Problèmes et rapports Hijack/AVG

Résolu
Kimboo Messages postés 49 Statut Membre -  
Kimboo Messages postés 49 Statut Membre -
Bonjour, alors moi j'ai des problèmes qui sont survenues depuis quelques jours. En faite mon ordinateur n'arrête pas de faire un bruit bizarre pour vraiment aucune raison... Ça c'est produit récemment je n'avais même pas ouvert/modifier mon ordinateur. C'est un bruit plutôt grave qui ressemble à un bruit de ventilateur qui tourne beaucoup trop vite. J'ai ouvert mon ordinateur pour nettoyer la poussière mais aucun changement. De plus j'ai récemment des messages d'erreurs comme ceci: http://img93.imageshack.us/img93/9588/errorwindowsoz7.jpg

Voici mon rapport Hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:52, on 2008-08-28
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Personal Vault\VaultClientUpgrade.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Gestionnaire de securite\Rps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live Messenger Khalid Edition v5.1\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Fichiers communs\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Gestionnaire de securite\pkR.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] "C:\Program Files\Bell\Gestionnaire de securite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Gestionnaire de securite\IdxClnR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Gestionnaire de securite\IdxClnR.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Fichiers communs\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Gestionnaire de sécurité Sympatico (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\RpsSecurityAware.exe
O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe

--
End of file - 9919 bytes

PS: Récemment j'avais été attacké par le trojant Vundo/Virtumonde et j'ai suivie les étapes du mieu que j'ai pus et dans mes backups il y a ceci (Si ça peut aider a trouver quoique se soit):

2008-06-08, 18:05: O2 - BHO: (no name) - {F4FEB26A-A617-4255-8FF9-26D28B5F5FDC} - C:\WINDOWS\system32\ddcYOecD.dll (file missing)
2008-06-08, 18:05: O2 - BHO: (no name) - {B790E16A-7FF9-4D0A-BB37-61F3B55892E3} - C:\WINDOWS\system32\vtUnlkJD.dlll (file missing)
2008-06-08, 18:05: O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)
2008-06-08, 18:05: O2 - BHO: (no name) - {7A416FD0-459A-A345-034070D32066} - C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content... (Je ne peux pas lire d'avantage)
2008-07-08, 18:34: O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


Voici mon rapport AVG Anti-Spyware:

---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 21:33 2008-08-19

+ Résultat de l'analyse:

C:\System Volume Information\_restore{C592EEE8-8362-4445-98F0-1FDC60FA539D}\RP99\A0030194.exe/file.exe -> Backdoor.Nuclear.di : Aucune action entreprise.
C:\Documents and Settings\HP_Propriétaire\Mes documents\LimeWire\Saved\pas sans toi.wm -> Downloader.Wimad.m : Aucune action entreprise.
C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD 2.9.1.0 Keygen.exe/file.exe -> Backdoor.Nuclear.di : Aucune action entreprise.
C:\System Volume Information\_restore{C592EEE8-8362-4445-98F0-1FDC60FA539D}\RP58\A0013560.exe/file.exe -> Backdoor.Nuclear.di : Aucune action entreprise.
C:\System Volume Information\_restore{C592EEE8-8362-4445-98F0-1FDC60FA539D}\RP67\A0015557.dll -> Trojan.Monder.bbw : Aucune action entreprise.
C:\VundoFix Backups\kcqncpwc.dll.bad -> Trojan.Monder.bbw : Aucune action entreprise.

Fin du rapport

J'ai un Anti-Virus de la compagnie Sympatico (Freedom Anti-Virus) et selon la dernière analyse que j'ai fait hier il n'y aurai aucun virus dans mon ordinateur.

Merci d'avance pour votre aide!
Configuration: Windows XP
Firefox 3.0.1

25 réponses

  • 1
  • 2
  1. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    Salut,

    As-tu fait un autre topic pour ton infection ?
    0
  2. Kimboo Messages postés 49 Statut Membre
     
    uh j'ai deja fait un autre topic mais c'est pas le même problème la.... j'en ai fini avec lle trojant Vundo/Virtumonde
    0
  3. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    Donne-moi le lien de l'ancien topic car ça pourrait m'aider.
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    Salut,

    ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

    ---> Double-clique sur Combofix.exe
    Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
    Accepte en cliquant sur "Oui"

    ---> Mets-le en langue française F
    Tape sur la touche 1 (Yes) pour démarrer le scan.

    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

    Note : Le rapport se trouve également là : C:\ComboFix.txt
    0
  6. Kimboo Messages postés 49 Statut Membre
     
    wow le rapport est juste un tout petit peu long hehe le voici:

    ComboFix 08-08-29.02 - HP_Propriétaire 2008-08-29 18:41:36.3 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.201 [GMT -4:00]
    Endroit: C:\Documents and Settings\HP_Propriétaire\Bureau\ComboFix.exe
    * Création d'un nouveau point de restauration
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\RECYCLER\RB3.tmp

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-07-28 to 2008-08-29 ))))))))))))))))))))))))))))))))))))
    .

    2008-08-13 23:39 . 2008-08-28 23:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\uTorrent
    2008-08-13 22:33 . 2008-08-13 23:38 <REP> d-------- C:\Program Files\eMule
    2008-08-13 22:20 . 2008-05-01 10:36 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
    2008-08-13 22:16 . 2008-04-11 15:05 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
    2008-08-10 17:40 . 2008-08-10 17:41 <REP> d-------- C:\Program Files\LimeWire
    2008-08-10 17:40 . 2008-08-10 17:40 <REP> d-------- C:\Program Files\Google
    2008-08-08 00:08 . 2008-08-08 00:08 <REP> d-------- C:\Program Files\Personal Vault
    2008-08-08 00:07 . 2008-01-09 10:35 55,296 --a------ C:\WINDOWS\system32\drivers\rp_skt32.sys
    2008-08-08 00:07 . 2007-04-19 11:36 48,384 --a------ C:\WINDOWS\system32\drivers\rp_pkt32.sys
    2008-08-08 00:06 . 2008-08-08 00:06 <REP> d-------- C:\Program Files\Raxco
    2008-08-08 00:06 . 2008-08-08 00:26 <REP> d-------- C:\Program Files\Fichiers communs\Scanner
    2008-08-08 00:06 . 2008-08-08 00:06 <REP> d-------- C:\Program Files\Fichiers communs\Authentium
    2008-08-08 00:06 . 2008-08-08 00:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Raxco
    2008-08-08 00:01 . 2008-08-08 00:05 <REP> d-------- C:\Program Files\Bell
    2008-08-07 21:11 . 2008-08-07 21:15 <REP> d-------- C:\WINDOWS\SxsCaPendDel
    2008-08-07 20:43 . 2008-08-07 20:53 121 --a------ C:\WINDOWS\bdagent.INI
    2008-08-07 19:02 . 2008-08-07 21:08 81,984 --a------ C:\WINDOWS\system32\bdod.bin
    2008-08-07 18:43 . 2008-08-07 18:46 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
    2008-08-07 18:27 . 2004-11-04 23:36 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
    2008-08-07 18:27 . 2004-11-04 15:37 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
    2008-08-07 18:27 . 2004-11-04 15:37 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
    2008-08-07 18:27 . 2008-07-13 18:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
    2008-08-07 18:27 . 2008-07-13 18:54 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
    2008-08-07 18:27 . 2008-07-13 18:54 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
    2008-08-07 18:27 . 2008-07-13 18:54 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
    2008-08-07 18:27 . 2004-11-04 23:52 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
    2008-08-07 18:27 . 2004-11-05 15:54 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
    2008-08-07 18:27 . 2004-11-05 00:22 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
    2008-08-07 18:27 . 2004-11-04 23:36 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
    2008-08-07 18:27 . 2008-08-07 18:27 <REP> d-------- C:\Documents and Settings\Administrateur
    2008-08-07 15:13 . 2008-06-23 12:28 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
    2008-08-07 15:13 . 2007-04-17 05:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
    2008-08-07 15:13 . 2007-03-08 01:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
    2008-08-07 15:13 . 2008-06-23 12:28 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
    2008-08-07 15:13 . 2008-06-23 12:28 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
    2008-08-07 15:13 . 2008-06-23 12:28 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
    2008-08-07 15:13 . 2008-06-23 12:28 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
    2008-08-07 15:13 . 2008-06-23 12:28 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    2008-08-07 15:13 . 2008-06-23 05:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
    2008-08-06 21:42 . 2008-06-14 13:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-08-06 21:12 . 2008-08-06 21:12 <REP> d-------- C:\WINDOWS\system32\bits
    2008-08-06 21:12 . 2008-08-06 21:12 <REP> d-------- C:\WINDOWS\l2schemas
    2008-08-06 18:34 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
    2008-08-05 17:55 . 2008-08-25 21:17 <REP> d-------- C:\WINDOWS\system32\Adobe
    2008-08-04 02:56 . 2008-08-04 02:56 <REP> d-------- C:\Program Files\iPod
    2008-08-04 02:55 . 2008-08-04 03:01 <REP> d-------- C:\Program Files\iTunes
    2008-08-04 02:44 . 2008-08-04 02:44 <REP> d-------- C:\Program Files\Bonjour
    2008-08-04 02:01 . 2008-08-04 02:02 <REP> d-------- C:\Program Files\Safari
    2008-08-01 13:14 . 2008-08-01 13:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2008-07-31 20:26 . 2008-07-31 20:26 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Grisoft
    2008-07-31 20:25 . 2008-07-31 20:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-07-31 20:25 . 2007-05-30 08:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2008-07-31 20:16 . 2008-07-31 20:16 <REP> d-------- C:\Program Files\Yahoo!
    2008-07-31 20:16 . 2008-07-31 20:21 <REP> d-------- C:\Program Files\CCleaner
    2008-07-31 19:15 . 2008-07-31 19:15 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
    2008-07-31 18:16 . 2008-07-31 18:16 <REP> d-------- C:\Program Files\Trend Micro
    2008-07-31 17:17 . 2008-08-18 21:06 <REP> d-------- C:\VundoFix Backups

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-29 19:41 --------- d-----w C:\Program Files\Easy Internet signup
    2008-08-29 06:03 --------- d-----w C:\Program Files\PowerArchiver
    2008-08-29 02:52 958 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\wklnhst.dat
    2008-08-29 02:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-08-27 15:29 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Free Download Manager
    2008-08-27 15:17 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\LimeWire
    2008-08-08 06:07 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Bell
    2008-08-08 04:06 --------- d-----w C:\Program Files\CA
    2008-08-08 04:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bell
    2008-08-08 04:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-08-06 22:08 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
    2008-07-31 20:46 --------- d-----w C:\Program Files\Windows Live
    2008-07-31 20:42 --------- d-----w C:\Program Files\Windows Live Toolbar
    2008-07-31 17:36 141,612 ----a-w C:\WINDOWS\system32\drivers\dump_wmimmc.sys
    2008-07-28 22:07 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
    2008-07-28 08:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
    2008-07-28 08:01 --------- d-----w C:\Program Files\Elaborate Bytes
    2008-07-27 07:16 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-07-26 18:53 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Ventrilo
    2008-07-26 18:52 --------- d-----w C:\Program Files\Ventrilo
    2008-07-26 18:51 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-07-25 19:51 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\smc
    2008-07-25 19:30 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Uniblue
    2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
    2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
    2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
    2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
    2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
    2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
    2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
    2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
    2008-07-15 14:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    2008-07-14 22:09 65,536 ----a-w C:\WINDOWS\IFinst27.exe
    2008-07-14 22:09 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\LuckyTender
    2008-07-14 07:41 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Media Player Classic
    2008-07-14 04:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\ConeXware
    2008-07-14 04:33 --------- d-----w C:\Program Files\DAEMON Tools Lite
    2008-07-14 04:15 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\teamspeak2
    2008-07-14 04:14 --------- d-----w C:\Program Files\Teamspeak2_RC2
    2008-07-14 03:59 --------- d-----w C:\Program Files\mIRC
    2008-07-14 03:59 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\mIRC
    2008-07-14 03:37 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
    2008-07-14 03:37 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\DAEMON Tools
    2008-07-14 03:36 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-07-14 03:23 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Canneverbe_Limited
    2008-07-14 03:22 --------- d-----w C:\Program Files\CDBurnerXP
    2008-07-14 03:20 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\skypePM
    2008-07-14 03:08 --------- d-----w C:\Program Files\K-Lite Codec Pack
    2008-07-14 03:06 --------- d-----w C:\Program Files\Reference Assemblies
    2008-07-14 03:06 --------- d-----w C:\Program Files\MSBuild
    2008-07-14 03:04 --------- d-----w C:\Program Files\Free Download Manager
    2008-07-14 03:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
    2008-07-14 02:58 --------- d-----w C:\Program Files\WinISO
    2008-07-14 02:55 --------- d-----w C:\Program Files\Skype
    2008-07-14 02:55 --------- d-----w C:\Program Files\Fichiers communs\Skype
    2008-07-14 02:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
    2008-07-14 02:30 --------- d-----w C:\Program Files\Windows Live Messenger Khalid Edition v5.1
    2008-07-14 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-07-14 00:57 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-07-14 00:44 --------- d-----w C:\Program Files\uTorrent
    2008-07-13 23:38 --------- d-----w C:\Program Files\QuickTime
    2008-07-13 23:10 1,897 --sha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_PS512AA-ABA a815n_YC_0Pavi_QMXF505_E51FCheBLT2_47_IGoldfish2_SASUSTeK Computer INC._V1.xx_B3.10_T041112_WXH2_L40C_M504_J160_7Intel_8Pentium 4_93.06_#080713_N10EC8139_Z11C1048C_G80862582.MRK
    2008-07-13 23:07 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
    2008-07-13 22:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-07-13 22:19 --------- d-----w C:\Program Files\Java
    2008-07-13 22:15 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Template
    2008-07-13 22:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
    2008-07-13 22:11 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Apple Computer
    2008-07-13 17:33 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Notepad++
    2008-07-13 16:19 --------- d-----w C:\Program Files\Notepad++
    2008-07-13 09:31 --------- d-----w C:\Program Files\muvee Technologies
    2008-07-13 09:31 --------- d-----w C:\Program Files\InterVideo
    2008-07-13 09:31 --------- d-----w C:\Program Files\Fichiers communs\muvee Technologies
    2008-07-13 09:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
    2008-07-13 08:03 90,112 ----a-w C:\WINDOWS\DUMP2693.tmp
    2008-07-13 07:01 90,112 ----a-w C:\WINDOWS\DUMP2589.tmp
    2008-07-13 05:02 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\AdobeUM
    2008-07-13 05:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
    2008-07-13 05:01 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Sonic
    2008-07-13 05:01 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Leadertech
    2008-07-13 04:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\muvee Technologies
    2008-07-13 04:56 90,112 ----a-w C:\WINDOWS\DUMP2e43.tmp
    2008-07-13 04:39 --------- d-----w C:\Program Files\Apple Software Update
    2008-07-13 04:38 --------- d-----w C:\Program Files\Fichiers communs\Apple
    2008-07-13 04:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
    2008-07-13 04:32 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\MSNInstaller
    2008-07-13 03:54 90,112 ----a-w C:\WINDOWS\DUMP2625.tmp
    2008-07-13 03:44 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\InstallShield
    2008-07-13 03:36 --------- d-----w C:\Program Files\Profile
    2008-07-10 13:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
    2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
    2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
    2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-07-31_19.55.16.84 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-07-07 20:24:11 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll
    + 2007-11-30 12:39:29 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spmsg.dll
    + 2007-11-30 12:39:29 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spuninst.exe
    + 2007-11-30 12:39:29 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\spcustom.dll
    + 2007-11-30 12:39:26 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\update.exe
    + 2007-11-30 12:39:29 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\updspapi.dll
    + 2008-07-11 12:51:51 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
    + 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spmsg.dll
    + 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spuninst.exe
    + 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\spcustom.dll
    + 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
    + 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\updspapi.dll
    + 2008-06-24 16:53:52 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3QFE\mscms.dll
    + 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spmsg.dll
    + 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spuninst.exe
    + 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\spcustom.dll
    + 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\update.exe
    + 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\updspapi.dll
    + 2008-04-14 02:33:18 39,424 ------w C:\WINDOWS\AppPatch\acadproc.dll
    - 2004-08-19 20:09:20 1,852,416 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
    + 2008-04-14 02:33:18 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
    - 2004-08-19 20:09:20 450,048 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
    + 2008-04-14 02:33:18 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
    - 2004-08-19 20:09:20 137,728 ----a-w C:\WINDOWS\AppPatch\aclua.dll
    + 2008-04-14 02:33:18 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
    - 2004-08-19 20:09:20 244,736 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
    + 2008-04-14 02:33:18 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
    - 2004-08-19 20:09:20 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
    + 2008-04-14 02:33:18 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
    - 2004-11-05 03:31:21 1,100,392 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
    + 2008-08-08 07:34:02 1,103,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
    - 2004-11-05 03:31:22 141,928 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    + 2008-08-08 07:34:03 144,784 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    - 2004-11-05 03:31:22 408,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
    + 2008-08-08 07:34:23 411,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
    - 2004-11-05 03:31:22 35,448 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
    + 2008-08-08 07:34:17 38,304 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
    - 2004-11-05 03:31:22 461,416 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Owc11\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Owc11.dll
    + 2008-08-08 07:33:45 464,272 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Owc11\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Owc11.dll
    - 2004-11-05 03:31:22 223,856 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    + 2008-08-08 07:34:28 226,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    - 2004-11-05 03:31:22 20,080 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
    + 2008-08-08 07:33:51 22,928 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
    - 2004-11-05 03:31:22 662,120 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2008-08-08 07:34:48 664,968 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    - 2004-11-05 03:31:22 371,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
    + 2008-08-08 07:33:50 374,152 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
    - 2004-11-05 03:31:22 64,088 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    + 2008-08-08 07:31:10 66,936 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    - 2004-11-05 03:31:22 223,800 ----a-w C:\WINDOWS\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
    + 2008-08-08 07:31:03 226,656 ----a-w C:\WINDOWS\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
    + 2008-08-08 07:14:52 226,656 ----a-w C:\WINDOWS\assembly\tmp\[u]0/uV28FLRX\OFFICE.DLL
    + 2008-08-08 07:15:05 66,936 ----a-w C:\WINDOWS\assembly\tmp\JTZ5BIOU\Microsoft.Vbe.Interop.dll
    + 2008-03-24 23:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
    - 2008-06-14 17:59:52 272,768 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
    + 2008-06-14 17:33:37 272,768 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
    - 2004-08-19 20:09:54 1,036,288 ----a-w C:\WINDOWS\explorer.exe
    + 2008-04-14 02:34:03 1,037,824 ----a-w C:\WINDOWS\explorer.exe
    - 2004-08-19 20:09:44 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
    + 2008-04-14 02:33:41 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
    - 2004-08-19 20:09:46 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
    + 2008-04-14 02:33:46 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
    - 2004-08-19 20:09:48 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
    + 2008-04-14 02:33:46 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
    - 2004-08-19 20:09:56 10,752 ----a-w C:\WINDOWS\hh.exe
    + 2008-04-14 02:34:06 10,752 ----a-w C:\WINDOWS\hh.exe
    + 2004-08-19 20:09:20 61,440 -c----w C:\WINDOWS\ie7\admparse.dll
    + 2004-08-19 20:09:20 101,888 -c----w C:\WINDOWS\ie7\advpack.dll
    + 2004-08-19 20:09:22 35,328 -c----w C:\WINDOWS\ie7\corpol.dll
    + 2006-06-02 19:32:20 33,792 -c----w C:\WINDOWS\ie7\custsat.dll
    + 2008-04-21 07:02:28 357,888 -c----w C:\WINDOWS\ie7\dxtmsft.dll
    + 2008-04-21 07:02:28 205,312 -c----w C:\WINDOWS\ie7\dxtrans.dll
    + 2008-04-21 07:02:28 55,808 -c----w C:\WINDOWS\ie7\extmgr.dll
    + 2004-08-19 20:09:28 38,912 -c----w C:\WINDOWS\ie7\hmmapi.dll
    + 2004-08-19 20:09:56 34,304 -c----w C:\WINDOWS\ie7\ie4uinit.exe
    + 2004-08-19 20:09:28 139,264 -c----w C:\WINDOWS\ie7\ieakeng.dll
    + 2004-08-19 20:09:28 221,696 -c----w C:\WINDOWS\ie7\ieaksie.dll
    + 2004-08-04 04:00:00 245,760 -c----w C:\WINDOWS\ie7\ieakui.dll
    + 2004-08-19 20:09:28 323,584 -c----w C:\WINDOWS\ie7\iedkcs32.dll
    + 2008-04-17 10:52:54 18,432 -c----w C:\WINDOWS\ie7\iedw.exe
    + 2004-08-19 20:09:28 81,920 -c----w C:\WINDOWS\ie7\ieencode.dll
    + 2008-04-21 07:02:29 251,392 -c----w C:\WINDOWS\ie7\iepeers.dll
    + 2004-08-19 20:09:28 49,152 -c----w C:\WINDOWS\ie7\iernonce.dll
    + 2004-08-19 20:09:28 63,488 -c----w C:\WINDOWS\ie7\iesetup.dll
    + 2004-08-19 20:09:56 93,184 -c----w C:\WINDOWS\ie7\iexplore.exe
    + 2004-08-19 20:09:30 35,840 -c----w C:\WINDOWS\ie7\imgutil.dll
    + 2008-04-21 07:02:29 96,768 -c----w C:\WINDOWS\ie7\inseng.dll
    + 2004-08-19 20:09:32 450,560 -c----w C:\WINDOWS\ie7\jscript.dll
    + 2008-04-21 07:02:29 16,384 -c----w C:\WINDOWS\ie7\jsproxy.dll
    + 2004-08-19 20:09:32 22,528 -c----w C:\WINDOWS\ie7\licmgr10.dll
    + 2004-08-19 20:10:00 29,184 -c----w C:\WINDOWS\ie7\mshta.exe
    + 2008-04-21 07:02:34 3,080,704 -c----w C:\WINDOWS\ie7\mshtml.dll
    + 2008-04-21 07:02:34 449,024 -c----w C:\WINDOWS\ie7\mshtmled.dll
    + 2004-08-19 20:08:28 57,344 -c----w C:\WINDOWS\ie7\mshtmler.dll
    + 2004-08-04 04:00:00 146,432 -c----w C:\WINDOWS\ie7\msls31.dll
    + 2008-04-21 07:02:34 146,432 -c----w C:\WINDOWS\ie7\msrating.dll
    + 2008-04-21 07:02:35 532,480 -c----w C:\WINDOWS\ie7\mstime.dll
    + 2004-08-19 20:09:38 97,280 -c----w C:\WINDOWS\ie7\occache.dll
    + 2008-04-21 07:02:35 39,424 -c----w C:\WINDOWS\ie7\pngfilt.dll
    + 2007-09-26 22:34:42 33,472 -c----w C:\WINDOWS\ie7\spuninst\iecustom.dll
    + 2007-09-26 22:32:30 66,048 -c--a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
    + 2006-09-06 21:43:28 216,800 -c----w C:\WINDOWS\ie7\spuninst\spuninst.exe
    + 2006-09-06 21:43:30 394,976 -c----w C:\WINDOWS\ie7\spuninst\updspapi.dll
    + 2004-08-19 20:09:48 37,888 -c----w C:\WINDOWS\ie7\url.dll
    + 2008-04-21 07:02:39 617,984 -c----w C:\WINDOWS\ie7\urlmon.dll
    + 2004-08-19 20:09:48 417,792 -c----w C:\WINDOWS\ie7\vbscript.dll
    + 2004-08-19 20:09:48 848,384 -c----w C:\WINDOWS\ie7\vgx.dll
    + 2004-08-19 20:09:48 281,600 -c----w C:\WINDOWS\ie7\webcheck.dll
    + 2008-04-21 07:02:40 663,552 -c----w C:\WINDOWS\ie7\wininet.dll
    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:35:47 394,976 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
    + 2007-08-13 22:54:10 765,952 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\vgx.dll
    + 2007-08-13 22:39:00 123,904 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
    + 2007-08-13 22:35:46 346,624 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
    + 2007-08-13 22:35:38 214,528 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
    + 2007-08-13 22:54:10 131,584 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
    + 2007-08-13 22:36:26 61,952 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\icardie.dll
    + 2007-08-13 22:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
    + 2007-08-13 22:39:26 152,064 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
    + 2007-08-13 22:39:54 229,376 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
    + 2007-08-13 21:56:54 161,792 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
    + 2007-02-12 20:10:12 2,451,312 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dat
    + 2007-07-11 16:27:48 383,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dll
    + 2007-08-13 22:39:50 382,976 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
    + 2007-08-13 22:54:10 6,049,280 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieframe.dll
    + 2007-08-13 22:39:10 43,008 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
    + 2007-08-13 22:34:04 266,752 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iertutil.dll
    + 2007-08-13 22:39:10 13,312 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
    + 2007-08-13 22:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
    + 2007-08-13 22:54:10 27,136 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
    + 2007-08-13 22:54:10 458,752 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeeds.dll
    + 2007-08-13 22:54:10 50,688 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeedsbs.dll
    + 2007-08-13 22:54:12 3,578,368 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
    + 2007-08-13 22:54:10 475,648 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
    + 2007-08-13 22:44:26 192,000 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
    + 2007-08-13 22:54:10 670,720 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
    + 2007-08-13 22:44:06 101,376 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
    + 2007-08-13 22:36:12 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\updspapi.dll
    + 2007-08-13 22:44:30 105,984 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\url.dll
    + 2007-08-13 22:54:10 1,162,240 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
    + 2007-08-13 22:54:10 231,424 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
    + 2007-08-13 22:54:10 818,688 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
    + 2008-04-23 04:16:39 124,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
    + 2008-04-23 04:16:39 347,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
    + 2008-04-23 04:16:39 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
    + 2008-04-23 04:16:39 133,120 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
    + 2008-04-23 04:16:39 63,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll
    + 2008-04-22 07:41:08 70,656 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
    + 2008-04-23 04:16:39 153,088 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
    + 2008-04-23 04:16:39 230,400 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
    + 2008-04-20 05:07:51 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
    + 2008-04-23 04:16:39 383,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll
    + 2008-04-23 04:16:39 384,512 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
    + 2008-04-23 04:16:39 6,066,176 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll
    + 2008-04-23 04:16:39 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
    + 2008-04-23 04:16:39 267,776 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll
    + 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
    + 2008-04-22 07:41:30 625,664 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
    + 2008-04-23 04:16:40 27,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
    + 2008-04-23 04:16:40 459,264 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll
    + 2008-04-23 04:16:40 52,224 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll
    + 2008-04-24 02:16:42 3,591,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
    + 2008-04-23 04:16:40 478,208 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
    + 2008-04-23 04:16:40 193,024 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
    + 2008-04-23 04:16:40 671,232 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
    + 2008-04-23 04:16:40 102,912 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
    + 2008-04-23 04:16:40 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll
    + 2008-04-23 04:16:40 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll
    + 2008-04-23 04:16:40 1,159,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
    + 2008-04-23 04:16:40 233,472 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
    + 2008-04-23 04:16:40 826,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
    - 2004-08-19 20:09:34 220,160 ----a-w C:\WINDOWS\ime\mscandui.dll
    + 2008-04-14 02:33:30 220,160 ----a-w C:\WINDOWS\ime\mscandui.dll
    - 2004-08-19 20:09:44 130,048 ----a-w C:\WINDOWS\ime\softkbd.dll
    + 2008-04-14 02:33:41 130,048 ----a-w C:\WINDOWS\ime\softkbd.dll
    - 2004-08-19 20:08:56 62,976 ----a-w C:\WINDOWS\ime\spgrmr.dll
    + 2008-04-13 16:43:18 62,976 ----a-w C:\WINDOWS\ime\spgrmr.dll
    - 2004-08-19 20:09:44 272,384 ----a-w C:\WINDOWS\ime\sptip.dll
    + 2008-04-14 02:33:46 272,384 ----a-w C:\WINDOWS\ime\sptip.dll
    - 2004-08-19 20:10:04 208,896 ----a-w C:\WINDOWS\inf\unregmp2.exe
    + 2008-04-14 02:34:26 208,896 ----a-w C:\WINDOWS\inf\unregmp2.exe
    + 2003-07-15 18:43:20 87,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\ADDRPARS.DLL
    + 2003-07-15 18:57:34 38,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
    + 2003-07-15 18:53:06 94,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\AW.DLL
    + 2003-07-15 10:53:24 60,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\BLNMGR.DLL
    + 2003-07-15 10:53:22 46,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\BLNMGRPS.DLL
    + 2003-07-15 15:14:28 350,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL
    + 2003-07-15 23:18:12 47,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
    + 2003-07-26 14:57:20 75,832 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DLGSETP.DLL
    + 2003-07-15 18:56:54 14,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
    + 2003-07-15 18:57:14 98,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
    + 2003-08-01 11:19:52 131,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\ENVELOPE.DLL
    + 2003-08-13 22:34:38 10,073,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\EXCEL.EXE
    + 2003-07-15 18:41:44 13,368 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FINDER.EXE
    + 2003-08-04 06:56:16 1,146,184 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FM20.DLL
    + 2002-10-08 05:49:36 192,573 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FORM.DLL
    + 2003-07-15 19:36:14 186,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL
    + 2003-07-15 18:40:12 179,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPERSON.DLL
    + 2003-07-26 15:00:16 1,157,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPSRVUTL.DLL
    + 2003-07-26 15:14:50 799,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL
    + 2003-07-15 19:11:42 2,139,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\GRAPH.EXE
    + 2003-07-15 10:57:44 87,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL
    + 2003-07-15 18:53:50 161,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\IETAG.DLL
    + 2003-07-24 18:32:32 121,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\IMPMAIL.DLL
    + 2003-05-29 11:42:48 514,680 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\INTLNAME.DLL
    + 2003-06-19 13:31:44 758,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL
    + 2003-06-19 13:31:10 252,928 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
    + 2003-06-19 13:31:48 17,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL
    + 2003-06-19 13:31:48 18,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL
    + 2003-06-19 13:31:46 35,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL
    + 2003-06-19 13:31:34 443,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
    + 2003-05-29 11:42:50 342,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\METCONV.DLL
    + 2003-07-15 18:46:08 176,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MIMEDIR.DLL
    + 2003-07-15 19:01:44 445,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MODHELP.DLL
    + 2003-07-15 18:57:14 124,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSB1CORE.DLL
    + 2003-07-15 19:12:22 47,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSB1XTOR.DLL
    + 2003-07-15 10:58:04 230,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSCDM.DLL
    + 2002-12-18 15:08:50 359,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSDMENG.DLL
    + 2002-12-18 15:08:54 1,383,592 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSDMINE.DLL
    + 2003-07-15 18:56:14 40,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSE7.EXE
    + 2003-07-15 18:51:44 87,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
    + 2002-04-10 16:14:36 187,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSMDUN80.DLL
    + 2003-07-15 18:52:52 17,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
    + 2003-08-08 20:23:16 12,172,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSO.DLL
    + 2003-07-15 10:57:16 120,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
    + 2003-07-15 15:14:18 106,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL
    + 2003-07-24 10:35:26 127,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL
    + 2003-07-15 18:52:52 27,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
    + 2003-07-15 18:44:06 25,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOEURO.DLL
    + 2003-07-15 18:52:56 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
    + 2002-12-18 15:09:24 2,071,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOLAP80.DLL
    + 2003-07-15 18:56:16 54,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOMSE.DLL
    + 2003-07-11 22:15:48 1,292,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSONSEXT.DLL
    + 2003-07-15 23:18:52 376,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSORUN.DLL
    + 2003-07-15 10:52:54 28,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
    + 2003-07-15 18:52:52 35,896 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSV.DLL
    + 2003-07-15 18:53:00 55,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSVABW.DLL
    + 2003-07-15 18:53:20 39,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
    + 2003-07-15 18:46:16 42,040 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
    + 2003-07-15 18:45:12 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
    + 2003-07-15 18:45:12 39,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
    + 2003-06-19 13:31:24 1,033,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL
    + 2003-06-19 13:31:54 788,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPFILT.DLL
    + 2003-06-19 13:31:50 16,384 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
    + 2003-06-20 12:05:52 128,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPSCAN.EXE
    + 2003-06-20 12:05:50 364,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
    + 2003-07-15 19:02:42 637,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSQRY32.EXE
    + 2003-07-15 18:52:58 41,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
    + 2003-07-15 19:02:14 627,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE
    + 2003-07-15 18:56:24 124,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE
    + 2003-07-24 18:40:00 482,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL
    + 2003-07-15 19:00:54 145,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
    + 2003-07-15 18:57:10 56,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\NAME.DLL
    + 2003-07-15 18:56:52 13,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
    + 2003-06-19 13:31:58 6,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OCRPS.DLL
    + 2004-11-05 03:31:22 223,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OFFICE.DLL
    + 2003-07-15 23:14:26 283,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OIS.EXE
    + 2003-07-15 23:14:26 828,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL
    + 2003-07-15 23:14:26 27,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
    + 2003-07-15 23:14:26 242,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
    + 2003-07-15 19:05:24 1,054,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
    + 2003-07-15 10:53:08 95,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OSA.EXE
    + 2003-07-15 18:41:56 24,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLACCT.DLL
    + 2003-07-15 18:44:34 102,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLCTL.DLL
    + 2003-08-10 19:06:42 7,522,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLLIB.DLL
    + 2003-07-15 18:44:32 88,128 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
    + 2003-07-15 18:45:18 196,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLOOK.EXE
    + 2003-07-15 18:43:48 139,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLPH.DLL
    + 2003-07-15 18:43:18 64,056 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
    + 2003-07-15 18:43:16 49,208 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
    + 2003-08-02 11:09:04 8,086,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OWC11.DLL
    + 2003-07-31 08:40:40 6,133,312 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\POWERPNT.EXE
    + 2003-07-15 23:18:54 430,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL
    + 2003-07-15 23:18:44 93,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
    + 2003-08-01 11:21:08 1,782,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PPTVIEW.EXE
    + 2002-10-08 06:11:00 167,997 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PSOM.DLL
    + 2003-07-15 18:42:26 37,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
    + 2003-05-09 17:54:00 77,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
    + 2003-07-15 18:57:08 40,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
    + 2002-10-08 05:49:42 81,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\REVERSE.DLL
    + 2003-07-15 18:43:30 74,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\RM.DLL
    + 2003-07-22 07:46:38 390,712 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\RTFHTML.DLL
    + 2003-07-15 18:57:18 349,248 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SELFCERT.EXE
    + 2003-07-15 18:44:16 66,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
    + 2003-07-15 10:57:08 58,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
    + 2003-08-07 09:31:22 362,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SETLANG.EXE
    + 2003-07-15 18:53:14 11,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
    + 2003-08-04 06:52:32 2,808,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL
    + 2002-10-08 05:53:04 106,561 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\THOCRAPI.DLL
    + 2003-07-15 19:00:22 99,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
    + 2002-10-08 05:50:44 241,729 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWCUTCHR.DLL
    + 2002-10-08 05:51:04 180,289 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWCUTLIN.DLL
    + 2002-10-08 05:51:14 147,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWLAY32.DLL
    + 2002-10-08 05:51:20 102,467 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWORIENT.DLL
    + 2002-10-08 05:50:04 118,847 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWRECE.DLL
    + 2002-10-08 05:49:56 81,983 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWRECS.DLL
    + 2002-10-08 05:51:44 221,252 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWSTRUCT.DLL
    + 2003-07-15 18:57:40 59,960 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\UNBIND.EXE
    + 2003-07-04 11:19:36 2,502,656 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\VBE6.DLL
    + 2004-11-05 03:31:22 64,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
    + 2003-08-07 09:24:20 12,037,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\WINWORD.EXE
    + 2002-10-08 06:03:34 1,794,113 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\XIMAGE3B.DLL
    + 2003-05-01 07:52:32 1,581,120 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\XPAGE3C.DLL
    + 2003-01-18 10:03:34 59,466 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\XSCAN32.DAT
    + 2007-03-22 23:07:56 91,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
    + 2007-04-19 18:10:18 45,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\AUTHZAX.DLL
    + 2007-03-22 23:29:56 99,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\AW.DLL
    + 2007-04-19 18:07:38 66,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\BLNMGR.DLL
    + 2007-04-19 18:07:34 52,064 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\BLNMGRPS.DLL
    + 2007-03-22 23:06:08 355,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\CDLMSO.DLL
    + 2007-04-19 17:55:16 53,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DFUICOM.EXE
    + 2007-03-22 23:07:54 80,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DLGSETP.DLL
    + 2007-03-22 23:23:32 19,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DSITF.DLL
    + 2007-05-10 17:44:02 121,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DSSM.EXE
    + 2007-03-22 23:29:28 43,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DWDCW20.DLL
    + 2007-03-22 23:29:28 39,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DWTRIG20.EXE
    + 2001-06-06 04:13:22 289,926 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ENGDIC.DAT
    + 2001-06-06 04:13:22 34,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ENGIDX.DAT
    + 2007-04-19 17:53:52 137,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ENVELOPE.DLL
    + 2007-05-31 17:41:06 10,352,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\EXCEL.EXE
    + 2007-06-06 14:53:34 1,195,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\FM20.DLL
    + 2007-04-19 17:57:32 2,152,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\GRAPH.EXE
    + 2007-04-19 18:09:30 167,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\IETAG.DLL
    + 2007-04-19 17:53:52 127,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\IMPMAIL.DLL
    + 2001-06-06 04:13:24 18,844 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\JFONT.DAT
    + 2001-06-06 04:13:26 65,536 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\LOOKUP.DAT
    + 2007-04-19 17:54:04 183,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MIMEDIR.DLL
    + 2007-04-19 18:01:52 238,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSCDM.DLL
    + 2005-05-04 04:06:28 465,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSDMENG.DLL
    + 2005-05-04 04:06:32 1,411,816 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSDMINE.DLL
    + 2005-05-04 04:06:26 199,408 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSMDUN80.DLL
    + 2007-06-18 21:16:32 12,259,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSO.DLL
    + 2007-04-19 18:10:34 127,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOAUTH.DLL
    + 2007-04-19 17:56:58 29,024 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOEURO.DLL
    + 2007-04-19 18:07:38 61,280 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOHTMED.EXE
    + 2007-05-02 17:45:26 2,123,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOLAP80.DLL
    + 2007-04-19 17:49:28 383,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSORUN.DLL
    + 2007-04-19 18:07:24 36,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOSTYLE.DLL
    + 2001-10-23 20:13:42 53,260 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OCRHC.DAT
    + 2001-06-06 04:13:26 40,972 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OCRVC.DAT
    + 2007-05-31 17:43:46 7,613,280 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLLIB.DLL
    + 2007-04-19 17:53:44 106,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLMIME.DLL
    + 2007-05-31 17:42:14 200,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLOOK.EXE
    + 2007-04-19 17:53:56 149,856 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLPH.DLL
    + 2007-04-19 17:53:24 69,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLRPC.DLL
    + 2007-05-10 17:45:34 8,069,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OWC11.DLL
    + 2007-05-31 17:35:22 6,420,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
    + 2007-03-22 23:07:10 41,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
    + 2007-06-06 16:07:40 100,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\REFEDIT.DLL
    + 2007-03-22 23:07:54 78,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\RM.DLL
    + 2007-04-19 18:10:20 65,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\SEQCHK10.DLL
    + 2007-03-22 23:29:16 14,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\SMARTTAGINSTALL.EXE
    + 2007-05-10 17:42:52 2,839,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\STSLIST.DLL
    + 2007-03-22 23:22:02 103,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\TRANSMGR.DLL
    + 2007-05-09 21:19:48 2,585,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\VBE6.DLL
    + 2007-05-31 17:37:40 12,310,368 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\WINWORD.EXE
    - 2008-07-13 23:02:37 10,134 ----a-r C:\WINDOWS\Installer\{03D5D136-7031-4F84-9DFC-8D2B4B3FB49E}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:37 10,134 ----a-r C:\WINDOWS\Installer\{03D5D136-7031-4F84-9DFC-8D2B4B3FB49E}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:10 10,134 ----a-r C:\WINDOWS\Installer\{0B831FD2-7291-4291-9510-6AA39E3A45AC}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:10 10,134 ----a-r C:\WINDOWS\Installer\{0B831FD2-7291-4291-9510-6AA39E3A45AC}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:17 10,134 ----a-r C:\WINDOWS\Installer\{17B03967-126B-478A-88ED-BF699690E528}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:22 10,134 ----a-r C:\WINDOWS\Installer\{17B03967-126B-478A-88ED-BF699690E528}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:23 10,134 ----a-r C:\WINDOWS\Installer\{19C68497-1E4A-4285-8CCF-435872CD3436}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:27 10,134 ----a-r C:\WINDOWS\Installer\{19C68497-1E4A-4285-8CCF-435872CD3436}\ARPPRODUCTICON.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ARPPRODUCTICON.exe
    + 2008-08-10 21:41:25 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ARPPRODUCTICON.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
    - 2008-07-13 22:58:31 26,582 ----a-r C:\WINDOWS\Installer\{212F5777-1190-4DEF-8E4D-6B2F313B45E7}\PerfectDisk.exe
    + 2008-08-08 04:06:25 26,582 ----a-r C:\WINDOWS\Installer\{212F5777-1190-4DEF-8E4D-6B2F313B45E7}\PerfectDisk.exe
    + 2008-08-04 07:04:30 102,400 ----a-r C:\WINDOWS\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
    + 2008-08-04 06:44:49 86,016 ----a-r C:\WINDOWS\Installer\{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}\PrntWzrdIco.exe
    - 2008-07-13 22:58:05 10,134 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\ARPPRODUCTICON.exe
    + 2008-08-08 04:05:56 10,134 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\ARPPRODUCTICON.exe
    - 2008-07-13 22:58:05 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Desktop_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    + 2008-08-08 04:05:56 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Desktop_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    - 2008-07-13 22:58:05 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Sm_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    + 2008-08-08 04:05:56 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Sm_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    - 2008-07-13 23:02:14 10,134 ----a-r C:\WINDOWS\Installer\{4DE542B7-B384-453E-BB5B-60A5DAD98903}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:19 10,134 ----a-r C:\WINDOWS\Installer\{4DE542B7-B384-453E-BB5B-60A5DAD98903}\ARPPRODUCTICON.exe
    - 2008-07-13 22:58:36 10,134 ----a-r C:\WINDOWS\Installer\{741CDDCC-F4F0-4CCC-9F47-25DB8FF66BFD}\ARPPRODUCTICON.exe
    + 2008-08-08 04:06:30 10,134 ----a-r C:\WINDOWS\Installer\{741CDDCC-F4F0-4CCC-9F47-25DB8FF66BFD}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:20 10,134 ----a-r C:\WINDOWS\Installer\{86F040E3-2285-4DDC-B082-7A75DB9BA7DF}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:25 10,134 ----a-r C:\WINDOWS\Installer\{86F040E3-2285-4DDC-B082-7A75DB9BA7DF}\ARPPRODUCTICON.exe
    - 2008-07-27 07:19:43 12,288 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    + 2008-08-14 07:52:15 12,288 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2008-07-27 07:19:43 135,168 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    + 2008-08-14 07:52:14 135,168 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2008-07-27 07:19:43 11,264 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    + 2008-08-14 07:52:15 11,264 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2008-07-27 07:19:43 27,136 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2008-08-14 07:52:15 27,136 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2008-07-27 07:19:43 4,096 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2008-08-14 07:52:15 4,096 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    - 2008-07-27 07:19:43 794,624 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2008-08-14 07:52:15 794,624 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2008-07-27 07:19:43 249,856 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2008-08-14 07:52:14 249,856 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2008-07-27 07:19:43 23,040 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2008-08-14 07:52:15 23,040 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2008-07-27 07:19:43 286,720 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2008-08-14 07:52:14 286,720 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2008-07-27 07:19:43 409,600 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-08-14 07:52:14 409,600 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    - 2008-07-13 23:02:40 10,134 ----a-r C:\WINDOWS\Installer\{9616B735-928A-441E-B9A1-C95E1E1C8925}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:40 10,134 ----a-r C:\WINDOWS\Installer\{9616B735-928A-441E-B9A1-C95E1E1C8925}\ARPPRODUCTICON.exe
    - 2008-07-13 22:59:02 10,134 ----a-r C:\WINDOWS\Installer\{965912F1-ED70-4299-A506-88AAB9D4E92C}\ARPPRODUCTICON.exe
    + 2008-08-08 04:06:42 10,134 ----a-r C:\WINDOWS\Installer\{965912F1-ED70-4299-A506-88AAB9D4E92C}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:31 10,134 ----a-r C:\WINDOWS\Installer\{A593A0F9-376D-43E1-BDAF-2088396E654E}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:32 10,134 ----a-r C:\WINDOWS\Installer\{A593A0F9-376D-43E1-BDAF-208
    0
  7. Kimboo Messages postés 49 Statut Membre
     
    ComboFix 08-08-29.02 - HP_Propriétaire 2008-08-29 18:41:36.3 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.201 [GMT -4:00]
    Endroit: C:\Documents and Settings\HP_Propriétaire\Bureau\ComboFix.exe
    * Création d'un nouveau point de restauration
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\RECYCLER\RB3.tmp

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-07-28 to 2008-08-29 ))))))))))))))))))))))))))))))))))))
    .

    2008-08-13 23:39 . 2008-08-28 23:44 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\uTorrent
    2008-08-13 22:33 . 2008-08-13 23:38 <REP> d-------- C:\Program Files\eMule
    2008-08-13 22:20 . 2008-05-01 10:36 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
    2008-08-13 22:16 . 2008-04-11 15:05 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
    2008-08-10 17:40 . 2008-08-10 17:41 <REP> d-------- C:\Program Files\LimeWire
    2008-08-10 17:40 . 2008-08-10 17:40 <REP> d-------- C:\Program Files\Google
    2008-08-08 00:08 . 2008-08-08 00:08 <REP> d-------- C:\Program Files\Personal Vault
    2008-08-08 00:07 . 2008-01-09 10:35 55,296 --a------ C:\WINDOWS\system32\drivers\rp_skt32.sys
    2008-08-08 00:07 . 2007-04-19 11:36 48,384 --a------ C:\WINDOWS\system32\drivers\rp_pkt32.sys
    2008-08-08 00:06 . 2008-08-08 00:06 <REP> d-------- C:\Program Files\Raxco
    2008-08-08 00:06 . 2008-08-08 00:26 <REP> d-------- C:\Program Files\Fichiers communs\Scanner
    2008-08-08 00:06 . 2008-08-08 00:06 <REP> d-------- C:\Program Files\Fichiers communs\Authentium
    2008-08-08 00:06 . 2008-08-08 00:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Raxco
    2008-08-08 00:01 . 2008-08-08 00:05 <REP> d-------- C:\Program Files\Bell
    2008-08-07 21:11 . 2008-08-07 21:15 <REP> d-------- C:\WINDOWS\SxsCaPendDel
    2008-08-07 20:43 . 2008-08-07 20:53 121 --a------ C:\WINDOWS\bdagent.INI
    2008-08-07 19:02 . 2008-08-07 21:08 81,984 --a------ C:\WINDOWS\system32\bdod.bin
    2008-08-07 18:43 . 2008-08-07 18:46 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
    2008-08-07 18:27 . 2004-11-04 23:36 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
    2008-08-07 18:27 . 2004-11-04 15:37 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
    2008-08-07 18:27 . 2004-11-04 15:37 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
    2008-08-07 18:27 . 2008-07-13 18:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
    2008-08-07 18:27 . 2008-07-13 18:54 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
    2008-08-07 18:27 . 2008-07-13 18:54 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
    2008-08-07 18:27 . 2008-07-13 18:54 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
    2008-08-07 18:27 . 2004-11-04 23:52 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
    2008-08-07 18:27 . 2004-11-05 15:54 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
    2008-08-07 18:27 . 2004-11-05 00:22 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
    2008-08-07 18:27 . 2004-11-04 23:36 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
    2008-08-07 18:27 . 2008-08-07 18:27 <REP> d-------- C:\Documents and Settings\Administrateur
    2008-08-07 15:13 . 2008-06-23 12:28 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
    2008-08-07 15:13 . 2007-04-17 05:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
    2008-08-07 15:13 . 2007-03-08 01:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
    2008-08-07 15:13 . 2008-06-23 12:28 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
    2008-08-07 15:13 . 2008-06-23 12:28 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
    2008-08-07 15:13 . 2008-06-23 12:28 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
    2008-08-07 15:13 . 2008-06-23 12:28 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
    2008-08-07 15:13 . 2008-06-23 12:28 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    2008-08-07 15:13 . 2008-06-23 05:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
    2008-08-06 21:42 . 2008-06-14 13:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-08-06 21:12 . 2008-08-06 21:12 <REP> d-------- C:\WINDOWS\system32\bits
    2008-08-06 21:12 . 2008-08-06 21:12 <REP> d-------- C:\WINDOWS\l2schemas
    2008-08-06 18:34 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
    2008-08-05 17:55 . 2008-08-25 21:17 <REP> d-------- C:\WINDOWS\system32\Adobe
    2008-08-04 02:56 . 2008-08-04 02:56 <REP> d-------- C:\Program Files\iPod
    2008-08-04 02:55 . 2008-08-04 03:01 <REP> d-------- C:\Program Files\iTunes
    2008-08-04 02:44 . 2008-08-04 02:44 <REP> d-------- C:\Program Files\Bonjour
    2008-08-04 02:01 . 2008-08-04 02:02 <REP> d-------- C:\Program Files\Safari
    2008-08-01 13:14 . 2008-08-01 13:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2008-07-31 20:26 . 2008-07-31 20:26 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Grisoft
    2008-07-31 20:25 . 2008-07-31 20:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-07-31 20:25 . 2007-05-30 08:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2008-07-31 20:16 . 2008-07-31 20:16 <REP> d-------- C:\Program Files\Yahoo!
    2008-07-31 20:16 . 2008-07-31 20:21 <REP> d-------- C:\Program Files\CCleaner
    2008-07-31 19:15 . 2008-07-31 19:15 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
    2008-07-31 18:16 . 2008-07-31 18:16 <REP> d-------- C:\Program Files\Trend Micro
    2008-07-31 17:17 . 2008-08-18 21:06 <REP> d-------- C:\VundoFix Backups

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-29 19:41 --------- d-----w C:\Program Files\Easy Internet signup
    2008-08-29 06:03 --------- d-----w C:\Program Files\PowerArchiver
    2008-08-29 02:52 958 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\wklnhst.dat
    2008-08-29 02:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-08-27 15:29 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Free Download Manager
    2008-08-27 15:17 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\LimeWire
    2008-08-08 06:07 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Bell
    2008-08-08 04:06 --------- d-----w C:\Program Files\CA
    2008-08-08 04:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bell
    2008-08-08 04:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-08-06 22:08 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
    2008-07-31 20:46 --------- d-----w C:\Program Files\Windows Live
    2008-07-31 20:42 --------- d-----w C:\Program Files\Windows Live Toolbar
    2008-07-31 17:36 141,612 ----a-w C:\WINDOWS\system32\drivers\dump_wmimmc.sys
    2008-07-28 22:07 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
    2008-07-28 08:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
    2008-07-28 08:01 --------- d-----w C:\Program Files\Elaborate Bytes
    2008-07-27 07:16 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-07-26 18:53 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Ventrilo
    2008-07-26 18:52 --------- d-----w C:\Program Files\Ventrilo
    2008-07-26 18:51 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-07-25 19:51 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\smc
    2008-07-25 19:30 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Uniblue
    2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
    2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
    2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
    2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
    2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
    2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
    2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
    2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
    2008-07-15 14:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    2008-07-14 22:09 65,536 ----a-w C:\WINDOWS\IFinst27.exe
    2008-07-14 22:09 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\LuckyTender
    2008-07-14 07:41 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Media Player Classic
    2008-07-14 04:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\ConeXware
    2008-07-14 04:33 --------- d-----w C:\Program Files\DAEMON Tools Lite
    2008-07-14 04:15 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\teamspeak2
    2008-07-14 04:14 --------- d-----w C:\Program Files\Teamspeak2_RC2
    2008-07-14 03:59 --------- d-----w C:\Program Files\mIRC
    2008-07-14 03:59 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\mIRC
    2008-07-14 03:37 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
    2008-07-14 03:37 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\DAEMON Tools
    2008-07-14 03:36 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-07-14 03:23 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Canneverbe_Limited
    2008-07-14 03:22 --------- d-----w C:\Program Files\CDBurnerXP
    2008-07-14 03:20 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\skypePM
    2008-07-14 03:08 --------- d-----w C:\Program Files\K-Lite Codec Pack
    2008-07-14 03:06 --------- d-----w C:\Program Files\Reference Assemblies
    2008-07-14 03:06 --------- d-----w C:\Program Files\MSBuild
    2008-07-14 03:04 --------- d-----w C:\Program Files\Free Download Manager
    2008-07-14 03:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
    2008-07-14 02:58 --------- d-----w C:\Program Files\WinISO
    2008-07-14 02:55 --------- d-----w C:\Program Files\Skype
    2008-07-14 02:55 --------- d-----w C:\Program Files\Fichiers communs\Skype
    2008-07-14 02:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
    2008-07-14 02:30 --------- d-----w C:\Program Files\Windows Live Messenger Khalid Edition v5.1
    2008-07-14 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-07-14 00:57 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-07-14 00:44 --------- d-----w C:\Program Files\uTorrent
    2008-07-13 23:38 --------- d-----w C:\Program Files\QuickTime
    2008-07-13 23:10 1,897 --sha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_PS512AA-ABA a815n_YC_0Pavi_QMXF505_E51FCheBLT2_47_IGoldfish2_SASUSTeK Computer INC._V1.xx_B3.10_T041112_WXH2_L40C_M504_J160_7Intel_8Pentium 4_93.06_#080713_N10EC8139_Z11C1048C_G80862582.MRK
    2008-07-13 23:07 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
    2008-07-13 22:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-07-13 22:19 --------- d-----w C:\Program Files\Java
    2008-07-13 22:15 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Template
    2008-07-13 22:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
    2008-07-13 22:11 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Apple Computer
    2008-07-13 17:33 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Notepad++
    2008-07-13 16:19 --------- d-----w C:\Program Files\Notepad++
    2008-07-13 09:31 --------- d-----w C:\Program Files\muvee Technologies
    2008-07-13 09:31 --------- d-----w C:\Program Files\InterVideo
    2008-07-13 09:31 --------- d-----w C:\Program Files\Fichiers communs\muvee Technologies
    2008-07-13 09:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
    2008-07-13 08:03 90,112 ----a-w C:\WINDOWS\DUMP2693.tmp
    2008-07-13 07:01 90,112 ----a-w C:\WINDOWS\DUMP2589.tmp
    2008-07-13 05:02 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\AdobeUM
    2008-07-13 05:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
    2008-07-13 05:01 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Sonic
    2008-07-13 05:01 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Leadertech
    2008-07-13 04:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\muvee Technologies
    2008-07-13 04:56 90,112 ----a-w C:\WINDOWS\DUMP2e43.tmp
    2008-07-13 04:39 --------- d-----w C:\Program Files\Apple Software Update
    2008-07-13 04:38 --------- d-----w C:\Program Files\Fichiers communs\Apple
    2008-07-13 04:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
    2008-07-13 04:32 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\MSNInstaller
    2008-07-13 03:54 90,112 ----a-w C:\WINDOWS\DUMP2625.tmp
    2008-07-13 03:44 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\InstallShield
    2008-07-13 03:36 --------- d-----w C:\Program Files\Profile
    2008-07-10 13:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
    2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
    2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
    2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-07-31_19.55.16.84 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-07-07 20:24:11 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll
    + 2007-11-30 12:39:29 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spmsg.dll
    + 2007-11-30 12:39:29 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spuninst.exe
    + 2007-11-30 12:39:29 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\spcustom.dll
    + 2007-11-30 12:39:26 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\update.exe
    + 2007-11-30 12:39:29 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\updspapi.dll
    + 2008-07-11 12:51:51 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
    + 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spmsg.dll
    + 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spuninst.exe
    + 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\spcustom.dll
    + 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
    + 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\updspapi.dll
    + 2008-06-24 16:53:52 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3QFE\mscms.dll
    + 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spmsg.dll
    + 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spuninst.exe
    + 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\spcustom.dll
    + 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\update.exe
    + 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\updspapi.dll
    + 2008-04-14 02:33:18 39,424 ------w C:\WINDOWS\AppPatch\acadproc.dll
    - 2004-08-19 20:09:20 1,852,416 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
    + 2008-04-14 02:33:18 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
    - 2004-08-19 20:09:20 450,048 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
    + 2008-04-14 02:33:18 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
    - 2004-08-19 20:09:20 137,728 ----a-w C:\WINDOWS\AppPatch\aclua.dll
    + 2008-04-14 02:33:18 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
    - 2004-08-19 20:09:20 244,736 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
    + 2008-04-14 02:33:18 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
    - 2004-08-19 20:09:20 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
    + 2008-04-14 02:33:18 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
    - 2004-11-05 03:31:21 1,100,392 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
    + 2008-08-08 07:34:02 1,103,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
    - 2004-11-05 03:31:22 141,928 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    + 2008-08-08 07:34:03 144,784 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
    - 2004-11-05 03:31:22 408,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
    + 2008-08-08 07:34:23 411,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
    - 2004-11-05 03:31:22 35,448 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
    + 2008-08-08 07:34:17 38,304 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
    - 2004-11-05 03:31:22 461,416 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Owc11\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Owc11.dll
    + 2008-08-08 07:33:45 464,272 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Owc11\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Owc11.dll
    - 2004-11-05 03:31:22 223,856 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    + 2008-08-08 07:34:28 226,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
    - 2004-11-05 03:31:22 20,080 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
    + 2008-08-08 07:33:51 22,928 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
    - 2004-11-05 03:31:22 662,120 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    + 2008-08-08 07:34:48 664,968 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
    - 2004-11-05 03:31:22 371,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
    + 2008-08-08 07:33:50 374,152 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
    - 2004-11-05 03:31:22 64,088 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    + 2008-08-08 07:31:10 66,936 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
    - 2004-11-05 03:31:22 223,800 ----a-w C:\WINDOWS\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
    + 2008-08-08 07:31:03 226,656 ----a-w C:\WINDOWS\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
    + 2008-08-08 07:14:52 226,656 ----a-w C:\WINDOWS\assembly\tmp\[u]0/uV28FLRX\OFFICE.DLL
    + 2008-08-08 07:15:05 66,936 ----a-w C:\WINDOWS\assembly\tmp\JTZ5BIOU\Microsoft.Vbe.Interop.dll
    + 2008-03-24 23:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
    - 2008-06-14 17:59:52 272,768 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
    + 2008-06-14 17:33:37 272,768 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
    - 2004-08-19 20:09:54 1,036,288 ----a-w C:\WINDOWS\explorer.exe
    + 2008-04-14 02:34:03 1,037,824 ----a-w C:\WINDOWS\explorer.exe
    - 2004-08-19 20:09:44 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
    + 2008-04-14 02:33:41 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
    - 2004-08-19 20:09:46 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
    + 2008-04-14 02:33:46 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
    - 2004-08-19 20:09:48 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
    + 2008-04-14 02:33:46 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
    - 2004-08-19 20:09:56 10,752 ----a-w C:\WINDOWS\hh.exe
    + 2008-04-14 02:34:06 10,752 ----a-w C:\WINDOWS\hh.exe
    + 2004-08-19 20:09:20 61,440 -c----w C:\WINDOWS\ie7\admparse.dll
    + 2004-08-19 20:09:20 101,888 -c----w C:\WINDOWS\ie7\advpack.dll
    + 2004-08-19 20:09:22 35,328 -c----w C:\WINDOWS\ie7\corpol.dll
    + 2006-06-02 19:32:20 33,792 -c----w C:\WINDOWS\ie7\custsat.dll
    + 2008-04-21 07:02:28 357,888 -c----w C:\WINDOWS\ie7\dxtmsft.dll
    + 2008-04-21 07:02:28 205,312 -c----w C:\WINDOWS\ie7\dxtrans.dll
    + 2008-04-21 07:02:28 55,808 -c----w C:\WINDOWS\ie7\extmgr.dll
    + 2004-08-19 20:09:28 38,912 -c----w C:\WINDOWS\ie7\hmmapi.dll
    + 2004-08-19 20:09:56 34,304 -c----w C:\WINDOWS\ie7\ie4uinit.exe
    + 2004-08-19 20:09:28 139,264 -c----w C:\WINDOWS\ie7\ieakeng.dll
    + 2004-08-19 20:09:28 221,696 -c----w C:\WINDOWS\ie7\ieaksie.dll
    + 2004-08-04 04:00:00 245,760 -c----w C:\WINDOWS\ie7\ieakui.dll
    + 2004-08-19 20:09:28 323,584 -c----w C:\WINDOWS\ie7\iedkcs32.dll
    + 2008-04-17 10:52:54 18,432 -c----w C:\WINDOWS\ie7\iedw.exe
    + 2004-08-19 20:09:28 81,920 -c----w C:\WINDOWS\ie7\ieencode.dll
    + 2008-04-21 07:02:29 251,392 -c----w C:\WINDOWS\ie7\iepeers.dll
    + 2004-08-19 20:09:28 49,152 -c----w C:\WINDOWS\ie7\iernonce.dll
    + 2004-08-19 20:09:28 63,488 -c----w C:\WINDOWS\ie7\iesetup.dll
    + 2004-08-19 20:09:56 93,184 -c----w C:\WINDOWS\ie7\iexplore.exe
    + 2004-08-19 20:09:30 35,840 -c----w C:\WINDOWS\ie7\imgutil.dll
    + 2008-04-21 07:02:29 96,768 -c----w C:\WINDOWS\ie7\inseng.dll
    + 2004-08-19 20:09:32 450,560 -c----w C:\WINDOWS\ie7\jscript.dll
    + 2008-04-21 07:02:29 16,384 -c----w C:\WINDOWS\ie7\jsproxy.dll
    + 2004-08-19 20:09:32 22,528 -c----w C:\WINDOWS\ie7\licmgr10.dll
    + 2004-08-19 20:10:00 29,184 -c----w C:\WINDOWS\ie7\mshta.exe
    + 2008-04-21 07:02:34 3,080,704 -c----w C:\WINDOWS\ie7\mshtml.dll
    + 2008-04-21 07:02:34 449,024 -c----w C:\WINDOWS\ie7\mshtmled.dll
    + 2004-08-19 20:08:28 57,344 -c----w C:\WINDOWS\ie7\mshtmler.dll
    + 2004-08-04 04:00:00 146,432 -c----w C:\WINDOWS\ie7\msls31.dll
    + 2008-04-21 07:02:34 146,432 -c----w C:\WINDOWS\ie7\msrating.dll
    + 2008-04-21 07:02:35 532,480 -c----w C:\WINDOWS\ie7\mstime.dll
    + 2004-08-19 20:09:38 97,280 -c----w C:\WINDOWS\ie7\occache.dll
    + 2008-04-21 07:02:35 39,424 -c----w C:\WINDOWS\ie7\pngfilt.dll
    + 2007-09-26 22:34:42 33,472 -c----w C:\WINDOWS\ie7\spuninst\iecustom.dll
    + 2007-09-26 22:32:30 66,048 -c--a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
    + 2006-09-06 21:43:28 216,800 -c----w C:\WINDOWS\ie7\spuninst\spuninst.exe
    + 2006-09-06 21:43:30 394,976 -c----w C:\WINDOWS\ie7\spuninst\updspapi.dll
    + 2004-08-19 20:09:48 37,888 -c----w C:\WINDOWS\ie7\url.dll
    + 2008-04-21 07:02:39 617,984 -c----w C:\WINDOWS\ie7\urlmon.dll
    + 2004-08-19 20:09:48 417,792 -c----w C:\WINDOWS\ie7\vbscript.dll
    + 2004-08-19 20:09:48 848,384 -c----w C:\WINDOWS\ie7\vgx.dll
    + 2004-08-19 20:09:48 281,600 -c----w C:\WINDOWS\ie7\webcheck.dll
    + 2008-04-21 07:02:40 663,552 -c----w C:\WINDOWS\ie7\wininet.dll
    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:35:47 394,976 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
    + 2007-08-13 22:54:10 765,952 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\vgx.dll
    + 2007-08-13 22:39:00 123,904 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
    + 2007-08-13 22:35:46 346,624 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
    + 2007-08-13 22:35:38 214,528 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
    + 2007-08-13 22:54:10 131,584 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
    + 2007-08-13 22:36:26 61,952 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\icardie.dll
    + 2007-08-13 22:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
    + 2007-08-13 22:39:26 152,064 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
    + 2007-08-13 22:39:54 229,376 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
    + 2007-08-13 21:56:54 161,792 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
    + 2007-02-12 20:10:12 2,451,312 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dat
    + 2007-07-11 16:27:48 383,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dll
    + 2007-08-13 22:39:50 382,976 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
    + 2007-08-13 22:54:10 6,049,280 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieframe.dll
    + 2007-08-13 22:39:10 43,008 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
    + 2007-08-13 22:34:04 266,752 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iertutil.dll
    + 2007-08-13 22:39:10 13,312 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
    + 2007-08-13 22:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
    + 2007-08-13 22:54:10 27,136 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
    + 2007-08-13 22:54:10 458,752 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeeds.dll
    + 2007-08-13 22:54:10 50,688 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeedsbs.dll
    + 2007-08-13 22:54:12 3,578,368 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
    + 2007-08-13 22:54:10 475,648 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
    + 2007-08-13 22:44:26 192,000 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
    + 2007-08-13 22:54:10 670,720 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
    + 2007-08-13 22:44:06 101,376 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
    + 2007-08-13 22:36:12 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\updspapi.dll
    + 2007-08-13 22:44:30 105,984 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\url.dll
    + 2007-08-13 22:54:10 1,162,240 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
    + 2007-08-13 22:54:10 231,424 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
    + 2007-08-13 22:54:10 818,688 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
    + 2008-04-23 04:16:39 124,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
    + 2008-04-23 04:16:39 347,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
    + 2008-04-23 04:16:39 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
    + 2008-04-23 04:16:39 133,120 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
    + 2008-04-23 04:16:39 63,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll
    + 2008-04-22 07:41:08 70,656 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
    + 2008-04-23 04:16:39 153,088 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
    + 2008-04-23 04:16:39 230,400 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
    + 2008-04-20 05:07:51 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
    + 2008-04-23 04:16:39 383,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll
    + 2008-04-23 04:16:39 384,512 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
    + 2008-04-23 04:16:39 6,066,176 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll
    + 2008-04-23 04:16:39 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
    + 2008-04-23 04:16:39 267,776 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll
    + 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
    + 2008-04-22 07:41:30 625,664 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
    + 2008-04-23 04:16:40 27,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
    + 2008-04-23 04:16:40 459,264 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll
    + 2008-04-23 04:16:40 52,224 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll
    + 2008-04-24 02:16:42 3,591,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
    + 2008-04-23 04:16:40 478,208 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
    + 2008-04-23 04:16:40 193,024 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
    + 2008-04-23 04:16:40 671,232 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
    + 2008-04-23 04:16:40 102,912 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
    + 2008-04-23 04:16:40 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
    + 2007-03-06 01:34:38 216,800 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:35:48 394,976 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll
    + 2008-04-23 04:16:40 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll
    + 2008-04-23 04:16:40 1,159,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
    + 2008-04-23 04:16:40 233,472 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
    + 2008-04-23 04:16:40 826,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
    - 2004-08-19 20:09:34 220,160 ----a-w C:\WINDOWS\ime\mscandui.dll
    + 2008-04-14 02:33:30 220,160 ----a-w C:\WINDOWS\ime\mscandui.dll
    - 2004-08-19 20:09:44 130,048 ----a-w C:\WINDOWS\ime\softkbd.dll
    + 2008-04-14 02:33:41 130,048 ----a-w C:\WINDOWS\ime\softkbd.dll
    - 2004-08-19 20:08:56 62,976 ----a-w C:\WINDOWS\ime\spgrmr.dll
    + 2008-04-13 16:43:18 62,976 ----a-w C:\WINDOWS\ime\spgrmr.dll
    - 2004-08-19 20:09:44 272,384 ----a-w C:\WINDOWS\ime\sptip.dll
    + 2008-04-14 02:33:46 272,384 ----a-w C:\WINDOWS\ime\sptip.dll
    - 2004-08-19 20:10:04 208,896 ----a-w C:\WINDOWS\inf\unregmp2.exe
    + 2008-04-14 02:34:26 208,896 ----a-w C:\WINDOWS\inf\unregmp2.exe
    + 2003-07-15 18:43:20 87,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\ADDRPARS.DLL
    + 2003-07-15 18:57:34 38,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
    + 2003-07-15 18:53:06 94,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\AW.DLL
    + 2003-07-15 10:53:24 60,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\BLNMGR.DLL
    + 2003-07-15 10:53:22 46,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\BLNMGRPS.DLL
    + 2003-07-15 15:14:28 350,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL
    + 2003-07-15 23:18:12 47,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
    + 2003-07-26 14:57:20 75,832 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DLGSETP.DLL
    + 2003-07-15 18:56:54 14,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
    + 2003-07-15 18:57:14 98,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
    + 2003-08-01 11:19:52 131,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\ENVELOPE.DLL
    + 2003-08-13 22:34:38 10,073,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\EXCEL.EXE
    + 2003-07-15 18:41:44 13,368 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FINDER.EXE
    + 2003-08-04 06:56:16 1,146,184 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FM20.DLL
    + 2002-10-08 05:49:36 192,573 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FORM.DLL
    + 2003-07-15 19:36:14 186,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL
    + 2003-07-15 18:40:12 179,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPERSON.DLL
    + 2003-07-26 15:00:16 1,157,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPSRVUTL.DLL
    + 2003-07-26 15:14:50 799,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL
    + 2003-07-15 19:11:42 2,139,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\GRAPH.EXE
    + 2003-07-15 10:57:44 87,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL
    + 2003-07-15 18:53:50 161,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\IETAG.DLL
    + 2003-07-24 18:32:32 121,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\IMPMAIL.DLL
    + 2003-05-29 11:42:48 514,680 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\INTLNAME.DLL
    + 2003-06-19 13:31:44 758,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL
    + 2003-06-19 13:31:10 252,928 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
    + 2003-06-19 13:31:48 17,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL
    + 2003-06-19 13:31:48 18,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL
    + 2003-06-19 13:31:46 35,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL
    + 2003-06-19 13:31:34 443,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
    + 2003-05-29 11:42:50 342,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\METCONV.DLL
    + 2003-07-15 18:46:08 176,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MIMEDIR.DLL
    + 2003-07-15 19:01:44 445,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MODHELP.DLL
    + 2003-07-15 18:57:14 124,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSB1CORE.DLL
    + 2003-07-15 19:12:22 47,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSB1XTOR.DLL
    + 2003-07-15 10:58:04 230,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSCDM.DLL
    + 2002-12-18 15:08:50 359,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSDMENG.DLL
    + 2002-12-18 15:08:54 1,383,592 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSDMINE.DLL
    + 2003-07-15 18:56:14 40,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSE7.EXE
    + 2003-07-15 18:51:44 87,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
    + 2002-04-10 16:14:36 187,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSMDUN80.DLL
    + 2003-07-15 18:52:52 17,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
    + 2003-08-08 20:23:16 12,172,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSO.DLL
    + 2003-07-15 10:57:16 120,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
    + 2003-07-15 15:14:18 106,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL
    + 2003-07-24 10:35:26 127,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL
    + 2003-07-15 18:52:52 27,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
    + 2003-07-15 18:44:06 25,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOEURO.DLL
    + 2003-07-15 18:52:56 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
    + 2002-12-18 15:09:24 2,071,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOLAP80.DLL
    + 2003-07-15 18:56:16 54,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOMSE.DLL
    + 2003-07-11 22:15:48 1,292,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSONSEXT.DLL
    + 2003-07-15 23:18:52 376,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSORUN.DLL
    + 2003-07-15 10:52:54 28,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
    + 2003-07-15 18:52:52 35,896 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSV.DLL
    + 2003-07-15 18:53:00 55,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSVABW.DLL
    + 2003-07-15 18:53:20 39,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
    + 2003-07-15 18:46:16 42,040 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
    + 2003-07-15 18:45:12 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
    + 2003-07-15 18:45:12 39,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
    + 2003-06-19 13:31:24 1,033,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL
    + 2003-06-19 13:31:54 788,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPFILT.DLL
    + 2003-06-19 13:31:50 16,384 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
    + 2003-06-20 12:05:52 128,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPSCAN.EXE
    + 2003-06-20 12:05:50 364,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
    + 2003-07-15 19:02:42 637,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSQRY32.EXE
    + 2003-07-15 18:52:58 41,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
    + 2003-07-15 19:02:14 627,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE
    + 2003-07-15 18:56:24 124,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE
    + 2003-07-24 18:40:00 482,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL
    + 2003-07-15 19:00:54 145,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
    + 2003-07-15 18:57:10 56,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\NAME.DLL
    + 2003-07-15 18:56:52 13,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
    + 2003-06-19 13:31:58 6,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OCRPS.DLL
    + 2004-11-05 03:31:22 223,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OFFICE.DLL
    + 2003-07-15 23:14:26 283,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OIS.EXE
    + 2003-07-15 23:14:26 828,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL
    + 2003-07-15 23:14:26 27,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
    + 2003-07-15 23:14:26 242,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
    + 2003-07-15 19:05:24 1,054,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
    + 2003-07-15 10:53:08 95,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OSA.EXE
    + 2003-07-15 18:41:56 24,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLACCT.DLL
    + 2003-07-15 18:44:34 102,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLCTL.DLL
    + 2003-08-10 19:06:42 7,522,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLLIB.DLL
    + 2003-07-15 18:44:32 88,128 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
    + 2003-07-15 18:45:18 196,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLOOK.EXE
    + 2003-07-15 18:43:48 139,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLPH.DLL
    + 2003-07-15 18:43:18 64,056 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
    + 2003-07-15 18:43:16 49,208 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
    + 2003-08-02 11:09:04 8,086,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\OWC11.DLL
    + 2003-07-31 08:40:40 6,133,312 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\POWERPNT.EXE
    + 2003-07-15 23:18:54 430,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL
    + 2003-07-15 23:18:44 93,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
    + 2003-08-01 11:21:08 1,782,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PPTVIEW.EXE
    + 2002-10-08 06:11:00 167,997 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\PSOM.DLL
    + 2003-07-15 18:42:26 37,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
    + 2003-05-09 17:54:00 77,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
    + 2003-07-15 18:57:08 40,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
    + 2002-10-08 05:49:42 81,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\REVERSE.DLL
    + 2003-07-15 18:43:30 74,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\RM.DLL
    + 2003-07-22 07:46:38 390,712 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\RTFHTML.DLL
    + 2003-07-15 18:57:18 349,248 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SELFCERT.EXE
    + 2003-07-15 18:44:16 66,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
    + 2003-07-15 10:57:08 58,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
    + 2003-08-07 09:31:22 362,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SETLANG.EXE
    + 2003-07-15 18:53:14 11,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
    + 2003-08-04 06:52:32 2,808,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL
    + 2002-10-08 05:53:04 106,561 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\THOCRAPI.DLL
    + 2003-07-15 19:00:22 99,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
    + 2002-10-08 05:50:44 241,729 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWCUTCHR.DLL
    + 2002-10-08 05:51:04 180,289 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWCUTLIN.DLL
    + 2002-10-08 05:51:14 147,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWLAY32.DLL
    + 2002-10-08 05:51:20 102,467 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWORIENT.DLL
    + 2002-10-08 05:50:04 118,847 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWRECE.DLL
    + 2002-10-08 05:49:56 81,983 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWRECS.DLL
    + 2002-10-08 05:51:44 221,252 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\TWSTRUCT.DLL
    + 2003-07-15 18:57:40 59,960 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\UNBIND.EXE
    + 2003-07-04 11:19:36 2,502,656 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\VBE6.DLL
    + 2004-11-05 03:31:22 64,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
    + 2003-08-07 09:24:20 12,037,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\WINWORD.EXE
    + 2002-10-08 06:03:34 1,794,113 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\XIMAGE3B.DLL
    + 2003-05-01 07:52:32 1,581,120 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\XPAGE3C.DLL
    + 2003-01-18 10:03:34 59,466 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.5614\XSCAN32.DAT
    + 2007-03-22 23:07:56 91,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
    + 2007-04-19 18:10:18 45,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\AUTHZAX.DLL
    + 2007-03-22 23:29:56 99,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\AW.DLL
    + 2007-04-19 18:07:38 66,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\BLNMGR.DLL
    + 2007-04-19 18:07:34 52,064 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\BLNMGRPS.DLL
    + 2007-03-22 23:06:08 355,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\CDLMSO.DLL
    + 2007-04-19 17:55:16 53,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DFUICOM.EXE
    + 2007-03-22 23:07:54 80,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DLGSETP.DLL
    + 2007-03-22 23:23:32 19,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DSITF.DLL
    + 2007-05-10 17:44:02 121,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DSSM.EXE
    + 2007-03-22 23:29:28 43,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DWDCW20.DLL
    + 2007-03-22 23:29:28 39,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\DWTRIG20.EXE
    + 2001-06-06 04:13:22 289,926 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ENGDIC.DAT
    + 2001-06-06 04:13:22 34,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ENGIDX.DAT
    + 2007-04-19 17:53:52 137,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\ENVELOPE.DLL
    + 2007-05-31 17:41:06 10,352,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\EXCEL.EXE
    + 2007-06-06 14:53:34 1,195,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\FM20.DLL
    + 2007-04-19 17:57:32 2,152,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\GRAPH.EXE
    + 2007-04-19 18:09:30 167,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\IETAG.DLL
    + 2007-04-19 17:53:52 127,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\IMPMAIL.DLL
    + 2001-06-06 04:13:24 18,844 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\JFONT.DAT
    + 2001-06-06 04:13:26 65,536 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\LOOKUP.DAT
    + 2007-04-19 17:54:04 183,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MIMEDIR.DLL
    + 2007-04-19 18:01:52 238,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSCDM.DLL
    + 2005-05-04 04:06:28 465,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSDMENG.DLL
    + 2005-05-04 04:06:32 1,411,816 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSDMINE.DLL
    + 2005-05-04 04:06:26 199,408 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSMDUN80.DLL
    + 2007-06-18 21:16:32 12,259,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSO.DLL
    + 2007-04-19 18:10:34 127,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOAUTH.DLL
    + 2007-04-19 17:56:58 29,024 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOEURO.DLL
    + 2007-04-19 18:07:38 61,280 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOHTMED.EXE
    + 2007-05-02 17:45:26 2,123,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOLAP80.DLL
    + 2007-04-19 17:49:28 383,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSORUN.DLL
    + 2007-04-19 18:07:24 36,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\MSOSTYLE.DLL
    + 2001-10-23 20:13:42 53,260 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OCRHC.DAT
    + 2001-06-06 04:13:26 40,972 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OCRVC.DAT
    + 2007-05-31 17:43:46 7,613,280 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLLIB.DLL
    + 2007-04-19 17:53:44 106,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLMIME.DLL
    + 2007-05-31 17:42:14 200,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLOOK.EXE
    + 2007-04-19 17:53:56 149,856 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLPH.DLL
    + 2007-04-19 17:53:24 69,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OUTLRPC.DLL
    + 2007-05-10 17:45:34 8,069,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\OWC11.DLL
    + 2007-05-31 17:35:22 6,420,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
    + 2007-03-22 23:07:10 41,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
    + 2007-06-06 16:07:40 100,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\REFEDIT.DLL
    + 2007-03-22 23:07:54 78,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\RM.DLL
    + 2007-04-19 18:10:20 65,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\SEQCHK10.DLL
    + 2007-03-22 23:29:16 14,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\SMARTTAGINSTALL.EXE
    + 2007-05-10 17:42:52 2,839,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\STSLIST.DLL
    + 2007-03-22 23:22:02 103,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\TRANSMGR.DLL
    + 2007-05-09 21:19:48 2,585,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\VBE6.DLL
    + 2007-05-31 17:37:40 12,310,368 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\C040211900063D11C8EF10054038389C\11.0.8173\WINWORD.EXE
    - 2008-07-13 23:02:37 10,134 ----a-r C:\WINDOWS\Installer\{03D5D136-7031-4F84-9DFC-8D2B4B3FB49E}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:37 10,134 ----a-r C:\WINDOWS\Installer\{03D5D136-7031-4F84-9DFC-8D2B4B3FB49E}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:10 10,134 ----a-r C:\WINDOWS\Installer\{0B831FD2-7291-4291-9510-6AA39E3A45AC}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:10 10,134 ----a-r C:\WINDOWS\Installer\{0B831FD2-7291-4291-9510-6AA39E3A45AC}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:17 10,134 ----a-r C:\WINDOWS\Installer\{17B03967-126B-478A-88ED-BF699690E528}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:22 10,134 ----a-r C:\WINDOWS\Installer\{17B03967-126B-478A-88ED-BF699690E528}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:23 10,134 ----a-r C:\WINDOWS\Installer\{19C68497-1E4A-4285-8CCF-435872CD3436}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:27 10,134 ----a-r C:\WINDOWS\Installer\{19C68497-1E4A-4285-8CCF-435872CD3436}\ARPPRODUCTICON.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ARPPRODUCTICON.exe
    + 2008-08-10 21:41:25 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ARPPRODUCTICON.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
    - 2008-07-14 02:33:28 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
    + 2008-08-10 21:41:26 26,694 ----a-r C:\WINDOWS\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
    - 2008-07-13 22:58:31 26,582 ----a-r C:\WINDOWS\Installer\{212F5777-1190-4DEF-8E4D-6B2F313B45E7}\PerfectDisk.exe
    + 2008-08-08 04:06:25 26,582 ----a-r C:\WINDOWS\Installer\{212F5777-1190-4DEF-8E4D-6B2F313B45E7}\PerfectDisk.exe
    + 2008-08-04 07:04:30 102,400 ----a-r C:\WINDOWS\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
    + 2008-08-04 06:44:49 86,016 ----a-r C:\WINDOWS\Installer\{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}\PrntWzrdIco.exe
    - 2008-07-13 22:58:05 10,134 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\ARPPRODUCTICON.exe
    + 2008-08-08 04:05:56 10,134 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\ARPPRODUCTICON.exe
    - 2008-07-13 22:58:05 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Desktop_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    + 2008-08-08 04:05:56 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Desktop_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    - 2008-07-13 22:58:05 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Sm_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    + 2008-08-08 04:05:56 25,214 ----a-r C:\WINDOWS\Installer\{4B1AF076-1233-44C6-9A3C-2E14F843BF24}\Sm_Fr_Rps_A64EE928C7A645A784CE59FBDBDD9D1B.exe
    - 2008-07-13 23:02:14 10,134 ----a-r C:\WINDOWS\Installer\{4DE542B7-B384-453E-BB5B-60A5DAD98903}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:19 10,134 ----a-r C:\WINDOWS\Installer\{4DE542B7-B384-453E-BB5B-60A5DAD98903}\ARPPRODUCTICON.exe
    - 2008-07-13 22:58:36 10,134 ----a-r C:\WINDOWS\Installer\{741CDDCC-F4F0-4CCC-9F47-25DB8FF66BFD}\ARPPRODUCTICON.exe
    + 2008-08-08 04:06:30 10,134 ----a-r C:\WINDOWS\Installer\{741CDDCC-F4F0-4CCC-9F47-25DB8FF66BFD}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:20 10,134 ----a-r C:\WINDOWS\Installer\{86F040E3-2285-4DDC-B082-7A75DB9BA7DF}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:25 10,134 ----a-r C:\WINDOWS\Installer\{86F040E3-2285-4DDC-B082-7A75DB9BA7DF}\ARPPRODUCTICON.exe
    - 2008-07-27 07:19:43 12,288 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    + 2008-08-14 07:52:15 12,288 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2008-07-27 07:19:43 135,168 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    + 2008-08-14 07:52:14 135,168 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2008-07-27 07:19:43 11,264 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    + 2008-08-14 07:52:15 11,264 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2008-07-27 07:19:43 27,136 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2008-08-14 07:52:15 27,136 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2008-07-27 07:19:43 4,096 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2008-08-14 07:52:15 4,096 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    - 2008-07-27 07:19:43 794,624 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2008-08-14 07:52:15 794,624 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2008-07-27 07:19:43 249,856 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2008-08-14 07:52:14 249,856 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2008-07-27 07:19:43 23,040 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2008-08-14 07:52:15 23,040 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2008-07-27 07:19:43 286,720 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2008-08-14 07:52:14 286,720 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2008-07-27 07:19:43 409,600 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-08-14 07:52:14 409,600 ----a-r C:\WINDOWS\Installer\{9112040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    - 2008-07-13 23:02:40 10,134 ----a-r C:\WINDOWS\Installer\{9616B735-928A-441E-B9A1-C95E1E1C8925}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:40 10,134 ----a-r C:\WINDOWS\Installer\{9616B735-928A-441E-B9A1-C95E1E1C8925}\ARPPRODUCTICON.exe
    - 2008-07-13 22:59:02 10,134 ----a-r C:\WINDOWS\Installer\{965912F1-ED70-4299-A506-88AAB9D4E92C}\ARPPRODUCTICON.exe
    + 2008-08-08 04:06:42 10,134 ----a-r C:\WINDOWS\Installer\{965912F1-ED70-4299-A506-88AAB9D4E92C}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:31 10,134 ----a-r C:\WINDOWS\Installer\{A593A0F9-376D-43E1-BDAF-2088396E654E}\ARPPRODUCTICON.exe
    + 2008-08-08 04:08:32 10,134 ----a-r C:\WINDOWS\Installer\{A593A0F9-376D-43E1-BDAF-2088396E654E}\ARPPRODUCTICON.exe
    - 2008-07-13 23:02:27 10,134 ----a-r C:\W
    0
  8. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    Le rapport n'est pas complet.

    Peux-tu me l'envoyer sur destrio5@free.fr ?
    0
  9. Kimboo Messages postés 49 Statut Membre
     
    C'est fait j'attend de tes nouvelles :)
    0
  10. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    ---> Supprime le dossier C:\VundoFix Backups\

    ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la vider :
    http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme
    0
  11. Kimboo Messages postés 49 Statut Membre
     
    Ok le document est belle est bien supprimé de mon ordinateur voici mon rapport le plus récent

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:46:59, on 2008-08-30
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\HP\KBD\KBD.EXE
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\WINDOWS\ALCWZRD.EXE
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
    C:\Program Files\Bell\Gestionnaire de securite\Rps.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Fichiers communs\Authentium\AntiVirus\dvpapi.exe
    C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
    C:\Program Files\Personal Vault\VaultClientUpgrade.exe
    C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
    C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
    C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Gestionnaire de securite\pkR.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
    O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] "C:\Program Files\Bell\Gestionnaire de securite\Rps.exe"
    O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Gestionnaire de securite\IdxClnR.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Fichiers communs\Authentium\AntiVirus\dvpapi.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
    O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
    O23 - Service: Gestionnaire de sécurité Sympatico (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\RpsSecurityAware.exe
    O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
    O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
    O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe
    0
  12. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    ---> Fais un scan rapide avec MBAM, supprime tout ce qu'il trouve et poste le rapport :
    http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
    0
  13. Kimboo Messages postés 49 Statut Membre
     
    Désolé pour mon retard alors voici mon rapport MBAM:

    Malwarebytes' Anti-Malware 1.26
    Version de la base de données: 1126
    Windows 5.1.2600 Service Pack 3

    2008-09-07 19:42:55
    mbam-log-2008-09-07 (19-42-55).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 124333
    Temps écoulé: 1 hour(s), 20 minute(s), 5 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 6

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\QooBox\Quarantine\C\WINDOWS\system32\fjbgpfxf.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\jtpyis.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\opnNHaBU.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\qcsfsqbo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\tuvUOFuu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\xdydiegu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    0
  14. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    Ok, tu as toujours des problèmes ?
    0
  15. Kimboo Messages postés 49 Statut Membre
     
    Non aucun problème et le bruit c'est finalement arrêté :) toute fois il y a se message (http://img93.imageshack.us/img93/9588/errorwindowsoz7.jpg ) qui apparait de temps à autre mais rien de bien grave. Merci encore :D
    0
  16. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    ---> Installe Antivir, fais un scan complet, supprime tout ce qu'il trouve et poste le rapport :
    http://dl1.avgate.net/down/windows/antivir_workstation_winu_fr_h.exe
    0
  17. Kimboo Messages postés 49 Statut Membre
     
    Voila le rapport

    Avira AntiVir Personal
    Date de création du fichier de rapport : 2008-09-13 18:48

    La recherche porte sur 1612438 souches de virus.

    Détenteur de la licence :Avira AntiVir PersonalEdition Classic
    Numéro de série : 0000149996-ADJIE-0001
    Plateforme : Windows XP
    Version de Windows :(Service Pack 3) [5.1.2600]
    Mode Boot : Démarré normalement
    Identifiant : SYSTEM
    Nom de l'ordinateur :NOM-4335C342C2C

    Informations de version :
    BUILD.DAT : 8.1.0.47 16931 Bytes 2008-08-19 11:45:00
    AVSCAN.EXE : 8.1.4.7 315649 Bytes 2008-06-26 14:57:49
    AVSCAN.DLL : 8.1.4.1 49921 Bytes 2008-07-21 19:44:27
    LUKE.DLL : 8.1.4.5 164097 Bytes 2008-06-12 18:44:16
    LUKERES.DLL : 8.1.4.0 13057 Bytes 2008-07-04 13:30:27
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 16:33:34
    ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 2008-06-24 19:54:15
    ANTIVIR2.VDF : 7.0.6.153 3341312 Bytes 2008-09-12 01:05:16
    ANTIVIR3.VDF : 7.0.6.154 2048 Bytes 2008-09-12 01:05:16
    Version du moteur: 8.1.1.28
    AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-02-25 15:58:21
    AESCRIPT.DLL : 8.1.0.70 319866 Bytes 2008-09-09 01:05:51
    AESCN.DLL : 8.1.0.23 119156 Bytes 2008-07-10 18:44:49
    AERDL.DLL : 8.1.1.1 397683 Bytes 2008-09-09 01:05:50
    AEPACK.DLL : 8.1.2.1 364917 Bytes 2008-07-15 18:58:35
    AEOFFICE.DLL : 8.1.0.23 196987 Bytes 2008-09-09 01:05:48
    AEHEUR.DLL : 8.1.0.51 1397111 Bytes 2008-09-09 01:05:47
    AEHELP.DLL : 8.1.0.15 115063 Bytes 2008-07-10 18:44:48
    AEGEN.DLL : 8.1.0.36 315764 Bytes 2008-09-09 01:05:45
    AEEMU.DLL : 8.1.0.7 430452 Bytes 2008-07-31 14:33:21
    AECORE.DLL : 8.1.1.11 172406 Bytes 2008-09-09 01:05:44
    AEBB.DLL : 8.1.0.1 53617 Bytes 2008-07-10 18:44:48
    AVWINLL.DLL : 1.0.0.12 15105 Bytes 2008-07-09 14:40:02
    AVPREF.DLL : 8.0.2.0 38657 Bytes 2008-05-16 15:27:58
    AVREP.DLL : 8.0.0.2 98344 Bytes 2008-09-09 01:05:43
    AVREG.DLL : 8.0.0.1 33537 Bytes 2008-05-09 17:26:37
    AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 14:29:19
    AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 2008-06-12 18:27:46
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 23:28:02
    SMTPLIB.DLL : 1.2.0.23 28929 Bytes 2008-06-12 18:49:36
    NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 18:05:07
    RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 2008-07-04 13:23:16
    RCTEXT.DLL : 8.0.52.1 86273 Bytes 2008-07-17 16:08:43

    Configuration pour la recherche actuelle :
    Nom de la tâche..................: Contrôle intégral du système
    Fichier de configuration.........: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Documentation....................: bas
    Action principale................: interactif
    Action secondaire................: ignorer
    Recherche sur les secteurs d'amorçage maître: marche
    Recherche sur les secteurs d'amorçage: marche
    Secteurs d'amorçage..............: C:, D:,
    Recherche dans les programmes actifs: marche
    Recherche en cours sur l'enregistrement: marche
    Recherche de Rootkits............: arrêt
    Fichier mode de recherche........: Sélection de fichiers intelligente
    Recherche sur les archives.......: marche
    Limiter la profondeur de récursivité: 20
    Archive Smart Extensions.........: marche
    Heuristique de macrovirus........: marche
    Heuristique fichier..............: moyen

    Début de la recherche : 2008-09-13 18:48

    La recherche sur les processus démarrés commence :
    Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'distnoted.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'AppleMobileDeviceHelper.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'iTunes.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'firefox.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'dumprep.exe' - '0' module(s) sont contrôlés
    Processus de recherche 'dumprep.exe' - '0' module(s) sont contrôlés
    Processus de recherche 'usnsvc.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'msnmsgr.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'rpsupdaterR.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'PDEngine.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'iPodService.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'SSAComHandler.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'VaultClientUpgrade.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'PDAgent.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'NMSAccessU.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'MDM.EXE' - '1' module(s) sont contrôlés
    Processus de recherche 'ITMRTSVC.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'dvpapi.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'guard.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'AppleMobileDeviceService.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'Updates from HP.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'VeohClient.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'daemon.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'iTunesHelper.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'RPS.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'SSA.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'avgas.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'AGRSMMSG.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'ALCWZRD.EXE' - '1' module(s) sont contrôlés
    Processus de recherche 'hphmon06.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'hpsysdrv.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'kbd.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'Fws.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
    Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
    '52' processus ont été contrôlés avec '52' modules

    La recherche sur les secteurs d'amorçage maître commence :
    Secteur d'amorçage maître HD0
    [INFO] Aucun virus trouvé !
    Secteur d'amorçage maître HD1
    [INFO] Aucun virus trouvé !
    [AVERTISSEMENT] Erreur système [21]: Le périphérique n'est pas prêt.
    Secteur d'amorçage maître HD2
    [INFO] Aucun virus trouvé !
    [AVERTISSEMENT] Erreur système [21]: Le périphérique n'est pas prêt.
    Secteur d'amorçage maître HD3
    [INFO] Aucun virus trouvé !
    [AVERTISSEMENT] Erreur système [21]: Le périphérique n'est pas prêt.
    Secteur d'amorçage maître HD4
    [INFO] Aucun virus trouvé !
    [AVERTISSEMENT] Erreur système [21]: Le périphérique n'est pas prêt.

    La recherche sur les secteurs d'amorçage commence :
    Secteur d'amorçage 'C:\'
    [INFO] Aucun virus trouvé !
    Secteur d'amorçage 'D:\'
    [INFO] Aucun virus trouvé !

    La recherche sur les renvois aux fichiers exécutables (registre) commence.
    Le registre a été contrôlé ( '63' fichiers).

    La recherche sur les fichiers sélectionnés commence :

    Recherche débutant dans 'C:\' <Karim>
    C:\hiberfil.sys
    [AVERTISSEMENT] Impossible d'ouvrir le fichier !
    C:\pagefile.sys
    [AVERTISSEMENT] Impossible d'ouvrir le fichier !
    C:\hp\drivers\hpiz423\setup\CreativeProjects\CreativeProjects.cab
    [0] Type d'archive: CAB (Microsoft)
    --> card_bday7_4F_A4_FO.png.CAA9CF90_D0FB_41C4_B5F6_021539430C23
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    C:\hp\drivers\hpiz423\setup\DocProc\Data1.cab
    [0] Type d'archive: CAB (Microsoft)
    --> F8032_eng.ytr.518BAB6F_45CA_4000_AACD_DDDDF89E007E
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    C:\hp\drivers\hpiz423\setup\RedBox\Data1.cab
    [0] Type d'archive: CAB (Microsoft)
    --> hprbevdb.dll
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\AiOHelp\6200_help.cab
    [0] Type d'archive: CAB (Microsoft)
    --> aio17.dll6.9FAB98ED_2143_4534_9750_7CD4ECEB9596
    [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
    C:\WINDOWS\system32\drivers\sptd.sys
    [AVERTISSEMENT] Impossible d'ouvrir le fichier !
    Recherche débutant dans 'D:\' <HP_RECOVERY>

    Fin de la recherche : 2008-09-13 21:35
    Temps nécessaire: 2:46:32 Heure(s)

    La recherche a été effectuée intégralement

    7761 Les répertoires ont été contrôlés
    457612 Des fichiers ont été contrôlés
    0 Des virus ou programmes indésirables ont été trouvés
    0 Des fichiers ont été classés comme suspects
    0 Des fichiers ont été supprimés
    0 Des virus ou programmes indésirables ont été réparés
    0 Les fichiers ont été déplacés dans la quarantaine
    0 Les fichiers ont été renommés
    3 Impossible de contrôler des fichiers
    457609 Fichiers non infectés
    14913 Les archives ont été contrôlées
    11 Avertissements
    0 Consignes
    0
  18. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
     
    C'est depuis l'installation du SP3 ?
    0
  19. Kimboo Messages postés 49 Statut Membre
     
    Je n'avais jamais fait le lien mais oui c'est exactement depuis l'installation du SP3 O_O
    0
  • 1
  • 2