Bonjour,
Voilà le rapport complet de mon problème, et les rapports des programes que vous m'avez dit de lancer:
j'ai un problème avec windows live messenger, enffet, mon adresse envoi à tous mes contact des différents sites internet, et même quand je suis deconnecté de windows live (ordinateur eteind aussi) mon adresse se connecte toute seule en envoyant à mes contacts des différents sites internet. Et en plus de ça, depuis que j'ai créer mon compte windows live je me connecte à chaque fois sur mon adresse sans problème, mais pour ce qui concerne ma boite email je l'ai jamais ouvert, et elle n'est toujours pas activer, et il y a 2 jours j'ai essayé de rentré et elle m'a demander de l'activer, et là la page d'internet explorer 8 se charge jusqu'au bout mais elle reste toute blanche, j'ai essayé même de la laissé très lentemps pour qu'elle puisse s'affiché à son aise, et je jette de temps en temps un coût d'oeil, mais toujours pas moyen, elle ne s'active pas (j'en sais même pas y accéder).J'ai un antivirus avast avec clé valide, j'ai fait une analyse, rien à trouvé, j'ai installer antispyrware, j'ai fait une analyse, rien à trouvé, j'ai installé antimalwaresbytes, j'ai fairt une analyse, rien à trouvé. l'odinateur est en ordre toutes les mises à jours ont été instalé correctment, j'ai fait une analyse avec windows defender, rien à trouvé, j'ai installé une mise à jour de Oncare scanner pour windows live, le problème y est encore, j'ai lancé GenProc qui m'a donné ce rapport:
Rapport GenProc 2.584 [1]
@ 12/06/2009 à 21:24:10
@ Windows Vista Service Pack 2 - Mode normal
# Etape 1/ Télécharge :
- CCleaner http://www.ccleaner.com/download/builds/downloading-slim (FileHippo). Ce logiciel va permettre de supprimer tous les fichiers temporaires. Lance-le et clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. Ferme le programme.
- rustbfix http://uploads.ejvindh.andymanchesta.com/RustbFix.exe ( (ejvindh) et sauvegarde-le sur ton Bureau.
- Double clique sur rustbfix.exe afin de lancer l'outil.
- Si une infection Rustock.b est détectée, une invite t'indiquera qu'il est nécessaire de redémarrer l'ordi.
- Ce redémarrage pourrait être plus long que d'habitude, et il est possible que deux redémarrages soient requis. Tout cela se fera automatiquement.
- Suite au(x) redémarrage(s), deux rapports s'ouvriront : (C:\avenger.txt & C:\rustbfix\pelog.txt).
- Poste le contenu de ces deux rapports, ainsi qu'un rapport HijackThis http://tinyurl.com/GenProc-HijackThis
----------------------------------------------------------------------
~~ Arguments de la procédure ~~
# Détections [1] GenProc 2.584 12/06/2009 à 21:24:41
Rustock: le 12/06/2009 à 21:24:42 "pe386" present
~~ Fin à 21:24:42 ~~
J’ai lancé rustbfix qui m’a donné ce rapport:
************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************
13/06/2009 15:42:47,02
No Rustock.b-rootkits found
******************************* End of Logfile ********************************
J'ai lancé hijackthis qui m'a donné ce rapport:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:46:00, on 13/06/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\System32\notepad.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vb32&d=0209&m=aspire_6530
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/firefox?client=firefox-a&rls=org.mozilla:fr:official
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vb32&d=0209&m=aspire_6530
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
F2 - REG:system.ini: UserInit=Userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Orion.lnk = C:\Program Files\Convesoft\Orion\Messenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O13 - Gopher Prefix:
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTRConnect (ntrconnect) - NTRglobal - C:\Program Files\NTR global\NTRconnect\NTRconnect.exe
J’ai désactiver le contrôle des comptes d’utilisateur, et j’ai redémarrer le PC, puis, j’ai executer chacun de ces programmes ci-dessous en tant qu’administrateur:
J’ai lance Ad-Remover qui m’a donné qui m’a donné 2 rapport, 1 pour le scan, et un pour le nettoyage,
Pour le scan :
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_J | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 14/06/2009 à 10:30 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 20:20:13, 17/06/2009 | Mode Normal | Option: SCAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows Vista™ Home Basic Service Pack 2 v6.0.6002
Nom du PC: PC-DE-MIMOUN | Utilisateur actuel: mimoun
.
Administrateur: Administrateur *Desactive*
N'est pas administrateur: Invité *Desactive*
Administrateur: mimoun
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
HKCR\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
HKCR\MediaPlayer.GraphicsUtils
HKCR\MediaPlayer.GraphicsUtils.1
HKCR\MgMediaPlayer.GifAnimator
HKCR\MgMediaPlayer.GifAnimator.1
HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKCU\Software\SweetIM
HKLM\Software\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
HKLM\Software\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
HKLM\Software\Classes\MediaPlayer.GraphicsUtils
HKLM\Software\Classes\MediaPlayer.GraphicsUtils.1
HKLM\Software\Classes\MgMediaPlayer.GifAnimator
HKLM\Software\Classes\MgMediaPlayer.GifAnimator.1
HKLM\Software\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
HKLM\Software\SweetIM
HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\Registry\User\S-1-5-21-1296028825-2768064146-476506390-1000\Software\Sweetim
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Sweetim
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\PROGRA~2\SweetIM
C:\ProgramData\SweetIM
C:\Program Files\SweetIM
C:\Windows\Installer\12e8d66.msi
.
============== Scan additionnel ==============
.
.
.
* Internet Explorer Version 8.0.6001.18783 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vb32&d=0209&m=aspire_6530
Default_Search_URL: hxxp://fr.gdark.com
Start Page: hxxp://www.google.fr/firefox?client=firefox-a&rls=org.mozilla
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vb32&d=0209&m=aspire_6530
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://fr.gdark.com
Start Page: hxxp://fr.gdark.com
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
+---------------------------------------------------------------------------+
7609 Octet(s) - C:\Ad-Report-SCAN.log
1 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
Fin à: 20:31:26 | 17/06/2009
.
============== E.O.F ==============
.
Pour le nettoyage
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_J | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 14/06/2009 à 10:30 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 21:03:11, 17/06/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows Vista™ Home Basic Service Pack 2 v6.0.6002
Nom du PC: PC-DE-MIMOUN | Utilisateur actuel: mimoun
.
Administrateur: Administrateur *Desactive*
N'est pas administrateur: Invité *Desactive*
Administrateur: mimoun
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
HKCR\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
HKCR\MediaPlayer.GraphicsUtils
HKCR\MediaPlayer.GraphicsUtils.1
HKCR\MgMediaPlayer.GifAnimator
HKCR\MgMediaPlayer.GifAnimator.1
HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKCU\Software\SweetIM
HKLM\Software\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
HKLM\Software\SweetIM
HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\Registry\User\S-1-5-21-1296028825-2768064146-476506390-1000\Software\Sweetim
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Sweetim
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
C:\PROGRA~2\SweetIM\Messenger
C:\PROGRA~2\SweetIM\Messenger\conf
C:\PROGRA~2\SweetIM\Messenger\data
C:\PROGRA~2\SweetIM\Messenger\logs
C:\PROGRA~2\SweetIM\Messenger\update
C:\PROGRA~2\SweetIM\Messenger\conf\adapter.xml
C:\PROGRA~2\SweetIM\Messenger\conf\autoupdate.xml
C:\PROGRA~2\SweetIM\Messenger\conf\logger.xml
C:\PROGRA~2\SweetIM\Messenger\conf\messages.xml
C:\PROGRA~2\SweetIM\Messenger\conf\sweetim.xml
C:\PROGRA~2\SweetIM\Messenger\conf\sweetimapp.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users
C:\PROGRA~2\SweetIM\Messenger\conf\users\btissamdu26@hotmail.fr
C:\PROGRA~2\SweetIM\Messenger\conf\users\main_user_config.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\sarahlabrunedu13@hotmail.fr
C:\PROGRA~2\SweetIM\Messenger\conf\users\xx-miss-07@hotmail.fr
C:\PROGRA~2\SweetIM\Messenger\conf\users\zinadu26@hotmail.fr
C:\PROGRA~2\SweetIM\Messenger\conf\users\btissamdu26@hotmail.fr\content_update_notification.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\btissamdu26@hotmail.fr\emoticons_shortcut.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\btissamdu26@hotmail.fr\user_config.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\sarahlabrunedu13@hotmail.fr\content_update_notification.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\sarahlabrunedu13@hotmail.fr\emoticons_shortcut.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\sarahlabrunedu13@hotmail.fr\user_config.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\xx-miss-07@hotmail.fr\content_update_notification.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\xx-miss-07@hotmail.fr\emoticons_shortcut.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\xx-miss-07@hotmail.fr\lastuse_Audibles.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\xx-miss-07@hotmail.fr\lastuse_Emoticons.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\xx-miss-07@hotmail.fr\lastuse_Winks.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\xx-miss-07@hotmail.fr\user_config.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\zinadu26@hotmail.fr\content_update_notification.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\zinadu26@hotmail.fr\emoticons_shortcut.xml
C:\PROGRA~2\SweetIM\Messenger\conf\users\zinadu26@hotmail.fr\user_config.xml
C:\PROGRA~2\SweetIM\Messenger\data\contentdb
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00010859.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\0001085D.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00010896.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\0001089A.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000108A9.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000108AA.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000108C4.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\0001092C.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00010952.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00010954.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00010968.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00010970.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00010981.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\0002006E.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00020073.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00020076.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\0002016A.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000201C5.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00020344.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\0003009A.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000300A1.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000300D7.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00050005.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000600B2.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000601B9.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00060299.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000602E7.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\0008000D.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00080011.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00080017.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00080027.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\00080040.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000800D0.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000800D9.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000800ED.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\000800EF.dat
C:\PROGRA~2\SweetIM\Messenger\data\contentdb\cache_indx.dat
C:\PROGRA~2\SweetIM
C:\Program Files\SweetIM\Messenger
C:\Program Files\SweetIM\Toolbars
C:\Program Files\SweetIM\Messenger\default.xml
C:\Program Files\SweetIM\Messenger\mgAdaptersProxy.dll
C:\Program Files\SweetIM\Messenger\mgAIMAuto.dll
C:\Program Files\SweetIM\Messenger\mgAIMMessengerAdapter.dll
C:\Program Files\SweetIM\Messenger\mgArchive.dll
C:\Program Files\SweetIM\Messenger\mgcommon.dll
C:\Program Files\SweetIM\Messenger\mgcommunication.dll
C:\Program Files\SweetIM\Messenger\mgconfig.dll
C:\Program Files\SweetIM\Messenger\mgFlashPlayer.dll
C:\Program Files\SweetIM\Messenger\mghooking.dll
C:\Program Files\SweetIM\Messenger\mgICQAuto.dll
C:\Program Files\SweetIM\Messenger\mgICQMessengerAdapter.dll
C:\Program Files\SweetIM\Messenger\mgIEPlayer.dll
C:\Program Files\SweetIM\Messenger\mglogger.dll
C:\Program Files\SweetIM\Messenger\mgMediaPlayer.dll
C:\Program Files\SweetIM\Messenger\mgMsnAuto.dll
C:\Program Files\SweetIM\Messenger\mgMsnMessengerAdapter.dll
C:\Program Files\SweetIM\Messenger\mgsimcommon.dll
C:\Program Files\SweetIM\Messenger\mgSweetIM.dll
C:\Program Files\SweetIM\Messenger\mgUpdateSupport.dll
C:\Program Files\SweetIM\Messenger\mgxml_wrapper.dll
C:\Program Files\SweetIM\Messenger\mgYahooAuto.dll
C:\Program Files\SweetIM\Messenger\mgYahooMessengerAdapter.dll
C:\Program Files\SweetIM\Messenger\msvcp71.dll
C:\Program Files\SweetIM\Messenger\msvcr71.dll
C:\Program Files\SweetIM\Messenger\resources
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\SweetIM\Messenger\resources\images
C:\Program Files\SweetIM\Messenger\resources\images\AudibleButton.png
C:\Program Files\SweetIM\Messenger\resources\images\DisplayPicturesButton.png
C:\Program Files\SweetIM\Messenger\resources\images\EmoticonButton.png
C:\Program Files\SweetIM\Messenger\resources\images\NudgeButton.png
C:\Program Files\SweetIM\Messenger\resources\images\SoundFxButton.png
C:\Program Files\SweetIM\Messenger\resources\images\WinksButton.png
C:\Program Files\SweetIM\Toolbars\Internet Explorer
C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources
C:\Program Files\SweetIM
C:\Windows\Installer\12e8d66.msi
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
.
.
* Internet Explorer Version 8.0.6001.18783 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
+---------------------------------------------------------------------------+
13928 Octet(s) - C:\Ad-Report-CLEAN.log
7831 Octet(s) - C:\Ad-Report-SCAN.log
20 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
27 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
Fin à: 21:07:34 | 17/06/2009
.
============== E.O.F ==============
.
J’ai passé Msnfix en suivant bien la procédure de 1 à Z, et qui ne m’a donné aucun rapport après le redémarrage, ni enregistrer sous le dossier msnfix sous forme date et heur.
J’ai fait un Resit qui m’a denné 2 rapport :
Un est nommé Resit Log:
Logfile of random's system information tool 1.06 (written by random/random)
Run by mimoun at 2009-06-17 20:06:38
Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 2
System drive C: has 78 GB (69%) free of 113 GB
Total RAM: 2814 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:06:43, on 17/06/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\notepad.exe
C:\Program Files\Windows Live\Messenger\msvs.exe
C:\Users\mimoun\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\mimoun.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vb32&d=0209&m=aspire_6530
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/firefox?client=firefox-a&rls=org.mozilla:fr:official
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vb32&d=0209&m=aspire_6530
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O13 - Gopher Prefix:
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTRConnect (ntrconnect) - NTRglobal - C:\Program Files\NTR global\NTRconnect\NTRconnect.exe
End of file - 5578 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-07-29 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-07-29 142896]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1049896]
"LManager"=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [2008-06-17 817672]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-05-20 111928]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=~C:\Program Files\Windows Live\Messenger\msnmsgr.exe /background []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ntrconnect]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{580670c3-382f-11de-a135-00238b74db36}]
shell\AutoRun\command - 1nkbd8h.bat
shell\explore\command - 1nkbd8h.bat
shell\open\command - 1nkbd8h.bat
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2009-06-17 20:06:38 ----D---- C:\rsit
2009-06-17 20:06:38 ----D---- \rsit
2009-06-17 14:00:41 ----D---- C:\Program Files\Common Files\SWF Studio
2009-06-15 00:16:21 ----A---- C:\Windows\msnfix.txt
2009-06-13 22:43:41 ----D---- C:\Program Files\Trend Micro
2009-06-13 15:42:46 ----D---- C:\Rustbfix
2009-06-13 15:42:46 ----D---- \Rustbfix
2009-06-13 15:38:50 ----D---- C:\Program Files\CCleaner
2009-06-12 22:21:14 ----D---- C:\Program Files\SweetIM
2009-06-12 21:22:25 ----D---- C:\Program Files\IZArc
2009-06-11 21:33:49 ----A---- C:\Windows\system32\localspl.dll
2009-06-11 21:33:46 ----A---- C:\Windows\system32\mshtml.dll
2009-06-11 21:33:45 ----A---- C:\Windows\system32\iertutil.dll
2009-06-11 21:33:45 ----A---- C:\Windows\system32\ieframe.dll
2009-06-11 21:33:44 ----A---- C:\Windows\system32\wininet.dll
2009-06-11 21:33:44 ----A---- C:\Windows\system32\urlmon.dll
2009-06-11 21:33:44 ----A---- C:\Windows\system32\iedkcs32.dll
2009-06-11 21:33:43 ----A---- C:\Windows\system32\jsproxy.dll
2009-06-11 21:33:43 ----A---- C:\Windows\system32\ieui.dll
2009-06-11 21:33:43 ----A---- C:\Windows\system32\iesetup.dll
2009-06-11 21:33:43 ----A---- C:\Windows\system32\iernonce.dll
2009-06-11 21:33:43 ----A---- C:\Windows\system32\ie4uinit.exe
2009-06-11 21:33:29 ----A---- C:\Windows\system32\rpcrt4.dll
2009-06-10 16:45:58 ----D---- C:\ProgramData\Friends Games
2009-06-08 00:32:40 ----D---- C:\ProgramData\SweetIM
2009-06-08 00:26:48 ----D---- C:\Program Files\Windows Live Safety Center
2009-06-05 18:55:51 ----D---- C:\ProgramData\Malwarebytes
2009-06-05 18:38:33 ----D---- C:\ProgramData\Arovax
2009-06-05 15:45:28 ----D---- C:\Windows\system32\eu-ES
2009-06-05 15:45:28 ----D---- C:\Windows\system32\ca-ES
2009-06-05 15:45:27 ----D---- C:\Windows\system32\vi-VN
2009-06-05 15:35:08 ----D---- C:\Windows\system32\EventProviders
2009-06-05 15:33:45 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-06-05 15:33:41 ----A---- C:\Windows\system32\SLsvc.exe
2009-06-05 15:33:41 ----A---- C:\Windows\system32\SLCExt.dll
2009-06-05 15:33:39 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-06-05 15:33:39 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-06-05 15:33:38 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-06-05 15:33:37 ----A---- C:\Windows\system32\mssrch.dll
2009-06-05 15:33:34 ----A---- C:\Windows\system32\tquery.dll
2009-06-05 15:33:33 ----A---- C:\Windows\system32\RMActivate_isv.exe
2009-06-05 15:33:33 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-06-05 15:33:33 ----A---- C:\Windows\system32\lsasrv.dll
2009-06-05 15:33:32 ----A---- C:\Windows\system32\scavenge.dll
2009-06-05 15:33:32 ----A---- C:\Windows\system32\RMActivate.exe
2009-06-05 15:33:31 ----A---- C:\Windows\system32\msi.dll
2009-06-05 15:33:30 ----A---- C:\Windows\system32\WscEapPr.dll
2009-06-05 15:33:30 ----A---- C:\Windows\system32\secproc_isv.dll
2009-06-05 15:33:30 ----A---- C:\Windows\system32\imapi2fs.dll
2009-06-05 15:33:29 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-06-05 15:33:29 ----A---- C:\Windows\system32\sysmain.dll
2009-06-05 15:33:28 ----A---- C:\Windows\system32\icardagt.exe
2009-06-05 15:33:27 ----A---- C:\Windows\system32\mf.dll
2009-06-05 15:33:27 ----A---- C:\Windows\system32\EhStorShell.dll
2009-06-05 15:33:26 ----A---- C:\Windows\system32\spreview.exe
2009-06-05 15:33:26 ----A---- C:\Windows\system32\spinstall.exe
2009-06-05 15:33:25 ----A---- C:\Windows\system32\spwizui.dll
2009-06-05 15:33:25 ----A---- C:\Windows\system32\drmv2clt.dll
2009-06-05 15:33:24 ----A---- C:\Windows\system32\shell32.dll
2009-06-05 15:33:24 ----A---- C:\Windows\system32\secproc.dll
2009-06-05 15:33:24 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-06-05 15:33:23 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-06-05 15:33:23 ----A---- C:\Windows\system32\p2psvc.dll
2009-06-05 15:33:23 ----A---- C:\Windows\system32\mssvp.dll
2009-06-05 15:33:23 ----A---- C:\Windows\system32\mssphtb.dll
2009-06-05 15:33:23 ----A---- C:\Windows\system32\mscoree.dll
2009-06-05 15:33:22 ----A---- C:\Windows\system32\mssph.dll
2009-06-05 15:33:22 ----A---- C:\Windows\system32\imapi2.dll
2009-06-05 15:33:21 ----A---- C:\Windows\system32\sdohlp.dll
2009-06-05 15:33:21 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-06-05 15:33:21 ----A---- C:\Windows\system32\esent.dll
2009-06-05 15:33:20 ----A---- C:\Windows\system32\sperror.dll
2009-06-05 15:33:20 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2009-06-05 15:33:20 ----A---- C:\Windows\system32\IMJP10K.DLL
2009-06-05 15:33:20 ----A---- C:\Windows\system32\DevicePairing.dll
2009-06-05 15:33:19 ----A---- C:\Windows\system32\wevtsvc.dll
2009-06-05 15:33:19 ----A---- C:\Windows\system32\SLC.dll
2009-06-05 15:33:19 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-06-05 15:33:19 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-06-05 15:33:19 ----A---- C:\Windows\system32\korwbrkr.dll
2009-06-05 15:33:19 ----A---- C:\Windows\system32\IasMigReader.exe
2009-06-05 15:33:18 ----A---- C:\Windows\system32\wmp.dll
2009-06-05 15:33:18 ----A---- C:\Windows\system32\msshsq.dll
2009-06-05 15:33:17 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-06-05 15:33:17 ----A---- C:\Windows\system32\msjet40.dll
2009-06-05 15:33:17 ----A---- C:\Windows\system32\MPSSVC.dll
2009-06-05 15:33:16 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-06-05 15:33:16 ----A---- C:\Windows\system32\msxml6.dll
2009-06-05 15:33:15 ----A---- C:\Windows\system32\Query.dll
2009-06-05 15:33:15 ----A---- C:\Windows\system32\qmgr.dll
2009-06-05 15:33:15 ----A---- C:\Windows\system32\P2PGraph.dll
2009-06-05 15:33:15 ----A---- C:\Windows\system32\msexch40.dll
2009-06-05 15:33:15 ----A---- C:\Windows\system32\diagperf.dll
2009-06-05 15:33:14 ----A---- C:\Windows\system32\srchadmin.dll
2009-06-05 15:33:14 ----A---- C:\Windows\system32\ole32.dll
2009-06-05 15:33:14 ----A---- C:\Windows\system32\ntdll.dll
2009-06-05 15:33:14 ----A---- C:\Windows\system32\msxml3.dll
2009-06-05 15:33:13 ----A---- C:\Windows\system32\winload.exe
2009-06-05 15:33:13 ----A---- C:\Windows\system32\uDWM.dll
2009-06-05 15:33:13 ----A---- C:\Windows\system32\mmc.exe
2009-06-05 15:33:13 ----A---- C:\Windows\system32\mblctr.exe
2009-06-05 15:33:13 ----A---- C:\Windows\system32\EncDec.dll
2009-06-05 15:33:13 ----A---- C:\Windows\system32\dfsr.exe
2009-06-05 15:33:12 ----A---- C:\Windows\system32\riched20.dll
2009-06-05 15:33:12 ----A---- C:\Windows\system32\RacEngn.dll
2009-06-05 15:33:12 ----A---- C:\Windows\system32\IasMigPlugin.dll
2009-06-05 15:33:12 ----A---- C:\Windows\system32\fdBth.dll
2009-06-05 15:33:11 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-06-05 15:33:11 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-06-05 15:33:11 ----A---- C:\Windows\system32\milcore.dll
2009-06-05 15:33:11 ----A---- C:\Windows\system32\kernel32.dll
2009-06-05 15:33:10 ----A---- C:\Windows\system32\spoolss.dll
2009-06-05 15:33:10 ----A---- C:\Windows\system32\schedsvc.dll
2009-06-05 15:33:10 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-06-05 15:33:10 ----A---- C:\Windows\system32\EhStorAPI.dll
2009-06-05 15:33:10 ----A---- C:\Windows\system32\CertEnroll.dll
2009-06-05 15:33:09 ----A---- C:\Windows\system32\msjtes40.dll
2009-06-05 15:33:08 ----A---- C:\Windows\system32\WinSAT.exe
2009-06-05 15:33:08 ----A---- C:\Windows\system32\msvcp60.dll
2009-06-05 15:33:08 ----A---- C:\Windows\system32\infocardapi.dll
2009-06-05 15:33:08 ----A---- C:\Windows\system32\gpedit.dll
2009-06-05 15:33:08 ----A---- C:\Windows\system32\es.dll
2009-06-05 15:33:07 ----A---- C:\Windows\system32\WMPhoto.dll
2009-06-05 15:33:07 ----A---- C:\Windows\system32\WebClnt.dll
2009-06-05 15:33:07 ----A---- C:\Windows\system32\mstext40.dll
2009-06-05 15:33:07 ----A---- C:\Windows\system32\msexcl40.dll
2009-06-05 15:33:07 ----A---- C:\Windows\system32\Magnify.exe
2009-06-05 15:33:07 ----A---- C:\Windows\system32\advapi32.dll
2009-06-05 15:33:06 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2009-06-05 15:33:06 ----A---- C:\Windows\system32\vssapi.dll
2009-06-05 15:33:06 ----A---- C:\Windows\system32\slwmi.dll
2009-06-05 15:33:06 ----A---- C:\Windows\system32\msxbde40.dll
2009-06-05 15:33:06 ----A---- C:\Windows\system32\comsvcs.dll
2009-06-05 15:33:05 ----A---- C:\Windows\system32\PresentationHost.exe
2009-06-05 15:33:05 ----A---- C:\Windows\system32\mstscax.dll
2009-06-05 15:33:05 ----A---- C:\Windows\system32\msrepl40.dll
2009-06-05 15:33:05 ----A---- C:\Windows\system32\authui.dll
2009-06-05 15:33:04 ----A---- C:\Windows\system32\propsys.dll
2009-06-05 15:33:04 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-05 15:33:04 ----A---- C:\Windows\system32\newdev.dll
2009-06-05 15:33:04 ----A---- C:\Windows\system32\iasrecst.dll
2009-06-05 15:33:04 ----A---- C:\Windows\system32\gpsvc.dll
2009-06-05 15:33:04 ----A---- C:\Windows\system32\eudcedit.exe
2009-06-05 15:33:04 ----A---- C:\Windows\system32\crypt32.dll
2009-06-05 15:33:04 ----A---- C:\Windows\explorer.exe
2009-06-05 15:33:03 ----A---- C:\Windows\system32\setupapi.dll
2009-06-05 15:33:03 ----A---- C:\Windows\system32\rpcss.dll
2009-06-05 15:33:03 ----A---- C:\Windows\system32\mspbde40.dll
2009-06-05 15:33:03 ----A---- C:\Windows\system32\d3d9.dll
2009-06-05 15:33:02 ----A---- C:\Windows\system32\msltus40.dll
2009-06-05 15:33:02 ----A---- C:\Windows\system32\mfc42.dll
2009-06-05 15:33:02 ----A---- C:\Windows\system32\davclnt.dll
2009-06-05 15:33:01 ----A---- C:\Windows\system32\shlwapi.dll
2009-06-05 15:33:01 ----A---- C:\Windows\system32\msrd3x40.dll
2009-06-05 15:33:01 ----A---- C:\Windows\system32\msdtctm.dll
2009-06-05 15:33:01 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2009-06-05 15:33:01 ----A---- C:\Windows\system32\EhStorAuthn.dll
2009-06-05 15:33:01 ----A---- C:\Windows\system32\browseui.dll
2009-06-05 15:33:00 ----A---- C:\Windows\system32\wevtapi.dll
2009-06-05 15:33:00 ----A---- C:\Windows\system32\photowiz.dll
2009-06-05 15:33:00 ----A---- C:\Windows\system32\nlhtml.dll
2009-06-05 15:32:59 ----A---- C:\Windows\system32\win32spl.dll
2009-06-05 15:32:59 ----A---- C:\Windows\system32\user32.dll
2009-06-05 15:32:59 ----A---- C:\Windows\system32\samsrv.dll
2009-06-05 15:32:59 ----A---- C:\Windows\system32\quartz.dll
2009-06-05 15:32:59 ----A---- C:\Windows\system32\ci.dll
2009-06-05 15:32:58 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-06-05 15:32:58 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-06-05 15:32:58 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-06-05 15:32:58 ----A---- C:\Windows\system32\oleaut32.dll
2009-06-05 15:32:58 ----A---- C:\Windows\system32\msv1_0.dll
2009-06-05 15:32:58 ----A---- C:\Windows\system32\kerberos.dll
2009-06-05 15:32:58 ----A---- C:\Windows\system32\IKEEXT.DLL
2009-06-05 15:32:57 ----A---- C:\Windows\system32\winhttp.dll
2009-06-05 15:32:57 ----A---- C:\Windows\system32\netshell.dll
2009-06-05 15:32:57 ----A---- C:\Windows\system32\mswstr10.dll
2009-06-05 15:32:57 ----A---- C:\Windows\system32\compcln.exe
2009-06-05 15:32:57 ----A---- C:\Windows\system32\audiosrv.dll
2009-06-05 15:32:57 ----A---- C:\Windows\system32\apds.dll
2009-06-05 15:32:56 ----A---- C:\Windows\system32\xmlfilter.dll
2009-06-05 15:32:56 ----A---- C:\Windows\system32\VSSVC.exe
2009-06-05 15:32:56 ----A---- C:\Windows\system32\QAGENTRT.DLL
2009-06-05 15:32:56 ----A---- C:\Windows\system32\msvcrt.dll
2009-06-05 15:32:56 ----A---- C:\Windows\system32\msctf.dll
2009-06-05 15:32:56 ----A---- C:\Windows\system32\gdi32.dll
2009-06-05 15:32:56 ----A---- C:\Windows\system32\emdmgmt.dll
2009-06-05 15:32:55 ----A---- C:\Windows\system32\sqlsrv32.dll
2009-06-05 15:32:55 ----A---- C:\Windows\system32\SLUI.exe
2009-06-05 15:32:55 ----A---- C:\Windows\system32\msrd2x40.dll
2009-06-05 15:32:55 ----A---- C:\Windows\system32\mfc42u.dll
2009-06-05 15:32:55 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-06-05 15:32:55 ----A---- C:\Windows\system32\eapphost.dll
2009-06-05 15:32:54 ----A---- C:\Windows\system32\winresume.exe
2009-06-05 15:32:54 ----A---- C:\Windows\system32\propdefs.dll
2009-06-05 15:32:54 ----A---- C:\Windows\system32\odbc32.dll
2009-06-05 15:32:53 ----A---- C:\Windows\system32\wevtutil.exe
2009-06-05 15:32:53 ----A---- C:\Windows\system32\shdocvw.dll
2009-06-05 15:32:53 ----A---- C:\Windows\system32\mssitlb.dll
2009-06-05 15:32:53 ----A---- C:\Windows\system32\dbgeng.dll
2009-06-05 15:32:52 ----A---- C:\Windows\system32\WsmSvc.dll
2009-06-05 15:32:52 ----A---- C:\Windows\system32\swprv.dll
2009-06-05 15:32:52 ----A---- C:\Windows\system32\mmcndmgr.dll
2009-06-05 15:32:51 ----A---- C:\Windows\system32\vds.exe
2009-06-05 15:32:51 ----A---- C:\Windows\system32\usp10.dll
2009-06-05 15:32:51 ----A---- C:\Windows\system32\drvinst.exe
2009-06-05 15:32:50 ----A---- C:\Windows\system32\WSDApi.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\Wldap32.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\wcnwiz.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\schannel.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\netlogon.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\msscb.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\msctfp.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\evr.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\devmgr.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-06-05 15:32:50 ----A---- C:\Windows\system32\BFE.DLL
2009-06-05 15:32:50 ----A---- C:\Windows\system32\adsldpc.dll
2009-06-05 15:32:49 ----A---- C:\Windows\system32\WMVSDECD.DLL
2009-06-05 15:32:49 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-06-05 15:32:49 ----A---- C:\Windows\system32\wercon.exe
2009-06-05 15:32:49 ----A---- C:\Windows\system32\services.exe
2009-06-05 15:32:48 ----A---- C:\Windows\system32\wcncsvc.dll
2009-06-05 15:32:48 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-06-05 15:32:48 ----A---- C:\Windows\system32\msdtcprx.dll
2009-06-05 15:32:48 ----A---- C:\Windows\system32\msdrm.dll
2009-06-05 15:32:48 ----A---- C:\Windows\system32\mimefilt.dll
2009-06-05 15:32:48 ----A---- C:\Windows\system32\comdlg32.dll
2009-06-05 15:32:48 ----A---- C:\Windows\system32\certcli.dll
2009-06-05 15:32:48 ----A---- C:\Windows\system32\adtschema.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\taskeng.exe
2009-06-05 15:32:47 ----A---- C:\Windows\system32\rtffilt.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\reg.exe
2009-06-05 15:32:47 ----A---- C:\Windows\system32\mswdat10.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\msjter40.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\ipsmsnap.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\dnsapi.dll
2009-06-05 15:32:47 ----A---- C:\Windows\system32\certutil.exe
2009-06-05 15:32:46 ----A---- C:\Windows\system32\w32time.dll
2009-06-05 15:32:46 ----A---- C:\Windows\system32\rsaenh.dll
2009-06-05 15:32:46 ----A---- C:\Windows\system32\msshooks.dll
2009-06-05 15:32:46 ----A---- C:\Windows\system32\msscntrs.dll
2009-06-05 15:32:46 ----A---- C:\Windows\system32\msihnd.dll
2009-06-05 15:32:46 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-06-05 15:32:46 ----A---- C:\Windows\system32\bthserv.dll
2009-06-05 15:32:46 ----A---- C:\Windows\system32\bcrypt.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\TsWpfWrp.exe
2009-06-05 15:32:45 ----A---- C:\Windows\system32\netapi32.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\mtxclu.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\msstrc.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\mscories.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\MMDevAPI.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\inetpp.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\inetcomm.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\hidserv.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\fundisc.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\dfshim.dll
2009-06-05 15:32:45 ----A---- C:\Windows\system32\cryptsvc.dll
2009-06-05 15:32:44 ----A---- C:\Windows\s