Rapport HijackThis suite à pb de Rootkit-Gen

BurningShip -  
 Burning Ship -
Bonjour,

j'ai un problème avec un "Win32 : Rootkit-Gen" détecté par Avast depuis 3 jours. Ca a commencé avec le fichier suspect nmdfgds0.dll, puis le lendemain le logiciel malveillant em8tqm.cmd, détecté sur mes deux disques dures C: et D:

Au cours d'un scan au démarrage avec Avast j'ai mis pas mal de fichiers en quarantaine, et depuis mon ordinateur fonctionne bien. J'ai fait un scan avec AVG Anti-Rootkit qui n'a rien trouvé.

Cependant hier en voulant accéder à des fichiers stockés sur D: je suis passé par Poste de Travail, et là l'ordinateur m'a dit "D: n'existe pas", puis un autre message "Choisissez le programme pour ouvrir le fichier D:" (alors qu'il s'agit d'un disque dur, évidemment). Même message pour C:. Les fichiers n'ont pas disparus puisque les raccourcis que j'avais mis sur le bureau pour certains dossiers de photos fonctionnent toujours et je peux voir les images.

Qu'est-ce qui cloche ? Voilà un rapport Hijackthis :

--------------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25:23, on 28/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\Wireless Console\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://squirrelmail.eleves.ens.fr//src/login.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy-web.univ-paris4.fr/auto-proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Wireless Console] C:\Program Files\ASUS\Wireless Console\wcourier.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Zshutdown] c:\sysprep\patch\sysprep.cmd
O4 - HKLM\..\Run: [GameFace Messenger] C:\Program Files\GameFace Messenger\GameFace.exe
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O18 - Protocol: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll
O18 - Protocol: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c988733cd7b65a) (gupdate1c988733cd7b65a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
A voir également:

7 réponses

Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   572
 
salut,

Telecharges Ccleaner : https://filehippo.com/download_ccleaner/

- Pendant l'installation, décoches la case proposant la barre Yahoo et celle proposant d'ajouter l'options des mises a jours..
- Une fois installé, fermes toutes les applications en cours et lances Ccleaner
- clic sur mode avancé et décoche la case " effacer les fichiers du....plus vieux que 48h, ne touches pas aux autres parametres
- Clic sur "Nettoyeur " >> " analyse " >> et lances le nettoyage, puis refermes le programme
telecharge SDFix sur ton bureau : http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

- Fermes toutes les applications en cours, puis double clic sur le raccourci de ton bureau
- Clic sur " Install " pour l'extraire dans un dossier dedié

- Redemarres ton pc en mode sans echec :
- Au demarrage du pc, tapotes sur la touche F8 ou F5 du clavier juste aprés le bip du bios et avant le logo " windows "
- Un ecran avec plusieurs choix apparaitra > selectionnes " mode sans echec " et valides par la touche " Entrée " de ton clavier

- Une fois en " mode sans echec " , ouvres le fichier créé, puis double clic sur " Runthis.bat "
- Une fenetre noir apparait, appuies sur la touche " Y " pour lancer le nettoyage
- Le bureau va disparaitre, c'est normal
- L'outil va travailler, patientes jusqu'à la fin du scan
- Une fois terminé, Sdfix te signalera que l'ordi doit redemarrer, acceptes en pressant une touche..
- Le pc va redemarrer en mode normal, une fois ton bureau en place, il va générer un rapport
- Sauvegardes le et poste son contenu ( tu le trouveras aussi à c:\report.txt)
2
BurningShip
 
Ok je vais faire tout ça merci.

Pour commencer, Ccleaner : je ne trouve pas l'option "effacer les fichiers... plus vieux 48h" que je dois décocher. Dans le pg je vois une fenêtre, avec à gauche Nettoyeur, Registre, Outils et Options. C'est Nettoyeur qui est ouvert, et à l'ouverture aucune des options de la rubrique "Avancé" n'est cochée.

Je lance tel quel ou je dois vraiment trouver et décocher la case dont tu parles ?
0
BurningShip
 
Voilà le rapport SDFix

--------------------------------------------------------------------------------------

[b]SDFix: Version 1.240 [/b]
Run by Julien on 28/03/2009 at 12:23

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:\autorun.inf - Deleted
C:\WINDOWS\browser.exe - Deleted





Removing Temp Files

[b]ADS Check [/b]:



[b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 12:27:24
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\System32\\usmt\\migwiz.exe"="C:\\WINDOWS\\System32\\usmt\\migwiz.exe:*:Enabled:Assistant Transfert de fichiers et de paramŠtres"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe:*:Disabled:AOL"
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe:*:Disabled:AOL"
"C:\\Program Files\\ASUS\\ASUS Live Update\\LiveUpdt.exe"="C:\\Program Files\\ASUS\\ASUS Live Update\\LiveUpdt.exe:*:Enabled:LiveUpdt"
"C:\\WINDOWS\\System32\\rtcshare.exe"="C:\\WINDOWS\\System32\\rtcshare.exe:*:Enabled:Partage de l'application RTC"
"C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windows© NetMeeting©"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\AGE3.EXE"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\AGE3.EXE:*:Enabled:Age of Empires 3"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\SecondLife\\SLVoice.exe"="C:\\Program Files\\SecondLife\\SLVoice.exe:*:Enabled:SLVoice"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[b]Remaining Files [/b]:


File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:

Tue 16 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sun 8 Feb 2004 33,280 A..H. --- "C:\Documents and Settings\Julien\Mes documents\ARCHIVES JULIEN\Khƒgne\~WRL0543.tmp"
Sat 8 Jan 2005 24,064 A..H. --- "C:\Documents and Settings\Julien\Mes documents\ARCHIVES JULIEN\Khƒgne\~WRL2270.tmp"
Mon 25 Jun 2001 19,968 A..HR --- "C:\Documents and Settings\Julien\Mes documents\ARCHIVES JULIEN\Ecrire\L‚gŠret‚\~WRL1253.tmp"
Sun 15 Jan 2006 19,456 A..H. --- "C:\Documents and Settings\Julien\Mes documents\ARCHIVES JULIEN\Ecrire\L‚gŠret‚\~WRL2488.tmp"
Tue 8 May 2007 220,160 A..H. --- "C:\Documents and Settings\Julien\Mes documents\ARCHIVES TRAVAIL\M1\WHAT MAKES A GENERATION\Poubelle\~WRL0003.tmp"

[b]Finished![/b]
0
BurningShip > BurningShip
 
Dis-donc on apprend un paquet de choses sur moi avec ces rapports !

Est-ce que je pourrai supprimer ces messages à la fin ?
0
BurningShip > BurningShip
 
Tout fonctionne bien mais quand je clique sur D: depuis Poste de Travail il me demande toujours "Choisissez le programme pour ouvrir le fichier D:", CE QUI EST TOUT DE MEME BIZARRE !

Merci pour ton aide,

BS
0
Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   572
 
Ok, bien infecté :

Telecharges Combofix et enregistres le sur ton bureau

http://download.bleepingcomputer.com/sUBs/ComboFix.exe -

/!\ Desactives ton antivirus et la garde de ton antispyware ( si tu en as un) /!\

- Deconnectes toi et fermes toutes les applications en cours
- Double clic sur Combofix.exe >> un message apparait > réponds " oui "
- ( Il est conseillé d'installer la console de recuperations)
- Selectionnes la langue et presse la touche 1 ( yes) pour lancer le scan

/!\ Ne touche ni à la souris, ni au clavier durant le scan, cela pourrait figer l'ordi /!\

- A la fin du scan, Combofix aura besoin de redemarrer pour finir la desinfection, laisses le faire
- Une fois terminé, un rapport s'affiche, poste son contenu que tu peux aussi trouver à c:\combofix.txt
1
BurningShip
 
ComboFix 09-03-27.02 - Julien 2009-03-28 13:55:35.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.594 [GMT 1:00]
Lancé depuis: c:\documents and settings\Julien\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090327-0] *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_PCIDump


((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-28 ))))))))))))))))))))))))))))))))))))
.

2009-03-28 13:42 . 2009-03-28 13:42 <REP> d-------- C:\rsit
2009-03-28 12:22 . 2009-03-28 12:22 579,584 --a------ c:\windows\system32\dllcache\user32.dll
2009-03-28 12:20 . 2009-03-28 12:20 <REP> d-------- c:\windows\ERUNT
2009-03-28 12:04 . 2008-11-06 02:03 <REP> d-------- C:\SDFix
2009-03-28 11:41 . 2009-03-28 11:41 <REP> d-------- c:\program files\CCleaner
2009-03-28 11:25 . 2009-03-28 11:25 <REP> d-------- c:\program files\Trend Micro
2009-03-26 11:20 . 2007-01-18 13:00 3,968 --a------ c:\windows\system32\drivers\AvgArCln.sys
2009-03-16 00:05 . 2009-03-27 21:46 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-16 00:05 . 2009-03-16 00:05 1,409 --a------ c:\windows\QTFont.for
2009-03-11 21:10 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2009-03-11 21:10 . 2007-05-16 16:45 1,124,720 --a------ c:\windows\system32\D3DCompiler_34.dll
2009-03-11 21:10 . 2007-05-16 16:45 443,752 --a------ c:\windows\system32\d3dx10_34.dll
2009-03-11 21:10 . 2007-05-31 19:30 266,088 --a------ c:\windows\system32\xactengine2_8.dll
2009-03-11 21:10 . 2007-04-04 18:55 261,480 --a------ c:\windows\system32\xactengine2_7.dll
2009-03-11 21:10 . 2007-04-04 18:53 81,768 --a------ c:\windows\system32\xinput1_3.dll
2009-03-11 21:10 . 2007-05-31 19:29 18,280 --a------ c:\windows\system32\x3daudio1_2.dll
2009-03-11 21:08 . 2009-03-11 21:08 319 --a------ c:\windows\game.ini
2009-03-11 20:42 . 2009-03-11 20:42 <REP> d-------- c:\program files\Activision
2009-03-11 20:40 . 2009-03-11 20:40 <REP> d--hs---- c:\windows\ftpcache

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 14:05 1,846,912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 14:05 1,846,912 ------w c:\windows\system32\dllcache\win32k.sys
2009-01-21 18:06 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-16 20:15 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2006-04-18 17:20 10,779,136 ----a-w c:\program files\CJXP54LF.EXE
2008-11-28 20:00 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-11-28 20:00 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-11-28 20:00 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-11-28 20:00 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-11-28 20:00 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="1" [X]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-19 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2005-07-28 102400]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-23 7286784]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2003-09-19 172032]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2005-06-16 86016]
"Wireless Console"="c:\program files\ASUS\Wireless Console\wcourier.exe" [2005-07-22 57344]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-12-22 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-12-22 688218]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-05-31 401408]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-06-03 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-05-31 356352]
"RemoteControl"="c:\program files\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 32768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-28 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-21 136600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-06-03 185896]
"nwiz"="nwiz.exe" [2005-09-23 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 c:\windows\RTHDCPL.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
ASUS ChkMail.lnk - c:\program files\ASUS\Asus ChkMail\ChkMail.exe [2006-02-27 32768]
SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2006-10-10 217088]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2005-05-31 22:46 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\usmt\\migwiz.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\ASUS\\ASUS Live Update\\LiveUpdt.exe"=
"c:\\WINDOWS\\System32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\AGE3.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=

R0 R592;R592;c:\windows\system32\drivers\R592.sys [2004-10-15 57088]
R0 risdpntk;risdpntk;c:\windows\system32\drivers\risdpntk.sys [2004-10-15 27264]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-04 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-04 20560]
S2 gupdate1c988733cd7b65a;Google Update Service (gupdate1c988733cd7b65a);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-06 133104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - em8tqm.cmd
\Shell\open\Command - em8tqm.cmd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59c170bc-618c-11dc-bf2b-00150041ceb6}]
\Shell\AutoRun\command - H:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66acf430-2796-11db-be18-00150041ceb6}]
\Shell\AutoRun\command - H:\em8tqm.cmd
\Shell\open\Command - H:\em8tqm.cmd
.
Contenu du dossier 'Tâches planifiées'

2009-03-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-06 16:54]
.
- - - - ORPHELINS SUPPRIMES - - - -

WebBrowser-{8F6D9079-D956-4D31-B7CC-CE6FA3044EE5} - (no file)
HKCU-Run-Skype - c:\program files\Skype\Phone\Skype.exe
HKCU-Run-cdoosoft - c:\windows\system32\olhrwef.exe
HKLM-Run-Zshutdown - c:\sysprep\patch\sysprep.cmd
HKLM-Run-GameFace Messenger - c:\program files\GameFace Messenger\GameFace.exe
HKLM-Run-NB Probe - (no file)


.
------- Examen supplémentaire -------
.
uStart Page = https://squirrelmail.eleves.ens.fr//src/login.php
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - c:\program files\LizardTech\Express View\expressview.dll
Handler: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - c:\program files\LizardTech\Express View\expressview.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Julien\Application Data\Mozilla\Firefox\Profiles\bq0yv25m.default\
FF - prefs.js: browser.startup.homepage - hxxp://maps.google.com/?mid=1236432644
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 13:59:39
Windows 5.1.2600 Service Pack 3 FAT NTAPI

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(1044)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXE
c:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXE
c:\program files\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
c:\program files\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
c:\program files\INTEL\WIRELESS\BIN\1XCONFIG.EXE
c:\windows\ATKKBSERVICE.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\FICHIERS COMMUNS\LIGHTSCRIBE\LSSRVC.EXE
c:\windows\SYSTEM32\NVSVC32.EXE
c:\program files\INTEL\WIRELESS\BIN\OPROTSVC.EXE
c:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXE
c:\program files\ASUS\NB PROBE\SPM\SPMGR.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ALWIL SOFTWARE\AVAST4\ASHDISP.EXE
c:\windows\ATK0100\ATKOSD.EXE
c:\program files\SBC Self Support Tool\bin\mpbtn.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-03-28 14:01:44 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-28 13:01:42

Avant-CF: 8 686 698 496 octets libres
Après-CF: 8,650,817,536 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

192 --- E O F --- 2009-03-17 10:06:56
0
BurningShip > BurningShip
 
Le disque D: s'ouvre à nouveau normalement quand je clique dessus depuis Poste de Travail.

Est-ce que ça veut dire que tout est réglé ?

Enorme merci pour ton aide en tout cas !
0
Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   572
 
Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

- Fermes toutes les applications en cours et double clic sur RSIT.exe
- Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
- Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
- Postes le contenu des 2 rapports
0
BurningShip
 
Voilà LOG :
------------------------------------------------------------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Julien at 2009-03-28 13:42:00
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 8 GB (19%) free of 45 GB
Total RAM: 1023 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:42:05, on 28/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\Wireless Console\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Julien\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Julien.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.mail.ens.fr/clipper/src/login.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy-web.univ-paris4.fr/auto-proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Wireless Console] C:\Program Files\ASUS\Wireless Console\wcourier.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Zshutdown] c:\sysprep\patch\sysprep.cmd
O4 - HKLM\..\Run: [GameFace Messenger] C:\Program Files\GameFace Messenger\GameFace.exe
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll
O18 - Protocol: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c988733cd7b65a) (gupdate1c988733cd7b65a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
0
BurningShip
 
info.txt logfile of random's system information tool 1.06 2009-03-28 13:42:07

======Uninstall list======

-->C:\PROGRA~1\SBCSEL~1\CustomUninstall.exe SBC
-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Age of Empires III-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{485775E8-AEB8-46BD-922B-242879E03DD5}
Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
Asus ChkMail-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Asus\Asus ChkMail\Uninst.isu"
ASUS Enhanced Display Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x40c
ASUS Live Update-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ASUS\ASUS Live Update\Uninst.isu" -c"C:\Program Files\ASUS\ASUS Live Update\Uninst.dll"
ASUS VideoSecurity Online-->c:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{169E414A-37C7-434E-9021-27A03AE087CD}
Asus_A6_ScreenSaver-->C:\WINDOWS\Asus_A6_ScreenSaver.scr /u
ASUSDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
ATK0100 ACPI UTILITY-->C:\WINDOWS\ATK0100\XPunin.exe
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AVG Anti-Rootkit Free-->C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\Uninstall.exe
BisonCam, NB Pro-->C:\WINDOWS\BisonRem.exe
BroadJump Client Foundation-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BroadJump\Client Foundation\Uninst.isu" -c"C:\Program Files\BroadJump\Client Foundation\RmvBJCFD.dll" -b"CFD" -h"CFD" -a
BSPlayer-->"C:\Program Files\Webteh\BSplayer\uninstall.exe"
Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x040c
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CDex extraction audio-->"C:\Program Files\CDex_150\uninstall.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Free Video Converter V 1.4-->"C:\Program Files\Free Video Converter\unins000.exe"
Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x40c -removeonly
Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x40c -removeonly
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
HDAUDIO SoftV92 Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10431966\HXFSETUP.EXE -U -IHDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_10431966
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{3CCB732A-E472-4CF9-B1EE-F18365341FE0}
Intel(R) PROSet/Wireless Software-->C:\WINDOWS\Installer\iProInst.exe
J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
Lizardtech Express View Browser Plug-in-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9CD8FC8E-A1CA-4634-96BC-CD6B2D4797CC}\Setup.exe" -l0x9
mCore-->MsiExec.exe /I{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}
mDriver-->MsiExec.exe /I{28DA872A-0848-48CF-B749-19A198157A2A}
mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
mEoU.msi-->MsiExec.exe /I{B502B428-3386-40A9-98DB-079AAB72E64F}
mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
mIWCA-->MsiExec.exe /I{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}
mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
Mozilla Firefox (2.0.0.18)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
mZConfig-->MsiExec.exe /I{7CD7A451-7224-49C8-95EF-9A1859C66607}
NB Probe-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}\setup.exe" -l0x9
Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID=""
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
PCFriendly-->C:\Program Files\PCFriendly\inuninst.exe
PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
Power4 Gear-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4462AD13-F2AA-4CBD-9F95-293C38EED870}\setup.exe" -l0x9
PowerDirector-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" -uninstall
QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083} /l1036
RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Unity Web Player-->C:\Program Files\Unity\WebPlayer\Uninstall.exe
VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp (remove only)-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{01523985-2098-43AF-9C97-12B07BE02A9B}
Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinFlash-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\setup.exe" -l0x9
WinSCP 3.8 beta-->"C:\Program Files\WinSCP3\unins000.exe"
Wireless Console-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\setup.exe" -l0x9 -removeonly
Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"

======Hosts File======

127.0.0.1 localhost

======Security center information======

AV: avast! antivirus 4.8.1335 [VPS 090327-0]

======System event log======

Computer Name: TYLERDURDEN
Event Code: 7036
Message: Le service Service de transfert intelligent en arrière-plan est entré dans l'état : en cours d'exécution.

Record Number: 25158
Source Name: Service Control Manager
Time Written: 20090223024111.000000+060
Event Type: Informations
User:

Computer Name: TYLERDURDEN
Event Code: 7036
Message: Le service avast! Web Scanner est entré dans l'état : en cours d'exécution.

Record Number: 25157
Source Name: Service Control Manager
Time Written: 20090223024111.000000+060
Event Type: Informations
User:

Computer Name: TYLERDURDEN
Event Code: 7036
Message: Le service NLA (Network Location Awareness) est entré dans l'état : en cours d'exécution.

Record Number: 25156
Source Name: Service Control Manager
Time Written: 20090223024111.000000+060
Event Type: Informations
User:

Computer Name: TYLERDURDEN
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

Record Number: 25155
Source Name: Service Control Manager
Time Written: 20090223024111.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: TYLERDURDEN
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

Record Number: 25154
Source Name: Service Control Manager
Time Written: 20090223024111.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

=====Application event log=====

Computer Name: TYLERDURDEN
Event Code: 1904
Message:
Record Number: 8888
Source Name: HHCTRL
Time Written: 20081114131813.000000+060
Event Type: Informations
User:

Computer Name: TYLERDURDEN
Event Code: 1904
Message:
Record Number: 8887
Source Name: HHCTRL
Time Written: 20081114131813.000000+060
Event Type: Informations
User:

Computer Name: TYLERDURDEN
Event Code: 1904
Message:
Record Number: 8886
Source Name: HHCTRL
Time Written: 20081114131813.000000+060
Event Type: Informations
User:

Computer Name: TYLERDURDEN
Event Code: 1904
Message:
Record Number: 8885
Source Name: HHCTRL
Time Written: 20081114131813.000000+060
Event Type: Informations
User:

Computer Name: TYLERDURDEN
Event Code: 1904
Message:
Record Number: 8884
Source Name: HHCTRL
Time Written: 20081114131813.000000+060
Event Type: Informations
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Samsung\Samsung PC Studio 3\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
"PROCESSOR_REVISION"=0d08
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

-----------------EOF-----------------
0
Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   572
 
Re,

- En plus de RSIT, regardes le tuto pour ccleaner :

https://www.malekal.com/tutoriel-ccleaner/

Dis-donc on apprend un paquet de choses sur moi avec ces rapports !

Ah bon, tu peux me dire quoi de plus qu'un autre pc ?

Est-ce que je pourrai supprimer ces messages à la fin ?

dans ce cas, ce n'est pas sur un forum qu'il faut faire desinfecter ton pc, mais chez un technicien !!!
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   572
 
Télécharge ATF Cleaner par Atribune sur ton bureau : http://www.atribune.org/ccount/click.php?id=1
- Démarre ATF-Cleaner et coche toutes les cases.
- Clique sur <Empty Selected> et au message "Done Cleaning" sur <Ok>
NB : Si tu utilises Firefox ou Opera :
- Clique sur Firefox ou Opera en haut puis choisis <Select All>.
- Clique sur le bouton <Empty Selected> (NB : Si tu veux conserver tes mots de passe sauvegardés alors clique sur <No> à l'invite).
- Clique sur <Main> pour revenir à menu principal
- Clique sur <Exit>, du menu prinicipal, pour quitter ATFcleaner.
NB : Si le prefetch est nettoyé le redémarrage du PC sera plus lent.

-----------------------------

> Avec Combofix :
- Crée un nouveau document texte : clic droit de souris sur le bureau => Nouveau => Document Texte, et copie/colle dedans les lignes suivantes :

KILLALL::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mount
points2\{66acf430-2796-11db-be18-00150041ceb6}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mount
points2\{59c170bc-618c-11dc-bf2b-00150041ceb6}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mount
points2\D]

Files::
H:\em8tqm.cmd
c:\windows\QTFont.qfn
c:\windows\QTFont.for



- Enregistre ce fichier sous le nom CFScript (Type du fichier : tous les fichiers)
- Ferme tous tes navigateurs web (donc copie ou imprime les instructions suivantes avant si besoin est).
- Désactive ton antivirus et tes autres protections résidentes (ex : Spybot) si tu en as (c'est important).
- Fait un glisser/déposer de ce fichier CFScript sur le programme ComboFix.exe comme sur le lien :
http://img517.imageshack.us/img517/8662/cfscript10uc2.gif


( Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relâche alors le bouton de la souris).
- Combofix va démarrer puis<gras> une fenêtre bleue va apparaître. Au message qui s'affiche (Type 1 to continue, or 2 to abort) : tape 1 puis valide.
- Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal !
- Ne touche à rien tant que le scan n'est pas terminé sinon le PC peut planter !
- Une fois le scan achevé, un rapport va s'afficher: poste le stp.

. -----------------------------

- Telecharges Malwarebytes' Anti-Malware :
http://www.malwarebytes.org/mbam/program/mbam-setup.exe


- Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
- Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
- Executes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
- A la fin du scan clic sur " Afficher les resultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la selection "
- Si il a besoin de redemarrer le pc pour finir la desinfection, acceptes
- Un rapport s'etablira, postes son contenu.
----------------------------------
0
BurningShip
 
Hello,

je n'arrive pas à poster le log de Combofix, peut-être parce qu'il est très long. Quand je veux le coller dans la fenêtre d'IE le navigateur se fige et plante. Préfères-tu que je le colle en plusieurs segments ?

En revanche voilà le log de Malwarebytes, qui n'a rien détecté :




Malwarebytes' Anti-Malware 1.35
Version de la base de données: 1916
Windows 5.1.2600 Service Pack 3

29/03/2009 21:46:21
mbam-log-2009-03-29 (21-46-21).txt

Type de recherche: Examen rapide
Eléments examinés: 66022
Temps écoulé: 3 minute(s), 9 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
0
BurningShip
 
Voilà le rapport de Combofix, que j'ai réussi à coller ici en utilisant Firefox au lieu d'IE.

J'attends tes instructions, merci beaucoup pour ton aide !


--------------------------------------


ComboFix 09-03-27.02 - Julien 2009-03-29 21:24:09.2 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.601 [GMT 2:00]
Lancé depuis: c:\documents and settings\Julien\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Julien\Bureau\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090329-0] *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-29 ))))))))))))))))))))))))))))))))))))
.

2009-03-28 13:42 . 2009-03-28 13:42 <REP> d-------- C:\rsit
2009-03-28 12:22 . 2009-03-28 12:22 579,584 --a------ c:\windows\system32\dllcache\user32.dll
2009-03-28 12:20 . 2009-03-28 12:20 <REP> d-------- c:\windows\ERUNT
2009-03-28 12:04 . 2008-11-06 02:03 <REP> d-------- C:\SDFix
2009-03-28 11:41 . 2009-03-28 11:41 <REP> d-------- c:\program files\CCleaner
2009-03-28 11:25 . 2009-03-28 11:25 <REP> d-------- c:\program files\Trend Micro
2009-03-26 11:20 . 2007-01-18 13:00 3,968 --a------ c:\windows\system32\drivers\AvgArCln.sys
2009-03-16 00:05 . 2009-03-27 21:46 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-16 00:05 . 2009-03-16 00:05 1,409 --a------ c:\windows\QTFont.for
2009-03-11 21:10 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2009-03-11 21:10 . 2007-05-16 16:45 1,124,720 --a------ c:\windows\system32\D3DCompiler_34.dll
2009-03-11 21:10 . 2007-05-16 16:45 443,752 --a------ c:\windows\system32\d3dx10_34.dll
2009-03-11 21:10 . 2007-05-31 19:30 266,088 --a------ c:\windows\system32\xactengine2_8.dll
2009-03-11 21:10 . 2007-04-04 18:55 261,480 --a------ c:\windows\system32\xactengine2_7.dll
2009-03-11 21:10 . 2007-04-04 18:53 81,768 --a------ c:\windows\system32\xinput1_3.dll
2009-03-11 21:10 . 2007-05-31 19:29 18,280 --a------ c:\windows\system32\x3daudio1_2.dll
2009-03-11 21:08 . 2009-03-11 21:08 319 --a------ c:\windows\game.ini
2009-03-11 20:42 . 2009-03-11 20:42 <REP> d-------- c:\program files\Activision
2009-03-11 20:40 . 2009-03-11 20:40 <REP> d--hs---- c:\windows\ftpcache

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 13:05 1,846,912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 13:05 1,846,912 ------w c:\windows\system32\dllcache\win32k.sys
2009-01-21 17:06 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-16 19:15 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2006-04-18 16:20 10,779,136 ----a-w c:\program files\CJXP54LF.EXE
2008-11-28 19:00 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-11-28 19:00 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-11-28 19:00 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-11-28 19:00 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-11-28 19:00 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-03-28_14.01.01.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-11-17 18:41:20 354,304 ------w c:\windows\$hf_mig$\KB873339\SP2QFE\hypertrm.dll
+ 2004-11-17 17:41:20 354,304 ------w c:\windows\$hf_mig$\KB873339\SP2QFE\hypertrm.dll
- 2004-10-14 09:35:08 8,192 ------w c:\windows\$hf_mig$\KB873339\spmsg.dll
+ 2004-10-14 08:35:08 8,192 ------w c:\windows\$hf_mig$\KB873339\spmsg.dll
- 2004-10-14 09:36:22 172,032 ------w c:\windows\$hf_mig$\KB873339\spuninst.exe
+ 2004-10-14 08:36:22 172,032 ------w c:\windows\$hf_mig$\KB873339\spuninst.exe
- 2004-10-14 09:36:20 21,504 ------w c:\windows\$hf_mig$\KB873339\update\spcustom.dll
+ 2004-10-14 08:36:20 21,504 ------w c:\windows\$hf_mig$\KB873339\update\spcustom.dll
- 2004-10-14 09:35:12 666,624 ------w c:\windows\$hf_mig$\KB873339\update\update.exe
+ 2004-10-14 08:35:12 666,624 ------w c:\windows\$hf_mig$\KB873339\update\update.exe
- 2005-01-19 04:51:58 451,584 ------w c:\windows\$hf_mig$\KB885250\SP2QFE\mrxsmb.sys
+ 2005-01-19 03:51:58 451,584 ------w c:\windows\$hf_mig$\KB885250\SP2QFE\mrxsmb.sys
- 2004-11-30 13:46:52 8,192 ------w c:\windows\$hf_mig$\KB885250\spmsg.dll
+ 2004-11-30 12:46:52 8,192 ------w c:\windows\$hf_mig$\KB885250\spmsg.dll
- 2004-11-30 19:22:42 172,032 ------w c:\windows\$hf_mig$\KB885250\spuninst.exe
+ 2004-11-30 18:22:42 172,032 ------w c:\windows\$hf_mig$\KB885250\spuninst.exe
- 2004-11-30 19:22:42 21,504 ------w c:\windows\$hf_mig$\KB885250\update\spcustom.dll
+ 2004-11-30 18:22:42 21,504 ------w c:\windows\$hf_mig$\KB885250\update\spcustom.dll
- 2004-11-30 13:46:52 666,624 ------w c:\windows\$hf_mig$\KB885250\update\update.exe
+ 2004-11-30 12:46:52 666,624 ------w c:\windows\$hf_mig$\KB885250\update\update.exe
- 2004-10-28 02:29:48 728,576 ------w c:\windows\$hf_mig$\KB885835\SP2QFE\lsasrv.dll
+ 2004-10-28 01:29:48 728,576 ------w c:\windows\$hf_mig$\KB885835\SP2QFE\lsasrv.dll
- 2004-10-28 02:15:16 448,128 ------w c:\windows\$hf_mig$\KB885835\SP2QFE\mrxsmb.sys
+ 2004-10-28 01:15:16 448,128 ------w c:\windows\$hf_mig$\KB885835\SP2QFE\mrxsmb.sys
- 2004-10-28 02:14:56 174,592 ------w c:\windows\$hf_mig$\KB885835\SP2QFE\rdbss.sys
+ 2004-10-28 01:14:56 174,592 ------w c:\windows\$hf_mig$\KB885835\SP2QFE\rdbss.sys
- 2004-10-14 10:35:08 8,192 ------w c:\windows\$hf_mig$\KB885835\spmsg.dll
+ 2004-10-14 09:35:08 8,192 ------w c:\windows\$hf_mig$\KB885835\spmsg.dll
- 2004-10-14 10:36:22 172,032 ------w c:\windows\$hf_mig$\KB885835\spuninst.exe
+ 2004-10-14 09:36:22 172,032 ------w c:\windows\$hf_mig$\KB885835\spuninst.exe
- 2004-10-14 10:36:20 21,504 ------w c:\windows\$hf_mig$\KB885835\update\spcustom.dll
+ 2004-10-14 09:36:20 21,504 ------w c:\windows\$hf_mig$\KB885835\update\spcustom.dll
- 2004-10-14 10:35:12 666,624 ------w c:\windows\$hf_mig$\KB885835\update\update.exe
+ 2004-10-14 09:35:12 666,624 ------w c:\windows\$hf_mig$\KB885835\update\update.exe
- 2004-10-14 10:35:08 8,192 ------w c:\windows\$hf_mig$\KB885836\spmsg.dll
+ 2004-10-14 09:35:08 8,192 ------w c:\windows\$hf_mig$\KB885836\spmsg.dll
- 2004-10-14 10:36:22 172,032 ------w c:\windows\$hf_mig$\KB885836\spuninst.exe
+ 2004-10-14 09:36:22 172,032 ------w c:\windows\$hf_mig$\KB885836\spuninst.exe
- 2004-10-14 10:36:20 21,504 ------w c:\windows\$hf_mig$\KB885836\update\spcustom.dll
+ 2004-10-14 09:36:20 21,504 ------w c:\windows\$hf_mig$\KB885836\update\spcustom.dll
- 2004-10-14 10:35:12 666,624 ------w c:\windows\$hf_mig$\KB885836\update\update.exe
+ 2004-10-14 09:35:12 666,624 ------w c:\windows\$hf_mig$\KB885836\update\update.exe
- 2004-09-29 23:31:18 134,912 ------w c:\windows\$hf_mig$\KB886185\SP2QFE\ipnat.sys
+ 2004-09-29 22:31:18 134,912 ------w c:\windows\$hf_mig$\KB886185\SP2QFE\ipnat.sys
- 2004-10-14 19:35:06 8,192 ------w c:\windows\$hf_mig$\KB886185\spmsg.dll
+ 2004-10-14 18:35:06 8,192 ------w c:\windows\$hf_mig$\KB886185\spmsg.dll
- 2004-10-14 19:36:20 172,032 ------w c:\windows\$hf_mig$\KB886185\spuninst.exe
+ 2004-10-14 18:36:20 172,032 ------w c:\windows\$hf_mig$\KB886185\spuninst.exe
- 2004-10-14 19:36:20 21,504 ------w c:\windows\$hf_mig$\KB886185\update\spcustom.dll
+ 2004-10-14 18:36:20 21,504 ------w c:\windows\$hf_mig$\KB886185\update\spcustom.dll
- 2004-10-14 19:35:12 666,624 ------w c:\windows\$hf_mig$\KB886185\update\update.exe
+ 2004-10-14 18:35:12 666,624 ------w c:\windows\$hf_mig$\KB886185\update\update.exe
- 2004-10-13 17:21:24 1,694,208 ------w c:\windows\$hf_mig$\KB887472\SP2QFE\msmsgs.exe
+ 2004-10-13 16:21:24 1,694,208 ------w c:\windows\$hf_mig$\KB887472\SP2QFE\msmsgs.exe
- 2004-10-14 10:35:08 8,192 ------w c:\windows\$hf_mig$\KB887472\spmsg.dll
+ 2004-10-14 09:35:08 8,192 ------w c:\windows\$hf_mig$\KB887472\spmsg.dll
- 2004-10-14 10:36:22 172,032 ------w c:\windows\$hf_mig$\KB887472\spuninst.exe
+ 2004-10-14 09:36:22 172,032 ------w c:\windows\$hf_mig$\KB887472\spuninst.exe
- 2004-10-14 10:36:20 21,504 ------w c:\windows\$hf_mig$\KB887472\update\spcustom.dll
+ 2004-10-14 09:36:20 21,504 ------w c:\windows\$hf_mig$\KB887472\update\spcustom.dll
- 2004-10-14 10:35:12 666,624 ------w c:\windows\$hf_mig$\KB887472\update\update.exe
+ 2004-10-14 09:35:12 666,624 ------w c:\windows\$hf_mig$\KB887472\update\update.exe
- 2004-10-09 00:18:28 262,272 ------w c:\windows\$hf_mig$\KB887742\SP2QFE\http.sys
+ 2004-10-08 23:18:28 262,272 ------w c:\windows\$hf_mig$\KB887742\SP2QFE\http.sys
- 2004-10-14 09:35:08 8,192 ------w c:\windows\$hf_mig$\KB887742\spmsg.dll
+ 2004-10-14 08:35:08 8,192 ------w c:\windows\$hf_mig$\KB887742\spmsg.dll
- 2004-10-14 09:36:22 172,032 ------w c:\windows\$hf_mig$\KB887742\spuninst.exe
+ 2004-10-14 08:36:22 172,032 ------w c:\windows\$hf_mig$\KB887742\spuninst.exe
- 2004-10-14 09:36:20 21,504 ------w c:\windows\$hf_mig$\KB887742\update\spcustom.dll
+ 2004-10-14 08:36:20 21,504 ------w c:\windows\$hf_mig$\KB887742\update\spcustom.dll
- 2004-10-14 09:35:12 666,624 ------w c:\windows\$hf_mig$\KB887742\update\update.exe
+ 2004-10-14 08:35:12 666,624 ------w c:\windows\$hf_mig$\KB887742\update\update.exe
- 2004-11-16 22:16:08 68,608 ------w c:\windows\$hf_mig$\KB888113\SP2QFE\hlink.dll
+ 2004-11-16 21:16:08 68,608 ------w c:\windows\$hf_mig$\KB888113\SP2QFE\hlink.dll
- 2004-10-14 09:35:08 8,192 ------w c:\windows\$hf_mig$\KB888113\spmsg.dll
+ 2004-10-14 08:35:08 8,192 ------w c:\windows\$hf_mig$\KB888113\spmsg.dll
- 2004-10-14 09:36:22 172,032 ------w c:\windows\$hf_mig$\KB888113\spuninst.exe
+ 2004-10-14 08:36:22 172,032 ------w c:\windows\$hf_mig$\KB888113\spuninst.exe
- 2004-10-14 09:36:20 21,504 ------w c:\windows\$hf_mig$\KB888113\update\spcustom.dll
+ 2004-10-14 08:36:20 21,504 ------w c:\windows\$hf_mig$\KB888113\update\spcustom.dll
- 2004-10-14 09:35:12 666,624 ------w c:\windows\$hf_mig$\KB888113\update\update.exe
+ 2004-10-14 08:35:12 666,624 ------w c:\windows\$hf_mig$\KB888113\update\update.exe
- 2004-12-07 20:32:32 96,768 ------w c:\windows\$hf_mig$\KB888302\SP2QFE\srvsvc.dll
+ 2004-12-07 19:32:32 96,768 ------w c:\windows\$hf_mig$\KB888302\SP2QFE\srvsvc.dll
- 2004-11-30 13:46:52 8,192 ------w c:\windows\$hf_mig$\KB888302\spmsg.dll
+ 2004-11-30 12:46:52 8,192 ------w c:\windows\$hf_mig$\KB888302\spmsg.dll
- 2004-11-30 19:22:42 172,032 ------w c:\windows\$hf_mig$\KB888302\spuninst.exe
+ 2004-11-30 18:22:42 172,032 ------w c:\windows\$hf_mig$\KB888302\spuninst.exe
- 2004-11-30 19:22:42 21,504 ------w c:\windows\$hf_mig$\KB888302\update\spcustom.dll
+ 2004-11-30 18:22:42 21,504 ------w c:\windows\$hf_mig$\KB888302\update\spcustom.dll
- 2004-11-30 13:46:52 666,624 ------w c:\windows\$hf_mig$\KB888302\update\update.exe
+ 2004-11-30 12:46:52 666,624 ------w c:\windows\$hf_mig$\KB888302\update\update.exe
- 2005-04-22 06:20:20 57,344 ------w c:\windows\$hf_mig$\KB890046\SP2QFE\agentdpv.dll
+ 2005-04-22 05:20:20 57,344 ------w c:\windows\$hf_mig$\KB890046\SP2QFE\agentdpv.dll
- 2005-05-17 01:44:44 19,456 ------w c:\windows\$hf_mig$\KB890046\SP2QFE\spru040c.dll
+ 2005-05-17 00:44:44 19,456 ------w c:\windows\$hf_mig$\KB890046\SP2QFE\spru040c.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB890046\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB890046\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB890046\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB890046\spuninst.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB890046\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB890046\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB890046\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB890046\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB890046\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB890046\update\updspapi.dll
- 2005-03-02 19:20:32 62,464 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\authz.dll
+ 2005-03-02 18:20:32 62,464 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\authz.dll
- 2005-03-02 19:13:14 2,137,600 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlmp.exe
+ 2005-03-02 18:13:14 2,137,600 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlmp.exe
- 2005-03-02 19:13:12 2,059,008 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
+ 2005-03-02 18:13:12 2,059,008 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
- 2005-03-02 19:13:16 2,017,280 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrpamp.exe
+ 2005-03-02 18:13:16 2,017,280 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrpamp.exe
- 2005-03-02 19:13:24 2,181,632 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
+ 2005-03-02 18:13:24 2,181,632 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
- 2005-03-02 19:20:32 578,048 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
+ 2005-03-02 18:20:32 578,048 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
- 2005-03-02 19:13:08 1,836,416 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\win32k.sys
+ 2005-03-02 18:13:08 1,836,416 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\win32k.sys
- 2005-03-02 19:20:32 291,840 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\winsrv.dll
+ 2005-03-02 18:20:32 291,840 ------w c:\windows\$hf_mig$\KB890859\SP2QFE\winsrv.dll
- 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB890859\spmsg.dll
+ 2005-02-24 17:35:26 15,072 ------w c:\windows\$hf_mig$\KB890859\spmsg.dll
- 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB890859\spuninst.exe
+ 2005-02-24 17:35:26 213,216 ------w c:\windows\$hf_mig$\KB890859\spuninst.exe
- 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB890859\update\spcustom.dll
+ 2005-02-24 17:35:26 22,240 ------w c:\windows\$hf_mig$\KB890859\update\spcustom.dll
- 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB890859\update\update.exe
+ 2005-02-24 17:35:26 730,336 ------w c:\windows\$hf_mig$\KB890859\update\update.exe
- 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB890859\update\updspapi.dll
+ 2005-02-24 17:35:26 395,488 ------w c:\windows\$hf_mig$\KB890859\update\updspapi.dll
- 2004-11-30 13:46:52 8,192 ------w c:\windows\$hf_mig$\KB891781\spmsg.dll
+ 2004-11-30 12:46:52 8,192 ------w c:\windows\$hf_mig$\KB891781\spmsg.dll
- 2004-11-30 19:22:42 172,032 ------w c:\windows\$hf_mig$\KB891781\spuninst.exe
+ 2004-11-30 18:22:42 172,032 ------w c:\windows\$hf_mig$\KB891781\spuninst.exe
- 2004-11-30 19:22:42 21,504 ------w c:\windows\$hf_mig$\KB891781\update\spcustom.dll
+ 2004-11-30 18:22:42 21,504 ------w c:\windows\$hf_mig$\KB891781\update\spcustom.dll
- 2004-11-30 13:46:52 666,624 ------w c:\windows\$hf_mig$\KB891781\update\update.exe
+ 2004-11-30 12:46:52 666,624 ------w c:\windows\$hf_mig$\KB891781\update\update.exe
- 2005-07-08 17:30:34 249,344 ------w c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
+ 2005-07-08 16:30:34 249,344 ------w c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB893756\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB893756\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB893756\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB893756\spuninst.exe
- 2005-07-07 18:27:08 30,720 ------w c:\windows\$hf_mig$\KB893756\update\arpidfix.exe
+ 2005-07-07 17:27:08 30,720 ------w c:\windows\$hf_mig$\KB893756\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB893756\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB893756\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB893756\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB893756\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB893756\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB893756\update\updspapi.dll
- 2005-04-28 20:36:10 1,286,144 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\ole32.dll
+ 2005-04-28 19:36:10 1,286,144 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\ole32.dll
- 2005-04-28 20:36:10 75,264 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\olecli32.dll
+ 2005-04-28 19:36:10 75,264 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\olecli32.dll
- 2005-04-28 20:36:10 37,376 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\olecnv32.dll
+ 2005-04-28 19:36:10 37,376 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\olecnv32.dll
- 2005-04-28 20:36:10 396,288 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
+ 2005-04-28 19:36:10 396,288 ------w c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB894391\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB894391\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB894391\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB894391\spuninst.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB894391\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB894391\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB894391\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB894391\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB894391\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB894391\update\updspapi.dll
- 2005-05-27 00:26:50 10,752 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\hh.exe
+ 2005-05-26 23:26:50 10,752 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\hh.exe
- 2005-05-27 03:11:04 41,472 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\hhsetup.dll
+ 2005-05-27 02:11:04 41,472 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\hhsetup.dll
- 2005-05-27 03:11:04 155,136 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\itircl.dll
+ 2005-05-27 02:11:04 155,136 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\itircl.dll
- 2005-05-27 03:11:04 137,216 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\itss.dll
+ 2005-05-27 02:11:04 137,216 ------w c:\windows\$hf_mig$\KB896358\SP2QFE\itss.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB896358\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB896358\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB896358\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB896358\spuninst.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB896358\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB896358\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB896358\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB896358\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB896358\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB896358\update\updspapi.dll
- 2005-05-10 01:22:22 332,544 ------w c:\windows\$hf_mig$\KB896422\SP2QFE\srv.sys
+ 2005-05-10 00:22:22 332,544 ------w c:\windows\$hf_mig$\KB896422\SP2QFE\srv.sys
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB896422\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB896422\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB896422\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB896422\spuninst.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB896422\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB896422\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB896422\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB896422\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB896422\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB896422\update\updspapi.dll
- 2005-06-11 01:17:14 57,856 ------w c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
+ 2005-06-11 00:17:14 57,856 ------w c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB896423\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB896423\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB896423\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB896423\spuninst.exe
- 2005-06-29 15:54:32 30,720 ------w c:\windows\$hf_mig$\KB896423\update\arpidfix.exe
+ 2005-06-29 14:54:32 30,720 ------w c:\windows\$hf_mig$\KB896423\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB896423\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB896423\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB896423\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB896423\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB896423\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB896423\update\updspapi.dll
- 2005-10-06 04:19:52 280,064 ------w c:\windows\$hf_mig$\KB896424\SP2QFE\gdi32.dll
+ 2005-10-06 03:19:52 280,064 ------w c:\windows\$hf_mig$\KB896424\SP2QFE\gdi32.dll
- 2005-10-06 04:12:58 1,839,616 ------w c:\windows\$hf_mig$\KB896424\SP2QFE\win32k.sys
+ 2005-10-06 03:12:58 1,839,616 ------w c:\windows\$hf_mig$\KB896424\SP2QFE\win32k.sys
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB896424\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB896424\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB896424\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB896424\spuninst.exe
- 2005-10-05 15:39:46 30,720 ------w c:\windows\$hf_mig$\KB896424\update\arpidfix.exe
+ 2005-10-05 14:39:46 30,720 ------w c:\windows\$hf_mig$\KB896424\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB896424\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB896424\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB896424\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB896424\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB896424\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB896424\update\updspapi.dll
- 2005-05-11 03:33:20 78,336 ------w c:\windows\$hf_mig$\KB896428\SP2QFE\telnet.exe
+ 2005-05-11 02:33:20 78,336 ------w c:\windows\$hf_mig$\KB896428\SP2QFE\telnet.exe
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB896428\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB896428\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB896428\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB896428\spuninst.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB896428\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB896428\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB896428\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB896428\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB896428\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB896428\update\updspapi.dll
- 2005-02-25 04:35:24 15,072 ------w c:\windows\$hf_mig$\KB898461\spmsg.dll
+ 2005-02-25 03:35:24 15,072 ------w c:\windows\$hf_mig$\KB898461\spmsg.dll
- 2005-02-25 04:35:24 213,216 ------w c:\windows\$hf_mig$\KB898461\spuninst.exe
+ 2005-02-25 03:35:24 213,216 ------w c:\windows\$hf_mig$\KB898461\spuninst.exe
- 2005-02-25 04:35:24 22,752 ------w c:\windows\$hf_mig$\KB898461\spupdsvc.exe
+ 2005-02-25 03:35:24 22,752 ------w c:\windows\$hf_mig$\KB898461\spupdsvc.exe
- 2005-02-25 04:35:24 22,240 ------w c:\windows\$hf_mig$\KB898461\update\spcustom.dll
+ 2005-02-25 03:35:24 22,240 ------w c:\windows\$hf_mig$\KB898461\update\spcustom.dll
- 2005-02-25 04:35:24 730,336 ------w c:\windows\$hf_mig$\KB898461\update\update.exe
+ 2005-02-25 03:35:24 730,336 ------w c:\windows\$hf_mig$\KB898461\update\update.exe
- 2005-02-25 04:35:26 395,488 ------w c:\windows\$hf_mig$\KB898461\update\updspapi.dll
+ 2005-02-25 03:35:26 395,488 ------w c:\windows\$hf_mig$\KB898461\update\updspapi.dll
- 2005-06-15 18:48:50 297,984 ------w c:\windows\$hf_mig$\KB899587\SP2QFE\kerberos.dll
+ 2005-06-15 17:48:50 297,984 ------w c:\windows\$hf_mig$\KB899587\SP2QFE\kerberos.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB899587\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB899587\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB899587\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB899587\spuninst.exe
- 2005-06-29 15:54:32 30,720 ------w c:\windows\$hf_mig$\KB899587\update\arpidfix.exe
+ 2005-06-29 14:54:32 30,720 ------w c:\windows\$hf_mig$\KB899587\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB899587\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB899587\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB899587\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB899587\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB899587\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB899587\update\updspapi.dll
- 2005-06-10 05:06:02 139,528 ------w c:\windows\$hf_mig$\KB899591\SP2QFE\rdpwd.sys
+ 2005-06-10 04:06:02 139,528 ------w c:\windows\$hf_mig$\KB899591\SP2QFE\rdpwd.sys
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB899591\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB899591\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB899591\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB899591\spuninst.exe
- 2005-06-29 15:54:32 30,720 ------w c:\windows\$hf_mig$\KB899591\update\arpidfix.exe
+ 2005-06-29 14:54:32 30,720 ------w c:\windows\$hf_mig$\KB899591\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB899591\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB899591\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB899591\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB899591\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB899591\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB899591\update\updspapi.dll
- 2006-02-15 01:30:08 142,464 ------w c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
+ 2006-02-15 00:30:08 142,464 ------w c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB900485\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB900485\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB900485\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB900485\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB900485\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB900485\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB900485\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB900485\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB900485\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB900485\update\updspapi.dll
- 2005-09-01 02:46:30 19,968 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
+ 2005-09-01 01:46:30 19,968 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
- 2005-09-23 04:26:14 8,508,928 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\shell32.dll
+ 2005-09-23 03:26:14 8,508,928 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\shell32.dll
- 2005-09-03 01:08:22 474,624 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\shlwapi.dll
+ 2005-09-03 00:08:22 474,624 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\shlwapi.dll
- 2005-09-27 01:47:42 23,552 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\spru040c.dll
+ 2005-09-27 00:47:42 23,552 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\spru040c.dll
- 2005-09-01 02:46:32 292,352 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\winsrv.dll
+ 2005-09-01 01:46:32 292,352 ------w c:\windows\$hf_mig$\KB900725\SP2QFE\winsrv.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB900725\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB900725\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB900725\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB900725\spuninst.exe
- 2005-09-26 16:36:24 30,720 ------w c:\windows\$hf_mig$\KB900725\update\arpidfix.exe
+ 2005-09-26 15:36:24 30,720 ------w c:\windows\$hf_mig$\KB900725\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB900725\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB900725\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB900725\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB900725\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB900725\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB900725\update\updspapi.dll
- 2005-09-10 02:53:06 2,068,480 ------w c:\windows\$hf_mig$\KB901017\SP2QFE\cdosys.dll
+ 2005-09-10 01:53:06 2,068,480 ------w c:\windows\$hf_mig$\KB901017\SP2QFE\cdosys.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB901017\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB901017\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB901017\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB901017\spuninst.exe
- 2005-09-09 15:26:26 30,720 ------w c:\windows\$hf_mig$\KB901017\update\arpidfix.exe
+ 2005-09-09 14:26:26 30,720 ------w c:\windows\$hf_mig$\KB901017\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB901017\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB901017\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB901017\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB901017\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB901017\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB901017\update\updspapi.dll
- 2005-06-29 02:54:24 254,976 ------w c:\windows\$hf_mig$\KB901214\SP2QFE\icm32.dll
+ 2005-06-29 01:54:24 254,976 ------w c:\windows\$hf_mig$\KB901214\SP2QFE\icm32.dll
- 2005-06-29 02:54:24 73,728 ------w c:\windows\$hf_mig$\KB901214\SP2QFE\mscms.dll
+ 2005-06-29 01:54:24 73,728 ------w c:\windows\$hf_mig$\KB901214\SP2QFE\mscms.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB901214\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB901214\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB901214\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB901214\spuninst.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB901214\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB901214\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB901214\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB901214\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB901214\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB901214\update\updspapi.dll
- 2005-07-26 05:29:18 225,792 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\catsrv.dll
+ 2005-07-26 04:29:18 225,792 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\catsrv.dll
- 2005-07-26 05:29:20 625,152 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\catsrvut.dll
+ 2005-07-26 04:29:20 625,152 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\catsrvut.dll
- 2005-07-26 05:29:20 110,080 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\clbcatex.dll
+ 2005-07-26 04:29:20 110,080 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\clbcatex.dll
- 2005-07-26 05:29:22 498,688 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\clbcatq.dll
+ 2005-07-26 04:29:22 498,688 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\clbcatq.dll
- 2005-07-26 05:29:22 60,416 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\colbact.dll
+ 2005-07-26 04:29:22 60,416 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\colbact.dll
- 2005-07-26 05:29:22 195,072 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comadmin.dll
+ 2005-07-26 04:29:22 195,072 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comadmin.dll
- 2005-07-26 05:29:24 97,792 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comrepl.dll
+ 2005-07-26 04:29:24 97,792 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comrepl.dll
- 2005-07-26 05:29:26 1,267,200 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comsvcs.dll
+ 2005-07-26 04:29:26 1,267,200 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comsvcs.dll
- 2005-07-26 05:29:28 540,160 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comuid.dll
+ 2005-07-26 04:29:28 540,160 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\comuid.dll
- 2005-07-26 05:29:28 243,200 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
+ 2005-07-26 04:29:28 243,200 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
- 2005-07-26 00:42:36 8,704 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\migregdb.exe
+ 2005-07-25 23:42:36 8,704 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\migregdb.exe
- 2005-07-26 05:29:30 425,472 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\msdtcprx.dll
+ 2005-07-26 04:29:30 425,472 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\msdtcprx.dll
- 2005-07-26 05:29:32 945,152 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\msdtctm.dll
+ 2005-07-26 04:29:32 945,152 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\msdtctm.dll
- 2005-07-26 05:29:32 161,280 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\msdtcuiu.dll
+ 2005-07-26 04:29:32 161,280 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\msdtcuiu.dll
- 2005-07-26 05:29:32 66,560 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\mtxclu.dll
+ 2005-07-26 04:29:32 66,560 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\mtxclu.dll
- 2005-07-26 05:29:32 91,136 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\mtxoci.dll
+ 2005-07-26 04:29:32 91,136 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\mtxoci.dll
- 2005-07-26 05:29:38 1,285,632 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\ole32.dll
+ 2005-07-26 04:29:38 1,285,632 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\ole32.dll
- 2005-07-26 05:29:38 75,264 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\olecli32.dll
+ 2005-07-26 04:29:38 75,264 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\olecli32.dll
- 2005-07-26 05:29:38 37,376 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\olecnv32.dll
+ 2005-07-26 04:29:38 37,376 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\olecnv32.dll
- 2005-07-26 05:29:40 398,336 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
+ 2005-07-26 04:29:40 398,336 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
- 2005-07-26 05:29:40 101,376 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\txflog.dll
+ 2005-07-26 04:29:40 101,376 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\txflog.dll
- 2005-07-26 05:29:40 11,776 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\xolehlp.dll
+ 2005-07-26 04:29:40 11,776 ------w c:\windows\$hf_mig$\KB902400\SP2QFE\xolehlp.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB902400\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB902400\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB902400\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB902400\spuninst.exe
- 2005-07-25 18:21:18 30,720 ------w c:\windows\$hf_mig$\KB902400\update\arpidfix.exe
+ 2005-07-25 17:21:18 30,720 ------w c:\windows\$hf_mig$\KB902400\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB902400\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB902400\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB902400\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB902400\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB902400\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB902400\update\updspapi.dll
- 2005-08-30 05:16:04 1,293,824 ------w c:\windows\$hf_mig$\KB904706\SP2QFE\quartz.dll
+ 2005-08-30 04:16:04 1,293,824 ------w c:\windows\$hf_mig$\KB904706\SP2QFE\quartz.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB904706\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB904706\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB904706\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB904706\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB904706\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB904706\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB904706\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB904706\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB904706\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB904706\update\updspapi.dll
- 2005-08-22 19:26:28 197,632 ------w c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
+ 2005-08-22 18:26:28 197,632 ------w c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
- 2005-02-25 04:35:24 15,072 ------w c:\windows\$hf_mig$\KB905414\spmsg.dll
+ 2005-02-25 03:35:24 15,072 ------w c:\windows\$hf_mig$\KB905414\spmsg.dll
- 2005-02-25 04:35:24 213,216 ------w c:\windows\$hf_mig$\KB905414\spuninst.exe
+ 2005-02-25 03:35:24 213,216 ------w c:\windows\$hf_mig$\KB905414\spuninst.exe
- 2005-08-20 00:50:32 30,720 ------w c:\windows\$hf_mig$\KB905414\update\arpidfix.exe
+ 2005-08-19 23:50:32 30,720 ------w c:\windows\$hf_mig$\KB905414\update\arpidfix.exe
- 2005-02-25 04:35:24 22,240 ------w c:\windows\$hf_mig$\KB905414\update\spcustom.dll
+ 2005-02-25 03:35:24 22,240 ------w c:\windows\$hf_mig$\KB905414\update\spcustom.dll
- 2005-02-25 04:35:24 730,336 ------w c:\windows\$hf_mig$\KB905414\update\update.exe
+ 2005-02-25 03:35:24 730,336 ------w c:\windows\$hf_mig$\KB905414\update\update.exe
- 2005-02-25 04:35:26 395,488 ------w c:\windows\$hf_mig$\KB905414\update\updspapi.dll
+ 2005-02-25 03:35:26 395,488 ------w c:\windows\$hf_mig$\KB905414\update\updspapi.dll
- 2005-08-23 04:41:24 124,928 ------w c:\windows\$hf_mig$\KB905749\SP2QFE\umpnpmgr.dll
+ 2005-08-23 03:41:24 124,928 ------w c:\windows\$hf_mig$\KB905749\SP2QFE\umpnpmgr.dll
- 2005-02-24 19:35:26 15,072 ------w c:\windows\$hf_mig$\KB905749\spmsg.dll
+ 2005-02-24 18:35:26 15,072 ------w c:\windows\$hf_mig$\KB905749\spmsg.dll
- 2005-02-24 19:35:26 213,216 ------w c:\windows\$hf_mig$\KB905749\spuninst.exe
+ 2005-02-24 18:35:26 213,216 ------w c:\windows\$hf_mig$\KB905749\spuninst.exe
- 2005-08-22 17:01:30 30,720 ------w c:\windows\$hf_mig$\KB905749\update\arpidfix.exe
+ 2005-08-22 16:01:30 30,720 ------w c:\windows\$hf_mig$\KB905749\update\arpidfix.exe
- 2005-02-24 19:35:26 22,240 ------w c:\windows\$hf_mig$\KB905749\update\spcustom.dll
+ 2005-02-24 18:35:26 22,240 ------w c:\windows\$hf_mig$\KB905749\update\spcustom.dll
- 2005-02-24 19:35:26 730,336 ------w c:\windows\$hf_mig$\KB905749\update\update.exe
+ 2005-02-24 18:35:26 730,336 ------w c:\windows\$hf_mig$\KB905749\update\update.exe
- 2005-02-24 19:35:26 395,488 ------w c:\windows\$hf_mig$\KB905749\update\updspapi.dll
+ 2005-02-24 18:35:26 395,488 ------w c:\windows\$hf_mig$\KB905749\update\updspapi.dll
- 2005-10-17 22:26:30 80,896 ------w c:\windows\$hf_mig$\KB908519\SP2QFE\fontsub.dll
+ 2005-10-17 21:26:30 80,896 ------w c:\windows\$hf_mig$\KB908519\SP2QFE\fontsub.dll
- 2005-10-17 22:26:30 117,760 ------w c:\windows\$hf_mig$\KB908519\SP2QFE\t2embed.dll
+ 2005-10-17 21:26:30 117,760 ------w c:\windows\$hf_mig$\KB908519\SP2QFE\t2embed.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB908519\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB908519\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB908519\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB908519\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB908519\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB908519\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB908519\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB908519\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB908519\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB908519\update\updspapi.dll
- 2006-03-17 05:49:26 8,510,976 ------w c:\windows\$hf_mig$\KB908531\SP2QFE\shell32.dll
+ 2006-03-17 04:49:26 8,510,976 ------w c:\windows\$hf_mig$\KB908531\SP2QFE\shell32.dll
- 2006-03-22 02:51:44 25,088 ------w c:\windows\$hf_mig$\KB908531\SP2QFE\spru040c.dll
+ 2006-03-22 01:51:44 25,088 ------w c:\windows\$hf_mig$\KB908531\SP2QFE\spru040c.dll
- 2006-03-17 02:05:36 28,672 ------w c:\windows\$hf_mig$\KB908531\SP2QFE\verclsid.exe
+ 2006-03-17 01:05:36 28,672 ------w c:\windows\$hf_mig$\KB908531\SP2QFE\verclsid.exe
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB908531\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB908531\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB908531\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB908531\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB908531\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB908531\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB908531\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB908531\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB908531\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB908531\update\updspapi.dll
- 2005-10-20 23:32:18 1,097,728 ------w c:\windows\$hf_mig$\KB910437\SP2QFE\esent.dll
+ 2005-10-20 22:32:18 1,097,728 ------w c:\windows\$hf_mig$\KB910437\SP2QFE\esent.dll
- 2005-10-13 00:15:24 15,072 ------w c:\windows\$hf_mig$\KB910437\spmsg.dll
+ 2005-10-12 23:15:24 15,072 ------w c:\windows\$hf_mig$\KB910437\spmsg.dll
- 2005-10-13 00:15:24 216,800 ------w c:\windows\$hf_mig$\KB910437\spuninst.exe
+ 2005-10-12 23:15:24 216,800 ------w c:\windows\$hf_mig$\KB910437\spuninst.exe
- 2005-10-13 00:15:24 22,752 ------w c:\windows\$hf_mig$\KB910437\update\spcustom.dll
+ 2005-10-12 23:15:24 22,752 ------w c:\windows\$hf_mig$\KB910437\update\spcustom.dll
- 2005-10-13 00:15:26 727,776 ------w c:\windows\$hf_mig$\KB910437\update\update.exe
+ 2005-10-12 23:15:26 727,776 ------w c:\windows\$hf_mig$\KB910437\update\update.exe
- 2005-10-13 00:15:44 394,976 ------w c:\windows\$hf_mig$\KB910437\update\updspapi.dll
+ 2005-10-12 23:15:44 394,976 ------w c:\windows\$hf_mig$\KB910437\update\updspapi.dll
- 2006-05-14 09:59:06 180,736 ------w c:\windows\$hf_mig$\KB911280\SP2QFE\rasmans.dll
+ 2006-05-14 08:59:06 180,736 ------w c:\windows\$hf_mig$\KB911280\SP2QFE\rasmans.dll
- 2005-10-13 00:18:46 15,072 ------w c:\windows\$hf_mig$\KB911280\spmsg.dll
+ 2005-10-12 23:18:46 15,072 ------w c:\windows\$hf_mig$\KB911280\spmsg.dll
- 2005-10-13 00:18:46 216,800 ------w c:\windows\$hf_mig$\KB911280\spuninst.exe
+ 2005-10-12 23:18:46 216,800 ------w c:\windows\$hf_mig$\KB911280\spuninst.exe
- 2005-10-13 00:18:46 22,752 ------w c:\windows\$hf_mig$\KB911280\update\spcustom.dll
+ 2005-10-12 23:18:46 22,752 ------w c:\windows\$hf_mig$\KB911280\update\spcustom.dll
- 2005-10-13 00:18:46 727,776 ------w c:\windows\$hf_mig$\KB911280\update\update.exe
+ 2005-10-12 23:18:46 727,776 ------w c:\windows\$hf_mig$\KB911280\update\update.exe
- 2005-10-13 00:18:50 394,976 ------w c:\windows\$hf_mig$\KB911280\update\updspapi.dll
+ 2005-10-12 23:18:50 394,976 ------w c:\windows\$hf_mig$\KB911280\update\updspapi.dll
- 2006-03-23 06:53:24 143,360 ------w c:\windows\$hf_mig$\KB911562\SP2QFE\msadco.dll
+ 2006-03-23 05:53:24 143,360 ------w c:\windows\$hf_mig$\KB911562\SP2QFE\msadco.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB911562\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB911562\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB911562\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB911562\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB911562\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB911562\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB911562\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB911562\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB911562\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB911562\update\updspapi.dll
- 2006-03-17 10:14:32 679,424 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\inetcomm.dll
+ 2006-03-17 09:14:32 679,424 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\inetcomm.dll
- 2006-03-17 10:14:32 1,311,744 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\msoe.dll
+ 2006-03-17 09:14:32 1,311,744 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\msoe.dll
- 2006-03-17 10:14:32 510,464 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\wab32.dll
+ 2006-03-17 09:14:32 510,464 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\wab32.dll
- 2006-03-17 10:14:32 85,504 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\wabimp.dll
+ 2006-03-17 09:14:32 85,504 ------w c:\windows\$hf_mig$\KB911567\SP2QFE\wabimp.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB911567\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB911567\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB911567\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB911567\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB911567\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB911567\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB911567\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB911567\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB911567\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB911567\update\updspapi.dll
- 2006-01-04 05:19:20 68,096 ------w c:\windows\$hf_mig$\KB911927\SP2QFE\webclnt.dll
+ 2006-01-04 04:19:20 68,096 ------w c:\windows\$hf_mig$\KB911927\SP2QFE\webclnt.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB911927\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB911927\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB911927\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB911927\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB911927\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB911927\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB911927\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB911927\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB911927\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB911927\update\updspapi.dll
- 2006-03-04 05:00:28 1,022,976 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\browseui.dll
+ 2006-03-04 04:00:28 1,022,976 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\browseui.dll
- 2006-03-04 05:00:28 152,064 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\cdfview.dll
+ 2006-03-04 04:00:28 152,064 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\cdfview.dll
- 2006-03-04 05:00:28 1,056,768 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\danim.dll
+ 2006-03-04 04:00:28 1,056,768 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\danim.dll
- 2006-03-04 05:00:28 205,312 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\dxtrans.dll
+ 2006-03-04 04:00:28 205,312 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\dxtrans.dll
- 2006-03-04 05:00:28 55,808 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\extmgr.dll
+ 2006-03-04 04:00:28 55,808 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\extmgr.dll
- 2006-03-04 02:34:42 18,432 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\iedw.exe
+ 2006-03-04 01:34:42 18,432 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\iedw.exe
- 2006-03-04 05:00:28 251,904 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\iepeers.dll
+ 2006-03-04 04:00:28 251,904 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\iepeers.dll
- 2006-03-04 05:00:28 96,768 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\inseng.dll
+ 2006-03-04 04:00:28 96,768 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\inseng.dll
- 2006-03-23 21:32:00 3,076,608 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\mshtml.dll
+ 2006-03-23 20:32:00 3,076,608 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\mshtml.dll
- 2006-03-04 05:00:30 448,512 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\mshtmled.dll
+ 2006-03-04 04:00:30 448,512 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\mshtmled.dll
- 2006-03-04 05:00:30 146,432 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\msrating.dll
+ 2006-03-04 04:00:30 146,432 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\msrating.dll
- 2006-03-04 05:00:30 532,480 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\mstime.dll
+ 2006-03-04 04:00:30 532,480 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\mstime.dll
- 2006-03-04 05:00:30 39,424 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\pngfilt.dll
+ 2006-03-04 04:00:30 39,424 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\pngfilt.dll
- 2006-03-30 10:29:28 1,495,040 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\shdocvw.dll
+ 2006-03-30 09:29:28 1,495,040 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\shdocvw.dll
- 2006-03-04 05:00:32 474,624 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\shlwapi.dll
+ 2006-03-04 04:00:32 474,624 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\shlwapi.dll
- 2006-03-30 02:52:08 25,088 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\spru040c.dll
+ 2006-03-30 01:52:08 25,088 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\spru040c.dll
- 2006-03-18 12:07:52 616,448 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\urlmon.dll
+ 2006-03-18 11:07:52 616,448 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\urlmon.dll
- 2006-03-04 05:00:32 667,648 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
+ 2006-03-04 04:00:32 667,648 ------w c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
- 2005-10-13 00:18:46 15,072 ------w c:\windows\$hf_mig$\KB912812\spmsg.dll
+ 2005-10-12 23:18:46 15,072 ------w c:\windows\$hf_mig$\KB912812\spmsg.dll
- 2005-10-13 00:18:46 216,800 ------w c:\windows\$hf_mig$\KB912812\spuninst.exe
+ 2005-10-12 23:18:46 216,800 ------w c:\windows\$hf_mig$\KB912812\spuninst.exe
- 2005-10-13 00:18:46 22,752 ------w c:\windows\$hf_mig$\KB912812\update\spcustom.dll
+ 2005-10-12 23:18:46 22,752 ------w c:\windows\$hf_mig$\KB912812\update\spcustom.dll
- 2005-10-13 00:18:46 727,776 ------w c:\windows\$hf_mig$\KB912812\update\update.exe
+ 2005-10-12 23:18:46 727,776 ------w c:\windows\$hf_mig$\KB912812\update\update.exe
- 2005-10-13 00:18:50 394,976 ------w c:\windows\$hf_mig$\KB912812\update\updspapi.dll
+ 2005-10-12 23:18:50 394,976 ------w c:\windows\$hf_mig$\KB912812\update\updspapi.dll
- 2005-12-29 04:08:44 280,064 ------w c:\windows\$hf_mig$\KB912919\SP2QFE\gdi32.dll
+ 2005-12-29 03:08:44 280,064 ------w c:\windows\$hf_mig$\KB912919\SP2QFE\gdi32.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB912919\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB912919\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB912919\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB912919\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB912919\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB912919\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB912919\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB912919\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB912919\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB912919\update\updspapi.dll
- 2006-01-13 18:07:08 360,448 ------w c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
+ 2006-01-13 17:07:08 360,448 ------w c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
- 2005-10-13 00:15:24 15,072 ------w c:\windows\$hf_mig$\KB913446\spmsg.dll
+ 2005-10-12 23:15:24 15,072 ------w c:\windows\$hf_mig$\KB913446\spmsg.dll
- 2005-10-13 00:15:24 216,800 ------w c:\windows\$hf_mig$\KB913446\spuninst.exe
+ 2005-10-12 23:15:24 216,800 ------w c:\windows\$hf_mig$\KB913446\spuninst.exe
- 2005-10-13 00:15:24 22,752 ------w c:\windows\$hf_mig$\KB913446\update\spcustom.dll
+ 2005-10-12 23:15:24 22,752 ------w c:\windows\$hf_mig$\KB913446\update\spcustom.dll
- 2005-10-13 00:15:26 727,776 ------w c:\windows\$hf_mig$\KB913446\update\update.exe
+ 2005-10-12 23:15:26 727,776 ------w c:\windows\$hf_mig$\KB913446\update\update.exe
- 2005-10-13 00:15:44 394,976 ------w c:\windows\$hf_mig$\KB913446\update\updspapi.dll
+ 2005-10-12 23:15:44 394,976 ------w c:\windows\$hf_mig$\KB913446\update\updspapi.dll
- 2006-03-01 20:42:12 426,496 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\msdtcprx.dll
+ 2006-03-01 19:42:12 426,496 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\msdtcprx.dll
- 2006-03-01 20:42:12 956,416 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\msdtctm.dll
+ 2006-03-01 19:42:12 956,416 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\msdtctm.dll
- 2006-03-01 20:42:12 161,280 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\msdtcuiu.dll
+ 2006-03-01 19:42:12 161,280 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\msdtcuiu.dll
- 2006-03-01 20:42:12 66,560 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\mtxclu.dll
+ 2006-03-01 19:42:12 66,560 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\mtxclu.dll
- 2006-03-01 20:42:12 91,136 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\mtxoci.dll
+ 2006-03-01 19:42:12 91,136 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\mtxoci.dll
- 2006-03-01 20:42:12 11,776 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\xolehlp.dll
+ 2006-03-01 19:42:12 11,776 ------w c:\windows\$hf_mig$\KB913580\SP2QFE\xolehlp.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB913580\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB913580\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB913580\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB913580\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB913580\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB913580\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB913580\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB913580\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB913580\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB913580\update\updspapi.dll
- 2006-05-19 15:16:50 112,640 ------w c:\windows\$hf_mig$\KB914388\SP2QFE\dhcpcsvc.dll
+ 2006-05-19 14:16:50 112,640 ------w c:\windows\$hf_mig$\KB914388\SP2QFE\dhcpcsvc.dll
- 2006-05-19 15:16:52 147,456 ------w c:\windows\$hf_mig$\KB914388\SP2QFE\dnsapi.dll
+ 2006-05-19 14:16:52 147,456 ------w c:\windows\$hf_mig$\KB914388\SP2QFE\dnsapi.dll
- 2006-05-19 15:16:52 95,744 ------w c:\windows\$hf_mig$\KB914388\SP2QFE\iphlpapi.dll
+ 2006-05-19 14:16:52 95,744 ------w c:\windows\$hf_mig$\KB914388\SP2QFE\iphlpapi.dll
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB914388\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB914388\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB914388\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB914388\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB914388\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB914388\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB914388\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB914388\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB914388\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB914388\update\updspapi.dll
- 2006-05-05 11:16:40 454,400 ------w c:\windows\$hf_mig$\KB914389\SP2QFE\mrxsmb.sys
+ 2006-05-05 10:16:40 454,400 ------w c:\windows\$hf_mig$\KB914389\SP2QFE\mrxsmb.sys
- 2006-05-05 11:22:52 174,592 ------w c:\windows\$hf_mig$\KB914389\SP2QFE\rdbss.sys
+ 2006-05-05 10:22:52 174,592 ------w c:\windows\$hf_mig$\KB914389\SP2QFE\rdbss.sys
- 2005-10-13 00:15:26 15,072 ------w c:\windows\$hf_mig$\KB914389\spmsg.dll
+ 2005-10-12 23:15:26 15,072 ------w c:\windows\$hf_mig$\KB914389\spmsg.dll
- 2005-10-13 00:15:26 216,800 ------w c:\windows\$hf_mig$\KB914389\spuninst.exe
+ 2005-10-12 23:15:26 216,800 ------w c:\windows\$hf_mig$\KB914389\spuninst.exe
- 2005-10-13 00:15:26 22,752 ------w c:\windows\$hf_mig$\KB914389\update\spcustom.dll
+ 2005-10-12 23:15:26 22,752 ------w c:\windows\$hf_mig$\KB914389\update\spcustom.dll
- 2005-10-13 00:15:28 727,776 ------w c:\windows\$hf_mig$\KB914389\update\update.exe
+ 2005-10-12 23:15:28 727,776 ------w c:\windows\$hf_mig$\KB914389\update\update.exe
- 2005-10-13 00:15:46 394,976 ------w c:\windows\$hf_mig$\KB914389\update\updspapi.dll
+ 2005-10-12 23:15:46 394,976 ------w c:\windows\$hf_mig$\KB914389\update\updspapi.dll
- 2006-05-10 06:26:48 1,022,976 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\browseui.dll
+ 2006-05-10 05:26:48 1,022,976 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\browseui.dll
- 2006-05-10 06:26:48 152,064 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\cdfview.dll
+ 2006-05-10 05:26:48 152,064 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\cdfview.dll
- 2006-05-10 06:26:48 1,056,768 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\danim.dll
+ 2006-05-10 05:26:48 1,056,768 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\danim.dll
- 2006-05-10 06:26:48 357,888 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\dxtmsft.dll
+ 2006-05-10 05:26:48 357,888 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\dxtmsft.dll
- 2006-05-10 06:26:48 205,312 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\dxtrans.dll
+ 2006-05-10 05:26:48 205,312 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\dxtrans.dll
- 2006-05-10 06:26:48 55,808 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\extmgr.dll
+ 2006-05-10 05:26:48 55,808 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\extmgr.dll
- 2006-05-09 12:41:32 18,432 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\iedw.exe
+ 2006-05-09 11:41:32 18,432 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\iedw.exe
- 2006-05-10 06:26:48 251,904 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\iepeers.dll
+ 2006-05-10 05:26:48 251,904 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\iepeers.dll
- 2006-05-10 06:26:48 96,768 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\inseng.dll
+ 2006-05-10 05:26:48 96,768 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\inseng.dll
- 2006-05-10 06:26:48 15,872 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\jsproxy.dll
+ 2006-05-10 05:26:48 15,872 ------w c:\windows\$hf_mig$\KB916281\SP2QFE\jsproxy.dll
- 2006-05-19 16:07:58 3,076,096 ------w c:\windows\$hf_mig$\KB916281
0
BurningShip > BurningShip
 
En fait non... seule une partie du log se colle. Quand je le colle dans un document Word il occupe 583 pages, c'est sans doute ça le problème !
0
Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   572
 
Clique sur Démarrer puis Exécuter. Tapes combofix /u dans la zone de saisie puis OK.
- ( il y a un espace entre combofix et /u)

------------------
Telecharges Toolscleaner2 sur ton bureau : http://pc-system.fr/

- Cliques sur " Recherche " et patientes
- Ciques ensuites sur supprimer " pour finaliser
- Clic sur exit >> un rapport sera généré, postes son contenu

-------------------------------

* Mets Adobe à jour : ( n'installes pas la barre d'outil google, décoches la)
https://get2.adobe.com/reader/otherversions/

---------------------
* Installes la dernière version de Java :
https://www.java.com/fr/download/manual.jsp

-------------------
* Une fois à jour, télécharges JavaRa.zip
http://raproducts.org/click/click.php?id=1
---> Autorise le processus a se connecter si il te le demande
. Cliques sur Install et suis les instructions

- Quand l'installation est finie, reviens à l'écran JavaRa

-Clic sur " Remove Old Versions " ou " supprimer les anciennes versions " --> cliques sur " oui "

-l'outil va travailler, cliques ensuite sur " Ok " et à nouveau sur Ok

- Un rapport s'ouvrira, refermes l'application puis postes le

-----------------------------

Ensuite mets un coup de ccleaner --> analyse + nettoyage
--> Registre : chercher des erreurs et reparer les erreurs, jusqu'à 0 erreurs
( sauvegarde le registre, tu le supprimeras plus tard

------------------------

Fais un scan en ligne ici https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Avec Internet Explorer)

- En bas à droite, clique sur Démarrer Online-scanner

- Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte

- Accepte les Contrôles ActiveX

- Choisis Poste de travail pour le scan.

- Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport

- Pour t'aider à utiliser le scan en ligne :
https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566

NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
----------------------------
0
BurningShip
 
Toolscleaner n'a pas généré de rapport -sauf erreur - mais il a supprimé plusieurs des programmes en question.

Je m'occupe de la suite. Voilà le rapport de JavaRa :




JavaRa 1.13 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Sun Mar 29 22:35:45 2009

Found and removed: C:\Program Files\Java\jre1.5.0_03

Found and removed: C:\Program Files\Java\jre1.5.0_11

Found and removed: C:\Program Files\Java\jre1.6.0_01

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: C:\Program Files\Java\jre1.6.0_05

Found and removed: C:\Program Files\Java\jre1.6.0_07

Found and removed: Software\JavaSoft\Java2D\1.5.0_03

Found and removed: Software\JavaSoft\Java2D\1.5.0_11

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510003

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510003

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510003

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\JavaPlugin.150_03

Found and removed: SOFTWARE\Classes\JavaPlugin.150_11

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_11

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_11

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D511001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150030}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150110}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\JavaPlugin.160_01

Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160010}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_11

Found and removed: Software\Classes\JavaPlugin.160_01

Found and removed: Software\Classes\JavaPlugin.160_03

Found and removed: Software\Classes\JavaPlugin.160_05

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

Found and removed: Software\JavaSoft\Java2D\1.6.0_01

Found and removed: Software\JavaSoft\Java2D\1.6.0_03

Found and removed: Software\JavaSoft\Java2D\1.6.0_05

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_11\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

------------------------------------

Finished reporting.
0
BurningShip
 
Ci-dessous rapport du scan en ligne. "Toutes les parties sont saines".

Est-ce que c'est le bout du tunnel ?

Autre question que j'aurais peut-être dû poser bien plus tôt : puis-je brancher mon disque dur externe sur mon pc ? Je l'utilise pour sauvegarder une copie de tous mes fichiers. Je ne l'ai pas branché depuis plusieurs jours (la dernière fois avant l'apparition des problèmes de virus), mais comment être sûr qu'il n'a pas été contaminé avant ?

MERCI MILLE FOIS ! J'attends de tes nouvelles pour savoir ce que je dois faire.

-------------

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Monday, March 30, 2009 12:01:29 AM
Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600)
Kaspersky On-line Scanner version : 5.0.84.2
Dernière mise à jour de la base antivirus Kaspersky : 29/03/2009
Enregistrements dans la base antivirus Kaspersky : 1793134
-------------------------------------------------------------------------------

Paramètres d'analyse:
Analyser avec la base antivirus suivante: standard
Analyser les archives: vrai
Analyser les bases de messagerie: vrai

Cible de l'analyse - Poste de travail:
C:\
D:\
E:\
F:\
G:\

Statistiques de l'analyse:
Total d'objets analysés: 81295
Nombre de virus trouvés: 0
Nombre d'objets infectés: 0 / 0
Nombre d'objets suspects: 0
Durée de l'analyse: 01:05:08

Nom de l'objet infecté / Nom du virus / Dernière action
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\Temp\_avast4_\Webshlock.txt L'objet est verrouillé ignoré
C:\WINDOWS\Temp\Perflib_Perfdata_328.dat L'objet est verrouillé ignoré
C:\WINDOWS\Temp\Perflib_Perfdata_920.dat L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\Julien\Tracing\WindowsLiveMessenger-uccapi-0.uccapilog L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré
C:\System Volume Information\_restore{9C28189F-7551-4866-A2EC-6D08A138015B}\RP464\change.log L'objet est verrouillé ignoré
D:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
D:\System Volume Information\_restore{9C28189F-7551-4866-A2EC-6D08A138015B}\RP464\change.log L'objet est verrouillé ignoré

Analyse terminée.
0
BurningShip
 
Bonjour,

est-ce que tu as pu jeter un oeil au dernier scan ? Si je comprends bien il me semble que tout est réparé maintenant, est-ce que tu peux me confirmer ça ?

Juste quelques questions pour en finir :

- puis-je brancher mon disque dur externe maintenant ? éventuellement en le scannant immédiatement avec MalwareBytes ?

- il y a encore des fichiers mis en quarantaine par Avast au début de l'infection, que dois-je en faire ?

- est-ce que je peux désinstaller les programmes utilisés pour le nettoyage ? J'en ai toute une liste, dans l'ordre : AVG Anti-Rootkit, CCleaner, ATF Cleaner, Malwarebytes, ToolsCleaner, JavaRa. Je pense garder Ccleaner et Malwarebytes qui peuvent être utile par la suite.

Merci beaucoup pour ton aide en tout cas, je ne sais pas ce que j'aurais fait sans toi !

BS
0
Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   572
 
Salut,

- Pour repondre à tes questions :

puis-je brancher mon disque dur externe maintenant ? éventuellement en le scannant immédiatement avec MalwareBytes ?

- Passes plutot Flash_Disinfector qui est plus approprié pour tes disques amovibles :

Télécharge Flash Disinfector (de sUBs) :
https://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe
et enregistres le sur ton bureau
- Double clique sur l'icone de ton bureau pour le lancer
- Une fenêtre "Start Flash Disinfector" apparait --> branches tes disques amovibles (clés USB, , disques durs externes, iPod...) et clique sur OK.
-les icônes vont disparaitre, c'est normal !
- Lorsque le message "Finish" apparaît, clique sur OK.

PS : ton antivirus va peut-etre s'affoler sur ce programme, Il s'agit d'un faux-positif. Si c'est le cas, désactive le ou ignore l'alerte

--------------

il y a encore des fichiers mis en quarantaine par Avast au début de l'infection, que dois-je en faire ?


- Ils sont en quarantaine donc rien à craindre, pour verifier --> postes le rapport
- De plus Avast c'est pas génial comme Antivirus, en gratuit tu as Avira Antivir qui est trés performant

* Au cas ou : https://www.avira.com/

un tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/

--------------
- Des programmes que je t'ai fais téléchargé, tu ne dois garder que CCleaner et Malwarebytes

--> pour ccleaner : https://www.malekal.com/tutoriel-ccleaner/

--> Malwarebytes : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

- Si tu décides de prendre Avira, tu peux le parametrer pour la detection des Rootkits au demarrage, sers toi du tuto..
-----------------
Une fois que tu auras passé Flash_disinfector, tu peux lui aussi le supprimer de ton pc

- Peux tu poster le rapport ToolsCleaner --> il se trouve à la racine du disque dur
.
0
Burning Ship
 
Merci pour tes conseils. En lisant plusieurs articles du forum j'avais effectivement fini par passer à Antivir il y a deux jours. J'imagine que les fichiers mis en quarantaine par Avast ont disparu avec lui ? (J'ai également passé le programme "Désinstalleur d'Avast" en mode sans échec après la désinstallation, comme conseillé sur le forum).

Le rapport de Toolscleaner est vide (juste "Recherche : " suivi de rien du tout). J'avais fait un peu de ménage, c'est peut-être pour ça ?

J'ai gardé CCleaner, bien utile. Dans quels cas dois-je utilser Malwarebytes ?

Puis-je supprimer Toolscleaner ?

Merci pour tout, encore une fois. Je pense que tout est résolu maintenant... !
0