Rechercher : dans
Par :

Mon ordi rame qd plusieurs prog en même tps

Dernière réponse le 21 nov 2009 à 21:01:17 manusss, le 15 nov 2009 à 02:26:07 
 Signaler ce message aux modérateurs

Bonjour,
Logfile of random's system information tool 1.06 (written by random/random)
Run by Emmanuel at 2009-11-15 02:00:41
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 31 GB (43%) free of 71 GB
Total RAM: 2045 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:00:55, on 15/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Acer\Empowering Technology\eDSMSNfix.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Emmanuel\AppData\Local\irseeg.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\wuauclt.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Opera\opera.exe
C:\Users\Emmanuel\AppData\Local\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\Emmanuel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\Windows\system32\BhoECart.dll
O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDSMSNfix] C:\Acer\Empowering Technology\eDSMSNfix.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [irseeg] "c:\users\emmanuel\appdata\local\irseeg.exe" irseeg
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O20 - AppInit_DLLs: eNetHook.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service Google Update (gupdate1ca2f9a65fc94ef) (gupdate1ca2f9a65fc94ef) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
End of file - 10369 bytes

======Scheduled tasks folder======

C:\Windows\tasks\AppleSoftwareUpdate.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2E03C0FD-4C48-43A7-9A54-00240C70FF16}]
ECarteBleueBrowserHelper Class - C:\Windows\system32\BhoECart.dll [2003-10-31 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}]
VMN Toolbar - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL [2007-08-21 1895896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2009-02-06 61808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-13 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Windows\system32\eDStoolbar.dll [2007-02-06 151552]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar avec bloqueur de fenêtres pop-up - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll []
{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - VMN Toolbar - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL [2007-08-21 1895896]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"ALaunch"=C:\Acer\ALaunch\AlaunchClient.exe []
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2006-12-01 4186112]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-10-23 815104]
"eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2007-02-06 464168]
"Acer Tour"= []
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2006-12-08 614400]
"eRecoveryService"= []
"eDSMSNfix"=C:\Acer\Empowering Technology\eDSMSNfix.exe [2007-02-08 13312]
"Acer Tour Reminder"=C:\Acer\AcerTour\Reminder.exe [2007-01-17 151552]
"WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
"SetPanel"=C:\Acer\APanel\APanel.cmd []
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
"fssui"=C:\Program Files\Windows Live\Family Safety\fsui.exe [2009-02-06 454000]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"Acer Tour Reminder"= []
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
"BitTorrent"=C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized []
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]
"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2005-08-11 249856]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-09-07 39408]
"irseeg"=c:\users\emmanuel\appdata\local\irseeg.exe [2009-11-14 311808]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="eNetHook.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36b87c6e-cd5d-11de-a0a7-0016d4d7a68f}]
shell\AutoRun\command - setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9621c8f9-38ba-11de-8f38-0016d4d7a68f}]
shell\AutoRun\command - g12g.exe
shell\open\command - g12g.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed761bfa-4aa9-11de-b3bd-0016d4d7a68f}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f73c6254-bb01-11dc-a666-0016d4d7a68f}]
shell\AutoRun\command - F:\
shell\explore\command - F:\RECYCLED\INFO.exe
shell\open\command - F:\RECYCLED\INFO.exe


======List of files/folders created in the last 3 months======

2009-11-15 02:00:42 ----D---- C:\Program Files\trend micro
2009-11-15 02:00:41 ----D---- C:\rsit
2009-11-14 14:55:00 ----A---- C:\Windows\system32\wups2.dll
2009-11-14 14:54:59 ----A---- C:\Windows\system32\wuauclt.exe
2009-11-14 14:54:57 ----A---- C:\Windows\system32\wucltux.dll
2009-11-14 14:54:56 ----A---- C:\Windows\system32\wuaueng.dll
2009-11-14 14:52:55 ----A---- C:\Windows\system32\wups.dll
2009-11-14 14:52:55 ----A---- C:\Windows\system32\wudriver.dll
2009-11-14 14:52:55 ----A---- C:\Windows\system32\wuapi.dll
2009-11-14 14:52:40 ----A---- C:\Windows\system32\wuwebv.dll
2009-11-14 14:52:40 ----A---- C:\Windows\system32\wuapp.exe
2009-11-14 12:15:14 ----A---- C:\Windows\swfobject.js
2009-11-14 12:15:13 ----A---- C:\Windows\paotred dispount.txt
2009-11-14 12:15:13 ----A---- C:\Windows\paotred dispount.ini
2009-11-14 12:15:13 ----A---- C:\Windows\paotred dispount.exe
2009-11-14 12:15:12 ----D---- C:\Windows\paotred dispount Uninstaller
2009-11-06 22:59:12 ----A---- C:\Windows\system32\mshtml.dll
2009-10-28 09:22:47 ----A---- C:\Windows\system32\wmp.dll
2009-10-28 09:22:41 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-28 09:22:38 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-19 19:16:42 ----D---- C:\ProgramData\ALM
2009-10-19 19:05:21 ----D---- C:\Program Files\Adobe Media Player
2009-10-19 18:59:47 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-10-19 18:38:22 ----D---- C:\Program Files\Common Files\Macrovision Shared
2009-10-17 11:18:52 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-17 11:18:31 ----A---- C:\Windows\system32\wininet.dll
2009-10-17 11:18:27 ----A---- C:\Windows\system32\urlmon.dll
2009-10-17 11:18:06 ----A---- C:\Windows\system32\ieframe.dll
2009-10-17 11:17:55 ----A---- C:\Windows\system32\ieui.dll
2009-10-17 11:17:43 ----A---- C:\Windows\system32\ieencode.dll
2009-10-17 11:17:33 ----A---- C:\Windows\system32\ieapfltr.dll
2009-10-17 11:16:57 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-17 11:16:56 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-17 11:09:57 ----A---- C:\Windows\system32\msasn1.dll
2009-10-17 11:09:32 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2009-10-15 10:08:49 ----D---- C:\Program Files\Ubisoft
2009-10-09 20:55:30 ----D---- C:\Program Files\Philcarto
2009-10-09 18:04:30 ----A---- C:\Windows\IsUninst.exe
2009-10-09 17:53:12 ----D---- C:\Program Files\Disk Cleaner
2009-10-04 14:19:09 ----D---- C:\Program Files\Virtualis
2009-10-02 21:14:39 ----N---- C:\Windows\system32\MpSigStub.exe
2009-09-20 13:52:25 ----D---- C:\Windows\system32\eu-ES
2009-09-20 13:52:25 ----D---- C:\Windows\system32\ca-ES
2009-09-20 13:52:24 ----D---- C:\Windows\system32\vi-VN
2009-09-20 11:44:28 ----D---- C:\Windows\system32\EventProviders
2009-09-19 12:06:34 ----A---- C:\Windows\system32\netiohlp.dll
2009-09-19 12:06:22 ----A---- C:\Windows\system32\NETSTAT.EXE
2009-09-19 12:06:21 ----A---- C:\Windows\system32\TCPSVCS.EXE
2009-09-19 12:06:21 ----A---- C:\Windows\system32\ARP.EXE
2009-09-19 12:06:20 ----A---- C:\Windows\system32\HOSTNAME.EXE
2009-09-19 12:06:20 ----A---- C:\Windows\system32\finger.exe
2009-09-19 12:06:19 ----A---- C:\Windows\system32\MRINFO.EXE
2009-09-19 12:06:18 ----A---- C:\Windows\system32\ROUTE.EXE
2009-09-19 12:06:14 ----A---- C:\Windows\system32\netevent.dll
2009-09-19 12:04:23 ----A---- C:\Windows\system32\jscript.dll
2009-09-19 12:04:16 ----A---- C:\Windows\system32\wlansvc.dll
2009-09-19 12:04:16 ----A---- C:\Windows\system32\wlanhlp.dll
2009-09-19 12:04:15 ----A---- C:\Windows\system32\wlanmsm.dll
2009-09-19 12:04:15 ----A---- C:\Windows\system32\L2SecHC.dll
2009-09-19 12:04:14 ----A---- C:\Windows\system32\wlansec.dll
2009-09-19 12:04:13 ----A---- C:\Windows\system32\wlanapi.dll
2009-09-19 12:04:03 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-09-19 12:04:02 ----A---- C:\Windows\system32\mf.dll
2009-09-19 12:04:00 ----A---- C:\Windows\system32\rrinstaller.exe
2009-09-19 12:04:00 ----A---- C:\Windows\system32\mfps.dll
2009-09-19 12:04:00 ----A---- C:\Windows\system32\mfpmp.exe
2009-09-19 12:03:58 ----A---- C:\Windows\system32\mferror.dll
2009-09-19 11:58:39 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-09-19 11:58:31 ----A---- C:\Windows\system32\SLsvc.exe
2009-09-19 11:58:31 ----A---- C:\Windows\system32\SLCExt.dll
2009-09-19 11:58:27 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-09-19 11:58:27 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-09-19 11:58:25 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-09-19 11:58:22 ----A---- C:\Windows\system32\mssrch.dll
2009-09-19 11:58:16 ----A---- C:\Windows\system32\tquery.dll
2009-09-19 11:58:13 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-09-19 11:58:11 ----A---- C:\Windows\system32\RMActivate_isv.exe
2009-09-19 11:58:08 ----A---- C:\Windows\system32\scavenge.dll
2009-09-19 11:58:07 ----A---- C:\Windows\system32\RMActivate.exe
2009-09-19 11:57:57 ----A---- C:\Windows\system32\msi.dll
2009-09-19 11:57:49 ----A---- C:\Windows\system32\imapi2fs.dll
2009-09-19 11:57:41 ----A---- C:\Windows\system32\secproc_isv.dll
2009-09-19 11:57:40 ----A---- C:\Windows\system32\WscEapPr.dll
2009-09-19 11:57:39 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-09-19 11:57:38 ----A---- C:\Windows\system32\sysmain.dll
2009-09-19 11:57:31 ----A---- C:\Windows\system32\icardagt.exe
2009-09-19 11:57:27 ----A---- C:\Windows\system32\EhStorShell.dll
2009-09-19 11:57:27 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2009-09-19 11:57:23 ----A---- C:\Windows\system32\spreview.exe
2009-09-19 11:57:22 ----A---- C:\Windows\system32\spinstall.exe
2009-09-19 11:57:21 ----A---- C:\Windows\system32\drmv2clt.dll
2009-09-19 11:57:17 ----A---- C:\Windows\system32\spwizui.dll
2009-09-19 11:57:17 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-09-19 11:57:16 ----A---- C:\Windows\system32\secproc.dll
2009-09-19 11:57:14 ----A---- C:\Windows\system32\shell32.dll
2009-09-19 11:57:09 ----A---- C:\Windows\system32\p2psvc.dll
2009-09-19 11:57:08 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-09-19 11:57:07 ----A---- C:\Windows\system32\mssvp.dll
2009-09-19 11:57:05 ----A---- C:\Windows\system32\mscoree.dll
2009-09-19 11:57:04 ----A---- C:\Windows\system32\mssphtb.dll
2009-09-19 11:57:04 ----A---- C:\Windows\system32\mssph.dll
2009-09-19 11:57:04 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2009-09-19 11:57:03 ----A---- C:\Windows\system32\imapi2.dll
2009-09-19 11:57:02 ----A---- C:\Windows\system32\sdohlp.dll
2009-09-19 11:57:01 ----A---- C:\Windows\system32\esent.dll
2009-09-19 11:57:00 ----A---- C:\Windows\system32\IMJP10K.DLL
2009-09-19 11:57:00 ----A---- C:\Windows\system32\DevicePairing.dll
2009-09-19 11:56:59 ----A---- C:\Windows\system32\sperror.dll
2009-09-19 11:56:59 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2009-09-19 11:56:59 ----A---- C:\Windows\system32\korwbrkr.dll
2009-09-19 11:56:58 ----A---- C:\Windows\system32\wevtsvc.dll
2009-09-19 11:56:58 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-09-19 11:56:57 ----A---- C:\Windows\system32\SLC.dll
2009-09-19 11:56:57 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-09-19 11:56:57 ----A---- C:\Windows\system32\msshsq.dll
2009-09-19 11:56:57 ----A---- C:\Windows\system32\IasMigReader.exe
2009-09-19 11:56:52 ----A---- C:\Windows\system32\msjet40.dll
2009-09-19 11:56:52 ----A---- C:\Windows\system32\MPSSVC.dll
2009-09-19 11:56:51 ----A---- C:\Windows\system32\msxml6.dll
2009-09-19 11:56:49 ----A---- C:\Windows\system32\Query.dll
2009-09-19 11:56:49 ----A---- C:\Windows\system32\qmgr.dll
2009-09-19 11:56:47 ----A---- C:\Windows\system32\P2PGraph.dll
2009-09-19 11:56:47 ----A---- C:\Windows\system32\msexch40.dll
2009-09-19 11:56:47 ----A---- C:\Windows\system32\diagperf.dll
2009-09-19 11:56:46 ----A---- C:\Windows\system32\ole32.dll
2009-09-19 11:56:46 ----A---- C:\Windows\system32\ntdll.dll
2009-09-19 11:56:45 ----A---- C:\Windows\system32\srchadmin.dll
2009-09-19 11:56:44 ----A---- C:\Windows\system32\msxml3.dll
2009-09-19 11:56:43 ----A---- C:\Windows\system32\winload.exe
2009-09-19 11:56:43 ----A---- C:\Windows\system32\mblctr.exe
2009-09-19 11:56:42 ----A---- C:\Windows\system32\uDWM.dll
2009-09-19 11:56:42 ----A---- C:\Windows\system32\mmc.exe
2009-09-19 11:56:42 ----A---- C:\Windows\system32\EncDec.dll
2009-09-19 11:56:41 ----A---- C:\Windows\system32\riched20.dll
2009-09-19 11:56:41 ----A---- C:\Windows\system32\IasMigPlugin.dll
2009-09-19 11:56:41 ----A---- C:\Windows\system32\dfsr.exe
2009-09-19 11:56:40 ----A---- C:\Windows\system32\fdBth.dll
2009-09-19 11:56:39 ----A---- C:\Windows\system32\RacEngn.dll
2009-09-19 11:56:37 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-09-19 11:56:37 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-09-19 11:56:37 ----A---- C:\Windows\system32\milcore.dll
2009-09-19 11:56:37 ----A---- C:\Windows\system32\kernel32.dll
2009-09-19 11:56:36 ----A---- C:\Windows\system32\spoolss.dll
2009-09-19 11:56:36 ----A---- C:\Windows\system32\EhStorAPI.dll
2009-09-19 11:56:36 ----A---- C:\Windows\system32\CertEnroll.dll
2009-09-19 11:56:35 ----A---- C:\Windows\system32\schedsvc.dll
2009-09-19 11:56:35 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-09-19 11:56:33 ----A---- C:\Windows\system32\msvcp60.dll
2009-09-19 11:56:33 ----A---- C:\Windows\system32\msjtes40.dll
2009-09-19 11:56:33 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2009-09-19 11:56:32 ----A---- C:\Windows\system32\infocardapi.dll
2009-09-19 11:56:32 ----A---- C:\Windows\system32\gpedit.dll
2009-09-19 11:56:30 ----A---- C:\Windows\system32\WinSAT.exe
2009-09-19 11:56:30 ----A---- C:\Windows\system32\es.dll
2009-09-19 11:56:29 ----A---- C:\Windows\system32\PresentationSettings.exe
2009-09-19 11:56:28 ----A---- C:\Windows\system32\mstext40.dll
2009-09-19 11:56:28 ----A---- C:\Windows\system32\Magnify.exe
2009-09-19 11:56:28 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2009-09-19 11:56:27 ----A---- C:\Windows\system32\advapi32.dll
2009-09-19 11:56:25 ----A---- C:\Windows\system32\WMPhoto.dll
2009-09-19 11:56:25 ----A---- C:\Windows\system32\WebClnt.dll
2009-09-19 11:56:25 ----A---- C:\Windows\system32\msexcl40.dll
2009-09-19 11:56:24 ----A---- C:\Windows\system32\slwmi.dll
2009-09-19 11:56:24 ----A---- C:\Windows\system32\comsvcs.dll
2009-09-19 11:56:23 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2009-09-19 11:56:23 ----A---- C:\Windows\system32\msxbde40.dll
2009-09-19 11:56:22 ----A---- C:\Windows\system32\vssapi.dll
2009-09-19 11:56:22 ----A---- C:\Windows\system32\msfeeds.dll
2009-09-19 11:56:21 ----A---- C:\Windows\system32\authui.dll
2009-09-19 11:56:20 ----A---- C:\Windows\system32\NetProjW.dll
2009-09-19 11:56:19 ----A---- C:\Windows\system32\vbscript.dll
2009-09-19 11:56:19 ----A---- C:\Windows\system32\PresentationHost.exe
2009-09-19 11:56:19 ----A---- C:\Windows\system32\msrepl40.dll
2009-09-19 11:56:18 ----A---- C:\Windows\system32\propsys.dll
2009-09-19 11:56:18 ----A---- C:\Windows\system32\newdev.dll
2009-09-19 11:56:17 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-09-19 11:56:17 ----A---- C:\Windows\system32\iasrecst.dll
2009-09-19 11:56:17 ----A---- C:\Windows\system32\gpsvc.dll
2009-09-19 11:56:17 ----A---- C:\Windows\system32\eudcedit.exe
2009-09-19 11:56:16 ----A---- C:\Windows\system32\crypt32.dll
2009-09-19 11:56:16 ----A---- C:\Windows\explorer.exe
2009-09-19 11:56:15 ----A---- C:\Windows\system32\rpcss.dll
2009-09-19 11:56:15 ----A---- C:\Windows\system32\iedkcs32.dll
2009-09-19 11:56:14 ----A---- C:\Windows\system32\setupapi.dll
2009-09-19 11:56:14 ----A---- C:\Windows\system32\mspbde40.dll
2009-09-19 11:56:13 ----A---- C:\Windows\system32\d3d9.dll
2009-09-19 11:56:12 ----A---- C:\Windows\system32\msltus40.dll
2009-09-19 11:56:12 ----A---- C:\Windows\system32\davclnt.dll
2009-09-19 11:56:11 ----A---- C:\Windows\system32\shlwapi.dll
2009-09-19 11:56:11 ----A---- C:\Windows\system32\msrd3x40.dll
2009-09-19 11:56:11 ----A---- C:\Windows\system32\mfc42.dll
2009-09-19 11:56:11 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2009-09-19 11:56:11 ----A---- C:\Windows\system32\EhStorAuthn.dll
2009-09-19 11:56:10 ----A---- C:\Windows\system32\wevtapi.dll
2009-09-19 11:56:10 ----A---- C:\Windows\system32\msdtctm.dll
2009-09-19 11:56:10 ----A---- C:\Windows\system32\browseui.dll
2009-09-19 11:56:09 ----A---- C:\Windows\system32\photowiz.dll
2009-09-19 11:56:09 ----A---- C:\Windows\system32\nlhtml.dll
2009-09-19 11:56:07 ----A---- C:\Windows\system32\user32.dll
2009-09-19 11:56:07 ----A---- C:\Windows\system32\samsrv.dll
2009-09-19 11:56:06 ----A---- C:\Windows\system32\quartz.dll
2009-09-19 11:56:06 ----A---- C:\Windows\system32\ci.dll
2009-09-19 11:56:05 ----A---- C:\Windows\system32\win32spl.dll
2009-09-19 11:56:05 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-09-19 11:56:04 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-09-19 11:56:04 ----A---- C:\Windows\system32\oleaut32.dll
2009-09-19 11:56:03 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-09-19 11:56:02 ----A---- C:\Windows\system32\netshell.dll
2009-09-19 11:56:02 ----A---- C:\Windows\system32\IKEEXT.DLL
2009-09-19 11:56:01 ----A---- C:\Windows\system32\compcln.exe
2009-09-19 11:56:00 ----A---- C:\Windows\system32\winhttp.dll
2009-09-19 11:56:00 ----A---- C:\Windows\system32\apds.dll
2009-09-19 11:55:59 ----A---- C:\Windows\system32\xmlfilter.dll
2009-09-19 11:55:59 ----A---- C:\Windows\system32\mswstr10.dll
2009-09-19 11:55:59 ----A---- C:\Windows\system32\audiosrv.dll
2009-09-19 11:55:58 ----A---- C:\Windows\system32\emdmgmt.dll
2009-09-19 11:55:57 ----A---- C:\Windows\system32\msctf.dll
2009-09-19 11:55:55 ----A---- C:\Windows\system32\msvcrt.dll
2009-09-19 11:55:55 ----A---- C:\Windows\system32\gdi32.dll
2009-09-19 11:55:54 ----A---- C:\Windows\system32\VSSVC.exe
2009-09-19 11:55:54 ----A---- C:\Windows\system32\QAGENTRT.DLL
2009-09-19 11:55:53 ----A---- C:\Windows\system32\mfc42u.dll
2009-09-19 11:55:53 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-09-19 11:55:52 ----A---- C:\Windows\system32\SLUI.exe
2009-09-19 11:55:52 ----A---- C:\Windows\system32\eapphost.dll
2009-09-19 11:55:51 ----A---- C:\Windows\system32\sqlsrv32.dll
2009-09-19 11:55:51 ----A---- C:\Windows\system32\msrd2x40.dll
2009-09-19 11:55:49 ----A---- C:\Windows\system32\winresume.exe
2009-09-19 11:55:49 ----A---- C:\Windows\system32\propdefs.dll
2009-09-19 11:55:49 ----A---- C:\Windows\system32\odbc32.dll
2009-09-19 11:55:47 ----A---- C:\Windows\system32\shdocvw.dll
2009-09-19 11:55:45 ----A---- C:\Windows\system32\dbgeng.dll
2009-09-19 11:55:44 ----A---- C:\Windows\system32\wevtutil.exe
2009-09-19 11:55:44 ----A---- C:\Windows\system32\mssitlb.dll
2009-09-19 11:55:42 ----A---- C:\Windows\system32\WsmSvc.dll
2009-09-19 11:55:41 ----A---- C:\Windows\system32\swprv.dll
2009-09-19 11:55:41 ----A---- C:\Windows\system32\mmcndmgr.dll
2009-09-19 11:55:40 ----A---- C:\Windows\system32\usp10.dll
2009-09-19 11:55:39 ----A---- C:\Windows\system32\vds.exe
2009-09-19 11:55:38 ----A---- C:\Windows\system32\mshtmled.dll
2009-09-19 11:55:38 ----A---- C:\Windows\system32\drvinst.exe
2009-09-19 11:55:37 ----A---- C:\Windows\system32\netlogon.dll
2009-09-19 11:55:37 ----A---- C:\Windows\system32\msscb.dll
2009-09-19 11:55:37 ----A---- C:\Windows\system32\msctfp.dll
2009-09-19 11:55:37 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-09-19 11:55:37 ----A---- C:\Windows\system32\devmgr.dll
2009-09-19 11:55:37 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-09-19 11:55:37 ----A---- C:\Windows\system32\adsldpc.dll
2009-09-19 11:55:36 ----A---- C:\Windows\system32\BFE.DLL
2009-09-19 11:55:35 ----A---- C:\Windows\system32\evr.dll
2009-09-19 11:55:34 ----A---- C:\Windows\system32\Wldap32.dll
2009-09-19 11:55:34 ----A---- C:\Windows\system32\wcnwiz.dll
2009-09-19 11:55:33 ----A---- C:\Windows\system32\WSDApi.dll
2009-09-19 11:55:33 ----A---- C:\Windows\system32\WMVSDECD.DLL
2009-09-19 11:55:33 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-09-19 11:55:32 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-09-19 11:55:31 ----A---- C:\Windows\system32\services.exe
2009-09-19 11:55:30 ----A---- C:\Windows\system32\wercon.exe
2009-09-19 11:55:30 ----A---- C:\Windows\system32\iertutil.dll
2009-09-19 11:55:29 ----A---- C:\Windows\system32\mimefilt.dll
2009-09-19 11:55:29 ----A---- C:\Windows\system32\comdlg32.dll
2009-09-19 11:55:29 ----A---- C:\Windows\system32\adtschema.dll
2009-09-19 11:55:28 ----A---- C:\Windows\system32\wcncsvc.dll
2009-09-19 11:55:28 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-09-19 11:55:27 ----A---- C:\Windows\system32\msdrm.dll
2009-09-19 11:55:27 ----A---- C:\Windows\system32\certcli.dll
2009-09-19 11:55:26 ----A---- C:\Windows\system32\mswdat10.dll
2009-09-19 11:55:26 ----A---- C:\Windows\system32\msjter40.dll
2009-09-19 11:55:26 ----A---- C:\Windows\system32\msdtcprx.dll
2009-09-19 11:55:26 ----A---- C:\Windows\system32\ipsmsnap.dll
2009-09-19 11:55:25 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-09-19 11:55:25 ----A---- C:\Windows\system32\taskeng.exe
2009-09-19 11:55:25 ----A---- C:\Windows\system32\rtffilt.dll
2009-09-19 11:55:25 ----A---- C:\Windows\system32\reg.exe
2009-09-19 11:55:25 ----A---- C:\Windows\system32\dnsapi.dll
2009-09-19 11:55:24 ----A---- C:\Windows\system32\certutil.exe
2009-09-19 11:55:23 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-09-19 11:55:21 ----A---- C:\Windows\system32\w32time.dll
2009-09-19 11:55:20 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-09-19 11:55:17 ----A---- C:\Windows\system32\bcrypt.dll
2009-09-19 11:55:16 ----A---- C:\Windows\system32\msshooks.dll
2009-09-19 11:55:16 ----A---- C:\Windows\system32\msscntrs.dll
2009-09-19 11:55:15 ----A---- C:\Windows\system32\bthserv.dll
2009-09-19 11:55:13 ----A---- C:\Windows\system32\rsaenh.dll
2009-09-19 11:55:11 ----A---- C:\Windows\system32\msihnd.dll
2009-09-19 11:55:10 ----A---- C:\Windows\system32\MMDevAPI.dll
2009-09-19 11:55:09 ----A---- C:\Windows\system32\TsWpfWrp.exe
2009-09-19 11:55:09 ----A---- C:\Windows\system32\msstrc.dll
2009-09-19 11:55:06 ----A---- C:\Windows\system32\inetcomm.dll
2009-09-19 11:55:05 ----A---- C:\Windows\system32\dfshim.dll
2009-09-19 11:55:04 ----A---- C:\Windows\system32\netapi32.dll
2009-09-19 11:55:03 ----A---- C:\Windows\system32\inetpp.dll
2009-09-19 11:55:01 ----A---- C:\Windows\system32\mtxclu.dll
2009-09-19 11:55:01 ----A---- C:\Windows\system32\fundisc.dll
2009-09-19 11:55:01 ----A---- C:\Windows\system32\cryptsvc.dll
2009-09-19 11:55:00 ----A---- C:\Windows\system32\mscories.dll
2009-09-19 11:55:00 ----A---- C:\Windows\system32\hidserv.dll
2009-09-19 11:54:58 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-09-19 11:54:57 ----A---- C:\Windows\system32\wmicmiplugin.dll
2009-09-19 11:54:56 ----A---- C:\Windows\system32\profsvc.dll
2009-09-19 11:54:55 ----A---- C:\Windows\system32\termsrv.dll
2009-09-19 11:54:50 ----A---- C:\Windows\system32\shsvcs.dll
2009-09-19 11:54:50 ----A---- C:\Windows\system32\msiexec.exe
2009-09-19 11:54:50 ----A---- C:\Windows\system32\imapi.dll
2009-09-19 11:54:48 ----A---- C:\Windows\system32\wdc.dll
2009-09-19 11:54:48 ----A---- C:\Windows\system32\chsbrkr.dll
2009-09-19 11:54:47 ----A---- C:\Windows\system32\iassdo.dll
2009-09-19 11:54:46 ----A---- C:\Windows\system32\rasmans.dll
2009-09-19 11:54:46 ----A---- C:\Windows\system32\pnidui.dll
2009-09-19 11:54:45 ----A---- C:\Windows\system32\spoolsv.exe
2009-09-19 11:54:45 ----A---- C:\Windows\system32\icardres.dll
2009-09-19 11:54:45 ----A---- C:\Windows\system32\autofmt.exe
2009-09-19 11:54:43 ----A---- C:\Windows\system32\wersvc.dll
2009-09-19 11:54:43 ----A---- C:\Windows\system32\slmgr.vbs
2009-09-19 11:54:43 ----A---- C:\Windows\system32\scrrun.dll
2009-09-19 11:54:43 ----A---- C:\Windows\system32\PSHED.DLL
2009-09-19 11:54:42 ----A---- C:\Windows\system32\pdh.dll
2009-09-19 11:54:41 ----A---- C:\Windows\system32\dhcpcsvc.dll
2009-09-19 11:54:41 ----A---- C:\Windows\system32\CertEnrollUI.dll
2009-09-19 11:54:41 ----A---- C:\Windows\system32\azroles.dll
2009-09-19 11:54:39 ----A---- C:\Windows\system32\pidgenx.dll
2009-09-19 11:54:37 ----A---- C:\Windows\system32\wmpmde.dll
2009-09-19 11:54:36 ----A---- C:\Windows\system32\winlogon.exe
2009-09-19 11:54:36 ----A---- C:\Windows\system32\SyncCenter.dll
2009-09-19 11:54:33 ----A---- C:\Windows\system32\SLUINotify.dll
2009-09-19 11:54:33 ----A---- C:\Windows\system32\msjetoledb40.dll
2009-09-19 11:54:32 ----A---- C:\Windows\system32\comuid.dll
2009-09-19 11:54:31 ----A---- C:\Windows\system32\ncrypt.dll
2009-09-19 11:54:31 ----A---- C:\Windows\system32\certmgr.dll
2009-09-19 11:54:30 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-09-19 11:54:30 ----A---- C:\Windows\system32\sethc.exe
2009-09-19 11:54:30 ----A---- C:\Windows\system32\kd1394.dll
2009-09-19 11:54:29 ----A---- C:\Windows\system32\spp.dll
2009-09-19 11:54:29 ----A---- C:\Windows\system32\scrobj.dll
2009-09-19 11:54:29 ----A---- C:\Windows\system32\iassam.dll
2009-09-19 11:54:28 ----A---- C:\Windows\system32\wisptis.exe
2009-09-19 11:54:28 ----A---- C:\Windows\system32\untfs.dll
2009-09-19 11:54:28 ----A---- C:\Windows\system32\rtutils.dll
2009-09-19 11:54:26 ----A---- C:\Windows\system32\taskcomp.dll
2009-09-19 11:54:26 ----A---- C:\Windows\system32\dwm.exe
2009-09-19 11:54:25 ----A---- C:\Windows\system32\autochk.exe
2009-09-19 11:54:23 ----A---- C:\Windows\system32\printui.dll
2009-09-19 11:54:23 ----A---- C:\Windows\system32\iasnap.dll
2009-09-19 11:54:22 ----A---- C:\Windows\system32\autoconv.exe
2009-09-19 11:54:20 ----A---- C:\Windows\system32\winsrv.dll
2009-09-19 11:54:20 ----A---- C:\Windows\system32\cscript.exe
2009-09-19 11:54:19 ----A---- C:\Windows\system32\userenv.dll
2009-09-19 11:54:19 ----A---- C:\Windows\system32\onex.dll
2009-09-19 11:54:19 ----A---- C:\Windows\system32\kdcom.dll
2009-09-19 11:54:19 ----A---- C:\Windows\system32\basecsp.dll
2009-09-19 11:54:19 ----A---- C:\Windows\system32\audiodg.exe
2009-09-19 11:54:18 ----A---- C:\Windows\system32\wow32.dll
2009-09-19 11:54:18 ----A---- C:\Windows\system32\osk.exe
2009-09-19 11:54:18 ----A---- C:\Windows\system32\mswsock.dll
2009-09-19 11:54:17 ----A---- C:\Windows\system32\winmm.dll
2009-09-19 11:54:17 ----A---- C:\Windows\system32\spcmsg.dll
2009-09-19 11:54:17 ----A---- C:\Windows\system32\RelMon.dll
2009-09-19 11:54:17 ----A---- C:\Windows\system32\kdusb.dll
2009-09-19 11:54:16 ----A---- C:\Windows\system32\WinSCard.dll
2009-09-19 11:54:16 ----A---- C:\Windows\system32\rdpencom.dll
2009-09-19 11:54:16 ----A---- C:\Windows\system32\msftedit.dll
2009-09-19 11:54:15 ----A---- C:\Windows\system32\WerFaultSecure.exe
2009-09-19 11:54:15 ----A---- C:\Windows\system32\offfilt.dll
2009-09-19 11:54:14 ----A---- C:\Windows\system32\dnsrslvr.dll
2009-09-19 11:54:13 ----A---- C:\Windows\system32\wsepno.dll
2009-09-19 11:54:13 ----A---- C:\Windows\system32\WerFault.exe
2009-09-19 11:54:13 ----A---- C:\Windows\system32\Utilman.exe
2009-09-19 11:54:13 ----A---- C:\Windows\system32\stobject.dll
2009-09-19 11:54:13 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2009-09-19 11:54:13 ----A---- C:\Windows\system32\secproc_ssp.dll
2009-09-19 11:54:12 ----A---- C:\Windows\system32\SndVol.exe
2009-09-19 11:54:12 ----A---- C:\Windows\system32\mfplat.dll
2009-09-19 11:54:12 ----A---- C:\Windows\system32\mcmde.dll
2009-09-19 11:54:12 ----A---- C:\Windows\system32\diskraid.exe
2009-09-19 11:54:12 ----A---- C:\Windows\system32\apphelp.dll
2009-09-19 11:54:11 ----A---- C:\Windows\system32\wiaservc.dll
2009-09-19 11:54:11 ----A---- C:\Windows\system32\sysclass.dll
2009-09-19 11:54:11 ----A---- C:\Windows\system32\prnntfy.dll
2009-09-19 11:54:11 ----A---- C:\Windows\system32\msnetobj.dll
2009-09-19 11:54:11 ----A---- C:\Windows\system32\mscms.dll
2009-09-19 11:54:11 ----A---- C:\Windows\system32\adsmsext.dll
2009-09-19 11:54:10 ----A---- C:\Windows\system32\wscript.exe
2009-09-19 11:54:10 ----A---- C:\Windows\system32\odbccp32.dll
2009-09-19 11:54:10 ----A---- C:\Windows\system32\iasdatastore.dll
2009-09-19 11:54:09 ----A---- C:\Windows\system32\ulib.dll
2009-09-19 11:54:08 ----A---- C:\Windows\system32\dsound.dll
2009-09-19 11:54:07 ----A---- C:\Windows\system32\rastapi.dll
2009-09-19 11:54:07 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2009-09-19 11:54:07 ----A---- C:\Windows\system32\cryptui.dll
2009-09-19 11:54:06 ----A---- C:\Windows\system32\wscntfy.dll
2009-09-19 11:54:06 ----A---- C:\Windows\system32\pnpsetup.dll
2009-09-19 11:54:06 ----A---- C:\Windows\system32\ipsecsnp.dll
2009-09-19 11:54:06 ----A---- C:\Windows\system32\fdProxy.dll
2009-09-19 11:54:05 ----A---- C:\Windows\system32\wlangpui.dll
2009-09-19 11:54:05 ----A---- C:\Windows\system32\vdsdyn.dll
2009-09-19 11:54:05 ----A---- C:\Windows\system32\rastls.dll
2009-09-19 11:54:05 ----A---- C:\Windows\system32\iashlpr.dll
2009-09-19 11:54:05 ----A---- C:\Windows\system32\gpapi.dll
2009-09-19 11:54:05 ----A---- C:\Windows\system32\diskpart.exe
2009-09-19 11:54:05 ----A---- C:\Windows\system32\brcpl.dll
2009-09-19 11:54:04 ----A---- C:\Windows\system32\wscsvc.dll
2009-09-19 11:54:04 ----A---- C:\Windows\system32\WMVENCOD.DLL
2009-09-19 11:54:04 ----A---- C:\Windows\system32\rasapi32.dll
2009-09-19 11:54:04 ----A---- C:\Windows\system32\logman.exe
2009-09-19 11:54:04 ----A---- C:\Windows\system32\iepeers.dll
2009-09-19 11:54:03 ----A---- C:\Windows\system32\wusa.exe
2009-09-19 11:54:03 ----A---- C:\Windows\system32\regsvc.dll
2009-09-19 11:54:03 ----A---- C:\Windows\system32\ntprint.dll
2009-09-19 11:54:03 ----A---- C:\Windows\system32\mscorier.dll
2009-09-19 11:54:02 ----A---- C:\Windows\system32\zipfldr.dll
2009-09-19 11:54:02 ----A---- C:\Windows\system32\wshext.dll
2009-09-19 11:54:02 ----A---- C:\Windows\system32\wpccpl.dll
2009-09-19 11:54:02 ----A---- C:\Windows\system32\iasrad.dll
2009-09-19 11:54:02 ----A---- C:\Windows\system32\findstr.exe
2009-09-19 11:54:01 ----A---- C:\Windows\system32\webcheck.dll
2009-09-19 11:54:01 ----A---- C:\Windows\system32\rasdlg.dll
2009-09-19 11:54:01 ----A---- C:\Windows\system32\netcenter.dll
2009-09-19 11:54:00 ----A---- C:\Windows\system32\wsnmp32.dll
2009-09-19 11:54:00 ----A---- C:\Windows\system32\wer.dll
2009-09-19 11:54:00 ----A---- C:\Windows\system32\themecpl.dll
2009-09-19 11:54:00 ----A---- C:\Windows\system32\iassvcs.dll
2009-09-19 11:53:58 ----A---- C:\Windows\system32\uxsms.dll
2009-09-19 11:53:58 ----A---- C:\Windows\system32\srvsvc.dll
2009-09-19 11:53:58 ----A---- C:\Windows\system32\mssprxy.dll
2009-09-19 11:53:57 ----A---- C:\Windows\system32\tsbyuv.dll
2009-09-19 11:53:57 ----A---- C:\Windows\system32\scansetting.dll
2009-09-19 11:53:57 ----A---- C:\Windows\system32\ntmarta.dll
2009-09-19 11:53:56 ----A---- C:\Windows\system32\slcc.dll
2009-09-19 11:53:56 ----A---- C:\Windows\system32\msutb.dll
2009-09-19 11:53:56 ----A---- C:\Windows\system32\mstlsapi.dll
2009-09-19 11:53:56 ----A---- C:\Windows\system32\iasads.dll
2009-09-19 11:53:55 ----A---- C:\Windows\system32\powrprof.dll
2009-09-19 11:53:55 ----A---- C:\Windows\system32\mstsc.exe
2009-09-19 11:53:54 ----A---- C:\Windows\system32\powercpl.dll
2009-09-19 11:53:54 ----A---- C:\Windows\system32\networkmap.dll
2009-09-19 11:53:54 ----A---- C:\Windows\system32\iasacct.dll
2009-09-19 11:53:53 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2009-09-19 11:53:53 ----A---- C:\Windows\system32\newdev.exe
2009-09-19 11:53:53 ----A---- C:\Windows\system32\authz.dll
2009-09-19 11:53:52 ----A---- C:\Windows\system32\sud.dll
2009-09-19 11:53:52 ----A---- C:\Windows\system32\dot3svc.dll
2009-09-19 11:53:52 ----A---- C:\Windows\system32\connect.dll
2009-09-19 11:53:51 ----A---- C:\Windows\system32\systemcpl.dll
2009-09-19 11:53:51 ----A---- C:\Windows\system32\pcaui.dll
2009-09-19 11:53:50 ----A---- C:\Windows\system32\themeui.dll
2009-09-19 11:53:50 ----A---- C:\Windows\system32\accessibilitycpl.dll
2009-09-19 11:53:49 ----A---- C:\Windows\system32\usercpl.dll
2009-09-19 11:53:49 ----A---- C:\Windows\system32\samlib.dll
2009-09-19 11:53:49 ----A---- C:\Windows\system32\mmci.dll
2009-09-19 11:53:48 ----A---- C:\Windows\system32\wlanpref.dll
2009-09-19 11:53:48 ----A---- C:\Windows\system32\qdvd.dll
2009-09-19 11:53:48 ----A---- C:\Windows\system32\autoplay.dll
2009-09-19 11:53:47 ----A---- C:\Windows\system32\rpchttp.dll
2009-09-19 11:53:47 ----A---- C:\Windows\system32\regapi.dll
2009-09-19 11:53:47 ----A---- C:\Windows\system32\msinfo32.exe
2009-09-19 11:53:47 ----A---- C:\Windows\system32\ieaksie.dll
2009-09-19 11:53:46 ----A---- C:\Windows\system32\wpcao.dll
2009-09-19 11:53:46 ----A---- C:\Windows\system32\vdsutil.dll
2009-09-19 11:53:46 ----A---- C:\Windows\system32\tapisrv.dll
2009-09-19 11:53:45 ----A---- C:\Windows\system32\scksp.dll
2009-09-19 11:53:45 ----A---- C:\Windows\system32\scesrv.dll
2009-09-19 11:53:45 ----A---- C:\Windows\system32\mpr.dll
2009-09-19 11:53:45 ----A---- C:\Windows\system32\feclient.dll
2009-09-19 11:53:44 ----A---- C:\Windows\system32\rekeywiz.exe
2009-09-19 11:53:44 ----A---- C:\Windows\system32\psisdecd.dll
2009-09-19 11:53:44 ----A---- C:\Windows\system32\oleprn.dll
2009-09-19 11:53:44 ----A---- C:\Windows\system32\imm32.dll
2009-09-19 11:53:44 ----A---- C:\Windows\system32\Faultrep.dll
2009-09-19 11:53:44 ----A---- C:\Windows\system32\dot3msm.dll
2009-09-19 11:53:44 ----A---- C:\Windows\system32\AudioSes.dll
2009-09-19 11:53:43 ----A---- C:\Windows\system32\wscisvif.dll
2009-09-19 11:53:43 ----A---- C:\Windows\system32\sdclt.exe
2009-09-19 11:53:43 ----A---- C:\Windows\system32\iaspolcy.dll
2009-09-19 11:53:43 ----A---- C:\Windows\system32\dpapimig.exe
2009-09-19 11:53:43 ----A---- C:\Windows\system32\DeviceEject.exe
2009-09-19 11:53:42 ----A---- C:\Windows\system32\qedit.dll
2009-09-19 11:53:42 ----A---- C:\Windows\system32\pnpui.dll
2009-09-19 11:53:42 ----A---- C:\Windows\system32\perfdisk.dll
2009-09-19 11:53:42 ----A---- C:\Windows\system32\ncryptui.dll
2009-09-19 11:53:42 ----A---- C:\Windows\system32\hdwwiz.exe
2009-09-19 11:53:42 ----A---- C:\Windows\system32\certreq.exe
2009-09-19 11:53:41 ----A---- C:\Windows\system32\TSTheme.exe
2009-09-19 11:53:41 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2009-09-19 11:53:41 ----A---- C:\Windows\system32\scecli.dll
2009-09-19 11:53:41 ----A---- C:\Windows\system32\rasplap.dll
2009-09-19 11:53:41 ----A---- C:\Windows\system32\rasgcw.dll
2009-09-19 11:53:41 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2009-09-19 11:53:41 ----A---- C:\Windows\system32\extmgr.dll
2009-09-19 11:53:40 ----A---- C:\Windows\system32\spwinsat.dll
2009-09-19 11:53:39 ----A---- C:\Windows\system32\tcpmon.dll
2009-09-19 11:53:39 ----A---- C:\Windows\system32\tcpipcfg.dll
2009-09-19 11:53:39 ----A---- C:\Windows\system32\PnPUnattend.exe
2009-09-19 11:53:39 ----A---- C:\Windows\system32\fdWSD.dll
2009-09-19 11:53:39 ----A---- C:\Windows\system32\cmmon32.exe
2009-09-19 11:53:38 ----A---- C:\Windows\system32\whealogr.dll
2009-09-19 11:53:37 ----A---- C:\Windows\system32\srcore.dll
2009-09-19 11:53:37 ----A---- C:\Windows\system32\SCardSvr.dll
2009-09-19 11:53:37 ----A---- C:\Windows\system32\conime.exe
2009-09-19 11:53:37 ----A---- C:\Windows\system32\cmdial32.dll
2009-09-19 11:53:36 ----A---- C:\Windows\system32\SnippingTool.exe
2009-09-19 11:53:36 ----A---- C:\Windows\system32\raschap.dll
2009-09-19 11:53:36 ----A---- C:\Windows\system32\fontext.dll
2009-09-19 11:53:35 ----A---- C:\Windows\system32\wlanui.dll
2009-09-19 11:53:35 ----A---- C:\Windows\system32\wiaaut.dll
2009-09-19 11:53:35 ----A---- C:\Windows\system32\MSVidCtl.dll
2009-09-19 11:53:34 ----A---- C:\Windows\system32\WMVXENCD.DLL
2009-09-19 11:53:34 ----A---- C:\Windows\system32\shwebsvc.dll
2009-09-19 11:53:34 ----A---- C:\Windows\system32\rasppp.dll
2009-09-19 11:53:34 ----A---- C:\Windows\system32\PnPutil.exe
2009-09-19 11:53:34 ----A---- C:\Windows\system32\dsprop.dll
2009-09-19 11:53:33 ----A---- C:\Windows\system32\oobefldr.dll
2009-09-19 11:53:33 ----A---- C:\Windows\system32\dimsroam.dll
2009-09-19 11:53:32 ----A---- C:\Windows\system32\shsetup.dll
2009-09-19 11:53:32 ----A---- C:\Windows\system32\rasmontr.dll
2009-09-19 11:53:32 ----A---- C:\Windows\system32\occache.dll
2009-09-19 11:53:32 ----A---- C:\Windows\system32\modemui.dll
2009-09-19 11:53:31 ----A---- C:\Windows\system32\mscandui.dll
2009-09-19 11:53:31 ----A---- C:\Windows\system32\chtbrkr.dll
2009-09-19 11:53:30 ----A---- C:\Windows\system32\wmdrmsdk.dll
2009-09-19 11:53:30 ----A---- C:\Windows\system32\wlgpclnt.dll
2009-09-19 11:53:30 ----A---- C:\Windows\system32\dataclen.dll
2009-09-19 11:53:29 ----A---- C:\Windows\system32\rdpwsx.dll
2009-09-19 11:53:29 ----A---- C:\Windows\system32\blackbox.dll
2009-09-19 11:53:28 ----A---- C:\Windows\system32\smss.exe
2009-09-19 11:53:28 ----A---- C:\Windows\system32\netplwiz.dll
2009-09-19 11:53:28 ----A---- C:\Windows\system32\credui.dll
2009-09-19 11:53:27 ----A---- C:\Windows\system32\WSDMon.dll
2009-09-19 11:53:27 ----A---- C:\Windows\system32\wmpeffects.dll
2009-09-19 11:53:27 ----A---- C:\Windows\system32\mstime.dll
2009-09-19 11:53:27 ----A---- C:\Windows\system32\certprop.dll
2009-09-19 11:53:26 ----A---- C:\Windows\system32\wpcsvc.dll
2009-09-19 11:53:26 ----A---- C:\Windows\system32\networkexplorer.dll
2009-09-19 11:53:26 ----A---- C:\Windows\system32\msscp.dll
2009-09-19 11:53:26 ----A---- C:\Windows\system32\logagent.exe
2009-09-19 11:53:26 ----A---- C:\Windows\system32\ifmon.dll
2009-09-19 11:53:26 ----A---- C:\Windows\system32\cipher.exe
2009-09-19 11:53:25 ----A---- C:\Windows\system32\wscapi.dll
2009-09-19 11:53:25 ----A---- C:\Windows\system32\thawbrkr.dll
2009-09-19 11:53:25 ----A---- C:\Windows\system32\msrating.dll
2009-09-19 11:53:25 ----A---- C:\Windows\system32\msimtf.dll
2009-09-19 11:53:25 ----A---- C:\Windows\system32\InkEd.dll
2009-09-19 11:53:25 ----A---- C:\Windows\system32\gpresult.exe
2009-09-19 11:53:24 ----A---- C:\Windows\system32\softkbd.dll
2009-09-19 11:53:24 ----A---- C:\Windows\system32\sendmail.dll
2009-09-19 11:53:24 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2009-09-19 11:53:23 ----A---- C:\Windows\system32\olepro32.dll
2009-09-19 11:53:23 ----A---- C:\Windows\system32\msctfui.dll
2009-09-19 11:53:23 ----A---- C:\Windows\system32\dmsynth.dll
2009-09-19 11:53:22 ----A---- C:\Windows\system32\drmmgrtn.dll
2009-09-19 11:53:21 ----A---- C:\Windows\system32\puiapi.dll
2009-09-19 11:53:21 ----A---- C:\Windows\system32\input.dll
2009-09-19 11:53:21 ----A---- C:\Windows\system32\cdd.dll
2009-09-19 11:53:20 ----A---- C:\Windows\system32\wshbth.dll
2009-09-19 11:53:20 ----A---- C:\Windows\system32\version.dll
2009-09-19 11:53:20 ----A---- C:\Windows\system32\SLLUA.exe
2009-09-19 11:53:20 ----A---- C:\Windows\system32\msisip.dll
2009-09-19 11:53:20 ----A---- C:\Windows\system32\mprapi.dll
2009-09-19 11:53:20 ----A---- C:\Windows\system32\ExplorerFrame.dll
2009-09-19 11:53:19 ----A---- C:\Windows\system32\fc.exe
2009-09-19 11:53:18 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-09-19 11:53:18 ----A---- C:\Windows\system32\msjint40.dll
2009-09-19 11:53:18 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2009-09-19 11:53:18 ----A---- C:\Windows\system32\l2nacp.dll
2009-09-19 11:53:18 ----A---- C:\Windows\system32\fdSSDP.dll
2009-09-19 11:53:18 ----A---- C:\Windows\system32\eapp3hst.dll
2009-09-19 11:53:18 ----A---- C:\Windows\system32\dmusic.dll
2009-09-19 11:53:18 ----A---- C:\Windows\system32\cscapi.dll
2009-09-19 11:53:17 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-09-19 11:53:17 ----A---- C:\Windows\system32\ftp.exe
2009-09-19 11:53:17 ----A---- C:\Windows\system32\cscdll.dll
2009-09-19 11:53:16 ----A---- C:\Windows\system32\wsdchngr.dll
2009-09-19 11:53:16 ----A---- C:\Windows\system32\Storprop.dll
2009-09-19 11:53:16 ----A---- C:\Windows\system32\SMBHelperClass.dll
2009-09-19 11:53:16 ----A---- C:\Windows\system32\rasdiag.dll
2009-09-19 11:53:16 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-09-19 11:53:16 ----A---- C:\Windows\system32\bthci.dll
2009-09-19 11:53:15 ----A---- C:\Windows\system32\rasdial.exe
2009-09-19 11:53:15 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-09-19 11:53:15 ----A---- C:\Windows\system32\ipconfig.exe
2009-09-19 11:53:15 ----A---- C:\Windows\system32\fdWCN.dll
2009-09-19 11:53:15 ----A---- C:\Windows\system32\eappcfg.dll
2009-09-19 11:53:15 ----A---- C:\Windows\system32\dot3cfg.dll
2009-09-19 11:53:15 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2009-09-19 11:53:15 ----A---- C:\Windows\system32\bthudtask.exe
2009-09-19 11:53:14 ----A---- C:\Windows\system32\tscupgrd.exe
2009-09-19 11:53:14 ----A---- C:\Windows\system32\slcinst.dll
2009-09-19 11:53:14 ----A---- C:\Windows\system32\nslookup.exe
2009-09-19 11:53:14 ----A---- C:\Windows\system32\networkitemfactory.dll
2009-09-19 11:53:14 ----A---- C:\Windows\system32\eappgnui.dll
2009-09-19 11:53:13 ----A---- C:\Windows\system32\ocsetup.exe
2009-09-19 11:53:13 ----A---- C:\Windows\system32\mmcico.dll
2009-09-19 11:53:13 ----A---- C:\Windows\system32\hbaapi.dll
2009-09-19 11:53:13 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2009-09-19 11:53:13 ----A---- C:\Windows\system32\fdeploy.dll
2009-09-19 11:53:12 ----A---- C:\Windows\system32\PNPXAssoc.dll
2009-09-19 11:53:11 ----A---- C:\Windows\system32\gpupdate.exe
2009-09-19 11:53:10 ----A---- C:\Windows\system32\csrstub.exe
2009-09-19 11:53:10 ----A---- C:\Windows\system32\cbsra.exe
2009-09-19 11:53:10 ----A---- C:\Windows\system32\bitsigd.dll
2009-09-19 11:53:09 ----A---- C:\Windows\system32\NcdProp.dll
2009-09-19 11:53:09 ----A---- C:\Windows\system32\iscsilog.dll
2009-09-19 11:53:08 ----A---- C:\Windows\system32\vdmdbg.dll
2009-09-19 11:53:08 ----A---- C:\Windows\system32\odbcconf.dll
2009-09-19 11:53:07 ----A---- C:\Windows\system32\winrnr.dll
2009-09-19 11:53:07 ----A---- C:\Windows\system32\slwga.dll
2009-09-19 11:53:07 ----A---- C:\Windows\system32\inetppui.dll
2009-09-19 11:53:06 ----A---- C:\Windows\system32\midimap.dll
2009-09-19 11:53:01 ----A---- C:\Windows\system32\msimsg.dll
2009-09-19 11:53:01 ----A---- C:\Windows\system32\f3ahvoas.dll
2009-09-19 11:51:51 ----A---- C:\Windows\system32\SmiEngine.dll
2009-09-19 11:51:45 ----A---- C:\Windows\system32\wdscore.dll
2009-09-19 11:51:45 ----A---- C:\Windows\system32\PkgMgr.exe
2009-09-19 11:51:39 ----A---- C:\Windows\system32\drvstore.dll
2009-09-07 10:04:18 ----D---- C:\ProgramData\Google Updater
2009-09-07 10:04:12 ----D---- C:\Program Files\Google
2009-09-03 17:19:24 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-09-03 17:19:22 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-08-26 21:44:32 ----A---- C:\Windows\system32\tzres.dll
2009-08-26 19:17:26 ----A---- C:\Windows\system32\gameux.dll
2009-08-17 22:33:52 ----A---- C:\Windows\system32\FM20.DLL
2009-08-16 11:46:36 ----A---- C:\Windows\system32\lsasrv.dll
2009-08-16 11:46:35 ----A---- C:\Windows\system32\kerberos.dll
2009-08-16 11:46:33 ----A---- C:\Windows\system32\wdigest.dll
2009-08-16 11:46:32 ----A---- C:\Windows\system32\schannel.dll
2009-08-16 11:46:26 ----A---- C:\Windows\system32\secur32.dll
2009-08-16 11:46:26 ----A---- C:\Windows\system32\lsass.exe

======List of files/folders modified in the last 3 months======

2009-11-15 02:00:55 ----D---- C:\Windows\Prefetch
2009-11-15 02:00:51 ----D---- C:\Windows\Temp
2009-11-15 02:00:42 ----RD---- C:\Program Files
2009-11-15 01:41:58 ----HD---- C:\ProgramData
2009-11-14 20:09:21 ----D---- C:\Windows\Tasks
2009-11-14 18:30:58 ----D---- C:\Windows\System32
2009-11-14 18:30:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-11-14 18:30:57 ----D---- C:\Windows\inf
2009-11-14 17:24:14 ----D---- C:\Windows\rescache
2009-11-14 17:12:02 ----D---- C:\ProgramData\FLEXnet
2009-11-14 17:04:30 ----D---- C:\Windows\system32\fr-FR
2009-11-14 17:03:01 ----D---- C:\Windows\winsxs
2009-11-14 14:55:52 ----D---- C:\Windows\system32\catroot
2009-11-14 14:52:28 ----SHD---- C:\System Volume Information
2009-11-14 12:15:14 ----AD---- C:\Windows
2009-11-13 22:27:38 ----SHD---- C:\Windows\Installer
2009-11-13 19:14:11 ----D---- C:\Windows\system32\catroot2
2009-11-12 23:31:01 ----D---- C:\Windows\system32\config
2009-11-12 23:30:47 ----D---- C:\Windows\system32\wbem
2009-11-12 23:30:47 ----D---- C:\Windows\system32\Tasks
2009-11-12 23:30:47 ----D---- C:\Windows\system32\spool
20

1

Jerome_59, le 15 nov 2009 à 02:31:14

Ta battu le record du plus grand message de CCM ! :p

Répondre à Jerome_59

2

anthony5151, le 15 nov 2009 à 17:40:30

Bonjour,



1) Il y a une infection de disque amovible :

• Télécharge USBFix (de Chiquitine29 et C_XX) sur ton Bureau
• Branche tes sources de données externes à ton PC (clé USB, disque dur externe, lecteur mp3 etc...) sans les ouvrir
• Double clique sur le programme USBFix sur ton Bureau / Fais un clic droit sur le programme USBFix et choisis 'Exécuter en tant qu'administrateur'.
• Au menu principal, choisis l'option 2 (Suppression)
• Ton Bureau va disparaitre, puis l'ordinateur va redémarrer --> c'est normal
• Laisse travailler l'outil jusqu'au bout
• A la fin, le rapport va s'afficher --> poste le dans ta prochaine réponse stp

Aide en images : Nettoyage



2) Il y a sur ton ordinateur une infection Navipromo, qui affiche des publicités intempestives, et qui s'est installée via des programmes "gratuits", dont ceux-ci :

• Funky Emoticons
• Games Attack
• go-astro
• GoRecord
• HotTVPlayer / HotTVPlayer & Paris Hilton
• Live-Player
• MailSkinner
• Messenger Skinner
• Instant Access
• InternetGameBox
• Officiale Emule (Version d'Emule modifiée)
• Original-solitaire
• SuperSexPlayer
• Speed Downloading
• Sudoplanet
• Webmediaplayer


Pour désinfecter, merci de suivre exactement cette procédure :

• Télécharge Navilog1 (créé par IL-MAFIOSO) sur ton Bureau.
• Lance Navilog en faisant un clic-droit sur le raccourci présent sur ton Bureau et en choisissant "Exécuter en tant qu'administrateur"
• Au menu principal, fais le choix 1 (Recherche / Désinfection automatique)
• Si des éléments indésirables sont trouvés, navilog fera redémarrer l'ordinateur. Patiente alors jusqu'au message «Scan terminé le...»
• A la fin, le rapport (C:\cleannavi.txt) va s'ouvrir dans le bloc-notes, poste le dans ta prochaine réponse stp.

L'habit ne fait pas le moine.
Le savoir n'est utile que s'il est transmis

Répondre à anthony5151

3

manusss, le 21 nov 2009 à 19:07:22

Bonsoir;

x Navipromo version 4.0.5 commencé le 21/11/2009 18:45:20,19

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 X2 Mobile Technology TL-56 )
BIOS : Ver 1.00PARTTBL
USER : Emmanuel ( Administrator )
BOOT : Normal boot

Antivirus : avast! antivirus 4.8.1229 [VPS 090918-0] 4.8.1229 (Activated)


C:\ (Local Disk) - NTFS - Total:69 Go (Free:26 Go)
D:\ (Local Disk) - NTFS - Total:69 Go (Free:26 Go)
E:\ (CD or DVD)


Recherche executée en mode normal

Nettoyage exécuté au redémarrage de l'ordinateur


C:\Users\Emmanuel\AppData\Local\jfujet.bat supprimé !


Nettoyage contenu C:\Windows\Temp effectué !
Nettoyage contenu C:\Users\Emmanuel\AppData\Local\Temp effectué !


*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok




*** Scan terminé 21/11/2009 19:02:41,13 ***

merci par avance

Répondre à manusss

4

 anthony5151, le 21 nov 2009 à 21:01:17

Il manque le rapport USBFix ;)

Quand tu l'auras posté, fais redémarrer ton ordinateur et poste un nouveau rapport RSIT stp

L'habit ne fait pas le moine.
Le savoir n'est utile que s'il est transmis

Répondre à anthony5151
Collection CommentÇaMarche.net