01net    Web


Actuellement en ligne : 427 Utilisateurs dont 52 dans Sécurité, virus et assimilés >S'inscrire      >S'identifier      >Recherche      >Aide  
modéré par A.Ouloube, naheulbeuk, bibou0007, totoftotof, IL-MAFIOSO  
01net > Forum de 01net > Sécurité, virus et assimilés > Failles de sécurité
> module introuvable
Auteur
Message
 
<     1   2       >
toadadvance
  
   
      ?   @     Posté le 20/10/2007 23:03:09  
Voter pour ce message
Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0

; Results at 20/10/2007 22:59:11 for strings:
; 'protected'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ed72f0d2-b701-4c53-adc3-f2fb59946dd8}]
@="ProtectedModeAPI"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1fe9ff6d-3d95-4c1e-90f6-9f5c418c3791}]
@="IProtectedModeAPI"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{73C105EE-9DFF-4A07-B83C-7EFF290C266E}]
@="IProtectedModeMenuServices"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\audio]
"InfoTip"="prop:Artist;Album;Year;Track;Duration;Type;Bitrate;Protected;Size"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\video]
"InfoTip"="prop:Type;DocTitle;EpisodeName;ProgramDescription;Duration;Bitrate;Dimensions;Protected;Size"

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2492000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2563000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb26da000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2a57000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2adc000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb30f5000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb3203000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"PMDisplayName"="Computer [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"PMDisplayName"="Local intranet [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"PMDisplayName"="Trusted sites [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"PMDisplayName"="Internet [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"PMDisplayName"="Restricted sites [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\Commands]
; Contents of value:
; %SystemRoot%\system32\asr_pfu.exe /backup
"ASR protected file utility"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,\
52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,\
00,32,00,5c,00,61,00,73,00,72,00,5f,00,70,00,66,00,75,00,2e,00,65,00,78,00,\
65,00,20,00,2f,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]
"ActiveService"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage\Enum]
"0"="Root\\LEGACY_PROTECTEDSTORAGE\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\Setup\AllowStart\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]
"ActiveService"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Enum]
"0"="Root\\LEGACY_PROTECTEDSTORAGE\\0000"

[HKEY_CURRENT_USER\Software\IncrediMail\Identities\{A1EE6AA3-3145-4062-8B31-62BFD5A3D6E7}\Accounts\{FF61061B-3795-4AE2-968C-68D83780543A}]
"ProtectedFrom"=dword:00000000

[HKEY_CURRENT_USER\Software\IncrediMail\Identities\{A1EE6AA3-3145-4062-8B31-62BFD5A3D6E7}\Accounts\{FF61061B-3795-4AE2-968C-68D83780543A}\Backup]
"ProtectedFrom"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Protected Storage System Provider]

[HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"PMDisplayName"="My Computer [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"PMDisplayName"="Local intranet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"PMDisplayName"="Trusted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"PMDisplayName"="Internet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"PMDisplayName"="Restricted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"PMDisplayName"="My Computer [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"PMDisplayName"="Local intranet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"PMDisplayName"="Trusted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"PMDisplayName"="Internet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"PMDisplayName"="Restricted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Skype\ProtectedStorage]

; End Of The Log...
toadadvance
  
   
      ?   @     Posté le 20/10/2007 23:08:47  
Voter pour ce message
Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0

; Results at 20/10/2007 22:59:11 for strings:
; 'protected'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ed72f0d2-b701-4c53-adc3-f2fb59946dd8}]
@="ProtectedModeAPI"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1fe9ff6d-3d95-4c1e-90f6-9f5c418c3791}]
@="IProtectedModeAPI"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{73C105EE-9DFF-4A07-B83C-7EFF290C266E}]
@="IProtectedModeMenuServices"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\audio]
"InfoTip"="prop:Artist;Album;Year;Track;Duration;Type;Bitrate;Protected;Size"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\video]
"InfoTip"="prop:Type;DocTitle;EpisodeName;ProgramDescription;Duration;Bitrate;Dimensions;Protected;Size"

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2492000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2563000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb26da000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2a57000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb2adc000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb30f5000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Macrovision\Safecast\ShellWizards\0xb3203000\Info\ProtectedProductPath]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Protected Storage System Provider]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"PMDisplayName"="Computer [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"PMDisplayName"="Local intranet [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"PMDisplayName"="Trusted sites [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"PMDisplayName"="Internet [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"PMDisplayName"="Restricted sites [Protected Mode]"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\Commands]
; Contents of value:
; %SystemRoot%\system32\asr_pfu.exe /backup
"ASR protected file utility"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,\
52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,\
00,32,00,5c,00,61,00,73,00,72,00,5f,00,70,00,66,00,75,00,2e,00,65,00,78,00,\
65,00,20,00,2f,00,62,00,61,00,63,00,6b,00,75,00,70,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]
"ActiveService"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ProtectedStorage\Enum]
"0"="Root\\LEGACY_PROTECTEDSTORAGE\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\Setup\AllowStart\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BackupRestore\KeysNotToRestore]
; Contents of value:
; CurrentControlSet\Control\Session Manager\AllowProtectedRenames
;
"Session Manager"=hex(7):43,00,75,00,72,00,72,00,65,00,6e,00,74,00,43,00,6f,00,\
6e,00,74,00,72,00,6f,00,6c,00,53,00,65,00,74,00,5c,00,43,00,6f,00,6e,00,74,\
00,72,00,6f,00,6c,00,5c,00,53,00,65,00,73,00,73,00,69,00,6f,00,6e,00,20,00,\
4d,00,61,00,6e,00,61,00,67,00,65,00,72,00,5c,00,41,00,6c,00,6c,00,6f,00,77,\
00,50,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,52,00,65,00,6e,00,\
61,00,6d,00,65,00,73,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000]
"Service"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PROTECTEDSTORAGE\0000\Control]
"ActiveService"="ProtectedStorage"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FTRTSVC]
"Description"="Allow protected access to routing table"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Npfs\Aliases]
; Contents of value:
; protected_storage
; netlogon
; lsarpc
; samr
;
"lsass"=hex(7):70,00,72,00,6f,00,74,00,65,00,63,00,74,00,65,00,64,00,5f,00,73,\
00,74,00,6f,00,72,00,61,00,67,00,65,00,00,00,6e,00,65,00,74,00,6c,00,6f,00,\
67,00,6f,00,6e,00,00,00,6c,00,73,00,61,00,72,00,70,00,63,00,00,00,73,00,61,\
00,6d,00,72,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectedStorage\Enum]
"0"="Root\\LEGACY_PROTECTEDSTORAGE\\0000"

[HKEY_CURRENT_USER\Software\IncrediMail\Identities\{A1EE6AA3-3145-4062-8B31-62BFD5A3D6E7}\Accounts\{FF61061B-3795-4AE2-968C-68D83780543A}]
"ProtectedFrom"=dword:00000000

[HKEY_CURRENT_USER\Software\IncrediMail\Identities\{A1EE6AA3-3145-4062-8B31-62BFD5A3D6E7}\Accounts\{FF61061B-3795-4AE2-968C-68D83780543A}\Backup]
"ProtectedFrom"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Protected Storage System Provider]

[HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\ProtectedRoots]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"PMDisplayName"="My Computer [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"PMDisplayName"="Local intranet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"PMDisplayName"="Trusted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"PMDisplayName"="Internet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"PMDisplayName"="Restricted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"PMDisplayName"="My Computer [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"PMDisplayName"="Local intranet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"PMDisplayName"="Trusted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"PMDisplayName"="Internet [Protected Mode]"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"PMDisplayName"="Restricted sites [Protected Mode]"

[HKEY_CURRENT_USER\Software\Skype\ProtectedStorage]

; End Of The Log...
XmichouX
  
  :-)
      ?   @     Posté le 21/10/2007 12:34:29  
Voter pour ce message
Re,

Refais un scan smitfraudix option 2 en mode sans échec.
Poste le rapport accompagné d'un nouveau Hijackthis.
toadadvance
  
   
      ?   @     Posté le 21/10/2007 20:09:28  
Voter pour ce message
SmitFraudFix v2.240

Rapport fait à 20:00:47,59, 21/10/2007
Executé à partir de C:\Documents and Settings\ESSAI\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode sans echec

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{4C948D98-119C-4FD7-9A8B-6F815A8EA969}: NameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{D7667741-4E0E-4A72-A198-9B764C583CDF}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4C948D98-119C-4FD7-9A8B-6F815A8EA969}: NameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{D7667741-4E0E-4A72-A198-9B764C583CDF}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{4C948D98-119C-4FD7-9A8B-6F815A8EA969}: NameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{D7667741-4E0E-4A72-A198-9B764C583CDF}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{4C948D98-119C-4FD7-9A8B-6F815A8EA969}: NameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{D7667741-4E0E-4A72-A198-9B764C583CDF}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

Nettoyage terminé.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin
Logfile of HijackThis v1.99.1
Scan saved at 20:06:05, on 21/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Acer\Acer eMode Management\AspireService.exe
C:\Program Files\Acer\Acer eConsole\MediaSync.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
C:\PROGRA~1\WANADOO\TaskBarIcon.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Documents and Settings\ESSAI\Bureau\hidjackis\scanner.exe

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\WANADOO\SEARCH~1.DLL
R3 - URLSearchHook: Online TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Online TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Online TV Toolbar - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:\Program Files\Online_TV\tbOnl1.dll
O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:\Program Files\Multi_Media\tbMul0.dll (file missing)
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul1.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ntiMUI] "c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [eRecoveryService] "C:\Acer\Empowering Technology\eRecovery\Monitor.exe"
O4 - HKLM\..\Run: [AspireService] "C:\Program Files\Acer\Acer eMode Management\AspireService.exe"
O4 - HKLM\..\Run: [MediaSync] "C:\Program Files\Acer\Acer eConsole\MediaSync.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - Startup: .protected
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: .protected
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?6ccdbac588ed446b82927da9b49f648
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?6ccdbac588ed446b82927da9b49f648
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Magician's%20Handbook%20-%20Cursed%20Valley/Images/stg_drm.ocx
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_s(...)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb(...)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Magician's%20Handbook%20-%20Cursed%20Valley/Images/armhelper.ocx
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/feeding_frenzy/SproutLauncher.(...)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/shapo/shapo.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/bejeweled2/Oberongamesl(...)
O16 - DPF: {FFFDF6F2-F7BC-4B90-B789-CB7BBDA13AD6} (CLaunchPrint Object) - http://eshare.hpphoto.com/Download/HPeServicesLocalPrint.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C948D98-119C-4FD7-9A8B-6F815A8EA969}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


XmichouX
  
  :-)
      ?   @     Posté le 21/10/2007 22:02:37  
Voter pour ce message
Télécharge Combofix (par sUBs) sur ton Bureau. (Tuto)
Double clique combofix.exe.
Tape sur la touche 1 (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.

Le rapport se trouve ici : C:\Combofix.txt
toadadvance
  
   
      ?   @     Posté le 22/10/2007 00:29:08  
Voter pour ce message
ComboFix 07-10-20.6 - ESSAI 2007-10-22 0:19:12.6 - FAT32x86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.454 [GMT 2:00]
Running from: C:\Documents and Settings\ESSAI\Bureau\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\.protected
C:\Documents and Settings\ESSAI\Application Data.\Ultimate Cleaner
c:\Documents and Settings\ESSAI\Local Settings\Application Data\syeqwbavch.dat
C:\Documents and Settings\ESSAI\Local Settings\Application Data\syeqwbavch.dat
C:\Documents and Settings\ESSAI\Local Settings\Application Data\syeqwbavch.exe
c:\documents and settings\essai\local settings\application data\syeqwbavch.exe
c:\Documents and Settings\ESSAI\Local Settings\Application Data\syeqwbavch_nav.dat
C:\Documents and Settings\ESSAI\Local Settings\Application Data\syeqwbavch_nav.dat
c:\Documents and Settings\ESSAI\Local Settings\Application Data\syeqwbavch_navps.dat
C:\Documents and Settings\ESSAI\Local Settings\Application Data\syeqwbavch_navps.dat
C:\WINDOWS\system32\nvs2.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\poof


((((((((((((((((((((((((((((( Fichiers créés 2007-09-21 to 2007-10-21 ))))))))))))))))))))))))))))))))))))
.

2007-10-22 00:12 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-21 08:39 <REP> d-------- C:\AGATHA_CHRISTIE_ATTWN
2007-10-20 18:47 <REP> d-------- C:\Program Files\CDBurnerXP Pro 3
2007-10-19 22:39 <REP> d-------- C:\Program Files\Lavasoft
2007-10-19 22:01 <REP> d--hs---- C:\FOUND.044
2007-10-19 20:02 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-19 20:02 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-19 20:02 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-19 20:02 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-19 20:02 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-19 15:33 <REP> d-------- C:\Program Files\Abra Academy - Returning Cast
2007-10-18 19:49 <REP> d-------- C:\WINDOWS\pss
2007-10-18 17:31 <REP> d--hs---- C:\FOUND.043
2007-10-14 09:17 <REP> d-------- C:\Program Files\Abra Academy
2007-10-14 00:38 <REP> d-------- C:\Documents and Settings\ESSAI\Application Data\Abra Academy2
2007-10-14 00:12 <REP> d-------- C:\Documents and Settings\ESSAI\Application Data\GibbHill Properties Ltd
2007-10-13 22:10 <REP> d-------- C:\WINDOWS\system32\FlashAX
2007-10-12 18:01 <REP> d-------- C:\Program Files\Windows Live Favorites
2007-10-12 18:00 <REP> d-------- C:\Program Files\Windows Live Toolbar
2007-10-12 18:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-10-11 00:36 <REP> d-------- C:\Program Files\Magician's Handbook - Cursed Valley
2007-10-11 00:36 <REP> d-------- C:\Documents and Settings\ESSAI\Application Data\SpinTop
2007-10-10 22:16 <REP> d-------- C:\WINDOWS\ERUNT
2007-10-09 12:50 <REP> d-------- C:\Program Files\Little Shop Of Treasures
2007-10-07 12:47 20 ---h----- C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2007-10-06 16:22 <REP> d-------- C:\Program Files\Forgotten Riddles The Mayan Princess
2007-10-06 15:33 <REP> d-------- C:\Documents and Settings\ESSAI\Application Data\Legends of pirates
2007-09-28 10:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Aliasworlds
2007-09-26 19:12 <REP> d-------- C:\Program Files\Little Shop of Treasures 2 [Beta] DeLEGiON

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 18:00 5,064 ----a-w C:\WINDOWS\system32\tmp.reg
2007-10-07 10:55 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-09-15 18:30 --------- d-----w C:\Program Files\ReflexiveArcade
2007-09-15 10:21 --------- d-----w C:\Documents and Settings\ESSAI\Application Data\ForgottenRiddles
2007-09-14 16:51 --------- d-----r C:\Program Files\jeux
2007-09-06 12:24 --------- d-----w C:\Program Files\MultiMedia France Toolbar
2007-08-31 08:55 --------- d-----w C:\Documents and Settings\ESSAI\Application Data\VeniceMysteryData
2007-08-25 16:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2007-08-21 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\AlawarGameBox
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 09:59 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 09:59 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 09:59 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 09:59 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 09:59 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 09:59 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 09:59 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 09:59 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 09:59 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 09:59 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 09:59 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 09:59 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 09:59 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 09:59 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 09:59 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 09:59 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 09:59 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 09:59 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 09:59 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 09:59 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 09:59 105,984 ----a-w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 09:59 102,400 ----a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 09:59 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:22 63,488 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:22 625,152 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:22 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 17:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-07-30 17:19 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\WUPS.DLL
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2007-07-26 23:06 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-07-26 23:06 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-07-26 23:06 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-07-26 23:06 144,704 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-07-26 23:06 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-07-26 23:06 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-07-26 23:06 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-07-26 23:06 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-07-26 23:03 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-07-26 23:03 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-07-26 23:03 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-07-26 23:03 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-07-26 23:03 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-07-26 23:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-07-26 23:03 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-07-26 23:03 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-07-26 23:03 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-07-26 23:03 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-07-26 23:03 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-07-26 23:03 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-07-26 23:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2006-09-16 17:27 0 ----a-w C:\Documents and Settings\ESSAI\HidExpTitanic.dat
2006-02-13 09:52 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2007-02-26 06:06:16 452,006 --sh--w C:\WINDOWS\system32\tttss.bak1
.

((((((((((((((((((((((((((((( snapshot@2007-10-22_ 0.14.32,59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-05 03:00:00 2,804,224 ------w C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msi.dll
+ 2004-08-05 03:00:00 77,312 ------w C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msiexec.exe
+ 2004-08-05 03:00:00 331,264 ------w C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msihnd.dll
+ 2004-08-05 03:00:00 884,736 ------w C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msimsg.dll
+ 2004-08-05 03:00:00 44,032 ------w C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msisip.dll
+ 2005-05-04 12:45:28 213,216 ------w C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe
+ 2005-05-04 12:45:28 395,488 ------w C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\updspapi.dll
+ 2006-05-25 08:29:04 213,216 ------w C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe
+ 2006-05-25 08:29:04 371,424 ------w C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\updspapi.dll
+ 2006-05-24 10:32:48 213,216 ------w C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe
+ 2006-05-24 10:32:48 371,424 ------w C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 134,912 ------w C:\WINDOWS\$NtUninstallKB886185$\ipnat.sys
+ 2004-10-14 17:36:20 172,032 ------w C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
+ 2004-08-05 03:00:00 263,040 ------w C:\WINDOWS\$NtUninstallKB887742$\http.sys
+ 2004-10-14 08:36:22 172,032 ------w C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
+ 2004-08-05 03:00:00 678,400 ------w C:\WINDOWS\$NtUninstallKB887797$\inetcomm.dll
+ 2004-08-05 03:00:00 1,311,232 ------w C:\WINDOWS\$NtUninstallKB887797$\msoe.dll
+ 2004-10-14 09:36:22 172,032 ------w C:\WINDOWS\$NtUninstallKB887797$\spuninst\spuninst.exe
+ 2004-08-05 03:00:00 504,832 ------w C:\WINDOWS\$NtUninstallKB887797$\wab32.dll
+ 2004-08-05 03:00:00 84,992 ------w C:\WINDOWS\$NtUninstallKB887797$\wabimp.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB893066$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 359,040 ------w C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB893756$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 246,272 ------w C:\WINDOWS\$NtUninstallKB893756$\tapisrv.dll
+ 2004-08-05 03:00:00 1,281,024 ------w C:\WINDOWS\$NtUninstallKB894391$\ole32.dll
+ 2004-08-05 03:00:00 69,120 ------w C:\WINDOWS\$NtUninstallKB894391$\olecli32.dll
+ 2004-08-05 03:00:00 34,304 ------w C:\WINDOWS\$NtUninstallKB894391$\olecnv32.dll
+ 2004-08-05 03:00:00 395,776 ------w C:\WINDOWS\$NtUninstallKB894391$\rpcss.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB894391$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 57,856 ------w C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB896423$\spuninst\updspapi.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB896424$\spuninst\updspapi.dll
+ 2005-03-02 18:07:54 1,836,416 ------w C:\WINDOWS\$NtUninstallKB896424$\win32k.sys
+ 2005-02-25 02:35:24 213,216 ------w C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe
+ 2005-02-25 02:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB898461$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 294,400 ------w C:\WINDOWS\$NtUninstallKB899587$\kerberos.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB899587$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 139,400 ------w C:\WINDOWS\$NtUninstallKB899591$\rdpwd.sys
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB899591$\spuninst\updspapi.dll
+ 2004-08-03 20:39:38 142,464 ------w C:\WINDOWS\$NtUninstallKB900485$\aec.sys
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB900485$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 18,944 ------w C:\WINDOWS\$NtUninstallKB900725$\linkinfo.dll
+ 2005-02-28 23:12:24 8,506,368 ------w C:\WINDOWS\$NtUninstallKB900725$\shell32.dll
+ 2005-05-02 20:57:12 474,112 ------w C:\WINDOWS\$NtUninstallKB900725$\shlwapi.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB900725$\spuninst\updspapi.dll
+ 2005-03-02 18:10:36 291,840 ------w C:\WINDOWS\$NtUninstallKB900725$\winsrv.dll
+ 2004-10-18 19:43:10 679,424 ------w C:\WINDOWS\$NtUninstallKB900930$\inetcomm.dll
+ 2004-10-18 19:43:10 1,311,744 ------w C:\WINDOWS\$NtUninstallKB900930$\msoe.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB900930$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB900930$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 2,067,968 ------w C:\WINDOWS\$NtUninstallKB901017$\cdosys.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB901017$\spuninst\updspapi.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB901190$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 229,888 ------w C:\WINDOWS\$NtUninstallKB902400$\catsrv.dll
+ 2004-08-05 03:00:00 628,224 ------w C:\WINDOWS\$NtUninstallKB902400$\catsrvut.dll
+ 2004-08-05 03:00:00 110,080 ------w C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll
+ 2004-08-05 03:00:00 501,248 ------w C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll
+ 2004-08-05 03:00:00 62,464 ------w C:\WINDOWS\$NtUninstallKB902400$\colbact.dll
+ 2004-08-05 03:00:00 195,584 ------w C:\WINDOWS\$NtUninstallKB902400$\comadmin.dll
+ 2004-08-05 03:00:00 82,432 ------w C:\WINDOWS\$NtUninstallKB902400$\comrepl.dll
+ 2004-08-05 03:00:00 1,251,840 ------w C:\WINDOWS\$NtUninstallKB902400$\comsvcs.dll
+ 2004-08-05 03:00:00 540,160 ------w C:\WINDOWS\$NtUninstallKB902400$\comuid.dll
+ 2004-08-05 03:00:00 243,200 ------w C:\WINDOWS\$NtUninstallKB902400$\es.dll
+ 2004-08-05 03:00:00 7,680 ------w C:\WINDOWS\$NtUninstallKB902400$\migregdb.exe
+ 2004-08-05 03:00:00 425,472 ------w C:\WINDOWS\$NtUninstallKB902400$\msdtcprx.dll
+ 2004-08-05 03:00:00 949,248 ------w C:\WINDOWS\$NtUninstallKB902400$\msdtctm.dll
+ 2004-08-05 03:00:00 161,280 ------w C:\WINDOWS\$NtUninstallKB902400$\msdtcuiu.dll
+ 2004-08-05 03:00:00 66,560 ------w C:\WINDOWS\$NtUninstallKB902400$\mtxclu.dll
+ 2004-08-05 03:00:00 90,112 ------w C:\WINDOWS\$NtUninstallKB902400$\mtxoci.dll
+ 2005-04-28 18:32:30 1,284,608 ------w C:\WINDOWS\$NtUninstallKB902400$\ole32.dll
+ 2005-04-28 18:32:30 1,284,608 ------w C:\WINDOWS\$NtUninstallKB902400$\ole32.dll.000
+ 2005-04-28 18:32:30 75,264 ------w C:\WINDOWS\$NtUninstallKB902400$\olecli32.dll
+ 2005-04-28 18:32:30 75,264 ------w C:\WINDOWS\$NtUninstallKB902400$\olecli32.dll.000
+ 2005-04-28 18:32:30 37,888 ------w C:\WINDOWS\$NtUninstallKB902400$\olecnv32.dll
+ 2005-04-28 18:32:30 395,776 ------w C:\WINDOWS\$NtUninstallKB902400$\rpcss.dll
+ 2005-04-28 18:32:30 395,776 ------w C:\WINDOWS\$NtUninstallKB902400$\rpcss.dll.000
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB902400$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 101,376 ------w C:\WINDOWS\$NtUninstallKB902400$\txflog.dll
+ 2004-08-05 03:00:00 11,776 ------w C:\WINDOWS\$NtUninstallKB902400$\xolehlp.dll
+ 2004-08-05 03:00:00 1,293,824 ------w C:\WINDOWS\$NtUninstallKB904706$\quartz.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB904706$\spuninst\updspapi.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB904942$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 49,152 ------w C:\WINDOWS\$NtUninstallKB904942$\wdigest.dll
+ 2004-08-05 03:00:00 198,144 ------w C:\WINDOWS\$NtUninstallKB905414$\netman.dll
+ 2005-02-25 02:35:24 213,216 ------w C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe
+ 2005-02-25 02:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB905414$\spuninst\updspapi.dll
+ 2005-02-24 18:35:26 213,216 ------w C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe
+ 2005-02-24 18:35:26 395,488 ------w C:\WINDOWS\$NtUninstallKB905749$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 119,808 ------w C:\WINDOWS\$NtUninstallKB905749$\umpnpmgr.dll
+ 2005-05-02 20:57:10 1,020,416 ------w C:\WINDOWS\$NtUninstallKB905915$\browseui.dll
+ 2005-05-02 20:57:10 152,064 ------w C:\WINDOWS\$NtUninstallKB905915$\cdfview.dll
+ 2004-08-05 03:00:00 1,056,256 ------w C:\WINDOWS\$NtUninstallKB905915$\danim.dll
+ 2004-08-05 03:00:00 201,728 ------w C:\WINDOWS\$NtUninstallKB905915$\dxtrans.dll
+ 2004-08-05 03:00:00 55,808 ------w C:\WINDOWS\$NtUninstallKB905915$\extmgr.dll
+ 2005-05-01 00:19:08 18,432 ------w C:\WINDOWS\$NtUninstallKB905915$\iedw.exe
+ 2005-05-02 20:57:10 250,880 ------w C:\WINDOWS\$NtUninstallKB905915$\iepeers.dll
+ 2005-05-02 20:57:12 96,768 ------w C:\WINDOWS\$NtUninstallKB905915$\inseng.dll
+ 2005-05-02 11:57:12 3,011,072 ------w C:\WINDOWS\$NtUninstallKB905915$\mshtml.dll
+ 2005-05-02 20:57:12 448,512 ------w C:\WINDOWS\$NtUninstallKB905915$\mshtmled.dll
+ 2005-05-02 20:57:12 146,432 ------w C:\WINDOWS\$NtUninstallKB905915$\msrating.dll
+ 2004-08-05 03:00:00 530,432 ------w C:\WINDOWS\$NtUninstallKB905915$\mstime.dll
+ 2005-05-02 20:57:12 39,424 ------w C:\WINDOWS\$NtUninstallKB905915$\pngfilt.dll
+ 2005-05-02 20:57:12 1,484,288 ------w C:\WINDOWS\$NtUninstallKB905915$\shdocvw.dll
+ 2005-09-02 23:06:12 474,112 ------w C:\WINDOWS\$NtUninstallKB905915$\shlwapi.dll
+ 2005-09-02 23:06:12 474,112 ------w C:\WINDOWS\$NtUninstallKB905915$\shlwapi.dll.000
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB905915$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB905915$\spuninst\updspapi.dll
+ 2005-05-02 20:57:12 605,696 ------w C:\WINDOWS\$NtUninstallKB905915$\urlmon.dll
+ 2005-05-02 20:57:12 662,016 ------w C:\WINDOWS\$NtUninstallKB905915$\wininet.dll
+ 2004-08-05 03:00:00 79,360 ------w C:\WINDOWS\$NtUninstallKB908519$\fontsub.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB908519$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 210,432 ------w C:\WINDOWS\$NtUninstallKB908519$\t2embed.dll
+ 2005-09-23 02:07:00 8,506,880 ------w C:\WINDOWS\$NtUninstallKB908531$\shell32.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB908531$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 1,097,728 ------w C:\WINDOWS\$NtUninstallKB910437$\esent.dll
+ 2005-10-12 22:15:24 216,800 ------w C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe
+ 2005-10-12 22:15:44 394,976 ------w C:\WINDOWS\$NtUninstallKB910437$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 174,080 ------w C:\WINDOWS\$NtUninstallKB911280$\rasmans.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB911280$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 143,360 ------w C:\WINDOWS\$NtUninstallKB911562$\msadco.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB911562$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 364,544 ------w C:\WINDOWS\$NtUninstallKB911564$\npdsplay.dll
+ 2005-06-28 07:23:40 216,800 ------w C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe
+ 2005-06-28 07:23:54 371,424 ------w C:\WINDOWS\$NtUninstallKB911564$\spuninst\updspapi.dll
+ 2005-06-28 07:23:40 216,800 ------w C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe
+ 2005-06-28 07:23:54 371,424 ------w C:\WINDOWS\$NtUninstallKB911565$\spuninst\updspapi.dll
+ 2004-08-10 22:41:20 5,550,080 ------w C:\WINDOWS\$NtUninstallKB911565$\wmp.dll
+ 2005-05-05 20:24:18 679,424 ------w C:\WINDOWS\$NtUninstallKB911567$\inetcomm.dll
+ 2005-05-05 20:24:18 1,311,744 ------w C:\WINDOWS\$NtUninstallKB911567$\msoe.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB911567$\spuninst\updspapi.dll
+ 2004-10-18 19:43:10 505,344 ------w C:\WINDOWS\$NtUninstallKB911567$\wab32.dll
+ 2004-10-18 19:43:10 85,504 ------w C:\WINDOWS\$NtUninstallKB911567$\wabimp.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB911927$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 67,584 ------w C:\WINDOWS\$NtUninstallKB911927$\webclnt.dll
+ 2005-11-23 23:08:34 1,022,976 ------w C:\WINDOWS\$NtUninstallKB912812$\browseui.dll
+ 2005-10-21 02:41:00 152,064 ------w C:\WINDOWS\$NtUninstallKB912812$\cdfview.dll
+ 2005-11-05 02:17:22 1,056,768 ------w C:\WINDOWS\$NtUninstallKB912812$\danim.dll
+ 2005-10-21 02:41:00 205,312 ------w C:\WINDOWS\$NtUninstallKB912812$\dxtrans.dll
+ 2005-10-21 02:41:00 55,808 ------w C:\WINDOWS\$NtUninstallKB912812$\extmgr.dll
+ 2005-10-21 00:45:40 18,432 ------w C:\WINDOWS\$NtUninstallKB912812$\iedw.exe
+ 2005-10-21 02:41:00 251,392 ------w C:\WINDOWS\$NtUninstallKB912812$\iepeers.dll
+ 2005-10-21 02:41:00 96,768 ------w C:\WINDOWS\$NtUninstallKB912812$\inseng.dll
+ 2005-11-23 23:08:36 3,013,632 ------w C:\WINDOWS\$NtUninstallKB912812$\mshtml.dll
+ 2005-10-21 02:41:04 448,512 ------w C:\WINDOWS\$NtUninstallKB912812$\mshtmled.dll
+ 2005-10-21 02:41:04 146,432 ------w C:\WINDOWS\$NtUninstallKB912812$\msrating.dll
+ 2005-10-21 02:41:04 530,944 ------w C:\WINDOWS\$NtUninstallKB912812$\mstime.dll
+ 2005-10-21 02:41:04 39,424 ------w C:\WINDOWS\$NtUninstallKB912812$\pngfilt.dll
+ 2005-12-01 03:01:16 1,492,992 ------w C:\WINDOWS\$NtUninstallKB912812$\shdocvw.dll
+ 2005-10-21 02:41:04 474,112 ------w C:\WINDOWS\$NtUninstallKB912812$\shlwapi.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB912812$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB912812$\spuninst\updspapi.dll
+ 2005-11-05 02:17:26 606,208 ------w C:\WINDOWS\$NtUninstallKB912812$\urlmon.dll
+ 2005-10-21 02:41:06 662,528 ------w C:\WINDOWS\$NtUninstallKB912812$\wininet.dll
+ 2005-05-16 15:42:16 16,896 ------w C:\WINDOWS\$NtUninstallKB912812$\xpsp3res.dll
+ 2004-08-05 03:00:00 278,016 ------w C:\WINDOWS\$NtUninstallKB912919$\gdi32.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB912919$\spuninst\updspapi.dll
+ 2005-10-12 22:15:24 216,800 ------w C:\WINDOWS\$NtUninstallKB913446$\spuninst\spuninst.exe
+ 2005-10-12 22:15:44 394,976 ------w C:\WINDOWS\$NtUninstallKB913446$\spuninst\updspapi.dll
+ 2006-02-14 12:37:50 359,808 ------w C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
+ 2005-07-26 03:39:58 425,472 ------w C:\WINDOWS\$NtUninstallKB913580$\msdtcprx.dll
+ 2005-07-26 03:40:00 945,152 ------w C:\WINDOWS\$NtUninstallKB913580$\msdtctm.dll
+ 2005-07-26 03:40:00 161,280 ------w C:\WINDOWS\$NtUninstallKB913580$\msdtcuiu.dll
+ 2005-07-26 03:40:00 66,560 ------w C:\WINDOWS\$NtUninstallKB913580$\mtxclu.dll
+ 2005-07-26 03:40:00 91,136 ------w C:\WINDOWS\$NtUninstallKB913580$\mtxoci.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB913580$\spuninst\updspapi.dll
+ 2005-07-26 03:40:00 11,776 ------w C:\WINDOWS\$NtUninstallKB913580$\xolehlp.dll
+ 2004-08-05 03:00:00 111,616 ------w C:\WINDOWS\$NtUninstallKB914388$\dhcpcsvc.dll
+ 2004-08-05 03:00:00 148,480 ------w C:\WINDOWS\$NtUninstallKB914388$\dnsapi.dll
+ 2004-08-05 03:00:00 95,744 ------w C:\WINDOWS\$NtUninstallKB914388$\iphlpapi.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB914388$\spuninst\updspapi.dll
+ 2005-01-19 04:26:52 451,584 ------w C:\WINDOWS\$NtUninstallKB914389$\mrxsmb.sys
+ 2004-10-28 01:13:58 174,592 ------w C:\WINDOWS\$NtUninstallKB914389$\rdbss.sys
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB914389$\spuninst\updspapi.dll
+ 2004-12-21 10:14:24 28,672 ------w C:\WINDOWS\$NtUninstallKB914440$\custsat.dll
+ 2005-10-12 22:15:24 216,800 ------w C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe
+ 2005-10-12 22:15:44 394,976 ------w C:\WINDOWS\$NtUninstallKB914440$\spuninst\updspapi.dll
+ 2005-10-12 22:12:26 213,216 ------w C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe
+ 2005-10-12 22:12:34 371,424 ------w C:\WINDOWS\$NtUninstallKB915865$\spuninst\updspapi.dll
+ 2006-03-04 03:34:58 1,023,488 ------w C:\WINDOWS\$NtUninstallKB916281$\browseui.dll
+ 2006-03-04 03:34:58 152,064 ------w C:\WINDOWS\$NtUninstallKB916281$\cdfview.dll
+ 2006-03-04 03:34:58 1,056,768 ------w C:\WINDOWS\$NtUninstallKB916281$\danim.dll
+ 2004-08-05 03:00:00 357,888 ------w C:\WINDOWS\$NtUninstallKB916281$\dxtmsft.dll
+ 2006-03-04 03:34:58 205,312 ------w C:\WINDOWS\$NtUninstallKB916281$\dxtrans.dll
+ 2006-03-04 03:34:58 55,808 ------w C:\WINDOWS\$NtUninstallKB916281$\extmgr.dll
+ 2006-03-04 00:39:06 18,432 ------w C:\WINDOWS\$NtUninstallKB916281$\iedw.exe
+ 2006-03-04 03:34:58 251,392 ------w C:\WINDOWS\$NtUninstallKB916281$\iepeers.dll
+ 2006-03-04 03:34:58 96,768 ------w C:\WINDOWS\$NtUninstallKB916281$\inseng.dll
+ 2004-08-05 03:00:00 15,872 ------w C:\WINDOWS\$NtUninstallKB916281$\jsproxy.dll
+ 2006-03-23 20:35:42 3,074,560 ------w C:\WINDOWS\$NtUninstallKB916281$\mshtml.dll
+ 2006-03-04 03:35:00 448,512 ------w C:\WINDOWS\$NtUninstallKB916281$\mshtmled.dll
+ 2006-03-04 03:35:00 146,432 ------w C:\WINDOWS\$NtUninstallKB916281$\msrating.dll
+ 2006-03-04 03:35:02 532,480 ------w C:\WINDOWS\$NtUninstallKB916281$\mstime.dll
+ 2006-03-04 03:35:02 39,424 ------w C:\WINDOWS\$NtUninstallKB916281$\pngfilt.dll
+ 2006-03-30 09:26:12 1,492,992 ------w C:\WINDOWS\$NtUninstallKB916281$\shdocvw.dll
+ 2006-03-04 03:35:02 474,624 ------w C:\WINDOWS\$NtUninstallKB916281$\shlwapi.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB916281$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB916281$\spuninst\updspapi.dll
+ 2006-03-18 11:09:54 615,424 ------w C:\WINDOWS\$NtUninstallKB916281$\urlmon.dll
+ 2006-03-04 03:35:02 662,528 ------w C:\WINDOWS\$NtUninstallKB916281$\wininet.dll
+ 2006-03-30 01:16:46 17,920 ------w C:\WINDOWS\$NtUninstallKB916281$\xpsp3res.dll
+ 2004-10-08 22:48:22 262,400 ------w C:\WINDOWS\$NtUninstallKB916595$\http.sys
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB916595$\spuninst\updspapi.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB917159$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB917159$\spuninst\updspapi.dll
+ 2005-05-10 00:17:52 332,544 ------w C:\WINDOWS\$NtUninstallKB917159$\srv.sys
+ 2004-08-05 03:00:00 450,560 ------w C:\WINDOWS\$NtUninstallKB917344$\jscript.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB917344$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 1,048,576 ------w C:\WINDOWS\$NtUninstallKB917422$\kernel32.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB917422$\spuninst\updspapi.dll
+ 2005-06-28 08:23:40 216,800 ------w C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe
+ 2005-06-28 08:23:54 371,424 ------w C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\updspapi.dll
+ 2006-03-10 04:09:14 5,533,696 ------w C:\WINDOWS\$NtUninstallKB917734_WMP10$\wmp.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB917953$\spuninst\updspapi.dll
+ 2006-01-13 01:28:14 359,808 ------w C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
+ 2004-08-05 03:00:00 537,088 ------w C:\WINDOWS\$NtUninstallKB918118$\msftedit.dll
+ 2004-08-05 03:00:00 431,616 ------w C:\WINDOWS\$NtUninstallKB918118$\riched20.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB918118$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 144,896 ------w C:\WINDOWS\$NtUninstallKB918439$\jgdw400.dll
+ 2004-08-05 03:00:00 42,496 ------w C:\WINDOWS\$NtUninstallKB918439$\jgpl400.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB918439$\spuninst\updspapi.dll
+ 2006-05-10 05:24:34 1,023,488 ------w C:\WINDOWS\$NtUninstallKB918899$\browseui.dll
+ 2006-05-10 05:24:34 152,064 ------w C:\WINDOWS\$NtUninstallKB918899$\cdfview.dll
+ 2006-05-10 05:24:34 1,056,768 ------w C:\WINDOWS\$NtUninstallKB918899$\danim.dll
+ 2006-05-10 05:24:36 357,888 ------w C:\WINDOWS\$NtUninstallKB918899$\dxtmsft.dll
+ 2006-05-10 05:24:36 205,312 ------w C:\WINDOWS\$NtUninstallKB918899$\dxtrans.dll
+ 2006-05-10 05:24:36 55,808 ------w C:\WINDOWS\$NtUninstallKB918899$\extmgr.dll
+ 2006-05-09 11:00:38 18,432 ------w C:\WINDOWS\$NtUninstallKB918899$\iedw.exe
+ 2006-05-10 05:24:36 251,392 ------w C:\WINDOWS\$NtUninstallKB918899$\iepeers.dll
+ 2006-05-10 05:24:36 96,768 ------w C:\WINDOWS\$NtUninstallKB918899$\inseng.dll
+ 2006-05-10 05:24:36 16,384 ------w C:\WINDOWS\$NtUninstallKB918899$\jsproxy.dll
+ 2006-05-19 15:09:50 3,073,536 ------w C:\WINDOWS\$NtUninstallKB918899$\mshtml.dll
+ 2006-05-10 05:24:36 448,512 ------w C:\WINDOWS\$NtUninstallKB918899$\mshtmled.dll
+ 2006-05-10 05:24:36 146,432 ------w C:\WINDOWS\$NtUninstallKB918899$\msrating.dll
+ 2006-05-10 05:24:38 532,480 ------w C:\WINDOWS\$NtUninstallKB918899$\mstime.dll
+ 2006-05-10 05:24:38 39,424 ------w C:\WINDOWS\$NtUninstallKB918899$\pngfilt.dll
+ 2006-05-29 15:29:14 1,494,528 ------w C:\WINDOWS\$NtUninstallKB918899$\shdocvw.dll
+ 2006-05-10 05:24:40 474,624 ------w C:\WINDOWS\$NtUninstallKB918899$\shlwapi.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB918899$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB918899$\spuninst\updspapi.dll
+ 2006-05-10 05:24:40 615,936 ------w C:\WINDOWS\$NtUninstallKB918899$\urlmon.dll
+ 2006-05-10 05:24:40 662,528 ------w C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
+ 2006-05-11 08:57:36 26,624 ------w C:\WINDOWS\$NtUninstallKB918899$\xpsp3res.dll
+ 2004-08-05 03:00:00 200,064 ------w C:\WINDOWS\$NtUninstallKB919007$\rmcast.sys
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB919007$\spuninst\updspapi.dll
+ 2006-10-12 13:04:14 42,496 ------w C:\WINDOWS\$NtUninstallKB920213$\agentdp2.dll
+ 2006-10-12 13:04:14 57,344 ------w C:\WINDOWS\$NtUninstallKB920213$\agentdpv.dll
+ 2006-10-12 10:09:54 256,512 ------w C:\WINDOWS\$NtUninstallKB920213$\agentsvr.exe
+ 2005-10-12 22:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe
+ 2005-10-12 22:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB920213$\spuninst\updspapi.dll
+ 2006-10-16 09:40:52 121,856 ------w C:\WINDOWS\$NtUninstallKB920213$\xpsp3res.dll
+ 2004-08-05 03:00:00 41,984 ------w C:\WINDOWS\$NtUninstallKB920213_0$\agentdp2.dll
+ 2005-04-22 05:08:20 57,344 ------w C:\WINDOWS\$NtUninstallKB920213_0$\agentdpv.dll
+ 2004-08-05 03:00:00 256,512 ------w C:\WINDOWS\$NtUninstallKB920213_0$\agentsvr.exe
+ 2005-10-12 22:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB920213_0$\spuninst\spuninst.exe
+ 2005-10-12 22:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB920213_0$\spuninst\updspapi.dll
+ 2006-09-18 08:12:14 121,856 ------w C:\WINDOWS\$NtUninstallKB920213_0$\xpsp3res.dll
+ 2006-03-17 09:11:46 679,424 ------w C:\WINDOWS\$NtUninstallKB920214$\inetcomm.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB920214$\spuninst\updspapi.dll
+ 2004-11-16 21:17:58 68,608 ------w C:\WINDOWS\$NtUninstallKB920670$\hlink.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB920670$\spuninst\updspapi.dll
+ 2006-05-19 13:23:36 148,480 ------w C:\WINDOWS\$NtUninstallKB920683$\dnsapi.dll
+ 2004-08-05 03:00:00 8,192 ------w C:\WINDOWS\$NtUninstallKB920683$\rasadhlp.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB920683$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 69,120 ------w C:\WINDOWS\$NtUninstallKB920685$\ciodm.dll
+ 2004-08-05 03:00:00 1,440,768 ------w C:\WINDOWS\$NtUninstallKB920685$\query.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB920685$\spuninst\updspapi.dll
+ 2004-08-03 21:07:50 171,776 ------w C:\WINDOWS\$NtUninstallKB920872$\kmixer.sys
+ 2004-08-03 21:07:48 6,400 ------w C:\WINDOWS\$NtUninstallKB920872$\splitter.sys
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB920872$\spuninst\updspapi.dll
+ 2004-08-03 21:15:06 82,944 ------w C:\WINDOWS\$NtUninstallKB920872$\wdmaud.sys
+ 2006-03-17 04:07:40 8,508,416 ------w C:\WINDOWS\$NtUninstallKB921398$\shell32.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB921398$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 553,472 ------w C:\WINDOWS\$NtUninstallKB921503$\oleaut32.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB921503$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 332,288 ------w C:\WINDOWS\$NtUninstallKB921883$\netapi32.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB921883$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 16,896 ------w C:\WINDOWS\$NtUninstallKB922582$\fltlib.dll
+ 2004-08-05 03:00:00 22,528 ------w C:\WINDOWS\$NtUninstallKB922582$\fltmc.exe
+ 2004-08-05 03:00:00 124,800 ------w C:\WINDOWS\$NtUninstallKB922582$\fltmgr.sys
+ 2005-10-12 23:15:24 216,800 ------w C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe
+ 2005-10-12 23:15:44 394,976 ------w C:\WINDOWS\$NtUninstallKB922582$\spuninst\updspapi.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB922616$\spuninst\updspapi.dll
+ 2006-06-23 11:11:42 1,023,488 ------w C:\WINDOWS\$NtUninstallKB922760$\browseui.dll
+ 2006-06-23 11:11:42 152,064 ------w C:\WINDOWS\$NtUninstallKB922760$\cdfview.dll
+ 2006-06-23 11:11:42 1,056,768 ------w C:\WINDOWS\$NtUninstallKB922760$\danim.dll
+ 2006-06-23 11:11:44 357,888 ------w C:\WINDOWS\$NtUninstallKB922760$\dxtmsft.dll
+ 2006-06-23 11:11:44 205,312 ------w C:\WINDOWS\$NtUninstallKB922760$\dxtrans.dll
+ 2006-06-23 11:11:44 55,808 ------w C:\WINDOWS\$NtUninstallKB922760$\extmgr.dll
+ 2006-06-23 08:35:52 18,432 ------w C:\WINDOWS\$NtUninstallKB922760$\iedw.exe
+ 2006-06-23 11:11:44 251,392 ------w C:\WINDOWS\$NtUninstallKB922760$\iepeers.dll
+ 2006-06-23 11:11:44 96,768 ------w C:\WINDOWS\$NtUninstallKB922760$\inseng.dll
+ 2006-06-23 11:11:44 16,384 ------w C:\WINDOWS\$NtUninstallKB922760$\jsproxy.dll
+ 2006-07-28 11:28:08 3,075,072 ------w C:\WINDOWS\$NtUninstallKB922760$\mshtml.dll
+ 2006-06-23 11:11:44 448,512 ------w C:\WINDOWS\$NtUninstallKB922760$\mshtmled.dll
+ 2006-06-23 11:11:44 146,432 ------w C:\WINDOWS\$NtUninstallKB922760$\msrating.dll
+ 2006-06-23 11:11:44 532,480 ------w C:\WINDOWS\$NtUninstallKB922760$\mstime.dll
+ 2006-06-23 11:11:44 39,424 ------w C:\WINDOWS\$NtUninstallKB922760$\pngfilt.dll
+ 2006-06-23 11:11:46 474,624 ------w C:\WINDOWS\$NtUninstallKB922760$\shlwapi.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB922760$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB922760$\spuninst\updspapi.dll
+ 2006-07-25 20:41:02 615,936 ------w C:\WINDOWS\$NtUninstallKB922760$\urlmon.dll
+ 2006-06-23 11:11:46 663,040 ------w C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
+ 2006-06-23 08:53:42 26,624 ------w C:\WINDOWS\$NtUninstallKB922760$\xpsp3res.dll
+ 2004-08-05 03:00:00 100,352 ------w C:\WINDOWS\$NtUninstallKB922819$\6to4svc.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB922819$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 223,616 ------w C:\WINDOWS\$NtUninstallKB922819$\tcpip6.sys
+ 2004-08-05 03:00:00 611,328 ------w C:\WINDOWS\$NtUninstallKB923191$\comctl32.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB923191$\spuninst\updspapi.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB923414$\spuninst\updspapi.dll
+ 2006-04-21 06:12:28 332,800 ------w C:\WINDOWS\$NtUninstallKB923414$\srv.sys
+ 2004-08-05 03:00:00 81,408 ------w C:\WINDOWS\$NtUninstallKB923694$\directdb.dll
+ 2006-07-27 13:26:20 679,424 ------w C:\WINDOWS\$NtUninstallKB923694$\inetcomm.dll
+ 2006-03-17 09:11:46 1,311,744 ------w C:\WINDOWS\$NtUninstallKB923694$\msoe.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB923694$\spuninst\updspapi.dll
+ 2006-03-17 09:11:46 510,464 ------w C:\WINDOWS\$NtUninstallKB923694$\wab32.dll
+ 2006-03-17 09:11:46 85,504 ------w C:\WINDOWS\$NtUninstallKB923694$\wabimp.dll
+ 2004-08-05 03:00:00 147,968 ------w C:\WINDOWS\$NtUninstallKB923980$\nwprovau.dll
+ 2005-10-12 22:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe
+ 2005-10-12 22:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB923980$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 1,236,480 ------w C:\WINDOWS\$NtUninstallKB924191$\msxml3.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB924191$\spuninst\updspapi.dll
+ 2004-10-28 01:24:00 728,576 ------w C:\WINDOWS\$NtUninstallKB924270$\lsasrv.dll
+ 2006-07-14 15:41:06 332,288 ------w C:\WINDOWS\$NtUninstallKB924270$\netapi32.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB924270$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 132,096 ------w C:\WINDOWS\$NtUninstallKB924270$\wkssvc.dll
+ 2006-06-23 11:11:46 1,494,528 ------w C:\WINDOWS\$NtUninstallKB924496$\shdocvw.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB924496$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 924,432 ------w C:\WINDOWS\$NtUninstallKB924667$\mfc40u.dll
+ 2004-08-05 03:00:00 1,024,000 ------w C:\WINDOWS\$NtUninstallKB924667$\mfc42u.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB924667$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 499,741 ------w C:\WINDOWS\$NtUninstallKB925398_WMP64$\dxmasf.dll
+ 2005-06-28 08:23:40 216,800 ------w C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe
+ 2005-06-28 08:23:54 371,424 ------w C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 246,302 ------w C:\WINDOWS\$NtUninstallKB925398_WMP64$\strmdll.dll
+ 2005-10-12 23:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB925486$\spuninst\spuninst.exe
+ 2005-10-12 23:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB925486$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 848,384 ------w C:\WINDOWS\$NtUninstallKB925486$\vgx.dll
+ 2005-12-29 01:56:04 280,064 ------w C:\WINDOWS\$NtUninstallKB925902$\gdi32.dll
+ 2004-08-05 03:00:00 39,936 ------w C:\WINDOWS\$NtUninstallKB925902$\mf3216.dll
+ 2006-01-19 19:29:26 216,800 ------w C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe
+ 2006-01-19 19:29:26 394,976 ------w C:\WINDOWS\$NtUninstallKB925902$\spuninst\updspapi.dll
+ 2005-03-02 18:10:36 578,048 ------w C:\WINDOWS\$NtUninstallKB925902$\user32.dll
+ 2005-10-06 02:08:50 1,839,616 ------w C:\WINDOWS\$NtUninstallKB925902$\win32k.sys
+ 2005-10-12 22:12:26 213,216 ------w C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe
+ 2005-10-12 22:12:34 371,424 ------w C:\WINDOWS\$NtUninstallKB926239$\spuninst\updspapi.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB926255$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 716,800 ------w C:\WINDOWS\$NtUninstallKB926255$\sxs.dll
+ 2004-08-05 03:00:00 119,808 ------w C:\WINDOWS\$NtUninstallKB926436$\oledlg.dll
+ 2005-10-12 22:18:46 216,800 ------w C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe
+ 2005-10-12 22:18:50 394,976 ------w C:\WINDOWS\$NtUninstallKB926436$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 536,576 ------w C:\WINDOWS\$NtUninstallKB927779$\msado15.dll
+ 2004-08-05 03:00:00 180,224 ------w C:\WINDOWS\$NtUninstallKB927779$\msadomd.dll
+ 2004-08-05 03:00:00 200,704 ------w C:\WINDOWS\$NtUninstallKB927779$\msadox.dll
+ 2004-08-05 03:00:00 102,400 ------w C:\WINDOWS\$NtUninstallKB927779$\msjro.dll
+ 2006-01-19 18:29:26 216,800 ------w C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe
+ 2006-01-19 18:29:26 394,976 ------w C:\WINDOWS\$NtUninstallKB927779$\spuninst\updspapi.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB927802$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 333,824 ------w C:\WINDOWS\$NtUninstallKB927802$\wiaservc.dll
+ 2005-05-04 12:45:32 2,890,240 ------w C:\WINDOWS\$NtUninstallKB927891$\msi.dll
+ 2006-12-14 08:53:58 216,800 ------w C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe
+ 2006-12-14 08:53:58 394,976 ------w C:\WINDOWS\$NtUninstallKB927891$\spuninst\updspapi.dll
+ 2006-07-13 13:36:02 8,509,952 ------w C:\WINDOWS\$NtUninstallKB928255$\shell32.dll
+ 2004-08-05 03:00:00 135,168 ------w C:\WINDOWS\$NtUninstallKB928255$\shsvcs.dll
+ 2006-01-19 18:29:26 216,800 ------w C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe
+ 2006-01-19 18:29:26 394,976 ------w C:\WINDOWS\$NtUninstallKB928255$\spuninst\updspapi.dll
+ 2005-10-12 22:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe
+ 2005-10-12 22:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB928843$\spuninst\updspapi.dll
+ 2006-11-08 04:07:30 86,528 ------w C:\WINDOWS\$NtUninstallKB929123$\directdb.dll
+ 2006-11-08 04:07:30 679,424 ------w C:\WINDOWS\$NtUninstallKB929123$\inetcomm.dll
+ 2006-11-08 04:07:30 1,314,816 ------w C:\WINDOWS\$NtUninstallKB929123$\msoe.dll
+ 2006-01-19 19:29:26 216,800 ------w C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe
+ 2006-01-19 19:29:26 394,976 ------w C:\WINDOWS\$NtUninstallKB929123$\spuninst\updspapi.dll
+ 2006-11-08 04:07:30 510,976 ------w C:\WINDOWS\$NtUninstallKB929123$\wab32.dll
+ 2006-11-08 04:07:30 85,504 ------w C:\WINDOWS\$NtUninstallKB929123$\wabimp.dll
+ 2006-01-19 18:29:26 216,800 ------w C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe
+ 2006-01-19 18:29:26 394,976 ------w C:\WINDOWS\$NtUninstallKB931836$\spuninst\updspapi.dll
+ 2007-03-06 01:34:38 216,800 ------w C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe
+ 2007-03-06 01:35:48 394,976 ------w C:\WINDOWS\$NtUninstallKB933360$\spuninst\updspapi.dll
+ 2007-01-29 07:58:06 60,416 ------w C:\WINDOWS\$NtUninstallKB933360$\tzchange.exe
+ 2006-07-05 10:56:38 1,049,088 ------w C:\WINDOWS\$NtUninstallKB935839$\kernel32.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB935839$\spuninst\updspapi.dll
+ 2004-08-05 03:00:00 144,896 ------w C:\WINDOWS\$NtUninstallKB935840$\schannel.dll
+ 2006-01-19 19:29:26 216,800 ------w C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe
+ 2006-01-19 19:29:26 394,976 ------w C:\WINDOWS\$NtUninstallKB935840$\spuninst\updspapi.dll
+ 2006-09-13 05:03:06 1,084,416 ------w C:\WINDOWS\$NtUninstallKB936021$\msxml3.dll
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB936021$\spuninst\updspapi.dll
+ 2005-06-28 08:23:40 216,800 ------w C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe
+ 2005-06-28 08:23:54 371,424 ------w C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\updspapi.dll
+ 2006-10-18 20:47:20 10,834,432 ------w C:\WINDOWS\$NtUninstallKB936782_WMP11$\wmp.dll
+ 2004-08-05 03:00:00 1,036,288 ------w C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
+ 2005-10-12 23:15:26 216,800 ------w C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe
+ 2005-10-12 23:15:46 394,976 ------w C:\WINDOWS\$NtUninstallKB938828$\spuninst\updspapi.dll
+ 2007-03-08 15:37:50 281,600 ------w C:\WINDOWS\$NtUninstallKB938829$\gdi32.dll
+ 2006-01-19 19:29:26 216,800 ------w C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe
+ 2006-01-19 19:29:26 394,976 ------w C:\WINDOWS\$NtUninstallKB938829$\spuninst\updspapi.dll
+ 2005-06-28 08:23:40 216,800 ------w C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe
+ 2005-06-28 08:23:54 371,424 ------w C:\WINDOWS\$NtUninstallKB939683$\spuninst\updspapi.dll
+ 2006-10-24 18:14:08 317,440 ------w C:\WINDOWS\$NtUninstallKB939683$\unregmp2.exe
+ 2006-09-25 15:58:48 221,488 ------w C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe
+ 2006-09-25 15:58:48 379,184 ------w C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\updspapi.dll
+ 2005-01-28 13:22:12 486,912 ------w C:\WINDOWS\$NtUninstallWMFDist11$\audiodev.dll
+ 2005-01-28 06:53:28 294,912 ------w C:\WINDOWS\$NtUninstallWMFDist11$\blackbox.dll
+ 2005-01-28 06:53:20 164,864 ------w C:\WINDOWS\$NtUninstallWMFDist11$\cewmdm.dll
+ 2005-01-28 06:53:38 502,272 ------w C:\WINDOWS\$NtUninstallWMFDist11$\drmv2clt.dll
+ 2005-01-28 06:53:16 6,656 ------w C:\WINDOWS\$NtUninstallWMFDist11$\laprxy.dll
+ 2005-01-27 23:21:46 96,768 ------w C:\WINDOWS\$NtUninstallWMFDist11$\logagent.exe
+ 2004-08-05 03:00:00 310,272 ------w C:\WINDOWS\$NtUninstallWMFDist11$\mp43dmod.dll
+ 2004-08-05 03:00:00 384,512 ------w C:\WINDOWS\$NtUninstallWMFDist11$\mp4sdmod.dll
+ 2004-08-05 03:00:00 240,640 ------w C:\WINDOWS\$NtUninstallWMFDist11$\mpg4dmod.dll
+ 2005-01-28 06:53:22 142,336 ------w C:\WINDOWS\$NtUninstallWMFDist11$\msnetobj.dll
+ 2005-01-28 06:53:20 25,088 ------w C:\WINDOWS\$NtUninstallWMFDist11$\mspmsnsv.dll
+ 2005-01-28 06:53:20 173,568 ------w C:\WINDOWS\$NtUninstallWMFDist11$\mspmsp.dll
+ 2005-01-28 11:32:44 364,784 ------w C:\WINDOWS\$NtUninstallWMFDist11$\msscp.dll
+ 2005-01-28 13:22:12 316,416 ------w C:\WINDOWS\$NtUninstallWMFDist11$\mswmdm.dll
+ 2005-01-28 06:53:22 221,184 ------w C:\WINDOWS\$NtUninstallWMFDist11$\qasf.dll
+ 2006-05-16 17:11:54 213,216 ------w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe
+ 2006-05-16 17:11:54 371,424 ------w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\updspapi.dll
+ 2006-10-18 20:58:00 13,312 ------w C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
+ 2005-01-27 23:36:04 47,104 ------w C:\WINDOWS\$NtUninstallWMFDist11$\uwdf.exe
+ 2005-01-27 23:35:58 15,872 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wdfapi.dll
+ 2005-01-27 23:36:00 38,912 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wdfmgr.exe
+ 2005-01-28 11:32:44 396,528 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmadmod.dll
+ 2005-01-28 06:53:18 716,288 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmadmoe.dll
+ 2005-01-28 06:53:16 224,768 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmasf.dll
+ 2005-01-28 06:53:20 28,160 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmdmlog.dll
+ 2005-01-28 06:53:20 33,792 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmdmps.dll
+ 2005-01-28 06:53:50 335,872 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmdev.dll
+ 2005-01-28 06:53:54 290,816 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmdrmnet.dll
+ 2005-01-28 06:53:16 150,016 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmidx.dll
+ 2005-01-28 06:53:16 1,027,072 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmnetmgr.dll
+ 2005-01-28 11:32:56 774,904 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmsdmod.dll
+ 2005-01-28 06:53:18 1,119,744 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmsdmoe2.dll
+ 2005-01-28 13:22:12 827,392 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmsetsdk.exe
+ 2005-01-28 11:32:44 413,944 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmspdmod.dll
+ 2005-01-28 06:53:18 940,544 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmspdmoe.dll
+ 2005-01-28 11:32:56 1,218,808 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmvadvd.dll
+ 2005-01-28 06:53:20 1,512,448 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmvadve.dll
+ 2005-01-28 11:32:58 2,370,296 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmvcore.dll
+ 2005-01-28 11:32:58 895,736 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmvdmod.dll
+ 2005-01-28 06:53:18 1,003,008 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wmvdmoe2.dll
+ 2005-01-27 23:36:28 38,912 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wpd_ci.dll
+ 2005-01-27 23:36:20 61,952 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wpdconns.dll
+ 2005-01-27 23:36:24 114,176 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wpdmtp.dll
+ 2005-01-27 23:36:22 66,560 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wpdmtpus.dll
+ 2005-01-27 23:36:28 331,264 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wpdsp.dll
+ 2005-01-27 23:36:24 18,944 ------w C:\WINDOWS\$NtUninstallWMFDist11$\wpdusb.sys
+ 2005-01-28 13:22:24 8,704 ------w C:\WINDOWS\$NtUninstallwmp11$\asferror.dll
+ 2005-01-28 13:22:12 352,256 ------w C:\WINDOWS\$NtUninstallwmp11$\mpvis.dll
+ 2005-01-28 13:22:12 827,392 ------w C:\WINDOWS\$NtUninstallwmp11$\setup_wm.exe
+ 2006-05-16 17:11:54 213,216 ------w C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe
+ 2006-05-16 17:11:56 394,976 ------w C:\WINDOWS\$NtUninstallwmp11$\spuninst\updspapi.dll
+ 2005-01-28 13:22:12 192,512 ------w C:\WINDOWS\$NtUninstallwmp11$\unregmp2.exe
+ 2005-01-28 13:22:24 226,304 ------w C:\WINDOWS\$NtUninstall