VIRuS thAYEt Myo HACKINg DaY!

ANOuilh -  
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   -
Logfile of random's system information tool 1.06 (written by random/random)
Run by Amar at 2009-11-01 02:51:34
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 156 GB (69%) free of 226 GB
Total RAM: 3066 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:51:38, on 01/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\BackUp\explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATICAE.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Amar\AppData\Local\pbcnaa.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Windows\system32\conime.exe
C:\Users\Amar\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Amar\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Amar\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Amar\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Users\Amar\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Amar\Desktop\RSIT.exe
C:\Program Files\trend micro\Amar.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.com/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://troner.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHots.dll
R3 - URLSearchHook: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbinte.dll
R3 - URLSearchHook: myBabylon English4 Toolbar - {fc600575-3013-4e8e-941c-4b00dafce730} - C:\Program Files\myBabylon_English4\tbmyBa.dll
F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbinte.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHots.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O2 - BHO: myBabylon English4 Toolbar - {fc600575-3013-4e8e-941c-4b00dafce730} - C:\Program Files\myBabylon_English4\tbmyBa.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHots.dll
O3 - Toolbar: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbinte.dll
O3 - Toolbar: myBabylon English4 Toolbar - {fc600575-3013-4e8e-941c-4b00dafce730} - C:\Program Files\myBabylon_English4\tbmyBa.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [explorer] C:\Windows\BackUp\explorer.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_SC467.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Amar\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [pbcnaa] "c:\users\amar\appdata\local\pbcnaa.exe" pbcnaa
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345} (Symantec Configuration Class) - https://support.norton.com/sp/en/us/home/current/info
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.807.15159 (GoogleDesktopManager-071508-051939) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 14117 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Extension de garantie-Amar.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-583370343-2912786679-2086142570-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-583370343-2912786679-2086142570-1000UA.job
C:\Windows\tasks\Norton Internet Security - Effectuer une analyse complète du système - Amar.job
C:\Windows\tasks\Recovery DVD Creator-Amar.job
C:\Windows\tasks\User_Feed_Synchronization-{1789B7F3-6B2A-4AFD-9454-68184B69E1DB}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-07-17 279944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31c322dc-5878-452e-a2d8-c4aab9973c9a}]
interdescargas-FR Toolbar - C:\Program Files\interdescargas-FR\tbinte.dll [2009-10-01 2166296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll [2009-03-31 357744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-05-22 116088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-16 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
Babylon IE plugin - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll [2009-09-08 252816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-30 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [2009-10-06 762864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C56CB6B0-0D96-11D6-8C65-B2868B609932}]
NTIECatcher Class - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll [2005-09-08 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-09-30 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
Hotspot Shield Toolbar - C:\Program Files\Hotspot_Shield\tbHots.dll [2009-07-02 2215960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\Google\Google_BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2009-03-02 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-16 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
Hotspot Shield Class - C:\Program Files\Hotspot Shield\hssie\HssIE.dll [2009-10-16 218160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fc600575-3013-4e8e-941c-4b00dafce730}]
myBabylon English4 Toolbar - C:\Program Files\myBabylon_English4\tbmyBa.dll [2009-07-02 2215960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2009-03-31 357744]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-30 256112]
{c95a4e8e-816d-4655-8c79-d736da1adb6d} - Hotspot Shield Toolbar - C:\Program Files\Hotspot_Shield\tbHots.dll [2009-07-02 2215960]
{31c322dc-5878-452e-a2d8-c4aab9973c9a} - interdescargas-FR Toolbar - C:\Program Files\interdescargas-FR\tbinte.dll [2009-10-01 2166296]
{fc600575-3013-4e8e-941c-4b00dafce730} - myBabylon English4 Toolbar - C:\Program Files\myBabylon_English4\tbmyBa.dll [2009-07-02 2215960]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-07-17 279944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-06-08 894512]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-05-22 24064]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-06-27 6295552]
"toolbar_eula_launcher"=C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe [2007-02-20 28672]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-16 136600]
"explorer"=C:\Windows\BackUp\explorer.exe [2008-09-29 316607]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"Carbonite Backup"=C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe [2009-07-28 671376]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-10-24 417792]
"Babylon Client"=C:\Program Files\Babylon\Babylon-Pro\Babylon.exe [2009-09-08 3730832]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"=C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe [2008-02-04 1038136]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"EPSON Stylus DX4400 Series"=C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE [2007-03-01 180736]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"Google Update"=C:\Users\Amar\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-08 133104]
"pbcnaa"=c:\users\amar\appdata\local\pbcnaa.exe [2009-10-22 360448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\system32\EZUPBH~1.DLL [2008-12-03 49152]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoViewContextMenu"=0
"NoRun"=0
"NoFind"=0
"NoDesktop"=0
"HideClock"=0
"NoFolderOptions"=1
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d7c9d83d-c24b-11dd-8207-0017c43edd32}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\explorer.exe
shell\Explore\command - E:\explorer.exe
shell\Open\command - E:\explorer.exe

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-11-01 02:34:18 ----N---- C:\Windows\system32\MpSigStub.exe
2009-11-01 01:46:18 ----D---- C:\Program Files\trend micro
2009-11-01 01:46:16 ----D---- C:\rsit
2009-10-29 17:19:54 ----D---- C:\Users\Amar\AppData\Roaming\gtk-2.0
2009-10-29 17:07:40 ----D---- C:\Program Files\AskBarDis
2009-10-29 17:06:13 ----D---- C:\Users\Amar\AppData\Roaming\Participatory Culture Foundation
2009-10-29 17:04:23 ----D---- C:\Program Files\Participatory Culture Foundation
2009-10-28 21:37:25 ----D---- C:\Casino
2009-10-28 11:28:08 ----A---- C:\Windows\system32\wmp.dll
2009-10-28 11:28:06 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-28 11:28:06 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-26 23:17:27 ----D---- C:\Downloads
2009-10-26 22:06:29 ----D---- C:\Users\Amar\AppData\Roaming\Free Download Manager
2009-10-26 22:06:11 ----D---- C:\Program Files\Free Download Manager
2009-10-26 22:06:07 ----D---- C:\Program Files\myBabylon_English4
2009-10-26 22:06:05 ----D---- C:\Program Files\Babylon
2009-10-26 22:06:04 ----D---- C:\Users\Amar\AppData\Roaming\Babylon
2009-10-26 22:06:04 ----D---- C:\ProgramData\Babylon
2009-10-26 20:30:18 ----D---- C:\Program Files\Common Files\DivX Shared
2009-10-26 20:30:17 ----D---- C:\Program Files\DivX
2009-10-24 20:58:05 ----D---- C:\ProgramData\Apple Computer
2009-10-24 20:57:07 ----D---- C:\Program Files\Common Files\Apple
2009-10-24 20:56:48 ----D---- C:\ProgramData\Apple
2009-10-24 20:56:48 ----D---- C:\Program Files\Apple Software Update
2009-10-24 20:53:12 ----D---- C:\Program Files\QuickTime
2009-10-22 21:23:03 ----D---- C:\Program Files\interdescargas-FR
2009-10-22 21:22:20 ----A---- C:\Windows\Instaler Setup Log.txt
2009-10-22 12:30:37 ----A---- C:\Windows\system32\mshtml.dll
2009-10-22 12:30:36 ----A---- C:\Windows\system32\ieframe.dll
2009-10-22 12:30:35 ----A---- C:\Windows\system32\wininet.dll
2009-10-22 12:30:35 ----A---- C:\Windows\system32\urlmon.dll
2009-10-22 12:30:35 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-22 12:30:35 ----A---- C:\Windows\system32\iertutil.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\occache.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\msfeedssync.exe
2009-10-22 12:30:34 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-22 12:30:34 ----A---- C:\Windows\system32\ieui.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\iesysprep.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\iesetup.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\iernonce.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\iepeers.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-22 12:30:34 ----A---- C:\Windows\system32\ie4uinit.exe
2009-10-18 11:13:51 ----D---- C:\ProgramData\Carbonite
2009-10-18 11:13:51 ----D---- C:\Program Files\Carbonite
2009-10-16 16:09:19 ----D---- C:\Hotspot Shield
2009-10-16 13:18:26 ----D---- C:\Program Files\Conduit
2009-10-16 13:18:25 ----D---- C:\Program Files\Hotspot_Shield
2009-10-16 13:16:33 ----D---- C:\Program Files\Hotspot Shield
2009-10-16 09:02:59 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-16 09:02:52 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-16 09:02:52 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-16 09:02:36 ----A---- C:\Windows\system32\msasn1.dll
2009-10-16 09:02:32 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2009-10-13 14:27:31 ----A---- C:\setgooglesearch.exe
2009-10-07 12:11:00 ----A---- C:\Windows\system32\wups2.dll
2009-10-07 12:11:00 ----A---- C:\Windows\system32\wucltux.dll
2009-10-07 12:11:00 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-07 12:11:00 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-07 12:10:41 ----A---- C:\Windows\system32\wups.dll
2009-10-07 12:10:41 ----A---- C:\Windows\system32\wudriver.dll
2009-10-07 12:10:41 ----A---- C:\Windows\system32\wuapi.dll
2009-10-07 12:10:35 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-07 12:10:35 ----A---- C:\Windows\system32\wuapp.exe
2009-10-06 16:16:41 ----D---- C:\Program Files\Microsoft
2009-10-06 16:16:23 ----D---- C:\Program Files\Windows Live SkyDrive
2009-10-06 16:16:05 ----D---- C:\Program Files\Windows Live
2009-10-06 16:10:44 ----D---- C:\Program Files\Common Files\Windows Live
2009-10-05 19:02:38 ----D---- C:\ProgramData\Media Center Programs
2009-10-05 18:50:56 ----D---- C:\Program Files\Common Files\Steam
2009-10-05 18:50:53 ----D---- C:\Program Files\Steam
2009-10-05 18:49:39 ----D---- C:\Program Files\Sports Interactive
2009-10-05 18:35:10 ----D---- C:\ProgramData\ATI
2009-10-05 17:37:56 ----D---- C:\Windows\system32\eu-ES
2009-10-05 17:37:56 ----D---- C:\Windows\system32\ca-ES
2009-10-05 17:37:55 ----D---- C:\Windows\system32\vi-VN
2009-10-05 17:25:07 ----D---- C:\Windows\system32\EventProviders
2009-10-05 17:24:22 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-10-05 17:24:19 ----A---- C:\Windows\system32\SLCExt.dll
2009-10-05 17:24:18 ----A---- C:\Windows\system32\SLsvc.exe
2009-10-05 17:24:17 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-10-05 17:24:17 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-10-05 17:24:16 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-10-05 17:24:13 ----A---- C:\Windows\system32\mssrch.dll
2009-10-05 17:24:11 ----A---- C:\Windows\system32\tquery.dll
2009-10-05 17:24:10 ----A---- C:\Windows\system32\RMActivate_isv.exe
2009-10-05 17:24:10 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-10-05 17:24:09 ----A---- C:\Windows\system32\scavenge.dll
2009-10-05 17:24:09 ----A---- C:\Windows\system32\RMActivate.exe
2009-10-05 17:24:08 ----A---- C:\Windows\system32\msi.dll
2009-10-05 17:24:07 ----A---- C:\Windows\system32\imapi2fs.dll
2009-10-05 17:24:06 ----A---- C:\Windows\system32\WscEapPr.dll
2009-10-05 17:24:06 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-10-05 17:24:06 ----A---- C:\Windows\system32\sysmain.dll
2009-10-05 17:24:06 ----A---- C:\Windows\system32\secproc_isv.dll
2009-10-05 17:24:05 ----A---- C:\Windows\system32\icardagt.exe
2009-10-05 17:24:04 ----A---- C:\Windows\system32\EhStorShell.dll
2009-10-05 17:24:04 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2009-10-05 17:24:02 ----A---- C:\Windows\system32\spreview.exe
2009-10-05 17:24:02 ----A---- C:\Windows\system32\spinstall.exe
2009-10-05 17:24:02 ----A---- C:\Windows\system32\drmv2clt.dll
2009-10-05 17:24:01 ----A---- C:\Windows\system32\spwizui.dll
2009-10-05 17:24:01 ----A---- C:\Windows\system32\shell32.dll
2009-10-05 17:24:01 ----A---- C:\Windows\system32\secproc.dll
2009-10-05 17:24:01 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-10-05 17:23:59 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-10-05 17:23:59 ----A---- C:\Windows\system32\p2psvc.dll
2009-10-05 17:23:59 ----A---- C:\Windows\system32\mssvp.dll
2009-10-05 17:23:58 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2009-10-05 17:23:58 ----A---- C:\Windows\system32\mscoree.dll
2009-10-05 17:23:57 ----A---- C:\Windows\system32\mssphtb.dll
2009-10-05 17:23:57 ----A---- C:\Windows\system32\mssph.dll
2009-10-05 17:23:57 ----A---- C:\Windows\system32\imapi2.dll
2009-10-05 17:23:56 ----A---- C:\Windows\system32\sdohlp.dll
2009-10-05 17:23:55 ----A---- C:\Windows\system32\IMJP10K.DLL
2009-10-05 17:23:55 ----A---- C:\Windows\system32\esent.dll
2009-10-05 17:23:55 ----A---- C:\Windows\system32\DevicePairing.dll
2009-10-05 17:23:54 ----A---- C:\Windows\system32\wevtsvc.dll
2009-10-05 17:23:54 ----A---- C:\Windows\system32\sperror.dll
2009-10-05 17:23:54 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2009-10-05 17:23:54 ----A---- C:\Windows\system32\korwbrkr.dll
2009-10-05 17:23:53 ----A---- C:\Windows\system32\SLC.dll
2009-10-05 17:23:53 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-10-05 17:23:53 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-10-05 17:23:53 ----A---- C:\Windows\system32\IasMigReader.exe
2009-10-05 17:23:52 ----A---- C:\Windows\system32\msshsq.dll
2009-10-05 17:23:51 ----A---- C:\Windows\system32\msjet40.dll
2009-10-05 17:23:51 ----A---- C:\Windows\system32\MPSSVC.dll
2009-10-05 17:23:50 ----A---- C:\Windows\system32\msxml6.dll
2009-10-05 17:23:49 ----A---- C:\Windows\system32\Query.dll
2009-10-05 17:23:49 ----A---- C:\Windows\system32\qmgr.dll
2009-10-05 17:23:48 ----A---- C:\Windows\system32\P2PGraph.dll
2009-10-05 17:23:48 ----A---- C:\Windows\system32\msexch40.dll
2009-10-05 17:23:48 ----A---- C:\Windows\system32\diagperf.dll
2009-10-05 17:23:47 ----A---- C:\Windows\system32\srchadmin.dll
2009-10-05 17:23:47 ----A---- C:\Windows\system32\ole32.dll
2009-10-05 17:23:47 ----A---- C:\Windows\system32\ntdll.dll
2009-10-05 17:23:47 ----A---- C:\Windows\system32\msxml3.dll
2009-10-05 17:23:46 ----A---- C:\Windows\system32\winload.exe
2009-10-05 17:23:46 ----A---- C:\Windows\system32\uDWM.dll
2009-10-05 17:23:46 ----A---- C:\Windows\system32\mmc.exe
2009-10-05 17:23:46 ----A---- C:\Windows\system32\mblctr.exe
2009-10-05 17:23:46 ----A---- C:\Windows\system32\EncDec.dll
2009-10-05 17:23:46 ----A---- C:\Windows\system32\dfsr.exe
2009-10-05 17:23:45 ----A---- C:\Windows\system32\riched20.dll
2009-10-05 17:23:45 ----A---- C:\Windows\system32\IasMigPlugin.dll
2009-10-05 17:23:44 ----A---- C:\Windows\system32\RacEngn.dll
2009-10-05 17:23:44 ----A---- C:\Windows\system32\fdBth.dll
2009-10-05 17:23:43 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-10-05 17:23:43 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-10-05 17:23:43 ----A---- C:\Windows\system32\kernel32.dll
2009-10-05 17:23:42 ----A---- C:\Windows\system32\spoolss.dll
2009-10-05 17:23:42 ----A---- C:\Windows\system32\milcore.dll
2009-10-05 17:23:42 ----A---- C:\Windows\system32\EhStorAPI.dll
2009-10-05 17:23:42 ----A---- C:\Windows\system32\CertEnroll.dll
2009-10-05 17:23:41 ----A---- C:\Windows\system32\schedsvc.dll
2009-10-05 17:23:41 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-10-05 17:23:40 ----A---- C:\Windows\system32\msvcp60.dll
2009-10-05 17:23:40 ----A---- C:\Windows\system32\msjtes40.dll
2009-10-05 17:23:40 ----A---- C:\Windows\system32\infocardapi.dll
2009-10-05 17:23:40 ----A---- C:\Windows\system32\gpedit.dll
2009-10-05 17:23:40 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2009-10-05 17:23:38 ----A---- C:\Windows\system32\WinSAT.exe
2009-10-05 17:23:38 ----A---- C:\Windows\system32\es.dll
2009-10-05 17:23:37 ----A---- C:\Windows\system32\PresentationSettings.exe
2009-10-05 17:23:37 ----A---- C:\Windows\system32\mstext40.dll
2009-10-05 17:23:37 ----A---- C:\Windows\system32\Magnify.exe
2009-10-05 17:23:37 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2009-10-05 17:23:37 ----A---- C:\Windows\system32\advapi32.dll
2009-10-05 17:23:35 ----A---- C:\Windows\system32\WMPhoto.dll
2009-10-05 17:23:35 ----A---- C:\Windows\system32\WebClnt.dll
2009-10-05 17:23:35 ----A---- C:\Windows\system32\slwmi.dll
2009-10-05 17:23:35 ----A---- C:\Windows\system32\msexcl40.dll
2009-10-05 17:23:35 ----A---- C:\Windows\system32\comsvcs.dll
2009-10-05 17:23:34 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2009-10-05 17:23:34 ----A---- C:\Windows\system32\vssapi.dll
2009-10-05 17:23:34 ----A---- C:\Windows\system32\msxbde40.dll
2009-10-05 17:23:33 ----A---- C:\Windows\system32\authui.dll
2009-10-05 17:23:32 ----A---- C:\Windows\system32\propsys.dll
2009-10-05 17:23:32 ----A---- C:\Windows\system32\PresentationHost.exe
2009-10-05 17:23:32 ----A---- C:\Windows\system32\newdev.dll
2009-10-05 17:23:32 ----A---- C:\Windows\system32\NetProjW.dll
2009-10-05 17:23:32 ----A---- C:\Windows\system32\msrepl40.dll
2009-10-05 17:23:31 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-10-05 17:23:31 ----A---- C:\Windows\system32\iasrecst.dll
2009-10-05 17:23:31 ----A---- C:\Windows\system32\gpsvc.dll
2009-10-05 17:23:30 ----A---- C:\Windows\system32\eudcedit.exe
2009-10-05 17:23:30 ----A---- C:\Windows\system32\crypt32.dll
2009-10-05 17:23:30 ----A---- C:\Windows\explorer.exe
2009-10-05 17:23:29 ----A---- C:\Windows\system32\setupapi.dll
2009-10-05 17:23:29 ----A---- C:\Windows\system32\rpcss.dll
2009-10-05 17:23:28 ----A---- C:\Windows\system32\mspbde40.dll
2009-10-05 17:23:28 ----A---- C:\Windows\system32\msltus40.dll
2009-10-05 17:23:28 ----A---- C:\Windows\system32\davclnt.dll
2009-10-05 17:23:28 ----A---- C:\Windows\system32\d3d9.dll
2009-10-05 17:23:27 ----A---- C:\Windows\system32\shlwapi.dll
2009-10-05 17:23:27 ----A---- C:\Windows\system32\msrd3x40.dll
2009-10-05 17:23:27 ----A---- C:\Windows\system32\mfc42.dll
2009-10-05 17:23:27 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2009-10-05 17:23:27 ----A---- C:\Windows\system32\EhStorAuthn.dll
2009-10-05 17:23:26 ----A---- C:\Windows\system32\wevtapi.dll
2009-10-05 17:23:26 ----A---- C:\Windows\system32\photowiz.dll
2009-10-05 17:23:26 ----A---- C:\Windows\system32\nlhtml.dll
2009-10-05 17:23:26 ----A---- C:\Windows\system32\msdtctm.dll
2009-10-05 17:23:26 ----A---- C:\Windows\system32\browseui.dll
2009-10-05 17:23:24 ----A---- C:\Windows\system32\user32.dll
2009-10-05 17:23:24 ----A---- C:\Windows\system32\samsrv.dll
2009-10-05 17:23:24 ----A---- C:\Windows\system32\quartz.dll
2009-10-05 17:23:24 ----A---- C:\Windows\system32\ci.dll
2009-10-05 17:23:23 ----A---- C:\Windows\system32\win32spl.dll
2009-10-05 17:23:23 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-10-05 17:23:23 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-10-05 17:23:23 ----A---- C:\Windows\system32\oleaut32.dll
2009-10-05 17:23:22 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-10-05 17:23:22 ----A---- C:\Windows\system32\netshell.dll
2009-10-05 17:23:22 ----A---- C:\Windows\system32\IKEEXT.DLL
2009-10-05 17:23:22 ----A---- C:\Windows\system32\compcln.exe
2009-10-05 17:23:21 ----A---- C:\Windows\system32\winhttp.dll
2009-10-05 17:23:21 ----A---- C:\Windows\system32\mswstr10.dll
2009-10-05 17:23:21 ----A---- C:\Windows\system32\apds.dll
2009-10-05 17:23:20 ----A---- C:\Windows\system32\xmlfilter.dll
2009-10-05 17:23:20 ----A---- C:\Windows\system32\msvcrt.dll
2009-10-05 17:23:20 ----A---- C:\Windows\system32\msctf.dll
2009-10-05 17:23:20 ----A---- C:\Windows\system32\emdmgmt.dll
2009-10-05 17:23:20 ----A---- C:\Windows\system32\audiosrv.dll
2009-10-05 17:23:19 ----A---- C:\Windows\system32\VSSVC.exe
2009-10-05 17:23:19 ----A---- C:\Windows\system32\QAGENTRT.DLL
2009-10-05 17:23:19 ----A---- C:\Windows\system32\mfc42u.dll
2009-10-05 17:23:19 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-10-05 17:23:19 ----A---- C:\Windows\system32\gdi32.dll
2009-10-05 17:23:18 ----A---- C:\Windows\system32\sqlsrv32.dll
2009-10-05 17:23:18 ----A---- C:\Windows\system32\SLUI.exe
2009-10-05 17:23:18 ----A---- C:\Windows\system32\msrd2x40.dll
2009-10-05 17:23:18 ----A---- C:\Windows\system32\eapphost.dll
2009-10-05 17:23:17 ----A---- C:\Windows\system32\odbc32.dll
2009-10-05 17:23:16 ----A---- C:\Windows\system32\winresume.exe
2009-10-05 17:23:16 ----A---- C:\Windows\system32\shdocvw.dll
2009-10-05 17:23:16 ----A---- C:\Windows\system32\propdefs.dll
2009-10-05 17:23:15 ----A---- C:\Windows\system32\wevtutil.exe
2009-10-05 17:23:15 ----A---- C:\Windows\system32\dbgeng.dll
2009-10-05 17:23:14 ----A---- C:\Windows\system32\mssitlb.dll
2009-10-05 17:23:13 ----A---- C:\Windows\system32\WsmSvc.dll
2009-10-05 17:23:13 ----A---- C:\Windows\system32\swprv.dll
2009-10-05 17:23:13 ----A---- C:\Windows\system32\mmcndmgr.dll
2009-10-05 17:23:12 ----A---- C:\Windows\system32\vds.exe
2009-10-05 17:23:12 ----A---- C:\Windows\system32\usp10.dll
2009-10-05 17:23:11 ----A---- C:\Windows\system32\netlogon.dll
2009-10-05 17:23:11 ----A---- C:\Windows\system32\msscb.dll
2009-10-05 17:23:11 ----A---- C:\Windows\system32\msctfp.dll
2009-10-05 17:23:11 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-10-05 17:23:11 ----A---- C:\Windows\system32\drvinst.exe
2009-10-05 17:23:11 ----A---- C:\Windows\system32\devmgr.dll
2009-10-05 17:23:11 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-10-05 17:23:11 ----A---- C:\Windows\system32\BFE.DLL
2009-10-05 17:23:11 ----A---- C:\Windows\system32\adsldpc.dll
2009-10-05 17:23:10 ----A---- C:\Windows\system32\wcnwiz.dll
2009-10-05 17:23:10 ----A---- C:\Windows\system32\evr.dll
2009-10-05 17:23:09 ----A---- C:\Windows\system32\WSDApi.dll
2009-10-05 17:23:09 ----A---- C:\Windows\system32\WMVSDECD.DLL
2009-10-05 17:23:09 ----A---- C:\Windows\system32\Wldap32.dll
2009-10-05 17:23:09 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-10-05 17:23:09 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-10-05 17:23:08 ----A---- C:\Windows\system32\wercon.exe
2009-10-05 17:23:08 ----A---- C:\Windows\system32\wcncsvc.dll
2009-10-05 17:23:08 ----A---- C:\Windows\system32\services.exe
2009-10-05 17:23:08 ----A---- C:\Windows\system32\mimefilt.dll
2009-10-05 17:23:08 ----A---- C:\Windows\system32\comdlg32.dll
2009-10-05 17:23:08 ----A---- C:\Windows\system32\adtschema.dll
2009-10-05 17:23:07 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-10-05 17:23:07 ----A---- C:\Windows\system32\mswdat10.dll
2009-10-05 17:23:07 ----A---- C:\Windows\system32\msjter40.dll
2009-10-05 17:23:07 ----A---- C:\Windows\system32\msdtcprx.dll
2009-10-05 17:23:07 ----A---- C:\Windows\system32\msdrm.dll
2009-10-05 17:23:07 ----A---- C:\Windows\system32\ipsmsnap.dll
2009-10-05 17:23:07 ----A---- C:\Windows\system32\certcli.dll
2009-10-05 17:23:06 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-10-05 17:23:06 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-10-05 17:23:06 ----A---- C:\Windows\system32\taskeng.exe
2009-10-05 17:23:06 ----A---- C:\Windows\system32\rtffilt.dll
2009-10-05 17:23:06 ----A---- C:\Windows\system32\reg.exe
2009-10-05 17:23:06 ----A---- C:\Windows\system32\dnsapi.dll
2009-10-05 17:23:06 ----A---- C:\Windows\system32\certutil.exe
2009-10-05 17:23:05 ----A---- C:\Windows\system32\w32time.dll
2009-10-05 17:23:05 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-10-05 17:23:05 ----A---- C:\Windows\system32\bcrypt.dll
2009-10-05 17:23:04 ----A---- C:\Windows\system32\rsaenh.dll
2009-10-05 17:23:04 ----A---- C:\Windows\system32\msshooks.dll
2009-10-05 17:23:04 ----A---- C:\Windows\system32\msscntrs.dll
2009-10-05 17:23:04 ----A---- C:\Windows\system32\bthserv.dll
2009-10-05 17:23:03 ----A---- C:\Windows\system32\TsWpfWrp.exe
2009-10-05 17:23:03 ----A---- C:\Windows\system32\msstrc.dll
2009-10-05 17:23:03 ----A---- C:\Windows\system32\msihnd.dll
2009-10-05 17:23:03 ----A---- C:\Windows\system32\MMDevAPI.dll
2009-10-05 17:23:03 ----A---- C:\Windows\system32\inetcomm.dll
2009-10-05 17:23:03 ----A---- C:\Windows\system32\dfshim.dll
2009-10-05 17:23:02 ----A---- C:\Windows\system32\netapi32.dll
2009-10-05 17:23:02 ----A---- C:\Windows\system32\mtxclu.dll
2009-10-05 17:23:02 ----A---- C:\Windows\system32\inetpp.dll
2009-10-05 17:23:02 ----A---- C:\Windows\system32\hidserv.dll
2009-10-05 17:23:02 ----A---- C:\Windows\system32\fundisc.dll
2009-10-05 17:23:02 ----A---- C:\Windows\system32\cryptsvc.dll
2009-10-05 17:23:01 ----A---- C:\Windows\system32\wmicmiplugin.dll
2009-10-05 17:23:01 ----A---- C:\Windows\system32\termsrv.dll
2009-10-05 17:23:01 ----A---- C:\Windows\system32\profsvc.dll
2009-10-05 17:23:01 ----A---- C:\Windows\system32\mscories.dll
2009-10-05 17:23:01 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-10-05 17:23:00 ----A---- C:\Windows\system32\shsvcs.dll
2009-10-05 17:23:00 ----A---- C:\Windows\system32\msiexec.exe
2009-10-05 17:23:00 ----A---- C:\Windows\system32\imapi.dll
2009-10-05 17:22:59 ----A---- C:\Windows\system32\wdc.dll
2009-10-05 17:22:59 ----A---- C:\Windows\system32\rasmans.dll
2009-10-05 17:22:59 ----A---- C:\Windows\system32\pnidui.dll
2009-10-05 17:22:59 ----A---- C:\Windows\system32\iassdo.dll
2009-10-05 17:22:59 ----A---- C:\Windows\system32\chsbrkr.dll
2009-10-05 17:22:58 ----A---- C:\Windows\system32\wersvc.dll
2009-10-05 17:22:58 ----A---- C:\Windows\system32\spoolsv.exe
2009-10-05 17:22:58 ----A---- C:\Windows\system32\slmgr.vbs
2009-10-05 17:22:58 ----A---- C:\Windows\system32\scrrun.dll
2009-10-05 17:22:58 ----A---- C:\Windows\system32\PSHED.DLL
2009-10-05 17:22:58 ----A---- C:\Windows\system32\icardres.dll
2009-10-05 17:22:58 ----A---- C:\Windows\system32\autofmt.exe
2009-10-05 17:22:57 ----A---- C:\Windows\system32\pidgenx.dll
2009-10-05 17:22:57 ----A---- C:\Windows\system32\pdh.dll
2009-10-05 17:22:57 ----A---- C:\Windows\system32\dhcpcsvc.dll
2009-10-05 17:22:57 ----A---- C:\Windows\system32\CertEnrollUI.dll
2009-10-05 17:22:57 ----A---- C:\Windows\system32\azroles.dll
2009-10-05 17:22:56 ----A---- C:\Windows\system32\wmpmde.dll
2009-10-05 17:22:56 ----A---- C:\Windows\system32\winlogon.exe
2009-10-05 17:22:56 ----A---- C:\Windows\system32\SyncCenter.dll
2009-10-05 17:22:54 ----A---- C:\Windows\system32\SLUINotify.dll
2009-10-05 17:22:54 ----A---- C:\Windows\system32\sethc.exe
2009-10-05 17:22:54 ----A---- C:\Windows\system32\ncrypt.dll
2009-10-05 17:22:54 ----A---- C:\Windows\system32\msjetoledb40.dll
2009-10-05 17:22:54 ----A---- C:\Windows\system32\kd1394.dll
2009-10-05 17:22:54 ----A---- C:\Windows\system32\comuid.dll
2009-10-05 17:22:54 ----A---- C:\Windows\system32\certmgr.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\wisptis.exe
2009-10-05 17:22:53 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\untfs.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\taskcomp.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\spp.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\scrobj.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\rtutils.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\iassam.dll
2009-10-05 17:22:53 ----A---- C:\Windows\system32\dwm.exe
2009-10-05 17:22:53 ----A---- C:\Windows\system32\autochk.exe
2009-10-05 17:22:52 ----A---- C:\Windows\system32\printui.dll
2009-10-05 17:22:52 ----A---- C:\Windows\system32\iasnap.dll
2009-10-05 17:22:52 ----A---- C:\Windows\system32\autoconv.exe
2009-10-05 17:22:51 ----A---- C:\Windows\system32\wow32.dll
2009-10-05 17:22:51 ----A---- C:\Windows\system32\winsrv.dll
2009-10-05 17:22:51 ----A---- C:\Windows\system32\userenv.dll
2009-10-05 17:22:51 ----A---- C:\Windows\system32\onex.dll
2009-10-05 17:22:51 ----A---- C:\Windows\system32\kdcom.dll
2009-10-05 17:22:51 ----A---- C:\Windows\system32\cscript.exe
2009-10-05 17:22:51 ----A---- C:\Windows\system32\basecsp.dll
2009-10-05 17:22:51 ----A---- C:\Windows\system32\audiodg.exe
2009-10-05 17:22:50 ----A---- C:\Windows\system32\winmm.dll
2009-10-05 17:22:50 ----A---- C:\Windows\system32\spcmsg.dll
2009-10-05 17:22:50 ----A---- C:\Windows\system32\RelMon.dll
2009-10-05 17:22:50 ----A---- C:\Windows\system32\osk.exe
2009-10-05 17:22:50 ----A---- C:\Windows\system32\mswsock.dll
2009-10-05 17:22:50 ----A---- C:\Windows\system32\kdusb.dll
2009-10-05 17:22:49 ----A---- C:\Windows\system32\WinSCard.dll
2009-10-05 17:22:49 ----A---- C:\Windows\system32\WerFaultSecure.exe
2009-10-05 17:22:49 ----A---- C:\Windows\system32\rdpencom.dll
2009-10-05 17:22:49 ----A---- C:\Windows\system32\offfilt.dll
2009-10-05 17:22:49 ----A---- C:\Windows\system32\msftedit.dll
2009-10-05 17:22:49 ----A---- C:\Windows\system32\dnsrslvr.dll
2009-10-05 17:22:48 ----A---- C:\Windows\system32\wsepno.dll
2009-10-05 17:22:48 ----A---- C:\Windows\system32\WerFault.exe
2009-10-05 17:22:48 ----A---- C:\Windows\system32\Utilman.exe
2009-10-05 17:22:48 ----A---- C:\Windows\system32\stobject.dll
2009-10-05 17:22:48 ----A---- C:\Windows\system32\SndVol.exe
2009-10-05 17:22:48 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2009-10-05 17:22:48 ----A---- C:\Windows\system32\secproc_ssp.dll
2009-10-05 17:22:48 ----A---- C:\Windows\system32\mfplat.dll
2009-10-05 17:22:48 ----A---- C:\Windows\system32\diskraid.exe
2009-10-05 17:22:48 ----A---- C:\Windows\system32\apphelp.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\wscript.exe
2009-10-05 17:22:47 ----A---- C:\Windows\system32\wiaservc.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\sysclass.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\prnntfy.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\odbccp32.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\msnetobj.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\mscms.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\mcmde.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\iasdatastore.dll
2009-10-05 17:22:47 ----A---- C:\Windows\system32\adsmsext.dll
2009-10-05 17:22:46 ----A---- C:\Windows\system32\ulib.dll
2009-10-05 17:22:46 ----A---- C:\Windows\system32\dsound.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\wscntfy.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\wlangpui.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\rastapi.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\pnpsetup.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\ipsecsnp.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2009-10-05 17:22:45 ----A---- C:\Windows\system32\fdProxy.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\cryptui.dll
2009-10-05 17:22:45 ----A---- C:\Windows\system32\brcpl.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\wusa.exe
2009-10-05 17:22:44 ----A---- C:\Windows\system32\wscsvc.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\WMVENCOD.DLL
2009-10-05 17:22:44 ----A---- C:\Windows\system32\vdsdyn.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\regsvc.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\rastls.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\rasapi32.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\ntprint.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\mscorier.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\logman.exe
2009-10-05 17:22:44 ----A---- C:\Windows\system32\iasrad.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\iashlpr.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\gpapi.dll
2009-10-05 17:22:44 ----A---- C:\Windows\system32\diskpart.exe
2009-10-05 17:22:43 ----A---- C:\Windows\system32\zipfldr.dll
2009-10-05 17:22:43 ----A---- C:\Windows\system32\wshext.dll
2009-10-05 17:22:43 ----A---- C:\Windows\system32\wpccpl.dll
2009-10-05 17:22:43 ----A---- C:\Windows\system32\wer.dll
2009-10-05 17:22:43 ----A---- C:\Windows\system32\rasdlg.dll
2009-10-05 17:22:43 ----A---- C:\Windows\system32\netcenter.dll
2009-10-05 17:22:43 ----A---- C:\Windows\system32\iassvcs.dll
2009-10-05 17:22:43 ----A---- C:\Windows\system32\findstr.exe
2009-10-05 17:22:42 ----A---- C:\Windows\system32\wsnmp32.dll
2009-10-05 17:22:42 ----A---- C:\Windows\system32\uxsms.dll
2009-10-05 17:22:42 ----A---- C:\Windows\system32\themecpl.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\tsbyuv.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\srvsvc.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\slcc.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\scansetting.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\powrprof.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\ntmarta.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\networkmap.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\msutb.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\mstsc.exe
2009-10-05 17:22:41 ----A---- C:\Windows\system32\mstlsapi.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\mssprxy.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\iasads.dll
2009-10-05 17:22:41 ----A---- C:\Windows\system32\iasacct.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\themeui.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\systemcpl.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\sud.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\powercpl.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\pcaui.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\newdev.exe
2009-10-05 17:22:40 ----A---- C:\Windows\system32\dot3svc.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\connect.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\authz.dll
2009-10-05 17:22:40 ----A---- C:\Windows\system32\accessibilitycpl.dll
2009-10-05 17:22:39 ----A---- C:\Windows\system32\wlanpref.dll
2009-10-05 17:22:39 ----A---- C:\Windows\system32\usercpl.dll
2009-10-05 17:22:39 ----A---- C:\Windows\system32\samlib.dll
2009-10-05 17:22:39 ----A---- C:\Windows\system32\rpchttp.dll
2009-10-05 17:22:39 ----A---- C:\Windows\system32\qdvd.dll
2009-10-05 17:22:39 ----A---- C:\Windows\system32\mmci.dll
2009-10-05 17:22:39 ----A---- C:\Windows\system32\autoplay.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\wpcao.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\vdsutil.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\tapisrv.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\scksp.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\scesrv.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\regapi.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\psisdecd.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\oleprn.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\msinfo32.exe
2009-10-05 17:22:38 ----A---- C:\Windows\system32\mpr.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\imm32.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\feclient.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\dot3msm.dll
2009-10-05 17:22:38 ----A---- C:\Windows\system32\AudioSes.dll
2009-10-05 17:22:37 ----A---- C:\Windows\system32\wscisvif.dll
2009-10-05 17:22:37 ----A---- C:\Windows\system32\sdclt.exe
2009-10-05 17:22:37 ----A---- C:\Windows\system32\rekeywiz.exe
2009-10-05 17:22:37 ----A---- C:\Windows\system32\ncryptui.dll
2009-10-05 17:22:37 ----A---- C:\Windows\system32\iaspolcy.dll
2009-10-05 17:22:37 ----A---- C:\Windows\system32\Faultrep.dll
2009-10-05 17:22:37 ----A---- C:\Windows\system32\dpapimig.exe
2009-10-05 17:22:37 ----A---- C:\Windows\system32\DeviceEject.exe
2009-10-05 17:22:36 ----A---- C:\Windows\system32\whealogr.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\TSTheme.exe
2009-10-05 17:22:36 ----A---- C:\Windows\system32\tcpmon.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\tcpipcfg.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\spwinsat.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\scecli.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\rasplap.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\rasgcw.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\qedit.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\PnPUnattend.exe
2009-10-05 17:22:36 ----A---- C:\Windows\system32\pnpui.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\perfdisk.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\hdwwiz.exe
2009-10-05 17:22:36 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2009-10-05 17:22:36 ----A---- C:\Windows\system32\fdWSD.dll
2009-10-05 17:22:36 ----A---- C:\Windows\system32\cmmon32.exe
2009-10-05 17:22:36 ----A---- C:\Windows\system32\certreq.exe
2009-10-05 17:22:35 ----A---- C:\Windows\system32\WMVXENCD.DLL
2009-10-05 17:22:35 ----A---- C:\Windows\system32\wlanui.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\wiaaut.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\srcore.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\SnippingTool.exe
2009-10-05 17:22:35 ----A---- C:\Windows\system32\shwebsvc.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\SCardSvr.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\rasppp.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\raschap.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\PnPutil.exe
2009-10-05 17:22:35 ----A---- C:\Windows\system32\MSVidCtl.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\fontext.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\dsprop.dll
2009-10-05 17:22:35 ----A---- C:\Windows\system32\conime.exe
2009-10-05 17:22:35 ----A---- C:\Windows\system32\cmdial32.dll
2009-10-05 17:22:34 ----A---- C:\Windows\system32\oobefldr.dll
2009-10-05 17:22:34 ----A---- C:\Windows\system32\dimsroam.dll
2009-10-05 17:22:33 ----A---- C:\Windows\system32\wmdrmsdk.dll
2009-10-05 17:22:33 ----A---- C:\Windows\system32\shsetup.dll
2009-10-05 17:22:33 ----A---- C:\Windows\system32\rasmontr.dll
2009-10-05 17:22:33 ----A---- C:\Windows\system32\mscandui.dll
2009-10-05 17:22:33 ----A---- C:\Windows\system32\modemui.dll
2009-10-05 17:22:33 ----A---- C:\Windows\system32\chtbrkr.dll
2009-10-05 17:22:32 ----A---- C:\Windows\system32\wlgpclnt.dll
2009-10-05 17:22:32 ----A---- C:\Windows\system32\dataclen.dll
2009-10-05 17:22:32 ----A---- C:\Windows\system32\blackbox.dll
2009-10-05 17:22:31 ----A---- C:\Windows\system32\WSDMon.dll
2009-10-05 17:22:31 ----A---- C:\Windows\system32\wmpeffects.dll
2009-10-05 17:22:31 ----A---- C:\Windows\system32\smss.exe
2009-10-05 17:22:31 ----A---- C:\Windows\system32\rdpwsx.dll
2009-10-05 17:22:31 ----A---- C:\Windows\system32\netplwiz.dll
2009-10-05 17:22:31 ----A---- C:\Windows\system32\credui.dll
2009-10-05 17:22:31 ----A---- C:\Windows\system32\certprop.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\wscapi.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\wpcsvc.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\networkexplorer.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\msscp.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\msimtf.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\logagent.exe
2009-10-05 17:22:30 ----A---- C:\Windows\system32\InkEd.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\ifmon.dll
2009-10-05 17:22:30 ----A---- C:\Windows\system32\gpresult.exe
2009-10-05 17:22:30 ----A---- C:\Windows\system32\cipher.exe
2009-10-05 17:22:29 ----A---- C:\Windows\system32\thawbrkr.dll
2009-10-05 17:22:29 ----A---- C:\Windows\system32\softkbd.dll
2009-10-05 17:22:29 ----A---- C:\Windows\system32\sendmail.dll
2009-10-05 17:22:29 ----A---- C:\Windows\system32\olepro32.dll
2009-10-05 17:22:29 ----A---- C:\Windows\system32\msctfui.dll
2009-10-05 17:22:29 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2009-10-05 17:22:29 ----A---- C:\Windows\system32\dmsynth.dll
2009-10-05 17:22:28 ----A---- C:\Windows\system32\wshbth.dll
2009-10-05 17:22:28 ----A---- C:\Windows\system32\version.dll
2009-10-05 17:22:28 ----A---- C:\Windows\system32\SLLUA.exe
2009-10-05 17:22:28 ----A---- C:\Windows\system32\puiapi.dll
2009-10-05 17:2
A voir également:

3 réponses

Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
Bonjour,

- Désactive l'UAC le temps de la désinfection.

- Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le Bureau.

- Double-clique sur Navilog1.exe afin de lancer l'installation.

- Double-clique sur Navilog1 présent sur le Bureau.
(Sous Vista, il faut cliquer droit sur Navilog1 et choisir Exécuter en tant qu'administrateur)

- Appuie sur 1 puis valide avec Entrée pour choisir Français.

- Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options.

- Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix.

- Patiente le temps du scan. Navilog1 te demandera de redémarrer ton PC.

- Patiente jusqu'au message : *** Scan terminé le ..... ***

- Le scan fini, le Bloc-notes contenant le rapport sera affiché, poste le rapport dans ta prochaine réponse.

- Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\cleannavi.txt
1
ANOuilh
 
Malwarebytes' Anti-Malware 1.41
Version de la base de données: 3076
Windows 6.0.6002 Service Pack 2

01/11/2009 13:24:34
mbam-log-2009-11-01 (13-24-34).txt

Type de recherche: Examen rapide
Eléments examinés: 125996
Temps écoulé: 13 minute(s), 16 second(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 4
Valeur(s) du Registre infectée(s): 2
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 8
Fichier(s) infecté(s): 20

Processus mémoire infecté(s):
C:\Windows\BackUp\explorer.exe (Worm.AutoRun) -> Unloaded process successfully.

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\OOO (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live-Player (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\OOO (Rogue.LivePlayer) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pbcnaa (Trojan.Agent.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\explorer (Worm.AutoRun) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-10 (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-11 (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-12 (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-14 (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-19 (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-21 (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-22 (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\Bron.tok-16-26 (Worm.Brontok) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
c:\Users\Amar\AppData\Local\pbcnaa.exe (Trojan.Agent.H) -> Delete on reboot.
C:\Windows\BackUp\explorer.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\Program Files\explorer.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\Program Files\{17350501621331}.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\explorer.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\$Recycle.Bin\S-1-5-21-583370343-2912786679-2086142570-1002\$REAROD3.exe (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Downloads\u95.zip (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\Users\Amar\Local Settings\Application Data\pbcnaa_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\Users\Amar\Local Settings\Application Data\pbcnaa_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\inetinfo.exe (Worm.Brontok) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\csrss.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\csrss.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\services.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\services.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\smss.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\smss.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
C:\Users\Habib\Local Settings\Application Data\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
--> Relance MBAM, va dans Quarantaine et supprime tout.

--> Refais un scan RSIT et poste le rapport log.
0