Bonsoir
au msg precedent le rapport de Malwarebyte
et le 3° demandé (combofix) :
ComboFix 09-08-27.01 - Dudu 27/08/2009 20:47.2.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1535.1198 [GMT 2:00]
Running from: c:\documents and settings\Dudu\Mes documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
.
2009-08-22 05:34 . 2009-08-22 05:34 152576 ----a-w- c:\documents and settings\Dudu\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-20 17:56 . 2009-08-27 13:03 -------- d-----w- C:\FindyKill
2009-08-19 10:20 . 2009-08-22 10:42 -------- d-----w- c:\windows\BDOSCAN8
2009-08-18 11:40 . 2008-11-20 19:19 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-08-18 11:40 . 2008-11-20 19:19 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-08-18 11:11 . 2009-08-18 11:11 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-08-17 17:06 . 2009-08-17 17:06 -------- d-----w- c:\program files\ESET
2009-08-15 20:33 . 2009-08-15 20:33 1961720 ----a-w- c:\documents and settings\Dudu\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-08-03 19:32 . 2009-08-03 19:32 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-03 19:31 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 19:31 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-03 15:20 . 2009-08-03 15:20 -------- d-sh--w- c:\documents and settings\Dudu\PrivacIE
2009-08-03 12:28 . 2009-08-03 12:28 -------- d-sh--w- c:\documents and settings\Dudu\IETldCache
2009-08-03 12:25 . 2009-07-03 16:57 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-08-03 12:25 . 2009-07-03 16:57 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-03 12:25 . 2009-08-03 12:25 -------- d-----w- c:\windows\ie8updates
2009-08-03 12:24 . 2009-07-01 07:08 101376 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-08-03 12:22 . 2009-08-03 12:24 -------- dc-h--w- c:\windows\ie8
2009-08-03 12:19 . 2009-08-03 12:19 152576 ----a-w- c:\documents and settings\Dudu\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-08-02 20:03 . 2009-08-17 17:40 -------- d-----w- c:\program files\Ad-remover
2009-08-02 19:29 . 2009-08-11 20:40 -------- d-----w- C:\ToolBar SD
2009-08-01 17:32 . 2009-08-27 15:16 -------- d-----w- c:\program files\trend micro
2009-08-01 17:32 . 2009-08-01 17:33 -------- d-----w- C:\rsit
2009-08-01 13:53 . 2009-08-18 13:02 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-01 13:53 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-08-01 13:53 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-08-01 13:53 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-08-01 13:53 . 2009-08-01 13:53 -------- d-----w- c:\program files\Avira
2009-08-01 13:53 . 2009-08-01 13:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-08-01 07:19 . 2009-08-11 20:43 -------- d-----w- C:\GenProc
2009-07-31 19:45 . 2009-07-31 19:45 -------- d-----w- c:\documents and settings\Dudu\Application Data\Malwarebytes
2009-07-31 19:45 . 2009-08-03 19:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-31 19:45 . 2009-07-31 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-31 19:20 . 2009-07-31 19:20 -------- d-----w- c:\program files\CCleaner
2009-07-30 18:44 . 2009-07-30 18:44 -------- d-----w- c:\documents and settings\Dudu\Application Data\Snapfish
2009-07-30 18:44 . 2009-07-30 18:44 -------- d-----w- c:\documents and settings\Dudu\Local Settings\Application Data\Snapfish
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2060-08-18 17:02 . 2005-08-10 16:26 1496064 -c----w- c:\windows\system32\CC3250MT.DLL
2060-08-18 16:40 . 2005-08-10 16:26 909824 -c----w- c:\windows\system32\cp3245mt.dll
2060-08-18 16:40 . 2005-08-10 16:26 24064 -c----w- c:\windows\system32\borlndmm.dll
2009-08-27 17:47 . 2009-03-11 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-27 13:09 . 2006-03-06 05:22 -------- d-----w- c:\documents and settings\Dudu\Application Data\OpenOffice.org2
2009-08-22 05:35 . 2004-11-18 01:12 -------- d-----w- c:\program files\Java
2009-08-19 06:25 . 2004-11-18 01:02 65362 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-19 06:25 . 2004-11-18 01:02 449322 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-18 11:10 . 2005-11-01 11:18 -------- d-----w- c:\program files\Google
2009-08-17 17:46 . 2004-11-18 01:15 -------- d-----w- c:\program files\Jasc Software Inc
2009-08-11 19:35 . 2005-10-01 19:59 -------- d-----w- c:\documents and settings\Dudu\Application Data\Skype
2009-08-05 09:00 . 2004-08-05 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 19:37 . 2004-11-18 01:13 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-25 03:23 . 2009-02-18 13:42 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:03 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-05 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 16:57 . 2004-08-05 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-16 14:40 . 2004-08-05 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2004-08-05 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 10:44 . 2004-08-05 12:00 78848 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:14 . 2004-08-05 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 07:21 . 2004-08-05 12:00 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:15 . 2004-08-05 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:10 . 2004-08-05 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2008-05-23 07:49 . 2008-05-23 07:49 15397 -c--a-w- c:\program files\settings.dat
2008-03-19 08:01 . 2008-07-20 15:43 3114816 -c--a-w- c:\program files\LBP.EXE
2008-04-29 11:16 . 2007-09-30 08:17 88 -csh--r- c:\windows\SYSTEM32\E93BEE3297.sys
2008-04-29 11:16 . 2007-09-30 08:17 2516 -csha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
------- Sigcheck -------
[7] 2004-08-05 12:00 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\SYSTEM32\DLLCACHE\beep.sys
c:\windows\system32\drivers\beep.sys ... is missing !!
.
(((((((((((((((((((((((((((((
SnapShot@2009-08-01_13.12.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 00:19 . 2007-11-07 00:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2004-05-20 01:00 . 2008-11-20 19:19 88560 c:\windows\SYSTEM32\VXBLOCK.dll
+ 2007-01-29 08:58 . 2009-07-14 11:03 46080 c:\windows\SYSTEM32\tzchange.exe
+ 2005-06-29 20:59 . 2009-01-07 16:21 26144 c:\windows\SYSTEM32\spupdsvc.exe
+ 2007-05-28 06:34 . 2009-01-07 16:21 17952 c:\windows\SYSTEM32\spmsg.dll
+ 2009-08-18 11:40 . 2008-11-20 19:19 72176 c:\windows\SYSTEM32\pxhpinst.exe
+ 2004-08-05 12:00 . 2009-03-08 02:31 46592 c:\windows\SYSTEM32\pngfilt.dll
+ 2004-11-18 01:02 . 2009-08-19 06:25 54280 c:\windows\SYSTEM32\PERFC009.DAT
- 2004-11-18 01:02 . 2009-04-25 12:20 54280 c:\windows\SYSTEM32\PERFC009.DAT
- 2006-06-29 07:05 . 2006-06-29 07:05 23552 c:\windows\SYSTEM32\normaliz.dll
+ 2006-06-29 07:05 . 2009-01-07 16:20 23552 c:\windows\SYSTEM32\normaliz.dll
- 2006-06-28 16:59 . 2006-06-28 16:59 24576 c:\windows\SYSTEM32\nlsdl.dll
+ 2006-06-28 16:59 . 2009-01-07 16:20 24576 c:\windows\SYSTEM32\nlsdl.dll
+ 2004-08-05 12:00 . 2009-03-08 02:31 48128 c:\windows\SYSTEM32\mshtmler.dll
- 2004-08-05 12:00 . 2006-10-17 10:28 48128 c:\windows\SYSTEM32\mshtmler.dll
+ 2004-08-05 12:00 . 2009-03-08 02:31 66560 c:\windows\SYSTEM32\mshtmled.dll
- 2004-08-05 12:00 . 2006-10-17 10:56 45568 c:\windows\SYSTEM32\mshta.exe
+ 2004-08-05 12:00 . 2009-03-08 02:31 45568 c:\windows\SYSTEM32\mshta.exe
+ 2006-10-17 10:58 . 2009-03-08 02:31 13312 c:\windows\SYSTEM32\msfeedssync.exe
+ 2006-11-07 20:03 . 2009-07-03 16:57 55296 c:\windows\SYSTEM32\msfeedsbs.dll
+ 2009-08-01 18:26 . 2009-08-01 18:26 84661 c:\windows\SYSTEM32\Macromed\Flash\uninstall_plugin.exe
+ 2008-04-21 08:03 . 2009-08-15 20:33 88589 c:\windows\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
+ 2004-08-05 12:00 . 2009-03-08 02:34 43008 c:\windows\SYSTEM32\licmgr10.dll
+ 2004-08-05 12:00 . 2009-07-03 16:57 25600 c:\windows\SYSTEM32\jsproxy.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 94720 c:\windows\SYSTEM32\inseng.dll
+ 2004-08-05 12:00 . 2009-03-08 02:31 34816 c:\windows\SYSTEM32\imgutil.dll
+ 2006-11-07 02:26 . 2009-03-08 02:32 36864 c:\windows\SYSTEM32\ieudinit.exe
+ 2004-08-05 12:00 . 2009-03-08 02:32 71680 c:\windows\SYSTEM32\iesetup.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 55808 c:\windows\SYSTEM32\iernonce.dll
+ 2006-06-29 07:05 . 2009-01-07 16:20 26112 c:\windows\SYSTEM32\idndl.dll
- 2006-06-29 07:05 . 2006-06-29 07:05 26112 c:\windows\SYSTEM32\idndl.dll
+ 2006-10-17 10:58 . 2009-03-08 02:31 59904 c:\windows\SYSTEM32\icardie.dll
+ 2009-08-01 13:53 . 2009-08-01 13:58 28520 c:\windows\SYSTEM32\DRIVERS\ssmdrv.sys
+ 2008-11-20 19:19 . 2008-11-20 19:19 43872 c:\windows\SYSTEM32\DRIVERS\pxhelp20.sys
+ 2004-08-05 12:00 . 2009-06-15 10:44 78848 c:\windows\SYSTEM32\DLLCACHE\telnet.exe
+ 2006-05-10 05:24 . 2009-03-08 02:31 46592 c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2004-08-05 12:00 . 2009-03-08 02:31 48128 c:\windows\SYSTEM32\DLLCACHE\mshtmler.dll
- 2004-08-05 12:00 . 2006-10-17 10:28 48128 c:\windows\SYSTEM32\DLLCACHE\mshtmler.dll
+ 2006-05-10 05:24 . 2009-03-08 02:31 66560 c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
- 2004-08-05 12:00 . 2006-10-17 10:56 45568 c:\windows\SYSTEM32\DLLCACHE\mshta.exe
+ 2004-08-05 12:00 . 2009-03-08 02:31 45568 c:\windows\SYSTEM32\DLLCACHE\mshta.exe
+ 2007-05-09 10:39 . 2009-07-03 16:57 55296 c:\windows\SYSTEM32\DLLCACHE\msfeedsbs.dll
+ 2004-08-05 12:00 . 2009-03-08 02:34 43008 c:\windows\SYSTEM32\DLLCACHE\licmgr10.dll
+ 2004-08-05 12:00 . 2009-07-03 16:57 25600 c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 94720 c:\windows\SYSTEM32\DLLCACHE\inseng.dll
+ 2006-10-17 10:57 . 2009-03-08 02:31 34816 c:\windows\SYSTEM32\DLLCACHE\imgutil.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 71680 c:\windows\SYSTEM32\DLLCACHE\iesetup.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 55808 c:\windows\SYSTEM32\DLLCACHE\iernonce.dll
+ 2007-08-20 09:59 . 2009-03-08 02:31 59904 c:\windows\SYSTEM32\DLLCACHE\icardie.dll
+ 2004-08-05 12:00 . 2009-03-08 02:24 68608 c:\windows\SYSTEM32\DLLCACHE\hmmapi.dll
+ 2009-06-29 15:57 . 2009-03-08 02:33 18944 c:\windows\SYSTEM32\DLLCACHE\corpol.dll
+ 2009-06-10 14:14 . 2009-06-10 14:14 85504 c:\windows\SYSTEM32\DLLCACHE\avifil32.dll
+ 2009-07-17 19:03 . 2009-07-17 19:03 58880 c:\windows\SYSTEM32\DLLCACHE\atl.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 72704 c:\windows\SYSTEM32\DLLCACHE\admparse.dll
+ 2004-08-05 12:00 . 2009-03-08 02:33 18944 c:\windows\SYSTEM32\corpol.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 72704 c:\windows\SYSTEM32\admparse.dll
- 2005-02-05 08:25 . 2009-07-15 15:03 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-08-03 12:26 . 2009-03-08 02:33 12288 c:\windows\ie8updates\KB972260-IE8\xpshims.dll
+ 2009-08-03 12:26 . 2009-03-08 02:31 55296 c:\windows\ie8updates\KB972260-IE8\msfeedsbs.dll
+ 2009-08-03 12:26 . 2009-03-08 02:33 25600 c:\windows\ie8updates\KB972260-IE8\jsproxy.dll
+ 2009-08-03 12:23 . 2009-03-08 14:14 58448 c:\windows\ie8\spuninst\iecustom.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 44544 c:\windows\ie8\pngfilt.dll
+ 2009-08-03 12:22 . 2006-10-17 10:28 48128 c:\windows\ie8\mshtmler.dll
+ 2009-08-03 12:22 . 2006-10-17 10:56 45568 c:\windows\ie8\mshta.exe
+ 2009-08-03 12:22 . 2006-10-17 10:58 12288 c:\windows\ie8\msfeedssync.exe
+ 2009-08-03 12:22 . 2009-06-29 15:57 52224 c:\windows\ie8\msfeedsbs.dll
+ 2009-08-03 12:22 . 2006-10-17 11:05 40960 c:\windows\ie8\licmgr10.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 27648 c:\windows\ie8\jsproxy.dll
+ 2009-08-03 12:22 . 2006-11-07 02:26 92672 c:\windows\ie8\inseng.dll
+ 2009-08-03 12:22 . 2006-10-17 10:57 36352 c:\windows\ie8\imgutil.dll
+ 2009-08-03 12:22 . 2006-11-07 02:26 55296 c:\windows\ie8\iesetup.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 44544 c:\windows\ie8\iernonce.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 78336 c:\windows\ie8\ieencode.dll
+ 2009-08-03 12:22 . 2009-06-29 11:07 70656 c:\windows\ie8\ie4uinit.exe
+ 2009-08-03 12:22 . 2009-06-29 15:57 63488 c:\windows\ie8\icardie.dll
+ 2009-08-03 12:22 . 2006-10-17 10:44 60416 c:\windows\ie8\hmmapi.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 17408 c:\windows\ie8\corpol.dll
+ 2009-08-03 12:22 . 2006-11-07 02:26 71680 c:\windows\ie8\admparse.dll
+ 2006-05-24 23:21 . 2006-05-24 23:21 53248 c:\windows\Downloaded Program Files\ipsupd.dll
+ 2006-05-24 23:22 . 2006-05-24 23:22 53248 c:\windows\bdoscandel.exe
+ 2009-08-19 10:23 . 2009-08-19 10:23 86016 c:\windows\BDOSCAN8\librtvr.dll
+ 2006-05-24 23:21 . 2006-05-24 23:21 53248 c:\windows\BDOSCAN8\ipsupd.dll
+ 2009-08-19 10:23 . 2009-08-19 10:23 27136 c:\windows\BDOSCAN8\avxt.dll
+ 2009-08-19 10:23 . 2009-08-19 10:23 10240 c:\windows\BDOSCAN8\avxs.dll
+ 2009-08-19 10:23 . 2009-08-19 10:23 45056 c:\windows\BDOSCAN8\avxdisk.dll
- 2005-02-05 08:25 . 2009-07-15 15:03 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-08-03 12:25 . 2009-03-08 02:35 2048 c:\windows\ie8updates\KB972636-IE8\iecompat.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 01:54 . 2008-07-29 01:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
- 2006-12-07 18:24 . 2008-04-14 02:33 121856 c:\windows\SYSTEM32\xmllite.dll
+ 2006-12-07 18:24 . 2009-01-07 16:21 121856 c:\windows\SYSTEM32\xmllite.dll
+ 2006-10-17 11:05 . 2009-03-08 02:34 208384 c:\windows\SYSTEM32\WinFXDocObj.exe
+ 2004-08-05 12:00 . 2009-03-08 02:34 236544 c:\windows\SYSTEM32\webcheck.dll
+ 2004-08-05 12:00 . 2009-03-08 02:33 420352 c:\windows\SYSTEM32\vbscript.dll
+ 2004-08-05 12:00 . 2009-03-08 02:34 105984 c:\windows\SYSTEM32\url.dll
- 2004-08-05 12:00 . 2009-06-29 15:57 105984 c:\windows\SYSTEM32\url.dll
+ 2004-08-24 15:04 . 2008-11-20 19:19 379376 c:\windows\SYSTEM32\PxWave.dll
+ 2004-08-24 15:04 . 2008-11-20 19:19 186864 c:\windows\SYSTEM32\pxmas.dll
+ 2004-09-07 01:01 . 2008-11-20 19:19 543216 c:\windows\SYSTEM32\pxdrv.dll
+ 2004-08-24 15:05 . 2008-11-20 19:19 588272 c:\windows\SYSTEM32\Px.dll
- 2004-11-18 01:02 . 2009-04-25 12:20 384596 c:\windows\SYSTEM32\PERFH009.DAT
+ 2004-11-18 01:02 . 2009-08-19 06:25 384596 c:\windows\SYSTEM32\PERFH009.DAT
+ 2004-08-05 12:00 . 2009-07-03 16:57 206848 c:\windows\SYSTEM32\occache.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 611840 c:\windows\SYSTEM32\mstime.dll
+ 2004-08-05 12:00 . 2009-03-08 02:34 193536 c:\windows\SYSTEM32\msrating.dll
- 2004-08-05 12:00 . 2006-11-07 20:03 156160 c:\windows\SYSTEM32\msls31.dll
+ 2004-08-05 12:00 . 2009-03-08 02:22 156160 c:\windows\SYSTEM32\msls31.dll
+ 2006-11-07 20:03 . 2009-07-03 16:57 594432 c:\windows\SYSTEM32\msfeeds.dll
+ 2009-01-07 16:20 . 2009-01-07 16:20 265720 c:\windows\SYSTEM32\msdbg2.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\SYSTEM32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\SYSTEM32\Macromed\Flash\FlashUtil10c.exe
+ 2004-08-05 12:00 . 2009-03-08 02:33 726528 c:\windows\SYSTEM32\jscript.dll
+ 2009-08-22 05:35 . 2009-07-25 03:23 149280 c:\windows\SYSTEM32\javaws.exe
+ 2009-08-22 05:35 . 2009-07-25 03:23 145184 c:\windows\SYSTEM32\javaw.exe
+ 2009-08-22 05:35 . 2009-07-25 03:23 145184 c:\windows\SYSTEM32\java.exe
+ 2006-11-07 20:03 . 2009-03-08 02:22 164352 c:\windows\SYSTEM32\ieui.dll
+ 2004-08-05 12:00 . 2009-07-03 16:57 184320 c:\windows\SYSTEM32\iepeers.dll
+ 2004-08-05 12:00 . 2009-07-03 16:57 386048 c:\windows\SYSTEM32\iedkcs32.dll
+ 2006-10-17 10:27 . 2009-03-08 02:11 445952 c:\windows\SYSTEM32\ieapfltr.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 163840 c:\windows\SYSTEM32\ieakui.dll
+ 2004-08-05 12:00 . 2009-03-08 02:33 229376 c:\windows\SYSTEM32\ieaksie.dll
+ 2004-08-05 12:00 . 2009-03-08 02:33 125952 c:\windows\SYSTEM32\ieakeng.dll
+ 2004-08-05 12:00 . 2009-07-03 11:01 173056 c:\windows\SYSTEM32\ie4uinit.exe
+ 2004-08-05 12:00 . 2009-03-08 02:31 216064 c:\windows\SYSTEM32\dxtrans.dll
+ 2004-08-05 12:00 . 2009-03-08 02:31 348160 c:\windows\SYSTEM32\dxtmsft.dll
+ 2009-07-13 21:43 . 2009-07-13 21:43 286208 c:\windows\SYSTEM32\DLLCACHE\wmpdxm.dll
+ 2009-06-10 06:15 . 2009-06-10 06:15 132096 c:\windows\SYSTEM32\DLLCACHE\wkssvc.dll
+ 2006-05-10 05:24 . 2009-07-03 16:57 915456 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
+ 2006-11-07 20:03 . 2009-03-08 02:34 236544 c:\windows\SYSTEM32\DLLCACHE\webcheck.dll
+ 2004-08-05 12:00 . 2009-03-08 02:33 759296 c:\windows\SYSTEM32\DLLCACHE\VGX.dll
+ 2008-05-09 10:55 . 2009-03-08 02:33 420352 c:\windows\SYSTEM32\DLLCACHE\vbscript.dll
+ 2006-10-17 11:05 . 2009-03-08 02:34 105984 c:\windows\SYSTEM32\DLLCACHE\url.dll
- 2006-10-17 11:05 . 2009-06-29 15:57 105984 c:\windows\SYSTEM32\DLLCACHE\url.dll
+ 2009-01-07 16:20 . 2009-01-07 16:20 134144 c:\windows\SYSTEM32\DLLCACHE\sqmapi.dll
+ 2009-01-07 16:21 . 2009-01-07 16:21 474624 c:\windows\SYSTEM32\DLLCACHE\shlwapi.dll
+ 2006-10-17 11:04 . 2009-07-03 16:57 206848 c:\windows\SYSTEM32\DLLCACHE\occache.dll
+ 2004-08-05 12:00 . 2009-08-05 09:00 205312 c:\windows\SYSTEM32\DLLCACHE\mswebdvd.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 611840 c:\windows\SYSTEM32\DLLCACHE\mstime.dll
+ 2006-05-10 05:24 . 2009-03-08 02:34 193536 c:\windows\SYSTEM32\DLLCACHE\msrating.dll
- 2006-11-07 20:03 . 2006-11-07 20:03 156160 c:\windows\SYSTEM32\DLLCACHE\msls31.dll
+ 2006-11-07 20:03 . 2009-03-08 02:22 156160 c:\windows\SYSTEM32\DLLCACHE\msls31.dll
+ 2007-05-09 10:39 . 2009-07-03 16:57 594432 c:\windows\SYSTEM32\DLLCACHE\msfeeds.dll
+ 2008-05-09 10:55 . 2009-03-08 02:33 726528 c:\windows\SYSTEM32\DLLCACHE\jscript.dll
+ 2006-10-17 11:04 . 2009-03-08 12:09 638816 c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
+ 2006-05-10 05:24 . 2009-07-03 16:57 184320 c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
+ 2006-11-07 02:27 . 2009-07-03 16:57 386048 c:\windows\SYSTEM32\DLLCACHE\iedkcs32.dll
+ 2007-05-09 10:39 . 2009-03-08 02:11 445952 c:\windows\SYSTEM32\DLLCACHE\ieapfltr.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 163840 c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
+ 2004-08-05 12:00 . 2009-03-08 02:33 229376 c:\windows\SYSTEM32\DLLCACHE\ieaksie.dll
+ 2004-08-05 12:00 . 2009-03-08 02:33 125952 c:\windows\SYSTEM32\DLLCACHE\ieakeng.dll
+ 2006-11-07 02:26 . 2009-07-03 11:01 173056 c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
+ 2006-05-10 05:24 . 2009-03-08 02:31 216064 c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
+ 2006-05-10 05:24 . 2009-03-08 02:31 348160 c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
+ 2006-11-07 02:26 . 2009-03-08 02:32 128512 c:\windows\SYSTEM32\DLLCACHE\advpack.dll
+ 2004-08-05 12:00 . 2009-03-08 02:32 128512 c:\windows\SYSTEM32\advpack.dll
+ 2009-08-02 21:19 . 2009-08-02 21:19 195584 c:\windows\Installer\c78cdb.msi
+ 2009-08-01 13:51 . 2009-08-01 13:51 228352 c:\windows\Installer\6a744.msi
+ 2005-02-05 08:25 . 2009-08-13 21:59 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2005-02-05 08:25 . 2009-08-13 21:59 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2005-02-05 08:25 . 2009-07-15 15:03 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-06-16 20:35 . 2008-06-16 20:35 464272 c:\windows\Installer\$PatchCache$\Managed\C040110900063D11C8EF10054038389C\11.0.8173\OWC11PIA.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 141360 c:\windows\Installer\$PatchCache$\Managed\C040110900063D11C8EF10054038389C\11.0.5614\ATP.DLL
+ 2009-08-03 12:25 . 2008-07-08 13:04 406392 c:\windows\ie8updates\KB972636-IE8\spuninst\updspapi.dll
+ 2009-08-03 12:25 . 2008-07-08 13:03 234872 c:\windows\ie8updates\KB972636-IE8\spuninst\spuninst.exe
+ 2009-08-03 12:26 . 2009-03-08 02:34 914944 c:\windows\ie8updates\KB972260-IE8\wininet.dll
+ 2009-08-03 12:26 . 2009-05-26 11:40 406392 c:\windows\ie8updates\KB972260-IE8\spuninst\updspapi.dll
+ 2009-08-03 12:26 . 2009-05-26 11:40 234872 c:\windows\ie8updates\KB972260-IE8\spuninst\spuninst.exe
+ 2009-08-03 12:26 . 2009-03-08 02:34 109568 c:\windows\ie8updates\KB972260-IE8\occache.dll
+ 2009-08-03 12:26 . 2009-03-08 02:32 594432 c:\windows\ie8updates\KB972260-IE8\msfeeds.dll
+ 2009-08-03 12:26 . 2009-03-08 02:33 246784 c:\windows\ie8updates\KB972260-IE8\ieproxy.dll
+ 2009-08-03 12:26 . 2009-03-08 02:31 183808 c:\windows\ie8updates\KB972260-IE8\iepeers.dll
+ 2009-08-03 12:26 . 2009-03-08 12:09 391536 c:\windows\ie8updates\KB972260-IE8\iedkcs32.dll
+ 2009-08-03 12:26 . 2009-03-08 02:32 173056 c:\windows\ie8updates\KB972260-IE8\ie4uinit.exe
+ 2009-08-03 12:22 . 2009-06-29 15:57 827392 c:\windows\ie8\wininet.dll
+ 2009-08-03 12:22 . 2006-10-17 11:05 206336 c:\windows\ie8\winfxdocobj.exe
+ 2009-08-03 12:22 . 2009-06-29 15:57 233472 c:\windows\ie8\webcheck.dll
+ 2009-08-03 12:22 . 2007-07-12 23:30 765952 c:\windows\ie8\vgx.dll
+ 2009-08-03 12:22 . 2008-05-09 10:55 430080 c:\windows\ie8\vbscript.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 105984 c:\windows\ie8\url.dll
+ 2009-08-03 12:23 . 2009-01-07 16:21 406048 c:\windows\ie8\spuninst\updspapi.dll
+ 2009-08-03 12:23 . 2009-01-07 16:21 235040 c:\windows\ie8\spuninst\spuninst.exe
+ 2009-08-03 12:22 . 2006-09-06 15:43 216800 c:\windows\ie8\spuninst.exe
+ 2009-08-03 12:22 . 2009-06-29 15:57 102912 c:\windows\ie8\occache.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 671232 c:\windows\ie8\mstime.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 193024 c:\windows\ie8\msrating.dll
+ 2009-08-03 12:22 . 2006-11-07 20:03 156160 c:\windows\ie8\msls31.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 477696 c:\windows\ie8\mshtmled.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 459264 c:\windows\ie8\msfeeds.dll
+ 2009-08-03 12:22 . 2008-05-09 10:55 512000 c:\windows\ie8\jscript.dll
+ 2009-08-03 12:22 . 2009-06-29 08:35 634632 c:\windows\ie8\iexplore.exe
+ 2009-08-03 12:22 . 2006-11-07 20:03 180736 c:\windows\ie8\ieui.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 268288 c:\windows\ie8\iertutil.dll
+ 2009-08-03 12:22 . 2006-11-07 20:03 287744 c:\windows\ie8\ieproxy.dll
+ 2009-08-03 12:22 . 2006-11-07 20:03 191488 c:\windows\ie8\iepeers.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 385024 c:\windows\ie8\iedkcs32.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 380928 c:\windows\ie8\ieapfltr.dll
+ 2009-08-03 12:22 . 2009-06-29 08:33 161792 c:\windows\ie8\ieakui.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 230400 c:\windows\ie8\ieaksie.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 153088 c:\windows\ie8\ieakeng.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 214528 c:\windows\ie8\dxtrans.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 347136 c:\windows\ie8\dxtmsft.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 124928 c:\windows\ie8\advpack.dll
+ 2006-05-24 23:21 . 2006-05-24 23:21 118784 c:\windows\Downloaded Program Files\bdupd.dll
+ 2004-12-07 15:07 . 2009-08-19 10:23 142848 c:\windows\BDOSCAN8\libfn.dll
+ 2006-05-24 23:21 . 2006-05-24 23:21 118784 c:\windows\BDOSCAN8\bdupd.dll
+ 2004-12-07 15:07 . 2009-08-19 10:23 102400 c:\windows\BDOSCAN8\bdcore.dll
+ 2009-08-13 21:59 . 2009-08-13 21:59 477056 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Owc11\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Owc11.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2004-08-05 12:00 . 2009-07-03 16:57 1208832 c:\windows\SYSTEM32\urlmon.dll
+ 2004-08-05 12:00 . 2009-07-19 13:15 5937152 c:\windows\SYSTEM32\mshtml.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\SYSTEM32\Macromed\Flash\NPSWF32.dll
+ 2006-10-17 10:57 . 2009-07-03 16:57 1985536 c:\windows\SYSTEM32\iertutil.dll
+ 2006-09-05 22:01 . 2009-02-06 19:07 3698584 c:\windows\SYSTEM32\ieapfltr.dat
+ 2009-05-01 18:30 . 2009-05-01 18:30 3366912 c:\windows\SYSTEM32\GPhotos.scr
+ 2006-05-10 05:24 . 2009-07-03 16:57 1208832 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2009-01-07 16:21 . 2009-01-07 16:21 1497088 c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
+ 2004-08-05 12:00 . 2009-06-10 07:21 2066432 c:\windows\SYSTEM32\DLLCACHE\mstscax.dll
+ 2004-08-05 12:00 . 2009-07-10 13:27 1315328 c:\windows\SYSTEM32\DLLCACHE\msoe.dll
+ 2006-05-19 15:09 . 2009-07-19 13:15 5937152 c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
+ 2007-05-09 10:40 . 2009-07-03 16:57 1985536 c:\windows\SYSTEM32\DLLCACHE\iertutil.dll
+ 2007-05-09 10:40 . 2009-02-06 19:07 3698584 c:\windows\SYSTEM32\DLLCACHE\ieapfltr.dat
+ 2009-01-07 16:21 . 2009-01-07 16:21 1022976 c:\windows\SYSTEM32\DLLCACHE\browseui.dll
+ 2009-08-05 00:11 . 2009-08-05 00:11 5518848 c:\windows\Installer\2a62564.msp
+ 2009-07-01 11:21 . 2009-07-01 11:21 8891904 c:\windows\Installer\2a6254e.msp
+ 2007-05-10 11:45 . 2007-05-10 11:45 8069464 c:\windows\Installer\$PatchCache$\Managed\C040110900063D11C8EF10054038389C\11.0.8173\OWC11.DLL
+ 2009-08-03 12:26 . 2009-03-08 02:34 1206784 c:\windows\ie8updates\KB972260-IE8\urlmon.dll
+ 2009-08-03 12:26 . 2009-03-08 02:41 5937152 c:\windows\ie8updates\KB972260-IE8\mshtml.dll
+ 2009-08-03 12:26 . 2009-03-08 02:32 1985024 c:\windows\ie8updates\KB972260-IE8\iertutil.dll
+ 2009-08-03 12:22 . 2009-06-29 15:57 1159680 c:\windows\ie8\urlmon.dll
+ 2009-08-03 12:22 . 2009-07-19 13:29 3597824 c:\windows\ie8\mshtml.dll
+ 2009-08-03 12:22 . 2009-07-19 13:29 6067200 c:\windows\ie8\ieframe.dll
+ 2009-08-03 12:22 . 2009-06-29 08:33 2452872 c:\windows\ie8\ieapfltr.dat
+ 2004-08-05 12:00 . 2009-07-13 21:43 10841088 c:\windows\SYSTEM32\wmp.dll
+ 2005-05-12 19:53 . 2009-07-30 00:49 24281536 c:\windows\SYSTEM32\MRT.exe
+ 2006-11-07 20:03 . 2009-07-19 16:45 11067392 c:\windows\SYSTEM32\ieframe.dll
+ 2009-07-13 21:43 . 2009-07-13 21:43 10841088 c:\windows\SYSTEM32\DLLCACHE\wmp.dll
+ 2007-05-09 10:39 . 2009-07-19 16:45 11067392 c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
+ 2009-07-01 11:19 . 2009-07-01 11:19 10607104 c:\windows\Installer\2a6254f.msp
+ 2009-08-03 12:26 . 2009-03-08 02:39 11063808 c:\windows\ie8updates\KB972260-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-11-03 4800512]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-14 172544]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AOL 9.0 Icône AOL.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\AOL 9.0 Icône AOL.lnk
backup=c:\windows\pss\AOL 9.0 Icône AOL.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AOL Compagnon.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\AOL Compagnon.lnk
backup=c:\windows\pss\AOL Compagnon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Contrôleur de calendrier Ulead.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Contrôleur de calendrier Ulead.lnk
backup=c:\windows\pss\Contrôleur de calendrier Ulead.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Device Detector 2.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Device Detector 2.lnk
backup=c:\windows\pss\Device Detector 2.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Docteur Club Internet.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Docteur Club Internet.lnk
backup=c:\windows\pss\Docteur Club Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WD Backup Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\WD Backup Monitor.lnk
backup=c:\windows\pss\WD Backup Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Dudu^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
path=c:\documents and settings\Dudu\Menu Démarrer\Programmes\Démarrage\Club Internet.lnk
backup=c:\windows\pss\Club Internet.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Dudu^Menu Démarrer^Programmes^Démarrage^ikowin32.exe]
path=c:\documents and settings\Dudu\Menu Démarrer\Programmes\Démarrage\ikowin32.exe
backup=c:\windows\pss\ikowin32.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Dudu^Menu Démarrer^Programmes^Démarrage^Yahoo! Widget Engine.lnk]
path=c:\documents and settings\Dudu\Menu Démarrer\Programmes\Démarrage\Yahoo! Widget Engine.lnk
backup=c:\windows\pss\Yahoo! Widget Engine.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"AOL ACS"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLAcsd.exe"=
"c:\\temp\\CI_HITACHI\\MAJ_Hitachi.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:shareaza
"6346:UDP"= 6346:UDP:shareaza
R0 Daemon;Daemon;c:\windows\SYSTEM32\DRIVERS\daemon.sys [18/12/2001 02:13 71488]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [01/08/2009 15:53 108289]
R3 WDMWANMP;NDIS WAN miniport;c:\windows\SYSTEM32\DRIVERS\wdmwanmp.sys [10/12/2004 15:41 25817]
S1 soqwx32;soqwx32;\??\c:\windows\system32\drivers\soqwx32.sys --> c:\windows\system32\drivers\soqwx32.sys [?]
S2 gupdate1c9a297a9ef4904;Service Google Update (gupdate1c9a297a9ef4904);c:\program files\Google\Update\GoogleUpdate.exe [12/03/2009 00:20 133104]
S2 spupdsvc;Windows Service Pack Installer update service;c:\windows\SYSTEM32\spupdsvc.exe [29/06/2005 22:59 26144]
S3 isdn_u;ISDN USB CAPI;c:\windows\SYSTEM32\DRIVERS\isdn_u.sys [10/12/2004 15:41 609514]
S3 UsbSf; Driver Service;c:\windows\SYSTEM32\DRIVERS\usbsf.sys [01/04/2006 12:31 17145]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-25 05:56]
2009-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 22:20]
2009-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-803201601-1562572127-4119657101-1006Core.job
- c:\documents and settings\Dudu\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-21 13:54]
2004-12-11 c:\windows\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-05 02:34]
2009-08-01 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://portail.club-internet.fr/
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_search_url =
hxxp://www.google.com/ie
mWindow Title =
uInternet Connection Wizard,ShellNext =
hxxp://www.euro.dell.com/countries/fr/fra/gen/default.htm
uInternet Settings,ProxyOverride = 127.0.0.1;localhost
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
Trusted Zone: secuser.com\www
TCP: {BCBAD8A3-C300-4314-BBC8-8B943008B22E} = 194.117.200.10,194.117.200.15
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} -
hxxp://www.mypixmania.com/importer/MypixUploader.cab
DPF: {54D53429-945C-4188-B460-C81356541882} -
hxxp://eshare.hpphoto.com/Download/HPeServicesLocalPrint.CAB
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
DPF: {6DB731A3-B074-4118-8B1C-32511C65D836} -
hxxp://www.mypixmania.com/fr/fr/tools/activex/fpu.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-27 20:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,14,30,f7,0d,94,
58,7f,55,c8,28,51,af,b0,29,a3,98,38,1a,5c,a3,cc,d1,f9,65,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:46,47,15,b0,92,4b,c7,ef,de,1f,ef,4f,75,
80,36,ce,71,3b,04,66,8b,46,0d,96,ef,2a,eb,0f,ad,2a,d9,5d,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,ee,fc,1c,2e,50,
56,b2,49,25,da,ec,7e,55,20,c9,26,bc,5c,d4,61,d4,77,8f,8f,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,0c,0f,82,62,fa,
1c,89,6d,3e,1e,9e,e0,57,5a,93,61,e9,4e,db,bf,2c,fb,9c,91,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,70,e1,d6,6e,f3,
26,05,e9,cd,44,cd,b9,a6,33,6c,cd,a8,5e,aa,7b,47,b2,bd,5b,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,ea,6a,19,f5,44,
ba,61,a0,b0,18,ed,a7,3f,8d,37,a4,dd,cd,7a,32,fa,15,b2,7a,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,16,44,27,61,07,
53,15,ac,31,77,e1,ba,b1,f8,68,02,6d,c0,8e,37,57,87,e6,d0,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,2f,6b,29,b8,de,
56,9c,1b,83,6c,56,8b,a0,85,96,ab,63,7b,10,97,53,55,a2,7c,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,76,51,a5,9f,2d,
1c,b8,d9,51,fa,6e,91,28,9e,14,cc,32,b8,b3,7e,22,3e,e0,25,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,b3,2e,ae,6f,03,
19,08,97,b1,cd,45,5a,a8,c4,f8,b9,e9,31,46,d1,be,47,ea,51,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,e1,c7,fe,57,64,
88,0f,ad,e3,0e,66,d5,eb,bc,2f,6b,11,fd,48,1d,3b,67,63,8f,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,e0,d0,e7,b2,c7,
02,5c,55,fa,ea,66,7f,d4,3b,6b,70,20,67,da,db,a5,12,ea,a3,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2880)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-08-27 21:00
ComboFix-quarantined-files.txt 2009-08-27 18:59
ComboFix2.txt 2009-08-01 13:16
Pre-Run: 24 409 432 064 octets libres
Post-Run: 24 638 382 080 octets libres
574 --- E O F --- 2009-08-26 20:20