.mat
2008-11-19 21:51 . 2008-11-19 21:51 0 --ahs---- c:\windows\System32\c00D992A.mat
2008-11-19 21:44 . 2008-11-19 21:44 0 --ahs---- c:\windows\System32\c00E657E.mat
2008-11-15 15:56 . 2008-11-16 12:05 <REP> d-------- c:\users\All Users\Sports Interactive
2008-11-15 15:56 . 2008-11-16 12:05 <REP> d-------- c:\programdata\Sports Interactive
2008-11-15 15:12 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\System32\d3dx9_32.dll
2008-11-12 18:06 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 18:06 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 18:06 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-12 15:36 . 2008-11-14 16:36 <REP> d-------- c:\users\da flute\AppData\Roaming\gtk-2.0
2008-11-11 17:09 . 2008-11-19 19:34 <REP> d-------- c:\users\da flute\AppData\Roaming\Azureus
2008-11-11 17:09 . 2008-11-11 17:09 <REP> d-------- c:\users\All Users\Azureus
2008-11-11 17:09 . 2008-11-11 17:09 <REP> d-------- c:\programdata\Azureus
2008-11-11 17:08 . 2008-11-11 19:41 <REP> d-------- c:\program files\Vuze
2008-11-09 18:49 . 2008-11-09 18:50 <REP> d-------- c:\program files\Gimp-2.0
2008-11-09 17:29 . 2008-11-10 11:17 <REP> d-------- c:\users\da flute\.gimp-2.6
2008-11-09 17:29 . 2008-11-09 17:29 <REP> d-------- c:\users\da flute\.gegl-0.0
2008-11-06 18:19 . 2008-11-06 18:19 0 --a------ c:\windows\nsreg.dat
2008-11-06 10:48 . 2008-11-06 10:48 <REP> d-------- c:\users\da flute\AppData\Roaming\Inkscape
2008-11-02 18:48 . 2008-08-05 10:49 428,544 --a------ c:\windows\System32\EncDec.dll
2008-11-02 18:48 . 2008-08-05 10:49 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-11-02 18:48 . 2008-08-05 10:48 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-11-02 18:48 . 2008-08-05 10:48 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-11-02 18:48 . 2008-08-05 10:48 80,896 --a------ c:\windows\System32\MSNP.ax
2008-10-28 22:54 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-28 22:54 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-10-28 22:54 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-10-27 21:36 . 2008-10-27 21:50 <REP> d-------- c:\program files\Inkscape

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 14:58 21,014 ----a-w c:\users\da flute\AppData\Roaming\wklnhst.dat
2008-11-19 18:34 --------- d-----w c:\program files\Microsoft Works
2008-11-19 18:34 --------- d-----w c:\program files\Microsoft Picture It! 9
2008-11-18 08:12 --------- d-----w c:\programdata\Microsoft Help
2008-11-15 15:16 --------- d-----w c:\users\da flute\AppData\Roaming\Sports Interactive
2008-11-13 22:35 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-13 22:33 --------- d-----w c:\users\da flute\AppData\Roaming\Sony
2008-11-11 15:53 --------- d-----w c:\program files\eMule
2008-11-06 21:48 --------- d-----w c:\program files\Google
2008-11-06 17:33 --------- d-----w c:\users\da flute\AppData\Roaming\Samsung
2008-11-01 13:47 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-10-21 08:37 --------- d-----w c:\program files\Common Files\Adobe
2008-10-18 16:09 --------- d-----w c:\users\da flute\AppData\Roaming\Toshiba
2008-10-18 12:05 --------- d-----w c:\programdata\FLEXnet
2008-10-18 11:58 --------- d-----w c:\program files\Bonjour
2008-10-18 11:39 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-10-17 09:57 --------- d-----w c:\program files\PDFCreator Toolbar
2008-10-17 09:39 --------- d-----w c:\program files\Windows Mail
2008-10-16 17:45 --------- d-----w c:\program files\DsNET Corp
2008-10-11 15:49 --------- d-----w c:\programdata\Symantec
2008-10-11 10:33 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-05 13:35 --------- d-----w c:\program files\Java
2008-10-05 09:00 --------- d-----w c:\users\da flute\AppData\Roaming\OpenOffice.org2
2008-10-03 22:01 --------- d-----w c:\program files\PDFCreator
2008-10-03 22:00 253,139 ----a-w c:\windows\PDFCreator_Toolbar_Uninstaller_8304.exe
2008-10-03 21:45 --------- d-----w c:\users\da flute\AppData\Roaming\PPTminimizer
2008-10-03 21:27 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-10-03 18:05 --------- d-----w c:\program files\MSBuild
2008-10-03 18:02 --------- d-----w c:\program files\Microsoft.NET
2008-10-03 17:50 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-29 18:38 --------- d-----w c:\program files\Messenger Plus! Live
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-08-31 14:47 174 --sha-w c:\program files\desktop.ini
2008-08-31 13:28 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-08-31 13:28 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-01-01 21:10 102,768 ----a-w c:\users\da flute\AppData\Roaming\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-11-21_15.57.50.69 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-20 20:55:50 278,064 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-11-21 16:19:47 278,064 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-11-21 16:20:35 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-11-21 16:20:35 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-11-21 14:49:50 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-11-21 16:21:55 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-11-21 14:49:50 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-11-21 16:38:11 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-11-21 16:38:11 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-11-20 12:13:20 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-11-21 16:40:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-11-20 12:13:20 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-21 16:40:42 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-20 12:13:20 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-21 16:40:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-11-20 12:11:25 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2008-11-21 17:30:15 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2008-11-20 20:49:16 104,940 ----a-w c:\windows\System32\perfc009.dat
+ 2008-11-21 16:27:17 104,940 ----a-w c:\windows\System32\perfc009.dat
- 2008-11-20 20:49:17 128,004 ----a-w c:\windows\System32\perfc00C.dat
+ 2008-11-21 16:27:17 128,004 ----a-w c:\windows\System32\perfc00C.dat
- 2008-11-20 20:49:17 595,506 ----a-w c:\windows\System32\perfh009.dat
+ 2008-11-21 16:27:17 595,506 ----a-w c:\windows\System32\perfh009.dat
- 2008-11-20 20:49:17 678,956 ----a-w c:\windows\System32\perfh00C.dat
+ 2008-11-21 16:27:17 678,956 ----a-w c:\windows\System32\perfh00C.dat
- 2008-11-20 20:45:46 12,764 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3252096393-2948737103-2338384716-1000_UserData.bin
+ 2008-11-21 16:22:22 13,188 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3252096393-2948737103-2338384716-1000_UserData.bin
- 2008-11-20 20:45:46 79,220 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-11-21 16:22:22 79,220 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-11-20 20:45:45 55,192 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-11-21 16:22:21 55,192 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-06-27 436088]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-05-22 413696]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-04-03 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"Desktop SMS"="c:\program files\IDM\Desktop SMS\DesktopSMS.exe" [2007-06-18 1507328]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-08 894512]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-07 c:\windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0010]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0010.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0010000]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0010000.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0012289]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0012289.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0013E64]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0013E64.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00147E2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00147E2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0014A2C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0014A2C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0014E0E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0014E0E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001640]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001640.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0016973]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0016973.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0017300]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0017300.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00178A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00178A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0017D86]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0017D86.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0018526]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0018526.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001AC62]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001AC62.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001ADAA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001ADAA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001B31E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001B31E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001B6E6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001B6E6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001B840]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001B840.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001CEC1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001CEC1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001D3A8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001D3A8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001E161]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001E161.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001E60E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001E60E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001EB90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001EB90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001EF0A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c001EF0A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c001FEA7]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c001FEA7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0020A78]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0020A78.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0021000]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0021000.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0021100]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0021100.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00234A6]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00234A6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0024524]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0024524.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0025244]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0025244.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00257E0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00257E0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026753]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026753.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026BEE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026BEE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026C40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026C40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026D40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026D40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0026F08]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0026F08.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00271A4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00271A4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0027E24]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0027E24.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0028E01]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0028E01.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0029614]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0029614.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002A068]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c002A068.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002B02E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002B02E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002B4E8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002B4E8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002B97E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002B97E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002C6D3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002C6D3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002D09]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002D09.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002D5B9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002D5B9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002D905]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002D905.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002E172]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002E172.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002E46C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002E46C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002E992]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002E992.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002ECDE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002ECDE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002EF10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002EF10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002F5B0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002F5B0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002FA5E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002FA5E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002FB22]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002FB22.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c002FF10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c002FF10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00306EC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00306EC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0031D4E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0031D4E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003201]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003201.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0032290]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0032290.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0032638]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0032638.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0032D1A]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0032D1A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0034066]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0034066.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0034545]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0034545.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0034D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0034D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0035FE8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0035FE8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003664E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003664E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003678C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003678C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003686C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003686C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0037729]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0037729.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0038867]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0038867.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0038CD8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0038CD8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003A264]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003A264.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003A7A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003A7A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003A91E]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c003A91E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003B3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003B3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003B69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003B69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003B70]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003B70.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003BD69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003BD69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003C6F4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003C6F4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003D4F1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003D4F1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003F622]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003F622.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003F686]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003F686.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c003FF90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c003FF90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0040]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0040.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00402B1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00402B1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00404DA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00404DA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0041272]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0041272.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0043F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0043F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00448C8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00448C8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00448C9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00448C9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0045122]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0045122.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0045734]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0045734.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00458C9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00458C9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00461C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00461C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0046745]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0046745.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0046A18]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0046A18.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004742E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004742E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004785A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004785A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00481BF]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00481BF.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00485CE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00485CE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004861E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004861E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0048661]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0048661.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0048B90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0048B90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0049628]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0049628.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0049789]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0049789.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00499FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00499FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0049F3F]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0049F3F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004A821]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c004A821.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004B1D1]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c004B1D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004B80C]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c004B80C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004C024]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004C024.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004C09]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004C09.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004C470]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004C470.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004CB82]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004CB82.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004EC38]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004EC38.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c004F23F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c004F23F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005012D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005012D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0050714]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0050714.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0051284]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0051284.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0051BE7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0051BE7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0052536]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0052536.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00527C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00527C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0053900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0053900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0053DE4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0053DE4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00541F8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00541F8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0054804]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0054804.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0054874]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0054874.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00556FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00556FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005692]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005692.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00570D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00570D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0058119]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0058119.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0059211]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0059211.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00593D2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00593D2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005ACF8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005ACF8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005AEE4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005AEE4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005B7C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005B7C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005C0CC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005C0CC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005C6E3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005C6E3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005CA38]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005CA38.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005CCE0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005CCE0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005CE0C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005CE0C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005D10B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005D10B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005D19D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005D19D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005D5E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005D5E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E0F4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E0F4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E1AC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E1AC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E518]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E518.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005E845]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005E845.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005EE1E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005EE1E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005F5C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005F5C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c005FC90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c005FC90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00614E4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00614E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00616C6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00616C6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0061C3E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0061C3E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0062524]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0062524.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00629CB]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00629CB.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064100]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0064100.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064474]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0064474.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006455C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006455C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064A9]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0064A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0064FBA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0064FBA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0065D9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0065D9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0065FE1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0065FE1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006623E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006623E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0066DFA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0066DFA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006776C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006776C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0067853]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0067853.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0067F03]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0067F03.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00684A8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00684A8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0068790]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0068790.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00690B1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00690B1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00696F2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00696F2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0069A40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0069A40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0069A79]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0069A79.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0069BA5]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0069BA5.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006A10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006A10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006A704]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006A704.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006A900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006A900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006AF7E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006AF7E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C032]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C032.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C225]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C225.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C27C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C27C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006C29C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006C29C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006D885]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006D885.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006DCEA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006DCEA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006EB82]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006EB82.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006FB10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006FB10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006FBC2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006FBC2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c006FEC2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c006FEC2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0071E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0071E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0074069]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0074069.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0075413]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0075413.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0076600]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0076600.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00769C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00769C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0076EA4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0076EA4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0076F90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0076F90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0077DF6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0077DF6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0078ADC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0078ADC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0079040]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0079040.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007959E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007959E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A30A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A30A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A62E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A62E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A813]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A813.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007A841]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007A841.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007D69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007D69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007EB24]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007EB24.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007F28E]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c007F28E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c007FBCD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c007FBCD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0080FC0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0080FC0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00817D8]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00817D8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0082896]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0082896.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0082E96]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0082E96.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00838B9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00838B9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0083F05]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0083F05.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008400]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008400.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008441D]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c008441D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0084721]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0084721.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0084D29]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0084D29.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0087A24]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0087A24.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0088108]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0088108.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0088840]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0088840.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0088F00]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0088F00.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0089246]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0089246.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0089564]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0089564.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008AEBC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008AEBC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008B39C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008B39C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008B69D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008B69D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008BC34]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008BC34.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008C347]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c008C347.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008CFBD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008CFBD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008D190]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008D190.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c008FE9E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c008FE9E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090691]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0090691.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0090900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090CBC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0090CBC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0090FA4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0090FA4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0091529]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0091529.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00924B6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00924B6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0093B7A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0093B7A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0094570]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0094570.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00959BA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00959BA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0095C7B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0095C7B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0095EE4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0095EE4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0096316]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0096316.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0096F5A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0096F5A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009776E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009776E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009799]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009799.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009831B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009831B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0098C20]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c0098C20.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0098E40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0098E40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0098F64]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0098F64.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00991D4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00991D4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009948D]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009948D.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c0099E06]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c0099E06.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009A4DA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009A4DA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009BAC4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009BAC4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009BCF2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009BCF2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009CE90]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009CE90.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009D1DC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009D1DC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009D9A3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009D9A3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009EC32]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009EC32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009EDB0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009EDB0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009EDC4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009EDC4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c009FDA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c009FDA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A108B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A108B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A20E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A20E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A2E1A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A2E1A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A3590]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A3590.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A3B32]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00A3B32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A4142]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A4142.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A45AE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A45AE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A4706]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A4706.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A4986]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A4986.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A646F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A646F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A6900]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A6900.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A71E2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A71E2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A7982]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00A7982.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A7BE0]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00A7BE0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A7F02]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A7F02.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A92CE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A92CE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00A9E2C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00A9E2C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AA4DA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AA4DA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AA5AE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AA5AE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AB240]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AB240.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AC40]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AC40.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AD511]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AD511.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AE259]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00AE259.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00AFC72]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00AFC72.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B0C22]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B0C22.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B0F41]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B0F41.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B1EC8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B1EC8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B2195]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B2195.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B236]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B236.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B31E2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B31E2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B4450]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B4450.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B45A4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B45A4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B4D98]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B4D98.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B5024]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B5024.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B5840]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B5840.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B5C69]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B5C69.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B707C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B707C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B70FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00B70FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00B97AD]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00B97AD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BAB8E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BAB8E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BB3A0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BB3A0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BB63A]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BB63A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BBB32]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BBB32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC0B4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC0B4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC18B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC18B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC3C7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC3C7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BC867]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BC867.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BCC22]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BCC22.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BDB3A]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BDB3A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BDC7C]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BDC7C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BDDB]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BDDB.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BEC31]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BEC31.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BEE09]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00BEE09.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BEE94]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BEE94.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BF021]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BF021.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00BF8D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00BF8D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C0090]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C0090.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C00B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C00B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C0386]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C0386.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C2652]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C2652.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C2D10]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C2D10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C39E7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C39E7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C3DC9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C3DC9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C4DA9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C4DA9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C66F6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C66F6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C67A1]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C67A1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C7440]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C7440.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C781E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C781E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C78E9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C78E9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C7B88]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00C7B88.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C7D52]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C7D52.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C9788]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C9788.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00C9A91]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00C9A91.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CA532]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CA532.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CA5AC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CA5AC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CA8E7]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CA8E7.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CACA9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CACA9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB0B4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB0B4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB411]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB411.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB729]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB729.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CB9CD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CB9CD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CBACC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CBACC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CBC8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CBC8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CCD31]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CCD31.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CDE41]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CDE41.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00CF735]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00CF735.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D0876]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D0876.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D16D1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D16D1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D29B0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D29B0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D2FD6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D2FD6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D37D5]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D37D5.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D3CBA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D3CBA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D4F96]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D4F96.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D766B]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D766B.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D7AB8]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D7AB8.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D88FE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D88FE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D8B63]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D8B63.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D9108]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D9108.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00D9280]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00D9280.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DBA84]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00DBA84.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DBE2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DBE2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DC04]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DC04.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DC571]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DC571.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DCE03]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00DCE03.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD072]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD072.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD308]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD308.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD413]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD413.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD8FA]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD8FA.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DD9A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DD9A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DDC81]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DDC81.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DE588]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DE588.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00DE9A9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00DE9A9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E0C10]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E0C10.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E0F32]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E0F32.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E1690]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E1690.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E216E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E216E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E401A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E401A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E64D0]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E64D0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E6536]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E6536.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E66A0]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00E66A0.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E7136]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E7136.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E75C4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E75C4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E7A78]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E7A78.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00E7CC6]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00E7CC6.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EA144]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EA144.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EA445]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EA445.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EA89E]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EA89E.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EAD80]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EAD80.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EBBE3]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00EBBE3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EBFBE]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EBFBE.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00ED939]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00ED939.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EE456]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EE456.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EF0D2]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EF0D2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00EF46A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00EF46A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F05B3]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F05B3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F0874]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F0874.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F10B9]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F10B9.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F165A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F165A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F228F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F228F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F2400]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F2400.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F28E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F28E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F29D2]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F29D2.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F2AAF]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F2AAF.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F3A56]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F3A56.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F4126]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F4126.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F63B1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F63B1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F6464]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F6464.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F6C3A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F6C3A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F7FB4]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F7FB4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F7FF3]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F7FF3.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F846]
--ahs---- 2008-11-20 08:58 20992 c:\users\da flute\AppData\Roaming\c00F846.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F91AD]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F91AD.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00F990F]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00F990F.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FA3E4]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FA3E4.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FA7A1]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FA7A1.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FB852]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FB852.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FB85A]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FB85A.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FC583]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FC583.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FCFDC]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FCFDC.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FDA2C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FDA2C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c00FDD6C]
--ahs---- 2008-11-20 08:02 20992 c:\users\da flute\AppData\Roaming\c00FDD6C.mat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E13B20E4-803B-491E-8A42-379E05A6D7BD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5AC6B7EB-6F12-4ED5-9867-48FF05758BB0}"= UDP:c:\program files\eMule\emule.exe:eMule
"{21446F4E-2F39-494C-B98A-741B0EB42815}"= TCP:c:\program files\eMule\emule.exe:eMule
"{3705BCE4-12D2-42CA-B40E-1CB8A80163DB}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{CDF77771-6C11-4F4D-A848-ECEDA7422CAE}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C0EB7E8D-57D8-412F-9D9C-5E9E4D7BB7BC}"= UDP:c:\program files\Codemasters\Le Seigneur des anneaux Online\lotroclient.exe:lotroclient
"{ACE42427-6AB7-44C2-AB45-A563B21B627C}"= TCP:c:\program files\Codemasters\Le Seigneur des anneaux Online\lotroclient.exe:lotroclient
"{09D1076A-1F05-4974-97EA-662312D682D0}"= UDP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineInvoker.exe:TurbineInvoker
"{D9EDD5D7-CC67-4D6E-9CEE-23F1E345A5C8}"= TCP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineInvoker.exe:TurbineInvoker
"{A362C5A7-6413-447E-90EA-38A7E7C3C059}"= Disabled:UDP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineLauncher.exe:TurbineLauncher
"{9BE5508B-0878-4FDC-9387-58DFEACAFFF6}"= Disabled:TCP:c:\program files\Codemasters\Le Seigneur des anneaux Online\TurbineLauncher.exe:TurbineLauncher
"{15E0727D-4C7E-41E9-9693-C3A972701D85}"= UDP:4662:emule
"{94B89F3E-D61B-42EE-AF6E-1084A6A12664}"= TCP:4672:emule
"TCP Query User{469E37F9-F0B4-4CEA-894D-02B64C5C439B}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{1FA9A288-68EF-4217-A184-F0AD2195A825}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{8D99EFC1-401E-43FA-910E-AEC4CC8B0F7B}c:\\users\\da flute\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\da flute\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{7DC14EDD-7E89-4453-9B61-939C4BCF0171}c:\\users\\da flute\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\da flute\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"{72BB0C5A-4B62-44AC-B448-E0858DFCF1E6}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{A527629A-444D-4CA1-968B-EB1DE172D405}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{03170058-34B5-40C8-802E-D02D9A0447D8}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
"{F140E44E-F93F-4C97-BEFE-94E43026DE3A}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
"{D84327D3-3DDF-48B3-93F3-7F973AEC82FE}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{E8BCF5F6-2ADC-450E-88ED-E66FC9918CCC}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{225D501F-332A-422C-8F78-B9C48E5E12EB}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{4320DF04-CD75-45B6-A37B-F5DDD56F8C78}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{EAAD8D78-4407-4849-8F4F-3BC859A7875E}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{5A439AB8-2812-47E2-985F-F6081D48A8A0}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{53777DB8-90AB-4A2C-9E12-0F3B196F0617}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 AtiPcie;ATI PCI Express (3GIO) Filter;c:\windows\system32\DRIVERS\AtiPcie.sys [2007-08-29 7680]
R0 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
R1 IDSvix86;Symantec Intrusion Prevention Driver;\??\c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20081120.001\IDSvix86.sys [2008-11-21 270384]
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-02-08 149352]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2007-08-29 2600960]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 41008]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2007-05-29 23888]

*Newly Created Service* - ERASERUTILDRVI7
.
Contenu du dossier 'Tâches planifiées'

2008-11-17 c:\windows\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - da flute.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-26 18:19]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-21 18:33:40
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
Heure de fin: 2008-11-21 18:35:17
ComboFix-quarantined-files.txt 2008-11-21 17:35:12
ComboFix2.txt 2008-11-21 14:59:41

Avant-CF: 44 403 089 408 octets libres
Après-CF: 44,263,227,392 octets libres

1103 --- E O F --- 2008-11-18 08:12:53
Verrouillé