Bonjour,
Ma machine plante très souvent (redémarrages, blue screen ...)
Quelqu'un peut-il m'aider à la requinquer ? (D'avance merci !)
Voici les 2 rapports RSIT
info.txt logfile of random's system information tool 1.06 2009-11-06 18:42:25
======Uninstall list======
-->MsiExec /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81000000003}
AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
CD Installation DartyBox-->"C:\Program Files\InstallShield Installation Information\{2962D91C-4D8F-46F8-AD24-0E17A92207A2}\setup.exe" -runfromtemp -l0x040c -removeonly
Conseiller de mise à niveau vers Windows 7-->MsiExec.exe /I{4983AA07-81D0-4605-BF92-49A343056DC8}
CyberLink DVD Suite Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" -uninstall
Driver Genius Professional Edition-->"C:\Program Files\Driver-Soft\DriverGenius\unins000.exe"
DVD Play BD & HD DVD-->"C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
GoToAssist 8.0.0.508-->C:\Program Files\Citrix\GoToAssist\508\G2AUninstaller.exe /uninstall
Hauppauge MCE XP/Vista Software Encoder (2.0.25180)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AFAD41A9-9687-48A3-848F-693C11451433}\setup.exe" -l0x9 -removeonly
HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}\setup.exe" -l0x9 -removeonly
HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
HP Photosmart Essential 2.5-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
HP Total Care Advisor-->MsiExec.exe /X{e96b3d28-47d6-43cc-98fd-7069eeab6b11}
HP Update-->MsiExec.exe /X{11B83AD3-7A46-4C2E-A568-9505981D4C6F}
Installation de la DartyBox en Ethernet-->"C:\Program Files\InstallShield Installation Information\{793CE0A7-2A75-4485-A81E-DFCE8AAF1702}\setup.exe" -runfromtemp -l0x040c -eth -pri /hide_progress -removeonly
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" -uninstall
LightScribe System Software-->MsiExec.exe /X{7F10292C-A190-4176-A665-A1ED3478DF86}
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
MioMore Desktop 2008-->C:\Program Files\InstallShield Installation Information\{7617FC2E-EA1B-4F07-A0F5-5D5F437CB32D}\Setup.exe -runfromtemp -l0x040c -removeonly
Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{7C0B3A39-6602-4E52-9561-01C24E7BDFC0}\muveesetup.exe -removeonly -runfromtemp
Norton AntiVirus-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\562C4DD5\16.7.2.11\InstStub.exe /X
NVIDIA Drivers-->C:\Windows\system32\nvunrm.exe UninstallGUI
NVIDIA PhysX-->MsiExec.exe /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" -uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
Solution de clavier multimédia amélioré-->C:\HP\KBD\Install.exe /u
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
======Security center information======
AV: Norton AntiVirus (disabled)
AS: Windows Defender
AS: Norton AntiVirus
======System event log======
Computer Name: PC-de-Pascal
Event Code: 4386
Message: Windows Servicing a requis un redémarrage pour terminer la modification de la mise à jour 938123-285_RTM_neutral_PACKAGE du package KB938123(Security Update) à l’état Résolution(Resolving)
Record Number: 11712
Source Name: Microsoft-Windows-Servicing
Time Written: 20090930201149.000000-000
Event Type: Avertissement
User: PC-de-Pascal\Pascal
Computer Name: PC-de-Pascal
Event Code: 4386
Message: Windows Servicing a requis un redémarrage pour terminer la modification de la mise à jour 938123-284_RTM_neutral_PACKAGE du package KB938123(Security Update) à l’état Résolution(Resolving)
Record Number: 11711
Source Name: Microsoft-Windows-Servicing
Time Written: 20090930201149.000000-000
Event Type: Avertissement
User: PC-de-Pascal\Pascal
Computer Name: PC-de-Pascal
Event Code: 4386
Message: Windows Servicing a requis un redémarrage pour terminer la modification de la mise à jour 938123-283_RTM_neutral_PACKAGE du package KB938123(Security Update) à l’état Résolution(Resolving)
Record Number: 11710
Source Name: Microsoft-Windows-Servicing
Time Written: 20090930201149.000000-000
Event Type: Avertissement
User: PC-de-Pascal\Pascal
Computer Name: PC-de-Pascal
Event Code: 4386
Message: Windows Servicing a requis un redémarrage pour terminer la modification de la mise à jour 938123-282_RTM_neutral_PACKAGE du package KB938123(Security Update) à l’état Résolution(Resolving)
Record Number: 11709
Source Name: Microsoft-Windows-Servicing
Time Written: 20090930201149.000000-000
Event Type: Avertissement
User: PC-de-Pascal\Pascal
Computer Name: PC-de-Pascal
Event Code: 4386
Message: Windows Servicing a requis un redémarrage pour terminer la modification de la mise à jour 938123-281_RTM_neutral_PACKAGE du package KB938123(Security Update) à l’état Résolution(Resolving)
Record Number: 11708
Source Name: Microsoft-Windows-Servicing
Time Written: 20090930201149.000000-000
Event Type: Avertissement
User: PC-de-Pascal\Pascal
=====Application event log=====
Computer Name: PC-de-Pascal
Event Code: 1530
Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.
DÉTAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-366900599-1579925252-3249589954-1000:
Process 604 (\Device\HarddiskVolume1\WINDOWS\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-366900599-1579925252-3249589954-1000
Record Number: 440
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090930162607.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM
Computer Name: PC-de-Pascal
Event Code: 5007
Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
Record Number: 402
Source Name: WerSvc
Time Written: 20090930160452.000000-000
Event Type: Erreur
User:
Computer Name: PC-de-Pascal
Event Code: 1008
Message: Le service Windows Search tente de supprimer l’ancien catalogue.
Record Number: 395
Source Name: Microsoft-Windows-Search
Time Written: 20090930160423.000000-000
Event Type: Avertissement
User:
Computer Name: LH-CJ0PW5KV2UP6
Event Code: 1036
Message: Échec de InitializePrintProvider pour le fournisseur inetpp.dll. Cela peut se produire à la suite d’une instabilité du système ou d’une insuffisance des ressources système.
Record Number: 361
Source Name: Microsoft-Windows-SpoolerSpoolss
Time Written: 20090930155808.000000-000
Event Type: Avertissement
User: AUTORITE NT\SYSTEM
Computer Name: LH-CJ0PW5KV2UP6
Event Code: 5007
Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
Record Number: 354
Source Name: WerSvc
Time Written: 20090930155616.000000-000
Event Type: Erreur
User:
=====Security event log=====
Computer Name: LH-CJ0PW5KV2UP6
Event Code: 4647
Message: Fermeture de session initiée par l’utilisateur :
Sujet :
ID de sécurité : S-1-5-21-3739240333-2321695255-2188316284-500
Nom du compte : Administrator
Domaine du compte : LH-CJ0PW5KV2UP6
ID d’ouverture de session : 0x33135
Cet événement est généré lorsqu’une fermeture de session est initiée, mais que le nombre de références du jeton n’étant pas zéro, la session ouverte ne peut pas être supprimée. Aucune autre activité initiée par l’utilisateur ne peut se produire. Cet événement peut être interprété comme un événement de fermeture de session.
Record Number: 235
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20070103171129.404800-000
Event Type: Succès de l'audit
User:
Computer Name: LH-CJ0PW5KV2UP6
Event Code: 4634
Message: Fermeture de session d’un compte.
Sujet :
ID de sécurité : S-1-5-7
Nom du compte : ANONYMOUS LOGON
Domaine du compte : AUTORITE NT
ID du compte : 0x21df4
Type d’ouverture de session : 3
Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
Record Number: 234
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20070103171127.470400-000
Event Type: Succès de l'audit
User:
Computer Name: LH-CJ0PW5KV2UP6
Event Code: 4616
Message: L’heure du système a été modifiée.
Sujet :
ID de sécurité : S-1-5-19
Nom du compte : SERVICE LOCAL
Domaine du compte : AUTORITE NT
ID d’ouverture de session : 0x3e5
Informations sur le processus :
ID du processus : 0x484
Nom : C:\Windows\System32\svchost.exe
Heure précédente : 18:11:27 03/01/2007
Nouvelle heure : 18:11:27 03/01/2007
Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
Record Number: 233
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20070103171127.174000-000
Event Type: Succès de l'audit
User:
Computer Name: LH-CJ0PW5KV2UP6
Event Code: 1100
Message: Le service d’enregistrement des événements a été arrêté.
Record Number: 232
Source Name: Microsoft-Windows-Eventlog
Time Written: 20070103171127.205200-000
Event Type: Succès de l'audit
User:
Computer Name: LH-CJ0PW5KV2UP6
Event Code: 1102
Message: Le journal d’audit a été effacé.
Objet :
ID de sécurité : S-1-5-21-3739240333-2321695255-2188316284-500
Nom de compte : Administrator
Nom de domaine : LH-CJ0PW5KV2UP6
ID de connexion : 0x33135
Record Number: 231
Source Name: Microsoft-Windows-Eventlog
Time Written: 20070103171106.198035-000
Event Type: Succès de l'audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=x86 Family 16 Model 2 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=0202
"NUMBER_OF_PROCESSORS"=4
"PLATFORM"=HPD
"PCBRAND"=Pavilion
"OnlineServices"=Services en ligne
-----------------EOF-----------------
Et voici le log:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Pascal at 2009-11-06 18:42:19
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 327 GB (70%) free of 466 GB
Total RAM: 3326 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:42:21, on 06/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\RtHDVCpl.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Windows\system32\schtasks.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\jusched.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Pascal\Desktop\RSIT.exe
C:\Program Files\trend micro\Pascal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-us.cab
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\508\g2aservice.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Chasis Button Service (HPBtnSrv) - Unknown owner - c:\hp\HPEZBTN\HPBtnSrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
End of file - 5667 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL [2009-08-22 107896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-04-07 501400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar Launcher - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-07-30 1086816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-07-30 1086816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"KBD"=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-01-15 4874240]
"HP Health Check Scheduler"=[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048]
"SunJavaUpdateReg"=C:\Windows\system32\jureg.exe [2007-04-07 54936]
""= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll [2009-09-30 10536]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 2 months======
2009-11-03 19:50:46 ----D---- C:\rsit
2009-11-03 19:50:46 ----D---- C:\Program Files\trend micro
2009-11-03 19:24:18 ----D---- C:\Users\Pascal\AppData\Roaming\Malwarebytes
2009-11-03 19:24:12 ----D---- C:\ProgramData\Malwarebytes
2009-11-03 19:24:11 ----HD---- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-02 11:36:35 ----D---- C:\Program Files\Microsoft Silverlight
2009-10-31 23:29:50 ----A---- C:\Windows\system32\javaws.exe
2009-10-31 23:29:50 ----A---- C:\Windows\system32\javaw.exe
2009-10-31 23:29:50 ----A---- C:\Windows\system32\java.exe
2009-10-28 09:53:52 ----A---- C:\Windows\system32\wmp.dll
2009-10-28 09:53:49 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-28 09:53:47 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-27 14:07:43 ----D---- C:\Program Files\Driver-Soft
2009-10-25 19:20:39 ----D---- C:\Program Files\Microsoft Windows 7 Upgrade Advisor
2009-10-20 10:44:47 ----A---- C:\Windows\system32\wups2.dll
2009-10-20 10:44:47 ----A---- C:\Windows\system32\wucltux.dll
2009-10-20 10:44:47 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-20 10:44:47 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-20 10:44:15 ----A---- C:\Windows\system32\wups.dll
2009-10-20 10:44:15 ----A---- C:\Windows\system32\wudriver.dll
2009-10-20 10:44:15 ----A---- C:\Windows\system32\wuapi.dll
2009-10-20 10:44:07 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-20 10:44:07 ----A---- C:\Windows\system32\wuapp.exe
2009-10-19 12:27:44 ----D---- C:\Windows\Minidump
2009-10-15 10:45:15 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-15 10:44:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-15 10:44:39 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-15 10:41:50 ----A---- C:\Windows\system32\mshtml.dll
2009-10-15 10:41:48 ----A---- C:\Windows\system32\ieframe.dll
2009-10-15 10:41:46 ----A---- C:\Windows\system32\wininet.dll
2009-10-15 10:41:46 ----A---- C:\Windows\system32\urlmon.dll
2009-10-15 10:41:46 ----A---- C:\Windows\system32\occache.dll
2009-10-15 10:41:46 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-15 10:41:46 ----A---- C:\Windows\system32\iertutil.dll
2009-10-15 10:41:46 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-15 10:41:45 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-15 10:41:45 ----A---- C:\Windows\system32\ieui.dll
2009-10-15 10:41:45 ----A---- C:\Windows\system32\iepeers.dll
2009-10-15 10:41:44 ----A---- C:\Windows\system32\msfeedssync.exe
2009-10-15 10:41:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-10-15 10:41:44 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-15 10:41:44 ----A---- C:\Windows\system32\iesysprep.dll
2009-10-15 10:41:44 ----A---- C:\Windows\system32\iesetup.dll
2009-10-15 10:41:44 ----A---- C:\Windows\system32\iernonce.dll
2009-10-15 10:41:44 ----A---- C:\Windows\system32\ie4uinit.exe
2009-10-15 10:41:38 ----A---- C:\Windows\system32\msasn1.dll
2009-10-15 10:41:24 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2009-10-14 12:09:57 ----A---- C:\Windows\ntbtlog.txt
2009-10-13 17:51:09 ----D---- C:\Program Files\Mio Technology
2009-10-11 22:03:00 ----RD---- C:\Program Files\Norton Support
2009-10-11 20:49:10 ----D---- C:\Windows\system32\vi-VN
2009-10-11 20:49:10 ----D---- C:\Windows\system32\eu-ES
2009-10-11 20:49:10 ----D---- C:\Windows\system32\ca-ES
2009-10-11 16:35:56 ----D---- C:\Windows\system32\EventProviders
2009-10-11 16:35:02 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-10-11 16:34:57 ----A---- C:\Windows\system32\SLsvc.exe
2009-10-11 16:34:57 ----A---- C:\Windows\system32\SLCExt.dll
2009-10-11 16:34:54 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-10-11 16:34:54 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-10-11 16:34:52 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-10-11 16:34:49 ----A---- C:\Windows\system32\mssrch.dll
2009-10-11 16:34:46 ----A---- C:\Windows\system32\tquery.dll
2009-10-11 16:34:45 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-10-11 16:34:44 ----A---- C:\Windows\system32\scavenge.dll
2009-10-11 16:34:44 ----A---- C:\Windows\system32\RMActivate_isv.exe
2009-10-11 16:34:44 ----A---- C:\Windows\system32\RMActivate.exe
2009-10-11 16:34:42 ----A---- C:\Windows\system32\msi.dll
2009-10-11 16:34:41 ----A---- C:\Windows\system32\WscEapPr.dll
2009-10-11 16:34:41 ----A---- C:\Windows\system32\secproc_isv.dll
2009-10-11 16:34:41 ----A---- C:\Windows\system32\imapi2fs.dll
2009-10-11 16:34:40 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-10-11 16:34:40 ----A---- C:\Windows\system32\sysmain.dll
2009-10-11 16:34:39 ----A---- C:\Windows\system32\icardagt.exe
2009-10-11 16:34:38 ----A---- C:\Windows\system32\EhStorShell.dll
2009-10-11 16:34:38 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2009-10-11 16:34:36 ----A---- C:\Windows\system32\spreview.exe
2009-10-11 16:34:36 ----A---- C:\Windows\system32\spinstall.exe
2009-10-11 16:34:36 ----A---- C:\Windows\system32\drmv2clt.dll
2009-10-11 16:34:35 ----A---- C:\Windows\system32\spwizui.dll
2009-10-11 16:34:35 ----A---- C:\Windows\system32\shell32.dll
2009-10-11 16:34:35 ----A---- C:\Windows\system32\secproc.dll
2009-10-11 16:34:35 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-10-11 16:34:33 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-10-11 16:34:33 ----A---- C:\Windows\system32\p2psvc.dll
2009-10-11 16:34:33 ----A---- C:\Windows\system32\mssvp.dll
2009-10-11 16:34:32 ----A---- C:\Windows\system32\mssphtb.dll
2009-10-11 16:34:32 ----A---- C:\Windows\system32\mssph.dll
2009-10-11 16:34:32 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2009-10-11 16:34:32 ----A---- C:\Windows\system32\mscoree.dll
2009-10-11 16:34:31 ----A---- C:\Windows\system32\imapi2.dll
2009-10-11 16:34:30 ----A---- C:\Windows\system32\sdohlp.dll
2009-10-11 16:34:30 ----A---- C:\Windows\system32\esent.dll
2009-10-11 16:34:29 ----A---- C:\Windows\system32\wevtsvc.dll
2009-10-11 16:34:29 ----A---- C:\Windows\system32\sperror.dll
2009-10-11 16:34:29 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2009-10-11 16:34:29 ----A---- C:\Windows\system32\korwbrkr.dll
2009-10-11 16:34:29 ----A---- C:\Windows\system32\IMJP10K.DLL
2009-10-11 16:34:29 ----A---- C:\Windows\system32\DevicePairing.dll
2009-10-11 16:34:28 ----A---- C:\Windows\system32\SLC.dll
2009-10-11 16:34:28 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-10-11 16:34:28 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-10-11 16:34:28 ----A---- C:\Windows\system32\msshsq.dll
2009-10-11 16:34:28 ----A---- C:\Windows\system32\IasMigReader.exe
2009-10-11 16:34:26 ----A---- C:\Windows\system32\msxml6.dll
2009-10-11 16:34:26 ----A---- C:\Windows\system32\msjet40.dll
2009-10-11 16:34:26 ----A---- C:\Windows\system32\MPSSVC.dll
2009-10-11 16:34:25 ----A---- C:\Windows\system32\Query.dll
2009-10-11 16:34:25 ----A---- C:\Windows\system32\qmgr.dll
2009-10-11 16:34:24 ----A---- C:\Windows\system32\P2PGraph.dll
2009-10-11 16:34:24 ----A---- C:\Windows\system32\ole32.dll
2009-10-11 16:34:24 ----A---- C:\Windows\system32\msexch40.dll
2009-10-11 16:34:24 ----A---- C:\Windows\system32\diagperf.dll
2009-10-11 16:34:23 ----A---- C:\Windows\system32\ntdll.dll
2009-10-11 16:34:22 ----A---- C:\Windows\system32\winload.exe
2009-10-11 16:34:22 ----A---- C:\Windows\system32\srchadmin.dll
2009-10-11 16:34:22 ----A---- C:\Windows\system32\msxml3.dll
2009-10-11 16:34:22 ----A---- C:\Windows\system32\mblctr.exe
2009-10-11 16:34:22 ----A---- C:\Windows\system32\EncDec.dll
2009-10-11 16:34:21 ----A---- C:\Windows\system32\uDWM.dll
2009-10-11 16:34:21 ----A---- C:\Windows\system32\riched20.dll
2009-10-11 16:34:21 ----A---- C:\Windows\system32\mmc.exe
2009-10-11 16:34:21 ----A---- C:\Windows\system32\IasMigPlugin.dll
2009-10-11 16:34:21 ----A---- C:\Windows\system32\dfsr.exe
2009-10-11 16:34:20 ----A---- C:\Windows\system32\RacEngn.dll
2009-10-11 16:34:20 ----A---- C:\Windows\system32\fdBth.dll
2009-10-11 16:34:19 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-10-11 16:34:19 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-10-11 16:34:19 ----A---- C:\Windows\system32\milcore.dll
2009-10-11 16:34:19 ----A---- C:\Windows\system32\kernel32.dll
2009-10-11 16:34:18 ----A---- C:\Windows\system32\spoolss.dll
2009-10-11 16:34:18 ----A---- C:\Windows\system32\schedsvc.dll
2009-10-11 16:34:18 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-10-11 16:34:18 ----A---- C:\Windows\system32\EhStorAPI.dll
2009-10-11 16:34:18 ----A---- C:\Windows\system32\CertEnroll.dll
2009-10-11 16:34:17 ----A---- C:\Windows\system32\msvcp60.dll
2009-10-11 16:34:17 ----A---- C:\Windows\system32\msjtes40.dll
2009-10-11 16:34:17 ----A---- C:\Windows\system32\infocardapi.dll
2009-10-11 16:34:17 ----A---- C:\Windows\system32\gpedit.dll
2009-10-11 16:34:17 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2009-10-11 16:34:16 ----A---- C:\Windows\system32\WinSAT.exe
2009-10-11 16:34:15 ----A---- C:\Windows\system32\PresentationSettings.exe
2009-10-11 16:34:15 ----A---- C:\Windows\system32\Magnify.exe
2009-10-11 16:34:15 ----A---- C:\Windows\system32\es.dll
2009-10-11 16:34:15 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2009-10-11 16:34:14 ----A---- C:\Windows\system32\mstext40.dll
2009-10-11 16:34:14 ----A---- C:\Windows\system32\advapi32.dll
2009-10-11 16:34:13 ----A---- C:\Windows\system32\WMPhoto.dll
2009-10-11 16:34:13 ----A---- C:\Windows\system32\WebClnt.dll
2009-10-11 16:34:13 ----A---- C:\Windows\system32\msexcl40.dll
2009-10-11 16:34:12 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2009-10-11 16:34:12 ----A---- C:\Windows\system32\vssapi.dll
2009-10-11 16:34:12 ----A---- C:\Windows\system32\slwmi.dll
2009-10-11 16:34:12 ----A---- C:\Windows\system32\msxbde40.dll
2009-10-11 16:34:12 ----A---- C:\Windows\system32\comsvcs.dll
2009-10-11 16:34:11 ----A---- C:\Windows\system32\authui.dll
2009-10-11 16:34:10 ----A---- C:\Windows\system32\propsys.dll
2009-10-11 16:34:10 ----A---- C:\Windows\system32\PresentationHost.exe
2009-10-11 16:34:10 ----A---- C:\Windows\system32\newdev.dll
2009-10-11 16:34:10 ----A---- C:\Windows\system32\NetProjW.dll
2009-10-11 16:34:10 ----A---- C:\Windows\system32\msrepl40.dll
2009-10-11 16:34:09 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-10-11 16:34:09 ----A---- C:\Windows\system32\iasrecst.dll
2009-10-11 16:34:09 ----A---- C:\Windows\system32\gpsvc.dll
2009-10-11 16:34:09 ----A---- C:\Windows\system32\eudcedit.exe
2009-10-11 16:34:09 ----A---- C:\Windows\system32\crypt32.dll
2009-10-11 16:34:09 ----A---- C:\Windows\explorer.exe
2009-10-11 16:34:08 ----A---- C:\Windows\system32\setupapi.dll
2009-10-11 16:34:08 ----A---- C:\Windows\system32\rpcss.dll
2009-10-11 16:34:08 ----A---- C:\Windows\system32\mspbde40.dll
2009-10-11 16:34:08 ----A---- C:\Windows\system32\d3d9.dll
2009-10-11 16:34:07 ----A---- C:\Windows\system32\msltus40.dll
2009-10-11 16:34:07 ----A---- C:\Windows\system32\mfc42.dll
2009-10-11 16:34:07 ----A---- C:\Windows\system32\davclnt.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\wevtapi.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\shlwapi.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\photowiz.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\nlhtml.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\msrd3x40.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\msdtctm.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\EhStorAuthn.dll
2009-10-11 16:34:06 ----A---- C:\Windows\system32\browseui.dll
2009-10-11 16:34:05 ----A---- C:\Windows\system32\user32.dll
2009-10-11 16:34:04 ----A---- C:\Windows\system32\samsrv.dll
2009-10-11 16:34:04 ----A---- C:\Windows\system32\quartz.dll
2009-10-11 16:34:04 ----A---- C:\Windows\system32\ci.dll
2009-10-11 16:34:03 ----A---- C:\Windows\system32\win32spl.dll
2009-10-11 16:34:03 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-10-11 16:34:03 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-10-11 16:34:03 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-10-11 16:34:03 ----A---- C:\Windows\system32\oleaut32.dll
2009-10-11 16:34:03 ----A---- C:\Windows\system32\netshell.dll
2009-10-11 16:34:03 ----A---- C:\Windows\system32\IKEEXT.DLL
2009-10-11 16:34:02 ----A---- C:\Windows\system32\winhttp.dll
2009-10-11 16:34:02 ----A---- C:\Windows\system32\compcln.exe
2009-10-11 16:34:02 ----A---- C:\Windows\system32\apds.dll
2009-10-11 16:34:01 ----A---- C:\Windows\system32\xmlfilter.dll
2009-10-11 16:34:01 ----A---- C:\Windows\system32\mswstr10.dll
2009-10-11 16:34:01 ----A---- C:\Windows\system32\msctf.dll
2009-10-11 16:34:01 ----A---- C:\Windows\system32\emdmgmt.dll
2009-10-11 16:34:01 ----A---- C:\Windows\system32\audiosrv.dll
2009-10-11 16:34:00 ----A---- C:\Windows\system32\VSSVC.exe
2009-10-11 16:34:00 ----A---- C:\Windows\system32\QAGENTRT.DLL
2009-10-11 16:34:00 ----A---- C:\Windows\system32\msvcrt.dll
2009-10-11 16:34:00 ----A---- C:\Windows\system32\mfc42u.dll
2009-10-11 16:34:00 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-10-11 16:34:00 ----A---- C:\Windows\system32\gdi32.dll
2009-10-11 16:33:59 ----A---- C:\Windows\system32\winresume.exe
2009-10-11 16:33:59 ----A---- C:\Windows\system32\sqlsrv32.dll
2009-10-11 16:33:59 ----A---- C:\Windows\system32\SLUI.exe
2009-10-11 16:33:59 ----A---- C:\Windows\system32\propdefs.dll
2009-10-11 16:33:59 ----A---- C:\Windows\system32\odbc32.dll
2009-10-11 16:33:59 ----A---- C:\Windows\system32\msrd2x40.dll
2009-10-11 16:33:59 ----A---- C:\Windows\system32\eapphost.dll
2009-10-11 16:33:58 ----A---- C:\Windows\system32\wevtutil.exe
2009-10-11 16:33:58 ----A---- C:\Windows\system32\shdocvw.dll
2009-10-11 16:33:58 ----A---- C:\Windows\system32\mssitlb.dll
2009-10-11 16:33:58 ----A---- C:\Windows\system32\dbgeng.dll
2009-10-11 16:33:57 ----A---- C:\Windows\system32\WsmSvc.dll
2009-10-11 16:33:56 ----A---- C:\Windows\system32\usp10.dll
2009-10-11 16:33:56 ----A---- C:\Windows\system32\swprv.dll
2009-10-11 16:33:56 ----A---- C:\Windows\system32\mmcndmgr.dll
2009-10-11 16:33:55 ----A---- C:\Windows\system32\vds.exe
2009-10-11 16:33:55 ----A---- C:\Windows\system32\netlogon.dll
2009-10-11 16:33:55 ----A---- C:\Windows\system32\msctfp.dll
2009-10-11 16:33:55 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-10-11 16:33:55 ----A---- C:\Windows\system32\drvinst.exe
2009-10-11 16:33:55 ----A---- C:\Windows\system32\devmgr.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\WSDApi.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\Wldap32.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\wcnwiz.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\msscb.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\evr.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-10-11 16:33:54 ----A---- C:\Windows\system32\BFE.DLL
2009-10-11 16:33:54 ----A---- C:\Windows\system32\adsldpc.dll
2009-10-11 16:33:53 ----A---- C:\Windows\system32\WMVSDECD.DLL
2009-10-11 16:33:53 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-10-11 16:33:53 ----A---- C:\Windows\system32\wercon.exe
2009-10-11 16:33:53 ----A---- C:\Windows\system32\services.exe
2009-10-11 16:33:52 ----A---- C:\Windows\system32\wcncsvc.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\mswdat10.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\msjter40.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\msdtcprx.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\msdrm.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\mimefilt.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\ipsmsnap.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\comdlg32.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\certcli.dll
2009-10-11 16:33:52 ----A---- C:\Windows\system32\adtschema.dll
2009-10-11 16:33:51 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-10-11 16:33:51 ----A---- C:\Windows\system32\w32time.dll
2009-10-11 16:33:51 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-10-11 16:33:51 ----A---- C:\Windows\system32\taskeng.exe
2009-10-11 16:33:51 ----A---- C:\Windows\system32\rtffilt.dll
2009-10-11 16:33:51 ----A---- C:\Windows\system32\reg.exe
2009-10-11 16:33:51 ----A---- C:\Windows\system32\dnsapi.dll
2009-10-11 16:33:51 ----A---- C:\Windows\system32\certutil.exe
2009-10-11 16:33:50 ----A---- C:\Windows\system32\TsWpfWrp.exe
2009-10-11 16:33:50 ----A---- C:\Windows\system32\rsaenh.dll
2009-10-11 16:33:50 ----A---- C:\Windows\system32\msstrc.dll
2009-10-11 16:33:50 ----A---- C:\Windows\system32\msshooks.dll
2009-10-11 16:33:50 ----A---- C:\Windows\system32\msscntrs.dll
2009-10-11 16:33:50 ----A---- C:\Windows\system32\msihnd.dll
2009-10-11 16:33:50 ----A---- C:\Windows\system32\MMDevAPI.dll
2009-10-11 16:33:50 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-10-11 16:33:50 ----A---- C:\Windows\system32\bthserv.dll
2009-10-11 16:33:50 ----A---- C:\Windows\system32\bcrypt.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\wmicmiplugin.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\termsrv.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\profsvc.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\netapi32.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\mtxclu.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\mscories.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\inetpp.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\inetcomm.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\hidserv.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\fundisc.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\dfshim.dll
2009-10-11 16:33:49 ----A---- C:\Windows\system32\cryptsvc.dll
2009-10-11 16:33:48 ----A---- C:\Windows\system32\wdc.dll
2009-10-11 16:33:48 ----A---- C:\Windows\system32\shsvcs.dll
2009-10-11 16:33:48 ----A---- C:\Windows\system32\msiexec.exe
2009-10-11 16:33:48 ----A---- C:\Windows\system32\imapi.dll
2009-10-11 16:33:48 ----A---- C:\Windows\system32\chsbrkr.dll
2009-10-11 16:33:47 ----A---- C:\Windows\system32\spoolsv.exe
2009-10-11 16:33:47 ----A---- C:\Windows\system32\rasmans.dll
2009-10-11 16:33:47 ----A---- C:\Windows\system32\pnidui.dll
2009-10-11 16:33:47 ----A---- C:\Windows\system32\icardres.dll
2009-10-11 16:33:47 ----A---- C:\Windows\system32\iassdo.dll
2009-10-11 16:33:47 ----A---- C:\Windows\system32\autofmt.exe
2009-10-11 16:33:46 ----A---- C:\Windows\system32\wersvc.dll
2009-10-11 16:33:46 ----A---- C:\Windows\system32\slmgr.vbs
2009-10-11 16:33:46 ----A---- C:\Windows\system32\scrrun.dll
2009-10-11 16:33:46 ----A---- C:\Windows\system32\PSHED.DLL
2009-10-11 16:33:46 ----A---- C:\Windows\system32\pidgenx.dll
2009-10-11 16:33:46 ----A---- C:\Windows\system32\pdh.dll
2009-10-11 16:33:46 ----A---- C:\Windows\system32\dhcpcsvc.dll
2009-10-11 16:33:46 ----A---- C:\Windows\system32\CertEnrollUI.dll
2009-10-11 16:33:46 ----A---- C:\Windows\system32\azroles.dll
2009-10-11 16:33:45 ----A---- C:\Windows\system32\wmpmde.dll
2009-10-11 16:33:45 ----A---- C:\Windows\system32\winlogon.exe
2009-10-11 16:33:45 ----A---- C:\Windows\system32\SyncCenter.dll
2009-10-11 16:33:44 ----A---- C:\Windows\system32\SLUINotify.dll
2009-10-11 16:33:44 ----A---- C:\Windows\system32\sethc.exe
2009-10-11 16:33:44 ----A---- C:\Windows\system32\ncrypt.dll
2009-10-11 16:33:44 ----A---- C:\Windows\system32\msjetoledb40.dll
2009-10-11 16:33:44 ----A---- C:\Windows\system32\kd1394.dll
2009-10-11 16:33:44 ----A---- C:\Windows\system32\comuid.dll
2009-10-11 16:33:44 ----A---- C:\Windows\system32\certmgr.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\wisptis.exe
2009-10-11 16:33:43 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\untfs.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\taskcomp.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\spp.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\scrobj.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\rtutils.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\iassam.dll
2009-10-11 16:33:43 ----A---- C:\Windows\system32\dwm.exe
2009-10-11 16:33:43 ----A---- C:\Windows\system32\autochk.exe
2009-10-11 16:33:42 ----A---- C:\Windows\system32\winsrv.dll
2009-10-11 16:33:42 ----A---- C:\Windows\system32\printui.dll
2009-10-11 16:33:42 ----A---- C:\Windows\system32\onex.dll
2009-10-11 16:33:42 ----A---- C:\Windows\system32\kdcom.dll
2009-10-11 16:33:42 ----A---- C:\Windows\system32\iasnap.dll
2009-10-11 16:33:42 ----A---- C:\Windows\system32\cscript.exe
2009-10-11 16:33:42 ----A---- C:\Windows\system32\basecsp.dll
2009-10-11 16:33:42 ----A---- C:\Windows\system32\autoconv.exe
2009-10-11 16:33:42 ----A---- C:\Windows\system32\audiodg.exe
2009-10-11 16:33:41 ----A---- C:\Windows\system32\wow32.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\WinSCard.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\winmm.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\userenv.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\spcmsg.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\RelMon.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\rdpencom.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\osk.exe
2009-10-11 16:33:41 ----A---- C:\Windows\system32\mswsock.dll
2009-10-11 16:33:41 ----A---- C:\Windows\system32\kdusb.dll
2009-10-11 16:33:40 ----A---- C:\Windows\system32\WerFaultSecure.exe
2009-10-11 16:33:40 ----A---- C:\Windows\system32\offfilt.dll
2009-10-11 16:33:40 ----A---- C:\Windows\system32\msftedit.dll
2009-10-11 16:33:40 ----A---- C:\Windows\system32\dnsrslvr.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\wsepno.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\wscript.exe
2009-10-11 16:33:39 ----A---- C:\Windows\system32\wiaservc.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\WerFault.exe
2009-10-11 16:33:39 ----A---- C:\Windows\system32\Utilman.exe
2009-10-11 16:33:39 ----A---- C:\Windows\system32\ulib.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\sysclass.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\stobject.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\SndVol.exe
2009-10-11 16:33:39 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\secproc_ssp.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\prnntfy.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\odbccp32.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\msnetobj.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\mscms.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\mfplat.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\mcmde.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2009-10-11 16:33:39 ----A---- C:\Windows\system32\iasdatastore.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\dsound.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\diskraid.exe
2009-10-11 16:33:39 ----A---- C:\Windows\system32\cryptui.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\apphelp.dll
2009-10-11 16:33:39 ----A---- C:\Windows\system32\adsmsext.dll
2009-10-11 16:33:38 ----A---- C:\Windows\system32\wscntfy.dll
2009-10-11 16:33:38 ----A---- C:\Windows\system32\rastapi.dll
2009-10-11 16:33:38 ----A---- C:\Windows\system32\pnpsetup.dll
2009-10-11 16:33:38 ----A---- C:\Windows\system32\ipsecsnp.dll
2009-10-11 16:33:38 ----A---- C:\Windows\system32\fdProxy.dll
2009-10-11 16:33:38 ----A---- C:\Windows\system32\brcpl.dll
2009-10-11 16:33:37 ----A---- C:\Windows\system32\wscsvc.dll
2009-10-11 16:33:37 ----A---- C:\Windows\system32\WMVENCOD.DLL
2009-10-11 16:33:37 ----A---- C:\Windows\system32\wlangpui.dll
2009-10-11 16:33:37 ----A---- C:\Windows\system32\vdsdyn.dll
2009-10-11 16:33:37 ----A---- C:\Windows\system32\rastls.dll
2009-10-11 16:33:37 ----A---- C:\Windows\system32\logman.exe
2009-10-11 16:33:37 ----A---- C:\Windows\system32\iashlpr.dll
2009-10-11 16:33:37 ----A---- C:\Windows\system32\gpapi.dll
2009-10-11 16:33:37 ----A---- C:\Windows\system32\diskpart.exe
2009-10-11 16:33:36 ----A---- C:\Windows\system32\zipfldr.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\wusa.exe
2009-10-11 16:33:36 ----A---- C:\Windows\system32\wshext.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\wpccpl.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\regsvc.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\rasapi32.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\ntprint.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\mscorier.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\iasrad.dll
2009-10-11 16:33:36 ----A---- C:\Windows\system32\findstr.exe
2009-10-11 16:33:35 ----A---- C:\Windows\system32\wsnmp32.dll
2009-10-11 16:33:35 ----A---- C:\Windows\system32\wer.dll
2009-10-11 16:33:35 ----A---- C:\Windows\system32\themecpl.dll
2009-10-11 16:33:35 ----A---- C:\Windows\system32\rasdlg.dll
2009-10-11 16:33:35 ----A---- C:\Windows\system32\netcenter.dll
2009-10-11 16:33:35 ----A---- C:\Windows\system32\iassvcs.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\uxsms.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\tsbyuv.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\srvsvc.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\slcc.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\scansetting.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\ntmarta.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\msutb.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\mstlsapi.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\mssprxy.dll
2009-10-11 16:33:34 ----A---- C:\Windows\system32\iasads.dll
2009-10-11 16:33:33 ----A---- C:\Windows\system32\powrprof.dll
2009-10-11 16:33:33 ----A---- C:\Windows\system32\powercpl.dll
2009-10-11 16:33:33 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2009-10-11 16:33:33 ----A---- C:\Windows\system32\networkmap.dll
2009-10-11 16:33:33 ----A---- C:\Windows\system32\mstsc.exe
2009-10-11 16:33:33 ----A---- C:\Windows\system32\iasacct.dll
2009-10-11 16:33:32 ----A---- C:\Windows\system32\sud.dll
2009-10-11 16:33:32 ----A---- C:\Windows\system32\newdev.exe
2009-10-11 16:33:32 ----A---- C:\Windows\system32\dot3svc.dll
2009-10-11 16:33:32 ----A---- C:\Windows\system32\connect.dll
2009-10-11 16:33:32 ----A---- C:\Windows\system32\authz.dll
2009-10-11 16:33:31 ----A---- C:\Windows\system32\themeui.dll
2009-10-11 16:33:31 ----A---- C:\Windows\system32\systemcpl.dll
2009-10-11 16:33:31 ----A---- C:\Windows\system32\samlib.dll
2009-10-11 16:33:31 ----A---- C:\Windows\system32\pcaui.dll
2009-10-11 16:33:31 ----A---- C:\Windows\system32\mmci.dll
2009-10-11 16:33:31 ----A---- C:\Windows\system32\accessibilitycpl.dll
2009-10-11 16:33:30 ----A---- C:\Windows\system32\wpcao.dll
2009-10-11 16:33:30 ----A---- C:\Windows\system32\wlanpref.dll
2009-10-11 16:33:30 ----A---- C:\Windows\system32\usercpl.dll
2009-10-11 16:33:30 ----A---- C:\Windows\system32\rpchttp.dll
2009-10-11 16:33:30 ----A---- C:\Windows\system32\regapi.dll
2009-10-11 16:33:30 ----A---- C:\Windows\system32\qdvd.dll
2009-10-11 16:33:30 ----A---- C:\Windows\system32\msinfo32.exe
2009-10-11 16:33:30 ----A---- C:\Windows\system32\autoplay.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\wscisvif.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\vdsutil.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\tapisrv.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\sdclt.exe
2009-10-11 16:33:29 ----A---- C:\Windows\system32\scksp.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\scesrv.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\rekeywiz.exe
2009-10-11 16:33:29 ----A---- C:\Windows\system32\psisdecd.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\oleprn.dll
2009-10-11 16:33:29 ----A---- C:\Windows\system32\mpr.dll