ORDINATEUR INFECTE

Bonjour,
je me rend sur le forum car je m'en sort plus, j'ais l'Ordinateur qui est infecté de plein de choses et je ne sais quoi faire, pouvez-vous m'aidez silvouplais ?

Merci beaucoup
Configuration: Windows XP
Internet Explorer 7.0

35 réponses

Résumé de la discussion

La problématique centrale est l'infection d'un ordinateur fonctionnant sous Windows XP avec Internet Explorer 7 et un besoin d'aide pour nettoyer et sécuriser le poste. Des outils comme Malwarebytes' Anti-Malware et CCleaner sont recommandés, suivis d'un démarrage en mode sans échec et d'un balayage complet, puis la suppression des malwares et la génération de rapports. En cas de symptômes tenaces, la procédure propose ensuite des outils complémentaires comme SDFix et HijackThis, l'exécution en mode sans échec et la sauvegarde des rapports avant redémarrage pour évaluer les éléments résiduels. Pour éviter de futures infections, il est conseillé d'activer les mises à jour de sécurité et d'utiliser des outils de sécurité régulièrement, tout en évitant les liens et téléchargements non vérifiés.

Bobot (l’IA à votre service)
  1. Quenini,

    Fait rien de cela stp Fabrice.

    A moins que tu veuilles acheter Kaspersky (le meilleur AV à mon sens). Le lien en question correspond à un lien commercial.

    Je passe à table...
    Je te réponds après.

    PS : jean_louis_57 merci de ne pas arriver comme un cheveu sur la soupe dans les discussions.
    2
    1. oki dlld, je suis tes conseils, je ne fai pas
      0
  2. Re

    Démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8
    ((Si F8 ne marche pas utilise la touche F5)).
    dès le début de l’allumage du pc sans t’arrêter.
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du
    clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
    ----------------------------------------------------------------------------
    Relance le programme Smitfraud,
    Cette fois choisit l’option 2,
    répond oui à tous ;
    Sauvegarde le rapport,
    Redémarre en mode normal,
    Copie/colle le rapport sauvegardé sur le forum

    ps :: si le rapport est trop long tu n'envoies que le début

    +++

    1
    1. Comme tu le dis , c'est yltra long ihi, mais voilà quand même le début :

      SmitFraudFix v2.320

      Rapport fait à 15:12:30,10, 09/05/2008
      Executé à partir de C:\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      127.0.0.1 www.007guard.com
      127.0.0.1 007guard.com
      127.0.0.1 008i.com
      127.0.0.1 www.008k.com
      127.0.0.1 008k.com
      127.0.0.1 www.00hq.com
      127.0.0.1 00hq.com
      127.0.0.1 010402.com
      127.0.0.1 www.032439.com
      127.0.0.1 032439.com
      127.0.0.1 www.1001-search.info
      127.0.0.1 1001-search.info
      127.0.0.1 www.100888290cs.com
      127.0.0.1 100888290cs.com
      127.0.0.1 www.100sexlinks.com
      127.0.0.1 100sexlinks.com
      127.0.0.1 www.10sek.com
      127.0.0.1 10sek.com
      127.0.0.1 www.123topsearch.com
      127.0.0.1 123topsearch.com
      127.0.0.1 www.132.com
      127.0.0.1 132.com
      127.0.0.1 www.136136.net
      127.0.0.1 136136.net
      127.0.0.1 www.139mm.com
      127.0.0.1 139mm.com
      127.0.0.1 www.163ns.com
      127.0.0.1 163ns.com
      127.0.0.1 171203.com
      127.0.0.1 17-plus.com
      127.0.0.1 www.1800searchonline.com
      127.0.0.1 1800searchonline.com
      127.0.0.1 www.180searchassistant.com
      127.0.0.1 180searchassistant.com
      127.0.0.1 www.180solutions.com
      127.0.0.1 180solutions.com
      127.0.0.1 www.181.365soft.info
      127.0.0.1 181.365soft.info
      127.0.0.1 www.1987324.com
      127.0.0.1 1987324.com
      127.0.0.1 www.1-domains-registrations.com
      127.0.0.1 1-domains-registrations.com
      127.0.0.1 www.1-extreme.biz
      127.0.0.1 1-extreme.biz
      127.0.0.1 www.1sexparty.com
      127.0.0.1 1sexparty.com
      127.0.0.1 www.1stantivirus.com
      127.0.0.1 1stantivirus.com
      127.0.0.1 www.1stpagehere.com
      127.0.0.1 1stpagehere.com
      127.0.0.1 www.1stsearchportal.com
      127.0.0.1 1stsearchportal.com
      127.0.0.1 2.82211.net
      127.0.0.1 www.2006ooo.com
      127.0.0.1 www.2007-download.com
      127.0.0.1 2007-download.com
      127.0.0.1 www.2020search.com
      127.0.0.1 2020search.com
      127.0.0.1 20x2p.com
      127.0.0.1 www.24.365soft.info
      127.0.0.1 24.365soft.info
      127.0.0.1 www.24-7pharmacy.info
      127.0.0.1 24-7pharmacy.info
      127.0.0.1 www.24-7searching-and-more.com
      127.0.0.1 24-7searching-and-more.com
      127.0.0.1 www.24teen.com
      127.0.0.1 24teen.com
      127.0.0.1 www.2every.net
      127.0.0.1 2every.net
      127.0.0.1 2ndpower.com
      127.0.0.1 www.2search.com
      127.0.0.1 2search.com
      127.0.0.1 www.2search.org
      127.0.0.1 2search.org
      127.0.0.1 www.2squared.com
      127.0.0.1 2squared.com
      127.0.0.1 www.3322.org
      127.0.0.1 3322.org
      127.0.0.1 365soft.info
      127.0.0.1 www.36site.com
      127.0.0.1 36site.com
      127.0.0.1 3721.com
      127.0.0.1 39-93.com
      127.0.0.1 www.3abetterinternet.com
      127.0.0.1 3abetterinternet.com
      127.0.0.1 www.3bay.it
      127.0.0.1 3bay.it
      127.0.0.1 www.3ebay.it
      127.0.0.1 3ebay.it
      127.0.0.1 www.3xclipsonline.com
      127.0.0.1 3xclipsonline.com
      127.0.0.1 www.3xcurves.com
      127.0.0.1 3xcurves.com
      127.0.0.1 www.3xfestival.com
      127.0.0.1 3xfestival.com
      127.0.0.1 www.3x-festival.com
      127.0.0.1 3x-festival.com
      127.0.0.1 www.3x-galls.com
      127.0.0.1 3x-galls.com
      127.0.0.1 www.3xmiracle.com
      127.0.0.1 3xmiracle.com
      127.0.0.1 www.3xmoviesblog.com
      127.0.0.1 3xmoviesblog.com
      127.0.0.1 www.404dns.com
      127.0.0.1 404dns.com
      127.0.0.1 www.4199.com
      127.0.0.1 4199.com
      127.0.0.1 www.4corn.net
      127.0.0.1 4corn.net
      127.0.0.1 www.4ebay.it
      127.0.0.1 4ebay.it
      127.0.0.1 4klm.com
      127.0.0.1 www.4mpg.com
      127.0.0.1 4mpg.com
      127.0.0.1 www.4repubblica.it
      127.0.0.1 4repubblica.it
      127.0.0.1 www.4softget.com
      127.0.0.1 4softget.com
      127.0.0.1 www.5iscali.it
      127.0.0.1 5iscali.it
      127.0.0.1 www.5repubblica.it
      127.0.0.1 5repubblica.it
      127.0.0.1 www.5starvideos.com
      127.0.0.1 5starvideos.com
      127.0.0.1 www.5tiscali.it
      127.0.0.1 5tiscali.it
      127.0.0.1 www.5zgmu7o20kt5d8yq.com
      127.0.0.1 5zgmu7o20kt5d8yq.com
      127.0.0.1 www.680180.net
      127.0.0.1 680180.net
      127.0.0.1 www.6iscali.it
      127.0.0.1 6iscali.it
      127.0.0.1 www.6njaga.com
      127.0.0.1 6njaga.com
      127.0.0.1 www.6sek.com
      127.0.0.1 6sek.com
      127.0.0.1 www.6tiscali.it
      127.0.0.1 6tiscali.it
      127.0.0.1 www.70-music.com
      127.0.0.1 70-music.com
      127.0.0.1 www.7322.com
      127.0.0.1 7322.com
      127.0.0.1 75tz.com
      127.0.0.1 www.777search.com
      127.0.0.1 777search.com
      127.0.0.1 www.777top.com
      127.0.0.1 777top.com
      127.0.0.1 www.7939.com
      127.0.0.1 7939.com
      127.0.0.1 www.7search.com
      127.0.0.1 7search.com
      127.0.0.1 80gw6ry3i3x3qbrkwhxhw.032439.com
      127.0.0.1 www.80-music.com
      127.0.0.1 80-music.com
      127.0.0.1 82211.net
      127.0.0.1 8866.org
      127.0.0.1 www.888.com
      127.0.0.1 888.com
      127.0.0.1 www.8ad.com
      127.0.0.1 8ad.com
      127.0.0.1 www.90-music.com
      127.0.0.1 90-music.com
      127.0.0.1 www.9505.com
      127.0.0.1 9505.com
      127.0.0.1 www.971searchbox.com
      127.0.0.1 971searchbox.com
      127.0.0.1 a.bestmanage.org
      127.0.0.1 www.aaabesthomepage.com
      127.0.0.1 aaabesthomepage.com
      127.0.0.1 aaasexypics.com
      127.0.0.1 www.aaawebfinder.com
      127.0.0.1 aaawebfinder.com
      127.0.0.1 www.aaqadarsztriv.com
      127.0.0.1 aaqadarsztriv.com
      127.0.0.1 www.aaqada-rsztriv.com
      127.0.0.1 aaqada-rsztriv.com
      127.0.0.1 www.aaqadaueorn.com
      127.0.0.1 aaqadaueorn.com
      127.0.0.1 www.aaqada-ueorn.com
      127.0.0.1 aaqada-ueorn.com
      127.0.0.1 www.aaqada-ygco.com
      127.0.0.1 aaqada-ygco.com
      127.0.0.1 www.aaqada-ymct.com
      127.0.0.1 aaqada-ymct.com
      127.0.0.1 aavc.com
      127.0.0.1 www.abcdperformance.com
      127.0.0.1 abcdperformance.com
      127.0.0.1 www.abc-find.info
      127.0.0.1 abc-find.info
      127.0.0.1 www.abcsearch.com
      127.0.0.1 abcsearch.com
      127.0.0.1 www.abetterinternet.com
      127.0.0.1 abetterinternet.com
      127.0.0.1 www.abnetsoft.info
      127.0.0.1 abnetsoft.info
      127.0.0.1 www.aboutclicker.com
      127.0.0.1 aboutclicker.com
      127.0.0.1 www.abrp.net
      127.0.0.1 abrp.net
      127.0.0.1 www.absolutee.com
      127.0.0.1 absolutee.com
      127.0.0.1 www.abyssmedia.com
      127.0.0.1 abyssmedia.com
      127.0.0.1 www.ac66.cn
      127.0.0.1 ac66.cn
      127.0.0.1 access.Navinetwork.com
      127.0.0.1 access.rapid-pass.net
      127.0.0.1 www.accessactivexvideo.com
      127.0.0.1 accessactivexvideo.com
      127.0.0.1 www.accessclips.com
      127.0.0.1 accessclips.com
      127.0.0.1 www.access-dvd.com
      127.0.0.1 access-dvd.com
      127.0.0.1 www.accesskeygenerator.com
      127.0.0.1 accesskeygenerator.com
      127.0.0.1 www.accessorygeeks.com
      127.0.0.1 accessorygeeks.com
      127.0.0.1 www.accessthefuture.net
      127.0.0.1 accessthefuture.net
      127.0.0.1 www.accessvid.net
      127.0.0.1 accessvid.net
      127.0.0.1 www.acemedic.com
      127.0.0.1 acemedic.com
      127.0.0.1 www.ace-webmaster.com
      127.0.0.1 ace-webmaster.com
      127.0.0.1 acjp.com
      127.0.0.1 www.acrobat-2007.com
      127.0.0.1 acrobat-2007.com
      127.0.0.1 www.acrobat-8.com
      127.0.0.1 acrobat-8.com
      127.0.0.1 www.acrobat-center.com
      127.0.0.1 acrobat-center.com
      127.0.0.1 www.acrobat-hq.com
      127.0.0.1 acrobat-hq.com
      127.0.0.1 www.acrobatreader-8.com
      127.0.0.1 acrobatreader-8.com
      127.0.0.1 www.acrobat-reader-8.de
      127.0.0.1 acrobat-reader-8.de
      127.0.0.1 www.acrobat-stop.com
      127.0.0.1 acrobat-stop.com
      127.0.0.1 www.actionbreastcancer.org
      127.0.0.1 actionbreastcancer.org
      127.0.0.1 www.activesearcher.info
      127.0.0.1 activesearcher.info
      127.0.0.1 www.activexaccessobject.com
      127.0.0.1 activexaccessobject.com
      127.0.0.1 www.activexaccessvideo.com
      127.0.0.1 activexaccessvideo.com
      127.0.0.1 www.activexemedia.com
      127.0.0.1 activexemedia.com
      127.0.0.1 www.activexmediaobject.com
      127.0.0.1 activexmediaobject.com
      127.0.0.1 www.activexmediapro.com
      127.0.0.1 activexmediapro.com
      127.0.0.1 www.activexmediasite.com
      127.0.0.1 activexmediasite.com
      127.0.0.1 www.activexmediasoftware.com
      127.0.0.1 activexmediasoftware.com
      127.0.0.1 www.activexmediasource.com
      127.0.0.1 activexmediasource.com
      127.0.0.1 www.activexmediatool.com
      127.0.0.1 activexmediatool.com
      127.0.0.1 www.activexmediatour.com
      127.0.0.1 activexmediatour.com
      127.0.0.1 www.activexsoftwares.com
      127.0.0.1 activexsoftwares.com
      127.0.0.1 www.activexsource.com
      127.0.0.1 activexsource.com
      127.0.0.1 www.activexupdate.com
      127.0.0.1 activexupdate.com
      127.0.0.1 www.activexvideo.com
      127.0.0.1 activexvideo.com
      127.0.0.1 www.activexvideotool.com
      127.0.0.1 activexvideotool.com
      127.0.0.1 www.ad.marketingsector.com
      127.0.0.1 ad.marketingsector.com
      127.0.0.1 www.ad.mokead.com
      127.0.0.1 ad.mokead.com
      127.0.0.1 ad.oinadserver.com
      127.0.0.1 ad.outerinfoads.com
      127.0.0.1 www.ad25.com
      127.0.0.1 ad25.com
      127.0.0.1 www.ad45.com
      127.0.0.1 ad45.com
      127.0.0.1 www.ad77.com
      127.0.0.1 ad77.com
      127.0.0.1 www.ad86.com
      127.0.0.1 ad86.com
      127.0.0.1 www.adamsupportgroup.org
      127.0.0.1 adamsupportgroup.org
      127.0.0.1 www.adarmor.com
      127.0.0.1 adarmor.com
      127.0.0.1 www.adasearch.com
      127.0.0.1 adasearch.com
      127.0.0.1 adaware.cc
      127.0.0.1 www.adawarenow.com
      127.0.0.1 adawarenow.com
      127.0.0.1 adchannel.contextplus.net
      127.0.0.1 www.addetect.com
      127.0.0.1 addetect.com
      127.0.0.1 www.add-hhh.info
      127.0.0.1 add-hhh.info
      127.0.0.1 www.addictivetechnologies.com
      127.0.0.1 addictivetechnologies.com
      127.0.0.1 www.addictivetechnologies.net
      127.0.0.1 addictivetechnologies.net
      127.0.0.1 www.addioerrori.com
      127.0.0.1 addioerrori.com
      127.0.0.1 www.add-manager.com
      127.0.0.1 add-manager.com
      127.0.0.1 www.adgate.info
      127.0.0.1 adgate.info
      127.0.0.1 www.adintelligence.net
      127.0.0.1 adintelligence.net
      127.0.0.1 www.adioserrores.com
      127.0.0.1 adioserrores.com
      127.0.0.1 www.adipics.com
      127.0.0.1 adipics.com
      127.0.0.1 www.adlogix.com
      127.0.0.1 adlogix.com
      127.0.0.1 www.admin2cash.biz
      127.0.0.1 admin2cash.biz
      127.0.0.1 adnet-plus.com
      127.0.0.1 www.adnetserver.com
      127.0.0.1 adnetserver.com
      127.0.0.1 adobe-download-now.com
      127.0.0.1 www.adobe-downloads.com
      127.0.0.1 adobe-downloads.com
      127.0.0.1 www.adobe-reader-8.fr
      127.0.0.1 adobe-reader-8.fr
      127.0.0.1 www.adprotect.com
      127.0.0.1 adprotect.com
      127.0.0.1 ads.centralmedia.ws
      127.0.0.1 ads.k8l.info
      127.0.0.1 ads.kmpads.com
      127.0.0.1 ads.kw.revenue.net
      127.0.0.1 ads.marketingsector.com
      127.0.0.1 ads.searchingbooth.com
      127.0.0.1 ads.z-quest.com
      127.0.0.1 ads1.revenue.net
      127.0.0.1 www.ads183.com
      127.0.0.1 ads183.com
      127.0.0.1 www.adscontex.com
      127.0.0.1 adscontex.com
      127.0.0.1 www.adservices1.enhance.com
      127.0.0.1 adservices1.enhance.com
      127.0.0.1 adservs.com
      127.0.0.1 www.adsextend.net
      127.0.0.1 adsextend.net
      127.0.0.1 www.adshttp.com
      127.0.0.1 adshttp.com
      127.0.0.1 www.adsniffer.com
      127.0.0.1 adsniffer.com
      127.0.0.1 www.adsonwww.com
      127.0.0.1 adsonwww.com
      127.0.0.1 www.adspics.com
      127.0.0.1 adspics.com
      127.0.0.1 www.adsrevenue.net
      127.0.0.1 adsrevenue.net
      127.0.0.1 www.adtrak.net
      127.0.0.1 adtrak.net
      127.0.0.1 adtrgt.com
      127.0.0.1 www.adult777search.info
      127.0.0.1 adult777search.info
      127.0.0.1 www.adultan.com
      127.0.0.1 adultan.com
      127.0.0.1 www.adult-engine-search.com
      127.0.0.1 adult-engine-search.com
      127.0.0.1 www.adult-erotic-guide.net
      127.0.0.1 adult-erotic-guide.net
      127.0.0.1 www.adultfilmsite.com
      127.0.0.1 adultfilmsite.com
      127.0.0.1 www.adult-friends-finder.net
      127.0.0.1 adult-friends-finder.net
      127.0.0.1 adultgambling.org
      127.0.0.1 adult-host.org
      127.0.0.1 www.adulthyperlinks.com
      127.0.0.1 adulthyperlinks.com
      127.0.0.1 www.adultmovieplus.com
      127.0.0.1 adultmovieplus.com
      127.0.0.1 www.adult-mpg.net
      127.0.0.1 adult-mpg.net
      127.0.0.1 adult-personal.us
      127.0.0.1 adultsgames.net
      127.0.0.1 www.adultsonlyvids.com
      127.0.0.1 adultsonlyvids.com
      127.0.0.1 www.adultsper.com
      127.0.0.1 adultsper.com
      127.0.0.1 www.adulttds.com
      127.0.0.1 adulttds.com
      127.0.0.1 www.adultzoneworld.com
      127.0.0.1 adultzoneworld.com
      127.0.0.1 www.advcash.biz
      127.0.0.1 advcash.biz
      127.0.0.1 advert.exaccess.ru
      127.0.0.1 www.advertisemoney.info
      127.0.0.1 advertisemoney.info
      127.0.0.1 advertising.paltalk.com
      127.0.0.1 www.advertising-money.info
      127.0.0.1 advertising-money.info
      127.0.0.1 ad-ware.cc
      127.0.0.1 www.ad-w-a-r-e.com
      127.0.0.1 ad-w-a-r-e.com
      127.0.0.1 www.a-d-w-a-r-e.com
      127.0.0.1 a-d-w-a-r-e.com
      127.0.0.1 www.adware.pro
      127.0.0.1 adware.pro
      127.0.0.1 www.adwarealert.com
      127.0.0.1 adwarealert.com
      127.0.0.1 www.ad-warealert.com
      127.0.0.1 ad-warealert.com
      127.0.0.1 www.adwarearrest.com
      127.0.0.1 adwarearrest.com
      127.0.0.1 www.adwarebazooka.com
      127.0.0.1 adwarebazooka.com
      127.0.0.1 www.adwarecommander.com
      127.0.0.1 adwarecommander.com
      127.0.0.1 www.adwarefinder.com
      127.0.0.1 adwarefinder.com
      127.0.0.1 www.adwaregold.com
      127.0.0.1 adwaregold.com
      127.0.0.1 www.adwarepatrol.com
      127.0.0.1 adwarepatrol.com
      127.0.0.1 www.adwareplatinum.com
      127.0.0.1 adwareplatinum.com
      127.0.0.1 www.adwareprotectionsite.com
      127.0.0.1 adwareprotectionsite.com
      127.0.0.1 www.adwarepunisher.com
      127.0.0.1 adwarepunisher.com
      127.0.0.1 www.adwareremover.ws
      127.0.0.1 adwareremover.ws
      127.0.0.1 www.adwaresafety.com
      127.0.0.1 adwaresafety.com
      127.0.0.1 www.adwarexp.com
      127.0.0.1 adwarexp.com
      127.0.0.1 affiliate.idownload.com
      127.0.0.1 www.aflgate.com
      127.0.0.1 aflgate.com
      127.0.0.1 africaspromise.org
      127.0.0.1 agava.com
      127.0.0.1 agava.ru
      127.0.0.1 agentstudio.com
      127.0.0.1 www.aginegialle.it
      127.0.0.1 aginegialle.it
      127.0.0.1 aifind.info
      127.0.0.1 www.aifind.info
      127.0.0.1 www.airtleworld.com
      127.0.0.1 airtleworld.com
      127.0.0.1 www.aitalia.it
      127.0.0.1 aitalia.it
      127.0.0.1 akamai.downloadv3.com
      127.0.0.1 www.aklitalia.it
      127.0.0.1 aklitalia.it
      127.0.0.1 akril.com
      127.0.0.1 alcatel.ws
      127.0.0.1 www.alertspy.com
      127.0.0.1 alertspy.com
      127.0.0.1 www.alfacleaner.com
      127.0.0.1 alfacleaner.com
      127.0.0.1 alfa-search.com
      127.0.0.1 www.alialia.it
      127.0.0.1 alialia.it
      127.0.0.1 www.aliotalia.it
      127.0.0.1 aliotalia.it
      127.0.0.1 www.alirtalia.it
      127.0.0.1 alirtalia.it
      127.0.0.1 www.alitaia.it
      127.0.0.1 alitaia.it
      127.0.0.1 www.alitaklia.it
      127.0.0.1 alitaklia.it
      127.0.0.1 www.alitala.it
      127.0.0.1 alitala.it
      127.0.0.1 www.alitali.it
      127.0.0.1 alitali.it
      127.0.0.1 www.alitaliaq.it
      127.0.0.1 alitaliaq.it
      127.0.0.1 www.alitalias.it
      127.0.0.1 alitalias.it
      127.0.0.1 www.alitaliaz.it
      127.0.0.1 alitaliaz.it
      127.0.0.1 www.alitalioa.it
      127.0.0.1 alitalioa.it
      127.0.0.1 www.alitalisa.it
      127.0.0.1 alitalisa.it
      127.0.0.1 www.alitaliua.it
      127.0.0.1 alitaliua.it
      127.0.0.1 www.alitalkia.it
      127.0.0.1 alitalkia.it
      127.0.0.1 www.alitaloia.it
      127.0.0.1 alitaloia.it
      127.0.0.1 www.alitaluia.it
      127.0.0.1 alitaluia.it
      127.0.0.1 www.alitaslia.it
      127.0.0.1 alitaslia.it
      127.0.0.1 www.alitlia.it
      127.0.0.1 alitlia.it
      127.0.0.1 www.alitralia.it
      127.0.0.1 alitralia.it
      0
    2. et voici aussi la fin :

      127.0.0.1 www.stromverbrauch.de
      127.0.0.1 stromverbrauch.de
      127.0.0.1 www.sudoku.de
      127.0.0.1 sudoku.de
      127.0.0.1 www.sudoku-jetzt.de
      127.0.0.1 sudoku-jetzt.de
      127.0.0.1 www.sudoku-welt.com
      127.0.0.1 sudoku-welt.com
      127.0.0.1 www.tattoo-paradies.de
      127.0.0.1 tattoo-paradies.de
      127.0.0.1 www.tattoo-server.com
      127.0.0.1 tattoo-server.com
      127.0.0.1 www.tattoos-paradies.de
      127.0.0.1 tattoos-paradies.de
      127.0.0.1 www.thespybot.com
      127.0.0.1 thespybot.com
      127.0.0.1 www.tiere-infos.de
      127.0.0.1 tiere-infos.de
      127.0.0.1 www.trauergedichte.de
      127.0.0.1 trauergedichte.de
      127.0.0.1 www.verkehrsprofi.com
      127.0.0.1 verkehrsprofi.com
      127.0.0.1 www.verwandschafts-test.de
      127.0.0.1 verwandschafts-test.de
      127.0.0.1 www.vorlagen-archiv.com
      127.0.0.1 vorlagen-archiv.com
      127.0.0.1 www.vorlagen-paradies.de
      127.0.0.1 vorlagen-paradies.de
      127.0.0.1 www.vorlagen-world.de
      127.0.0.1 vorlagen-world.de
      127.0.0.1 www.wer-bumst-mich.de
      127.0.0.1 wer-bumst-mich.de
      127.0.0.1 www.xlarea.com
      127.0.0.1 xlarea.com
      127.0.0.1 www.xldd.com
      127.0.0.1 xldd.com

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

      S!Ri's WS2Fix: LSP not Found.

      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
  3. Télécharge Zeb-Restore : http://telechargement.zebulon.fr/zeb-restore.html
    - Mets le dans un dossier, sur ton bureau par exemple.
    - Lance Zebrestore et coche la/les case(s) suivante(s) :

    RegEdit
    Clés RUN
    Bouton Arrêter
    Windows Update
    Gestionnaire des tâches
    Panneau de configuration
    Ajout/Suppression de programmes
    Policies
    Bureau
    Sites de confiance et sensibles
    Préfixes et Protocoles Internet
    Réinitialiser Fichier Hosts

    - Ne coche que la/les case(s) indiquée(s).
    - Clique sur le bouton Restaurer.

    Relance smitfraud option 2 pour vérification

    puis renvoie un log HiJack

    +++

    1
    1. 16:18 09/05/200816:18 09/05/2008Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:18:33, on 09/05/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\mysql\bin\mysqld-nt.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Apps\Softex\OmniPass\Omniserv.exe
      C:\WINDOWS\system32\slserv.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\Apps\Softex\OmniPass\OPXPApp.exe
      C:\WINDOWS\Explorer.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\WINDOWS\mHotkey.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
      C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
      C:\Program Files\MIC\HAWAII\Hawaii.exe
      C:\Apps\Softex\OmniPass\scureapp.exe
      C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
      C:\WINDOWS\system32\RunDLL32.exe
      C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\APPS\SMP\SmpSys.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\BitComet\BitComet.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Octoshape Streaming Services\FabricE\OctoshapeClient.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.seduction.fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O2 - BHO: (no name) - {D11A646E-0C3C-4EE3-9362-DB0D9DFF3D52} - C:\WINDOWS\system32\geBssPjk.dll (file missing)
      O2 - BHO: (no name) - {F035A9A0-19F1-4B31-9296-82CECC37DB49} - C:\WINDOWS\system32\efcYpPjK.dll (file missing)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [NECHotkey] mHotkey.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
      O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
      O4 - HKLM\..\Run: [MM_MODULE] C:\Program Files\MIC\HAWAII\Hawaii.exe
      O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
      O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
      O4 - HKLM\..\Run: [PD0630 STISvc] RunDLL32.exe P0630Pin.dll,RunDLL32EP 513
      O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
      O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\FabricE\OctoshapeClient.exe" -inv:bootrun
      O4 - HKCU\..\Run: [Windows Update] C:\WINDOWS\system32\rundll.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
      O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {E55FD215-A32E-43FE-A777-A7E8F165F554} (Flatcast Viewer 4.16) - http://80.237.209.20/objects/NpFv41629.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: nnnlmLcy - nnnlmLcy.dll (file missing)
      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
      O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
      O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe (file missing)
      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      0
    2. @Utilisateur anonymeCoucou,

      Relance smitfraud option 2 pour vérification (^^Marie^^)

      => poste le rapport stp !

      Merci
      0
    3. SmitFraudFix v2.320

      Rapport fait à 16:51:18,39, 09/05/2008
      Executé à partir de C:\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      127.0.0.1 localhost

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

      S!Ri's WS2Fix: LSP not Found.

      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
    4. @Utilisateur anonymeça va c'est disparu, le problem n'apparait plus, mais j'ai encore un problem, c'est que quand je veux mettre l'ordinateur en veille, il'ecran devien tou noir il se met en veille, mais l'ordinateur ne s'arrête pas, il continue de tourner ..

      Je suis vraimen nul lol bisoux
      0
  4. Bonsoir/bonjour,

    Ok Fabrice. Comment vas tu ?

    Bon il reste de la crasse sur ton PC....(pas grand chose mais il faut virer Windows Update quand même : le mauvais, même si son nom semble sympatique...).

    Alors,
    Gros nettoyage de printemps :
    > Les logiciels suivants (MalwareByte's Anti-Malware et Ccleaner) te seront utiles par la suite - ils sont à conserver...

    > Télécharge MalwareByte's Anti-Malware :
    - Installe le programme puis lance le stp.
    NB : S'il te manque COMCTL32.OCX alors télécharge le ici
    - Fais les mises à jour (clique sur "Mises à jour" puis "Recherche de mises à jour") puis ferme le programme.
    NB : Si tu as besoin : Tuto

    > Télécharge et installe Ccleaner :
    - Fais les mises à jour puis ferme le programme.
    Si besoin est tu trouveras des Tutoriaux : ici, ici et là.

    > Télécharge Clean (de Malekal Morte) (différent de Ccleaner)

    > Télécharge SDFix (de AndyManchesta) sur ton bureau :
    - Double clique sur l'archive SDFix qui à été créé sur le Bureau et installe le programme (l'installation va créer un dossier (à la racine du disque dur par défaut) nommé SDFix. Ferme ensuite le programme.

    > Commence par faire un copier/coller de ce poste (cette manip.): (conseillé)
    Ouvre un nouveau fichier Bloc notes (clique sur "Démarrer" => "Programmes" =>"Accessoires" => "Bloc notes"),
    puis fait un copier/coller de tout le contenu de la fenêtre de ce poste dans le fichier texte.
    Sauvegarde le sur le bureau, tu pourras alors y avoir accès même déconnecté ou en mode sans échec.

    > Démarre en mode sans échec : (image). Si problème : tuto ici

    > Lance MalwareByte's Anti-Malware,
    - Clique sur "Executer un examen complet" puis "Rechercher" et sélectionne tous tes disques durs => le scan débute....patiente...
    - A la fin du scanne, clique sur "supprimer" (Si des éléments sont difficiles à supprimer, un message te demandera de redémarrer : clique sur "Oui" alors)
    - Un rapport va être généré (le dernier après supression des infections) : sauvegarde le et poste le sur forum stp.

    > Lance Ccleaner,
    - Choisi l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures" (tout doit être supprimé).
    - Dans l'onglet "Nettoyeur" clique sur "Analyse".
    - Une fois l'analyse terminée, clique sur "Lancer le Nettoyage".
    - Dans l'onglet "registre" => Recherches des erreurs => Réparer les erreurs sélectionnées => enregistre une sauvegarde => corriger toutes erreurs sélectionnées => ok => fermer.
    N.B : Si Ccleaner te propose d'enregistrer une sauvegarde, reponds oui et enregistre sous 'Bureau'
    Recommence jusqu’à ce qu’il ne trouve plus rien (cela varie en général entre 1 et 4 fois).

    > Pour Clean (encore en mode sans échec) :
    - Double-clic sur clean.cmd
    - Une fenêtre va apparaître, choisis l'option 2, suis les consignes et poste le rapport clean (Le rapport clean se trouve ici : C:\rapport_clean.txt)
    NB : Si besoin : Tuto

    > Pour SDFix (toujours en mode sans échec) :
    - Vas dans c:/SDFix et double-clique sur RunThis.bat
    - Appuie sur < Y > puis < Entrée >....Le nettoyage commence....patience...
    - Le programme va te demander de relancer le PC, frappe une touche...
    - Le nettoyage se termine...un rapport apparait...
    -Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse

    > Relance ton PC en mode normal

    > Relance Hijackthis :
    Puis sélectionne < do a system scan and save a logfile >,

    Et envoie moi, par collier/coller, ton log Hijackthis stp,

    Bon courage,

    :)

    NB : N'oublie pas de poster TOUS les rapports stp ( MalwareByte's Anti-Malware, Clean (différent de Ccleaner - ne poste pas celui de Ccleaner), SDFix puis HiJAckT).

    A+
    1
    1. Allors voici tous les rapports obtenus :

      Malwarebytes' Anti-Malware 1.12
      Version de la base de données: 737

      Type de recherche: Examen complet (A:\|C:\|D:\|E:\|F:\|)
      Eléments examinés: 136572
      Temps écoulé: 31 minute(s), 59 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 34
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 15
      Fichier(s) infecté(s): 162

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\browsingadvisor.pornpro_bho (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\browsingadvisor.pornpro_bho.1 (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{f1e96edc-e0c8-be98-1f15-c29dbed83b53} (Adware.PlayMP3Z-biz) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mm_module (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/Publisher,version=1.5 (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\MozillaPlugins\@videoegg.com/Publisher,version=1.5 (Adware.VideoEgg) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Mirar (AdWare.Mirar) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\PlayMP3 (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      C:\Program Files\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
      C:\Program Files\FBrowserAdvisor (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Data (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Loader (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Loader\4665 (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520 (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4665 (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater\4665 (Adware.VideoEgg) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      C:\Program Files\MIC\HAWAII\uninst.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP100\A0074205.dll (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP69\A0029811.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Loader\4665\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater\updater.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater\VideoEggBroker.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater\VideoEggBroker.exe.old (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP117\A0075028.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP117\A0075044.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP117\A0075046.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP117\A0075047.old (Adware.VideoEgg) -> Quarantined and deleted successfully.
      C:\Program Files\FBrowsingAdvisor\Thumbs.db (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\DataLOCKED (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Uninstall.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Data\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Loader\loader.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\publisher.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\avcodec.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\crashRpt.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\FLVEncoder.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\lame_enc.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\LevelMeter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\libcurlve.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\libpng.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\npvideoegg-publisher.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\VideoEgg_FLVWriter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\zlib.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\aol_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\audio_combo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\audio_source.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\big_gray_logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\big_logo_cropped.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\blank_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\button_browse_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\button_browse_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\button_browse_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\camcorders_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\camcorder_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_bottom_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_top_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropshadow_horiz.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropshadow_vertical.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropzone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_instructions.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_sent.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_sent_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_sent_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\eraser.CUR (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\eraser_cursor.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\file_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\file_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\help.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorders.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorder_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorder_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_ff.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_file_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_file_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_phone_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_phone_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcam.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcams.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcam_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcam_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\loading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\loading_movie.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\locating.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo_bottom.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo_middle.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo_top.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\mobile_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\mobile_slide_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\movie_placeholder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\ok.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\ok_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\ok_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_rewind_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_rewind_to_start.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\playhead.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\powered_by.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\progress.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\refresh_list_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\refresh_list_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\refresh_list_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\restart.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\restart_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_over_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\tab_slide_deselected.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\tape_control.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_camcorder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_camcorder_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_file.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_file_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_phone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_phone_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_webcam.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_webcam_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_medium.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_thumbnail.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload_from.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_gray.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_green.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_orange.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_red.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\waiting_for_email.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\webcams_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\webcam_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\webcam_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\messages\messages.en-US.bundle (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater\updater.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater\4665\libcurlve.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      D:\Documents and Settings\Fabrice\Application Data\VideoEgg\Updater\4665\updater.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
      0
    2. voilaaa tout est posté ..

      Merci fortement encore une fois de m'aider
      0
  5. bonsoir,

    donne des précision sur ton os
    ton anti virus
    ton anti pub
    marque tes problèmes constaté
    0
    1. Alors j'ai comme antivirus : Avira Antivir

      Et j'aai aussi Zone Alarm d'installé, et les problemes sont que l'ordinateur en naviguant sur le net rame de plus en plus, et aussi a chaque 10 minutes, il y a 2 fenêtres de Avira Antivir qui apparaissent pour signaler un virus, ça ne s'en va pas, .

      Merci encore
      0
      1. bonjour

        je reviens pour te dire que ton anti virus est pas bon

        cela aussi fait que!!!
        0
        1. Bonjour Jean Louis

          Pourquoi ANTIVIR n'est pas bon ??

          0
      2. bonjour,

        se sont que des suppositions qui amène que

        http://www.commentcamarche.net/forum/affich 5704114 rapport antivir pas bon

        aprés la liberté d'expression fait que je les dits
        0
        1. Re

          Faut pas se baser sur 1 topik...

          Faut tout lire et comprendre pour quoi LE PC a été infecté..
          Comment l' AV a été paramétré, etc...

          Antivir est un excellent AV

          Faut voir dans l' Hijackthis, il parera de lui même

          +++
          0
      3. bonjour

        alors je donne mon avis le reste je cherche a répondre a des demandes d'aides

        c'est tout
        0
        1. Je te donne des tuyaux ;;))

          0
      4. merci a toi

        tu est doué aller je part des trucs a faire si tu veux mes coordonnée msn en mp je peut

        tout ça juste pour informatique
        0
        1. Mon fond d'écran que j'ai pris dans mes photo est pixelé quand les raccourcis sont en place .Comment faire pour règler ce petit problème?
          0
          1. bonjour

            tu as ta carte grphique a jour????
            l'image est sous quelle format
            0
            1. bonjour

              je te relance pour savoir ou tu en est ???
              0
              1. Contributeur sécurité
                Bonjour

                "je te relance pour savoir ou tu en est ???"

                Qui ? fabrygas et son probmème d'infection ou titof qui est arrivé comme un cheveu sur la soupe....
                Faut pas tout mélanger....
                0
                1. bonjour

                  toptitbal

                  concernant le prob de

                  fabrygas
                  0
                  1. Oui tout est en ordre et je te remercie fort .
                    0
                  2. @^^Marie^^ok je te donne ça , car oui il y a encore un petit problem.
                    0
                  3. @^^Marie^^Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 11:22:25, on 09/05/2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\LEXBCES.EXE
                    C:\WINDOWS\system32\LEXPPS.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                    C:\WINDOWS\eHome\ehRecvr.exe
                    C:\WINDOWS\eHome\ehSched.exe
                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\mysql\bin\mysqld-nt.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\Apps\Softex\OmniPass\Omniserv.exe
                    C:\WINDOWS\system32\slserv.exe
                    C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\Apps\Softex\OmniPass\OPXPApp.exe
                    C:\WINDOWS\Explorer.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\ehome\ehtray.exe
                    C:\WINDOWS\mHotkey.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    C:\WINDOWS\eHome\ehmsas.exe
                    C:\WINDOWS\system32\RUNDLL32.EXE
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
                    C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
                    C:\Program Files\MIC\HAWAII\Hawaii.exe
                    C:\Apps\Softex\OmniPass\scureapp.exe
                    C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                    C:\WINDOWS\system32\RunDLL32.exe
                    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\APPS\SMP\SmpSys.exe
                    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                    C:\Program Files\BitComet\BitComet.exe
                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Octoshape Streaming Services\FabricE\OctoshapeClient.exe
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.seduction.fr
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\
                    F3 - REG:win.ini: run=C:\WINDOWS\system32\scvhost.exe
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
                    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                    O2 - BHO: (no name) - {D11A646E-0C3C-4EE3-9362-DB0D9DFF3D52} - C:\WINDOWS\system32\geBssPjk.dll (file missing)
                    O2 - BHO: (no name) - {F035A9A0-19F1-4B31-9296-82CECC37DB49} - C:\WINDOWS\system32\efcYpPjK.dll (file missing)
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                    O4 - HKLM\..\Run: [NECHotkey] mHotkey.exe
                    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                    O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
                    O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
                    O4 - HKLM\..\Run: [MM_MODULE] C:\Program Files\MIC\HAWAII\Hawaii.exe
                    O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
                    O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                    O4 - HKLM\..\Run: [PD0630 STISvc] RunDLL32.exe P0630Pin.dll,RunDLL32EP 513
                    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
                    O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\FabricE\OctoshapeClient.exe" -inv:bootrun
                    O4 - HKCU\..\Run: [Windows Update] C:\WINDOWS\system32\rundll.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                    O4 - HKLM\..\Policies\Explorer\Run: [Generic Host Process] C:\WINDOWS\system32\scvhost.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                    O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
                    O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                    O16 - DPF: {E55FD215-A32E-43FE-A777-A7E8F165F554} (Flatcast Viewer 4.16) - http://80.237.209.20/objects/NpFv41629.dll
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                    O20 - Winlogon Notify: nnnlmLcy - nnnlmLcy.dll (file missing)
                    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                    O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                    O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
                    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
                    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe (file missing)
                    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                    0
                2. OK

                  Télécharge SmitfraudFix
                  Utilitaire de S!Ri: Moe et balltrap34
                  http://siri.urz.free.fr/Fix/SmitfraudFix.php
                  et télécharge SmitfraudFix.exe.

                  Regarde le tuto

                  Exécute le en choisissant l’option 1,
                  il va générer un rapport
                  Copie/colle le sur le poste stp.

                  Bon courage
                  A++

                  0
                  1. voici le rapport SmitfraudFix sans nettoyage :

                    SmitFraudFix v2.320

                    Rapport fait à 15:02:43,50, 09/05/2008
                    Executé à partir de C:\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode normal

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\LEXBCES.EXE
                    C:\WINDOWS\system32\LEXPPS.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                    C:\WINDOWS\eHome\ehRecvr.exe
                    C:\WINDOWS\eHome\ehSched.exe
                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\mysql\bin\mysqld-nt.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\Apps\Softex\OmniPass\Omniserv.exe
                    C:\WINDOWS\system32\slserv.exe
                    C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\Apps\Softex\OmniPass\OPXPApp.exe
                    C:\WINDOWS\Explorer.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\ehome\ehtray.exe
                    C:\WINDOWS\eHome\ehmsas.exe
                    C:\WINDOWS\mHotkey.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    C:\WINDOWS\system32\RUNDLL32.EXE
                    C:\WINDOWS\system32\rundll32.exe
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
                    C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
                    C:\Program Files\MIC\HAWAII\Hawaii.exe
                    C:\Apps\Softex\OmniPass\scureapp.exe
                    C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                    C:\WINDOWS\system32\RunDLL32.exe
                    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
                    C:\APPS\SMP\SmpSys.exe
                    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                    C:\Program Files\BitComet\BitComet.exe
                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                    C:\Program Files\Octoshape Streaming Services\FabricE\OctoshapeClient.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\cmd.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    Fichier hosts corrompu !

                    127.0.0.1 legal-at-spybot.info
                    127.0.0.1 www.legal-at-spybot.info

                    »»»»»»»»»»»»»»»»»»»»»»»» D:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\FabricE.SN115951590316

                    »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\FabricE.SN115951590316\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                    »»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\FABRIC~1.SN1\Favoris

                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    404Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    Description: Belkin Wireless G USB Network Adapter - Miniport d'ordonnancement de paquets
                    DNS Server Search Order: 212.27.54.252
                    DNS Server Search Order: 212.27.53.252

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{41FB9601-BAAB-467D-A119-B89EF17C971D}: DhcpNameServer=212.27.54.252 212.27.53.252
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin
                    0
                3. Bonsoir,
                  Je réponds pour ^^Marie^^,

                  http://www.commentcamarche.net/forum/affich 5917858 ordinateur infecte#30

                  Bin oui... C'est normal.... à regarder ton HiJackT...

                  Fais ceci stp : (histoire de supprimer Vundo et certains rootkits)...

                  > Télécharge ComboFix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe (par sUBs) sur ton Bureau.
                  Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
                  - Double clique combofix.exe
                  - Tape sur la touche 1 (Yes) pour démarrer le scan.
                  - Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
                  NOTE : Le rapport se trouve également ici : C:\Combofix.txt
                  Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                  A+

                  ;)
                  0
                  1. Je te remerci vraiment fort, je veux vraiment que l'ordinateur soit propre pour ne plus embêter personne.

                    Voici le rapport ComboFix obtenu :

                    ComboFix 08-05-08.1 - FabricE 2008-05-09 21:34:57.2 - NTFSx86
                    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1503 [GMT 2:00]
                    Endroit: D:\Documents and Settings\FabricE.SN115951590316\Bureau\ComboFix.exe
                    * Création d'un nouveau point de restauration
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\WINDOWS\system32\KjPpYcfe.ini2
                    C:\WINDOWS\system32\kjPssBeg.ini2
                    D:\Documents and Settings\FabricE.SN115951590316\Application Data\addon.dat

                    .
                    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    -------\Legacy_MSUPDATE
                    -------\Legacy_NPF

                    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-09 to 2008-05-09 ))))))))))))))))))))))))))))))))))))
                    .

                    2008-05-09 15:22 . 2008-05-09 15:22 <REP> d-------- C:\WINDOWS\BRABUS18 dir
                    2008-05-09 15:22 . 2008-05-09 15:22 12,288 --a------ C:\WINDOWS\impborl.dll
                    2008-05-09 15:02 . 2008-05-09 16:52 <REP> d-------- C:\SmitfraudFix
                    2008-05-09 15:02 . 2008-04-24 08:10 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
                    2008-05-09 15:02 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
                    2008-05-09 15:00 . 2008-05-09 15:00 1,390,255 --a------ C:\SmitfraudFix.exe
                    2008-05-09 02:03 . 2008-05-09 10:52 <REP> d-------- C:\Program Files\StuffPlug3
                    2008-05-09 00:17 . 2008-05-09 00:17 17,951 --a------ C:\gmail.htm
                    2008-05-08 22:56 . 2008-05-08 22:56 <REP> d-------- D:\Documents and Settings\FabricE.SN115951590316\Application Data\Uniblue
                    2008-05-08 21:15 . 2008-05-08 23:01 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Google Updater
                    2008-05-08 20:26 . 2008-05-08 20:26 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
                    2008-05-08 20:22 . 2008-05-08 20:22 <REP> d-------- C:\Program Files\Messenger Plus! Live
                    2008-05-08 19:04 . 2008-05-08 19:04 <REP> d-------- C:\Program Files\Avira
                    2008-05-08 17:55 . 2008-05-08 17:55 <REP> d-------- C:\Program Files\Yahoo!
                    2008-05-07 17:49 . 2005-11-10 12:54 402,944 -ra------ C:\WINDOWS\system32\drivers\BLKWGU.sys
                    2008-05-06 18:55 . 2008-05-06 18:55 <REP> d-------- D:\Documents and Settings\FabricE.SN115951590316\Application Data\vlc
                    2008-05-06 17:56 . 2008-05-06 17:56 <REP> d--hs---- C:\WINDOWS\ftpcache
                    2008-05-06 17:56 . 2008-05-06 17:56 <REP> d-------- C:\Program Files\Free
                    2008-04-30 15:46 . 2008-04-30 15:51 <REP> d-------- D:\Documents and Settings\FabricE.SN115951590316\Application Data\CamTrack
                    2008-04-30 15:46 . 2007-02-28 13:00 108,752 --a------ C:\WINDOWS\system32\drivers\dptrackerd.sys
                    2008-04-26 20:57 . 2008-04-26 20:57 742,101 --a------ C:\WINDOWS\system32\Image06.zip
                    2008-04-26 20:57 . 2008-05-04 22:37 741,575 --a------ C:\WINDOWS\system32\Image06.bmp .exe
                    2008-04-26 19:53 . 2008-05-08 14:35 <REP> d-------- C:\Program Files\Fake Webcam
                    2008-04-16 21:59 . 2008-04-20 18:20 <REP> d-------- C:\WINDOWS\system32\Bifrost
                    2008-04-16 20:16 . 2008-04-16 20:17 <REP> d-------- C:\Program Files\Datecracker
                    2008-04-14 21:05 . 2008-05-08 17:57 <REP> d-------- C:\Program Files\JkDefrag
                    2008-04-13 19:39 . 2008-04-13 19:39 93 --a------ C:\WINDOWS\wininit.ini
                    2008-04-13 19:21 . 2008-05-08 16:35 81,984 --a------ C:\WINDOWS\system32\bdod.bin
                    2008-04-13 19:14 . 2008-05-08 16:35 <REP> d-------- D:\Documents and Settings\All Users\Application Data\BitDefender
                    2008-04-13 19:11 . 2008-05-08 16:35 <REP> d-------- C:\Program Files\Fichiers communs\Softwin
                    2008-04-13 19:09 . 2008-05-08 16:05 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2008-04-13 19:09 . 2008-05-08 16:05 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                    2008-04-13 15:06 . 2008-04-16 20:32 108,336 --a------ C:\WINDOWS\system32\mswinsck.ocx
                    2008-04-13 11:17 . 2008-04-13 11:17 <REP> d-------- C:\Documents and Settings
                    2008-04-12 22:02 . 2008-04-12 23:13 <REP> d-------- C:\Program Files\MSN Password
                    2008-04-12 19:08 . 2008-05-08 14:34 <REP> d-------- C:\Program Files\Cain

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-05-09 00:38 --------- d-----w D:\Documents and Settings\All Users\Application Data\X10 Settings
                    2008-05-08 19:20 --------- d-----w D:\Documents and Settings\All Users\Application Data\WinZip
                    2008-05-08 19:16 --------- d-----w C:\Program Files\Google
                    2008-05-08 17:04 --------- d-----w D:\Documents and Settings\All Users\Application Data\Avira
                    2008-05-08 15:59 --------- d-----w D:\Documents and Settings\All Users\Application Data\WLInstaller
                    2008-05-08 15:59 --------- d-----w C:\Program Files\Windows Live
                    2008-05-08 12:47 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\Nokia
                    2008-05-08 12:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
                    2008-05-08 12:36 --------- d-----w C:\Program Files\FBrowsingAdvisor
                    2008-05-07 16:50 --------- d-----w D:\Documents and Settings\All Users\Application Data\nView_Profiles
                    2008-05-07 16:46 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\Skype
                    2008-05-07 16:38 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\skypePM
                    2008-05-07 15:44 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                    2008-05-06 16:35 --------- d-----w C:\Program Files\VideoLAN
                    2008-05-06 14:28 --------- d-----w C:\Program Files\SAGEM WiFi manager
                    2008-04-29 17:41 --------- d-----w C:\Program Files\Lexmark X1100 Series
                    2008-04-24 22:29 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\LimeWire
                    2008-04-13 09:05 --------- d-----w C:\Program Files\BitComet
                    2008-04-08 14:56 --------- d-----w C:\Program Files\Windows Media Connect 2
                    2008-04-08 14:56 --------- d-----w C:\Program Files\LimeWire
                    2008-04-08 14:56 --------- d-----w C:\Program Files\Cretacarte
                    2008-04-08 14:56 --------- d-----w C:\Program Files\AOL 9.0
                    2008-04-06 17:58 --------- d-----w C:\Program Files\Octoshape Streaming Services
                    2008-03-21 10:52 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\SoundSpectrum
                    2008-03-21 10:48 --------- d-----w C:\Program Files\SoundSpectrum
                    2008-01-24 16:17 32 ----a-w D:\Documents and Settings\All Users\Application Data\ezsid.dat
                    .
                    [code]<pre>
                    ----a-w 741,575 2008-05-04 20:37:42 C:\WINDOWS\system32\Image06.bmp .exe
                    </pre>/code

                    ((((((((((((((((((((((((((((( snapshot@2008-01-04_14.14.31,92 )))))))))))))))))))))))))))))))))))))))))
                    .
                    + 2006-03-24 04:49:05 49,152 ----a-w C:\WINDOWS\$hf_mig$\KB904942\SP2QFE\wdigest.dll
                    + 2005-10-12 23:15:25 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB904942\spmsg.dll
                    + 2005-10-12 23:15:26 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB904942\spuninst.exe
                    + 2005-10-12 23:15:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB904942\update\spcustom.dll
                    + 2005-10-12 23:15:28 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB904942\update\update.exe
                    + 2005-10-12 23:15:45 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB904942\update\updspapi.dll
                    + 2006-07-14 15:52:22 121,856 ----a-w C:\WINDOWS\$hf_mig$\KB915865\SP2QFE\xmllite.dll
                    + 2005-10-12 23:12:25 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB915865\spmsg.dll
                    + 2005-10-12 23:12:26 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB915865\spuninst.exe
                    + 2005-10-12 23:12:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\spcustom.dll
                    + 2005-10-12 23:12:28 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\update.exe
                    + 2005-10-12 23:12:33 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\updspapi.dll
                    + 2006-10-12 13:55:58 42,496 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentdp2.dll
                    + 2006-10-12 13:55:58 57,344 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentdpv.dll
                    + 2006-10-12 11:54:07 256,512 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentsvr.exe
                    + 2006-10-16 11:19:09 265,216 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\spru040c.dll
                    + 2005-10-12 23:18:45 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB920213\spmsg.dll
                    + 2005-10-12 23:18:45 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB920213\spuninst.exe
                    + 2005-10-12 23:18:45 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB920213\update\spcustom.dll
                    + 2005-10-12 23:18:46 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB920213\update\update.exe
                    + 2005-10-12 23:18:49 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB920213\update\updspapi.dll
                    + 2007-03-09 14:00:38 57,344 ----a-w C:\WINDOWS\$hf_mig$\KB932168\SP2QFE\agentdpv.dll
                    + 2007-03-09 11:51:20 265,216 ----a-w C:\WINDOWS\$hf_mig$\KB932168\SP2QFE\spru040c.dll
                    + 2006-01-19 19:29:25 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB932168\spmsg.dll
                    + 2006-01-19 19:29:25 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB932168\spuninst.exe
                    + 2006-01-19 19:29:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB932168\update\spcustom.dll
                    + 2006-01-19 19:29:26 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB932168\update\update.exe
                    + 2006-01-19 19:29:26 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB932168\update\updspapi.dll
                    + 2007-07-12 23:28:38 765,952 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
                    + 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
                    + 2007-10-10 23:22:14 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\advpack.dll
                    + 2007-10-10 23:22:14 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\dxtrans.dll
                    + 2007-10-10 23:22:14 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\extmgr.dll
                    + 2007-10-10 23:22:14 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\icardie.dll
                    + 2007-10-10 08:16:47 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ie4uinit.exe
                    + 2007-10-10 23:22:14 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieakeng.dll
                    + 2007-10-10 23:22:14 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieaksie.dll
                    + 2007-10-10 05:47:20 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieakui.dll
                    + 2007-07-01 03:31:33 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dat
                    + 2007-10-10 23:22:14 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dll
                    + 2007-10-10 23:22:15 388,096 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iedkcs32.dll
                    + 2007-10-10 23:22:16 6,067,200 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieframe.dll
                    + 2007-10-10 23:22:16 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iernonce.dll
                    + 2007-10-10 23:22:16 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iertutil.dll
                    + 2007-10-10 08:16:47 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieudinit.exe
                    + 2007-10-10 08:16:56 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
                    + 2007-10-10 23:22:16 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\jsproxy.dll
                    + 2007-10-10 23:22:16 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msfeeds.dll
                    + 2007-10-10 23:22:16 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msfeedsbs.dll
                    + 2007-10-30 23:40:57 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mshtml.dll
                    + 2007-10-10 23:22:18 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mshtmled.dll
                    + 2007-10-10 23:22:18 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msrating.dll
                    + 2007-10-10 23:22:18 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mstime.dll
                    + 2007-10-10 23:22:18 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\occache.dll
                    + 2007-10-10 23:22:18 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\url.dll
                    + 2007-10-10 23:22:19 1,162,240 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\urlmon.dll
                    + 2007-10-10 23:22:19 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\webcheck.dll
                    + 2007-10-10 23:22:19 825,344 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\spcustom.dll
                    + 2007-06-30 18:47:16 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\update.exe
                    + 2007-06-30 20:24:42 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\updspapi.dll
                    + 2007-12-04 18:30:15 551,936 ----a-w C:\WINDOWS\$hf_mig$\KB943055\SP2QFE\oleaut32.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\updspapi.dll
                    + 2007-11-07 09:50:06 733,696 ----a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll
                    + 2007-12-07 01:42:15 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\advpack.dll
                    + 2007-12-19 22:20:28 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtmsft.dll
                    + 2007-12-07 01:42:15 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtrans.dll
                    + 2007-12-07 01:42:15 133,120 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\extmgr.dll
                    + 2007-12-07 01:42:15 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\icardie.dll
                    + 2007-12-06 08:34:28 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ie4uinit.exe
                    + 2007-12-07 01:42:15 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakeng.dll
                    + 2007-12-07 01:42:16 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieaksie.dll
                    + 2007-12-06 05:00:02 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakui.dll
                    + 2007-07-01 03:31:33 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dat
                    + 2007-12-07 01:42:16 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dll
                    + 2007-12-07 01:42:16 388,096 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iedkcs32.dll
                    + 2007-12-07 01:42:19 6,067,200 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieframe.dll
                    + 2007-12-07 01:42:19 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iernonce.dll
                    + 2007-12-07 01:42:19 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iertutil.dll
                    + 2007-12-06 08:34:29 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieudinit.exe
                    + 2007-12-06 08:34:45 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
                    + 2007-12-07 01:42:20 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\jsproxy.dll
                    + 2007-12-07 01:42:20 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeeds.dll
                    + 2007-12-07 01:42:20 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeedsbs.dll
                    + 2007-12-07 01:42:21 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll
                    + 2007-12-07 01:42:21 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtmled.dll
                    + 2007-12-07 01:42:21 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msrating.dll
                    + 2007-12-07 01:42:21 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mstime.dll
                    + 2007-12-07 01:42:21 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\occache.dll
                    + 2008-01-11 05:54:27 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\pngfilt.dll
                    + 2007-12-07 01:42:21 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\url.dll
                    + 2007-12-07 01:42:22 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\urlmon.dll
                    + 2007-12-07 01:42:22 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\webcheck.dll
                    + 2007-12-07 01:42:22 825,344 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\updspapi.dll
                    + 2007-12-18 09:38:59 179,712 ----a-w C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\updspapi.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB946627\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB946627\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946627\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB946627\update\update.exe
                    + 2007-03-06 01:35:47 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB946627\update\updspapi.dll
                    + 2006-05-25 09:29:04 213,216 -c----w C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe
                    + 2006-05-25 09:29:04 371,424 -c----w C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\updspapi.dll
                    + 2006-05-24 11:32:48 213,216 -c----w C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe
                    + 2006-05-24 11:32:48 371,424 -c----w C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\updspapi.dll
                    + 2005-10-12 23:15:26 216,800 -c----w C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe
                    + 2005-10-12 23:15:45 394,976 -c----w C:\WINDOWS\$NtUninstallKB904942$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 49,152 -c----w C:\WINDOWS\$NtUninstallKB904942$\wdigest.dll
                    + 2004-08-10 12:00:00 28,672 -c----w C:\WINDOWS\$NtUninstallKB914440$\custsat.dll
                    + 2005-10-12 23:15:24 216,800 -c----w C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe
                    + 2005-10-12 23:15:43 394,976 -c----w C:\WINDOWS\$NtUninstallKB914440$\spuninst\updspapi.dll
                    + 2005-10-12 23:12:26 213,216 -c----w C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe
                    + 2005-10-12 23:12:33 371,424 -c----w C:\WINDOWS\$NtUninstallKB915865$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 41,984 -c----w C:\WINDOWS\$NtUninstallKB920213$\agentdp2.dll
                    + 2005-04-22 05:08:20 57,344 -c----w C:\WINDOWS\$NtUninstallKB920213$\agentdpv.dll
                    + 2004-08-10 13:00:00 256,512 -c----w C:\WINDOWS\$NtUninstallKB920213$\agentsvr.exe
                    + 2005-10-12 23:18:45 216,800 -c----w C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe
                    + 2005-10-12 23:18:49 394,976 -c----w C:\WINDOWS\$NtUninstallKB920213$\spuninst\updspapi.dll
                    + 2005-10-11 07:39:38 1,863,680 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehcm.dll
                    + 2005-10-11 07:32:46 864,256 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehepg.dll
                    + 2004-08-10 05:30:22 269,312 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehglid.dll
                    + 2004-08-10 05:30:24 178,688 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehkeyctl.dll
                    + 2005-10-11 07:40:32 237,568 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehrecvr.exe
                    + 2005-10-11 07:43:18 3,219,456 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehshell.exe
                    + 2005-08-05 14:38:54 492,032 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehui.dll
                    + 2005-08-05 14:38:52 356,352 -c----w C:\WINDOWS\$NtUninstallKB925766$\encdec.dll
                    + 2005-08-05 12:01:22 105,984 -c----w C:\WINDOWS\$NtUninstallKB925766$\mstvcapn.dll
                    + 2005-10-11 07:39:32 1,669,120 -c----w C:\WINDOWS\$NtUninstallKB925766$\msvidctl.dll
                    + 2005-08-05 14:38:54 239,104 -c----w C:\WINDOWS\$NtUninstallKB925766$\psisdecd.dll
                    + 2005-08-05 14:38:54 282,112 -c----w C:\WINDOWS\$NtUninstallKB925766$\sbe.dll
                    + 2005-10-13 12:23:02 216,800 -c----w C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe
                    + 2005-10-13 12:23:04 394,976 -c----w C:\WINDOWS\$NtUninstallKB925766$\spuninst\updspapi.dll
                    + 2005-10-12 23:12:26 213,216 -c----w C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe
                    + 2005-10-12 23:12:33 371,424 -c----w C:\WINDOWS\$NtUninstallKB926239$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 827,392 -c----w C:\WINDOWS\$NtUninstallKB926251$\setup_wm.exe
                    + 2005-06-28 08:23:40 216,800 -c----w C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe
                    + 2005-06-28 08:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB926251$\spuninst\updspapi.dll
                    + 2006-10-18 20:47:16 414,208 -c----w C:\WINDOWS\$NtUninstallKB929399$\msscp.dll
                    + 2005-06-28 09:23:26 213,216 -c----w C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe
                    + 2005-06-28 09:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB929399$\spuninst\updspapi.dll
                    + 2006-10-12 14:04:13 57,344 -c----w C:\WINDOWS\$NtUninstallKB932168$\agentdpv.dll
                    + 2006-10-12 14:04:13 57,344 -c----w C:\WINDOWS\$NtUninstallKB932168$\agentdpv.dll.000
                    + 2006-01-19 19:29:25 216,800 -c----w C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe
                    + 2006-01-19 19:29:26 394,976 -c----w C:\WINDOWS\$NtUninstallKB932168$\spuninst\updspapi.dll
                    + 2005-06-28 09:23:40 216,800 -c----w C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe
                    + 2005-06-28 09:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\updspapi.dll
                    + 2006-10-18 20:47:20 10,834,432 -c----w C:\WINDOWS\$NtUninstallKB936782_WMP11$\wmp.dll
                    + 2005-06-28 09:23:40 216,800 -c----w C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe
                    + 2005-06-28 09:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB939683$\spuninst\updspapi.dll
                    + 2006-11-03 08:58:34 317,440 -c----w C:\WINDOWS\$NtUninstallKB939683$\unregmp2.exe
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\updspapi.dll
                    + 2006-04-20 11:51:50 359,808 -c----w C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
                    + 2007-05-17 11:29:50 549,376 -c----w C:\WINDOWS\$NtUninstallKB943055$\oleaut32.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\updspapi.dll
                    + 2006-08-17 12:29:49 728,576 -c----w C:\WINDOWS\$NtUninstallKB943485$\lsasrv.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 181,248 -c----w C:\WINDOWS\$NtUninstallKB946026$\mrxdav.sys
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\updspapi.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:47 394,976 -c----w C:\WINDOWS\$NtUninstallKB946627$\spuninst\updspapi.dll
                    + 2006-09-25 16:58:48 221,488 -c----w C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe
                    + 2006-09-25 16:58:48 379,184 -c----w C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 483,328 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\audiodev.dll
                    + 2006-03-03 12:26:29 429,056 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\blackbox.dll
                    + 2005-08-03 17:29:52 207,872 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\cewmdm.dll
                    + 2005-08-03 17:29:52 178,936 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\drmupgds.exe
                    + 2006-03-03 12:26:57 581,632 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\drmv2clt.dll
                    + 2005-08-03 17:29:52 6,656 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\laprxy.dll
                    + 2005-08-03 17:29:52 96,768 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\logagent.exe
                    + 2005-08-03 17:29:52 106,496 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mfplat.dll
                    + 2004-08-10 13:00:00 310,272 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mp43dmod.dll
                    + 2004-08-10 13:00:00 384,512 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mp4sdmod.dll
                    + 2004-08-10 13:00:00 240,640 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mpg4dmod.dll
                    + 2005-08-03 17:29:52 115,200 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\msnetobj.dll
                    + 2005-08-03 17:29:52 25,088 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mspmsnsv.dll
                    + 2005-08-03 17:29:52 173,568 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mspmsp.dll
                    + 2005-08-03 17:29:52 353,520 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\msscp.dll
                    + 2005-08-03 17:29:52 315,904 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mswmdm.dll
                    + 2005-08-03 17:29:52 221,184 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\qasf.dll
                    + 2006-05-16 17:11:54 213,216 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe
                    + 2006-05-16 17:11:54 371,424 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\updspapi.dll
                    + 2006-11-02 10:46:52 13,312 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
                    + 2005-08-03 17:29:52 47,104 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\uwdf.exe
                    + 2005-08-03 17:29:52 15,872 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wdfapi.dll
                    + 2005-08-03 17:29:52 38,912 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wdfmgr.exe
                    + 2005-08-03 17:29:52 359,936 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmadmod.dll
                    + 2005-08-03 17:29:52 716,288 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmadmoe.dll
                    + 2007-10-24 16:58:46 228,864 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmasf.dll
                    + 2005-08-03 17:29:52 29,184 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdmlog.dll
                    + 2005-08-03 17:29:52 37,376 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdmps.dll
                    + 2005-08-03 17:29:52 344,064 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmdev.dll
                    + 2005-08-03 17:29:52 290,816 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmnet.dll
                    + 2005-08-03 17:29:52 180,224 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmsdk.dll
                    + 2005-08-03 17:29:52 150,016 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmidx.dll
                    + 2005-08-03 17:29:52 988,672 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmnetmgr.dll
                    + 2005-08-03 17:29:52 771,584 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmsdmod.dll
                    + 2005-08-03 17:29:52 1,119,744 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmsdmoe2.dll
                    + 2005-08-03 17:29:52 819,200 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmsetsdk.exe
                    + 2005-08-03 17:29:54 407,552 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmspdmod.dll
                    + 2005-08-03 17:29:54 940,544 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmspdmoe.dll
                    + 2005-08-03 17:29:54 1,216,000 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvadvd.dll
                    + 2005-08-03 17:29:54 1,512,448 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvadve.dll
                    + 2006-12-07 04:14:51 2,330,624 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvcore.dll
                    + 2005-08-03 17:29:54 826,368 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvdmod.dll
                    + 2005-08-03 17:29:54 1,003,008 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvdmoe2.dll
                    + 2006-03-03 12:33:09 38,912 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpd_ci.dll
                    + 2006-03-03 12:32:57 61,952 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdconns.dll
                    + 2006-03-03 12:33:00 114,176 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdmtp.dll
                    + 2006-03-03 12:33:00 66,560 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdmtpus.dll
                    + 2006-03-03 12:33:10 329,728 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdsp.dll
                    + 2006-03-03 12:33:01 18,944 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdusb.sys
                    + 2002-12-13 12:42:56 8,192 -c----w C:\WINDOWS\$NtUninstallwmp11$\asferror.dll
                    + 2004-08-10 13:00:00 356,352 -c----w C:\WINDOWS\$NtUninstallwmp11$\mpvis.dll
                    + 2006-10-31 15:38:48 827,392 -c----w C:\WINDOWS\$NtUninstallwmp11$\setup_wm.exe
                    + 2006-05-16 17:11:54 213,216 -c----w C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe
                    + 2006-05-16 17:11:56 394,976 -c----w C:\WINDOWS\$NtUninstallwmp11$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 192,512 -c----w C:\WINDOWS\$NtUninstallwmp11$\unregmp2.exe
                    + 2004-08-10 13:00:00 226,304 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmerror.dll
                    + 2004-08-10 13:00:00 118,784 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmlaunch.exe
                    + 2007-04-30 07:20:24 5,537,792 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmp.dll
                    + 2004-08-10 13:00:00 131,072 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpasf.dll
                    + 2004-08-10 13:00:00 77,824 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpband.dll
                    + 2004-08-10 13:00:00 278,528 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpdxm.dll
                    + 2004-08-10 13:00:00 28,672 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpenc.exe
                    + 2004-08-10 13:00:00 1,582,080 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpencen.dll
                    + 2006-02-16 00:31:06 73,728 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmplayer.exe
                    + 2006-02-16 00:29:56 3,424,256 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmploc.dll
                    + 2004-08-10 13:00:00 81,920 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpshell.dll
                    + 2004-08-10 13:00:00 174,080 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpsrcwp.dll
                    + 2006-09-16 00:05:22 221,488 -c----w C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe
                    + 2006-09-16 00:05:22 379,184 -c----w C:\WINDOWS\$NtUninstallWudf01000$\spuninst\updspapi.dll
                    + 2006-09-28 18:01:52 58,368 -c----w C:\WINDOWS\$NtUninstallWudf01000$\spuninst\WudfCustom.dll
                    + 2006-09-16 02:02:34 221,488 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe
                    + 2006-09-16 02:02:36 379,184 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\updspapi.dll
                    + 2006-09-15 21:30:12 70,656 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\WudfCustom.dll
                    + 2006-09-28 19:13:26 95,344 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfcoinstaller.dll
                    + 2006-09-28 17:56:38 146,432 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfhost.exe
                    + 2006-09-28 17:55:50 77,568 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfpf.sys
                    + 2006-09-28 17:56:16 165,376 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfplatform.dll
                    + 2006-09-28 18:00:34 82,944 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfrd.sys
                    + 2006-09-28 17:56:14 55,808 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfsvc.dll
                    + 2006-09-28 17:56:38 316,416 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfx.dll
                    + 2006-10-04 14:05:26 39,424 ------w C:\WINDOWS\AppPatch\acadproc.dll
                    - 2008-01-03 14:03:14 1,863,680 ----a-w C:\WINDOWS\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\ehcm.dll
                    + 2008-01-23 23:29:54 1,863,680 ----a-w C:\WINDOWS\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\ehcm.dll
                    - 2008-01-03 14:03:14 864,256 ----a-w C:\WINDOWS\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
                    + 2008-01-23 23:29:55 868,352 ----a-w C:\WINDOWS\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
                    - 2008-01-03 14:02:54 204,800 ----a-w C:\WINDOWS\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiPlay.dll
                    + 2008-01-23 23:29:55 204,800 ----a-w C:\WINDOWS\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiplay.dll
                    + 2008-04-11 08:38:21 69,120 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                    + 2008-04-11 08:38:25 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                    + 2008-04-11 08:38:11 4,444,160 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
                    + 2008-04-11 08:38:26 483,840 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
                    + 2008-04-11 08:38:16 3,036,160 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
                    + 2008-04-11 08:38:27 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
                    + 2008-04-11 08:38:27 113,664 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
                    + 2008-04-11 08:38:25 261,120 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
                    + 2008-04-11 08:38:15 5,431,296 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
                    + 2008-04-11 08:38:19 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                    + 2008-04-11 08:38:16 507,904 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
                    + 2008-04-11 08:38:21 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                    + 2008-04-11 08:38:22 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                    + 2008-04-11 08:38:23 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                    + 2008-04-11 08:38:23 6,656 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                    + 2008-04-11 08:38:28 348,160 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
                    + 2008-04-11 08:38:28 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                    + 2008-04-11 08:38:29 655,360 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
                    + 2008-04-11 08:38:29 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                    + 2008-04-11 08:38:24 749,568 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
                    + 2008-04-11 08:38:23 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
                    + 2008-04-11 08:38:22 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
                    + 2008-04-11 08:38:26 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                    + 2008-04-11 08:38:22 671,744 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
                    + 2008-04-11 08:38:13 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                    + 2008-04-11 08:38:27 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                    + 2008-04-11 08:38:21 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                    + 2008-04-11 08:38:21 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                    + 2008-04-11 08:38:24 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
                    + 2008-04-11 08:38:24 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                    + 2008-04-11 08:38:16 425,984 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
                    + 2008-04-11 08:38:17 741,376 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
                    + 2008-04-11 08:38:17 933,888 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
                    + 2008-04-11 08:38:29 5,070,848 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
                    + 2008-04-11 08:38:28 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
                    + 2008-04-11 08:38:20 401,408 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
                    + 2008-04-11 08:38:27 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                    + 2008-04-11 08:38:14 630,784 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
                    + 2008-04-11 08:38:27 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
                    + 2008-04-11 08:38:26 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
                    + 2008-04-11 08:38:26 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
                    + 2008-04-11 08:38:25 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
                    + 2008-04-11 08:38:14 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
                    + 2008-04-11 08:38:14 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
                    + 2008-04-11 08:38:19 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
                    + 2008-04-11 08:38:19 90,112 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                    + 2008-04-11 08:38:18 839,680 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
                    + 2008-04-11 08:38:20 5,013,504 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
                    + 2008-04-11 08:38:15 2,068,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
                    + 2008-04-11 08:38:18 3,076,096 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
                    + 2008-04-11 18:00:17 27,136 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\c6772fd12a581ad3be49e3f2a80b5622\Accessibility.ni.dll
                    + 2008-04-11 18:00:24 884,736 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\a1d353edc300e3aff0784202f68a657b\AspNetMMCExt.ni.dll
                    + 2008-04-11 18:00:26 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c10ec9b4de2b366236ec83237dc31281\CustomMarshalers.ni.dll
                    + 2008-04-11 18:00:25 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\837fe02bdcf637d5bf1e5ffb935ebb80\dfsvc.ni.exe
                    + 2008-04-11 18:00:30 876,544 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\9710a3c0d11dd264c3a6b88977699e9b\Microsoft.Build.Engine.ni.dll
                    + 2008-04-11 18:00:31 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e2858a45971fb30b0c0523dbb52c1d4e\Microsoft.Build.Framework.ni.dll
                    + 2008-04-11 18:00:36 1,695,744 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\63d69ffdf3c640d2d104a4b74e8115f8\Microsoft.Build.Tasks.ni.dll
                    + 2008-04-11 18:00:37 167,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\11cb5418c06e30100616fbf205588489\Microsoft.Build.Utilities.ni.dll
                    + 2008-04-11 18:00:43 1,740,800 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll
                    + 2008-04-11 10:48:03 11,722,752 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll
                    + 2008-04-11 18:00:46 1,011,712 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll
                    + 2008-04-11 10:49:22 7,049,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll
                    + 2008-04-11 18:00:49 1,798,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\c7dea4895e1fa33d65e448c03de48d26\System.Deployment.ni.dll
                    + 2008-04-11 10:49:56 10,969,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\c1e16b40e30a05c39be8aee46311841c\System.Design.ni.dll
                    + 2008-04-11 18:00:53 1,224,704 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\914668b240550f529e54bb772c6fc881\System.DirectoryServices.ni.dll
                    + 2008-04-11 18:00:55 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f11bc82c09955cb8438d3885a99c297d\System.DirectoryServices.Protocols.ni.dll
                    + 2008-04-11 10:50:00 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\b974f6c17d17a533adf6e7710c5a62fa\System.Drawing.Design.ni.dll
                    + 2008-04-11 10:49:59 1,667,072 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\[u]0/ue83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll
                    + 2008-04-11 18:00:58 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.ni.dll
                    + 2008-04-11 18:00:58 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.Wrapper.dll
                    + 2008-04-11 18:01:00 733,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\2b5994269cc5b996231c9b21afea9a91\System.Security.ni.dll
                    + 2008-04-11 18:01:02 233,472 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll
                    + 2008-04-11 18:01:05 679,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll
                    + 2008-04-11 21:39:50 2,342,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\37d87b3cab1c66ec4430ebb2abeaa570\System.Web.Mobile.ni.dll
                    + 2008-04-11 21:39:52 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5b81faf46fc63c20d5339b36edd02fa\System.Web.RegularExpressions.ni.dll
                    + 2008-04-11 21:39:56 1,986,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\38991368499e2109ea4099a0fe29c5a3\System.Web.Services.ni.dll
                    + 2008-04-11 21:39:45 12,509,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll
                    + 2008-04-11 10:50:26 13,193,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll
                    + 2008-04-11 10:50:37 5,771,264 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll
                    + 2008-04-11 10:48:52 8,265,728 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll
                    + 2008-05-09 19:38:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
                    + 2005-03-30 17:06:02 36,864 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\CtCamMgr.dll
                    + 2004-10-21 18:15:00 86,016 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\CtDrvIns.exe
                    + 2004-08-01 17:02:00 98,304 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\CtTwain.dll
                    + 2001-08-23 08:25:28 1,706,800 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\gdiplus.dll
                    + 2004-12-07 08:02:40 86,016 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\HookWnd.dll
                    + 2004-02-22 17:00:00 20,480 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Cfg.exe
                    + 2004-03-29 17:00:00 1,125,376 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Evx.sys
                    + 2005-06-05 17:01:00 49,152 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Hwx.dll
                    + 2005-06-05 17:01:00 36,864 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Pin.dll
                    + 2004-01-14 17:00:00 20,480 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Srv.exe
                    + 2005-06-05 17:01:00 32,768 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Sti.dll
                    + 2004-09-14 17:01:00 126,976 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Vfw.dll
                    + 2005-06-06 01:44:05 91,841 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Vid.sys
                    + 2006-06-15 17:33:54 1,132,192 ----a-w C:\WINDOWS\Downloaded Program Files\EPUWALcontrol.dll
                    + 2007-11-20 15:04:32 1,523,536 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
                    + 2007-02-22 21:41:12 304,544 ----a-w C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
                    + 2007-02-28 12:21:04 131,472 ----a-w C:\WINDOWS\Downloaded Program Files\msgrchkr.dll
                    + 2006-06-20 14:44:04 379,704 ----a-w C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
                    + 2008-05-08 19:33:40 1,193,952 ----a-w C:\WINDOWS\Downloaded Program Files\NpFv41629.dll
                    + 2006-06-20 14:44:02 117,560 ----a-w C:\WINDOWS\Downloaded Program Files\PURen-us.dll
                    + 2007-01-09 07:30:14 110,592 ----a-w C:\WINDOWS\Downloaded Program Files\PURfr-fr.dll
                    - 2005-08-05 14:38:54 239,104 ----a-w C:\WINDOWS\Driver Cache\i386\psisdecd.dll
                    + 2006-10-09 15:12:14 235,008 ----a-w C:\WINDOWS\Driver Cache\i386\psisdecd.dll
                    - 2005-10-11 07:39:38 1,863,680 ----a-w C:\WINDOWS\ehome\ehcm.dll
                    + 2006-10-09 15:16:00 1,863,680 ----a-w C:\WINDOWS\ehome\ehcm.dll
                    - 2005-10-11 07:32:46 864,256 ----a-w C:\WINDOWS\ehome\ehepg.dll
                    + 2006-10-09 15:07:44 868,352 ----a-w C:\WINDOWS\ehome\ehepg.dll
                    - 2005-10-11 07:40:36 332,288 ----a-w C:\WINDOWS\ehome\ehglid.dll
                    + 2006-10-09 15:17:04 328,704 ----a-w C:\WINDOWS\ehome\ehglid.dll
                    - 2004-08-10 05:30:24 178,688 ----a-w C:\WINDOWS\ehome\ehkeyctl.dll
                    + 2006-10-09 15:18:32 178,176 ----a-w C:\WINDOWS\ehome\ehkeyctl.dll
                    - 2005-10-11 07:40:32 237,568 ----a-w C:\WINDOWS\ehome\ehrecvr.exe
                    + 2006-10-09 15:16:56 237,568 ----a-w C:\WINDOWS\ehome\ehrecvr.exe
                    - 2005-10-11 07:43:18 3,219,456 ----a-w C:\WINDOWS\ehome\ehshell.exe
                    + 2006-10-09 15:19:14 3,223,552 ----a-w C:\WINDOWS\ehome\ehshell.exe
                    - 2005-08-05 14:38:54 492,032 ----a-w C:\WINDOWS\ehome\ehui.dll
                    + 2006-10-09 15:16:30 558,592 ----a-w C:\WINDOWS\ehome\ehui.dll
                    - 2005-08-05 12:01:22 105,984 ----a-w C:\WINDOWS\ehome\mstvcapn.dll
                    + 2006-10-09 15:12:52 107,008 ----a-w C:\WINDOWS\ehome\mstvcapn.dll
                    + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
                    + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
                    + 2008-01-12 14:16:47 360,580 ----a-w C:\WINDOWS\eSellerateEngine.dll
                    + 2000-08-31 06:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
                    + 2000-08-31 06:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
                    + 2004-08-10 13:00:00 2,589 ----a-w C:\WINDOWS\I386\RUNW32.BAT
                    + 2004-08-10 13:00:00 61,440 -c----w C:\WINDOWS\ie7\admparse.dll
                    + 2004-08-10 13:00:00 101,888 -c----w C:\WINDOWS\ie7\advpack.dll
                    + 2004-08-10 13:00:00 35,328 -c----w C:\WINDOWS\ie7\corpol.dll
                    + 2006-06-02 19:32:20 33,792 -c----w C:\WINDOWS\ie7\custsat.dll
                    + 2007-10-11 05:59:22 357,888 -c----w C:\WINDOWS\ie7\dxtmsft.dll
                    + 2007-10-11 05:59:22 205,824 -c----w C:\WINDOWS\ie7\dxtrans.dll
                    + 2007-10-11 05:59:22 55,808 -c----w C:\WINDOWS\ie7\extmgr.dll
                    + 2004-08-10 13:00:00 38,912 -c----w C:\WINDOWS\ie7\hmmapi.dll
                    + 2004-08-10 13:00:00 34,304 -c----w C:\WINDOWS\ie7\ie4uinit.exe
                    + 2004-08-10 13:00:00 139,264 -c----w C:\WINDOWS\ie7\ieakeng.dll
                    + 2004-08-10 13:00:00 221,696 -c----w C:\WINDOWS\ie7\ieaksie.dll
                    + 2004-08-10 13:00:00 245,760 -c----w C:\WINDOWS\ie7\ieakui.dll
                    + 2004-08-10 13:00:00 323,584 -c----w C:\WINDOWS\ie7\iedkcs32.dll
                    + 2007-10-10 10:48:23 18,432 -c----w C:\WINDOWS\ie7\iedw.exe
                    + 2004-08-10 13:00:00 81,920 -c----w C:\WINDOWS\ie7\ieencode.dll
                    + 2007-10-11 05:59:22 251,904 -c----w C:\WINDOWS\ie7\iepeers.dll
                    + 2004-08-10 13:00:00 49,152 -c----w C:\WINDOWS\ie7\iernonce.dll
                    + 2004-08-10 13:00:00 63,488 -c----w C:\WINDOWS\ie7\iesetup.dll
                    + 2004-08-10 13:00:00 93,184 -c----w C:\WINDOWS\ie7\iexplore.exe
                    + 2004-08-10 13:00:00 35,840 -c----w C:\WINDOWS\ie7\imgutil.dll
                    + 2007-10-11 05:59:22 96,768 -c----w C:\WINDOWS\ie7\inseng.dll
                    + 2007-11-14 07:28:02 450,560 -c----w C:\WINDOWS\ie7\jscript.dll
                    + 2007-10-11 05:59:22 16,384 -c----w C:\WINDOWS\ie7\jsproxy.dll
                    + 2004-08-10 13:00:00 22,528 -c----w C:\WINDOWS\ie7\licmgr10.dll
                    + 2004-08-10 13:00:00 29,184 -c----w C:\WINDOWS\ie7\mshta.exe
                    + 2007-10-30 09:57:54 3,086,848 -c----w C:\WINDOWS\ie7\mshtml.dll
                    + 2007-10-11 05:59:26 449,024 -c----w C:\WINDOWS\ie7\mshtmled.dll
                    + 2004-08-10 13:00:00 57,344 -c----w C:\WINDOWS\ie7\mshtmler.dll
                    + 2004-08-10 13:00:00 146,432 -c----w C:\WINDOWS\ie7\msls31.dll
                    + 2007-10-11 05:59:26 146,432 -c----w C:\WINDOWS\ie7\msrating.dll
                    + 2007-10-11 05:59:27 532,480 -c----w C:\WINDOWS\ie7\mstime.dll
                    + 2004-08-10 13:00:00 97,280 -c----w C:\WINDOWS\ie7\occache.dll
                    + 2007-10-11 05:59:27 39,424 -c----w C:\WINDOWS\ie7\pngfilt.dll
                    + 2007-09-26 17:34:42 33,472 -c----w C:\WINDOWS\ie7\spuninst\iecustom.dll
                    + 2007-09-26 17:32:30 66,048 -c--a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
                    + 2006-09-06 16:43:28 216,800 -c----w C:\WINDOWS\ie7\spuninst\spuninst.exe
                    + 2006-09-06 16:43:30 394,976 -c----w C:\WINDOWS\ie7\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 37,888 -c----w C:\WINDOWS\ie7\url.dll
                    + 2007-10-11 05:59:29 620,032 -c----w C:\WINDOWS\ie7\urlmon.dll
                    + 2004-08-10 13:00:00 417,792 -c----w C:\WINDOWS\ie7\vbscript.dll
                    + 2007-06-26 13:56:54 851,968 -c----w C:\WINDOWS\ie7\vgx.dll
                    + 2004-08-10 13:00:00 281,600 -c----w C:\WINDOWS\ie7\webcheck.dll
                    + 2007-10-11 05:59:29 670,208 -c----w C:\WINDOWS\ie7\wininet.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
                    + 2007-08-13 17:54:10 765,952 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
                    + 2007-08-13 17:39:00 123,904 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\advpack.dll
                    + 2007-08-13 17:39:00 123,904 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\advpack.dll.000
                    + 2007-08-13 17:35:38 214,528 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\dxtrans.dll
                    + 2007-08-13 17:54:10 131,584 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\extmgr.dll
                    + 2007-08-13 17:36:26 61,952 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\icardie.dll
                    + 2007-08-13 17:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ie4uinit.exe
                    + 2007-08-13 17:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ie4uinit.exe.000
                    + 2007-08-13 17:39:26 152,064 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakeng.dll
                    + 2007-08-13 17:39:26 152,064 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakeng.dll.000
                    + 2007-08-13 17:39:54 229,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieaksie.dll
                    + 2007-08-13 17:39:54 229,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieaksie.dll.000
                    + 2007-08-13 16:56:54 161,792 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakui.dll
                    + 2007-08-13 16:56:54 161,792 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakui.dll.000
                    + 2007-02-12 15:10:12 2,451,312 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieapfltr.dat
                    + 2007-07-11 11:27:48 383,488 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieapfltr.dll
                    + 2007-08-13 17:39:50 382,976 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iedkcs32.dll
                    + 2007-08-13 17:39:50 382,976 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iedkcs32.dll.000
                    + 2007-08-13 17:54:10 6,049,280 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieframe.dll
                    + 2007-08-13 17:39:10 43,008 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iernonce.dll
                    + 2007-08-13 17:39:10 43,008 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iernonce.dll.000
                    + 2007-08-13 17:34:04 266,752 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iertutil.dll
                    + 2007-08-13 17:39:10 13,312 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieudinit.exe
                    + 2007-08-13 17:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
                    + 2007-08-13 17:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe.000
                    + 2007-08-13 17:54:10 27,136 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\jsproxy.dll
                    + 2007-08-13 17:54:10 458,752 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msfeeds.dll
                    + 2007-08-13 17:54:10 50,688 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msfeedsbs.dll
                    + 2007-08-13 17:54:12 3,578,368 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mshtml.dll
                    + 2007-08-13 17:54:10 475,648 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mshtmled.dll
                    + 2007-08-13 17:44:26 192,000 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msrating.dll
                    + 2007-08-13 17:54:10 670,720 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mstime.dll
                    + 2007-08-13 17:44:06 101,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\occache.dll
                    + 2007-08-13 17:44:06 101,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\occache.dll.000
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe
                    + 2007-06-30 20:24:42 394,976 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\updspapi.dll
                    + 2007-08-13 17:44:30 105,984 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\url.dll
                    + 2007-08-13 17:44:30 105,984 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\url.dll.000
                    + 2007-08-13 17:54:10 1,162,240 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\urlmon.dll
                    + 2007-08-13 17:54:10 231,424 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\webcheck.dll
                    + 2007-08-13 17:54:10 231,424 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\webcheck.dll.000
                    + 2007-08-13 17:54:10 818,688 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
                    + 2007-10-10 23:49:42 124,928 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\advpack.dll
                    + 2007-08-13 17:35:46 346,624 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtmsft.dll
                    + 2007-10-10 23:49:42 214,528 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtrans.dll
                    + 2007-10-10 23:49:42 132,608 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\extmgr.dll
                    + 2007-10-10 23:49:42 63,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\icardie.dll
                    + 2007-10-10 11:00:41 70,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ie4uinit.exe
                    + 2007-10-10 23:49:42 153,088 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakeng.dll
                    + 2007-10-10 23:49:42 230,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieaksie.dll
                    + 2007-10-10 05:46:55 161,792 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakui.dll
                    + 2007-10-10 23:49:42 383,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieapfltr.dll
                    + 2007-10-10 23:49:42 384,512 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iedkcs32.dll
                    + 2007-10-10 23:49:43 6,065,664 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieframe.dll
                    + 2007-10-10 23:49:43 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iernonce.dll
                    + 2007-10-10 23:49:43 267,776 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iertutil.dll
                    + 2007-10-10 10:59:40 13,824 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieudinit.exe
                    + 2007-10-10 11:00:59 625,152 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
                    + 2007-10-10 23:49:44 27,648 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\jsproxy.dll
                    + 2007-10-10 23:49:44 459,264 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeeds.dll
                    + 2007-10-10 23:49:44 52,224 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeedsbs.dll
                    + 2007-10-31 03:53:50 3,590,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtml.dll
                    + 2007-10-10 23:49:44 478,208 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtmled.dll
                    + 2007-10-10 23:49:44 193,024 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msrating.dll
                    + 2007-10-10 23:49:45 671,232 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mstime.dll
                    + 2007-10-10 23:49:45 102,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\occache.dll
                    + 2007-08-13 17:36:12 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\pngfilt.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\updspapi.dll
                    + 2007-10-10 23:49:45 105,984 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\url.dll
                    + 2007-10-10 23:49:45 1,159,680 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\urlmon.dll
                    + 2007-10-10 23:49:45 232,960 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\webcheck.dll
                    + 2007-10-10 23:49:45 824,832 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
                    + 2007-12-07 02:08:32 124,928 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll
                    + 2007-12-19 22:53:23 347,136 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll
                    + 2007-12-07 02:08:32 214,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll
                    + 2007-12-07 02:08:32 133,120 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll
                    + 2007-12-07 02:08:32 63,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll
                    + 2007-12-06 11:02:31 70,656 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe
                    + 2007-12-07 02:08:32 153,088 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll
                    + 2007-12-07 02:08:32 230,400 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll
                    + 2007-12-06 04:59:51 161,792 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll
                    + 2007-12-07 02:08:32 383,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll
                    + 2007-12-07 02:08:32 384,512 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll
                    + 2007-12-07 02:08:33 6,066,176 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll
                    + 2007-12-07 02:08:33 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll
                    + 2007-12-07 02:08:33 267,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll
                    + 2007-12-06 11:00:58 13,824 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe
                    + 2007-12-06 11:03:16 625,664 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
                    + 2007-12-07 02:08:33 27,648 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll
                    + 2007-12-07 02:08:33 459,264 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll
                    + 2007-12-07 02:08:33 52,224 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll
                    + 2007-12-08 05:08:36 3,592,192 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll
                    + 2007-12-07 02:08:34 478,208 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll
                    + 2007-12-07 02:08:34 193,024 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll
                    + 2007-12-07 02:08:34 671,232 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll
                    + 2007-12-07 02:08:34 102,912 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll
                    + 2008-01-11 05:36:55 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll
                    + 2007-12-07 02:08:34 105,984 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll
                    + 2007-12-07 02:08:34 1,159,680 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll
                    + 2007-12-07 02:08:34 233,472 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll
                    + 2007-12-07 02:08:34 824,832 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
                    - 2004-08-10 13:00:00 192,512 ----a-w C:\WINDOWS\inf\unregmp2.exe
                    + 2007-06-29 10:59:14 318,976 ----a-w C:\WINDOWS\inf\unregmp2.exe
                    + 2008-03-12 14:43:47 2,560 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\cagicon.exe
                    - 2008-01-03 14:26:29 34,304 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\misc.exe
                    + 2008-03-12 14:43:46 34,304 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\misc.exe
                    - 2008-01-03 14:26:29 8,192 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
                    + 2008-03-12 14:43:47 8,192 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
                    - 2008-01-03 14:26:29 3,584 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
                    + 2008-03-12 14:43:47 3,584 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
                    - 2008-01-03 14:26:29 16,384 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\PEicons.exe
                    + 2008-03-12 14:43:47 16,384 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\PEicons.exe
                    - 2008-01-03 14:26:29 22,528 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\unbndico.exe
                    + 2008-03-12 14:43:47 22,528 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\unbndico.exe
                    - 2008-01-03 14:26:29 45
                    0
                  2. Je te remerci vraiment fort, je veux vraiment que l'ordinateur soit propre pour ne plus embêter personne.

                    Voici le rapport ComboFix obtenu :

                    ComboFix 08-05-08.1 - FabricE 2008-05-09 21:34:57.2 - NTFSx86
                    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1503 [GMT 2:00]
                    Endroit: D:\Documents and Settings\FabricE.SN115951590316\Bureau\ComboFix.exe
                    * Création d'un nouveau point de restauration
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\WINDOWS\system32\KjPpYcfe.ini2
                    C:\WINDOWS\system32\kjPssBeg.ini2
                    D:\Documents and Settings\FabricE.SN115951590316\Application Data\addon.dat

                    .
                    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    -------\Legacy_MSUPDATE
                    -------\Legacy_NPF

                    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-09 to 2008-05-09 ))))))))))))))))))))))))))))))))))))
                    .

                    2008-05-09 15:22 . 2008-05-09 15:22 <REP> d-------- C:\WINDOWS\BRABUS18 dir
                    2008-05-09 15:22 . 2008-05-09 15:22 12,288 --a------ C:\WINDOWS\impborl.dll
                    2008-05-09 15:02 . 2008-05-09 16:52 <REP> d-------- C:\SmitfraudFix
                    2008-05-09 15:02 . 2008-04-24 08:10 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
                    2008-05-09 15:02 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
                    2008-05-09 15:00 . 2008-05-09 15:00 1,390,255 --a------ C:\SmitfraudFix.exe
                    2008-05-09 02:03 . 2008-05-09 10:52 <REP> d-------- C:\Program Files\StuffPlug3
                    2008-05-09 00:17 . 2008-05-09 00:17 17,951 --a------ C:\gmail.htm
                    2008-05-08 22:56 . 2008-05-08 22:56 <REP> d-------- D:\Documents and Settings\FabricE.SN115951590316\Application Data\Uniblue
                    2008-05-08 21:15 . 2008-05-08 23:01 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Google Updater
                    2008-05-08 20:26 . 2008-05-08 20:26 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Messenger Plus!
                    2008-05-08 20:22 . 2008-05-08 20:22 <REP> d-------- C:\Program Files\Messenger Plus! Live
                    2008-05-08 19:04 . 2008-05-08 19:04 <REP> d-------- C:\Program Files\Avira
                    2008-05-08 17:55 . 2008-05-08 17:55 <REP> d-------- C:\Program Files\Yahoo!
                    2008-05-07 17:49 . 2005-11-10 12:54 402,944 -ra------ C:\WINDOWS\system32\drivers\BLKWGU.sys
                    2008-05-06 18:55 . 2008-05-06 18:55 <REP> d-------- D:\Documents and Settings\FabricE.SN115951590316\Application Data\vlc
                    2008-05-06 17:56 . 2008-05-06 17:56 <REP> d--hs---- C:\WINDOWS\ftpcache
                    2008-05-06 17:56 . 2008-05-06 17:56 <REP> d-------- C:\Program Files\Free
                    2008-04-30 15:46 . 2008-04-30 15:51 <REP> d-------- D:\Documents and Settings\FabricE.SN115951590316\Application Data\CamTrack
                    2008-04-30 15:46 . 2007-02-28 13:00 108,752 --a------ C:\WINDOWS\system32\drivers\dptrackerd.sys
                    2008-04-26 20:57 . 2008-04-26 20:57 742,101 --a------ C:\WINDOWS\system32\Image06.zip
                    2008-04-26 20:57 . 2008-05-04 22:37 741,575 --a------ C:\WINDOWS\system32\Image06.bmp .exe
                    2008-04-26 19:53 . 2008-05-08 14:35 <REP> d-------- C:\Program Files\Fake Webcam
                    2008-04-16 21:59 . 2008-04-20 18:20 <REP> d-------- C:\WINDOWS\system32\Bifrost
                    2008-04-16 20:16 . 2008-04-16 20:17 <REP> d-------- C:\Program Files\Datecracker
                    2008-04-14 21:05 . 2008-05-08 17:57 <REP> d-------- C:\Program Files\JkDefrag
                    2008-04-13 19:39 . 2008-04-13 19:39 93 --a------ C:\WINDOWS\wininit.ini
                    2008-04-13 19:21 . 2008-05-08 16:35 81,984 --a------ C:\WINDOWS\system32\bdod.bin
                    2008-04-13 19:14 . 2008-05-08 16:35 <REP> d-------- D:\Documents and Settings\All Users\Application Data\BitDefender
                    2008-04-13 19:11 . 2008-05-08 16:35 <REP> d-------- C:\Program Files\Fichiers communs\Softwin
                    2008-04-13 19:09 . 2008-05-08 16:05 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2008-04-13 19:09 . 2008-05-08 16:05 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                    2008-04-13 15:06 . 2008-04-16 20:32 108,336 --a------ C:\WINDOWS\system32\mswinsck.ocx
                    2008-04-13 11:17 . 2008-04-13 11:17 <REP> d-------- C:\Documents and Settings
                    2008-04-12 22:02 . 2008-04-12 23:13 <REP> d-------- C:\Program Files\MSN Password
                    2008-04-12 19:08 . 2008-05-08 14:34 <REP> d-------- C:\Program Files\Cain

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-05-09 00:38 --------- d-----w D:\Documents and Settings\All Users\Application Data\X10 Settings
                    2008-05-08 19:20 --------- d-----w D:\Documents and Settings\All Users\Application Data\WinZip
                    2008-05-08 19:16 --------- d-----w C:\Program Files\Google
                    2008-05-08 17:04 --------- d-----w D:\Documents and Settings\All Users\Application Data\Avira
                    2008-05-08 15:59 --------- d-----w D:\Documents and Settings\All Users\Application Data\WLInstaller
                    2008-05-08 15:59 --------- d-----w C:\Program Files\Windows Live
                    2008-05-08 12:47 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\Nokia
                    2008-05-08 12:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
                    2008-05-08 12:36 --------- d-----w C:\Program Files\FBrowsingAdvisor
                    2008-05-07 16:50 --------- d-----w D:\Documents and Settings\All Users\Application Data\nView_Profiles
                    2008-05-07 16:46 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\Skype
                    2008-05-07 16:38 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\skypePM
                    2008-05-07 15:44 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                    2008-05-06 16:35 --------- d-----w C:\Program Files\VideoLAN
                    2008-05-06 14:28 --------- d-----w C:\Program Files\SAGEM WiFi manager
                    2008-04-29 17:41 --------- d-----w C:\Program Files\Lexmark X1100 Series
                    2008-04-24 22:29 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\LimeWire
                    2008-04-13 09:05 --------- d-----w C:\Program Files\BitComet
                    2008-04-08 14:56 --------- d-----w C:\Program Files\Windows Media Connect 2
                    2008-04-08 14:56 --------- d-----w C:\Program Files\LimeWire
                    2008-04-08 14:56 --------- d-----w C:\Program Files\Cretacarte
                    2008-04-08 14:56 --------- d-----w C:\Program Files\AOL 9.0
                    2008-04-06 17:58 --------- d-----w C:\Program Files\Octoshape Streaming Services
                    2008-03-21 10:52 --------- d-----w D:\Documents and Settings\FabricE.SN115951590316\Application Data\SoundSpectrum
                    2008-03-21 10:48 --------- d-----w C:\Program Files\SoundSpectrum
                    2008-01-24 16:17 32 ----a-w D:\Documents and Settings\All Users\Application Data\ezsid.dat
                    .
                    [code]<pre>
                    ----a-w 741,575 2008-05-04 20:37:42 C:\WINDOWS\system32\Image06.bmp .exe
                    </pre>/code

                    ((((((((((((((((((((((((((((( snapshot@2008-01-04_14.14.31,92 )))))))))))))))))))))))))))))))))))))))))
                    .
                    + 2006-03-24 04:49:05 49,152 ----a-w C:\WINDOWS\$hf_mig$\KB904942\SP2QFE\wdigest.dll
                    + 2005-10-12 23:15:25 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB904942\spmsg.dll
                    + 2005-10-12 23:15:26 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB904942\spuninst.exe
                    + 2005-10-12 23:15:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB904942\update\spcustom.dll
                    + 2005-10-12 23:15:28 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB904942\update\update.exe
                    + 2005-10-12 23:15:45 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB904942\update\updspapi.dll
                    + 2006-07-14 15:52:22 121,856 ----a-w C:\WINDOWS\$hf_mig$\KB915865\SP2QFE\xmllite.dll
                    + 2005-10-12 23:12:25 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB915865\spmsg.dll
                    + 2005-10-12 23:12:26 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB915865\spuninst.exe
                    + 2005-10-12 23:12:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\spcustom.dll
                    + 2005-10-12 23:12:28 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\update.exe
                    + 2005-10-12 23:12:33 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\updspapi.dll
                    + 2006-10-12 13:55:58 42,496 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentdp2.dll
                    + 2006-10-12 13:55:58 57,344 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentdpv.dll
                    + 2006-10-12 11:54:07 256,512 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentsvr.exe
                    + 2006-10-16 11:19:09 265,216 ----a-w C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\spru040c.dll
                    + 2005-10-12 23:18:45 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB920213\spmsg.dll
                    + 2005-10-12 23:18:45 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB920213\spuninst.exe
                    + 2005-10-12 23:18:45 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB920213\update\spcustom.dll
                    + 2005-10-12 23:18:46 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB920213\update\update.exe
                    + 2005-10-12 23:18:49 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB920213\update\updspapi.dll
                    + 2007-03-09 14:00:38 57,344 ----a-w C:\WINDOWS\$hf_mig$\KB932168\SP2QFE\agentdpv.dll
                    + 2007-03-09 11:51:20 265,216 ----a-w C:\WINDOWS\$hf_mig$\KB932168\SP2QFE\spru040c.dll
                    + 2006-01-19 19:29:25 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB932168\spmsg.dll
                    + 2006-01-19 19:29:25 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB932168\spuninst.exe
                    + 2006-01-19 19:29:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB932168\update\spcustom.dll
                    + 2006-01-19 19:29:26 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB932168\update\update.exe
                    + 2006-01-19 19:29:26 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB932168\update\updspapi.dll
                    + 2007-07-12 23:28:38 765,952 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
                    + 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
                    + 2007-10-10 23:22:14 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\advpack.dll
                    + 2007-10-10 23:22:14 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\dxtrans.dll
                    + 2007-10-10 23:22:14 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\extmgr.dll
                    + 2007-10-10 23:22:14 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\icardie.dll
                    + 2007-10-10 08:16:47 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ie4uinit.exe
                    + 2007-10-10 23:22:14 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieakeng.dll
                    + 2007-10-10 23:22:14 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieaksie.dll
                    + 2007-10-10 05:47:20 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieakui.dll
                    + 2007-07-01 03:31:33 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dat
                    + 2007-10-10 23:22:14 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dll
                    + 2007-10-10 23:22:15 388,096 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iedkcs32.dll
                    + 2007-10-10 23:22:16 6,067,200 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieframe.dll
                    + 2007-10-10 23:22:16 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iernonce.dll
                    + 2007-10-10 23:22:16 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iertutil.dll
                    + 2007-10-10 08:16:47 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieudinit.exe
                    + 2007-10-10 08:16:56 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
                    + 2007-10-10 23:22:16 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\jsproxy.dll
                    + 2007-10-10 23:22:16 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msfeeds.dll
                    + 2007-10-10 23:22:16 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msfeedsbs.dll
                    + 2007-10-30 23:40:57 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mshtml.dll
                    + 2007-10-10 23:22:18 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mshtmled.dll
                    + 2007-10-10 23:22:18 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msrating.dll
                    + 2007-10-10 23:22:18 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mstime.dll
                    + 2007-10-10 23:22:18 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\occache.dll
                    + 2007-10-10 23:22:18 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\url.dll
                    + 2007-10-10 23:22:19 1,162,240 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\urlmon.dll
                    + 2007-10-10 23:22:19 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\webcheck.dll
                    + 2007-10-10 23:22:19 825,344 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\spcustom.dll
                    + 2007-06-30 18:47:16 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\update.exe
                    + 2007-06-30 20:24:42 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\updspapi.dll
                    + 2007-12-04 18:30:15 551,936 ----a-w C:\WINDOWS\$hf_mig$\KB943055\SP2QFE\oleaut32.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\updspapi.dll
                    + 2007-11-07 09:50:06 733,696 ----a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll
                    + 2007-12-07 01:42:15 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\advpack.dll
                    + 2007-12-19 22:20:28 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtmsft.dll
                    + 2007-12-07 01:42:15 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtrans.dll
                    + 2007-12-07 01:42:15 133,120 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\extmgr.dll
                    + 2007-12-07 01:42:15 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\icardie.dll
                    + 2007-12-06 08:34:28 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ie4uinit.exe
                    + 2007-12-07 01:42:15 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakeng.dll
                    + 2007-12-07 01:42:16 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieaksie.dll
                    + 2007-12-06 05:00:02 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakui.dll
                    + 2007-07-01 03:31:33 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dat
                    + 2007-12-07 01:42:16 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dll
                    + 2007-12-07 01:42:16 388,096 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iedkcs32.dll
                    + 2007-12-07 01:42:19 6,067,200 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieframe.dll
                    + 2007-12-07 01:42:19 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iernonce.dll
                    + 2007-12-07 01:42:19 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iertutil.dll
                    + 2007-12-06 08:34:29 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieudinit.exe
                    + 2007-12-06 08:34:45 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
                    + 2007-12-07 01:42:20 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\jsproxy.dll
                    + 2007-12-07 01:42:20 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeeds.dll
                    + 2007-12-07 01:42:20 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeedsbs.dll
                    + 2007-12-07 01:42:21 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll
                    + 2007-12-07 01:42:21 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtmled.dll
                    + 2007-12-07 01:42:21 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msrating.dll
                    + 2007-12-07 01:42:21 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mstime.dll
                    + 2007-12-07 01:42:21 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\occache.dll
                    + 2008-01-11 05:54:27 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\pngfilt.dll
                    + 2007-12-07 01:42:21 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\url.dll
                    + 2007-12-07 01:42:22 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\urlmon.dll
                    + 2007-12-07 01:42:22 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\webcheck.dll
                    + 2007-12-07 01:42:22 825,344 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\updspapi.dll
                    + 2007-12-18 09:38:59 179,712 ----a-w C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\update.exe
                    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\updspapi.dll
                    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB946627\spmsg.dll
                    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB946627\spuninst.exe
                    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946627\update\spcustom.dll
                    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB946627\update\update.exe
                    + 2007-03-06 01:35:47 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB946627\update\updspapi.dll
                    + 2006-05-25 09:29:04 213,216 -c----w C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe
                    + 2006-05-25 09:29:04 371,424 -c----w C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\updspapi.dll
                    + 2006-05-24 11:32:48 213,216 -c----w C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe
                    + 2006-05-24 11:32:48 371,424 -c----w C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\updspapi.dll
                    + 2005-10-12 23:15:26 216,800 -c----w C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe
                    + 2005-10-12 23:15:45 394,976 -c----w C:\WINDOWS\$NtUninstallKB904942$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 49,152 -c----w C:\WINDOWS\$NtUninstallKB904942$\wdigest.dll
                    + 2004-08-10 12:00:00 28,672 -c----w C:\WINDOWS\$NtUninstallKB914440$\custsat.dll
                    + 2005-10-12 23:15:24 216,800 -c----w C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe
                    + 2005-10-12 23:15:43 394,976 -c----w C:\WINDOWS\$NtUninstallKB914440$\spuninst\updspapi.dll
                    + 2005-10-12 23:12:26 213,216 -c----w C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe
                    + 2005-10-12 23:12:33 371,424 -c----w C:\WINDOWS\$NtUninstallKB915865$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 41,984 -c----w C:\WINDOWS\$NtUninstallKB920213$\agentdp2.dll
                    + 2005-04-22 05:08:20 57,344 -c----w C:\WINDOWS\$NtUninstallKB920213$\agentdpv.dll
                    + 2004-08-10 13:00:00 256,512 -c----w C:\WINDOWS\$NtUninstallKB920213$\agentsvr.exe
                    + 2005-10-12 23:18:45 216,800 -c----w C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe
                    + 2005-10-12 23:18:49 394,976 -c----w C:\WINDOWS\$NtUninstallKB920213$\spuninst\updspapi.dll
                    + 2005-10-11 07:39:38 1,863,680 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehcm.dll
                    + 2005-10-11 07:32:46 864,256 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehepg.dll
                    + 2004-08-10 05:30:22 269,312 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehglid.dll
                    + 2004-08-10 05:30:24 178,688 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehkeyctl.dll
                    + 2005-10-11 07:40:32 237,568 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehrecvr.exe
                    + 2005-10-11 07:43:18 3,219,456 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehshell.exe
                    + 2005-08-05 14:38:54 492,032 -c----w C:\WINDOWS\$NtUninstallKB925766$\ehui.dll
                    + 2005-08-05 14:38:52 356,352 -c----w C:\WINDOWS\$NtUninstallKB925766$\encdec.dll
                    + 2005-08-05 12:01:22 105,984 -c----w C:\WINDOWS\$NtUninstallKB925766$\mstvcapn.dll
                    + 2005-10-11 07:39:32 1,669,120 -c----w C:\WINDOWS\$NtUninstallKB925766$\msvidctl.dll
                    + 2005-08-05 14:38:54 239,104 -c----w C:\WINDOWS\$NtUninstallKB925766$\psisdecd.dll
                    + 2005-08-05 14:38:54 282,112 -c----w C:\WINDOWS\$NtUninstallKB925766$\sbe.dll
                    + 2005-10-13 12:23:02 216,800 -c----w C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe
                    + 2005-10-13 12:23:04 394,976 -c----w C:\WINDOWS\$NtUninstallKB925766$\spuninst\updspapi.dll
                    + 2005-10-12 23:12:26 213,216 -c----w C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe
                    + 2005-10-12 23:12:33 371,424 -c----w C:\WINDOWS\$NtUninstallKB926239$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 827,392 -c----w C:\WINDOWS\$NtUninstallKB926251$\setup_wm.exe
                    + 2005-06-28 08:23:40 216,800 -c----w C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe
                    + 2005-06-28 08:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB926251$\spuninst\updspapi.dll
                    + 2006-10-18 20:47:16 414,208 -c----w C:\WINDOWS\$NtUninstallKB929399$\msscp.dll
                    + 2005-06-28 09:23:26 213,216 -c----w C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe
                    + 2005-06-28 09:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB929399$\spuninst\updspapi.dll
                    + 2006-10-12 14:04:13 57,344 -c----w C:\WINDOWS\$NtUninstallKB932168$\agentdpv.dll
                    + 2006-10-12 14:04:13 57,344 -c----w C:\WINDOWS\$NtUninstallKB932168$\agentdpv.dll.000
                    + 2006-01-19 19:29:25 216,800 -c----w C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe
                    + 2006-01-19 19:29:26 394,976 -c----w C:\WINDOWS\$NtUninstallKB932168$\spuninst\updspapi.dll
                    + 2005-06-28 09:23:40 216,800 -c----w C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe
                    + 2005-06-28 09:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\updspapi.dll
                    + 2006-10-18 20:47:20 10,834,432 -c----w C:\WINDOWS\$NtUninstallKB936782_WMP11$\wmp.dll
                    + 2005-06-28 09:23:40 216,800 -c----w C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe
                    + 2005-06-28 09:23:54 371,424 -c----w C:\WINDOWS\$NtUninstallKB939683$\spuninst\updspapi.dll
                    + 2006-11-03 08:58:34 317,440 -c----w C:\WINDOWS\$NtUninstallKB939683$\unregmp2.exe
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\updspapi.dll
                    + 2006-04-20 11:51:50 359,808 -c----w C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
                    + 2007-05-17 11:29:50 549,376 -c----w C:\WINDOWS\$NtUninstallKB943055$\oleaut32.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\updspapi.dll
                    + 2006-08-17 12:29:49 728,576 -c----w C:\WINDOWS\$NtUninstallKB943485$\lsasrv.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 181,248 -c----w C:\WINDOWS\$NtUninstallKB946026$\mrxdav.sys
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\updspapi.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.exe
                    + 2007-03-06 01:35:47 394,976 -c----w C:\WINDOWS\$NtUninstallKB946627$\spuninst\updspapi.dll
                    + 2006-09-25 16:58:48 221,488 -c----w C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe
                    + 2006-09-25 16:58:48 379,184 -c----w C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 483,328 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\audiodev.dll
                    + 2006-03-03 12:26:29 429,056 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\blackbox.dll
                    + 2005-08-03 17:29:52 207,872 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\cewmdm.dll
                    + 2005-08-03 17:29:52 178,936 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\drmupgds.exe
                    + 2006-03-03 12:26:57 581,632 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\drmv2clt.dll
                    + 2005-08-03 17:29:52 6,656 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\laprxy.dll
                    + 2005-08-03 17:29:52 96,768 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\logagent.exe
                    + 2005-08-03 17:29:52 106,496 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mfplat.dll
                    + 2004-08-10 13:00:00 310,272 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mp43dmod.dll
                    + 2004-08-10 13:00:00 384,512 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mp4sdmod.dll
                    + 2004-08-10 13:00:00 240,640 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mpg4dmod.dll
                    + 2005-08-03 17:29:52 115,200 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\msnetobj.dll
                    + 2005-08-03 17:29:52 25,088 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mspmsnsv.dll
                    + 2005-08-03 17:29:52 173,568 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mspmsp.dll
                    + 2005-08-03 17:29:52 353,520 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\msscp.dll
                    + 2005-08-03 17:29:52 315,904 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\mswmdm.dll
                    + 2005-08-03 17:29:52 221,184 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\qasf.dll
                    + 2006-05-16 17:11:54 213,216 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe
                    + 2006-05-16 17:11:54 371,424 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\updspapi.dll
                    + 2006-11-02 10:46:52 13,312 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
                    + 2005-08-03 17:29:52 47,104 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\uwdf.exe
                    + 2005-08-03 17:29:52 15,872 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wdfapi.dll
                    + 2005-08-03 17:29:52 38,912 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wdfmgr.exe
                    + 2005-08-03 17:29:52 359,936 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmadmod.dll
                    + 2005-08-03 17:29:52 716,288 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmadmoe.dll
                    + 2007-10-24 16:58:46 228,864 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmasf.dll
                    + 2005-08-03 17:29:52 29,184 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdmlog.dll
                    + 2005-08-03 17:29:52 37,376 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdmps.dll
                    + 2005-08-03 17:29:52 344,064 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmdev.dll
                    + 2005-08-03 17:29:52 290,816 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmnet.dll
                    + 2005-08-03 17:29:52 180,224 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmsdk.dll
                    + 2005-08-03 17:29:52 150,016 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmidx.dll
                    + 2005-08-03 17:29:52 988,672 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmnetmgr.dll
                    + 2005-08-03 17:29:52 771,584 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmsdmod.dll
                    + 2005-08-03 17:29:52 1,119,744 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmsdmoe2.dll
                    + 2005-08-03 17:29:52 819,200 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmsetsdk.exe
                    + 2005-08-03 17:29:54 407,552 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmspdmod.dll
                    + 2005-08-03 17:29:54 940,544 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmspdmoe.dll
                    + 2005-08-03 17:29:54 1,216,000 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvadvd.dll
                    + 2005-08-03 17:29:54 1,512,448 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvadve.dll
                    + 2006-12-07 04:14:51 2,330,624 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvcore.dll
                    + 2005-08-03 17:29:54 826,368 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvdmod.dll
                    + 2005-08-03 17:29:54 1,003,008 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wmvdmoe2.dll
                    + 2006-03-03 12:33:09 38,912 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpd_ci.dll
                    + 2006-03-03 12:32:57 61,952 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdconns.dll
                    + 2006-03-03 12:33:00 114,176 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdmtp.dll
                    + 2006-03-03 12:33:00 66,560 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdmtpus.dll
                    + 2006-03-03 12:33:10 329,728 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdsp.dll
                    + 2006-03-03 12:33:01 18,944 -c----w C:\WINDOWS\$NtUninstallWMFDist11$\wpdusb.sys
                    + 2002-12-13 12:42:56 8,192 -c----w C:\WINDOWS\$NtUninstallwmp11$\asferror.dll
                    + 2004-08-10 13:00:00 356,352 -c----w C:\WINDOWS\$NtUninstallwmp11$\mpvis.dll
                    + 2006-10-31 15:38:48 827,392 -c----w C:\WINDOWS\$NtUninstallwmp11$\setup_wm.exe
                    + 2006-05-16 17:11:54 213,216 -c----w C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe
                    + 2006-05-16 17:11:56 394,976 -c----w C:\WINDOWS\$NtUninstallwmp11$\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 192,512 -c----w C:\WINDOWS\$NtUninstallwmp11$\unregmp2.exe
                    + 2004-08-10 13:00:00 226,304 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmerror.dll
                    + 2004-08-10 13:00:00 118,784 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmlaunch.exe
                    + 2007-04-30 07:20:24 5,537,792 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmp.dll
                    + 2004-08-10 13:00:00 131,072 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpasf.dll
                    + 2004-08-10 13:00:00 77,824 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpband.dll
                    + 2004-08-10 13:00:00 278,528 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpdxm.dll
                    + 2004-08-10 13:00:00 28,672 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpenc.exe
                    + 2004-08-10 13:00:00 1,582,080 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpencen.dll
                    + 2006-02-16 00:31:06 73,728 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmplayer.exe
                    + 2006-02-16 00:29:56 3,424,256 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmploc.dll
                    + 2004-08-10 13:00:00 81,920 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpshell.dll
                    + 2004-08-10 13:00:00 174,080 -c----w C:\WINDOWS\$NtUninstallwmp11$\wmpsrcwp.dll
                    + 2006-09-16 00:05:22 221,488 -c----w C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe
                    + 2006-09-16 00:05:22 379,184 -c----w C:\WINDOWS\$NtUninstallWudf01000$\spuninst\updspapi.dll
                    + 2006-09-28 18:01:52 58,368 -c----w C:\WINDOWS\$NtUninstallWudf01000$\spuninst\WudfCustom.dll
                    + 2006-09-16 02:02:34 221,488 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe
                    + 2006-09-16 02:02:36 379,184 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\updspapi.dll
                    + 2006-09-15 21:30:12 70,656 -c----w C:\WINDOWS\$NtUninstallWudf01005$\spuninst\WudfCustom.dll
                    + 2006-09-28 19:13:26 95,344 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfcoinstaller.dll
                    + 2006-09-28 17:56:38 146,432 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfhost.exe
                    + 2006-09-28 17:55:50 77,568 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfpf.sys
                    + 2006-09-28 17:56:16 165,376 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfplatform.dll
                    + 2006-09-28 18:00:34 82,944 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfrd.sys
                    + 2006-09-28 17:56:14 55,808 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfsvc.dll
                    + 2006-09-28 17:56:38 316,416 -c----w C:\WINDOWS\$NtUninstallWudf01005$\wudfx.dll
                    + 2006-10-04 14:05:26 39,424 ------w C:\WINDOWS\AppPatch\acadproc.dll
                    - 2008-01-03 14:03:14 1,863,680 ----a-w C:\WINDOWS\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\ehcm.dll
                    + 2008-01-23 23:29:54 1,863,680 ----a-w C:\WINDOWS\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\ehcm.dll
                    - 2008-01-03 14:03:14 864,256 ----a-w C:\WINDOWS\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
                    + 2008-01-23 23:29:55 868,352 ----a-w C:\WINDOWS\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
                    - 2008-01-03 14:02:54 204,800 ----a-w C:\WINDOWS\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiPlay.dll
                    + 2008-01-23 23:29:55 204,800 ----a-w C:\WINDOWS\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiplay.dll
                    + 2008-04-11 08:38:21 69,120 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                    + 2008-04-11 08:38:25 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                    + 2008-04-11 08:38:11 4,444,160 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
                    + 2008-04-11 08:38:26 483,840 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
                    + 2008-04-11 08:38:16 3,036,160 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
                    + 2008-04-11 08:38:27 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
                    + 2008-04-11 08:38:27 113,664 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
                    + 2008-04-11 08:38:25 261,120 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
                    + 2008-04-11 08:38:15 5,431,296 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
                    + 2008-04-11 08:38:19 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                    + 2008-04-11 08:38:16 507,904 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
                    + 2008-04-11 08:38:21 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                    + 2008-04-11 08:38:22 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                    + 2008-04-11 08:38:23 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                    + 2008-04-11 08:38:23 6,656 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                    + 2008-04-11 08:38:28 348,160 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
                    + 2008-04-11 08:38:28 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                    + 2008-04-11 08:38:29 655,360 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
                    + 2008-04-11 08:38:29 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                    + 2008-04-11 08:38:24 749,568 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
                    + 2008-04-11 08:38:23 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
                    + 2008-04-11 08:38:22 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
                    + 2008-04-11 08:38:26 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                    + 2008-04-11 08:38:22 671,744 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
                    + 2008-04-11 08:38:13 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                    + 2008-04-11 08:38:27 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                    + 2008-04-11 08:38:21 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                    + 2008-04-11 08:38:21 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                    + 2008-04-11 08:38:24 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
                    + 2008-04-11 08:38:24 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                    + 2008-04-11 08:38:16 425,984 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
                    + 2008-04-11 08:38:17 741,376 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
                    + 2008-04-11 08:38:17 933,888 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
                    + 2008-04-11 08:38:29 5,070,848 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
                    + 2008-04-11 08:38:28 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
                    + 2008-04-11 08:38:20 401,408 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
                    + 2008-04-11 08:38:27 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                    + 2008-04-11 08:38:14 630,784 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
                    + 2008-04-11 08:38:27 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
                    + 2008-04-11 08:38:26 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
                    + 2008-04-11 08:38:26 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
                    + 2008-04-11 08:38:25 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
                    + 2008-04-11 08:38:14 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
                    + 2008-04-11 08:38:14 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
                    + 2008-04-11 08:38:19 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
                    + 2008-04-11 08:38:19 90,112 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                    + 2008-04-11 08:38:18 839,680 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
                    + 2008-04-11 08:38:20 5,013,504 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
                    + 2008-04-11 08:38:15 2,068,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
                    + 2008-04-11 08:38:18 3,076,096 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
                    + 2008-04-11 18:00:17 27,136 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\c6772fd12a581ad3be49e3f2a80b5622\Accessibility.ni.dll
                    + 2008-04-11 18:00:24 884,736 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\a1d353edc300e3aff0784202f68a657b\AspNetMMCExt.ni.dll
                    + 2008-04-11 18:00:26 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c10ec9b4de2b366236ec83237dc31281\CustomMarshalers.ni.dll
                    + 2008-04-11 18:00:25 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\837fe02bdcf637d5bf1e5ffb935ebb80\dfsvc.ni.exe
                    + 2008-04-11 18:00:30 876,544 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\9710a3c0d11dd264c3a6b88977699e9b\Microsoft.Build.Engine.ni.dll
                    + 2008-04-11 18:00:31 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e2858a45971fb30b0c0523dbb52c1d4e\Microsoft.Build.Framework.ni.dll
                    + 2008-04-11 18:00:36 1,695,744 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\63d69ffdf3c640d2d104a4b74e8115f8\Microsoft.Build.Tasks.ni.dll
                    + 2008-04-11 18:00:37 167,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\11cb5418c06e30100616fbf205588489\Microsoft.Build.Utilities.ni.dll
                    + 2008-04-11 18:00:43 1,740,800 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll
                    + 2008-04-11 10:48:03 11,722,752 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll
                    + 2008-04-11 18:00:46 1,011,712 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll
                    + 2008-04-11 10:49:22 7,049,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll
                    + 2008-04-11 18:00:49 1,798,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\c7dea4895e1fa33d65e448c03de48d26\System.Deployment.ni.dll
                    + 2008-04-11 10:49:56 10,969,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\c1e16b40e30a05c39be8aee46311841c\System.Design.ni.dll
                    + 2008-04-11 18:00:53 1,224,704 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\914668b240550f529e54bb772c6fc881\System.DirectoryServices.ni.dll
                    + 2008-04-11 18:00:55 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f11bc82c09955cb8438d3885a99c297d\System.DirectoryServices.Protocols.ni.dll
                    + 2008-04-11 10:50:00 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\b974f6c17d17a533adf6e7710c5a62fa\System.Drawing.Design.ni.dll
                    + 2008-04-11 10:49:59 1,667,072 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\[u]0/ue83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll
                    + 2008-04-11 18:00:58 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.ni.dll
                    + 2008-04-11 18:00:58 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.Wrapper.dll
                    + 2008-04-11 18:01:00 733,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\2b5994269cc5b996231c9b21afea9a91\System.Security.ni.dll
                    + 2008-04-11 18:01:02 233,472 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll
                    + 2008-04-11 18:01:05 679,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll
                    + 2008-04-11 21:39:50 2,342,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\37d87b3cab1c66ec4430ebb2abeaa570\System.Web.Mobile.ni.dll
                    + 2008-04-11 21:39:52 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5b81faf46fc63c20d5339b36edd02fa\System.Web.RegularExpressions.ni.dll
                    + 2008-04-11 21:39:56 1,986,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\38991368499e2109ea4099a0fe29c5a3\System.Web.Services.ni.dll
                    + 2008-04-11 21:39:45 12,509,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll
                    + 2008-04-11 10:50:26 13,193,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll
                    + 2008-04-11 10:50:37 5,771,264 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll
                    + 2008-04-11 10:48:52 8,265,728 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll
                    + 2008-05-09 19:38:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
                    + 2005-03-30 17:06:02 36,864 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\CtCamMgr.dll
                    + 2004-10-21 18:15:00 86,016 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\CtDrvIns.exe
                    + 2004-08-01 17:02:00 98,304 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\CtTwain.dll
                    + 2001-08-23 08:25:28 1,706,800 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\gdiplus.dll
                    + 2004-12-07 08:02:40 86,016 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\HookWnd.dll
                    + 2004-02-22 17:00:00 20,480 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Cfg.exe
                    + 2004-03-29 17:00:00 1,125,376 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Evx.sys
                    + 2005-06-05 17:01:00 49,152 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Hwx.dll
                    + 2005-06-05 17:01:00 36,864 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Pin.dll
                    + 2004-01-14 17:00:00 20,480 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Srv.exe
                    + 2005-06-05 17:01:00 32,768 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Sti.dll
                    + 2004-09-14 17:01:00 126,976 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Vfw.dll
                    + 2005-06-06 01:44:05 91,841 ----a-r C:\WINDOWS\CtDrvInstall\{70303633-30646576-0000000000000000}\P0630Vid.sys
                    + 2006-06-15 17:33:54 1,132,192 ----a-w C:\WINDOWS\Downloaded Program Files\EPUWALcontrol.dll
                    + 2007-11-20 15:04:32 1,523,536 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
                    + 2007-02-22 21:41:12 304,544 ----a-w C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
                    + 2007-02-28 12:21:04 131,472 ----a-w C:\WINDOWS\Downloaded Program Files\msgrchkr.dll
                    + 2006-06-20 14:44:04 379,704 ----a-w C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
                    + 2008-05-08 19:33:40 1,193,952 ----a-w C:\WINDOWS\Downloaded Program Files\NpFv41629.dll
                    + 2006-06-20 14:44:02 117,560 ----a-w C:\WINDOWS\Downloaded Program Files\PURen-us.dll
                    + 2007-01-09 07:30:14 110,592 ----a-w C:\WINDOWS\Downloaded Program Files\PURfr-fr.dll
                    - 2005-08-05 14:38:54 239,104 ----a-w C:\WINDOWS\Driver Cache\i386\psisdecd.dll
                    + 2006-10-09 15:12:14 235,008 ----a-w C:\WINDOWS\Driver Cache\i386\psisdecd.dll
                    - 2005-10-11 07:39:38 1,863,680 ----a-w C:\WINDOWS\ehome\ehcm.dll
                    + 2006-10-09 15:16:00 1,863,680 ----a-w C:\WINDOWS\ehome\ehcm.dll
                    - 2005-10-11 07:32:46 864,256 ----a-w C:\WINDOWS\ehome\ehepg.dll
                    + 2006-10-09 15:07:44 868,352 ----a-w C:\WINDOWS\ehome\ehepg.dll
                    - 2005-10-11 07:40:36 332,288 ----a-w C:\WINDOWS\ehome\ehglid.dll
                    + 2006-10-09 15:17:04 328,704 ----a-w C:\WINDOWS\ehome\ehglid.dll
                    - 2004-08-10 05:30:24 178,688 ----a-w C:\WINDOWS\ehome\ehkeyctl.dll
                    + 2006-10-09 15:18:32 178,176 ----a-w C:\WINDOWS\ehome\ehkeyctl.dll
                    - 2005-10-11 07:40:32 237,568 ----a-w C:\WINDOWS\ehome\ehrecvr.exe
                    + 2006-10-09 15:16:56 237,568 ----a-w C:\WINDOWS\ehome\ehrecvr.exe
                    - 2005-10-11 07:43:18 3,219,456 ----a-w C:\WINDOWS\ehome\ehshell.exe
                    + 2006-10-09 15:19:14 3,223,552 ----a-w C:\WINDOWS\ehome\ehshell.exe
                    - 2005-08-05 14:38:54 492,032 ----a-w C:\WINDOWS\ehome\ehui.dll
                    + 2006-10-09 15:16:30 558,592 ----a-w C:\WINDOWS\ehome\ehui.dll
                    - 2005-08-05 12:01:22 105,984 ----a-w C:\WINDOWS\ehome\mstvcapn.dll
                    + 2006-10-09 15:12:52 107,008 ----a-w C:\WINDOWS\ehome\mstvcapn.dll
                    + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
                    + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
                    + 2008-01-12 14:16:47 360,580 ----a-w C:\WINDOWS\eSellerateEngine.dll
                    + 2000-08-31 06:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
                    + 2000-08-31 06:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
                    + 2004-08-10 13:00:00 2,589 ----a-w C:\WINDOWS\I386\RUNW32.BAT
                    + 2004-08-10 13:00:00 61,440 -c----w C:\WINDOWS\ie7\admparse.dll
                    + 2004-08-10 13:00:00 101,888 -c----w C:\WINDOWS\ie7\advpack.dll
                    + 2004-08-10 13:00:00 35,328 -c----w C:\WINDOWS\ie7\corpol.dll
                    + 2006-06-02 19:32:20 33,792 -c----w C:\WINDOWS\ie7\custsat.dll
                    + 2007-10-11 05:59:22 357,888 -c----w C:\WINDOWS\ie7\dxtmsft.dll
                    + 2007-10-11 05:59:22 205,824 -c----w C:\WINDOWS\ie7\dxtrans.dll
                    + 2007-10-11 05:59:22 55,808 -c----w C:\WINDOWS\ie7\extmgr.dll
                    + 2004-08-10 13:00:00 38,912 -c----w C:\WINDOWS\ie7\hmmapi.dll
                    + 2004-08-10 13:00:00 34,304 -c----w C:\WINDOWS\ie7\ie4uinit.exe
                    + 2004-08-10 13:00:00 139,264 -c----w C:\WINDOWS\ie7\ieakeng.dll
                    + 2004-08-10 13:00:00 221,696 -c----w C:\WINDOWS\ie7\ieaksie.dll
                    + 2004-08-10 13:00:00 245,760 -c----w C:\WINDOWS\ie7\ieakui.dll
                    + 2004-08-10 13:00:00 323,584 -c----w C:\WINDOWS\ie7\iedkcs32.dll
                    + 2007-10-10 10:48:23 18,432 -c----w C:\WINDOWS\ie7\iedw.exe
                    + 2004-08-10 13:00:00 81,920 -c----w C:\WINDOWS\ie7\ieencode.dll
                    + 2007-10-11 05:59:22 251,904 -c----w C:\WINDOWS\ie7\iepeers.dll
                    + 2004-08-10 13:00:00 49,152 -c----w C:\WINDOWS\ie7\iernonce.dll
                    + 2004-08-10 13:00:00 63,488 -c----w C:\WINDOWS\ie7\iesetup.dll
                    + 2004-08-10 13:00:00 93,184 -c----w C:\WINDOWS\ie7\iexplore.exe
                    + 2004-08-10 13:00:00 35,840 -c----w C:\WINDOWS\ie7\imgutil.dll
                    + 2007-10-11 05:59:22 96,768 -c----w C:\WINDOWS\ie7\inseng.dll
                    + 2007-11-14 07:28:02 450,560 -c----w C:\WINDOWS\ie7\jscript.dll
                    + 2007-10-11 05:59:22 16,384 -c----w C:\WINDOWS\ie7\jsproxy.dll
                    + 2004-08-10 13:00:00 22,528 -c----w C:\WINDOWS\ie7\licmgr10.dll
                    + 2004-08-10 13:00:00 29,184 -c----w C:\WINDOWS\ie7\mshta.exe
                    + 2007-10-30 09:57:54 3,086,848 -c----w C:\WINDOWS\ie7\mshtml.dll
                    + 2007-10-11 05:59:26 449,024 -c----w C:\WINDOWS\ie7\mshtmled.dll
                    + 2004-08-10 13:00:00 57,344 -c----w C:\WINDOWS\ie7\mshtmler.dll
                    + 2004-08-10 13:00:00 146,432 -c----w C:\WINDOWS\ie7\msls31.dll
                    + 2007-10-11 05:59:26 146,432 -c----w C:\WINDOWS\ie7\msrating.dll
                    + 2007-10-11 05:59:27 532,480 -c----w C:\WINDOWS\ie7\mstime.dll
                    + 2004-08-10 13:00:00 97,280 -c----w C:\WINDOWS\ie7\occache.dll
                    + 2007-10-11 05:59:27 39,424 -c----w C:\WINDOWS\ie7\pngfilt.dll
                    + 2007-09-26 17:34:42 33,472 -c----w C:\WINDOWS\ie7\spuninst\iecustom.dll
                    + 2007-09-26 17:32:30 66,048 -c--a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
                    + 2006-09-06 16:43:28 216,800 -c----w C:\WINDOWS\ie7\spuninst\spuninst.exe
                    + 2006-09-06 16:43:30 394,976 -c----w C:\WINDOWS\ie7\spuninst\updspapi.dll
                    + 2004-08-10 13:00:00 37,888 -c----w C:\WINDOWS\ie7\url.dll
                    + 2007-10-11 05:59:29 620,032 -c----w C:\WINDOWS\ie7\urlmon.dll
                    + 2004-08-10 13:00:00 417,792 -c----w C:\WINDOWS\ie7\vbscript.dll
                    + 2007-06-26 13:56:54 851,968 -c----w C:\WINDOWS\ie7\vgx.dll
                    + 2004-08-10 13:00:00 281,600 -c----w C:\WINDOWS\ie7\webcheck.dll
                    + 2007-10-11 05:59:29 670,208 -c----w C:\WINDOWS\ie7\wininet.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
                    + 2007-08-13 17:54:10 765,952 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
                    + 2007-08-13 17:39:00 123,904 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\advpack.dll
                    + 2007-08-13 17:39:00 123,904 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\advpack.dll.000
                    + 2007-08-13 17:35:38 214,528 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\dxtrans.dll
                    + 2007-08-13 17:54:10 131,584 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\extmgr.dll
                    + 2007-08-13 17:36:26 61,952 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\icardie.dll
                    + 2007-08-13 17:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ie4uinit.exe
                    + 2007-08-13 17:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ie4uinit.exe.000
                    + 2007-08-13 17:39:26 152,064 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakeng.dll
                    + 2007-08-13 17:39:26 152,064 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakeng.dll.000
                    + 2007-08-13 17:39:54 229,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieaksie.dll
                    + 2007-08-13 17:39:54 229,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieaksie.dll.000
                    + 2007-08-13 16:56:54 161,792 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakui.dll
                    + 2007-08-13 16:56:54 161,792 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakui.dll.000
                    + 2007-02-12 15:10:12 2,451,312 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieapfltr.dat
                    + 2007-07-11 11:27:48 383,488 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieapfltr.dll
                    + 2007-08-13 17:39:50 382,976 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iedkcs32.dll
                    + 2007-08-13 17:39:50 382,976 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iedkcs32.dll.000
                    + 2007-08-13 17:54:10 6,049,280 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieframe.dll
                    + 2007-08-13 17:39:10 43,008 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iernonce.dll
                    + 2007-08-13 17:39:10 43,008 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iernonce.dll.000
                    + 2007-08-13 17:34:04 266,752 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iertutil.dll
                    + 2007-08-13 17:39:10 13,312 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieudinit.exe
                    + 2007-08-13 17:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
                    + 2007-08-13 17:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe.000
                    + 2007-08-13 17:54:10 27,136 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\jsproxy.dll
                    + 2007-08-13 17:54:10 458,752 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msfeeds.dll
                    + 2007-08-13 17:54:10 50,688 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msfeedsbs.dll
                    + 2007-08-13 17:54:12 3,578,368 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mshtml.dll
                    + 2007-08-13 17:54:10 475,648 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mshtmled.dll
                    + 2007-08-13 17:44:26 192,000 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msrating.dll
                    + 2007-08-13 17:54:10 670,720 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mstime.dll
                    + 2007-08-13 17:44:06 101,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\occache.dll
                    + 2007-08-13 17:44:06 101,376 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\occache.dll.000
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe
                    + 2007-06-30 20:24:42 394,976 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\updspapi.dll
                    + 2007-08-13 17:44:30 105,984 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\url.dll
                    + 2007-08-13 17:44:30 105,984 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\url.dll.000
                    + 2007-08-13 17:54:10 1,162,240 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\urlmon.dll
                    + 2007-08-13 17:54:10 231,424 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\webcheck.dll
                    + 2007-08-13 17:54:10 231,424 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\webcheck.dll.000
                    + 2007-08-13 17:54:10 818,688 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
                    + 2007-10-10 23:49:42 124,928 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\advpack.dll
                    + 2007-08-13 17:35:46 346,624 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtmsft.dll
                    + 2007-10-10 23:49:42 214,528 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtrans.dll
                    + 2007-10-10 23:49:42 132,608 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\extmgr.dll
                    + 2007-10-10 23:49:42 63,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\icardie.dll
                    + 2007-10-10 11:00:41 70,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ie4uinit.exe
                    + 2007-10-10 23:49:42 153,088 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakeng.dll
                    + 2007-10-10 23:49:42 230,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieaksie.dll
                    + 2007-10-10 05:46:55 161,792 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakui.dll
                    + 2007-10-10 23:49:42 383,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieapfltr.dll
                    + 2007-10-10 23:49:42 384,512 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iedkcs32.dll
                    + 2007-10-10 23:49:43 6,065,664 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieframe.dll
                    + 2007-10-10 23:49:43 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iernonce.dll
                    + 2007-10-10 23:49:43 267,776 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iertutil.dll
                    + 2007-10-10 10:59:40 13,824 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieudinit.exe
                    + 2007-10-10 11:00:59 625,152 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
                    + 2007-10-10 23:49:44 27,648 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\jsproxy.dll
                    + 2007-10-10 23:49:44 459,264 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeeds.dll
                    + 2007-10-10 23:49:44 52,224 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeedsbs.dll
                    + 2007-10-31 03:53:50 3,590,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtml.dll
                    + 2007-10-10 23:49:44 478,208 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtmled.dll
                    + 2007-10-10 23:49:44 193,024 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msrating.dll
                    + 2007-10-10 23:49:45 671,232 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mstime.dll
                    + 2007-10-10 23:49:45 102,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\occache.dll
                    + 2007-08-13 17:36:12 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\pngfilt.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\updspapi.dll
                    + 2007-10-10 23:49:45 105,984 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\url.dll
                    + 2007-10-10 23:49:45 1,159,680 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\urlmon.dll
                    + 2007-10-10 23:49:45 232,960 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\webcheck.dll
                    + 2007-10-10 23:49:45 824,832 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
                    + 2007-12-07 02:08:32 124,928 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll
                    + 2007-12-19 22:53:23 347,136 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll
                    + 2007-12-07 02:08:32 214,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll
                    + 2007-12-07 02:08:32 133,120 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll
                    + 2007-12-07 02:08:32 63,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll
                    + 2007-12-06 11:02:31 70,656 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe
                    + 2007-12-07 02:08:32 153,088 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll
                    + 2007-12-07 02:08:32 230,400 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll
                    + 2007-12-06 04:59:51 161,792 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll
                    + 2007-12-07 02:08:32 383,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll
                    + 2007-12-07 02:08:32 384,512 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll
                    + 2007-12-07 02:08:33 6,066,176 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll
                    + 2007-12-07 02:08:33 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll
                    + 2007-12-07 02:08:33 267,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll
                    + 2007-12-06 11:00:58 13,824 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe
                    + 2007-12-06 11:03:16 625,664 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
                    + 2007-12-07 02:08:33 27,648 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll
                    + 2007-12-07 02:08:33 459,264 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll
                    + 2007-12-07 02:08:33 52,224 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll
                    + 2007-12-08 05:08:36 3,592,192 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll
                    + 2007-12-07 02:08:34 478,208 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll
                    + 2007-12-07 02:08:34 193,024 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll
                    + 2007-12-07 02:08:34 671,232 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll
                    + 2007-12-07 02:08:34 102,912 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll
                    + 2008-01-11 05:36:55 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll
                    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe
                    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll
                    + 2007-12-07 02:08:34 105,984 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll
                    + 2007-12-07 02:08:34 1,159,680 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll
                    + 2007-12-07 02:08:34 233,472 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll
                    + 2007-12-07 02:08:34 824,832 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
                    - 2004-08-10 13:00:00 192,512 ----a-w C:\WINDOWS\inf\unregmp2.exe
                    + 2007-06-29 10:59:14 318,976 ----a-w C:\WINDOWS\inf\unregmp2.exe
                    + 2008-03-12 14:43:47 2,560 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\cagicon.exe
                    - 2008-01-03 14:26:29 34,304 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\misc.exe
                    + 2008-03-12 14:43:46 34,304 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\misc.exe
                    - 2008-01-03 14:26:29 8,192 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
                    + 2008-03-12 14:43:47 8,192 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
                    - 2008-01-03 14:26:29 3,584 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
                    + 2008-03-12 14:43:47 3,584 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
                    - 2008-01-03 14:26:29 16,384 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\PEicons.exe
                    + 2008-03-12 14:43:47 16,384 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\PEicons.exe
                    - 2008-01-03 14:26:29 22,528 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\unbndico.exe
                    + 2008-03-12 14:43:47 22,528 ----a-r C:\WINDOWS\Installer\{911B040C-6000-11D3-8CFE-0050048383C9}\unbndico.exe
                    - 2008-01-03 14:26:29 45
                    0
                4. BÔ boulot DIID, merci -- t'1 3h du mat '' tu ronfles quand ??

                  ;;))

                  fabrygas, suis les conseils de DIID -- bon courage

                  A++

                  0
                  1. Merci beaucoup Marie ...
                    0
                5. Windows Registry Editor Version 5.00

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\bdcore.dll"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Softwin\\BitDefender10\\vsserv.exe"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\docfile.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\ceva_vfs.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\ve.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\uudecode.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\unpack.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\unpack.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\thebat.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\sfx.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\sdx.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\sdx.ivd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\rar.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\pst.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\pdf.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\nelf.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\mso.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\mime.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\html.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\mdx_w95.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\mdx_97.ivd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\mdx.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.ivd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\mbox.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\rpm.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\tar.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\iso.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\cevakrnl.rvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\instyler.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\hqx.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\gzip.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\hlp.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\dbx.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\cpio.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\cevakrnl.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\cevakrnl.ivd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\cab.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\bzip2.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\boot.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\arj.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\unpack.ivd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\regarch.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\proc.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.ivd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\ceva_dll.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\epoc.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Softwin\\BitDefender10\\bdsubmit.exe"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Softwin\\BitDefender10\\bdsubmit.dll"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\jpeg.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\nsis.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Softwin\\BitDefender10\\bdch.dll"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\ceva_emu.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\cran.ivd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\adsntfs.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i09"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i08"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i07"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i06"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i05"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i04"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i03"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i02"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\e_spyw.i01"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i08"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i07"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i06"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i03"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i02"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\7zip.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i01"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i19"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i17"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i16"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i15"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i14"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i13"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\mobmalware.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i12"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\gvmscripts.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\aspy_emu.cvd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\zip.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\z.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\xcookies.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\wise.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\viza.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\lha.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\alz.xmd"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
                  "C:\\Program Files\\Fichiers communs\\Softwin\\BitDefender Scan Server\\Plugins\\emalware.i11"=dword:00000001

                  [HKEY_CLASSES_ROOT\.3gp]
                  @="3GPFiles"

                  [HKEY_CLASSES_ROOT\.ADE]

                  [HKEY_CLASSES_ROOT\.ADP]

                  [HKEY_CLASSES_ROOT\.BAS]

                  [HKEY_CLASSES_ROOT\.DBX]

                  [HKEY_CLASSES_ROOT\.dgr]
                  @="Viewer"

                  [HKEY_CLASSES_ROOT\.evc]
                  @="Nokia.Multimedia"

                  [HKEY_CLASSES_ROOT\.MDA]

                  [HKEY_CLASSES_ROOT\.MDE]

                  [HKEY_CLASSES_ROOT\.MDZ]

                  [HKEY_CLASSES_ROOT\.mms]
                  @=""

                  [HKEY_CLASSES_ROOT\.mp4]
                  @="Mpeg4Files"

                  [HKEY_CLASSES_ROOT\.MST]

                  [HKEY_CLASSES_ROOT\.NCH]

                  [HKEY_CLASSES_ROOT\.nim]
                  @=""

                  [HKEY_CLASSES_ROOT\.npl]
                  @=""

                  [HKEY_CLASSES_ROOT\.obm]
                  @=""

                  [HKEY_CLASSES_ROOT\.otb]
                  @=""

                  [HKEY_CLASSES_ROOT\.t31]
                  @="Viewer"

                  [HKEY_CLASSES_ROOT\.VB]

                  [HKEY_CLASSES_ROOT\.wbm]
                  @=""

                  [HKEY_CLASSES_ROOT\.wbmp]
                  @=""

                  [HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fla]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fla\OpenWithList]
                  "a"="iexplore.exe"
                  "MRUList"="a"

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FR]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FR\OpenWithList]
                  "a"="audacity.exe"
                  "MRUList"="a"

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.frm]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.frm\OpenWithList]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mms]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nbu]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nbu\OpenWithList]
                  "a"="ContentCopier.exe"
                  "MRUList"="a"

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nbu\OpenWithProgids]
                  "Nokia.ContentCopier"=hex(0):

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nim]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.npl]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.obm]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otb]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.php\OpenWithList]
                  "a"="notepad.exe"
                  "MRUList"="a"

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList]
                  "a"="WinRAR.exe"
                  "MRUList"="badc"
                  "b"="iexplore.exe"
                  "c"="Skype.exe"
                  "d"="msnmsgr.exe"

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithProgids]
                  "WinRAR"=hex(0):

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.Stevven]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.Stevven\OpenWithList]
                  "a"="audacity.exe"
                  "MRUList"="a"

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\OpenWithList]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\OpenWithProgids]
                  "vcard_wab_auto_file"=hex(0):

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp]

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList]

                  [HKEY_CLASSES_ROOT\.p2m\shell\open]

                  [HKEY_CLASSES_ROOT\.p2m\shell\open\command]
                  @="C:\\Program Files\\Peer2Mail\\P2M.exe \"%1\""

                  [HKEY_CLASSES_ROOT\CamTrack.Animation\DefaultIcon]
                  @="C:\\Program Files\\DigitalPeers\\CamTrack\\camtrack.ico"

                  [HKEY_CLASSES_ROOT\CamTrack.Animation\shell\open]

                  [HKEY_CLASSES_ROOT\CamTrack.Animation\shell\open\command]
                  @="\"C:\\Program Files\\DigitalPeers\\CamTrack\\Camtrack.Manager.exe\" \"%1\""

                  [HKEY_CLASSES_ROOT\CGFileType.Document\DefaultIcon]
                  @="C:\\Program Files\\Peer2Mail\\P2M.exe,0"

                  [HKEY_CLASSES_ROOT\CGFileType.Document\shell\open]

                  [HKEY_CLASSES_ROOT\CGFileType.Document\shell\open\command]
                  @="C:\\Program Files\\Peer2Mail\\P2M.exe \"%1\""

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Add]
                  @="&Ajouter à la sélection Nokia Multimedia Player"

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Add\command]
                  @="\"C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MultimediaPlayer.exe\" /A\"%1\""

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Edit]
                  @="&Modifier avec Nokia Multimedia Factory"

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Edit\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MultimediaFactory.exe /e \"%1\" \"%2\""

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Forward]
                  @="&Transférer ce message multimédia"

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Forward\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MultimediaFactory.exe /f \"%1\" \"%2\""

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Open]
                  @="&Ouvrir avec Nokia Multimedia Player"

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Open\command]
                  @="\"C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MultimediaPlayer.exe\" \"%1\""

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Reply]
                  @="&Répondre à ce message multimédia"

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Reply\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MultimediaFactory.exe /r \"%1\" \"%2\""

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\ReplyAll]
                  @="Répondre à tous"

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\ReplyAll\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MultimediaFactory.exe /a \"%1\" \"%2\""

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Send]
                  @="&Envoyer ce message multimédia"

                  [HKEY_CLASSES_ROOT\contact_auto_file\shell\Send\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MultimediaFactory.exe /s \"%1\" \"%2\""

                  [HKEY_CLASSES_ROOT\Nokia.aac\DefaultIcon]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MusicManager.exe"

                  [HKEY_CLASSES_ROOT\Nokia.aac\shell\Open]

                  [HKEY_CLASSES_ROOT\Nokia.aac\shell\Open\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MusicManager.exe /play \"%1\""

                  [HKEY_CLASSES_ROOT\Nokia.aac\shell\Open\DropTarget]
                  "Clsid"=""

                  [HKEY_CLASSES_ROOT\Nokia.m4a\DefaultIcon]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MusicManager.exe"

                  [HKEY_CLASSES_ROOT\Nokia.m4a\shell\Open]

                  [HKEY_CLASSES_ROOT\Nokia.m4a\shell\Open\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MusicManager.exe /play \"%1\""

                  [HKEY_CLASSES_ROOT\Nokia.m4a\shell\Open\DropTarget]
                  "Clsid"=""

                  [HKEY_CLASSES_ROOT\ZAMailSafe\DefaultIcon]
                  @="C:\\Program Files\\Zone Labs\\ZoneAlarm\\UpdClient.exe,-279"

                  [HKEY_CLASSES_ROOT\ZAMailSafe\shell\open]

                  [HKEY_CLASSES_ROOT\ZAMailSafe\shell\open\command]
                  @="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\" -warning \"%1\""

                  [HKEY_CLASSES_ROOT\CLSID\{06075F5D-EF05-16D5-5687-249A7C80EB26}]
                  @="BrowserWatcher Class"
                  "AppID"="{C0AE27A2-FB16-65D9-7535-9DEDD84B7FF4}"

                  [HKEY_CLASSES_ROOT\CLSID\{06075F5D-EF05-16D5-5687-249A7C80EB26}\InprocServer32]
                  @="C:\\Program Files\\BrowsingAdvisor\\BrowsingAdvisor-2.dll"
                  "ThreadingModel"="Both"

                  [HKEY_CLASSES_ROOT\CLSID\{06075F5D-EF05-16D5-5687-249A7C80EB26}\ProgID]
                  @="BrowsingAdvisor.BrowserWatcher.1"

                  [HKEY_CLASSES_ROOT\CLSID\{06075F5D-EF05-16D5-5687-249A7C80EB26}\Programmable]

                  [HKEY_CLASSES_ROOT\CLSID\{06075F5D-EF05-16D5-5687-249A7C80EB26}\TypeLib]
                  @="{3239A0EA-4203-7BF5-CD1D-FDB0169B2778}"

                  [HKEY_CLASSES_ROOT\CLSID\{06075F5D-EF05-16D5-5687-249A7C80EB26}\VersionIndependentProgID]
                  @="BrowsingAdvisor.BrowserWatcher"

                  [HKEY_CLASSES_ROOT\CLSID\{37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}]
                  @="Windows Live OneCare safety scanner Malware Submission Module"

                  [HKEY_CLASSES_ROOT\CLSID\{37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}\LocalServer32]
                  @="\"C:\\Program Files\\Windows Live Safety Center\\wlscUploader.exe\""
                  "ThreadingModel"="apartment"

                  [HKEY_CLASSES_ROOT\CLSID\{37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}\ProgID]
                  @="wlscUploader.FileUploader.1"

                  [HKEY_CLASSES_ROOT\CLSID\{37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}\Programmable]

                  [HKEY_CLASSES_ROOT\CLSID\{37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}\TypeLib]
                  @="{AB0072AE-463B-4B48-921F-B42887EF97C9}"

                  [HKEY_CLASSES_ROOT\CLSID\{37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}\VersionIndependentProgID]
                  @="wlscUploader.FileUploader"

                  [HKEY_CLASSES_ROOT\CLSID\{55265A35-B335-44FE-BFB4-854E3461004D}]
                  @="Windows Live OneCare safety scanner Core Module"

                  [HKEY_CLASSES_ROOT\CLSID\{55265A35-B335-44FE-BFB4-854E3461004D}\InprocServer32]
                  @="C:\\Program Files\\Windows Live Safety Center\\wlscCore.dll"
                  "ThreadingModel"="both"

                  [HKEY_CLASSES_ROOT\CLSID\{55265A35-B335-44FE-BFB4-854E3461004D}\ProgID]
                  @="Microsoft.wlsc.Core.1"

                  [HKEY_CLASSES_ROOT\CLSID\{55265A35-B335-44FE-BFB4-854E3461004D}\Programmable]

                  [HKEY_CLASSES_ROOT\CLSID\{55265A35-B335-44FE-BFB4-854E3461004D}\TypeLib]
                  @="{C26A8181-4E47-4EA6-B62A-A0AFF1639E30}"

                  [HKEY_CLASSES_ROOT\CLSID\{55265A35-B335-44FE-BFB4-854E3461004D}\VersionIndependentProgID]
                  @="Microsoft.wlsc.Core"

                  [HKEY_CLASSES_ROOT\CLSID\{5B225ECB-2ED9-991D-713C-461009A60F29}]
                  @="PrecacheBrowserHost Class"
                  "AppID"="{C0AE27A2-FB16-65D9-7535-9DEDD84B7FF4}"

                  [HKEY_CLASSES_ROOT\CLSID\{5B225ECB-2ED9-991D-713C-461009A60F29}\InprocServer32]
                  @="C:\\Program Files\\BrowsingAdvisor\\BrowsingAdvisor-2.dll"
                  "ThreadingModel"="Both"

                  [HKEY_CLASSES_ROOT\CLSID\{5B225ECB-2ED9-991D-713C-461009A60F29}\ProgID]
                  @="BrowsingAdvisor.PrecacheBrowserHost.1"

                  [HKEY_CLASSES_ROOT\CLSID\{5B225ECB-2ED9-991D-713C-461009A60F29}\Programmable]

                  [HKEY_CLASSES_ROOT\CLSID\{5B225ECB-2ED9-991D-713C-461009A60F29}\TypeLib]
                  @="{3239A0EA-4203-7BF5-CD1D-FDB0169B2778}"

                  [HKEY_CLASSES_ROOT\CLSID\{5B225ECB-2ED9-991D-713C-461009A60F29}\VersionIndependentProgID]
                  @="BrowsingAdvisor.PrecacheBrowserHost"

                  [HKEY_CLASSES_ROOT\CLSID\{74870B39-2651-4A6C-A59B-2F66602FDC67}]
                  @="CWebTransport Object"

                  [HKEY_CLASSES_ROOT\CLSID\{74870B39-2651-4A6C-A59B-2F66602FDC67}\LocalServer32]
                  @="\"C:\\Program Files\\Windows Live Safety Center\\wlscUploader.exe\""
                  "ThreadingModel"="apartment"

                  [HKEY_CLASSES_ROOT\CLSID\{74870B39-2651-4A6C-A59B-2F66602FDC67}\ProgID]
                  @="CWebTransport.CWebTransport.1.0"

                  [HKEY_CLASSES_ROOT\CLSID\{74870B39-2651-4A6C-A59B-2F66602FDC67}\Programmable]

                  [HKEY_CLASSES_ROOT\CLSID\{74870B39-2651-4A6C-A59B-2F66602FDC67}\TypeLib]
                  @="{AB0072AE-463B-4B48-921F-B42887EF97C9}"

                  [HKEY_CLASSES_ROOT\CLSID\{74870B39-2651-4A6C-A59B-2F66602FDC67}\VersionIndependentProgID]
                  @="CWebTransport.CWebTransport"

                  [HKEY_CLASSES_ROOT\CLSID\{CE6AED26-A6CB-4267-6CA4-21F2C1C24324}]
                  @="Adehej.Otineh.Cehone class"

                  [HKEY_CLASSES_ROOT\CLSID\{CE6AED26-A6CB-4267-6CA4-21F2C1C24324}\InprocServer32]
                  @="\"C:\\Program Files\\Windows Live\\Photo Gallery\\WLXMediaPublishSubscribe.dll\""

                  [HKEY_CLASSES_ROOT\CLSID\{CE6AED26-A6CB-4267-6CA4-21F2C1C24324}\ProgID]
                  @="Microsoft.Photos.MediaPublishSubscribeInterface.1"

                  [HKEY_CLASSES_ROOT\CLSID\{CE6AED26-A6CB-4267-6CA4-21F2C1C24324}\TypeLib]
                  @="{F228A14F-1BBF-8ED7-73A8-ABF7D02A64E1}"

                  [HKEY_CLASSES_ROOT\CLSID\{CE6AED26-A6CB-4267-6CA4-21F2C1C24324}\VersionIndependentProgID]
                  @="Microsoft.Photos.MediaPublishSubscribeInterface"

                  [HKEY_CLASSES_ROOT\CLSID\{D11A646E-0C3C-4EE3-9362-DB0D9DFF3D52}]

                  [HKEY_CLASSES_ROOT\CLSID\{D11A646E-0C3C-4EE3-9362-DB0D9DFF3D52}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\geBssPjk.dll"
                  "ThreadingModel"="Both"

                  [HKEY_CLASSES_ROOT\CLSID\{D53096B8-0786-4cd4-894D-7632EB477881}]
                  @="Windows Live OneCare safety scanner AV/AS Scanner"

                  [HKEY_CLASSES_ROOT\CLSID\{D53096B8-0786-4cd4-894D-7632EB477881}\InprocServer32]
                  @="C:\\Program Files\\Windows Live Safety Center\\scnAVAS.dll"
                  "ThreadingModel"="both"

                  [HKEY_CLASSES_ROOT\CLSID\{D53096B8-0786-4cd4-894D-7632EB477881}\ProgID]
                  @="Microsoft.wlsc.Scanner.AVAS.1"

                  [HKEY_CLASSES_ROOT\CLSID\{D53096B8-0786-4cd4-894D-7632EB477881}\Programmable]

                  [HKEY_CLASSES_ROOT\CLSID\{D53096B8-0786-4cd4-894D-7632EB477881}\TypeLib]
                  @="{95025F64-7AFD-497D-9A9D-CDA6F5BD6908}"

                  [HKEY_CLASSES_ROOT\CLSID\{D53096B8-0786-4cd4-894D-7632EB477881}\VersionIndependentProgID]
                  @="Microsoft.wlsc.Scanner.AVAS"

                  [HKEY_CLASSES_ROOT\CLSID\{DD777EF2-30CE-4afd-AC19-EBC1F5976C82}]
                  @="MlfAddin Class"

                  [HKEY_CLASSES_ROOT\CLSID\{DD777EF2-30CE-4afd-AC19-EBC1F5976C82}\InprocServer32]
                  @="C:\\PROGRA~1\\ZONELA~1\\ZONEAL~1\\MAILFR~1\\mlfoshim.dll"
                  "ThreadingModel"="Apartment"

                  [HKEY_CLASSES_ROOT\CLSID\{DD777EF2-30CE-4afd-AC19-EBC1F5976C82}\ProgID]
                  @="MlfOutlookAddin.MlfAddin.1"

                  [HKEY_CLASSES_ROOT\CLSID\{DD777EF2-30CE-4afd-AC19-EBC1F5976C82}\Programmable]

                  [HKEY_CLASSES_ROOT\CLSID\{DD777EF2-30CE-4afd-AC19-EBC1F5976C82}\TypeLib]
                  @="{CF34D2A7-C8C6-4b4e-8752-F63C2BDF1CF0}"

                  [HKEY_CLASSES_ROOT\CLSID\{DD777EF2-30CE-4afd-AC19-EBC1F5976C82}\VersionIndependentProgID]
                  @="MlfOutlookAddin.MlfAddin"

                  [HKEY_CLASSES_ROOT\CLSID\{E70E903A-D723-4699-997E-E977694B9DA2}]
                  @="Fake Webcam Renderer"

                  [HKEY_CLASSES_ROOT\CLSID\{E70E903A-D723-4699-997E-E977694B9DA2}\InprocServer32]
                  @="C:\\Program Files\\Fake Webcam\\Vcam.ax"
                  "ThreadingModel"="Both"

                  [HKEY_CLASSES_ROOT\CLSID\{F035A9A0-19F1-4B31-9296-82CECC37DB49}]

                  [HKEY_CLASSES_ROOT\CLSID\{F035A9A0-19F1-4B31-9296-82CECC37DB49}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\efcYpPjK.dll"
                  "ThreadingModel"="Both"

                  [HKEY_CLASSES_ROOT\Applications\ContentCopier.exe\shell\Open]
                  @="&Ouvrir avec Content Copier"

                  [HKEY_CLASSES_ROOT\Applications\ContentCopier.exe\shell\Open\command]
                  @="\"C:\\Program Files\\Nokia\\Nokia PC Suite 6\\ContentCopier.exe\" \"%1\""
                  "command"=hex(7):4e,00,39,00,5a,00,3d,00,31,00,42,00,44,00,4c,00,2a,00,39,00,68,\
                  00,2b,00,4e,00,73,00,38,00,58,00,53,00,2d,00,25,00,47,00,43,00,6f,00,6e,00,\
                  74,00,65,00,6e,00,74,00,43,00,6f,00,70,00,69,00,65,00,72,00,3e,00,41,00,51,\
                  00,74,00,30,00,68,00,38,00,4e,00,78,00,5b,00,3f,00,44,00,26,00,37,00,75,00,\
                  4f,00,6f,00,4e,00,3f,00,61,00,63,00,20,00,22,00,25,00,31,00,22,00,00,00,16,\
                  00,00,00,11,00,11,00,1d3,00,10c,00,00,00,88d8,00,b3,00,88d8,00,b3,00,b3e0,00,\
                  16,00,88f4,00,b3,00,88f4,00,b3,00,bd90,00,16,00,8918,00,b3,00,8900,00,b3,00,\
                  c1c0,00,16,00,8924,00,b3,00,890c,00,b3,00,c1f8,00,16,00,8930,00,b3,00,8918,\
                  00,b3,00,c240,00,16,00,893c,00,b3,00,8924,00,b3,00,c268,00,16,00,8948,00,b3,\
                  00,8930,00,b3,00,c2c0,00,16,00,8954,00,b3,00,893c,00,b3,00,c308,00,16,00,8960,\
                  00,b3,00,8948,00,b3,00,c340,00,16,00,00,00,8954,00,b3,00,c378,00,16,00,00,00,11,\
                  00,11,00,1e0,00,108,00,dad,00,00,00,16,00,1f48,00,4a,00,00,00,a8ac,00,99,00,\
                  00,00,00,00

                  [HKEY_CLASSES_ROOT\Applications\MusicManager.exe\shell\Open]

                  [HKEY_CLASSES_ROOT\Applications\MusicManager.exe\shell\Open\Command]
                  @="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\MusicManager.exe /play \"%1\""

                  [HKEY_CLASSES_ROOT\Applications\MusicManager.exe\shell\Open\DropTarget]
                  "Clsid"=""

                  [HKEY_CLASSES_ROOT\Applications\winzip32.exe\shell\open]
                  @="Ouvrir avec &WinZip"

                  [HKEY_CLASSES_ROOT\Applications\winzip32.exe\shell\open\command]
                  @="C:\\PROGRA~1\\WINZIP\\winzip32.exe \"%1\""

                  [HKEY_CLASSES_ROOT\Applications\winzip32.exe\shell\print]

                  [HKEY_CLASSES_ROOT\Applications\winzip32.exe\shell\print\command]
                  @="C:\\PROGRA~1\\WINZIP\\winzip32.exe /print /ni \"%1\""

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
                  "c:\\WINDOWS\\winsxs\\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\\"=""

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders]
                  "D:\\Documents and Settings\\All Users\\Application Data\\BitDefender\\Desktop\\Temp\\"="1"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KB928365.T1_1ToU569_1]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Microsoft .NET Framework 2.0]
                  "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,e0,86,05,00,00,00,00,e8,98,d1,\
                  76,26,55,c8,01,00,00,00,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,\
                  57,00,53,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,\
                  00,4e,00,45,00,54,00,5c,00,46,00,72,00,61,00,6d,00,65,00,77,00,6f,00,72,00,\
                  6b,00,5c,00,76,00,32,00,2e,00,30,00,2e,00,35,00,30,00,37,00,32,00,37,00,5c,\
                  00,76,00,62,00,63,00,2e,00,65,00,78,00,65,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{10864676-F019-4492-91BC-6A5F68C72840}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{125F0ACC-D3FC-402B-8D96-27F6E46D00D5}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1AC4B415-0F2E-40CA-9747-425AA1654C17}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2D1B9BE8-22BC-4245-B86B-02B30F7C7AE4}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2ED60C17-4568-4CD5-830A-03C4688B09A1}]
                  "SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,40,0e,00,00,00,00,00,6e,8f,ab,\
                  3c,d4,4e,c8,01,02,00,00,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,\
                  61,00,6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,53,00,41,00,47,00,45,\
                  00,4d,00,20,00,57,00,69,00,46,00,69,00,20,00,6d,00,61,00,6e,00,61,00,67,00,\
                  65,00,72,00,5c,00,57,00,4c,00,41,00,4e,00,55,00,54,00,4c,00,2e,00,65,00,78,\
                  00,65,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{32971938-65B1-4B38-B483-9A32560B7CF2}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{45D68F08-56A0-4412-BB0F-8492BE978AC7}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4D072D56-B07B-4798-97B2-B9E7A4F53EAC}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{558CD0A7-0548-4220-88FE-01CC1477DF61}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{5AC9F44E-06C7-41E3-A464-37177AB9105D}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00
                  "Changed"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6793364B-A91C-49D3-923D-9932952E62FA}]
                  "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
                  00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
                  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
                  0
                  • 1
                  • 2