Problème avec generic host process

Résolu
Bonjour,
j'ai un problème avec generic host process au demarrage qui doit fermer . Après avoir lu et essayer de curer le problème , rien à faire toujours les mêmes problème ; plus de son , affichage windows 98 . Les péripheriques audio sont installés et fonctionnent , j'ai une carte son et elle fonctionne sous les logiciels pour le son ... bref . J'ai lu un message qui me conseil de faire un scan avec , RSTI , HijackThis . J'ai le rapport de deux fichiers pour RSTI . il semble que le virus Alureon soit à l'origine du problème .
Y a t il quelqu'un qui peut s'occuper de mon problème et de me conseiller un bon anti-virus .
Autre que Avira antivir ou avast .
Merci .

29 réponses

Résumé de la discussion

Le problème décrit est l’exécution au démarrage du Generic Host Process qui se ferme, provoquant la perte du son et une interface graphique proche de Windows 98, malgré des périphériques audio installés. Après différents dépôts et scans, une suspicion d’infection virale par Alureon est évoquée et des outils comme RSTI, HijackThis ou Malwarebytes ont été proposés pour diagnostiquer et nettoyer le système. Des solutions pratiques préconisent USBFix pour les périphériques USB suspects et Malwarebytes pour un balayage complet, tout en testant un antivirus alternatif à Avira ou Avast. En parallèle, le rapport d’outils et les retours des utilisateurs restent essentiels pour confirmer l’origine et adapter les mesures, notamment lors de la manipulation de clés USB et de correctifs système.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    ok

    sauf soucis

    => résolu

    bonne continuation
    1. Rapport delfix

      Rapport DelFix v6.0 - 28/10/2010 à 23:36,48
      Mis à jour le 22/10/10 à 13h30 par Xplode
      Système d'exploitation : Microsoft Windows XP (32 bits) [version 5.1.2600] Service Pack 3
      Navigateur : Mozilla Firefox 3.6.12 (fr) [Navigateur par défaut]
      Processeur : Genuine Intel(R) CPU T2400 @ 1.83GHz
      Mémoire vive totale : 1,99 Go
      Nom d'utilisateur : Vincent - NOM-A981367FE66 (Administrateur)
      Exécuté depuis : C:\Documents and Settings\Vincent\Bureau\DelFix.exe

      ~~~~~~ Dossier(s) ~~~~~~

      Supprimé : C:\Qoobox
      Supprimé : C:\USBFix
      Supprimé : C:\RSIT
      Supprimé : C:\Program Files\ZHPDiag
      Supprimé : C:\Program Files\trend micro
      Supprimé : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP

      ~~~~~~ Fichier(s) ~~~~~~

      Supprimé : C:\ComboFix.txt
      Supprimé : C:\UsbFix.txt
      Supprimé : C:\WINDOWS\grep.exe
      Supprimé : C:\WINDOWS\PEV.exe
      Supprimé : C:\WINDOWS\NIRCMD.exe
      Supprimé : C:\WINDOWS\MBR.exe
      Supprimé : C:\WINDOWS\sed.exe
      Supprimé : C:\WINDOWS\SWREG.exe
      Supprimé : C:\WINDOWS\SWSC.exe
      Supprimé : C:\WINDOWS\SWXCACLS.exe
      Supprimé : C:\WINDOWS\zip.exe
      Supprimé : C:\Documents and Settings\Vincent\Mes documents\Téléchargements\RSIT.exe
      Supprimé : C:\Documents and Settings\Vincent\Mes documents\Téléchargements\HiJackThis.exe

      ~~~~~~ Registre ~~~~~~

      Clé Supprimée : HKLM\Software\swearware
      Clé Supprimée : HKLM\Software\OldTimer Tools
      Clé Supprimée : HKLM\Software\TrendMicro
      Clé Supprimée : HKCU\SOFTWARE\USBFix
      Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USBFix
      Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
      Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ZHP

      ########## EOF - "C:\DelFixSuppr.txt" - [1857 octets] ##########
      1. Rapport Java :

        JavaRa 1.16 Removal Log.

        Report follows after line.

        ------------------------------------

        The JavaRa removal process was started on Thu Oct 28 22:45:57 2010

        Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}

        Found and removed: SOFTWARE\Classes\JavaPlugin.160_20

        Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_20

        Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_20

        Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

        Found and removed: Software\Classes\JavaPlugin.160_20

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

        Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_20

        Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_20

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

        Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

        Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

        ------------------------------------

        Finished reporting.
        1. Contributeur sécurité
          desktop.ini
          https://www.commentcamarche.net/faq/26897-desktop-ini

          on le garde

          ................

          apres avoir supprimé les restes de norton
          et pour finir

          1)

          Mettre à jour XP
          https://www.commentcamarche.net/telecharger/systemes-d-exploitation/20759-sp3-windows-xp/

          Et internet explorer (même si tu ne l'utilises pas)
          https://support.microsoft.com/fr-fr/allproducts

          ..........................

          2)

          Mettre à jour la Console Java ? :
          https://www.java.com/fr/download/uninstalltool.jsp

          et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).

          voici pour desinstaller :

          JavaRa
          http://raproducts.org/click/click.php?id=1

          Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
          * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
          * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
          * Choisis Français puis clique sur Select.
          * Clique sur Recherche de mises à jour.
          * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
          * Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
          * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
          * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
          * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
          * Ferme l'application.

          Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

          .............

          3)

          Mets à jour Adobe Reader (désinstalle avant la version antérieure)
          https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

          puis

          * Lancez Adobe Reader
          * Cliquez sur Edition --> Préférences --> JavaScript
          * Décochez "Activer Acrobat JavaScript"
          * Validez

          ....................

          4)
          IMPORTANT

          Purger la restauration systeme XP

          http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm

          .................

          5)

          Télécharge DelFix sur ton bureau.

          http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe

          1. Lance le, choisis le bouton SUPPRESSION

          2. Patiente pendant le scan jusqu'à l'ouverture du rapport.

          3. Copie/Colle le contenu du rapport dans ta prochaine réponse.

          Note : Le rapport se trouve également sous C:\DelFixSearch

          ...................................

          Recommandations pour l'avenir

          Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
          - logiciels non à jour (windows, internet explorer, java, adobe reader etc)
          - installation de toolbar
          - fréquentation de sites piégés
          - P2P
          - Application de cracks
          - Supports usb

          Pour t'aider dans cette tâche, voici quelques pistes

          Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
          http://www.mozilla-europe.org/fr/firefox/

          Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
          pour bloquer les publicités
          http://www.clubic.com/telecharger-fiche45912-adblock-plus.html

          ............................

          WOT - Extension pour ton navigateur internet :
          Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
          Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
          Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp

          ........................

          Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !

          ..........................

          Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
          http://www.teamxscript.org/usbfixTelechargement.html
          Au menu principal, choisis l'option 3 (Vaccination).
          ............................

          garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
          .......................

          Pour savoir si ton PC est à jour utilise Sécunia

          https://www.donnemoilinfo.com/sujet/Securiser/secunia-personal-inspector.php

          ...................

          Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
          https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

          * Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
          * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
          * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse

          ..........................
          utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html

          ........................
          A lire pour mieux comprendre l'environnement qui t'entoure
          http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
          https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf

          http://www.libellules.ch/...

          1. Ok c'est bon pour word et excel , merci .
            Pour faire le bilan : J'ai retrouvé le wi-fi , plus de message généric host process , plus de problème de son .

            En revanche , j'ai vu que dans "mes documents" un fichier caché avec le nom : desktop.ini était présent . Je voulais juste indiquer cela , j'avais lu dans mes recherches précédentes que ce fichier était lié avec le problème géneric host process ...

            dites moi ce que tu en penses . Merci pour tout depuis le début en tout cas.
            1. Contributeur sécurité
              ok

              il ne faut pas ouvrir plusieurs sujets..

              supprime donc les restes de norton comme l'avais indiqué jlpjlp à l'aide ce lien
              http://service1.symantec.com/support/inter/tsgeninfointl.nsf/fr_docid/20050414110429924

              dis nous ensuite si word traine encore à ouvrir
              1. Rapport Avira :

                Avira AntiVir Personal - Free Antivirus Updater

                Heure de création : Thu Oct 28 17:47:57 2010

                Système d'exploitation:
                Windows XP (Service Pack 2) [5.1.2600]

                Informations produit :
                Version produit : 9.0.0.77
                Updater : C:\Program Files\Avira\AntiVir Desktop\update.exe 9.0.0.52
                Plug-in : C:\Program Files\Avira\AntiVir Desktop\updext.dll 9.0.0.6

                Répertoire temporaire : C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\
                Répertoire de sauvegarde : C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\BACKUP\
                Répertoire dapos;installation : C:\Program Files\Avira\AntiVir Desktop\
                Répertoire de l'Updater : C:\Program Files\Avira\AntiVir Desktop\
                Répertoire AppData : C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\

                [UPD] [INFO] Contrôle en cours pour savoir si des fichiers plus récents sont disponibles.
                [UPD] [INFO] Sélection en cours du serveur de mise à jour 'http://80.190.143.237/update'.
                [UPD] [INFO] Téléchargement de 'http://80.190.143.237/update/idx/master.idx' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
                [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
                [UPD] [INFO] Téléchargement de 'http://80.190.143.237/update/idx/master.idx' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
                [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
                [UPD] [INFO] Téléchargement de 'http://80.190.143.237/update/idx/master.idx' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
                [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
                [UPD] [INFO] Sélection en cours du serveur de mise à jour 'http://62.146.66.182/update'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/master.idx' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
                [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/master.idx' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/wks_avira-win32-fr-pecl.idx' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-fr-pecl.idx'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/wks_avira-win32-fr-pecl.info.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-fr-pecl.info.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/vdf.info.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/ave2-win32-int.info.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\ave2-win32-int.info.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/specvir-win32-int.info.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\specvir-win32-int.info.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/idx/wks_avira-win32-fr-pecl-info.info.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-fr-pecl-info.info.gz'.
                [UPD] [INFO] Comparaison en cours des fichiers locaux avec la version disponible sur le serveur de mise à jour.
                [UPD] [INFO] Contrôle en cours du module SELFUPDATE :
                [UPD] [INFO] Contrôle en cours du module VDF :
                [UPD] [INFO] Fichier 'n_vdf/vbase029.vdf' (local, serveur) : 7.10.13.40 < 7.10.13.62
                [UPD] [INFO] Fichier 'n_vdf/vbase030.vdf' (local, serveur) : 7.10.13.41 < 7.10.13.63
                [UPD] [INFO] Fichier 'n_vdf/vbase031.vdf' (local, serveur) : 7.10.13.58 < 7.10.13.66
                [UPD] [INFO] Fichier 'n_vdf/aevdf.dat' (local, serveur) : 7.10.13.58 < 7.10.13.66
                [UPD] [INFO] Contrôle en cours du module AVE2 :
                [UPD] [INFO] Fichier 'ave2/win32/int/aeheur.dll' (local, serveur) : 8.1.2.36 < 8.1.2.37
                [UPD] [INFO] Fichier 'ave2/win32/int/aeset.dat' (local, serveur) : 8.2.4.84 < 8.2.4.86
                [UPD] [INFO] Contrôle en cours du module MAIN :
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/xp/avgntflt.inf' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/avupgsvc.exe' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/filelist.ini' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/presetup.exe' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/product.ini' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/vcredist_x86.exe' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
                [UPD] [INFO] Contrôle en cours du module AVREP_NT :
                [UPD] [INFO] Contrôle en cours du module COMMAPPDATA_AV :
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/addr_file.html' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Contrôle en cours du module COMMAPP :
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/produpd.avj' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/scanjob.avj' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/startupd.avj' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/updjob.avj' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Contrôle en cours du module COMMAPDATA_AV_PROFILES :
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/folder.avp' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/rootkit.avp' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Contrôle en cours du module TEXT :
                [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/eula.txt' est déjà installé et ne sera pas actualisé.
                [UPD] [INFO] Contrôle en cours du module DRV :
                [UPD] [INFO] Contrôle en cours du module PRODINFO :
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\BACKUP\' requiert 3071759 octets d'espace mémoire libre.
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\' requiert 6295070 octets d'espace mémoire libre.
                [UPD] [INFO] 'C:\Program Files\Avira\AntiVir Desktop\' requiert 3147535 octets d'espace mémoire libre.
                [UPD] [INFO] Espace mémoire OK.
                [UPD] [INFO] Lecteur : C:\, capacité disponible : 1494122496 octets.
                [UPD] [INFO] Téléchargement en cours de nouveaux fichiers...
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/n_vdf/vbase029.vdf.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase029.vdf.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/n_vdf/vbase030.vdf.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase030.vdf.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/n_vdf/vbase031.vdf.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\vbase031.vdf.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/n_vdf/aevdf.dat.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\n_vdf\aevdf.dat.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/ave2/win32/int/aeheur.dll.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aeheur.dll.gz'.
                [UPD] [INFO] Téléchargement de 'http://62.146.66.182/update/ave2/win32/int/aeset.dat.gz' vers'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aeset.dat.gz'.
                [UPD] [INFO] Fichier de licence : version intégrale
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase029.vdf' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\vbase029.vdf'.
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase030.vdf' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\vbase030.vdf'.
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\vbase031.vdf' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\vbase031.vdf'.
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\n_vdf\aevdf.dat' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aevdf.dat'.
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aeheur.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aeheur.dll'.
                [UPD] [INFO] 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aeset.dat' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aeset.dat'.
                [UPD] [INFO] Réinitialisation du Avira AntiVir Guard réussie.

                Résumé :
                ********
                6 fichiers téléchargés
                6 fichiers installés
                Fichier(s) téléchargé(s) : vbase029.vdf 7.10.13.62; vbase030.vdf 7.10.13.63; vbase031.vdf 7.10.13.66; aevdf.dat 7.10.13.66; aeheur.dll 8.1.2.37; aeset.dat 8.2.4.86;

                17:51:30 La mise à jour a été effectuée avec succès !
                1. Un premier fichier ZHP

                  http://www.cijoint.fr/cjlink.php?file=cj201010/cijTMuxCzq.txt

                  Entre temps j'ai posé la question concernant le problème word et excel .
                  On m a proposé de faire un scan OTL /

                  Qui de trouve sur ce lien : http://www.cijoint.fr/cjlink.php?file=cj201010/cijXzPDnty.txt

                  Je me suis rendu compte , qu'un fichier caché "desktop.ini" était présent dans "mes documents..."
                  1. Contributeur sécurité
                    poste moi aussi le rapport d'antivir comme demandé stp
                2. Contributeur sécurité
                  En revanche : pendant le scan , avira a trouvé quelques problèmes , j'ai supprimé au fur et à mesure .

                  peux tu me poster le rapport

                  .................

                  Fais un nouveau rapport ZHPdiag stp

                  Rend toi sur Cjoint : http://www.cijoint.fr/

                  Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

                  Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

                  Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

                  1. Tout semble etre ok à présent , j'ai retrouvé le wi-fi , pas de problème de son , plus de message "generic host process ..." .
                    Pour l'instant ca roule .
                    Merci .

                    Juste une chose : (important) Je ne peux plus ouvrir Word et Excel normalement .
                    ca prend beaucoup beaucoup de temps . il y a comme un scan , "demande de recherche de virus ..." un truc comme ça , j'ai Avira comme protection permanente . Est ce que ca vient de ca ? comment ouvrir ces fichiers plus rapidement . Merci
                    1. Voilà le deuxième scan :

                      Malwarebytes' Anti-Malware 1.46
                      www.malwarebytes.org

                      Version de la base de données: 4966

                      Windows 5.1.2600 Service Pack 2
                      Internet Explorer 6.0.2900.2180

                      28/10/2010 12:05:26
                      mbam-log-2010-10-28 (12-05-26).txt

                      Type d'examen: Examen complet (C:\|E:\|F:\|G:\|)
                      Elément(s) analysé(s): 247447
                      Temps écoulé: 16 heure(s), 16 minute(s), 6 seconde(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      En revanche : pendant le scan , avira a trouvé quelques problèmes , j'ai supprimé au fur et à mesure .
                      1. Contributeur sécurité
                        supprime de la quarantaine ce qui est trouvé et refais en un nouveau stp

                        CONTRIBUTEUR SECURITE

                        Désinfection = diagnostic + traitement + finalisation
                        "Restez" jusqu'au bout...merci
                        1. Voici le rapport que j'ai (en fait avant la mise à jour, j'ai effectué un scan complet en mode sans échec ... Faut il que je recommence en mode normal suite à la mise à jour ?

                          Rapport avant mise à jour sous Wxp Mode sans echec:

                          Malwarebytes' Anti-Malware 1.46
                          www.malwarebytes.org

                          Version de la base de données: 4052

                          Windows 5.1.2600 Service Pack 2 (Safe Mode)
                          Internet Explorer 6.0.2900.2180

                          27/10/2010 19:26:37
                          mbam-log-2010-10-27 (19-26-37).txt

                          Type d'examen: Examen complet (C:\|E:\|F:\|G:\|)
                          Elément(s) analysé(s): 222359
                          Temps écoulé: 59 minute(s), 21 seconde(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 2

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          C:\Program Files\Steinberg\Cubase SX\UNWISE.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
                          E:\System Volume Information\_restore{BE0DEF4E-BA59-4AD0-8CE4-8FBBD24279CF}\RP48\A0007944.EXE (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
                          1. Contributeur sécurité
                            bof

                            peux tu mettre à jour MBAM maintenant ?
                            1. Rapport Combo :

                              ComboFix 10-10-26.04 - Vincent 27/10/2010 18:07:08.1.2 - FAT32x86
                              Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.2047.1610 [GMT 2:00]
                              Lancé depuis: c:\documents and settings\Vincent\Bureau\ComboFix.exe
                              AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
                              AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
                              FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

                              AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
                              .

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              c:\documents and settings\Vincent\Application Data\avdrn.dat
                              c:\windows\system32\Ijl11.dll

                              .
                              ((((((((((((((((((((((((((((( Fichiers créés du 2010-09-27 au 2010-10-27 ))))))))))))))))))))))))))))))))))))
                              .

                              2010-10-27 12:54 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                              2010-10-27 12:54 . 2010-10-27 12:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                              2010-10-27 12:54 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
                              2010-10-27 12:54 . 2010-10-27 12:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                              2010-10-27 11:35 . 2010-10-27 11:35 -------- d-----w- C:\UsbFix
                              2010-10-27 09:15 . 2010-10-27 09:15 -------- d-----w- c:\program files\ZHPDiag
                              2010-10-26 16:25 . 2010-10-26 16:25 -------- d-----w- C:\rsit
                              2010-10-26 16:25 . 2010-10-26 16:25 -------- d-----w- c:\program files\trend micro
                              2010-10-25 15:53 . 2010-10-25 15:53 -------- d-----w- C:\spoolerlogs
                              2010-10-25 15:11 . 2010-09-03 14:20 891496 ----a-w- c:\windows\system32\RTSndMgr.CPL
                              2010-10-25 14:22 . 2010-10-25 14:22 -------- d-s---w- c:\documents and settings\Vincent\UserData
                              2010-10-25 14:21 . 2010-10-25 14:21 -------- d-----w- c:\documents and settings\Vincent\Application Data\HPAppData
                              2010-10-25 13:29 . 2010-10-25 13:29 -------- d-----w- c:\windows\system32\wbem\Repository
                              2010-09-28 19:19 . 2004-08-03 20:58 100992 ----a-w- c:\windows\system32\drivers\bthpan.sys
                              2010-09-28 19:19 . 2004-08-03 20:58 100992 ----a-w- c:\windows\system32\dllcache\bthpan.sys
                              2010-09-28 19:19 . 2004-08-03 21:10 59648 ----a-w- c:\windows\system32\drivers\rfcomm.sys
                              2010-09-28 19:19 . 2004-08-03 21:10 59648 ----a-w- c:\windows\system32\dllcache\rfcomm.sys
                              2010-09-28 19:19 . 2004-08-03 21:10 17024 ----a-w- c:\windows\system32\drivers\BthEnum.sys
                              2010-09-28 19:19 . 2004-08-03 21:10 17024 ----a-w- c:\windows\system32\dllcache\bthenum.sys
                              2010-09-28 19:18 . 2004-08-03 21:10 18944 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
                              2010-09-28 19:18 . 2004-08-03 21:10 18944 ----a-w- c:\windows\system32\dllcache\bthusb.sys
                              2010-09-27 19:20 . 2010-09-27 19:20 -------- d-----w- c:\windows\system32\LogFiles

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2010-09-23 16:45 . 2010-02-16 16:20 94208 ----a-w- c:\windows\DUMP700f.tmp
                              2010-09-03 14:20 . 2010-02-16 16:10 84584 ----a-w- c:\windows\SoundMan.exe
                              2010-09-03 14:20 . 2010-02-16 16:10 1489512 ----a-w- c:\windows\RtlUpd.exe
                              2010-09-03 14:20 . 2010-02-16 16:10 9721960 ----a-w- c:\windows\RTLCPL.EXE
                              2010-09-03 14:20 . 2010-02-16 16:10 6139496 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
                              2010-09-03 14:20 . 2010-02-16 16:10 19573352 ----a-w- c:\windows\RTHDCPL.EXE
                              2010-09-03 14:19 . 2010-02-16 16:10 2180712 ----a-w- c:\windows\MicCal.exe
                              2010-09-03 14:19 . 2010-02-16 16:10 285288 ----a-w- c:\windows\system32\ALSndMgr.Cpl
                              2010-09-03 14:19 . 2010-02-16 16:10 64104 ----a-w- c:\windows\Alcmtr.exe
                              2010-09-03 14:19 . 2010-02-16 16:10 2815592 ----a-w- c:\windows\ALCWZRD.EXE
                              2010-08-31 14:28 . 2010-02-16 16:45 1251944 ----a-w- c:\windows\RtlExUpd.dll
                              2010-08-09 12:28 . 2010-08-09 12:28 49152 ----a-r- c:\documents and settings\Vincent\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
                              2010-08-08 02:52 . 2010-02-16 16:20 94208 ----a-w- c:\windows\DUMP689d.tmp
                              .

                              ------- Sigcheck -------

                              [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\atapi.sys
                              [-] 2004-08-10 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
                              [-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys
                              [-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys

                              [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\asyncmac.sys
                              [-] 2004-08-10 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\drivers\asyncmac.sys
                              [-] 2004-08-10 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\asyncmac.sys

                              [-] 2004-08-10 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys
                              [-] 2004-08-10 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys

                              [-] 2008-04-14 . 16813155807C6881F4BFBF6657424659 . 25216 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\kbdclass.sys
                              [-] 2004-08-10 . E798705E8DC7FAB596EF6BFDF167E007 . 25216 . . [5.1.2600.2180] . . c:\windows\system32\drivers\kbdclass.sys

                              [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ndis.sys
                              [-] 2004-08-10 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys
                              [-] 2004-08-10 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ndis.sys

                              [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ntfs.sys
                              [-] 2004-08-10 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ntfs.sys
                              [-] 2004-08-10 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ntfs.sys
                              [-] 2004-08-10 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\I386\NTFS.SYS

                              [-] 2004-08-10 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys
                              [-] 2004-08-10 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys

                              [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
                              [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
                              [-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\tcpip.sys
                              [-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\tcpip.sys
                              [-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
                              [-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\tcpip.sys
                              [-] 2004-08-10 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\tcpip.sys

                              [-] 2008-04-14 . 06B54A7B1EF7CB16BFD0E208D343FA71 . 77824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\browser.dll
                              [-] 2004-08-10 . CE9DC7CC6D75515EE62CA341473EC5F3 . 77312 . . [5.1.2600.2180] . . c:\windows\system32\browser.dll
                              [-] 2004-08-10 . CE9DC7CC6D75515EE62CA341473EC5F3 . 77312 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\browser.dll

                              [-] 2008-04-14 . 91E6024D6D4DCDECDB36C43ECF9BBECB . 13312 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\lsass.exe
                              [-] 2004-08-10 . 9F3744A5C6F49291A7A685040A013399 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\lsass.exe
                              [-] 2004-08-10 . 9F3744A5C6F49291A7A685040A013399 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\lsass.exe

                              [-] 2008-04-14 . BE0CB143FA427D93440DED18DB8C918B . 198144 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\netman.dll
                              [-] 2004-08-10 . 624CF700BBFD8BE4097AAA146E6BD363 . 198144 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\netman.dll
                              [-] 2004-08-10 . 624CF700BBFD8BE4097AAA146E6BD363 . 198144 . . [5.1.2600.2180] . . c:\windows\system32\netman.dll

                              [-] 2008-04-14 . BAA0B6E647C1AD593E9BAE5CC31BCFFB . 409088 . . [6.7.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\qmgr.dll
                              [-] 2004-08-10 . 87424817F82CF6A7F55DAC01A20111A3 . 382464 . . [6.6.2600.2180] . . c:\windows\system32\qmgr.dll
                              [-] 2004-08-10 . 87424817F82CF6A7F55DAC01A20111A3 . 382464 . . [6.6.2600.2180] . . c:\windows\system32\dllcache\qmgr.dll

                              [-] 2009-02-09 . F83B964469D230F445613C44DF9FE25D . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
                              [-] 2009-02-09 . 0203B1AAD358F206CB0A3C1F93CCE17A . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\rpcss.dll
                              [-] 2009-02-09 . 5620353B93DD08016674E4FEE280190B . 399360 . . [5.1.2600.3520] . . c:\windows\system32\rpcss.dll
                              [-] 2009-02-09 . 5620353B93DD08016674E4FEE280190B . 399360 . . [5.1.2600.3520] . . c:\windows\system32\dllcache\rpcss.dll
                              [-] 2009-02-09 . BA1EF616F55210820F6462D033088497 . 401408 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\rpcss.dll
                              [-] 2008-04-14 . 3D65EB82E1FA6DB15A33E024C9E03CAB . 399360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\rpcss.dll
                              [-] 2004-08-10 . 2477917B158327410E615C582A3A4C0B . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\rpcss.dll

                              [-] 2009-02-09 . C3FB1D70CB88722267949694BA51759E . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\services.exe
                              [-] 2009-02-09 . 62789101F9C2401ED598AA2CDE7450C0 . 111104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
                              [-] 2009-02-09 . 9D6BF82FE50D55F20F8E10E0F6653886 . 111104 . . [5.1.2600.3520] . . c:\windows\system32\services.exe
                              [-] 2009-02-09 . 9D6BF82FE50D55F20F8E10E0F6653886 . 111104 . . [5.1.2600.3520] . . c:\windows\system32\dllcache\services.exe
                              [-] 2009-02-09 . 51A24094F076961A7FF73E5F7E991D68 . 111104 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\services.exe
                              [-] 2008-04-14 . 54CB50058851D95E56EC70D09F70857F . 109056 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\services.exe
                              [-] 2004-08-10 . 732E0B1ABAACE15D80EC19056B0A2AF9 . 108544 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\services.exe

                              [-] 2008-04-14 . 460E4CE148BD07218DA0B6A3D31885A9 . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\spoolsv.exe
                              [-] 2004-08-10 . B4EF928E4FAD79364A80ACBA6D999934 . 57856 . . [5.1.2600.2180] . . c:\windows\system32\spoolsv.exe
                              [-] 2004-08-10 . B4EF928E4FAD79364A80ACBA6D999934 . 57856 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\spoolsv.exe

                              [-] 2008-04-14 . DD73D6B9F6B4CB630CF35B438B540174 . 512000 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\winlogon.exe
                              [-] 2004-08-10 . D2DE785AEAB0BB8CA4C14A8A199DBE4E . 506368 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\winlogon.exe
                              [-] 2004-08-10 . D2DE785AEAB0BB8CA4C14A8A199DBE4E . 506368 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe

                              [-] 2008-04-14 . B4AA331468315B6A174C3F0D5B3BC135 . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\comctl32.dll
                              [-] 2008-04-14 . F92E6BEA9349D49341383F8403B4DFE5 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\asms\60\msft\windows\common\controls\comctl32.dll
                              [-] 2004-08-10 . A53B48B5AB9A5DA76ED247D61B0B0ADD . 611328 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll
                              [-] 2004-08-10 . A53B48B5AB9A5DA76ED247D61B0B0ADD . 611328 . . [5.82] . . c:\windows\system32\comctl32.dll
                              [-] 2004-08-10 . 97668958194B82F5B88EABC88ACA5AE1 . 1050624 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
                              [-] 2004-08-10 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
                              [-] 2004-08-10 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\I386\ASMS\6000\MSFT\WINDOWS\COMMON\CONTROLS\COMCTL32.DLL

                              [-] 2008-04-14 . 7A6D0B71035E123FDDA2156A25578AD3 . 62464 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\cryptsvc.dll
                              [-] 2004-08-10 . BDDF3723D95DC28D78B1E93119E0E6AB . 60416 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\cryptsvc.dll
                              [-] 2004-08-10 . BDDF3723D95DC28D78B1E93119E0E6AB . 60416 . . [5.1.2600.2180] . . c:\windows\system32\cryptsvc.dll

                              [-] 2008-07-07 19:31 . A5B1B7C76134329AA7547F6E6DA35410 . 253952 . . [2001.12.4414.320] . . c:\windows\system32\es.dll
                              [-] 2008-07-07 19:31 . A5B1B7C76134329AA7547F6E6DA35410 . 253952 . . [2001.12.4414.320] . . c:\windows\system32\dllcache\es.dll
                              [-] 2008-07-07 19:28 . EC16AE9B37EACF871629227A3F3913FD . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
                              [-] 2008-07-07 19:24 . 157F9C595FD0D10502497DC4C1348D17 . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
                              [-] 2008-07-07 19:18 . 74ECF4DDC685BD3249CAB323405FCC49 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
                              [-] 2008-04-14 01:33 . 9FD4A0615BF3E9388A46EDF8774C7294 . 246272 . . [2001.12.4414.701] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\es.dll
                              [-] 2004-08-10 12:00 . BBA1D0A306ABE68A13F58FDBE97E9AF4 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB950974$\es.dll

                              [-] 2008-04-14 . 0469B73DB32E5520F342C5E163AA3CCA . 110080 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\imm32.dll
                              [-] 2004-08-10 . 39EE5FAF56260EBB8D77A08F525EBBB4 . 110080 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\imm32.dll
                              [-] 2004-08-10 . 39EE5FAF56260EBB8D77A08F525EBBB4 . 110080 . . [5.1.2600.2180] . . c:\windows\system32\imm32.dll

                              [-] 2009-03-21 . 534040750B9E70B156A98F5D0E8F6D2A . 1051136 . . [5.1.2600.3541] . . c:\windows\system32\kernel32.dll
                              [-] 2009-03-21 . 534040750B9E70B156A98F5D0E8F6D2A . 1051136 . . [5.1.2600.3541] . . c:\windows\system32\dllcache\kernel32.dll
                              [-] 2009-03-21 . 98F08549604D090B6B2514AF845F329F . 1054720 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3GDR\kernel32.dll
                              [-] 2009-03-21 . C3AF0EEE26B59484E674673E3016AAB7 . 1056768 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
                              [-] 2009-03-21 . 2087E2764822A8D93A4CA7FA0FED35E8 . 1054208 . . [5.1.2600.3541] . . c:\windows\$hf_mig$\KB959426\SP2QFE\kernel32.dll
                              [-] 2008-04-14 . 3AC8886DFA5AB641417DF4D3B7F5512E . 1054720 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\kernel32.dll
                              [-] 2004-08-10 . 7830E20C74611281B1BDAE5888CD50F5 . 1048576 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB959426$\kernel32.dll

                              [-] 2008-04-14 . 5C64008E661307C4A3C3C25D9086CDE7 . 19968 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\linkinfo.dll
                              [-] 2004-08-10 . 9D21BC0235494F2B403026A1D3619E00 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\linkinfo.dll
                              [-] 2004-08-10 . 9D21BC0235494F2B403026A1D3619E00 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\linkinfo.dll

                              [-] 2008-04-14 . 982B2C204337C3B12211E1E1D9BA8C9C . 22016 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\lpk.dll
                              [-] 2004-08-10 . 8C97E0E3DAA99659D4F4B44CC1F282A6 . 22016 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\lpk.dll
                              [-] 2004-08-10 . 8C97E0E3DAA99659D4F4B44CC1F282A6 . 22016 . . [5.1.2600.2180] . . c:\windows\system32\lpk.dll

                              [-] 2010-04-16 . 5E2FF63E99CE871151A218DE09FC954F . 3094016 . . [6.00.2900.5969] . . c:\windows\$hf_mig$\KB982381\SP3GDR\mshtml.dll
                              [-] 2010-04-16 . E393E03FEDA7DD46EC8351195CB1E8CD . 3094528 . . [6.00.2900.5969] . . c:\windows\$hf_mig$\KB982381\SP3QFE\mshtml.dll
                              [-] 2010-04-16 . 89B865375750836754A2503F584760A4 . 3086336 . . [6.00.2900.3698] . . c:\windows\system32\mshtml.dll
                              [-] 2010-04-16 . 89B865375750836754A2503F584760A4 . 3086336 . . [6.00.2900.3698] . . c:\windows\system32\dllcache\mshtml.dll
                              [-] 2010-04-16 . BC72656B05A1DAE44C5B37709A19A575 . 3094016 . . [6.00.2900.3698] . . c:\windows\$hf_mig$\KB982381\SP2QFE\mshtml.dll
                              [-] 2010-02-26 . 151680CF029903DBDE2D5DC1D72727A6 . 3094016 . . [6.00.2900.3676] . . c:\windows\$hf_mig$\KB980182\SP2QFE\mshtml.dll
                              [-] 2010-02-26 . 54DED9F208264C669D83C50F1BE5023E . 3086336 . . [6.00.2900.3676] . . c:\windows\$NtUninstallKB982381$\mshtml.dll
                              [-] 2010-02-26 . 941F572A5703840868F77B485487CADC . 3094016 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3GDR\mshtml.dll
                              [-] 2010-02-26 . 30821D85390C63E9A0BD4D57159D1F05 . 3094528 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\mshtml.dll
                              [-] 2009-12-22 . F6AC48D7481AFD99038AA6454CDA5357 . 3084800 . . [6.00.2900.3660] . . c:\windows\$NtUninstallKB980182$\mshtml.dll
                              [-] 2009-12-22 . DB13F365BCF2AC27650C203F22148C21 . 3092480 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\mshtml.dll
                              [-] 2009-12-22 . A7F23A7113C54B1D3E8B736723431197 . 3092480 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\mshtml.dll
                              [-] 2009-12-22 . 0935EDE7EDD8031598F8183B487F55D8 . 3094528 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\mshtml.dll
                              [-] 2008-04-14 . C4153F037157C7BE7C54FD88887F027D . 3066880 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\mshtml.dll
                              [-] 2004-08-10 . 3FE8D0C4C2F3B928192BD06DCEE34B32 . 3003392 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB978207$\mshtml.dll

                              [-] 2008-04-14 . 3891413139EAABFEFE9B0CA49B5CD395 . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\msvcrt.dll
                              [-] 2008-04-14 . D33CD21D476C3A07DD88F83850A17432 . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\asms\70\msft\windows\mswincrt\msvcrt.dll
                              [-] 2004-08-10 . 351B1AD22FD0EC70D889766E0B4F72ED . 343040 . . [7.0.2600.2180] . . c:\windows\system32\dllcache\msvcrt.dll
                              [-] 2004-08-10 . 351B1AD22FD0EC70D889766E0B4F72ED . 343040 . . [7.0.2600.2180] . . c:\windows\system32\msvcrt.dll
                              [-] 2004-08-10 . 5C53FCABF891ECDC7156544E5B03FE71 . 343040 . . [7.0.2600.2180] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcrt.dll
                              [-] 2004-08-10 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
                              [-] 2004-08-10 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\I386\ASMS\7000\MSFT\WINDOWS\MSWINCRT\MSVCRT.DLL

                              [-] 2008-06-20 . 58AF8498C62E1E1DAB5AE59C6E08C180 . 247808 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
                              [-] 2008-06-20 . C759B3790D3BA760C52E218EF4886DAC . 247808 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
                              [-] 2008-06-20 . 8A52DE10680A40ECD04FA2C0FBC34190 . 247808 . . [5.1.2600.3394] . . c:\windows\system32\mswsock.dll
                              [-] 2008-06-20 . 8A52DE10680A40ECD04FA2C0FBC34190 . 247808 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\mswsock.dll
                              [-] 2008-06-20 . 4138FBDEDBC6FEAD215BB4C4B102F7DE . 247808 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
                              [-] 2008-04-14 . 196CCC3FDD21665DCAA9F83FFC03B41A . 247808 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\mswsock.dll
                              [-] 2004-08-10 . CCDD3433F3C3BD0D8502B38FD155B2F0 . 247808 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\mswsock.dll

                              [-] 2009-02-06 . ECD7791E0E9246CA5F218A19F3911EB9 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB968389\SP2QFE\netlogon.dll
                              [-] 2009-02-06 . ECD7791E0E9246CA5F218A19F3911EB9 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB975467\SP2QFE\netlogon.dll
                              [-] 2008-04-14 . 04821179C3171554C1BD1F9888A113E2 . 407040 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\netlogon.dll
                              [-] 2004-08-10 . FAF07FDCDE76000621A28D19F8E2E8EB . 407040 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\netlogon.dll
                              [-] 2004-08-10 . FAF07FDCDE76000621A28D19F8E2E8EB . 407040 . . [5.1.2600.2180] . . c:\windows\system32\netlogon.dll

                              [-] 2010-02-17 . ADDA825853063A00D75D66188C3F1449 . 2192000 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3GDR\ntoskrnl.exe
                              [-] 2010-02-16 . CA357A9B6DB4CDFEB23C6DF54509C98E . 2188928 . . [5.1.2600.3670] . . c:\windows\system32\dllcache\ntoskrnl.exe
                              [-] 2010-02-16 . CA357A9B6DB4CDFEB23C6DF54509C98E . 2188928 . . [5.1.2600.3670] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
                              [-] 2010-02-16 . 7D011FF1C0BE09A78B52C9D21CF56DB5 . 2145792 . . [5.1.2600.3670] . . c:\windows\system32\ntoskrnl.exe
                              [-] 2010-02-16 . 126C8FD13731649A7CD6F0A311CD49B8 . 2192128 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe
                              [-] 2009-12-09 . 9EC870EAB7D08695E59579C7AAC3B23D . 2191360 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
                              [-] 2009-12-09 . 820B01F1F60CAE90944E5720A08EB999 . 2144768 . . [5.1.2600.3654] . . c:\windows\$NtUninstallKB979683$\ntoskrnl.exe
                              [-] 2009-12-09 . 904558EAA6ADFD08A93410E2F6A68C53 . 2191232 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3GDR\ntoskrnl.exe
                              [-] 2009-08-04 . 263FA3A73C588A26306D3B403A45F5A9 . 2191232 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3GDR\ntoskrnl.exe
                              [-] 2009-08-04 . 63864AF70CAC631077A6C1223617336B . 2191360 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
                              [-] 2009-08-04 . DCEFB166769B708F654742C0E3634CFB . 2144768 . . [5.1.2600.3610] . . c:\windows\$NtUninstallKB977165$\ntoskrnl.exe
                              [-] 2009-02-10 . BEF458B8424553279E95E250D1E0CE7E . 2191232 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
                              [-] 2009-02-09 . B55AA66BC9269BC5257B915FFDAA790B . 2188160 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntoskrnl.exe
                              [-] 2009-02-09 . AB896577F35CF5FED7A9F87D3C3205ED . 2191104 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntoskrnl.exe
                              [-] 2008-04-14 . 099D639DA1EF6968D4E41795BB507E6B . 2191104 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ntoskrnl.exe
                              [-] 2005-09-29 . CD6A9F81C8B9BAF1E4393C6C476D17E7 . 2138112 . . [5.1.2600.2765] . . c:\windows\$NtUninstallKB971486$\ntoskrnl.exe
                              [-] 2004-08-10 . 36F32A5A83DF734E022734D93860A9A4 . 2150400 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896256$\ntoskrnl.exe

                              [-] 2008-04-14 . 9F2C862E39BF8E8FC51C3F6A6BCEB415 . 17408 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\powrprof.dll
                              [-] 2004-08-10 . B02E4DDBE0E98F42F3B61292DDB3A104 . 17408 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\powrprof.dll
                              [-] 2004-08-10 . B02E4DDBE0E98F42F3B61292DDB3A104 . 17408 . . [6.00.2900.2180] . . c:\windows\system32\powrprof.dll

                              [-] 2008-04-14 . 973B36634C544948C663E8269AA1B3A3 . 187392 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\scecli.dll
                              [-] 2004-08-10 . DEC0397F35D027874804EC72979D03CC . 186368 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\scecli.dll
                              [-] 2004-08-10 . DEC0397F35D027874804EC72979D03CC . 186368 . . [5.1.2600.2180] . . c:\windows\system32\scecli.dll

                              [-] 2008-04-14 . 9A4E7ECBB5B7FB86F3B926AB039F4FEC . 5120 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\sfc.dll
                              [-] 2004-08-10 . 94559DE281DADCB58E6A3919C7EAC0B4 . 5120 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfc.dll
                              [-] 2004-08-10 . 94559DE281DADCB58E6A3919C7EAC0B4 . 5120 . . [5.1.2600.2180] . . c:\windows\system32\sfc.dll

                              [-] 2008-04-14 . E4BDF223CD75478BF44567B4D5C2634D . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\svchost.exe
                              [-] 2004-08-10 . 1BD6C2F707A275CB7C16FD99FE0F31CA . 14336 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\svchost.exe
                              [-] 2004-08-10 . 1BD6C2F707A275CB7C16FD99FE0F31CA . 14336 . . [5.1.2600.2180] . . c:\windows\system32\svchost.exe

                              [-] 2008-04-14 . 8E5231171AD6595FF002E848CC54FCD7 . 249856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\tapisrv.dll
                              [-] 2004-08-10 . 2490CAE37DB8B6EC55E7A9415473D0AB . 246272 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\tapisrv.dll
                              [-] 2004-08-10 . 2490CAE37DB8B6EC55E7A9415473D0AB . 246272 . . [5.1.2600.2180] . . c:\windows\system32\tapisrv.dll

                              [-] 2008-04-14 . E853F84D3CE2FAA2A802E33CF89AC023 . 579584 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\user32.dll
                              [-] 2004-08-10 . E46FB493E3B33704F0715020CF52106B . 578048 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\user32.dll
                              [-] 2004-08-10 . E46FB493E3B33704F0715020CF52106B . 578048 . . [5.1.2600.2180] . . c:\windows\system32\user32.dll

                              [-] 2008-04-14 . E74DDB12188C2FF57A78624DBF7332FC . 26624 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\userinit.exe
                              [-] 2004-08-10 . D6D65EA32B190401B57EDB6706F29669 . 25088 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe
                              [-] 2004-08-10 . D6D65EA32B190401B57EDB6706F29669 . 25088 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\userinit.exe

                              [-] 2010-04-16 . 1B7EBDD150980FFA0597E94D4D6810A5 . 671232 . . [6.00.2900.5969] . . c:\windows\$hf_mig$\KB982381\SP3GDR\wininet.dll
                              [-] 2010-04-16 . 618BAA71E2639379B9947530677FF103 . 672768 . . [6.00.2900.5969] . . c:\windows\$hf_mig$\KB982381\SP3QFE\wininet.dll
                              [-] 2010-04-16 . 723ECE72C35ED65D1758068B17B76D7C . 666112 . . [6.00.2900.3698] . . c:\windows\system32\wininet.dll
                              [-] 2010-04-16 . 723ECE72C35ED65D1758068B17B76D7C . 666112 . . [6.00.2900.3698] . . c:\windows\system32\dllcache\wininet.dll
                              [-] 2010-04-16 . 230EB19059FD2C744132C1F907EBBC37 . 672768 . . [6.00.2900.3698] . . c:\windows\$hf_mig$\KB982381\SP2QFE\wininet.dll
                              [-] 2010-02-26 . E72B21BEDABC235E93A076BDDA31C85B . 666112 . . [6.00.2900.3676] . . c:\windows\$NtUninstallKB982381$\wininet.dll
                              [-] 2010-02-26 . 3A5B86C07128AB5EE198DAD8A341572C . 672768 . . [6.00.2900.3676] . . c:\windows\$hf_mig$\KB980182\SP2QFE\wininet.dll
                              [-] 2010-02-26 . 82782CBD6E1A6E87DCA435DBECEF9A73 . 671232 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3GDR\wininet.dll
                              [-] 2010-02-26 . 4527C7A356AFA4465BE5C713F8CB450C . 672768 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\wininet.dll
                              [-] 2009-12-22 . CE3FF5997569EF50ECCBF3E4EA41398C . 666112 . . [6.00.2900.3660] . . c:\windows\$NtUninstallKB980182$\wininet.dll
                              [-] 2009-12-22 . 798862A02332BA22D7677651541C7CC2 . 672768 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\wininet.dll
                              [-] 2009-12-22 . A3AF5EEC47D71F7F135CC4487E7D884D . 671232 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\wininet.dll
                              [-] 2009-12-22 . 6F18BDEDD53274AD3E5F55A454CD4A92 . 672768 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\wininet.dll
                              [-] 2008-04-14 . 4A6E04EA20F48D750D9BFED8600D516B . 670208 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\wininet.dll
                              [-] 2004-08-10 . 58FE94EF42E074F4CAD8BF02E70E6478 . 660480 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB978207$\wininet.dll

                              [-] 2008-04-14 . FB836F9E62D82904C983AD21296A5D9C . 82432 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ws2_32.dll
                              [-] 2004-08-10 . BC41F51A39D3B255805FDB759B7814AE . 82944 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ws2_32.dll
                              [-] 2004-08-10 . BC41F51A39D3B255805FDB759B7814AE . 82944 . . [5.1.2600.2180] . . c:\windows\system32\ws2_32.dll

                              [-] 2008-04-14 . 36A608BF354FCC64AD6C0F2B5E2B8806 . 19968 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ws2help.dll
                              [-] 2004-08-10 . CB99D66483437E06286D4401A151D4E4 . 19968 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ws2help.dll
                              [-] 2004-08-10 . CB99D66483437E06286D4401A151D4E4 . 19968 . . [5.1.2600.2180] . . c:\windows\system32\ws2help.dll

                              [-] 2008-04-14 . F2317622D29F9FF0F88AEECD5F60F0DD . 1037824 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\explorer.exe
                              [-] 2004-08-10 . 4C33E5B9A6197B6ED215F6CFBA0A2DAA . 1036288 . . [6.00.2900.2180] . . c:\windows\explorer.exe
                              [-] 2004-08-10 . 4C33E5B9A6197B6ED215F6CFBA0A2DAA . 1036288 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\explorer.exe

                              [-] 2008-04-14 . 9245FAF86A8235D5290A23C010DABD43 . 1287168 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ole32.dll
                              [-] 2004-08-10 . A2AD7FCB806A2035F506664883F45B32 . 1281024 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ole32.dll
                              [-] 2004-08-10 . A2AD7FCB806A2035F506664883F45B32 . 1281024 . . [5.1.2600.2180] . . c:\windows\system32\ole32.dll

                              [-] 2008-04-14 . 6ED29124A1C83BD0CF6B26BD01CA6F6F . 171520 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\srsvc.dll
                              [-] 2004-08-10 . 6469C53F4D16FA6055CCA265BC03DB66 . 171008 . . [5.1.2600.2180] . . c:\windows\system32\srsvc.dll
                              [-] 2004-08-10 . 6469C53F4D16FA6055CCA265BC03DB66 . 171008 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\srsvc.dll

                              [-] 2008-04-14 . 02DA31AB433A6C1110A736C85701DECA . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\wscntfy.exe
                              [-] 2004-08-10 . 54CDDAD404557ED98433D6ECBFC92691 . 13824 . . [5.1.2600.2180] . . c:\windows\system32\wscntfy.exe
                              [-] 2004-08-10 . 54CDDAD404557ED98433D6ECBFC92691 . 13824 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\wscntfy.exe

                              [-] 2008-04-14 . F92A87FDDA0C11C8604FBC2B864FA726 . 129024 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\xmlprov.dll
                              [-] 2004-08-10 . 21056AEF44322C3E2DD5391B6AEFA75A . 129536 . . [5.1.2600.2180] . . c:\windows\system32\xmlprov.dll
                              [-] 2004-08-10 . 21056AEF44322C3E2DD5391B6AEFA75A . 129536 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\xmlprov.dll

                              [-] 2008-04-14 . 4EC800BDF80521B0207BD2301DFC7D14 . 56320 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\eventlog.dll
                              [-] 2004-08-10 . 21E83876A6287F15538EF187D286FE11 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\eventlog.dll
                              [-] 2004-08-10 . 21E83876A6287F15538EF187D286FE11 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\eventlog.dll

                              [-] 2008-04-14 . E17C85D5B5CF477638433B851A98499E . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\sfcfiles.dll
                              [-] 2004-08-10 . ACF04FB3448D2C2CD3A851C138EC8AB6 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfcfiles.dll
                              [-] 2004-08-10 . ACF04FB3448D2C2CD3A851C138EC8AB6 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

                              [-] 2008-04-14 . 59DC5BB82E4C8E0B3EADCFDBC44BA6E4 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ctfmon.exe
                              [-] 2004-08-10 . 5584247B568C2E53934873F4B655FE6A . 15360 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe
                              [-] 2004-08-10 . 5584247B568C2E53934873F4B655FE6A . 15360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ctfmon.exe

                              [-] 2008-04-14 . B9F20D71E5B6CE89A7A94B38351FDBDC . 135680 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\shsvcs.dll
                              [-] 2004-08-10 . B590E69A45AE8FCBF7DDADE89CCE3588 . 135168 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\shsvcs.dll
                              [-] 2004-08-10 . B590E69A45AE8FCBF7DDADE89CCE3588 . 135168 . . [6.00.2900.2180] . . c:\windows\system32\shsvcs.dll

                              [-] 2008-04-14 . E598D81197E2E0EC42A0C55772BB00E8 . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\regsvc.dll
                              [-] 2004-08-10 . 345D02087F5696749C6120359B1E2988 . 59904 . . [5.1.2600.2180] . . c:\windows\system32\regsvc.dll
                              [-] 2004-08-10 . 345D02087F5696749C6120359B1E2988 . 59904 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\regsvc.dll

                              [-] 2008-04-14 . 55F5C5C1BE1A78E285033E432BA01597 . 194560 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\schedsvc.dll
                              [-] 2004-08-10 . 4612EC6DAF695B87A2529FCBB95B75DE . 193024 . . [5.1.2600.2180] . . c:\windows\system32\schedsvc.dll
                              [-] 2004-08-10 . 4612EC6DAF695B87A2529FCBB95B75DE . 193024 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\schedsvc.dll

                              [-] 2008-04-14 . EA9E0DB8684CEF2FD3BADD671DF5A112 . 71680 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ssdpsrv.dll
                              [-] 2004-08-10 . B636478A2569AE69CAF003254022A742 . 71680 . . [5.1.2600.2180] . . c:\windows\system32\ssdpsrv.dll
                              [-] 2004-08-10 . B636478A2569AE69CAF003254022A742 . 71680 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ssdpsrv.dll

                              [-] 2008-04-14 . 710BC85A8C22626EE094439E3EA0D38C . 297984 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\termsrv.dll
                              [-] 2004-08-10 . 7D521B8CF926459E270D18C559323815 . 297984 . . [5.1.2600.2180] . . c:\windows\system32\termsrv.dll
                              [-] 2004-08-10 . 7D521B8CF926459E270D18C559323815 . 297984 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\termsrv.dll

                              [-] 2008-04-14 . F36C9F78FC902C8DCE4D3B576BB0435A . 176640 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\appmgmts.dll
                              [-] 2004-08-10 . CE66077813D83C2D6908CDC64AE7E55A . 176640 . . [5.1.2600.2180] . . c:\windows\system32\appmgmts.dll
                              [-] 2004-08-10 . CE66077813D83C2D6908CDC64AE7E55A . 176640 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\appmgmts.dll

                              [-] 2004-08-10 . E4ABC1212B70BB03D35E60681C447210 . 12032 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

                              [-] 2008-04-13 15:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\aec.sys
                              [-] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\drivers\aec.sys
                              [-] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\dllcache\aec.sys

                              [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ip6fw.sys
                              [-] 2004-08-10 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ip6fw.sys
                              [-] 2004-08-10 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ip6fw.sys

                              [-] 2008-04-14 01:33 . CE21FE79AD3B913A79E0C742BED6BF85 . 927504 . . [4.1.0.61] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\mfc40u.dll
                              [-] 2004-08-10 12:00 . E1A34560BF6CE7C703BB67EC4FA70F43 . 924432 . . [4.1.6140] . . c:\windows\system32\mfc40u.dll
                              [-] 2004-08-10 12:00 . E1A34560BF6CE7C703BB67EC4FA70F43 . 924432 . . [4.1.6140] . . c:\windows\system32\dllcache\mfc40u.dll

                              [-] 2008-04-14 . E67A66A3781C1A483F0F8992664CBE0D . 33792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\msgsvc.dll
                              [-] 2004-08-10 . 97939358ED4487CBB4A0D743CE958266 . 33792 . . [5.1.2600.2180] . . c:\windows\system32\msgsvc.dll
                              [-] 2004-08-10 . 97939358ED4487CBB4A0D743CE958266 . 33792 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\msgsvc.dll

                              [-] 2004-08-10 12:00 . B751CE6043B33A2EFEABB2D6BA83EC67 . 25600 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll
                              [-] 2004-08-10 12:00 . B751CE6043B33A2EFEABB2D6BA83EC67 . 25600 . . [10.0.3790.3646] . . c:\windows\system32\dllcache\mspmsnsv.dll

                              [-] 2010-02-17 . 0757B640C97B21A44333E786D40526F6 . 2065792 . . [5.1.2600.3670] . . c:\windows\system32\dllcache\ntkrnlpa.exe
                              [-] 2010-02-17 . 0757B640C97B21A44333E786D40526F6 . 2065792 . . [5.1.2600.3670] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
                              [-] 2010-02-16 . F1D18F019F6A6FC54C3880CB10FCB1A7 . 2023936 . . [5.1.2600.3670] . . c:\windows\system32\ntkrnlpa.exe
                              [-] 2010-02-16 . 4394E451E25D9A01344D91BB16CF35CB . 2068864 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3GDR\ntkrnlpa.exe
                              [-] 2010-02-16 . 6CB7C9A8C7103FEA51B0D478128CEFC0 . 2068992 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe
                              [-] 2009-12-09 . 875EB5E5C8A6B3A2297D87029A880D23 . 2068224 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
                              [-] 2009-12-09 . E3032E946EB72B68B0A6064C49DD2382 . 2022912 . . [5.1.2600.3654] . . c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe
                              [-] 2009-12-09 . 4D169D0B512E2D39B2C1C371F055FBEA . 2068096 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3GDR\ntkrnlpa.exe
                              [-] 2009-08-04 . FE0C9C9035E3FDC193255C646BAC2C3D . 2068224 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
                              [-] 2009-08-04 . 6472BC2A0D37D13D9D177CCC11F9726B . 2068096 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3GDR\ntkrnlpa.exe
                              [-] 2009-08-04 . F33D8E4EF6AF136995639BDFA0466E23 . 2022912 . . [5.1.2600.3610] . . c:\windows\$NtUninstallKB977165$\ntkrnlpa.exe
                              [-] 2009-02-10 . F751E041E682F53EAF34F7FAEA78994D . 2068096 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntkrnlpa.exe
                              [-] 2009-02-09 . 0150FE5C1E07F8AE422FEC6C8E8A0C98 . 2065024 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntkrnlpa.exe
                              [-] 2009-02-09 . ED5E20AE4AC5A63A4FF43FFE704A5153 . 2068224 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
                              [-] 2008-04-14 . B71A8F101CEFAF82FC5EC16130A54A3F . 2067968 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ntkrnlpa.exe
                              [-] 2005-09-29 . 7A319C9E0C14ED6410E8B2753E3A32CE . 2017792 . . [5.1.2600.2765] . . c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe
                              [-] 2004-08-10 . 35567C8C50986C2BC5C3EFD79CB045E4 . 2017280 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896256$\ntkrnlpa.exe

                              [-] 2008-04-14 01:33 . 037D92B3A7853A183FCAB77FB1D13D6C . 438272 . . [5.1.2400.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ntmssvc.dll
                              [-] 2004-08-10 12:00 . 3F82A4226289510DF300813B9B87F0E5 . 438272 . . [5.1.2400.2180] . . c:\windows\system32\ntmssvc.dll
                              [-] 2004-08-10 12:00 . 3F82A4226289510DF300813B9B87F0E5 . 438272 . . [5.1.2400.2180] . . c:\windows\system32\dllcache\ntmssvc.dll

                              [-] 2008-04-14 . BD8166A495B02308F364B36249475F22 . 186368 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\upnphost.dll
                              [-] 2004-08-10 . 168AE9938F6BE31D198AF92496CCFA33 . 185344 . . [5.1.2600.2180] . . c:\windows\system32\upnphost.dll
                              [-] 2004-08-10 . 168AE9938F6BE31D198AF92496CCFA33 . 185344 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\upnphost.dll

                              [-] 2008-04-14 . 4BB396EA6CAA50F2208078602549F2F2 . 367616 . . [5.3.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\dsound.dll
                              [-] 2004-08-10 . 0AE00CA307264649EE2F5FC1CB1B0F1F . 367616 . . [5.3.2600.2180] . . c:\windows\system32\dsound.dll
                              [-] 2004-08-10 . 0AE00CA307264649EE2F5FC1CB1B0F1F . 367616 . . [5.3.2600.2180] . . c:\windows\system32\dllcache\dsound.dll

                              [-] 2008-04-14 . 7EAEC24B85DD04EDAA04A51CB07DF870 . 1689088 . . [5.03.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\d3d9.dll
                              [-] 2004-08-10 . EA9F86E5892D85E282311C53083903DC . 1689088 . . [5.03.2600.2180] . . c:\windows\system32\d3d9.dll
                              [-] 2004-08-10 . EA9F86E5892D85E282311C53083903DC . 1689088 . . [5.03.2600.2180] . . c:\windows\system32\dllcache\d3d9.dll

                              [-] 2008-04-14 . 75BD925DAB6E5323EDB6D5CFCDEB16D1 . 279552 . . [5.03.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ddraw.dll
                              [-] 2004-08-10 . 20A4E9DA85A1FF521AC5325FC3BADDF9 . 266240 . . [5.03.2600.2180] . . c:\windows\system32\ddraw.dll
                              [-] 2004-08-10 . 20A4E9DA85A1FF521AC5325FC3BADDF9 . 266240 . . [5.03.2600.2180] . . c:\windows\system32\dllcache\ddraw.dll

                              [-] 2008-04-14 01:33 . 3BA21BD333A1B8B222006E5464D44F49 . 84992 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\olepro32.dll
                              [-] 2004-08-10 12:00 . 5860F5A42B67EC8BBB5AA3CE7ABC9976 . 83456 . . [5.1.2600.2180] . . c:\windows\system32\olepro32.dll
                              [-] 2004-08-10 12:00 . 5860F5A42B67EC8BBB5AA3CE7ABC9976 . 83456 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\olepro32.dll

                              [-] 2008-04-14 . 08592889A219F7A60F9865B0EE7CAFF8 . 42496 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\perfctrs.dll
                              [-] 2004-08-10 . 719682744477D57B30248F4479EE8D0D . 42496 . . [5.1.2600.2180] . . c:\windows\system32\perfctrs.dll
                              [-] 2004-08-10 . 719682744477D57B30248F4479EE8D0D . 42496 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\perfctrs.dll

                              [-] 2008-04-14 . A71A42AD584FAD1A8D1EC5D807C6E528 . 18944 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\version.dll
                              [-] 2004-08-10 . 8B142E6DAC3BD370637E8AF6E87C2321 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\version.dll
                              [-] 2004-08-10 . 8B142E6DAC3BD370637E8AF6E87C2321 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\version.dll

                              [-] 2008-04-14 . 3D3C316BD1E112F3B9C532D8B9939BDC . 93184 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\iexplore.exe
                              [-] 2004-08-10 . 833E2B3F0E2484C0F2B804AE871B4381 . 93184 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\iexplore.exe
                              .
                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                              "FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe" [2010-07-26 231888]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
                              "ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
                              "ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
                              "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
                              "SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]
                              "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-02-15 417792]
                              "Nikon Transfer Monitor"="c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
                              "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
                              "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
                              "EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-12-28 569413]
                              "RTHDCPL"="RTHDCPL.EXE" [2010-09-03 19573352]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-10 15360]

                              c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
                              Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
                              2005-11-08 09:23 17920 ----a-w- c:\program files\ASUS\Splendid\ACMON.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
                              2006-01-02 16:41 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATKMEDIA]
                              2006-02-15 08:38 49152 ----a-w- c:\program files\ASUS\ATK Media\DMedia.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
                              2009-03-02 10:08 209153 ----a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
                              2004-08-03 22:55 110592 ----a-w- c:\windows\system32\bthprops.cpl

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
                              2004-08-27 13:22 58488 ----a-w- c:\program files\Fichiers communs\Symantec Shared\ccApp.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
                              2010-07-07 12:58 136176 ----a-w- c:\documents and settings\Vincent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
                              2007-10-14 19:17 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
                              2004-08-17 12:36 132248 ----a-w- c:\program files\Norton Internet Security\CfgWiz.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power_Gear]
                              2006-01-16 08:22 86016 ----a-w- c:\program files\ASUS\Power4 Gear\BatteryLife.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
                              2004-08-05 07:23 218240 ----a-w- c:\program files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
                              2005-10-20 21:26 761945 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
                              2004-08-30 16:29 33936 ----a-w- c:\program files\Norton Internet Security\UrlLstCk.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 2]
                              2005-10-17 15:09 987136 ----a-w- c:\program files\Wireless Console 2\wcourier.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                              "SPBBCSvc"=3 (0x3)
                              "SNDSrvc"=3 (0x3)
                              "SBService"=2 (0x2)
                              "navapsvc"=2 (0x2)
                              "ccSetMgr"=2 (0x2)
                              "ccPwdSvc"=3 (0x3)
                              "ccProxy"=2 (0x2)
                              "ccEvtMgr"=2 (0x2)
                              "ITECIRService"=2 (0x2)
                              "Ati HotKey Poller"=2 (0x2)

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                              "DisableMonitoring"=dword:00000001

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                              "EnableFirewall"= 0 (0x0)

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                              "%windir%\\system32\\sessmgr.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
                              "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                              "c:\\Program Files\\adslTV\\adsltv.exe"=
                              "c:\\Documents and Settings\\Vincent\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=

                              R2 ALSDrvr;Alesis Disk Driver;c:\windows\system32\drivers\alsdrvr.sys [23/03/2010 18:21 5119]
                              R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [18/02/2010 18:53 108289]
                              R3 ITECIR;ITE CIR Driver;c:\windows\system32\drivers\ITECIR.sys [16/02/2010 19:08 7366]
                              R3 SynMini;USB2.0 1.3M Web Cam;c:\windows\system32\drivers\SynMini.sys [16/02/2010 18:11 702326]
                              R3 SynScan;USB2.0 1.3M Web Cam Still Image;c:\windows\system32\drivers\SynScan.sys [16/02/2010 18:12 4790]
                              S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [25/10/2010 16:34 1691480]
                              S3 RDID1061;EDIROL UA-4FX;c:\windows\system32\drivers\Rdwm1061.sys [26/02/2010 17:05 174834]
                              S3 synasusb;eLicenser;c:\windows\system32\drivers\synasusb.sys [16/02/2010 21:59 23696]
                              S4 ITECIRService;ITE Remote Control Service;c:\windows\system32\RemoteControlService.exe [16/02/2010 19:08 656384]

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                              HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                              hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
                              .
                              Contenu du dossier 'Tâches planifiées'

                              2010-02-16 c:\windows\Tasks\Symantec NetDetect.job
                              - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2010-02-16 15:26]

                              2010-10-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1407359021-3251276571-90534096-1005Core.job
                              - c:\documents and settings\Vincent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-07 12:58]
                              .
                              .
                              ------- Examen supplémentaire -------
                              .
                              uInternet Connection Wizard,ShellNext = hxxp://www.asus.com/
                              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
                              FF - ProfilePath - c:\documents and settings\Vincent\Application Data\Mozilla\Firefox\Profiles\7lqxz3fi.default\
                              FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
                              FF - plugin: c:\documents and settings\Vincent\Application Data\Mozilla\plugins\npgoogletalk.dll
                              FF - plugin: c:\documents and settings\Vincent\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
                              FF - plugin: c:\documents and settings\Vincent\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
                              FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
                              FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                              FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

                              ---- PARAMETRES FIREFOX ----
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
                              c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
                              c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
                              .
                              - - - - ORPHELINS SUPPRIMES - - - -

                              HKLM-Run-Zshutdown - c:\sysprep\patch\sysprep.cmd
                              MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
                              MSConfigStartUp-PowerForPhone - c:\program files\ASUS\PowerForPhone\PowerForPhone.exe
                              AddRemove-HijackThis - H:\HijackThis.exe

                              **************************************************************************
                              Recherche de processus cachés ...

                              Recherche d'éléments en démarrage automatique cachés ...

                              Recherche de fichiers cachés ...

                              Scan terminé avec succès
                              Fichiers cachés:

                              **************************************************************************
                              .
                              --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                              [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð*€|ÿÿÿÿ.*€|þ»Ñw*]
                              "AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
                              .
                              --------------------- DLLs chargées dans les processus actifs ---------------------

                              - - - - - - - > 'winlogon.exe'(944)
                              c:\windows\system32\Ati2evxx.dll
                              .
                              Heure de fin: 2010-10-27 18:12:41
                              ComboFix-quarantined-files.txt 2010-10-27 16:12

                              Avant-CF: 23 821 352 960 octets libres
                              Après-CF: 24 541 986 816 octets libres

                              - - End Of File - - 3141C25E989C0A26B66982F56C2D766B
                              1. le lancement de combofix ne fonctionne pas ! rien ne s'inscrit . je me suis déconnecté avant le double clic ... j'ai fait plusieurs tentatives en redémarrant
                                1. Contributeur sécurité
                                  Attention, avant de commencer, lit attentivement la procédure, et imprime la

                                  Aide à l'utilisation
                                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                                  Télécharge ComboFix de sUBs sur ton Bureau :

                                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                  /!\ Déconnecte-toi du net et <gras>DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\ </gras>

                                  ---> Double-clique sur ComboFix.exe
                                  Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                                  SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
                                  (si il te propose de l'installer remets internet)

                                  ---> Mets-le en langue française F
                                  Tape sur la touche 1 (Yes) pour démarrer le scan.

                                  Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                                  En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                                  Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                                  /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                                  Note : Le rapport se trouve également là : C:\ComboFix.txt

                                  • 1
                                  • 2