Infection pc

Résolu
Bonjour,
Je suis sous WIN XP SP3
Depuis un certain temps mon pc au demarrage m'affiche des messages d'erreur type c:win\syst32\KOZEZUPO.dll ou RIBEMAGO.dll et d'autres...
J'ai fais des analyses antivirus, plusieurs logiciels anti spyware trojan, comme spybot ad-aware, spyrware pc doctor.
Et rien ne change. Si quelqu'un pouvait me venir en aide!!!!!!!!
Voici un rapport Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:13:57, on 20/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Documents and Settings\yannick creusot\Bureau\PampersPregnancyWidget.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Pampers Pregnancy Widget.lnk = C:\Documents and Settings\yannick creusot\Bureau\PampersPregnancyWidget.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{52441C7C-E5B9-4D6F-A48A-236A4BC93B2D}: NameServer = 212.27.53.252,212.27.54.252
O20 - AppInit_DLLs: c:\windows\system32\vegozadi.dll,,c:\windows\system32\sujibiwi.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Google Update Service (gupdate1c9087ee8c5a21c) (gupdate1c9087ee8c5a21c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 6112 bytes

Merci et bon week end
Configuration: Windows XP
Firefox 3.0.11

57 réponses

Résumé de la discussion

Des messages d'erreur au démarrage évoquent des fichiers infestés (KOZEZUPO.dll, RIBEMAGO.dll) sur Windows XP SP3 et des entrées suspectes dans HijackThis, signalant une infection potentielle et un besoin d'assainissement. Plusieurs réponses préconisent l'élimination des outils suspects et l'utilisation d'outils dédiés comme ToolsCleaner et CCleaner, puis la remise à zéro des éléments résiduels avant une analyse plus poussée. En parallèle, des recommandations incluent des scans complémentaires avec ComboFix, SDFix et Malwarebytes pour identifier d'éventuels rootkits, et le rapport des analyses est demandé pour valider le nettoyage. Des éléments complémentaires mentionnent aussi l'examen des fichiers système devenus suspects et l'impact potentiel sur les paramètres réseau, ce qui peut nécessiter une réinitialisation des composants critiques du système.

Bobot (l’IA à votre service)
  1. Voici le rapport:

    [ Rapport ToolsCleaner version 2.3.7 (par A.Rothstein & dj QUIOU) ]

    --> Recherche:

    C:\Combofix.txt: trouvé !
    C:\Qoobox: trouvé !
    C:\Documents and Settings\yannick creusot\Bureau\ComboFix.exe: trouvé !

    ---------------------------------
    --> Suppression:

    C:\Documents and Settings\yannick creusot\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
    C:\Combofix.txt: supprimé !
    C:\Qoobox: supprimé !

    Corbeille vidée!
    Fichiers temporaires nettoyés !
    1. Ok,

      Bon on va supprimer les outils utilisés :

      •Télécharge ToolsCleaner par A.Rothstein & dj QUIOU sur ton Bureau.

      http://pc-system.fr/
      http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
      http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe

      •Clique sur Recherche et laisse le scan se terminer.

      •Clique, sur Suppression pour finaliser.

      •Tu peux, si tu le souhaites, te servir des Options facultatives.

      •Clique sur Quitter, pour que le rapport puisse se créer.

      •Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).

      Passe un coup de CCleaner.

      1. plus de message au démarrage. apparemment j'en suis débarrassé.

        En tout cas merci pour ton aide et pour le temps que tu as passé avec moi!!!

        @+
        1. voici le lien d'analyse de virus total:

          http://www.virustotal.com/fr/analisis/d8662f4386c90335e179a5761db98ddda19253bd0e69dfd343ba6452b5410c16-1245784682

          merci
          1. Rends toi ici : https://www.virustotal.com/gui/

            Clique sur parcourir et cherche ce fichier : c:\windows\system32\drivers\klick.dat

            Clique sur envoyer et poste moi le rapport.

            fait de meme pour ce fichier : c:\windows\system32\drivers\klin.dat

            PS : si tu as un message comme quoi le fichier a deja été analyser, re-analyse-le .

            Bizarre que Combofix ne veuille pas les supprimer, ce sont d'apres ce que j'ai pu trouver, des rootkits, mais je veux une confirmatation donc fait cette manip stp.

            1. Bonjour

              Voici le rapport:

              ComboFix 09-06-22.08 - yannick creusot 25/06/2009 13:40.6 - NTFSx86
              Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.641 [GMT 2:00]
              Lancé depuis: c:\documents and settings\yannick creusot\Bureau\Combofix.exe
              Commutateurs utilisés :: c:\documents and settings\yannick creusot\Bureau\CFScript.txt
              AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}

              FILE ::
              "c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\dowuvedo.dll"
              "c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\haditapo.dll"
              "c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\jevaziji.exe"
              "c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\kozafuli.dll"
              "c:\documents and settings\yannick creusot\Application Data\U3\temp\cleanup.exe"
              "c:\windows\system32\drivers\klick.dat"
              "c:\windows\system32\drivers\klin.dat"
              .

              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
              .

              c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrdc.~lk\0.mdd
              c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrdc.~lk\1.mdd
              c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrdc.~lk\2.mdd
              c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrdc.~lk\3.mdd
              c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrdc.~lk\4.mdd
              c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrdc.~lk\5.mdd
              c:\documents and settings\yannick creusot\Local Settings\temp\wrdc.~lk\0.mdd
              c:\documents and settings\yannick creusot\Local Settings\temp\wrdc.~lk\1.mdd
              c:\documents and settings\yannick creusot\Local Settings\temp\wrdc.~lk\2.mdd
              c:\documents and settings\yannick creusot\Local Settings\temp\wrdc.~lk\3.mdd
              c:\documents and settings\yannick creusot\Local Settings\temp\wrdc.~lk\4.mdd
              c:\documents and settings\yannick creusot\Local Settings\temp\wrdc.~lk\5.mdd
              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\dowuvedo.dll
              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\haditapo.dll
              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\jevaziji.exe
              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\kozafuli.dll
              c:\documents and settings\yannick creusot\Application Data\U3\temp\cleanup.exe
              c:\windows\system32\drivers\klick.dat . . . . impossible à supprimer
              c:\windows\system32\drivers\klin.dat . . . . impossible à supprimer

              .
              ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-25 au 2009-06-25 ))))))))))))))))))))))))))))))))))))
              .

              2009-06-25 11:44 . 2009-06-25 11:44 94643 ------w- c:\windows\system32\drivers\klick.dat
              2009-06-25 11:44 . 2009-06-25 11:44 105395 ------w- c:\windows\system32\drivers\klin.dat
              2009-06-24 08:37 . 2009-06-24 08:37 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
              2009-06-24 06:36 . 2009-06-24 06:36 -------- d-sh--w- c:\documents and settings\yannick creusot\IETldCache
              2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\windows\system32\XPSViewer
              2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\program files\MSBuild
              2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\program files\Reference Assemblies
              2009-06-23 22:00 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
              2009-06-23 22:00 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
              2009-06-23 22:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
              2009-06-23 22:00 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
              2009-06-23 22:00 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
              2009-06-23 22:00 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
              2009-06-23 22:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
              2009-06-23 21:54 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
              2009-06-23 21:54 . 2009-06-23 21:54 -------- d-----w- c:\windows\ie8updates
              2009-06-23 21:53 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
              2009-06-23 21:53 . 2009-04-30 21:16 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
              2009-06-23 21:53 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
              2009-06-23 21:53 . 2009-04-30 21:16 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
              2009-06-23 21:52 . 2009-06-23 21:53 -------- dc-h--w- c:\windows\ie8
              2009-06-23 11:57 . 2009-06-23 11:57 9662 ----a-r- c:\documents and settings\yannick creusot\Application Data\Microsoft\Installer\{1043E281-B080-4947-9BD7-3F1D233BF6D2}\RegistryDefrag.exe
              2009-06-23 11:47 . 2009-06-23 11:47 -------- dc----w- c:\windows\system32\dllcache\cache
              2009-06-23 11:29 . 2009-06-23 11:29 -------- d-----w- C:\Rooter$
              2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Malwarebytes
              2009-06-22 19:33 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
              2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
              2009-06-22 19:33 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
              2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
              2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Yahoo!
              2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
              2009-06-21 15:51 . 2009-06-21 16:16 -------- d-----w- c:\windows\BDOSCAN8
              2009-06-21 09:31 . 2009-06-21 13:15 -------- d-----w- c:\documents and settings\yannick creusot\DoctorWeb
              2009-06-20 19:12 . 2009-06-20 19:12 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
              2009-06-20 19:10 . 2009-06-22 19:26 -------- d-----w- c:\windows\ERUNT
              2009-06-20 19:10 . 2009-06-20 19:22 -------- d-----w- C:\Backups
              2009-06-13 14:33 . 2008-12-11 06:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
              2009-06-13 14:33 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
              2009-06-13 14:33 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
              2009-06-13 14:33 . 2009-06-20 17:35 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
              2009-06-13 14:32 . 2009-06-13 14:34 -------- d-----w- c:\program files\Fichiers communs\PC Tools
              2009-06-13 14:32 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
              2009-06-13 14:32 . 2009-06-23 12:00 -------- d-----w- c:\program files\Spyware Doctor
              2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\PC Tools
              2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
              2009-06-11 15:18 . 2009-06-19 12:57 -------- d-----w- c:\program files\Ahead DVD Ripper
              2009-06-06 14:27 . 2009-06-06 14:27 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
              2009-06-06 14:27 . 2009-06-06 14:27 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
              2009-06-06 14:27 . 2009-06-06 14:27 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
              2009-06-06 14:18 . 2009-06-25 11:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
              2009-06-06 14:18 . 2009-06-25 11:43 557088 --sha-w- c:\windows\system32\drivers\fidbox2.dat
              2009-06-06 14:18 . 2009-06-25 11:43 2254368 --sha-w- c:\windows\system32\drivers\fidbox.dat
              2009-06-06 12:20 . 2009-06-06 19:44 -------- d-----w- c:\program files\Loaris Trojan Remover
              2009-05-29 17:48 . 2009-05-29 17:48 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
              2009-05-29 17:48 . 2009-05-29 17:48 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
              2009-05-29 17:48 . 2009-05-29 17:48 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
              2009-05-29 17:48 . 2009-05-29 17:48 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
              2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\MSN6
              2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
              2009-05-28 20:38 . 2009-05-28 20:38 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\VitySoft

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2009-06-25 11:43 . 2009-06-06 14:18 2984 --sha-w- c:\windows\system32\drivers\fidbox2.idx
              2009-06-25 11:43 . 2009-06-06 14:18 18692 --sha-w- c:\windows\system32\drivers\fidbox.idx
              2009-06-25 11:20 . 2008-02-26 14:20 -------- d-----w- c:\program files\Fichiers communs\Adobe
              2009-06-24 06:36 . 2008-02-26 13:35 18112 ----a-w- c:\documents and settings\yannick creusot\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
              2009-06-24 02:05 . 2008-12-13 09:08 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\FrostWire
              2009-06-23 22:06 . 2001-08-28 12:00 81162 ----a-w- c:\windows\system32\perfc00C.dat
              2009-06-23 22:06 . 2001-08-28 12:00 501362 ----a-w- c:\windows\system32\perfh00C.dat
              2009-06-23 18:58 . 2008-03-02 12:40 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\dvdcss
              2009-06-22 19:29 . 2008-07-28 14:28 -------- d-----w- c:\program files\Yahoo!
              2009-06-21 08:14 . 2009-06-21 08:14 0 --sh--w- c:\windows\SEA7077AE.tmp
              2009-06-20 12:43 . 2008-02-26 11:31 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\U3
              2009-06-06 14:27 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
              2009-06-06 14:18 . 2008-02-26 11:46 -------- d-----w- c:\program files\Kaspersky Lab
              2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
              2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
              2009-06-06 13:08 . 2009-02-21 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
              2009-06-06 12:54 . 2009-05-07 19:04 -------- d-----w- c:\program files\ZebHelpProcess
              2009-06-01 08:04 . 2008-06-13 14:53 -------- d-----w- c:\program files\Google
              2009-05-13 12:38 . 2009-05-13 12:38 52228 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\nifodiyu.exe
              2009-05-13 05:04 . 2001-08-28 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
              2009-05-11 16:28 . 2008-09-13 13:24 -------- d-----w- c:\program files\Tomtomax Maxi-Box
              2009-05-08 19:05 . 2009-05-08 19:04 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\vlc
              2009-05-07 19:04 . 2009-05-07 19:04 -------- d-----w- c:\program files\Fichiers communs\Borland Shared
              2009-05-07 15:33 . 2001-08-28 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
              2009-05-04 17:12 . 2008-02-26 14:09 -------- d-----w- c:\program files\CCleaner
              2009-05-01 17:48 . 2009-05-01 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
              2009-05-01 17:48 . 2009-05-01 19:11 15688 ----a-w- c:\windows\system32\lsdelete.exe
              2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
              2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
              2009-05-01 17:47 . 2009-05-01 17:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
              2009-05-01 17:46 . 2008-02-26 14:23 -------- d-----w- c:\program files\Lavasoft
              2009-04-19 19:50 . 2001-08-28 12:00 1847296 ----a-w- c:\windows\system32\win32k.sys
              2009-04-15 14:53 . 2008-02-26 12:17 585216 ----a-w- c:\windows\system32\rpcrt4.dll
              .

              ((((((((((((((((((((((((((((( SnapShot_2009-06-24_17.10.51 )))))))))))))))))))))))))))))))))))))))))
              .
              + 2006-06-05 12:14 . 2006-06-05 12:14 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
              - 2006-06-05 13:14 . 2006-06-05 13:14 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
              + 2006-06-05 12:14 . 2006-06-05 12:14 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
              - 2006-06-05 13:14 . 2006-06-05 13:14 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
              + 2006-06-05 12:14 . 2006-06-05 12:14 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
              - 2006-06-05 13:14 . 2006-06-05 13:14 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
              + 2009-06-25 11:20 . 2009-06-25 11:20 295606 c:\windows\Installer\{AC76BA86-7AD7-1036-7B44-A81300000003}\SC_Reader.exe
              .
              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
              REGEDIT4

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-04-20 337216]
              "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-19 518488]
              "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
              "AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-06-06 206088]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

              c:\documents and settings\yannick creusot\Menu D‚marrer\Programmes\D‚marrage\
              Pampers Pregnancy Widget.lnk - c:\documents and settings\yannick creusot\Bureau\PampersPregnancyWidget.exe [2009-1-5 4924787]
              Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-12 3746856]

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
              @="Service"

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
              @=""

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
              @=""

              [HKLM\~\startupfolder\C:^Documents and Settings^yannick creusot^Menu Démarrer^Programmes^Démarrage^Pampers Pregnancy Widget.lnk]
              path=c:\documents and settings\yannick creusot\Menu Démarrer\Programmes\Démarrage\Pampers Pregnancy Widget.lnk
              backup=c:\windows\pss\Pampers Pregnancy Widget.lnkStartup

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
              "DisableMonitoring"=dword:00000001

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
              "EnableFirewall"= 0 (0x0)

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "%windir%\\system32\\sessmgr.exe"=
              "c:\\Program Files\\HomePlayer1.5.4\\HomePlayer.exe"=
              "c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "c:\program files\uTorrent\uTorrent.exe"= c:\program files\uTorrent\uTorrent.exe:89.226.204.137/255.255.255.255:Enabled:µTorrent
              "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
              "c:\\Program Files\\iTunes\\iTunes.exe"=
              "c:\\Program Files\\FrostWire\\FrostWire.exe"=
              "c:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
              "c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
              "c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
              "c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2009\\avp.exe"=
              "c:\\Program Files\\Java\\jre1.6.0_03\\launch4j-tmp\\frd.exe"=

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
              "57488:TCP"= 57488:TCP:Pando P2P TCP Listening Port
              "57488:UDP"= 57488:UDP:Pando P2P UDP Listening Port
              "6881:TCP"= 6881:TCP:azureus
              "8080:TCP"= 8080:TCP:freeplayer
              "56680:TCP"= 56680:TCP:Pando P2P TCP Listening Port
              "56680:UDP"= 56680:UDP:Pando P2P UDP Listening Port

              R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 17:29 33808]
              R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [01/05/2009 19:48 64160]
              R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [13/06/2009 16:33 130936]
              R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 23:34 1003344]
              R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 17:06 24592]
              S2 gupdate1c9087ee8c5a21c;Google Update Service (gupdate1c9087ee8c5a21c);c:\program files\Google\Update\GoogleUpdate.exe [27/08/2008 21:55 133104]
              S3 adiusbae;USB ADSL LAN Adapter;c:\windows\system32\DRIVERS\adiusbae.sys --> c:\windows\system32\DRIVERS\adiusbae.sys [?]
              S3 fbxusb;FreeBox USB Network Adapter;c:\windows\system32\drivers\fbxusb.sys [01/08/2008 18:46 18953]
              S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [13/06/2009 16:32 348752]
              S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]

              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
              "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
              .
              Contenu du dossier 'Tâches planifiées'

              2009-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
              - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:48]

              2009-06-25 c:\windows\Tasks\GoogleUpdateTaskMachine.job
              - c:\program files\Google\Update\GoogleUpdate.exe [2008-08-27 05:33]
              .
              .
              ------- Examen supplémentaire -------
              .
              uStart Page = hxxp://fr.yahoo.com/
              uInternet Settings,ProxyOverride = *.local
              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
              IE: Easy-WebPrint Ajouter à la liste d'impressions
              IE: Easy-WebPrint Impression rapide
              IE: Easy-WebPrint Imprimer
              IE: Easy-WebPrint Prévisualiser
              Trusted Zone: secuser.com\www
              TCP: {52441C7C-E5B9-4D6F-A48A-236A4BC93B2D} = 212.27.53.252,212.27.54.252
              DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
              DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
              FF - ProfilePath -
              .

              **************************************************************************

              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2009-06-25 13:44
              Windows 5.1.2600 Service Pack 3 NTFS

              Recherche de processus cachés ...

              Recherche d'éléments en démarrage automatique cachés ...

              Recherche de fichiers cachés ...

              Scan terminé avec succès
              Fichiers cachés: 0

              **************************************************************************
              .
              --------------------- DLLs chargées dans les processus actifs ---------------------

              - - - - - - - > 'explorer.exe'(4084)
              c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
              c:\program files\Fichiers communs\Ahead\Lib\NeroSearchBar.dll
              c:\program files\Fichiers communs\Ahead\Lib\MFC71U.DLL
              c:\program files\Fichiers communs\Ahead\Lib\BCGCBPRO860un71.dll
              c:\windows\system32\eappprxy.dll
              c:\windows\system32\webcheck.dll
              c:\windows\system32\WPDShServiceObj.dll
              c:\windows\system32\PortableDeviceTypes.dll
              c:\windows\system32\PortableDeviceApi.dll
              .
              ------------------------ Autres processus actifs ------------------------
              .
              c:\windows\system32\nvsvc32.exe
              c:\windows\system32\wbem\unsecapp.exe
              c:\windows\system32\wscntfy.exe
              .
              **************************************************************************
              .
              Heure de fin: 2009-06-25 13:48 - La machine a redémarré
              ComboFix-quarantined-files.txt 2009-06-25 11:48
              ComboFix2.txt 2009-06-24 17:12
              ComboFix3.txt 2009-06-23 11:48

              Avant-CF: 6 274 220 032 octets libres
              Après-CF: 6 232 989 696 octets libres

              270 --- E O F --- 2009-06-24 02:07
              1. Recommence la manip, tu as dû faire une erreur quelques part, il faut qu'au debut du rapport j'ai le script que je t'ai donné.

                Suis bien les indications et reposte .

                1. Je n'y connais pas grand chose, j'ai fait sur conseil de mon pote et plus de msg

                  Voici le rapport merci:

                  ComboFix 09-06-22.08 - yannick creusot 24/06/2009 19:07.5 - NTFSx86
                  Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.625 [GMT 2:00]
                  Lancé depuis: c:\documents and settings\yannick creusot\Bureau\Combofix.exe
                  AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
                  .

                  ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-24 au 2009-06-24 ))))))))))))))))))))))))))))))))))))
                  .

                  2009-06-24 08:37 . 2009-06-24 08:37 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
                  2009-06-24 06:36 . 2009-06-24 06:36 -------- d-sh--w- c:\documents and settings\yannick creusot\IETldCache
                  2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\windows\system32\XPSViewer
                  2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\program files\MSBuild
                  2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\program files\Reference Assemblies
                  2009-06-23 22:00 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
                  2009-06-23 22:00 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
                  2009-06-23 22:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
                  2009-06-23 22:00 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
                  2009-06-23 22:00 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
                  2009-06-23 22:00 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
                  2009-06-23 22:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
                  2009-06-23 21:54 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
                  2009-06-23 21:54 . 2009-06-23 21:54 -------- d-----w- c:\windows\ie8updates
                  2009-06-23 21:53 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
                  2009-06-23 21:53 . 2009-04-30 21:16 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
                  2009-06-23 21:53 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
                  2009-06-23 21:53 . 2009-04-30 21:16 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
                  2009-06-23 21:52 . 2009-06-23 21:53 -------- dc-h--w- c:\windows\ie8
                  2009-06-23 11:57 . 2009-06-23 11:57 9662 ----a-r- c:\documents and settings\yannick creusot\Application Data\Microsoft\Installer\{1043E281-B080-4947-9BD7-3F1D233BF6D2}\RegistryDefrag.exe
                  2009-06-23 11:47 . 2009-06-23 11:47 -------- dc----w- c:\windows\system32\dllcache\cache
                  2009-06-23 11:29 . 2009-06-23 11:29 -------- d-----w- C:\Rooter$
                  2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Malwarebytes
                  2009-06-22 19:33 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                  2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                  2009-06-22 19:33 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
                  2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                  2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Yahoo!
                  2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
                  2009-06-21 15:51 . 2009-06-21 16:16 -------- d-----w- c:\windows\BDOSCAN8
                  2009-06-21 09:31 . 2009-06-21 13:15 -------- d-----w- c:\documents and settings\yannick creusot\DoctorWeb
                  2009-06-20 19:12 . 2009-06-20 19:12 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
                  2009-06-20 19:10 . 2009-06-22 19:26 -------- d-----w- c:\windows\ERUNT
                  2009-06-20 19:10 . 2009-06-20 19:22 -------- d-----w- C:\Backups
                  2009-06-13 14:33 . 2008-12-11 06:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
                  2009-06-13 14:33 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
                  2009-06-13 14:33 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
                  2009-06-13 14:33 . 2009-06-20 17:35 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                  2009-06-13 14:32 . 2009-06-13 14:34 -------- d-----w- c:\program files\Fichiers communs\PC Tools
                  2009-06-13 14:32 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
                  2009-06-13 14:32 . 2009-06-23 12:00 -------- d-----w- c:\program files\Spyware Doctor
                  2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\PC Tools
                  2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
                  2009-06-11 15:18 . 2009-06-19 12:57 -------- d-----w- c:\program files\Ahead DVD Ripper
                  2009-06-06 14:27 . 2009-06-06 14:27 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
                  2009-06-06 14:27 . 2009-06-06 14:27 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
                  2009-06-06 14:27 . 2009-06-06 14:27 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
                  2009-06-06 14:19 . 2009-06-06 14:27 94643 ----a-w- c:\windows\system32\drivers\klick.dat
                  2009-06-06 14:19 . 2009-06-06 14:27 105395 ----a-w- c:\windows\system32\drivers\klin.dat
                  2009-06-06 14:18 . 2009-06-24 06:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
                  2009-06-06 14:18 . 2009-06-24 02:07 557088 --sha-w- c:\windows\system32\drivers\fidbox2.dat
                  2009-06-06 14:18 . 2009-06-24 02:07 2254368 --sha-w- c:\windows\system32\drivers\fidbox.dat
                  2009-06-06 12:20 . 2009-06-06 19:44 -------- d-----w- c:\program files\Loaris Trojan Remover
                  2009-05-29 17:48 . 2009-05-29 17:48 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
                  2009-05-29 17:48 . 2009-05-29 17:48 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
                  2009-05-29 17:48 . 2009-05-29 17:48 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
                  2009-05-29 17:48 . 2009-05-29 17:48 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
                  2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\MSN6
                  2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
                  2009-05-28 20:38 . 2009-05-28 20:38 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\VitySoft

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2009-06-24 06:36 . 2008-02-26 13:35 18112 ----a-w- c:\documents and settings\yannick creusot\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                  2009-06-24 02:07 . 2009-06-06 14:18 2984 --sha-w- c:\windows\system32\drivers\fidbox2.idx
                  2009-06-24 02:07 . 2009-06-06 14:18 18692 --sha-w- c:\windows\system32\drivers\fidbox.idx
                  2009-06-24 02:05 . 2008-12-13 09:08 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\FrostWire
                  2009-06-23 22:06 . 2001-08-28 12:00 81162 ----a-w- c:\windows\system32\perfc00C.dat
                  2009-06-23 22:06 . 2001-08-28 12:00 501362 ----a-w- c:\windows\system32\perfh00C.dat
                  2009-06-23 18:58 . 2008-03-02 12:40 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\dvdcss
                  2009-06-22 19:29 . 2008-07-28 14:28 -------- d-----w- c:\program files\Yahoo!
                  2009-06-21 08:14 . 2009-06-21 08:14 0 --sh--w- c:\windows\SEA7077AE.tmp
                  2009-06-20 12:43 . 2008-02-26 11:31 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\U3
                  2009-06-20 12:29 . 2008-04-20 11:51 110592 ----a-w- c:\documents and settings\yannick creusot\Application Data\U3\temp\cleanup.exe
                  2009-06-06 14:27 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
                  2009-06-06 14:18 . 2008-02-26 11:46 -------- d-----w- c:\program files\Kaspersky Lab
                  2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                  2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
                  2009-06-06 13:08 . 2009-02-21 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
                  2009-06-06 12:54 . 2009-05-07 19:04 -------- d-----w- c:\program files\ZebHelpProcess
                  2009-06-01 08:04 . 2008-06-13 14:53 -------- d-----w- c:\program files\Google
                  2009-05-13 12:38 . 2009-05-13 12:38 52228 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\nifodiyu.exe
                  2009-05-13 12:38 . 2009-05-13 12:38 88580 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\haditapo.dll
                  2009-05-13 12:38 . 2009-05-13 12:38 52228 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\jevaziji.exe
                  2009-05-13 12:38 . 2009-05-13 12:38 49668 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\kozafuli.dll
                  2009-05-13 12:38 . 2009-05-13 12:38 49668 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\dowuvedo.dll
                  2009-05-13 05:04 . 2001-08-28 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
                  2009-05-11 16:28 . 2008-09-13 13:24 -------- d-----w- c:\program files\Tomtomax Maxi-Box
                  2009-05-08 19:05 . 2009-05-08 19:04 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\vlc
                  2009-05-07 19:04 . 2009-05-07 19:04 -------- d-----w- c:\program files\Fichiers communs\Borland Shared
                  2009-05-07 15:33 . 2001-08-28 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
                  2009-05-04 17:12 . 2008-02-26 14:09 -------- d-----w- c:\program files\CCleaner
                  2009-05-01 17:48 . 2009-05-01 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
                  2009-05-01 17:48 . 2009-05-01 19:11 15688 ----a-w- c:\windows\system32\lsdelete.exe
                  2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
                  2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
                  2009-05-01 17:47 . 2009-05-01 17:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
                  2009-05-01 17:46 . 2008-02-26 14:23 -------- d-----w- c:\program files\Lavasoft
                  2009-04-19 19:50 . 2001-08-28 12:00 1847296 ----a-w- c:\windows\system32\win32k.sys
                  2009-04-15 14:53 . 2008-02-26 12:17 585216 ----a-w- c:\windows\system32\rpcrt4.dll
                  .

                  ((((((((((((((((((((((((((((( SnapShot@2009-06-23_11.45.44 )))))))))))))))))))))))))))))))))))))))))
                  .
                  + 2008-07-29 19:10 . 2008-07-29 19:10 26112 c:\windows\system32\TsWpfWrp.exe
                  + 2008-02-26 13:24 . 2009-01-07 16:21 26144 c:\windows\system32\spupdsvc.exe
                  + 2009-06-23 22:01 . 2008-07-06 12:06 89088 c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
                  + 2009-01-08 21:06 . 2009-01-07 16:21 17952 c:\windows\system32\spmsg.dll
                  + 2008-07-29 17:59 . 2008-07-29 17:59 43544 c:\windows\system32\PresentationHostProxy.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\pngfilt.dll
                  + 2001-08-28 12:00 . 2009-06-23 22:06 67784 c:\windows\system32\perfc009.dat
                  + 2009-01-07 16:20 . 2009-01-07 16:20 23552 c:\windows\system32\normaliz.dll
                  + 2009-01-07 16:20 . 2009-01-07 16:20 24576 c:\windows\system32\nlsdl.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 15360 c:\windows\system32\mui\0409\mscorees.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\mshtmler.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:31 66560 c:\windows\system32\mshtmled.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\mshta.exe
                  + 2009-03-08 02:31 . 2009-03-08 02:31 13312 c:\windows\system32\msfeedssync.exe
                  + 2009-03-08 02:31 . 2009-03-08 02:31 55296 c:\windows\system32\msfeedsbs.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 83968 c:\windows\system32\mscories.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:34 43008 c:\windows\system32\licmgr10.dll
                  + 2001-08-28 12:00 . 2009-04-30 21:16 25600 c:\windows\system32\jsproxy.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\inseng.dll
                  + 2008-07-29 17:24 . 2008-07-29 17:24 97800 c:\windows\system32\infocardapi.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\imgutil.dll
                  + 2009-03-08 02:32 . 2009-03-08 02:32 36864 c:\windows\system32\ieudinit.exe
                  + 2001-08-28 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\iesetup.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\iernonce.dll
                  + 2009-01-07 16:20 . 2009-01-07 16:20 26112 c:\windows\system32\idndl.dll
                  + 2008-07-29 17:24 . 2008-07-29 17:24 11264 c:\windows\system32\icardres.dll
                  + 2009-03-08 02:31 . 2009-03-08 02:31 59904 c:\windows\system32\icardie.dll
                  + 2008-07-29 19:10 . 2008-07-29 19:10 73720 c:\windows\system32\dxva2.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 30749 c:\windows\system32\dllcache\vbajet32.dll
                  + 2004-08-19 23:09 . 2007-03-28 12:53 16384 c:\windows\system32\dllcache\tcptsat.dll
                  + 2004-08-19 23:10 . 2008-04-14 02:34 32827 c:\windows\system32\dllcache\tcptest.exe
                  + 2001-08-28 12:00 . 2008-04-14 02:33 25600 c:\windows\system32\dllcache\slayerxp.dll
                  + 2004-08-19 23:10 . 2008-04-14 02:34 16437 c:\windows\system32\dllcache\shtml.exe
                  + 2004-08-19 23:09 . 2008-04-14 02:33 20536 c:\windows\system32\dllcache\shtml.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 65024 c:\windows\system32\dllcache\shimeng.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:34 78848 c:\windows\system32\dllcache\sdbinst.exe
                  + 2001-08-28 12:00 . 2008-04-14 02:33 64000 c:\windows\system32\dllcache\samlib.dll
                  + 2009-06-23 18:20 . 2001-08-23 15:46 66048 c:\windows\system32\dllcache\s3legacy.dll
                  + 2009-03-08 02:31 . 2009-03-08 02:31 46592 c:\windows\system32\dllcache\pngfilt.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 84992 c:\windows\system32\dllcache\olepro32.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 77824 c:\windows\system32\dllcache\oledb32r.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 20511 c:\windows\system32\dllcache\odtext32.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 20510 c:\windows\system32\dllcache\odpdx32.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 20510 c:\windows\system32\dllcache\odfox32.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 20510 c:\windows\system32\dllcache\odexl32.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 20511 c:\windows\system32\dllcache\oddbse32.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:32 61471 c:\windows\system32\dllcache\odbcji32.dll
                  + 2001-08-28 12:00 . 2007-03-28 12:56 98304 c:\windows\system32\dllcache\odbcint.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 65536 c:\windows\system32\dllcache\odbccu32.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 65536 c:\windows\system32\dllcache\odbccr32.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:34 69632 c:\windows\system32\dllcache\odbcconf.exe
                  + 2001-08-28 12:00 . 2008-04-14 02:34 32768 c:\windows\system32\dllcache\odbcad32.exe
                  + 2001-08-28 12:00 . 2008-04-14 02:33 16384 c:\windows\system32\dllcache\odbc32gt.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 69632 c:\windows\system32\dllcache\ocmanage.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 10240 c:\windows\system32\dllcache\npwmsdrm.dll
                  - 2008-10-24 21:22 . 2008-04-14 02:33 10240 c:\windows\system32\dllcache\npwmsdrm.dll
                  + 2001-08-28 12:00 . 2008-04-13 19:20 91520 c:\windows\system32\dllcache\ndiswan.sys
                  + 2008-02-26 10:19 . 2008-04-14 02:33 24576 c:\windows\system32\dllcache\msxactps.dll
                  + 2001-08-28 12:00 . 2008-04-13 18:30 61440 c:\windows\system32\dllcache\msvcrt40.dll
                  + 2001-08-28 12:00 . 2008-03-25 04:50 60192 c:\windows\system32\dllcache\msjter40.dll
                  - 2008-03-25 04:50 . 2008-03-25 04:50 60192 c:\windows\system32\dllcache\msjter40.dll
                  + 2009-03-08 02:31 . 2009-03-08 02:31 48128 c:\windows\system32\dllcache\mshtmler.dll
                  + 2009-03-08 02:31 . 2009-03-08 02:31 66560 c:\windows\system32\dllcache\mshtmled.dll
                  + 2009-03-08 02:31 . 2009-03-08 02:31 45568 c:\windows\system32\dllcache\mshta.exe
                  + 2008-02-26 10:19 . 2008-04-14 02:33 36864 c:\windows\system32\dllcache\msdfmap.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 20480 c:\windows\system32\dllcache\msdatt.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msdasqlr.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msdaremr.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msdaprsr.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 77824 c:\windows\system32\dllcache\msdaosp.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 36864 c:\windows\system32\dllcache\mscpxl32.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 57344 c:\windows\system32\dllcache\msadrh15.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 57344 c:\windows\system32\dllcache\msador15.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 28672 c:\windows\system32\dllcache\msader15.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 24576 c:\windows\system32\dllcache\msaddsr.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 53248 c:\windows\system32\dllcache\msadcs.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msadcor.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msadcfr.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 61440 c:\windows\system32\dllcache\msadcf.dll
                  + 2008-02-26 10:19 . 2007-03-28 12:56 20480 c:\windows\system32\dllcache\msadcer.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 22528 c:\windows\system32\dllcache\mfcsubs.dll
                  + 2009-03-08 02:34 . 2009-03-08 02:34 43008 c:\windows\system32\dllcache\licmgr10.dll
                  + 2001-08-28 12:00 . 2009-04-30 21:16 25600 c:\windows\system32\dllcache\jsproxy.dll
                  + 2001-08-28 12:00 . 2008-04-13 19:19 75264 c:\windows\system32\dllcache\ipsec.sys
                  + 2009-03-08 02:32 . 2009-03-08 02:32 94720 c:\windows\system32\dllcache\inseng.dll
                  + 2009-03-08 02:31 . 2009-03-08 02:31 34816 c:\windows\system32\dllcache\imgutil.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 36921 c:\windows\system32\dllcache\imeshare.dll
                  + 2009-03-08 02:32 . 2009-03-08 02:32 71680 c:\windows\system32\dllcache\iesetup.dll
                  + 2009-03-08 02:32 . 2009-03-08 02:32 55808 c:\windows\system32\dllcache\iernonce.dll
                  + 2009-03-08 02:24 . 2009-03-08 02:24 68608 c:\windows\system32\dllcache\hmmapi.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:34 20538 c:\windows\system32\dllcache\fpremadm.exe
                  + 2004-08-19 23:09 . 2008-04-14 02:33 20541 c:\windows\system32\dllcache\fpexedll.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:34 15120 c:\windows\system32\dllcache\fp98sadm.exe
                  + 2004-08-19 23:09 . 2008-04-14 02:33 49212 c:\windows\system32\dllcache\fp4awebs.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 32826 c:\windows\system32\dllcache\fp4avss.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 41020 c:\windows\system32\dllcache\fp4avnb.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 49210 c:\windows\system32\dllcache\fp4areg.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 82035 c:\windows\system32\dllcache\fp4anscp.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 16384 c:\windows\system32\dllcache\ds32gt.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 32768 c:\windows\system32\dllcache\dispex.dll
                  + 2008-10-24 21:22 . 2008-04-14 02:33 39936 c:\windows\system32\dllcache\dimsroam.dll
                  + 2008-10-24 21:22 . 2008-04-14 02:33 19456 c:\windows\system32\dllcache\dimsntfy.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 62464 c:\windows\system32\dllcache\cryptsvc.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 64512 c:\windows\system32\dllcache\cryptnet.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 54784 c:\windows\system32\dllcache\cryptext.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 33280 c:\windows\system32\dllcache\cryptdll.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 75776 c:\windows\system32\dllcache\cryptdlg.dll
                  + 2009-03-08 02:33 . 2009-03-08 02:33 18944 c:\windows\system32\dllcache\corpol.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:31 16896 c:\windows\system32\dllcache\cfgmgr32.dll
                  + 2009-06-23 11:47 . 2008-10-16 13:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
                  + 2009-06-23 11:47 . 2008-04-14 02:33 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
                  + 2009-06-23 11:47 . 2008-04-14 02:34 26624 c:\windows\system32\dllcache\cache\userinit.exe
                  + 2009-06-23 11:47 . 2008-04-14 02:34 14336 c:\windows\system32\dllcache\cache\svchost.exe
                  + 2009-06-23 11:47 . 2008-04-14 02:34 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
                  + 2009-06-23 11:47 . 2008-04-14 02:33 17408 c:\windows\system32\dllcache\cache\powrprof.dll
                  + 2009-06-23 11:47 . 2008-04-14 02:34 13312 c:\windows\system32\dllcache\cache\lsass.exe
                  + 2009-06-23 11:47 . 2008-04-14 02:05 25216 c:\windows\system32\dllcache\cache\kbdclass.sys
                  + 2009-06-23 11:47 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
                  + 2009-06-23 11:47 . 2008-04-14 02:33 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
                  + 2004-08-19 23:09 . 2008-04-14 02:33 16439 c:\windows\system32\dllcache\author.exe
                  + 2004-08-19 23:09 . 2008-04-14 02:33 20540 c:\windows\system32\dllcache\author.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 30208 c:\windows\system32\dllcache\atmlib.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 65024 c:\windows\system32\dllcache\asycfilt.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 98304 c:\windows\system32\dllcache\ahui.exe
                  + 2008-10-24 21:21 . 2007-04-02 18:25 19456 c:\windows\system32\dllcache\agt0401.dll
                  + 2004-08-04 06:07 . 2008-04-13 18:36 44928 c:\windows\system32\dllcache\agpcpq.sys
                  + 2004-08-04 06:07 . 2008-04-13 18:36 42368 c:\windows\system32\dllcache\agp440.sys
                  + 2001-08-28 12:00 . 2008-04-14 02:33 44032 c:\windows\system32\dllcache\agentsr.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 24064 c:\windows\system32\dllcache\agentpsh.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 49152 c:\windows\system32\dllcache\agentmpx.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 57344 c:\windows\system32\dllcache\agentdpv.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 42496 c:\windows\system32\dllcache\agentdp2.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 24064 c:\windows\system32\dllcache\agentanm.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 68096 c:\windows\system32\dllcache\adsmsext.dll
                  + 2009-06-23 18:20 . 2001-08-17 18:11 46112 c:\windows\system32\dllcache\adptsf50.sys
                  + 2001-08-28 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\dllcache\admparse.dll
                  + 2009-06-23 18:20 . 2004-08-04 05:32 10880 c:\windows\system32\dllcache\admjoy.sys
                  + 2004-08-19 23:09 . 2008-04-14 02:33 16439 c:\windows\system32\dllcache\admin.exe
                  + 2004-08-19 23:09 . 2008-04-14 02:33 20540 c:\windows\system32\dllcache\admin.dll
                  + 2009-06-23 18:20 . 2001-08-17 18:11 20160 c:\windows\system32\dllcache\adm8511.sys
                  + 2001-08-28 12:00 . 2008-04-14 02:33 98304 c:\windows\system32\dllcache\actxprxy.dll
                  + 2001-08-28 12:00 . 2001-08-28 12:00 12032 c:\windows\system32\dllcache\acpiec.sys
                  + 2009-06-23 18:20 . 2001-08-23 15:46 61952 c:\windows\system32\dllcache\acerscad.dll
                  + 2008-02-26 10:19 . 2001-08-28 12:00 72192 c:\windows\system32\dllcache\acctres.dll
                  + 2009-06-23 18:20 . 2004-08-04 05:32 84480 c:\windows\system32\dllcache\ac97via.sys
                  + 2009-06-23 18:20 . 2001-08-17 18:20 96256 c:\windows\system32\dllcache\ac97intc.sys
                  + 2009-06-23 18:20 . 2001-08-17 19:52 23552 c:\windows\system32\dllcache\abp480n5.sys
                  + 2009-06-23 18:20 . 2001-08-23 15:46 98304 c:\windows\system32\dllcache\a3d.dll
                  + 2009-06-23 18:20 . 2001-08-23 15:46 38400 c:\windows\system32\dllcache\8514a.dll
                  + 2009-06-23 18:20 . 2008-04-13 18:46 48128 c:\windows\system32\dllcache\61883.sys
                  + 2009-06-23 18:20 . 2008-04-13 18:40 12288 c:\windows\system32\dllcache\4mmdat.sys
                  + 2009-06-23 18:20 . 2001-08-17 20:06 11264 c:\windows\system32\dllcache\1394vdbg.sys
                  + 2001-08-28 12:00 . 2008-04-13 18:46 53376 c:\windows\system32\dllcache\1394bus.sys
                  + 2008-07-25 09:16 . 2008-07-25 09:16 96760 c:\windows\system32\dfshim.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\corpol.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\admparse.dll
                  + 2008-07-29 21:40 . 2008-07-29 21:40 70648 c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
                  + 2008-07-29 21:40 . 2008-07-29 21:40 91136 c:\windows\Microsoft.NET\Framework\v3.5\MSBuild.exe
                  + 2008-07-29 21:40 . 2008-07-29 21:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.VisualC.STLCLR.dll
                  + 2008-07-29 21:40 . 2008-07-29 21:40 40960 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Data.Entity.Build.Tasks.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 89080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2052.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 92664 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1042.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 95224 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1041.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 89592 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1028.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 84480 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2052.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 94720 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1042.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 97792 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1041.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 84992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1028.dll
                  + 2008-07-29 16:47 . 2008-07-29 16:47 97280 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe
                  + 2008-07-29 21:40 . 2008-07-29 21:40 95224 c:\windows\Microsoft.NET\Framework\v3.5\EdmGen.exe
                  + 2008-07-29 21:40 . 2008-07-29 21:40 78856 c:\windows\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe
                  + 2008-07-29 21:40 . 2008-07-29 21:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
                  + 2008-07-29 21:40 . 2008-07-29 21:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess32.exe
                  + 2008-07-29 21:40 . 2008-07-29 21:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess.exe
                  + 2008-07-29 19:10 . 2008-07-29 19:10 46104 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
                  + 2008-07-29 17:59 . 2008-07-29 17:59 32768 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
                  + 2008-07-29 19:10 . 2008-07-29 19:10 71160 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
                  + 2008-07-29 17:32 . 2008-07-29 17:32 17448 c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
                  + 2008-07-29 17:16 . 2008-07-29 17:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
                  + 2008-07-29 17:16 . 2008-07-29 17:16 73728 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
                  + 2008-07-29 17:16 . 2008-07-29 17:16 20504 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
                  + 2008-07-29 17:16 . 2008-07-29 17:16 11280 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 37896 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 81400 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
                  + 2008-07-25 09:17 . 2008-07-25 09:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 57392 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 95232 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 61952 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
                  - 2005-09-23 06:28 . 2005-09-23 06:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                  + 2008-07-25 09:17 . 2008-07-25 09:17 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                  + 2008-07-25 09:17 . 2008-07-25 09:17 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
                  - 2005-09-23 06:28 . 2005-09-23 06:28 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
                  + 2008-07-25 09:17 . 2008-07-25 09:17 88584 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 24584 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 31744 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 19456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 77312 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 94208 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 46592 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 97792 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
                  - 2005-09-23 06:28 . 2005-09-23 06:28 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
                  - 2005-09-23 06:28 . 2005-09-23 06:28 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 65032 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
                  - 2005-09-23 06:28 . 2005-09-23 06:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
                  + 2008-07-25 09:17 . 2008-07-25 09:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 18936 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 62968 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 35320 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
                  + 2008-07-25 09:17 . 2008-07-25 09:17 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 27136 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 80376 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
                  + 2008-07-25 09:17 . 2008-07-25 09:17 89608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
                  + 2008-11-25 02:59 . 2008-11-25 02:59 31560 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 34312 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 33288 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 24576 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 33800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 17416 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 22024 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
                  + 2008-07-25 09:17 . 2008-07-25 09:17 58880 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 98808 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 96768 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 16896 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 82944 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
                  + 2009-06-23 21:54 . 2009-03-08 02:33 12288 c:\windows\ie8updates\KB969897-IE8\xpshims.dll
                  + 2009-06-23 21:54 . 2009-03-08 02:33 25600 c:\windows\ie8updates\KB969897-IE8\jsproxy.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 37888 c:\windows\ie8\url.dll
                  + 2009-06-23 21:53 . 2009-03-08 14:14 58448 c:\windows\ie8\spuninst\iecustom.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 39424 c:\windows\ie8\pngfilt.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 97280 c:\windows\ie8\occache.dll
                  + 2009-06-23 21:52 . 2008-04-14 01:56 57344 c:\windows\ie8\mshtmler.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:34 29184 c:\windows\ie8\mshta.exe
                  + 2009-06-23 21:52 . 2008-04-14 02:33 22528 c:\windows\ie8\licmgr10.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 15872 c:\windows\ie8\jsproxy.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 96768 c:\windows\ie8\inseng.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 35840 c:\windows\ie8\imgutil.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:34 93184 c:\windows\ie8\iexplore.exe
                  + 2009-06-23 21:52 . 2008-04-14 02:33 63488 c:\windows\ie8\iesetup.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 49152 c:\windows\ie8\iernonce.dll
                  + 2009-06-23 21:52 . 2009-04-29 04:34 81920 c:\windows\ie8\ieencode.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:34 34304 c:\windows\ie8\ie4uinit.exe
                  + 2009-06-23 21:52 . 2008-04-14 02:33 38912 c:\windows\ie8\hmmapi.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 35328 c:\windows\ie8\corpol.dll
                  + 2009-06-23 21:52 . 2008-04-14 02:33 61440 c:\windows\ie8\admparse.dll
                  + 2009-06-23 22:00 . 2008-07-06 12:06 89088 c:\windows\Driver Cache\i386\filterpipelineprintproc.dll
                  + 2009-06-23 22:09 . 2009-06-23 22:09 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\a715aa442ef87ae99b3ade185599249d\UIAutomationProvider.ni.dll
                  + 2009-06-23 22:14 . 2009-06-23 22:14 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\423f794d1f4ed6e120fbb02e436491cb\System.Windows.Presentation.ni.dll
                  + 2009-06-23 22:14 . 2009-06-23 22:14 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\19ca1747c1ea18a3b639b302bca8df93\System.Web.DynamicData.Design.ni.dll
                  + 2009-06-23 22:13 . 2009-06-23 22:13 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\532438e2acfcadc469a4d468c51f8451\System.ComponentModel.DataAnnotations.ni.dll
                  + 2009-06-23 22:13 . 2009-06-23 22:13 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\597b20e1b053d6a510cfe033c07a63e6\System.AddIn.Contract.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\9e987e971bf109c3698b7549e744005d\stdole.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 29184 c:\windows\assembly\NativeImages_v2.0.50727_32\SFMARKETLib\540c717be45888cd43141de5a88a1267\SFMARKETLib.ni.dll
                  + 2009-06-23 22:08 . 2009-06-23 22:08 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\2d7408a0232f2e2efd0d7adf5dfa733a\PresentationFontCache.ni.exe
                  + 2009-06-23 22:07 . 2009-06-23 22:07 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\c8fd2d9233f8ea3031fb16f697635231\PresentationCFFRasterizer.ni.dll
                  + 2009-06-23 22:13 . 2009-06-23 22:13 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\790cf1edb17ee41b59be62ecbd59613b\Microsoft.Vsa.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\ec83ec80653eb20ccc6ed42075c90aee\Microsoft.VisualC.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e9aba2eab90d647356f65e66053da02b\Microsoft.Build.Framework.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\28343d470d992f169ca0e7cdb3cc3117\Microsoft.Build.Framework.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.QTOControlL#\55682b329733421a87a3daffe1ec9819\Interop.QTOControlLib.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 76800 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.PortableDev#\f345d88e73e3780f3efde7572fe52a21\Interop.PortableDeviceTypesLib.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 77312 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.PortableDev#\2cb1b2476271a4e8ff3151f9b903285a\Interop.PortableDeviceApiLib.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 35328 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.CDDBUICONTR#\09da0d6c60de188515e99d8d2f26752b\Interop.CDDBUICONTROLLibSMS.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 72192 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.CDDBLINKLib#\dc2e912d6c4103336c5f3e0834452df5\Interop.CDDBLINKLibSMS.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 31744 c:\windows\assembly\NativeImages_v2.0.50727_32\Interfaces\f3c8bc6c484801a2e21e453c4dad5a98\Interfaces.ni.dll
                  + 2009-06-23 22:12 . 2009-06-23 22:12 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\f4e38208e88cb4cc314a1d6543b9fcc6\dfsvc.ni.exe
                  + 2009-06-23 22:12 . 2009-06-23 22:12 59904 c:\windows\assembly\NativeImages_v2.0.50727_32\AxInterop.QTOContro#\8486f1815d34f3016941a970a9bf0168\AxInterop.QTOControlLib.ni.dll
                  + 2009-06-23 22:11 . 2009-06-23 22:11 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11eb4f6606ba01e5128805759121ea6c\Accessibility.ni.dll
                  + 2009-06-23 22:01 . 2009-06-23 22:01 94208 c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
                  + 2009-06-23 22:01 . 2009-06-23 22:01 98304 c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
                  + 2009-06-23 22:01 . 2009-06-23 22:01 40960 c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 12288 c:\windows\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 61440 c:\windows\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 32768 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 77824 c:\windows\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
                  + 2009-06-23 22:01 . 2009-06-23 22:01 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
                  + 2009-06-23 22:01 . 2009-06-23 22:01 73728 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 53248 c:\windows\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 57344 c:\windows\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 45056 c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
                  + 2009-06-23 22:01 . 2009-06-23 22:01 46104 c:\windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
                  + 2009-06-23 22:01 . 2009-06-23 22:01 32768 c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 41984 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 94208 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                  - 2009-01-16 10:38 . 2009-01-16 10:38 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:33 5120 c:\windows\system32\dllcache\sfc.dll
                  + 2008-02-26 12:39 . 2004-08-02 13:20 4569 c:\windows\system32\dllcache\secupd.dat
                  - 2008-10-24 21:22 . 2008-04-14 02:31 4126 c:\windows\system32\dllcache\msdxmlc.dll
                  + 2001-08-28 12:00 . 2008-04-14 02:31 4126 c:\windows\system32\dllcache\msdxmlc.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdaurl.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdasc.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdaer.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdaenum.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdadc.dll
                  + 2008-02-26 10:19 . 2008-04-14 02:34 4639 c:\windows\system32\dllcache\mplayer2.exe
                  - 2008-10-24 21:22 . 2008-04-14 02:34 4639 c:\windows\system32\dllcache\mplayer2.exe
                  + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdpash.dll
                  + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdnepr.dll
                  + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdiultn.dll
                  + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdbhc.dll
                  + 2008-10-24 21:22 . 2008-04-14 02:33 7168 c:\windows\system32\dllcache\bitsprx4.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 3775 c:\windows\system32\dllcache\adv11nt5.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 3711 c:\windows\system32\dllcache\adv09nt5.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 3135 c:\windows\system32\dllcache\adv08nt5.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 3647 c:\windows\system32\dllcache\adv07nt5.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 3615 c:\windows\system32\dllcache\adv05nt5.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 3967 c:\windows\system32\dllcache\adv02nt5.dll
                  + 2004-08-19 23:09 . 2008-04-14 02:33 4255 c:\windows\system32\dllcache\adv01nt5.dll
                  + 2009-06-23 18:20 . 2001-08-17 19:53 7424 c:\windows\system32\dllcache\adicvls.sys
                  + 2001-08-28 12:00 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\actmovie.exe
                  + 2008-07-29 21:40 . 2008-07-29 21:40 5632 c:\windows\Microsoft.NET\Framework\v3.5\Sentinel.v3.5Client.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
                  - 2005-09-23 06:29 . 2005-09-23 06:29 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 6656 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
                  - 2005-09-23 06:28 . 2005-09-23 06:28 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
                  - 2005-09-23 06:28 . 2005-09-23 06:28 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
                  + 2008-07-25 09:16 . 2008-07-25 09:16 5120 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
                  + 2009-06-23 21:55 . 2009-03-08 02:35 2048 c:\windows\ie8updates\KB971930-IE8\iecompat.dll
                  + 2009-06-23 22:02 . 2009-06-23 22:02 5632 c:\windows\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                  - 2009-01-16 10:38 . 2009-01-16 10:38 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                  - 2009-01-16 10:38 . 2009-01-16 10:38 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                  + 2009-06-23 22:05 . 2009-06-23 22:05 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
                  - 2009-01-16 10:37 . 2009-01-16 10:37 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                  + 2009-06-23 22:06 . 2009-06-23 22:06 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 635904 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 558080 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll
                  + 2008-07-25 09:17 . 2008-07-25 09:17 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcm80.dll
                  + 2008-07-29 19:26 . 2008-07-29 19:26 301568 c:\windows\system32\XPSViewer\XPSViewer.exe
                  - 2008-10-24 21:23 . 2008-04-14 02:33 121856 c:\windows\system32\xmllite.dll
                  + 2008-10-24 21:23 . 2009-01-07 16:21 121856 c:\windows\system32\xmllite.dll
                  + 2009-03-08 02:34 . 2009-03-08 02:34 208384 c:\windows\system32\WinFXDocObj.exe
                  + 2001-08-28 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\webcheck.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:33 420352 c:\windows\system32\vbscript.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:34 105984 c:\windows\system32\url.dll
                  + 2008-07-29 17:59 . 2008-07-29 17:59 161296 c:\windows\system32\UIAutomationCore.dll
                  + 2009-06-23 22:01 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\mxdwdrv.dll
                  + 2009-06-23 22:01 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\i386\mxdwdrv.dll
                  + 2009-06-23 22:01 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\mxdwdrv.dll
                  + 2009-06-23 22:01 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\amd64\mxdwdrv.dll
                  + 2009-06-23 22:01 . 2008-07-06 12:06 147456 c:\windows\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
                  + 2009-06-23 22:00 . 2008-07-06 10:50 597504 c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
                  + 2009-06-23 22:00 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\3\unires.dll
                  + 2009-06-23 22:00 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
                  + 2009-06-23 22:00 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
                  + 2009-06-23 22:00 . 2008-07-06 12:06 198656 c:\windows\system32\spool\drivers\w32x86\3\mxdwdui.dll
                  + 2009-06-23 22:00 . 2008-07-06 12:06 765440 c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
                  + 2006-08-24 14:15 . 2006-08-24 14:15 150808 c:\windows\system32\rgb9rast_2.dll
                  + 2008-07-29 17:59 . 2008-07-29 17:59 781344 c:\windows\system32\PresentationNative_v0300.dll
                  + 2008-07-29 18:35 . 2008-07-29 18:35 326160 c:\windows\system32\PresentationHost.exe
                  + 2008-07-29 17:59 . 2008-07-29 17:59 105016 c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
                  + 2001-08-28 12:00 . 2009-06-23 22:06 432932 c:\windows\system32\perfh009.dat
                  + 2001-08-28 12:00 . 2009-03-08 02:34 109568 c:\windows\system32\occache.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:32 611840 c:\windows\system32\mstime.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\msrating.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\msls31.dll
                  + 2009-03-08 02:32 . 2009-03-08 02:32 594432 c:\windows\system32\msfeeds.dll
                  + 2009-01-07 16:20 . 2009-01-07 16:20 265720 c:\windows\system32\msdbg2.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 158720 c:\windows\system32\mscorier.dll
                  + 2008-07-25 09:16 . 2008-07-25 09:16 282112 c:\windows\system32\mscoree.dll
                  + 2003-01-13 13:57 . 2009-03-08 02:33 726528 c:\windows\system32\jscript.dll
                  + 2009-03-08 02:22 . 2009-03-08 02:22 164352 c:\windows\system32\ieui.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:31 183808 c:\windows\system32\iepeers.dll
                  + 2001-08-28 12:00 . 2009-04-30 21:16 385536 c:\windows\system32\iedkcs32.dll
                  + 2009-03-08 02:11 . 2009-03-08 02:11 445952 c:\windows\system32\ieapfltr.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\ieakui.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\ieaksie.dll
                  + 2001-08-28 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\ieakeng.dll
                  + 2001-08-28 12:00 . 2009-04-30 11:21 173056 c:\windows\system32\ie4uinit.exe
                  + 2008-07-29 17:24 . 2008-07-29 17:24 622080 c:\windows\system32\icardagt.exe
                  + 2008-02-26 10:08 . 2009-06-24 06:36 117360 c:\windows\system32\FNTCACHE.DAT
                  + 2008-07-29 19:10 . 2008-07-29 19:10 493048 c:\windows\system32\evr.dll
                  + 2001-0
                  1. Tu sais moi j'y connais pas grand chose, alors j'ai fait a tout hasard et j'ai plus de msg d'erreur!!

                    voici le rapport, merci:

                    ComboFix 09-06-22.08 - yannick creusot 24/06/2009 19:07.5 - NTFSx86
                    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.625 [GMT 2:00]
                    Lancé depuis: c:\documents and settings\yannick creusot\Bureau\Combofix.exe
                    AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
                    .

                    ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-24 au 2009-06-24 ))))))))))))))))))))))))))))))))))))
                    .

                    2009-06-24 08:37 . 2009-06-24 08:37 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
                    2009-06-24 06:36 . 2009-06-24 06:36 -------- d-sh--w- c:\documents and settings\yannick creusot\IETldCache
                    2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\windows\system32\XPSViewer
                    2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\program files\MSBuild
                    2009-06-23 22:01 . 2009-06-23 22:01 -------- d-----w- c:\program files\Reference Assemblies
                    2009-06-23 22:00 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
                    2009-06-23 22:00 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
                    2009-06-23 22:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
                    2009-06-23 22:00 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
                    2009-06-23 22:00 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
                    2009-06-23 22:00 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
                    2009-06-23 22:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
                    2009-06-23 21:54 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
                    2009-06-23 21:54 . 2009-06-23 21:54 -------- d-----w- c:\windows\ie8updates
                    2009-06-23 21:53 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
                    2009-06-23 21:53 . 2009-04-30 21:16 1985024 -c----w- c:\windows\system32\dllcache\iertutil.dll
                    2009-06-23 21:53 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
                    2009-06-23 21:53 . 2009-04-30 21:16 11064832 -c----w- c:\windows\system32\dllcache\ieframe.dll
                    2009-06-23 21:52 . 2009-06-23 21:53 -------- dc-h--w- c:\windows\ie8
                    2009-06-23 11:57 . 2009-06-23 11:57 9662 ----a-r- c:\documents and settings\yannick creusot\Application Data\Microsoft\Installer\{1043E281-B080-4947-9BD7-3F1D233BF6D2}\RegistryDefrag.exe
                    2009-06-23 11:47 . 2009-06-23 11:47 -------- dc----w- c:\windows\system32\dllcache\cache
                    2009-06-23 11:29 . 2009-06-23 11:29 -------- d-----w- C:\Rooter$
                    2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Malwarebytes
                    2009-06-22 19:33 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                    2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                    2009-06-22 19:33 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
                    2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                    2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Yahoo!
                    2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
                    2009-06-21 15:51 . 2009-06-21 16:16 -------- d-----w- c:\windows\BDOSCAN8
                    2009-06-21 09:31 . 2009-06-21 13:15 -------- d-----w- c:\documents and settings\yannick creusot\DoctorWeb
                    2009-06-20 19:12 . 2009-06-20 19:12 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
                    2009-06-20 19:10 . 2009-06-22 19:26 -------- d-----w- c:\windows\ERUNT
                    2009-06-20 19:10 . 2009-06-20 19:22 -------- d-----w- C:\Backups
                    2009-06-13 14:33 . 2008-12-11 06:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
                    2009-06-13 14:33 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
                    2009-06-13 14:33 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
                    2009-06-13 14:33 . 2009-06-20 17:35 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                    2009-06-13 14:32 . 2009-06-13 14:34 -------- d-----w- c:\program files\Fichiers communs\PC Tools
                    2009-06-13 14:32 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
                    2009-06-13 14:32 . 2009-06-23 12:00 -------- d-----w- c:\program files\Spyware Doctor
                    2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\PC Tools
                    2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
                    2009-06-11 15:18 . 2009-06-19 12:57 -------- d-----w- c:\program files\Ahead DVD Ripper
                    2009-06-06 14:27 . 2009-06-06 14:27 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
                    2009-06-06 14:27 . 2009-06-06 14:27 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
                    2009-06-06 14:27 . 2009-06-06 14:27 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
                    2009-06-06 14:19 . 2009-06-06 14:27 94643 ----a-w- c:\windows\system32\drivers\klick.dat
                    2009-06-06 14:19 . 2009-06-06 14:27 105395 ----a-w- c:\windows\system32\drivers\klin.dat
                    2009-06-06 14:18 . 2009-06-24 06:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
                    2009-06-06 14:18 . 2009-06-24 02:07 557088 --sha-w- c:\windows\system32\drivers\fidbox2.dat
                    2009-06-06 14:18 . 2009-06-24 02:07 2254368 --sha-w- c:\windows\system32\drivers\fidbox.dat
                    2009-06-06 12:20 . 2009-06-06 19:44 -------- d-----w- c:\program files\Loaris Trojan Remover
                    2009-05-29 17:48 . 2009-05-29 17:48 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
                    2009-05-29 17:48 . 2009-05-29 17:48 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
                    2009-05-29 17:48 . 2009-05-29 17:48 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
                    2009-05-29 17:48 . 2009-05-29 17:48 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
                    2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\MSN6
                    2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
                    2009-05-28 20:38 . 2009-05-28 20:38 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\VitySoft

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2009-06-24 06:36 . 2008-02-26 13:35 18112 ----a-w- c:\documents and settings\yannick creusot\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                    2009-06-24 02:07 . 2009-06-06 14:18 2984 --sha-w- c:\windows\system32\drivers\fidbox2.idx
                    2009-06-24 02:07 . 2009-06-06 14:18 18692 --sha-w- c:\windows\system32\drivers\fidbox.idx
                    2009-06-24 02:05 . 2008-12-13 09:08 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\FrostWire
                    2009-06-23 22:06 . 2001-08-28 12:00 81162 ----a-w- c:\windows\system32\perfc00C.dat
                    2009-06-23 22:06 . 2001-08-28 12:00 501362 ----a-w- c:\windows\system32\perfh00C.dat
                    2009-06-23 18:58 . 2008-03-02 12:40 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\dvdcss
                    2009-06-22 19:29 . 2008-07-28 14:28 -------- d-----w- c:\program files\Yahoo!
                    2009-06-21 08:14 . 2009-06-21 08:14 0 --sh--w- c:\windows\SEA7077AE.tmp
                    2009-06-20 12:43 . 2008-02-26 11:31 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\U3
                    2009-06-20 12:29 . 2008-04-20 11:51 110592 ----a-w- c:\documents and settings\yannick creusot\Application Data\U3\temp\cleanup.exe
                    2009-06-06 14:27 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
                    2009-06-06 14:18 . 2008-02-26 11:46 -------- d-----w- c:\program files\Kaspersky Lab
                    2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                    2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
                    2009-06-06 13:08 . 2009-02-21 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
                    2009-06-06 12:54 . 2009-05-07 19:04 -------- d-----w- c:\program files\ZebHelpProcess
                    2009-06-01 08:04 . 2008-06-13 14:53 -------- d-----w- c:\program files\Google
                    2009-05-13 12:38 . 2009-05-13 12:38 52228 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\nifodiyu.exe
                    2009-05-13 12:38 . 2009-05-13 12:38 88580 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\haditapo.dll
                    2009-05-13 12:38 . 2009-05-13 12:38 52228 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\jevaziji.exe
                    2009-05-13 12:38 . 2009-05-13 12:38 49668 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\kozafuli.dll
                    2009-05-13 12:38 . 2009-05-13 12:38 49668 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\dowuvedo.dll
                    2009-05-13 05:04 . 2001-08-28 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
                    2009-05-11 16:28 . 2008-09-13 13:24 -------- d-----w- c:\program files\Tomtomax Maxi-Box
                    2009-05-08 19:05 . 2009-05-08 19:04 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\vlc
                    2009-05-07 19:04 . 2009-05-07 19:04 -------- d-----w- c:\program files\Fichiers communs\Borland Shared
                    2009-05-07 15:33 . 2001-08-28 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
                    2009-05-04 17:12 . 2008-02-26 14:09 -------- d-----w- c:\program files\CCleaner
                    2009-05-01 17:48 . 2009-05-01 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
                    2009-05-01 17:48 . 2009-05-01 19:11 15688 ----a-w- c:\windows\system32\lsdelete.exe
                    2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
                    2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
                    2009-05-01 17:47 . 2009-05-01 17:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
                    2009-05-01 17:46 . 2008-02-26 14:23 -------- d-----w- c:\program files\Lavasoft
                    2009-04-19 19:50 . 2001-08-28 12:00 1847296 ----a-w- c:\windows\system32\win32k.sys
                    2009-04-15 14:53 . 2008-02-26 12:17 585216 ----a-w- c:\windows\system32\rpcrt4.dll
                    .

                    ((((((((((((((((((((((((((((( SnapShot@2009-06-23_11.45.44 )))))))))))))))))))))))))))))))))))))))))
                    .
                    + 2008-07-29 19:10 . 2008-07-29 19:10 26112 c:\windows\system32\TsWpfWrp.exe
                    + 2008-02-26 13:24 . 2009-01-07 16:21 26144 c:\windows\system32\spupdsvc.exe
                    + 2009-06-23 22:01 . 2008-07-06 12:06 89088 c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
                    + 2009-01-08 21:06 . 2009-01-07 16:21 17952 c:\windows\system32\spmsg.dll
                    + 2008-07-29 17:59 . 2008-07-29 17:59 43544 c:\windows\system32\PresentationHostProxy.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\pngfilt.dll
                    + 2001-08-28 12:00 . 2009-06-23 22:06 67784 c:\windows\system32\perfc009.dat
                    + 2009-01-07 16:20 . 2009-01-07 16:20 23552 c:\windows\system32\normaliz.dll
                    + 2009-01-07 16:20 . 2009-01-07 16:20 24576 c:\windows\system32\nlsdl.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 15360 c:\windows\system32\mui\0409\mscorees.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\mshtmler.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:31 66560 c:\windows\system32\mshtmled.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\mshta.exe
                    + 2009-03-08 02:31 . 2009-03-08 02:31 13312 c:\windows\system32\msfeedssync.exe
                    + 2009-03-08 02:31 . 2009-03-08 02:31 55296 c:\windows\system32\msfeedsbs.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 83968 c:\windows\system32\mscories.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:34 43008 c:\windows\system32\licmgr10.dll
                    + 2001-08-28 12:00 . 2009-04-30 21:16 25600 c:\windows\system32\jsproxy.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\inseng.dll
                    + 2008-07-29 17:24 . 2008-07-29 17:24 97800 c:\windows\system32\infocardapi.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\imgutil.dll
                    + 2009-03-08 02:32 . 2009-03-08 02:32 36864 c:\windows\system32\ieudinit.exe
                    + 2001-08-28 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\iesetup.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\iernonce.dll
                    + 2009-01-07 16:20 . 2009-01-07 16:20 26112 c:\windows\system32\idndl.dll
                    + 2008-07-29 17:24 . 2008-07-29 17:24 11264 c:\windows\system32\icardres.dll
                    + 2009-03-08 02:31 . 2009-03-08 02:31 59904 c:\windows\system32\icardie.dll
                    + 2008-07-29 19:10 . 2008-07-29 19:10 73720 c:\windows\system32\dxva2.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 30749 c:\windows\system32\dllcache\vbajet32.dll
                    + 2004-08-19 23:09 . 2007-03-28 12:53 16384 c:\windows\system32\dllcache\tcptsat.dll
                    + 2004-08-19 23:10 . 2008-04-14 02:34 32827 c:\windows\system32\dllcache\tcptest.exe
                    + 2001-08-28 12:00 . 2008-04-14 02:33 25600 c:\windows\system32\dllcache\slayerxp.dll
                    + 2004-08-19 23:10 . 2008-04-14 02:34 16437 c:\windows\system32\dllcache\shtml.exe
                    + 2004-08-19 23:09 . 2008-04-14 02:33 20536 c:\windows\system32\dllcache\shtml.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 65024 c:\windows\system32\dllcache\shimeng.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:34 78848 c:\windows\system32\dllcache\sdbinst.exe
                    + 2001-08-28 12:00 . 2008-04-14 02:33 64000 c:\windows\system32\dllcache\samlib.dll
                    + 2009-06-23 18:20 . 2001-08-23 15:46 66048 c:\windows\system32\dllcache\s3legacy.dll
                    + 2009-03-08 02:31 . 2009-03-08 02:31 46592 c:\windows\system32\dllcache\pngfilt.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 84992 c:\windows\system32\dllcache\olepro32.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 77824 c:\windows\system32\dllcache\oledb32r.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 20511 c:\windows\system32\dllcache\odtext32.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 20510 c:\windows\system32\dllcache\odpdx32.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 20510 c:\windows\system32\dllcache\odfox32.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 20510 c:\windows\system32\dllcache\odexl32.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 20511 c:\windows\system32\dllcache\oddbse32.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:32 61471 c:\windows\system32\dllcache\odbcji32.dll
                    + 2001-08-28 12:00 . 2007-03-28 12:56 98304 c:\windows\system32\dllcache\odbcint.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 65536 c:\windows\system32\dllcache\odbccu32.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 65536 c:\windows\system32\dllcache\odbccr32.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:34 69632 c:\windows\system32\dllcache\odbcconf.exe
                    + 2001-08-28 12:00 . 2008-04-14 02:34 32768 c:\windows\system32\dllcache\odbcad32.exe
                    + 2001-08-28 12:00 . 2008-04-14 02:33 16384 c:\windows\system32\dllcache\odbc32gt.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 69632 c:\windows\system32\dllcache\ocmanage.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 10240 c:\windows\system32\dllcache\npwmsdrm.dll
                    - 2008-10-24 21:22 . 2008-04-14 02:33 10240 c:\windows\system32\dllcache\npwmsdrm.dll
                    + 2001-08-28 12:00 . 2008-04-13 19:20 91520 c:\windows\system32\dllcache\ndiswan.sys
                    + 2008-02-26 10:19 . 2008-04-14 02:33 24576 c:\windows\system32\dllcache\msxactps.dll
                    + 2001-08-28 12:00 . 2008-04-13 18:30 61440 c:\windows\system32\dllcache\msvcrt40.dll
                    + 2001-08-28 12:00 . 2008-03-25 04:50 60192 c:\windows\system32\dllcache\msjter40.dll
                    - 2008-03-25 04:50 . 2008-03-25 04:50 60192 c:\windows\system32\dllcache\msjter40.dll
                    + 2009-03-08 02:31 . 2009-03-08 02:31 48128 c:\windows\system32\dllcache\mshtmler.dll
                    + 2009-03-08 02:31 . 2009-03-08 02:31 66560 c:\windows\system32\dllcache\mshtmled.dll
                    + 2009-03-08 02:31 . 2009-03-08 02:31 45568 c:\windows\system32\dllcache\mshta.exe
                    + 2008-02-26 10:19 . 2008-04-14 02:33 36864 c:\windows\system32\dllcache\msdfmap.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 20480 c:\windows\system32\dllcache\msdatt.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msdasqlr.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msdaremr.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msdaprsr.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 77824 c:\windows\system32\dllcache\msdaosp.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 36864 c:\windows\system32\dllcache\mscpxl32.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 57344 c:\windows\system32\dllcache\msadrh15.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 57344 c:\windows\system32\dllcache\msador15.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 28672 c:\windows\system32\dllcache\msader15.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 24576 c:\windows\system32\dllcache\msaddsr.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 53248 c:\windows\system32\dllcache\msadcs.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msadcor.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 16384 c:\windows\system32\dllcache\msadcfr.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 61440 c:\windows\system32\dllcache\msadcf.dll
                    + 2008-02-26 10:19 . 2007-03-28 12:56 20480 c:\windows\system32\dllcache\msadcer.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 22528 c:\windows\system32\dllcache\mfcsubs.dll
                    + 2009-03-08 02:34 . 2009-03-08 02:34 43008 c:\windows\system32\dllcache\licmgr10.dll
                    + 2001-08-28 12:00 . 2009-04-30 21:16 25600 c:\windows\system32\dllcache\jsproxy.dll
                    + 2001-08-28 12:00 . 2008-04-13 19:19 75264 c:\windows\system32\dllcache\ipsec.sys
                    + 2009-03-08 02:32 . 2009-03-08 02:32 94720 c:\windows\system32\dllcache\inseng.dll
                    + 2009-03-08 02:31 . 2009-03-08 02:31 34816 c:\windows\system32\dllcache\imgutil.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 36921 c:\windows\system32\dllcache\imeshare.dll
                    + 2009-03-08 02:32 . 2009-03-08 02:32 71680 c:\windows\system32\dllcache\iesetup.dll
                    + 2009-03-08 02:32 . 2009-03-08 02:32 55808 c:\windows\system32\dllcache\iernonce.dll
                    + 2009-03-08 02:24 . 2009-03-08 02:24 68608 c:\windows\system32\dllcache\hmmapi.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:34 20538 c:\windows\system32\dllcache\fpremadm.exe
                    + 2004-08-19 23:09 . 2008-04-14 02:33 20541 c:\windows\system32\dllcache\fpexedll.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:34 15120 c:\windows\system32\dllcache\fp98sadm.exe
                    + 2004-08-19 23:09 . 2008-04-14 02:33 49212 c:\windows\system32\dllcache\fp4awebs.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 32826 c:\windows\system32\dllcache\fp4avss.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 41020 c:\windows\system32\dllcache\fp4avnb.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 49210 c:\windows\system32\dllcache\fp4areg.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 82035 c:\windows\system32\dllcache\fp4anscp.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 16384 c:\windows\system32\dllcache\ds32gt.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 32768 c:\windows\system32\dllcache\dispex.dll
                    + 2008-10-24 21:22 . 2008-04-14 02:33 39936 c:\windows\system32\dllcache\dimsroam.dll
                    + 2008-10-24 21:22 . 2008-04-14 02:33 19456 c:\windows\system32\dllcache\dimsntfy.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 62464 c:\windows\system32\dllcache\cryptsvc.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 64512 c:\windows\system32\dllcache\cryptnet.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 54784 c:\windows\system32\dllcache\cryptext.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 33280 c:\windows\system32\dllcache\cryptdll.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 75776 c:\windows\system32\dllcache\cryptdlg.dll
                    + 2009-03-08 02:33 . 2009-03-08 02:33 18944 c:\windows\system32\dllcache\corpol.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:31 16896 c:\windows\system32\dllcache\cfgmgr32.dll
                    + 2009-06-23 11:47 . 2008-10-16 13:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
                    + 2009-06-23 11:47 . 2008-04-14 02:33 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
                    + 2009-06-23 11:47 . 2008-04-14 02:34 26624 c:\windows\system32\dllcache\cache\userinit.exe
                    + 2009-06-23 11:47 . 2008-04-14 02:34 14336 c:\windows\system32\dllcache\cache\svchost.exe
                    + 2009-06-23 11:47 . 2008-04-14 02:34 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
                    + 2009-06-23 11:47 . 2008-04-14 02:33 17408 c:\windows\system32\dllcache\cache\powrprof.dll
                    + 2009-06-23 11:47 . 2008-04-14 02:34 13312 c:\windows\system32\dllcache\cache\lsass.exe
                    + 2009-06-23 11:47 . 2008-04-14 02:05 25216 c:\windows\system32\dllcache\cache\kbdclass.sys
                    + 2009-06-23 11:47 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
                    + 2009-06-23 11:47 . 2008-04-14 02:33 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
                    + 2004-08-19 23:09 . 2008-04-14 02:33 16439 c:\windows\system32\dllcache\author.exe
                    + 2004-08-19 23:09 . 2008-04-14 02:33 20540 c:\windows\system32\dllcache\author.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 30208 c:\windows\system32\dllcache\atmlib.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 65024 c:\windows\system32\dllcache\asycfilt.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 98304 c:\windows\system32\dllcache\ahui.exe
                    + 2008-10-24 21:21 . 2007-04-02 18:25 19456 c:\windows\system32\dllcache\agt0401.dll
                    + 2004-08-04 06:07 . 2008-04-13 18:36 44928 c:\windows\system32\dllcache\agpcpq.sys
                    + 2004-08-04 06:07 . 2008-04-13 18:36 42368 c:\windows\system32\dllcache\agp440.sys
                    + 2001-08-28 12:00 . 2008-04-14 02:33 44032 c:\windows\system32\dllcache\agentsr.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 24064 c:\windows\system32\dllcache\agentpsh.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 49152 c:\windows\system32\dllcache\agentmpx.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 57344 c:\windows\system32\dllcache\agentdpv.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 42496 c:\windows\system32\dllcache\agentdp2.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 24064 c:\windows\system32\dllcache\agentanm.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 68096 c:\windows\system32\dllcache\adsmsext.dll
                    + 2009-06-23 18:20 . 2001-08-17 18:11 46112 c:\windows\system32\dllcache\adptsf50.sys
                    + 2001-08-28 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\dllcache\admparse.dll
                    + 2009-06-23 18:20 . 2004-08-04 05:32 10880 c:\windows\system32\dllcache\admjoy.sys
                    + 2004-08-19 23:09 . 2008-04-14 02:33 16439 c:\windows\system32\dllcache\admin.exe
                    + 2004-08-19 23:09 . 2008-04-14 02:33 20540 c:\windows\system32\dllcache\admin.dll
                    + 2009-06-23 18:20 . 2001-08-17 18:11 20160 c:\windows\system32\dllcache\adm8511.sys
                    + 2001-08-28 12:00 . 2008-04-14 02:33 98304 c:\windows\system32\dllcache\actxprxy.dll
                    + 2001-08-28 12:00 . 2001-08-28 12:00 12032 c:\windows\system32\dllcache\acpiec.sys
                    + 2009-06-23 18:20 . 2001-08-23 15:46 61952 c:\windows\system32\dllcache\acerscad.dll
                    + 2008-02-26 10:19 . 2001-08-28 12:00 72192 c:\windows\system32\dllcache\acctres.dll
                    + 2009-06-23 18:20 . 2004-08-04 05:32 84480 c:\windows\system32\dllcache\ac97via.sys
                    + 2009-06-23 18:20 . 2001-08-17 18:20 96256 c:\windows\system32\dllcache\ac97intc.sys
                    + 2009-06-23 18:20 . 2001-08-17 19:52 23552 c:\windows\system32\dllcache\abp480n5.sys
                    + 2009-06-23 18:20 . 2001-08-23 15:46 98304 c:\windows\system32\dllcache\a3d.dll
                    + 2009-06-23 18:20 . 2001-08-23 15:46 38400 c:\windows\system32\dllcache\8514a.dll
                    + 2009-06-23 18:20 . 2008-04-13 18:46 48128 c:\windows\system32\dllcache\61883.sys
                    + 2009-06-23 18:20 . 2008-04-13 18:40 12288 c:\windows\system32\dllcache\4mmdat.sys
                    + 2009-06-23 18:20 . 2001-08-17 20:06 11264 c:\windows\system32\dllcache\1394vdbg.sys
                    + 2001-08-28 12:00 . 2008-04-13 18:46 53376 c:\windows\system32\dllcache\1394bus.sys
                    + 2008-07-25 09:16 . 2008-07-25 09:16 96760 c:\windows\system32\dfshim.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\corpol.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\admparse.dll
                    + 2008-07-29 21:40 . 2008-07-29 21:40 70648 c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
                    + 2008-07-29 21:40 . 2008-07-29 21:40 91136 c:\windows\Microsoft.NET\Framework\v3.5\MSBuild.exe
                    + 2008-07-29 21:40 . 2008-07-29 21:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.VisualC.STLCLR.dll
                    + 2008-07-29 21:40 . 2008-07-29 21:40 40960 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Data.Entity.Build.Tasks.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 89080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2052.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 92664 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1042.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 95224 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1041.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 89592 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1028.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 84480 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2052.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 94720 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1042.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 97792 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1041.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 84992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1028.dll
                    + 2008-07-29 16:47 . 2008-07-29 16:47 97280 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe
                    + 2008-07-29 21:40 . 2008-07-29 21:40 95224 c:\windows\Microsoft.NET\Framework\v3.5\EdmGen.exe
                    + 2008-07-29 21:40 . 2008-07-29 21:40 78856 c:\windows\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe
                    + 2008-07-29 21:40 . 2008-07-29 21:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
                    + 2008-07-29 21:40 . 2008-07-29 21:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess32.exe
                    + 2008-07-29 21:40 . 2008-07-29 21:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess.exe
                    + 2008-07-29 19:10 . 2008-07-29 19:10 46104 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
                    + 2008-07-29 17:59 . 2008-07-29 17:59 32768 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
                    + 2008-07-29 19:10 . 2008-07-29 19:10 71160 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
                    + 2008-07-29 17:32 . 2008-07-29 17:32 17448 c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
                    + 2008-07-29 17:16 . 2008-07-29 17:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
                    + 2008-07-29 17:16 . 2008-07-29 17:16 73728 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
                    + 2008-07-29 17:16 . 2008-07-29 17:16 20504 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
                    + 2008-07-29 17:16 . 2008-07-29 17:16 11280 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 37896 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 81400 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
                    + 2008-07-25 09:17 . 2008-07-25 09:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 57392 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 95232 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 61952 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
                    - 2005-09-23 06:28 . 2005-09-23 06:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                    + 2008-07-25 09:17 . 2008-07-25 09:17 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                    + 2008-07-25 09:17 . 2008-07-25 09:17 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
                    - 2005-09-23 06:28 . 2005-09-23 06:28 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
                    + 2008-07-25 09:17 . 2008-07-25 09:17 88584 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 24584 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 31744 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 19456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 77312 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 94208 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 46592 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 97792 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
                    - 2005-09-23 06:28 . 2005-09-23 06:28 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
                    - 2005-09-23 06:28 . 2005-09-23 06:28 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 65032 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
                    - 2005-09-23 06:28 . 2005-09-23 06:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
                    + 2008-07-25 09:17 . 2008-07-25 09:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 18936 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 62968 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 35320 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
                    + 2008-07-25 09:17 . 2008-07-25 09:17 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 27136 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 80376 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
                    + 2008-07-25 09:17 . 2008-07-25 09:17 89608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
                    + 2008-11-25 02:59 . 2008-11-25 02:59 31560 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 34312 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 33288 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 24576 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 33800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 17416 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 22024 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
                    + 2008-07-25 09:17 . 2008-07-25 09:17 58880 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 98808 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 96768 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 16896 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 82944 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
                    + 2009-06-23 21:54 . 2009-03-08 02:33 12288 c:\windows\ie8updates\KB969897-IE8\xpshims.dll
                    + 2009-06-23 21:54 . 2009-03-08 02:33 25600 c:\windows\ie8updates\KB969897-IE8\jsproxy.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 37888 c:\windows\ie8\url.dll
                    + 2009-06-23 21:53 . 2009-03-08 14:14 58448 c:\windows\ie8\spuninst\iecustom.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 39424 c:\windows\ie8\pngfilt.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 97280 c:\windows\ie8\occache.dll
                    + 2009-06-23 21:52 . 2008-04-14 01:56 57344 c:\windows\ie8\mshtmler.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:34 29184 c:\windows\ie8\mshta.exe
                    + 2009-06-23 21:52 . 2008-04-14 02:33 22528 c:\windows\ie8\licmgr10.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 15872 c:\windows\ie8\jsproxy.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 96768 c:\windows\ie8\inseng.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 35840 c:\windows\ie8\imgutil.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:34 93184 c:\windows\ie8\iexplore.exe
                    + 2009-06-23 21:52 . 2008-04-14 02:33 63488 c:\windows\ie8\iesetup.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 49152 c:\windows\ie8\iernonce.dll
                    + 2009-06-23 21:52 . 2009-04-29 04:34 81920 c:\windows\ie8\ieencode.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:34 34304 c:\windows\ie8\ie4uinit.exe
                    + 2009-06-23 21:52 . 2008-04-14 02:33 38912 c:\windows\ie8\hmmapi.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 35328 c:\windows\ie8\corpol.dll
                    + 2009-06-23 21:52 . 2008-04-14 02:33 61440 c:\windows\ie8\admparse.dll
                    + 2009-06-23 22:00 . 2008-07-06 12:06 89088 c:\windows\Driver Cache\i386\filterpipelineprintproc.dll
                    + 2009-06-23 22:09 . 2009-06-23 22:09 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\a715aa442ef87ae99b3ade185599249d\UIAutomationProvider.ni.dll
                    + 2009-06-23 22:14 . 2009-06-23 22:14 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\423f794d1f4ed6e120fbb02e436491cb\System.Windows.Presentation.ni.dll
                    + 2009-06-23 22:14 . 2009-06-23 22:14 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\19ca1747c1ea18a3b639b302bca8df93\System.Web.DynamicData.Design.ni.dll
                    + 2009-06-23 22:13 . 2009-06-23 22:13 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\532438e2acfcadc469a4d468c51f8451\System.ComponentModel.DataAnnotations.ni.dll
                    + 2009-06-23 22:13 . 2009-06-23 22:13 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\597b20e1b053d6a510cfe033c07a63e6\System.AddIn.Contract.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 44032 c:\windows\assembly\NativeImages_v2.0.50727_32\stdole\9e987e971bf109c3698b7549e744005d\stdole.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 29184 c:\windows\assembly\NativeImages_v2.0.50727_32\SFMARKETLib\540c717be45888cd43141de5a88a1267\SFMARKETLib.ni.dll
                    + 2009-06-23 22:08 . 2009-06-23 22:08 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\2d7408a0232f2e2efd0d7adf5dfa733a\PresentationFontCache.ni.exe
                    + 2009-06-23 22:07 . 2009-06-23 22:07 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\c8fd2d9233f8ea3031fb16f697635231\PresentationCFFRasterizer.ni.dll
                    + 2009-06-23 22:13 . 2009-06-23 22:13 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\790cf1edb17ee41b59be62ecbd59613b\Microsoft.Vsa.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\ec83ec80653eb20ccc6ed42075c90aee\Microsoft.VisualC.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e9aba2eab90d647356f65e66053da02b\Microsoft.Build.Framework.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\28343d470d992f169ca0e7cdb3cc3117\Microsoft.Build.Framework.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.QTOControlL#\55682b329733421a87a3daffe1ec9819\Interop.QTOControlLib.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 76800 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.PortableDev#\f345d88e73e3780f3efde7572fe52a21\Interop.PortableDeviceTypesLib.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 77312 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.PortableDev#\2cb1b2476271a4e8ff3151f9b903285a\Interop.PortableDeviceApiLib.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 35328 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.CDDBUICONTR#\09da0d6c60de188515e99d8d2f26752b\Interop.CDDBUICONTROLLibSMS.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 72192 c:\windows\assembly\NativeImages_v2.0.50727_32\Interop.CDDBLINKLib#\dc2e912d6c4103336c5f3e0834452df5\Interop.CDDBLINKLibSMS.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 31744 c:\windows\assembly\NativeImages_v2.0.50727_32\Interfaces\f3c8bc6c484801a2e21e453c4dad5a98\Interfaces.ni.dll
                    + 2009-06-23 22:12 . 2009-06-23 22:12 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\f4e38208e88cb4cc314a1d6543b9fcc6\dfsvc.ni.exe
                    + 2009-06-23 22:12 . 2009-06-23 22:12 59904 c:\windows\assembly\NativeImages_v2.0.50727_32\AxInterop.QTOContro#\8486f1815d34f3016941a970a9bf0168\AxInterop.QTOControlLib.ni.dll
                    + 2009-06-23 22:11 . 2009-06-23 22:11 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\11eb4f6606ba01e5128805759121ea6c\Accessibility.ni.dll
                    + 2009-06-23 22:01 . 2009-06-23 22:01 94208 c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
                    + 2009-06-23 22:01 . 2009-06-23 22:01 98304 c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
                    + 2009-06-23 22:01 . 2009-06-23 22:01 40960 c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 12288 c:\windows\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 61440 c:\windows\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 32768 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 77824 c:\windows\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
                    + 2009-06-23 22:01 . 2009-06-23 22:01 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
                    + 2009-06-23 22:01 . 2009-06-23 22:01 73728 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 53248 c:\windows\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 57344 c:\windows\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 45056 c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
                    + 2009-06-23 22:01 . 2009-06-23 22:01 46104 c:\windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
                    + 2009-06-23 22:01 . 2009-06-23 22:01 32768 c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 41984 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 94208 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
                    - 2009-01-16 10:38 . 2009-01-16 10:38 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:33 5120 c:\windows\system32\dllcache\sfc.dll
                    + 2008-02-26 12:39 . 2004-08-02 13:20 4569 c:\windows\system32\dllcache\secupd.dat
                    - 2008-10-24 21:22 . 2008-04-14 02:31 4126 c:\windows\system32\dllcache\msdxmlc.dll
                    + 2001-08-28 12:00 . 2008-04-14 02:31 4126 c:\windows\system32\dllcache\msdxmlc.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdaurl.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdasc.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdaer.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdaenum.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\msdadc.dll
                    + 2008-02-26 10:19 . 2008-04-14 02:34 4639 c:\windows\system32\dllcache\mplayer2.exe
                    - 2008-10-24 21:22 . 2008-04-14 02:34 4639 c:\windows\system32\dllcache\mplayer2.exe
                    + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdpash.dll
                    + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdnepr.dll
                    + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdiultn.dll
                    + 2008-10-24 21:22 . 2008-04-14 02:31 6144 c:\windows\system32\dllcache\kbdbhc.dll
                    + 2008-10-24 21:22 . 2008-04-14 02:33 7168 c:\windows\system32\dllcache\bitsprx4.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 3775 c:\windows\system32\dllcache\adv11nt5.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 3711 c:\windows\system32\dllcache\adv09nt5.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 3135 c:\windows\system32\dllcache\adv08nt5.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 3647 c:\windows\system32\dllcache\adv07nt5.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 3615 c:\windows\system32\dllcache\adv05nt5.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 3967 c:\windows\system32\dllcache\adv02nt5.dll
                    + 2004-08-19 23:09 . 2008-04-14 02:33 4255 c:\windows\system32\dllcache\adv01nt5.dll
                    + 2009-06-23 18:20 . 2001-08-17 19:53 7424 c:\windows\system32\dllcache\adicvls.sys
                    + 2001-08-28 12:00 . 2008-04-14 02:33 4096 c:\windows\system32\dllcache\actmovie.exe
                    + 2008-07-29 21:40 . 2008-07-29 21:40 5632 c:\windows\Microsoft.NET\Framework\v3.5\Sentinel.v3.5Client.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
                    - 2005-09-23 06:29 . 2005-09-23 06:29 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 6656 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
                    - 2005-09-23 06:28 . 2005-09-23 06:28 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
                    - 2005-09-23 06:28 . 2005-09-23 06:28 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
                    + 2008-07-25 09:16 . 2008-07-25 09:16 5120 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
                    + 2009-06-23 21:55 . 2009-03-08 02:35 2048 c:\windows\ie8updates\KB971930-IE8\iecompat.dll
                    + 2009-06-23 22:02 . 2009-06-23 22:02 5632 c:\windows\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                    - 2009-01-16 10:38 . 2009-01-16 10:38 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
                    - 2009-01-16 10:38 . 2009-01-16 10:38 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                    + 2009-06-23 22:05 . 2009-06-23 22:05 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
                    - 2009-01-16 10:37 . 2009-01-16 10:37 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                    + 2009-06-23 22:06 . 2009-06-23 22:06 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 635904 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 558080 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll
                    + 2008-07-25 09:17 . 2008-07-25 09:17 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcm80.dll
                    + 2008-07-29 19:26 . 2008-07-29 19:26 301568 c:\windows\system32\XPSViewer\XPSViewer.exe
                    - 2008-10-24 21:23 . 2008-04-14 02:33 121856 c:\windows\system32\xmllite.dll
                    + 2008-10-24 21:23 . 2009-01-07 16:21 121856 c:\windows\system32\xmllite.dll
                    + 2009-03-08 02:34 . 2009-03-08 02:34 208384 c:\windows\system32\WinFXDocObj.exe
                    + 2001-08-28 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\webcheck.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:33 420352 c:\windows\system32\vbscript.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:34 105984 c:\windows\system32\url.dll
                    + 2008-07-29 17:59 . 2008-07-29 17:59 161296 c:\windows\system32\UIAutomationCore.dll
                    + 2009-06-23 22:01 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\mxdwdrv.dll
                    + 2009-06-23 22:01 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\i386\mxdwdrv.dll
                    + 2009-06-23 22:01 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\mxdwdrv.dll
                    + 2009-06-23 22:01 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\amd64\mxdwdrv.dll
                    + 2009-06-23 22:01 . 2008-07-06 12:06 147456 c:\windows\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
                    + 2009-06-23 22:00 . 2008-07-06 10:50 597504 c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
                    + 2009-06-23 22:00 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\3\unires.dll
                    + 2009-06-23 22:00 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
                    + 2009-06-23 22:00 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
                    + 2009-06-23 22:00 . 2008-07-06 12:06 198656 c:\windows\system32\spool\drivers\w32x86\3\mxdwdui.dll
                    + 2009-06-23 22:00 . 2008-07-06 12:06 765440 c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
                    + 2006-08-24 14:15 . 2006-08-24 14:15 150808 c:\windows\system32\rgb9rast_2.dll
                    + 2008-07-29 17:59 . 2008-07-29 17:59 781344 c:\windows\system32\PresentationNative_v0300.dll
                    + 2008-07-29 18:35 . 2008-07-29 18:35 326160 c:\windows\system32\PresentationHost.exe
                    + 2008-07-29 17:59 . 2008-07-29 17:59 105016 c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
                    + 2001-08-28 12:00 . 2009-06-23 22:06 432932 c:\windows\system32\perfh009.dat
                    + 2001-08-28 12:00 . 2009-03-08 02:34 109568 c:\windows\system32\occache.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:32 611840 c:\windows\system32\mstime.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\msrating.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\msls31.dll
                    + 2009-03-08 02:32 . 2009-03-08 02:32 594432 c:\windows\system32\msfeeds.dll
                    + 2009-01-07 16:20 . 2009-01-07 16:20 265720 c:\windows\system32\msdbg2.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 158720 c:\windows\system32\mscorier.dll
                    + 2008-07-25 09:16 . 2008-07-25 09:16 282112 c:\windows\system32\mscoree.dll
                    + 2003-01-13 13:57 . 2009-03-08 02:33 726528 c:\windows\system32\jscript.dll
                    + 2009-03-08 02:22 . 2009-03-08 02:22 164352 c:\windows\system32\ieui.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:31 183808 c:\windows\system32\iepeers.dll
                    + 2001-08-28 12:00 . 2009-04-30 21:16 385536 c:\windows\system32\iedkcs32.dll
                    + 2009-03-08 02:11 . 2009-03-08 02:11 445952 c:\windows\system32\ieapfltr.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\ieakui.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\ieaksie.dll
                    + 2001-08-28 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\ieakeng.dll
                    + 2001-08-28 12:00 . 2009-04-30 11:21 173056 c:\windows\system32\ie4uinit.exe
                    + 2008-07-29 17:24 . 2008-07-29 17:24 622080 c:\windows\system32\icardagt.exe
                    + 2008-02-26 10:08 . 2009-06-24 06:36 117360 c:\windows\system32\FNTCACHE.DAT
                    + 2008-07-29 19:10 . 2008-07-29 19:10 493048 c:\windows\system32\e
                    1. Tu sais c'est pas un utilitaire de chez Windows qui va te virer une infection Vundo !

                      1. J'en ai parlé à un pote et il m'a conseillé win xp manager

                        je vais faire on combofix et je post
                        1. "on m'a conseillé..."

                          euh c'est qui le ON ? tu te faisais aidé en parallele ????

                          Fait le script combofix !

                          1. Bonjour

                            On m'a conseillé WinXP manager. Je l'ai installé et fait le nettoyage et depuis je n'ai plus ces msg au demarrage.
                            Merci de ton aide pour essayer de tout eliminer
                            Quel scan puis je utiliser pour etre sur d'etre desinfecter.
                            Bonne journée
                            1. Créer un doc texte sur ton bureau :

                              pointe ta souris sur ton bureau , clique droit : va dans "nouveau" et choisis "document texte" .

                              Ensuite copie/colle le texte ci-dessous ( et rien d'autre!) dans le fichier texte que tu viens de créer :

                              File::
                              c:\windows\system32\drivers\klick.dat
                              c:\windows\system32\drivers\klin.dat
                              c:\documents and settings\yannick creusot\Application Data\U3\temp\cleanup.exe
                              :\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\nifodiyu.exe
                              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\haditapo.dll
                              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\jevaziji.exe
                              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\kozafuli.dll
                              c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\dowuvedo.dll

                              Puis va dans "fichier" et choisis "enregistrer sous ..." et tu le nommes exactement ainsi :
                              CFScript puis valide ...

                              * Nettoyage :

                              !! Déconnecte toi, ferme toutes tes applications et désactive TOUTES TES DEFENSES ( tu les réactiveras après ) !!

                              --->Sur ton bureau, fais glisser avec ta souris le fichier CFScript sur l'icône de ComboFix.exe .

                              (Regarde ici : http://img.photobucket.com/albums/v666/sUBs/CFScript.gif )

                              Cette manipulation va relancer combofix .
                              --> Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tape 1 puis valide.

                              Puis patiente le temps du scan.( Le Bureau va disparaître à plusieurs reprises : c'est normal!)

                              !! Ne touches à rien tant que le scan n'est pas terminé !!

                              Note : en fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                              Une fois le scan achevé, un rapport va s'afficher : poste le pour analyse ...

                              ( Attention : cette manipe a été faite pour ce PC . Toute réutilisation peut endommager sévèrement le système d'exploitation )

                              Ensuite :

                              rends toi ici : https://www.virustotal.com/gui/

                              clique sur parcourir et choisi ce fichier : c:\windows\system32\drivers\fidbox2.dat

                              clique sur envoyer et poste le rapport.

                              Fait de meme pour ces fichiers : c:\windows\system32\drivers\fidbox.dat
                              c:\windows\SEA7077AE.tmp

                              1. voici le rapport combo.fix mais tjrs pareil au demarrage
                                "erreur de chargement de C:\windows\system32\Ribemago.dll ou
                                Kozezupo.dll - le module specifié est introuvable"

                                rapport:
                                ComboFix 09-06-22.08 - yannick creusot 23/06/2009 13:41.4 - NTFSx86
                                Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.537 [GMT 2:00]
                                Lancé depuis: c:\documents and settings\yannick creusot\Bureau\Combofix.exe
                                AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
                                .

                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrd18.~lk\0.mdd
                                c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrd18.~lk\1.mdd
                                c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrd18.~lk\2.mdd
                                c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrd18.~lk\3.mdd
                                c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrd18.~lk\4.mdd
                                c:\docume~1\YANNIC~1\LOCALS~1\Temp\wrd18.~lk\5.mdd
                                c:\documents and settings\yannick creusot\Local Settings\temp\wrd18.~lk\0.mdd
                                c:\documents and settings\yannick creusot\Local Settings\temp\wrd18.~lk\1.mdd
                                c:\documents and settings\yannick creusot\Local Settings\temp\wrd18.~lk\2.mdd
                                c:\documents and settings\yannick creusot\Local Settings\temp\wrd18.~lk\3.mdd
                                c:\documents and settings\yannick creusot\Local Settings\temp\wrd18.~lk\4.mdd
                                c:\documents and settings\yannick creusot\Local Settings\temp\wrd18.~lk\5.mdd
                                c:\windows\system32\drivers\kl1.sys

                                .
                                ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-23 au 2009-06-23 ))))))))))))))))))))))))))))))))))))
                                .

                                2009-06-23 11:29 . 2009-06-23 11:29 -------- d-----w- C:\Rooter$
                                2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Malwarebytes
                                2009-06-22 19:33 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                                2009-06-22 19:33 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
                                2009-06-22 19:33 . 2009-06-22 19:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\Yahoo!
                                2009-06-22 19:29 . 2009-06-22 19:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
                                2009-06-21 15:51 . 2009-06-21 16:16 -------- d-----w- c:\windows\BDOSCAN8
                                2009-06-21 09:31 . 2009-06-21 13:15 -------- d-----w- c:\documents and settings\yannick creusot\DoctorWeb
                                2009-06-20 19:12 . 2009-06-20 19:12 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
                                2009-06-20 19:10 . 2009-06-22 19:26 -------- d-----w- c:\windows\ERUNT
                                2009-06-20 19:10 . 2009-06-20 19:22 -------- d-----w- C:\Backups
                                2009-06-13 14:33 . 2008-12-11 06:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
                                2009-06-13 14:33 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
                                2009-06-13 14:33 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
                                2009-06-13 14:33 . 2009-06-20 17:35 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                                2009-06-13 14:32 . 2009-06-13 14:34 -------- d-----w- c:\program files\Fichiers communs\PC Tools
                                2009-06-13 14:32 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
                                2009-06-13 14:32 . 2009-06-20 07:28 -------- d-----w- c:\program files\Spyware Doctor
                                2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\PC Tools
                                2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
                                2009-06-11 15:18 . 2009-06-19 12:57 -------- d-----w- c:\program files\Ahead DVD Ripper
                                2009-06-06 14:27 . 2009-06-06 14:27 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
                                2009-06-06 14:27 . 2009-06-06 14:27 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
                                2009-06-06 14:27 . 2009-06-06 14:27 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
                                2009-06-06 14:19 . 2009-06-06 14:27 94643 ----a-w- c:\windows\system32\drivers\klick.dat
                                2009-06-06 14:19 . 2009-06-06 14:27 105395 ----a-w- c:\windows\system32\drivers\klin.dat
                                2009-06-06 14:18 . 2009-06-23 11:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
                                2009-06-06 14:18 . 2009-06-23 11:44 548896 --sha-w- c:\windows\system32\drivers\fidbox2.dat
                                2009-06-06 14:18 . 2009-06-23 11:44 2254368 --sha-w- c:\windows\system32\drivers\fidbox.dat
                                2009-06-06 12:20 . 2009-06-06 19:44 -------- d-----w- c:\program files\Loaris Trojan Remover
                                2009-05-29 17:48 . 2009-05-29 17:48 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
                                2009-05-29 17:48 . 2009-05-29 17:48 83808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
                                2009-05-29 17:48 . 2009-05-29 17:48 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
                                2009-05-29 17:48 . 2009-05-29 17:48 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
                                2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\MSN6
                                2009-05-29 17:20 . 2009-05-29 17:20 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
                                2009-05-28 20:38 . 2009-05-28 20:38 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\VitySoft

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2009-06-23 11:44 . 2009-06-06 14:18 2956 --sha-w- c:\windows\system32\drivers\fidbox2.idx
                                2009-06-23 11:44 . 2009-06-06 14:18 18692 --sha-w- c:\windows\system32\drivers\fidbox.idx
                                2009-06-22 19:29 . 2008-07-28 14:28 -------- d-----w- c:\program files\Yahoo!
                                2009-06-22 19:26 . 2009-05-08 07:24 -------- d-----w- c:\program files\Trend Micro
                                2009-06-21 08:14 . 2009-06-21 08:14 0 --sh--w- c:\windows\SEA7077AE.tmp
                                2009-06-20 12:43 . 2008-02-26 11:31 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\U3
                                2009-06-20 12:29 . 2008-04-20 11:51 110592 ----a-w- c:\documents and settings\yannick creusot\Application Data\U3\temp\cleanup.exe
                                2009-06-20 07:31 . 2008-12-13 09:08 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\FrostWire
                                2009-06-09 15:40 . 2008-03-02 12:40 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\dvdcss
                                2009-06-06 14:27 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
                                2009-06-06 14:18 . 2008-02-26 11:46 -------- d-----w- c:\program files\Kaspersky Lab
                                2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                                2009-06-06 13:24 . 2008-02-26 14:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
                                2009-06-06 13:08 . 2009-02-21 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
                                2009-06-06 12:54 . 2009-05-07 19:04 -------- d-----w- c:\program files\ZebHelpProcess
                                2009-06-01 08:04 . 2008-06-13 14:53 -------- d-----w- c:\program files\Google
                                2009-05-13 12:38 . 2009-05-13 12:38 52228 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\nifodiyu.exe
                                2009-05-13 12:38 . 2009-05-13 12:38 88580 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\haditapo.dll
                                2009-05-13 12:38 . 2009-05-13 12:38 52228 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\jevaziji.exe
                                2009-05-13 12:38 . 2009-05-13 12:38 49668 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\kozafuli.dll
                                2009-05-13 12:38 . 2009-05-13 12:38 49668 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\ThreatWork\Submit\dowuvedo.dll
                                2009-05-11 16:28 . 2008-09-13 13:24 -------- d-----w- c:\program files\Tomtomax Maxi-Box
                                2009-05-08 19:05 . 2009-05-08 19:04 -------- d-----w- c:\documents and settings\yannick creusot\Application Data\vlc
                                2009-05-07 19:04 . 2009-05-07 19:04 -------- d-----w- c:\program files\Fichiers communs\Borland Shared
                                2009-05-07 15:33 . 2001-08-28 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
                                2009-05-04 17:12 . 2008-02-26 14:09 -------- d-----w- c:\program files\CCleaner
                                2009-05-01 17:48 . 2009-05-01 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
                                2009-05-01 17:48 . 2009-05-01 19:11 15688 ----a-w- c:\windows\system32\lsdelete.exe
                                2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
                                2009-05-01 17:48 . 2009-05-01 17:48 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
                                2009-05-01 17:47 . 2009-05-01 17:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
                                2009-05-01 17:46 . 2008-02-26 14:23 -------- d-----w- c:\program files\Lavasoft
                                2009-04-29 04:34 . 2001-08-28 12:00 670720 ----a-w- c:\windows\system32\wininet.dll
                                2009-04-29 04:34 . 2004-08-19 23:09 81920 ------w- c:\windows\system32\ieencode.dll
                                2009-04-25 11:08 . 2009-04-23 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\POPWWPROFILES
                                2009-04-19 19:50 . 2001-08-28 12:00 1847296 ----a-w- c:\windows\system32\win32k.sys
                                2009-04-15 14:55 . 2001-08-28 12:00 71488 ----a-w- c:\windows\system32\perfc00C.dat
                                2009-04-15 14:55 . 2001-08-28 12:00 458648 ----a-w- c:\windows\system32\perfh00C.dat
                                2009-04-15 14:53 . 2008-02-26 12:17 585216 ----a-w- c:\windows\system32\rpcrt4.dll
                                .

                                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                REGEDIT4

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-04-20 337216]
                                "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-19 518488]
                                "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
                                "AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-06-06 206088]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

                                c:\documents and settings\yannick creusot\Menu D‚marrer\Programmes\D‚marrage\
                                Pampers Pregnancy Widget.lnk - c:\documents and settings\yannick creusot\Bureau\PampersPregnancyWidget.exe [2009-1-5 4924787]
                                Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-12 3746856]

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
                                @=""

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
                                @=""

                                [HKLM\~\startupfolder\C:^Documents and Settings^yannick creusot^Menu Démarrer^Programmes^Démarrage^Pampers Pregnancy Widget.lnk]
                                path=c:\documents and settings\yannick creusot\Menu Démarrer\Programmes\Démarrage\Pampers Pregnancy Widget.lnk
                                backup=c:\windows\pss\Pampers Pregnancy Widget.lnkStartup

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
                                "DisableMonitoring"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                "%windir%\\system32\\sessmgr.exe"=
                                "c:\\Program Files\\HomePlayer1.5.4\\HomePlayer.exe"=
                                "c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
                                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                "c:\program files\uTorrent\uTorrent.exe"= c:\program files\uTorrent\uTorrent.exe:89.226.204.137/255.255.255.255:Enabled:µTorrent
                                "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                                "c:\\Program Files\\iTunes\\iTunes.exe"=
                                "c:\\Program Files\\FrostWire\\FrostWire.exe"=
                                "c:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
                                "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                                "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                "c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
                                "c:\\Program Files\\Google\\Update\\GoogleUpdate.exe"=
                                "c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 2009\\avp.exe"=
                                "c:\\Program Files\\Java\\jre1.6.0_03\\launch4j-tmp\\frd.exe"=

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                                "57488:TCP"= 57488:TCP:Pando P2P TCP Listening Port
                                "57488:UDP"= 57488:UDP:Pando P2P UDP Listening Port
                                "6881:TCP"= 6881:TCP:azureus
                                "8080:TCP"= 8080:TCP:freeplayer
                                "56680:TCP"= 56680:TCP:Pando P2P TCP Listening Port
                                "56680:UDP"= 56680:UDP:Pando P2P UDP Listening Port

                                R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 17:29 33808]
                                R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [01/05/2009 19:48 64160]
                                R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [13/06/2009 16:33 130936]
                                R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 23:34 1003344]
                                R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 17:06 24592]
                                S2 gupdate1c9087ee8c5a21c;Google Update Service (gupdate1c9087ee8c5a21c);c:\program files\Google\Update\GoogleUpdate.exe [27/08/2008 21:55 133104]
                                S3 adiusbae;USB ADSL LAN Adapter;c:\windows\system32\DRIVERS\adiusbae.sys --> c:\windows\system32\DRIVERS\adiusbae.sys [?]
                                S3 fbxusb;FreeBox USB Network Adapter;c:\windows\system32\drivers\fbxusb.sys [01/08/2008 18:46 18953]
                                S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [13/06/2009 16:32 348752]
                                S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
                                S4 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [26/02/2008 15:24 26488]
                                .
                                Contenu du dossier 'Tâches planifiées'

                                2009-06-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
                                - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:48]

                                2009-06-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
                                - c:\program files\Google\Update\GoogleUpdate.exe [2008-08-27 05:33]
                                .
                                .
                                ------- Examen supplémentaire -------
                                .
                                uStart Page = hxxp://fr.yahoo.com/
                                uInternet Settings,ProxyOverride = *.local
                                IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
                                IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
                                IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
                                IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
                                IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
                                Trusted Zone: secuser.com\www
                                TCP: {52441C7C-E5B9-4D6F-A48A-236A4BC93B2D} = 212.27.53.252,212.27.54.252
                                DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
                                FF - ProfilePath -
                                .

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2009-06-23 13:45
                                Windows 5.1.2600 Service Pack 3 NTFS

                                Recherche de processus cachés ...

                                Recherche d'éléments en démarrage automatique cachés ...

                                Recherche de fichiers cachés ...

                                Scan terminé avec succès
                                Fichiers cachés: 0

                                **************************************************************************
                                .
                                --------------------- DLLs chargées dans les processus actifs ---------------------

                                - - - - - - - > 'explorer.exe'(3048)
                                c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
                                c:\program files\Fichiers communs\Ahead\Lib\NeroSearchBar.dll
                                c:\program files\Fichiers communs\Ahead\Lib\MFC71U.DLL
                                c:\program files\Fichiers communs\Ahead\Lib\BCGCBPRO860un71.dll
                                c:\windows\system32\eappprxy.dll
                                c:\windows\system32\WPDShServiceObj.dll
                                c:\windows\system32\PortableDeviceTypes.dll
                                c:\windows\system32\PortableDeviceApi.dll
                                .
                                ------------------------ Autres processus actifs ------------------------
                                .
                                c:\windows\system32\nvsvc32.exe
                                c:\windows\system32\wbem\unsecapp.exe
                                c:\windows\system32\wscntfy.exe
                                c:\windows\system32\rundll32.exe
                                c:\windows\system32\rundll32.exe
                                c:\windows\system32\rundll32.exe
                                .
                                **************************************************************************
                                .
                                Heure de fin: 2009-06-23 13:48 - La machine a redémarré
                                ComboFix-quarantined-files.txt 2009-06-23 11:48

                                Avant-CF: 7 469 760 512 octets libres
                                Après-CF: 7 455 145 984 octets libres

                                WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                                [boot loader]
                                timeout=2
                                default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                                [operating systems]
                                c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                                multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn

                                234 --- E O F --- 2009-06-20 13:03
                                • 1
                                • 2
                                • 3