Je suis infecter par win32/psw.lineage.dn/psw lineage que faire?

Je suis infecter par win32/psw.lineage.dn/psw lineage que faire ?certain programme se bloque au lancement et on m indique la phrase du dessus alors que mon anti virus est a jour et ne trouve pas de menaces[kaspersky 2009] aidez moi svp

fais un essais d’esset en téléchargeant la version d’essai de 30 jour >ici<
c’est le meilleur que je connaisse, et qui est utilisé par les sociétés microsoft…
Edité le 13/10/2009 à 20:30

Salut

en respectant ce soft ==>Eset NOD32 ==>si ce que je crois qu a seiko ForYou sur son PC j ai bien peur que ton Eset n y peuves pas grand Chose et
t inquiétes ==>jeanmimigab vas s en occuper

BONSOIR et merci de m avoir repondu !
Scan saved at 20:41:32, on 13/10/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Windows\system32\conime.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM…\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM…\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM…\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM…\Run: [Google Quick Search Box] “C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe” /autorun
O4 - HKLM…\Run: [Skytel] Skytel.exe
O4 - HKLM…\Run: [UnlockerAssistant] “C:\Program Files\Unlocker\UnlockerAssistant.exe”
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM…\Run: [AVP] “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe”
O4 - HKCU…\Run: [swg] “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”
O4 - HKCU…\Run: [uTorrent] “C:\Program Files\uTorrent\uTorrent.exe”
O4 - HKUS\S-1-5-19…\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘SERVICE LOCAL’)
O4 - HKUS\S-1-5-19…\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘SERVICE LOCAL’)
O4 - HKUS\S-1-5-20…\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ‘SERVICE RÉSEAU’)
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O13 - Gopher Prefix:
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - download.eset.com…
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - acs.pandasoftware.com…
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - platformdl.adobe.com…
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe


End of file - 4945 bytes

Salut Cricri58 : comment sa tu abandonne un sujet de virus :slight_smile:

Je n abondonne pas un Sujet

jeanmimigab étant le premier et

je te présente ==>jeanmimigab un t- bon Helpeur nouveau sur Clubic depuis quelques temps

et retiens son nom ,tu verras :super:

cricri58:hello:

bonsoir j ai utiliser malware bytes en mode sans echec pour un scan,mais riendu tout…j espere que vous pourrez m aider

cool alors un autre désinfecteur :slight_smile:

me voila de retour avec combot fix
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6002.2.1252.33.1036.18.3070.2224 [GMT 2:00]
Lancé depuis: c:\users\gauthier\Desktop\seiko.exe
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\users\gauthier\AppData\Roaming\Desktopicon
c:\windows\is-ADNJ8.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-13 au 2009-10-13 ))))))))))))))))))))))))))))))))))))
.

2009-10-13 18:41 . 2009-10-13 18:41 -------- d-----w- c:\program files\Trend Micro
2009-10-13 14:52 . 2009-10-13 14:52 87552 ----a-w- c:\users\gauthier\AppData\Local\mbr_rest.exe
2009-10-13 14:52 . 2009-10-13 14:52 87552 ----a-w- c:\users\gauthier\AppData\Local\mbr_inst.exe
2009-10-13 14:01 . 2008-06-19 15:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-13 14:01 . 2009-10-13 14:01 -------- d-----w- c:\program files\Panda Security
2009-10-13 09:49 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-13 09:05 . 2009-10-13 09:49 -------- d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-13 09:05 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-13 08:33 . 2005-05-26 18:00 403968 ----a-w- c:\windows\system32\NCTWMAFile2.dll
2009-10-13 08:33 . 2005-06-01 18:15 966144 ----a-w- c:\windows\system32\NCTAudioInformation2.dll
2009-10-13 08:33 . 2005-06-01 18:11 877568 ----a-w- c:\windows\system32\NCTAudioFile2.dll
2009-10-13 08:33 . 2003-03-19 17:03 544768 ----a-w- c:\windows\system32\msvcr71d.dll
2009-10-13 08:33 . 2009-10-13 08:33 -------- d-----w- c:\program files\Magic Audio Converter
2009-10-12 17:18 . 2009-10-12 17:18 -------- d-----w- c:\programdata\2019D
2009-10-11 10:45 . 2009-10-11 10:45 -------- d-----w- c:\users\gauthier\AppData\Roaming\GlarySoft
2009-10-11 10:26 . 2009-10-12 07:45 -------- d-----w- c:\program files\Glary Utilities
2009-10-10 10:59 . 2009-10-10 10:59 -------- d-----w- c:\programdata\Sunbelt
2009-10-10 05:55 . 2009-10-10 05:55 -------- d-----w- c:\program files\Vodei
2009-10-07 19:09 . 2009-10-08 19:12 -------- dc----w- c:\windows\system32\DRVSTORE
2009-10-02 17:14 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-25 20:44 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-25 19:59 . 2009-09-25 19:59 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-25 19:59 . 2009-09-25 19:59 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-25 19:59 . 2009-07-15 09:48 17224 ----a-w- c:\windows\system32\authuitu.dll
2009-09-25 19:59 . 2009-07-15 09:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-09-25 19:55 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-25 19:55 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-25 19:48 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-25 19:48 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-25 19:48 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-25 19:48 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-25 19:48 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-25 19:48 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-25 19:48 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-25 19:48 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-25 19:48 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-25 19:48 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-25 19:48 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-25 19:46 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-25 19:46 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-25 19:46 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-25 19:46 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-25 19:46 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-25 19:46 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 20:20 . 2006-11-02 15:45 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-13 20:20 . 2006-11-02 15:45 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-13 20:18 . 2009-07-28 19:49 -------- d-----w- c:\users\gauthier\AppData\Roaming\uTorrent
2009-10-13 20:14 . 2009-07-29 15:16 -------- d-----w- c:\programdata\Kaspersky Lab
2009-10-13 20:13 . 2009-07-29 15:16 663584 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-13 20:13 . 2009-07-29 15:16 4396 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-13 20:13 . 2009-07-29 15:16 2956832 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-13 20:13 . 2009-07-29 15:16 25228 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-13 11:18 . 2009-08-14 08:35 691 ----a-w- c:\users\gauthier\AppData\Roaming\GetValue.vbs
2009-10-13 11:18 . 2009-08-14 08:35 35 ----a-w- c:\users\gauthier\AppData\Roaming\SetValue.bat
2009-10-12 12:43 . 2009-08-03 19:42 -------- d-----w- c:\program files\Unlocker
2009-10-12 12:43 . 2009-07-28 20:29 -------- d-----w- c:\users\gauthier\AppData\Roaming\vlc
2009-10-12 11:25 . 2009-07-29 15:08 -------- d-----w- c:\users\gauthier\AppData\Roaming\Softplicity
2009-10-12 06:32 . 2009-07-28 19:42 -------- d-----w- c:\programdata\NVIDIA
2009-10-11 17:33 . 2009-07-29 20:21 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-10-11 11:11 . 2009-07-29 15:13 -------- d-----w- c:\program files\DAMN NFO Viewer
2009-10-08 16:15 . 2009-07-28 22:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 19:10 . 2009-07-28 14:52 -------- d–h--w- c:\program files\InstallShield Installation Information
2009-09-25 20:45 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-25 18:28 . 2009-07-29 15:16 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-09-25 18:28 . 2009-07-29 15:16 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-09-22 18:19 . 2009-08-14 09:28 -------- d-----w- c:\users\gauthier\AppData\Roaming\dvdcss
2009-08-28 09:30 . 2009-07-29 20:19 -------- d-----w- c:\programdata\DVD Shrink
2009-08-03 19:32 . 2009-08-03 19:32 687104 ----a-w- c:\windows\is-EDA9J.exe
2009-08-03 18:36 . 2009-08-03 18:36 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-08-01 10:11 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-08-01 10:11 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-07-30 17:35 . 2009-07-28 14:47 52776 ----a-w- c:\users\gauthier\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-29 15:37 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-07-28 21:25 . 2009-07-28 21:25 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-07-28 21:25 . 2009-07-28 21:25 272896 ----a-w- c:\windows\system32\polstore.dll
2009-07-28 21:20 . 2009-07-28 21:20 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-07-28 21:19 . 2009-07-28 21:19 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-28 21:19 . 2009-07-28 21:19 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-28 21:19 . 2009-07-28 21:19 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-07-28 21:19 . 2009-07-28 21:19 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-28 21:19 . 2009-07-28 21:19 23552 ----a-w- c:\windows\system32\lpk.dll
2009-07-28 21:19 . 2009-07-28 21:19 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-28 21:08 . 2009-07-28 21:08 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-07-28 21:01 . 2009-07-28 21:01 623616 ----a-w- c:\windows\system32\localspl.dll
2009-07-28 20:52 . 2009-07-28 20:52 6656 ----a-w- c:\windows\system32\kbd106n.dll
2009-07-28 20:43 . 2009-07-28 20:43 37888 ----a-w- c:\windows\system32\printcom.dll
2009-07-28 20:42 . 2009-07-28 20:42 14848 ----a-w- c:\windows\system32\wshrm.dll
2009-07-28 20:32 . 2009-07-28 20:32 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-07-28 20:29 . 2009-07-28 20:29 84480 ----a-w- c:\windows\system32\INETRES.dll
2009-07-28 20:28 . 2009-07-28 20:28 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-07-28 20:27 . 2009-07-28 20:27 2048 ----a-w- c:\windows\system32\msxml6r.dll
2009-07-28 20:05 . 2009-07-28 20:05 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-07-28 20:05 . 2009-07-28 20:05 43544 ----a-w- c:\windows\system32\wups2.dll
2009-07-28 20:05 . 2009-07-28 20:05 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-07-28 20:05 . 2009-07-28 20:05 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-07-28 20:05 . 2009-07-28 20:05 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-07-28 20:05 . 2009-07-28 20:05 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-07-28 20:05 . 2009-07-28 20:05 34328 ----a-w- c:\windows\system32\wups.dll
2009-07-28 20:05 . 2009-07-28 20:05 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-07-28 20:05 . 2009-07-28 20:05 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-07-28 19:36 . 2009-07-28 14:47 680 ----a-w- c:\users\gauthier\AppData\Local\d3d9caps.dat
2009-07-28 14:52 . 2009-07-28 14:52 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-07-28 14:52 . 2009-07-28 14:52 315392 ----a-w- c:\windows\HideWin.exe
2009-07-21 21:52 . 2009-08-01 09:38 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-01 09:38 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-01 09:38 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-01 09:38 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 05:55 71680 ----a-w- c:\windows\system32\atl.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2009-07-29 39408]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-08-11 274224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-19 1008184]
“NVRaidService”=“c:\windows\system32\nvraidservice.exe” [2008-11-12 203296]
“Google Quick Search Box”=“c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe” [2009-07-29 122368]
“UnlockerAssistant”=“c:\program files\Unlocker\UnlockerAssistant.exe” [2008-05-02 15872]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2009-03-27 13687328]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2009-03-27 92704]
“AVP”=“c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe” [2009-07-29 208616]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2008-03-26 5369856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r ??\L:\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“NBKeyScan”=“c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”
“NeroFilterCheck”=c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“UpdatesDisableNotify”=“0x00000000”

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“FirewallOverride”=dword:00000001
“VistaSp2”=hex(b):44,80,42,13,be,14,ca,01

[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{9832D154-5445-41C0-BDA3-431397305320}”= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
“{C92D6446-3FEF-4AD5-95E2-BD11762B9BEC}”= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

[HKLM~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
“EnableFirewall”= 0 (0x0)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/2008 18:29 33808]
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [13/10/2009 16:01 28544]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/2008 17:28 20496]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [25/09/2009 21:59 604488]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [26/06/2009 22:55 66080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
“c:\windows\System32\rundll32.exe” “c:\windows\System32\iedkcs32.dll”,BrandIEActiveSetup SIGNUP
.
Contenu du dossier ‘Tâches planifiées’

2009-10-13 c:\windows\Tasks\GlaryInitialize.job

  • c:\program files\Glary Utilities\initialize.exe [2009-10-11 17:27]

2009-10-13 c:\windows\Tasks\Maintenance en 1 clic.job

  • c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 09:00]

2009-10-13 c:\windows\Tasks\User_Feed_Synchronization-{4D3A81A7-DADD-4A40-8576-479C1871638B}.job

  • c:\windows\system32\msfeedssync.exe [2009-08-01 20:13]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = www.google.fr…
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - download.eset.com…
    .

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-10-13 22:21
Windows 6.0.6002 Service Pack 2 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

c:\windows\TEMP\TMP0000005C2C10734040087C8C 524288 bytes executable

Scan terminé avec succès
Fichiers cachés: 1


.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker3”

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
“Version”=“1.0”
.
Heure de fin: 2009-10-13 22:22
ComboFix-quarantined-files.txt 2009-10-13 20:22

Avant-CF: 270 025 396 224 octets libres
Après-CF: 270 048 280 576 octets libres

229 — E O F — 2009-10-13 08:20
e…que dois je faire maitenant ?
Edité le 13/10/2009 à 22:58

bonjour, j ai suivi les instructiComboFix 09-10-13.04 - gauthier 14/10/2009 17:59.2.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6002.2.1252.33.1036.18.3070.2027 [GMT 2:00]
Lancé depuis: c:\users\gauthier\Desktop\seiko.exe
Commutateurs utilisés :: c:\users\gauthier\Desktop\CFScript.txt
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
“c:\windows\is-EDA9J.exe”
“c:\windows\TEMP\TMP0000005C2C10734040087C8C”
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\is-EDA9J.exe

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-14 au 2009-10-14 ))))))))))))))))))))))))))))))))))))
.

2009-10-14 16:03 . 2009-10-14 16:03 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-14 16:03 . 2009-10-14 16:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-13 20:16 . 2009-10-13 20:22 -------- d-----w- C:\seiko
2009-10-13 18:41 . 2009-10-13 18:41 -------- d-----w- c:\program files\Trend Micro
2009-10-13 14:52 . 2009-10-13 14:52 87552 ----a-w- c:\users\gauthier\AppData\Local\mbr_rest.exe
2009-10-13 14:52 . 2009-10-13 14:52 87552 ----a-w- c:\users\gauthier\AppData\Local\mbr_inst.exe
2009-10-13 14:01 . 2008-06-19 15:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-13 14:01 . 2009-10-13 14:01 -------- d-----w- c:\program files\Panda Security
2009-10-13 09:49 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-13 09:05 . 2009-10-13 09:49 -------- d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-13 09:05 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-13 08:33 . 2005-05-26 18:00 403968 ----a-w- c:\windows\system32\NCTWMAFile2.dll
2009-10-13 08:33 . 2005-06-01 18:15 966144 ----a-w- c:\windows\system32\NCTAudioInformation2.dll
2009-10-13 08:33 . 2005-06-01 18:11 877568 ----a-w- c:\windows\system32\NCTAudioFile2.dll
2009-10-13 08:33 . 2003-03-19 17:03 544768 ----a-w- c:\windows\system32\msvcr71d.dll
2009-10-13 08:33 . 2009-10-13 08:33 -------- d-----w- c:\program files\Magic Audio Converter
2009-10-12 17:18 . 2009-10-12 17:18 -------- d-----w- c:\programdata\2019D
2009-10-11 10:45 . 2009-10-11 10:45 -------- d-----w- c:\users\gauthier\AppData\Roaming\GlarySoft
2009-10-11 10:26 . 2009-10-12 07:45 -------- d-----w- c:\program files\Glary Utilities
2009-10-10 10:59 . 2009-10-10 10:59 -------- d-----w- c:\programdata\Sunbelt
2009-10-10 05:55 . 2009-10-10 05:55 -------- d-----w- c:\program files\Vodei
2009-10-07 19:09 . 2009-10-08 19:12 -------- dc----w- c:\windows\system32\DRVSTORE
2009-10-02 17:14 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-25 20:44 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-25 19:59 . 2009-09-25 19:59 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-25 19:59 . 2009-09-25 19:59 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-25 19:59 . 2009-07-15 09:48 17224 ----a-w- c:\windows\system32\authuitu.dll
2009-09-25 19:59 . 2009-07-15 09:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-09-25 19:55 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-25 19:55 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-25 19:48 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-25 19:48 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-25 19:48 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-25 19:48 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-25 19:48 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-25 19:48 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-25 19:48 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-25 19:48 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-25 19:48 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-25 19:48 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-25 19:48 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-25 19:46 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-25 19:46 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-25 19:46 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-25 19:46 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-25 19:46 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-25 19:46 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-14 15:49 . 2006-11-02 15:45 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-14 15:49 . 2006-11-02 15:45 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-14 15:45 . 2009-07-28 19:49 -------- d-----w- c:\users\gauthier\AppData\Roaming\uTorrent
2009-10-14 15:44 . 2009-07-29 15:16 -------- d-----w- c:\programdata\Kaspersky Lab
2009-10-14 15:43 . 2009-07-29 15:16 663584 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-14 15:43 . 2009-07-29 15:16 4396 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-14 15:43 . 2009-07-29 15:16 2956832 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-14 15:43 . 2009-07-29 15:16 25228 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-14 15:43 . 2009-07-29 15:16 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-14 15:43 . 2009-07-29 15:16 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-13 11:18 . 2009-08-14 08:35 691 ----a-w- c:\users\gauthier\AppData\Roaming\GetValue.vbs
2009-10-13 11:18 . 2009-08-14 08:35 35 ----a-w- c:\users\gauthier\AppData\Roaming\SetValue.bat
2009-10-12 12:43 . 2009-08-03 19:42 -------- d-----w- c:\program files\Unlocker
2009-10-12 12:43 . 2009-07-28 20:29 -------- d-----w- c:\users\gauthier\AppData\Roaming\vlc
2009-10-12 11:25 . 2009-07-29 15:08 -------- d-----w- c:\users\gauthier\AppData\Roaming\Softplicity
2009-10-12 06:32 . 2009-07-28 19:42 -------- d-----w- c:\programdata\NVIDIA
2009-10-11 17:33 . 2009-07-29 20:21 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-10-11 11:11 . 2009-07-29 15:13 -------- d-----w- c:\program files\DAMN NFO Viewer
2009-10-08 16:15 . 2009-07-28 22:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 19:10 . 2009-07-28 14:52 -------- d–h--w- c:\program files\InstallShield Installation Information
2009-09-25 20:45 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-22 18:19 . 2009-08-14 09:28 -------- d-----w- c:\users\gauthier\AppData\Roaming\dvdcss
2009-08-28 09:30 . 2009-07-29 20:19 -------- d-----w- c:\programdata\DVD Shrink
2009-08-03 18:36 . 2009-08-03 18:36 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-08-01 10:11 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-08-01 10:11 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-07-30 17:35 . 2009-07-28 14:47 52776 ----a-w- c:\users\gauthier\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-29 15:37 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-07-28 21:25 . 2009-07-28 21:25 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-07-28 21:25 . 2009-07-28 21:25 272896 ----a-w- c:\windows\system32\polstore.dll
2009-07-28 21:20 . 2009-07-28 21:20 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-07-28 21:19 . 2009-07-28 21:19 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-28 21:19 . 2009-07-28 21:19 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-28 21:19 . 2009-07-28 21:19 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-07-28 21:19 . 2009-07-28 21:19 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-28 21:19 . 2009-07-28 21:19 23552 ----a-w- c:\windows\system32\lpk.dll
2009-07-28 21:19 . 2009-07-28 21:19 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-28 21:08 . 2009-07-28 21:08 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-07-28 21:01 . 2009-07-28 21:01 623616 ----a-w- c:\windows\system32\localspl.dll
2009-07-28 20:52 . 2009-07-28 20:52 6656 ----a-w- c:\windows\system32\kbd106n.dll
2009-07-28 20:43 . 2009-07-28 20:43 37888 ----a-w- c:\windows\system32\printcom.dll
2009-07-28 20:42 . 2009-07-28 20:42 14848 ----a-w- c:\windows\system32\wshrm.dll
2009-07-28 20:32 . 2009-07-28 20:32 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-07-28 20:29 . 2009-07-28 20:29 84480 ----a-w- c:\windows\system32\INETRES.dll
2009-07-28 20:28 . 2009-07-28 20:28 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-07-28 20:27 . 2009-07-28 20:27 2048 ----a-w- c:\windows\system32\msxml6r.dll
2009-07-28 20:05 . 2009-07-28 20:05 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-07-28 20:05 . 2009-07-28 20:05 43544 ----a-w- c:\windows\system32\wups2.dll
2009-07-28 20:05 . 2009-07-28 20:05 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-07-28 20:05 . 2009-07-28 20:05 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-07-28 20:05 . 2009-07-28 20:05 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-07-28 20:05 . 2009-07-28 20:05 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-07-28 20:05 . 2009-07-28 20:05 34328 ----a-w- c:\windows\system32\wups.dll
2009-07-28 20:05 . 2009-07-28 20:05 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-07-28 20:05 . 2009-07-28 20:05 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-07-28 19:36 . 2009-07-28 14:47 680 ----a-w- c:\users\gauthier\AppData\Local\d3d9caps.dat
2009-07-28 14:52 . 2009-07-28 14:52 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-07-28 14:52 . 2009-07-28 14:52 315392 ----a-w- c:\windows\HideWin.exe
2009-07-21 21:52 . 2009-08-01 09:38 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-01 09:38 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-01 09:38 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-01 09:38 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 05:55 71680 ----a-w- c:\windows\system32\atl.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\2019D ----

2009-10-12 17:18 . 2009-07-07 14:19 2329 ----a-w- c:\programdata\2019D{BC8AE07E-5F63-4B48-A1C2-EBDA7C304EDD}.swf

((((((((((((((((((((((((((((( SnapShot@2009-10-13_20.21.32 )))))))))))))))))))))))))))))))))))))))))
.

  • 2009-07-28 14:57 . 2009-10-14 15:46 28994 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
  • 2006-11-02 13:02 . 2009-10-14 15:46 52890 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
  • 2009-07-28 14:44 . 2009-10-13 20:15 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-07-28 14:44 . 2009-10-14 15:55 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-07-28 14:44 . 2009-10-13 20:15 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-07-28 14:44 . 2009-10-14 15:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-07-28 14:44 . 2009-10-13 20:15 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-07-28 14:44 . 2009-10-14 15:55 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-13 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-08-01 09:54 . 2009-10-12 13:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-08-01 09:54 . 2009-10-12 13:39 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-13 20:23 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-13 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-12 13:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-07-28 14:49 . 2009-10-14 15:46 5524 c:\windows\System32\WDI{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3883846523-1448754031-3493128317-1000_UserData.bin
  • 2009-10-13 20:14 . 2009-10-13 20:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
  • 2009-10-14 15:44 . 2009-10-14 15:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
  • 2009-10-13 20:14 . 2009-10-13 20:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
  • 2009-10-14 15:44 . 2009-10-14 15:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
  • 2009-08-13 05:22 . 2009-06-15 21:17 439880 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\ksecdd.sys
  • 2009-08-13 05:22 . 2009-06-15 18:40 439880 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\ksecdd.sys
  • 2009-08-13 05:22 . 2009-06-15 23:20 408136 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\ksecdd.sys
  • 2006-11-02 10:33 . 2009-10-13 20:20 586980 c:\windows\System32\perfh009.dat
  • 2006-11-02 10:33 . 2009-10-14 15:49 586980 c:\windows\System32\perfh009.dat
  • 2006-11-02 10:33 . 2009-10-13 20:20 101052 c:\windows\System32\perfc009.dat
  • 2006-11-02 10:33 . 2009-10-14 15:49 101052 c:\windows\System32\perfc009.dat
  • 2006-11-02 10:22 . 2009-10-07 19:10 5505024 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
  • 2006-11-02 10:22 . 2009-10-14 15:49 5505024 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
  • 2009-10-14 15:58 . 2009-10-14 15:58 5496832 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
  • 2009-08-01 09:22 . 2009-10-14 15:53 153316302 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2009-07-29 39408]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-08-11 274224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-19 1008184]
“NVRaidService”=“c:\windows\system32\nvraidservice.exe” [2008-11-12 203296]
“Google Quick Search Box”=“c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe” [2009-07-29 122368]
“UnlockerAssistant”=“c:\program files\Unlocker\UnlockerAssistant.exe” [2008-05-02 15872]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2009-03-27 13687328]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2009-03-27 92704]
“AVP”=“c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe” [2009-07-29 208616]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2008-03-26 5369856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r ??\L:\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“NBKeyScan”=“c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”
“NeroFilterCheck”=c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“FirewallOverride”=dword:00000001
“VistaSp2”=hex(b):44,80,42,13,be,14,ca,01

[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{9832D154-5445-41C0-BDA3-431397305320}”= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
“{C92D6446-3FEF-4AD5-95E2-BD11762B9BEC}”= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/2008 18:29 33808]
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [13/10/2009 16:01 28544]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/2008 17:28 20496]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [25/09/2009 21:59 604488]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [26/06/2009 22:55 66080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
“c:\windows\System32\rundll32.exe” “c:\windows\System32\iedkcs32.dll”,BrandIEActiveSetup SIGNUP
.
Contenu du dossier ‘Tâches planifiées’

2009-10-14 c:\windows\Tasks\GlaryInitialize.job

  • c:\program files\Glary Utilities\initialize.exe [2009-10-11 17:27]

2009-10-14 c:\windows\Tasks\Maintenance en 1 clic.job

  • c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 09:00]

2009-10-14 c:\windows\Tasks\User_Feed_Synchronization-{4D3A81A7-DADD-4A40-8576-479C1871638B}.job

  • c:\windows\system32\msfeedssync.exe [2009-08-01 20:13]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = www.google.fr…
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - download.eset.com…
    .

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés:


.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker3”

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
“Version”=“1.0”
.
Heure de fin: 2009-10-14 18:05
ComboFix-quarantined-files.txt 2009-10-14 16:05
ComboFix2.txt 2009-10-13 20:22

Avant-CF: 269 622 767 616 octets libres
Après-CF: 269 585 764 352 octets libres

251 — E O F — 2009-10-13 08:20

bonsoir j ai fait le scan mais fallait il desactiver kasperski car il s est mis en route pour stopper un virrus eicar ? ComboFix 09-10-13.04 - gauthier 14/10/2009 19:20.3.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6002.2.1252.33.1036.18.3070.2046 [GMT 2:00]
Lancé depuis: c:\users\gauthier\Desktop\seiko.exe
Commutateurs utilisés :: c:\users\gauthier\Desktop\CFScript.txt
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\2019D
c:\programdata\2019D{BC8AE07E-5F63-4B48-A1C2-EBDA7C304EDD}.swf

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-14 au 2009-10-14 ))))))))))))))))))))))))))))))))))))
.

2009-10-14 17:25 . 2009-10-14 17:25 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-14 17:25 . 2009-10-14 17:25 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-14 15:55 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-14 15:55 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 15:55 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-14 15:53 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-14 15:53 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-14 15:53 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-13 20:16 . 2009-10-13 20:22 -------- d-----w- C:\seiko
2009-10-13 18:41 . 2009-10-13 18:41 -------- d-----w- c:\program files\Trend Micro
2009-10-13 14:52 . 2009-10-13 14:52 87552 ----a-w- c:\users\gauthier\AppData\Local\mbr_rest.exe
2009-10-13 14:52 . 2009-10-13 14:52 87552 ----a-w- c:\users\gauthier\AppData\Local\mbr_inst.exe
2009-10-13 14:01 . 2008-06-19 15:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-13 14:01 . 2009-10-13 14:01 -------- d-----w- c:\program files\Panda Security
2009-10-13 09:49 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-13 09:05 . 2009-10-13 09:49 -------- d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-13 09:05 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-13 08:33 . 2005-05-26 18:00 403968 ----a-w- c:\windows\system32\NCTWMAFile2.dll
2009-10-13 08:33 . 2005-06-01 18:15 966144 ----a-w- c:\windows\system32\NCTAudioInformation2.dll
2009-10-13 08:33 . 2005-06-01 18:11 877568 ----a-w- c:\windows\system32\NCTAudioFile2.dll
2009-10-13 08:33 . 2003-03-19 17:03 544768 ----a-w- c:\windows\system32\msvcr71d.dll
2009-10-13 08:33 . 2009-10-13 08:33 -------- d-----w- c:\program files\Magic Audio Converter
2009-10-11 10:45 . 2009-10-11 10:45 -------- d-----w- c:\users\gauthier\AppData\Roaming\GlarySoft
2009-10-11 10:26 . 2009-10-12 07:45 -------- d-----w- c:\program files\Glary Utilities
2009-10-10 10:59 . 2009-10-10 10:59 -------- d-----w- c:\programdata\Sunbelt
2009-10-10 05:55 . 2009-10-10 05:55 -------- d-----w- c:\program files\Vodei
2009-10-07 19:09 . 2009-10-08 19:12 -------- dc----w- c:\windows\system32\DRVSTORE
2009-10-02 17:14 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-25 20:44 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-09-25 19:59 . 2009-09-25 19:59 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-25 19:59 . 2009-09-25 19:59 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-25 19:59 . 2009-07-15 09:48 17224 ----a-w- c:\windows\system32\authuitu.dll
2009-09-25 19:59 . 2009-07-15 09:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-09-25 19:55 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-25 19:55 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-25 19:48 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-25 19:48 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-25 19:48 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-25 19:48 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-25 19:48 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-25 19:48 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-25 19:48 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-25 19:48 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-25 19:48 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-25 19:48 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-25 19:48 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-25 19:46 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-25 19:46 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-25 19:46 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-25 19:46 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-25 19:46 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-25 19:46 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-14 17:20 . 2009-07-28 19:49 -------- d-----w- c:\users\gauthier\AppData\Roaming\uTorrent
2009-10-14 17:16 . 2006-11-02 15:45 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-14 17:16 . 2006-11-02 15:45 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-14 17:12 . 2009-07-29 15:16 -------- d-----w- c:\programdata\Kaspersky Lab
2009-10-14 17:10 . 2009-07-29 15:16 663584 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-14 17:10 . 2009-07-29 15:16 4396 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-14 17:10 . 2009-07-29 15:16 2956832 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-14 17:10 . 2009-07-29 15:16 25228 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-14 17:10 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-14 15:43 . 2009-07-29 15:16 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-14 15:43 . 2009-07-29 15:16 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-13 11:18 . 2009-08-14 08:35 691 ----a-w- c:\users\gauthier\AppData\Roaming\GetValue.vbs
2009-10-13 11:18 . 2009-08-14 08:35 35 ----a-w- c:\users\gauthier\AppData\Roaming\SetValue.bat
2009-10-12 12:43 . 2009-08-03 19:42 -------- d-----w- c:\program files\Unlocker
2009-10-12 12:43 . 2009-07-28 20:29 -------- d-----w- c:\users\gauthier\AppData\Roaming\vlc
2009-10-12 11:25 . 2009-07-29 15:08 -------- d-----w- c:\users\gauthier\AppData\Roaming\Softplicity
2009-10-12 06:32 . 2009-07-28 19:42 -------- d-----w- c:\programdata\NVIDIA
2009-10-11 17:33 . 2009-07-29 20:21 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-10-11 11:11 . 2009-07-29 15:13 -------- d-----w- c:\program files\DAMN NFO Viewer
2009-10-08 16:15 . 2009-07-28 22:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-07 19:10 . 2009-07-28 14:52 -------- d–h--w- c:\program files\InstallShield Installation Information
2009-09-22 18:19 . 2009-08-14 09:28 -------- d-----w- c:\users\gauthier\AppData\Roaming\dvdcss
2009-08-28 09:30 . 2009-07-29 20:19 -------- d-----w- c:\programdata\DVD Shrink
2009-08-27 05:22 . 2009-10-14 15:54 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-14 15:54 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-14 15:54 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-14 15:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-03 18:36 . 2009-08-03 18:36 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-08-01 10:11 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-08-01 10:11 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-07-30 17:35 . 2009-07-28 14:47 52776 ----a-w- c:\users\gauthier\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-29 15:37 . 2008-01-29 16:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-07-28 21:25 . 2009-07-28 21:25 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-07-28 21:25 . 2009-07-28 21:25 272896 ----a-w- c:\windows\system32\polstore.dll
2009-07-28 21:20 . 2009-07-28 21:20 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-07-28 21:19 . 2009-07-28 21:19 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-28 21:19 . 2009-07-28 21:19 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-28 21:19 . 2009-07-28 21:19 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-07-28 21:19 . 2009-07-28 21:19 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-28 21:19 . 2009-07-28 21:19 23552 ----a-w- c:\windows\system32\lpk.dll
2009-07-28 21:19 . 2009-07-28 21:19 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-28 21:08 . 2009-07-28 21:08 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-07-28 21:01 . 2009-07-28 21:01 623616 ----a-w- c:\windows\system32\localspl.dll
2009-07-28 20:52 . 2009-07-28 20:52 6656 ----a-w- c:\windows\system32\kbd106n.dll
2009-07-28 20:43 . 2009-07-28 20:43 37888 ----a-w- c:\windows\system32\printcom.dll
2009-07-28 20:42 . 2009-07-28 20:42 14848 ----a-w- c:\windows\system32\wshrm.dll
2009-07-28 20:32 . 2009-07-28 20:32 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-07-28 20:29 . 2009-07-28 20:29 84480 ----a-w- c:\windows\system32\INETRES.dll
2009-07-28 20:28 . 2009-07-28 20:28 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-07-28 20:27 . 2009-07-28 20:27 2048 ----a-w- c:\windows\system32\msxml6r.dll
2009-07-28 20:05 . 2009-07-28 20:05 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-07-28 20:05 . 2009-07-28 20:05 43544 ----a-w- c:\windows\system32\wups2.dll
2009-07-28 20:05 . 2009-07-28 20:05 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-07-28 20:05 . 2009-07-28 20:05 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-07-28 20:05 . 2009-07-28 20:05 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-07-28 20:05 . 2009-07-28 20:05 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-07-28 20:05 . 2009-07-28 20:05 34328 ----a-w- c:\windows\system32\wups.dll
2009-07-28 20:05 . 2009-07-28 20:05 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-07-28 20:05 . 2009-07-28 20:05 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-07-28 19:36 . 2009-07-28 14:47 680 ----a-w- c:\users\gauthier\AppData\Local\d3d9caps.dat
2009-07-28 14:52 . 2009-07-28 14:52 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-07-28 14:52 . 2009-07-28 14:52 315392 ----a-w- c:\windows\HideWin.exe
2009-07-17 13:54 . 2009-08-12 05:55 71680 ----a-w- c:\windows\system32\atl.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-10-13_20.21.32 )))))))))))))))))))))))))))))))))))))))))
.

  • 2009-10-14 15:53 . 2009-09-14 09:48 98816 c:\windows\winsxs\x86_microsoft-windows-smbserver-common_31bf3856ad364e35_6.0.6001.22522_none_044c3353295315ad\srvnet.sys
  • 2009-10-14 15:53 . 2009-09-04 14:19 60928 c:\windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.22218_none_c9c75e79bba6335e\msasn1.dll
  • 2009-10-14 15:53 . 2009-09-04 11:41 60928 c:\windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6002.18106_none_c9469106a28244f5\msasn1.dll
  • 2009-10-14 15:53 . 2009-09-04 14:23 61440 c:\windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.22515_none_c7ddebb3be829235\msasn1.dll
  • 2009-10-14 15:53 . 2009-09-04 12:24 61440 c:\windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6001.18326_none_c74a7d60a56c2a8c\msasn1.dll
  • 2009-10-14 15:53 . 2009-09-04 12:32 60928 c:\windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.21122_none_c5e9b27fc167074b\msasn1.dll
  • 2009-10-14 15:53 . 2009-09-04 12:38 60928 c:\windows\winsxs\x86_microsoft-windows-msasn1_31bf3856ad364e35_6.0.6000.16922_none_c5603d92a849343f\msasn1.dll
  • 2009-10-14 15:55 . 2009-09-10 17:09 72704 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\secur32.dll
  • 2009-10-14 15:55 . 2009-09-09 13:17 72704 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\secur32.dll
  • 2009-10-14 15:55 . 2009-09-10 17:31 72704 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\secur32.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 71680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.22918_none_a940a7ff8d650ab7\iesetup.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 55808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.22918_none_a940a7ff8d650ab7\iernonce.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 71680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18828_none_a8ac3b48744f86de\iesetup.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 55808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18828_none_a8ac3b48744f86de\iernonce.dll
  • 2009-10-14 15:54 . 2009-08-27 11:43 13312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.22918_none_dfbde1e509adc50e\msfeedssync.exe
  • 2009-10-14 15:54 . 2009-08-27 13:22 55296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.22918_none_dfbde1e509adc50e\msfeedsbs.dll
  • 2009-10-14 15:54 . 2009-08-27 03:41 13312 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18828_none_df29752df0984135\msfeedssync.exe
  • 2009-10-14 15:54 . 2009-08-27 05:18 55296 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_8.0.6001.18828_none_df29752df0984135\msfeedsbs.dll
  • 2009-10-14 15:54 . 2009-08-27 13:29 64512 c:\windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_8.0.6001.22918_none_e558e658d0bed32f\WininetPlugin.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 25600 c:\windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_8.0.6001.22918_none_e558e658d0bed32f\jsproxy.dll
  • 2009-10-14 15:54 . 2009-08-27 05:22 64512 c:\windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_8.0.6001.18828_none_e4c479a1b7a94f56\WininetPlugin.dll
  • 2009-10-14 15:54 . 2009-08-27 05:18 25600 c:\windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_8.0.6001.18828_none_e4c479a1b7a94f56\jsproxy.dll
  • 2009-07-28 14:57 . 2009-10-14 17:13 29034 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
  • 2006-11-02 13:02 . 2009-10-14 17:13 52922 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
  • 2009-10-14 15:54 . 2009-08-27 03:41 13312 c:\windows\System32\msfeedssync.exe
  • 2009-08-01 09:38 . 2009-07-21 20:13 13312 c:\windows\System32\msfeedssync.exe
  • 2009-08-01 09:38 . 2009-07-21 21:48 55296 c:\windows\System32\msfeedsbs.dll
  • 2009-10-14 15:54 . 2009-08-27 05:18 55296 c:\windows\System32\msfeedsbs.dll
  • 2009-10-14 15:54 . 2009-08-27 05:22 64512 c:\windows\System32\migration\WininetPlugin.dll
  • 2009-08-01 09:38 . 2009-07-21 21:52 64512 c:\windows\System32\migration\WininetPlugin.dll
  • 2009-10-14 15:54 . 2009-08-27 05:18 25600 c:\windows\System32\jsproxy.dll
  • 2009-08-01 09:38 . 2009-07-21 21:47 25600 c:\windows\System32\jsproxy.dll
  • 2009-08-01 09:38 . 2009-07-21 21:47 55808 c:\windows\System32\iernonce.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 55808 c:\windows\System32\iernonce.dll
  • 2009-07-28 14:44 . 2009-10-13 20:15 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-07-28 14:44 . 2009-10-14 17:18 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-07-28 14:44 . 2009-10-13 20:15 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-07-28 14:44 . 2009-10-14 17:18 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-07-28 14:44 . 2009-10-14 17:18 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-07-28 14:44 . 2009-10-13 20:15 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-13 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-08-01 09:54 . 2009-10-12 13:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-08-01 09:54 . 2009-10-13 20:23 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-12 13:39 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-13 20:23 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-08-01 09:54 . 2009-10-12 13:39 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-10-14 17:12 . 2009-10-14 17:12 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\71446066f8f87652fa7303395df566cc\UIAutomationProvider.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\28aa280d39ac935204e8f97b628dd25e\PresentationFontCache.ni.exe
  • 2009-10-14 17:12 . 2009-10-14 17:12 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\32d58b6e9270ca077d0f3e787acd0a37\PresentationCFFRasterizer.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\84dda64a3e7cec7239ede8d5e48b5847\Microsoft.VisualC.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1bcbcac5237f54c73628936552c55b69\Accessibility.ni.dll
  • 2009-10-14 15:55 . 2009-09-10 14:44 9728 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\lsass.exe
  • 2009-10-14 15:55 . 2009-09-09 11:09 9728 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\lsass.exe
  • 2009-10-14 15:55 . 2009-09-10 14:47 7680 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\lsass.exe
  • 2009-07-28 14:49 . 2009-10-14 17:13 5524 c:\windows\System32\WDI{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3883846523-1448754031-3493128317-1000_UserData.bin
  • 2009-10-14 17:11 . 2009-10-14 17:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
  • 2009-10-13 20:14 . 2009-10-13 20:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
  • 2009-10-14 17:11 . 2009-10-14 17:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
  • 2009-10-13 20:14 . 2009-10-13 20:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
  • 2009-10-14 16:19 . 2009-09-04 06:59 388920 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.22219_none_fcfe427e14d1391e\SOS.dll
  • 2009-10-14 16:19 . 2009-09-04 06:59 388936 c:\windows\winsxs\x86_netfx-sos_dll_b03f5f7f11d50a3a_6.0.6002.18107_none_13cb1683fb2a8c7f\SOS.dll
  • 2009-10-14 16:19 . 2009-09-04 06:58 989528 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.22219_none_142ffabd20dc5d09\mscordacwks.dll
  • 2009-10-14 16:19 . 2009-09-04 06:58 989000 c:\windows\winsxs\x86_netfx-mscordacwks_b03f5f7f11d50a3a_6.0.6002.18107_none_2afccec30735b06a\mscordacwks.dll
  • 2009-10-14 15:53 . 2009-05-08 13:06 604672 c:\windows\winsxs\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.22131_none_fc80747986388ef6\WMSPDMOD.DLL
  • 2009-10-14 15:53 . 2009-05-08 12:53 604672 c:\windows\winsxs\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6002.18034_none_fbf9d88c6d183b31\WMSPDMOD.DLL
  • 2009-10-14 15:53 . 2009-04-02 12:22 604672 c:\windows\winsxs\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.22403_none_fabc72e988f818ad\WMSPDMOD.DLL
  • 2009-10-14 15:53 . 2009-04-02 12:37 604672 c:\windows\winsxs\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6001.18234_none_fa1364be6ff1e8e6\WMSPDMOD.DLL
  • 2009-10-14 15:53 . 2009-04-02 11:59 604672 c:\windows\winsxs\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.21033_none_f8b59abb8bea11aa\WMSPDMOD.DLL
  • 2009-10-14 15:53 . 2009-04-02 11:50 604672 c:\windows\winsxs\x86_microsoft-windows-wmspdmod_31bf3856ad364e35_6.0.6000.16838_none_f831274072c7bd51\WMSPDMOD.DLL
  • 2009-10-14 15:53 . 2009-09-14 09:34 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.22225_none_dc4c11540ccb53e5\srv2.sys
  • 2009-10-14 15:53 . 2009-09-14 09:29 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6002.18112_none_dbca4396f3a84c25\srv2.sys
  • 2009-10-14 15:53 . 2009-09-14 09:48 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.22522_none_da629e8e0fa7b2bc\srv2.sys
  • 2009-10-14 15:53 . 2009-09-14 09:44 144896 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6001.18331_none_d9cd2fa6f6931865\srv2.sys
  • 2009-10-14 15:53 . 2009-09-14 09:42 131072 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.21127_none_d8813796127cd699\srv2.sys
  • 2009-10-14 15:53 . 2009-09-14 09:50 130048 c:\windows\winsxs\x86_microsoft-windows-smbserver-v2_31bf3856ad364e35_6.0.6000.16927_none_d7f7c2a8f95f038d\srv2.sys
  • 2009-10-14 15:55 . 2009-09-10 17:08 218624 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.22223_none_7f10642478dc3089\msv1_0.dll
  • 2009-10-14 15:55 . 2009-09-10 16:48 218624 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6002.18111_none_7e8f96b15fb84220\msv1_0.dll
  • 2009-10-14 15:55 . 2009-09-09 13:16 214016 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.22518_none_7d39c39a7ba93e27\msv1_0.dll
  • 2009-10-14 15:55 . 2009-09-10 17:30 213504 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6001.18330_none_7c9282c162a30e60\msv1_0.dll
  • 2009-10-14 15:55 . 2009-09-10 17:29 216576 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.21125_none_7b458a667e8db33d\msv1_0.dll
  • 2009-10-14 15:55 . 2009-09-10 17:38 216576 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.0.6000.16926_none_7abd15c3656ef988\msv1_0.dll
  • 2009-10-14 15:55 . 2009-09-10 17:10 175104 c:\windows\winsxs\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6002.22223_none_3d2ac2689306813a\wdigest.dll
  • 2009-10-14 15:55 . 2009-09-09 13:17 175104 c:\windows\winsxs\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6001.22518_none_3b5421de95d38ed8\wdigest.dll
  • 2009-10-14 15:55 . 2009-09-10 17:31 175104 c:\windows\winsxs\x86_microsoft-windows-security-digest_31bf3856ad364e35_6.0.6000.21125_none_395fe8aa98b803ee\wdigest.dll
  • 2009-08-13 05:22 . 2009-06-15 21:17 439880 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\ksecdd.sys
  • 2009-08-13 05:22 . 2009-06-15 18:40 439880 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\ksecdd.sys
  • 2009-08-13 05:22 . 2009-06-15 23:20 408136 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\ksecdd.sys
  • 2009-10-14 15:54 . 2009-08-27 13:21 164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.22918_none_48125f7add0aca92\ieui.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18828_none_477df2c3c3f546b9\ieui.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.22918_none_ff020cabe8e8477c\iesysprep.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 109056 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_8.0.6001.18828_none_fe6d9ff4cfd2c3a3\iesysprep.dll
  • 2009-10-14 15:54 . 2009-08-27 11:44 173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.22918_none_a940a7ff8d650ab7\ie4uinit.exe
  • 2009-10-14 15:54 . 2009-08-27 03:42 173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18828_none_a8ac3b48744f86de\ie4uinit.exe
  • 2009-10-14 15:54 . 2009-08-27 13:29 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.22918_none_2b139d34bb6ff18c\sqmapi.dll
  • 2009-10-14 15:54 . 2009-08-27 05:22 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18828_none_2a7f307da25a6db3\sqmapi.dll
  • 2009-10-14 15:54 . 2009-08-27 13:26 206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.22918_none_1a965b07430ed6fa\occache.dll
  • 2009-10-14 15:54 . 2009-08-27 05:20 206848 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_8.0.6001.18828_none_1a01ee5029f95321\occache.dll
  • 2009-10-14 15:54 . 2009-08-27 13:31 638216 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22918_none_12d1f2e448ea4212\iexplore.exe
  • 2009-10-14 15:54 . 2009-08-27 11:44 133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22918_none_12d1f2e448ea4212\ieUnatt.exe
  • 2009-10-14 15:54 . 2009-08-27 05:23 638232 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe
  • 2009-10-14 15:54 . 2009-08-27 03:42 133632 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\ieUnatt.exe
  • 2009-10-14 15:54 . 2009-08-27 13:21 197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.22918_none_2afd22d0c924c41c\IEShims.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.18828_none_2a68b619b00f4043\IEShims.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 246272 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.22918_none_739ed73a797c5dae\ieproxy.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 246272 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.18828_none_730a6a836066d9d5\ieproxy.dll
  • 2009-10-14 15:54 . 2009-08-27 13:22 594432 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.22918_none_43567d27696225e7\msfeeds.dll
  • 2009-10-14 15:54 . 2009-08-27 05:18 594432 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_8.0.6001.18828_none_42c21070504ca20e\msfeeds.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.22918_none_2033778a20f99b91\iepeers.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 184320 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_8.0.6001.18828_none_1f9f0ad307e417b8\iepeers.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.22918_none_57c05f548668f3f6\iedkcs32.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 387584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.18828_none_572bf29d6d53701d\iedkcs32.dll
  • 2009-10-14 15:54 . 2009-08-27 13:29 916480 c:\windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_8.0.6001.22918_none_e558e658d0bed32f\wininet.dll
  • 2009-10-14 15:54 . 2009-08-27 05:22 916480 c:\windows\winsxs\x86_microsoft-windows-i…tocolimplementation_31bf3856ad364e35_8.0.6001.18828_none_e4c479a1b7a94f56\wininet.dll
  • 2009-08-04 04:29 . 2009-03-30 04:42 311296 c:\windows\winsxs\msil_mscorlib.resources_b77a5c561934e089_6.0.6002.22219_fr-fr_a8b0cd6bf104a38a\mscorlib.Resources.dll
  • 2009-08-04 04:29 . 2009-03-30 04:42 311296 c:\windows\winsxs\msil_mscorlib.resources_b77a5c561934e089_6.0.6002.18107_fr-fr_bf7da171d75df6eb\mscorlib.Resources.dll
  • 2006-11-02 10:33 . 2009-10-13 20:20 586980 c:\windows\System32\perfh009.dat
  • 2006-11-02 10:33 . 2009-10-14 17:16 586980 c:\windows\System32\perfh009.dat
  • 2006-11-02 10:33 . 2009-10-13 20:20 101052 c:\windows\System32\perfc009.dat
  • 2006-11-02 10:33 . 2009-10-14 17:16 101052 c:\windows\System32\perfc009.dat
  • 2009-10-14 15:54 . 2009-08-27 05:20 206848 c:\windows\System32\occache.dll
  • 2009-08-01 09:38 . 2009-07-21 21:50 206848 c:\windows\System32\occache.dll
  • 2009-10-14 15:54 . 2009-08-27 05:18 594432 c:\windows\System32\msfeeds.dll
  • 2009-08-01 09:38 . 2009-07-21 21:48 594432 c:\windows\System32\msfeeds.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 164352 c:\windows\System32\ieui.dll
  • 2009-08-01 09:38 . 2009-07-21 21:47 164352 c:\windows\System32\ieui.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 184320 c:\windows\System32\iepeers.dll
  • 2009-08-01 09:38 . 2009-07-21 21:47 184320 c:\windows\System32\iepeers.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 387584 c:\windows\System32\iedkcs32.dll
  • 2009-08-01 09:38 . 2009-07-21 20:13 173056 c:\windows\System32\ie4uinit.exe
  • 2009-10-14 15:54 . 2009-08-27 03:42 173056 c:\windows\System32\ie4uinit.exe
  • 2009-08-04 04:30 . 2009-03-30 04:42 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
  • 2009-10-14 16:19 . 2009-09-04 06:59 388936 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
  • 2009-10-14 16:19 . 2009-09-04 06:58 989000 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
  • 2009-08-04 04:30 . 2009-03-30 04:42 989000 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\4609787a9b076765ecb68581a25df450\UIAutomationTypes.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b0d40c6d0fc00ba251010b710ca452a6\System.ServiceProcess.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\3bf0444969d6c9bf5e3106c9aa59c1d0\System.Security.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f91c1865b06602c72f0efc99a0d4634a\System.Runtime.Serialization.Formatters.Soap.ni.dll
  • 2009-10-14 17:13 . 2009-10-14 17:13 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\cf90c37ebdf793f7d485cdf1461cefd7\System.Drawing.Design.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\78aac991cacbc9665c628f5466cec9c1\System.Configuration.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\97b0e9c797db7eb8c7e15a81d88b0f1f\System.Configuration.Install.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6a409c40a6067264d0592415fcfc266d\PresentationFramework.Luna.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\54e0042aba64d42f476234184b1b8f77\PresentationFramework.Classic.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3ae3d45b608b6e0fcb51d3a903563621\PresentationFramework.Royale.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\0fa8eb806fadfff925850522a53c3c18\PresentationFramework.Aero.ni.dll
  • 2009-10-14 16:19 . 2009-09-04 06:59 5818704 c:\windows\winsxs\x86_netfx-mscorwks_dll_b03f5f7f11d50a3a_6.0.6002.22219_none_1b6bd7d648db5136\mscorwks.dll
  • 2009-10-14 16:19 . 2009-09-04 06:59 5812544 c:\windows\winsxs\x86_netfx-mscorwks_dll_b03f5f7f11d50a3a_6.0.6002.18107_none_3238abdc2f34a497\mscorwks.dll
  • 2009-10-14 16:19 . 2009-09-04 06:58 4550656 c:\windows\winsxs\x86_mscorlib_b77a5c561934e089_6.0.6002.22219_none_b0c508e8db53ecb1\mscorlib.dll
  • 2009-10-14 16:19 . 2009-09-04 06:58 4550656 c:\windows\winsxs\x86_mscorlib_b77a5c561934e089_6.0.6002.18107_none_c791dceec1ad4012\mscorlib.dll
  • 2009-10-14 15:55 . 2009-08-05 14:10 3548216 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22191_none_6e402703caaf139b\ntoskrnl.exe
  • 2009-10-14 15:55 . 2009-08-05 14:10 3599928 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22191_none_6e402703caaf139b\ntkrnlpa.exe
  • 2009-10-14 15:55 . 2009-08-04 12:34 3548216 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18082_none_6dc25a6eb1887137\ntoskrnl.exe
  • 2009-10-14 15:55 . 2009-08-04 12:34 3600456 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18082_none_6dc25a6eb1887137\ntkrnlpa.exe
  • 2009-10-14 15:55 . 2009-08-05 17:15 3547736 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_6c6c8757cd796d3e\ntoskrnl.exe
  • 2009-10-14 15:55 . 2009-08-05 17:15 3599960 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_6c6c8757cd796d3e\ntkrnlpa.exe
  • 2009-10-14 15:55 . 2009-08-05 14:22 3546184 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18304_none_6c34687ab41f6f39\ntoskrnl.exe
  • 2009-10-14 15:55 . 2009-08-05 14:22 3597896 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18304_none_6c34687ab41f6f39\ntkrnlpa.exe
  • 2009-10-14 15:55 . 2009-08-05 14:10 3469896 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_6ad49de3d019654f\ntoskrnl.exe
  • 2009-10-14 15:55 . 2009-08-05 14:10 3503688 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_6ad49de3d019654f\ntkrnlpa.exe
  • 2009-10-14 15:55 . 2009-08-05 14:28 3467864 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16901_none_6a4b28f6b6fb9243\ntoskrnl.exe
  • 2009-10-14 15:55 . 2009-08-05 14:28 3502152 c:\windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16901_none_6a4b28f6b6fb9243\ntkrnlpa.exe
  • 2009-10-14 16:17 . 2009-09-01 07:40 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22224_none_f4e691bf81cad9ef\OESpamFilter.dat
  • 2009-10-14 16:17 . 2009-09-01 07:40 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18111_none_f464c40268a7d22f\OESpamFilter.dat
  • 2009-10-14 16:17 . 2009-09-01 07:39 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22521_none_f2fd1ef984a738c6\OESpamFilter.dat
  • 2009-10-14 16:17 . 2009-09-01 07:40 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18330_none_f267b0126b929e6f\OESpamFilter.dat
  • 2009-10-14 16:17 . 2009-09-01 07:40 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21126_none_f11bb801877c5ca3\OESpamFilter.dat
  • 2009-10-14 16:17 . 2009-09-01 07:40 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16926_none_f09243146e5e8997\OESpamFilter.dat
  • 2009-10-14 15:55 . 2009-09-10 17:07 1259520 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6002.22223_none_a8a80213731ca5a7\lsasrv.dll
  • 2009-10-14 15:55 . 2009-09-09 13:17 1258496 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.22518_none_a6d1618975e9b345\lsasrv.dll
  • 2009-10-14 15:55 . 2009-09-10 17:28 1235456 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6000.21125_none_a4dd285578ce285b\lsasrv.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 1986048 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.22918_none_2b139d34bb6ff18c\iertutil.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 1985536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18828_none_2a7f307da25a6db3\iertutil.dll
  • 2009-10-14 15:54 . 2009-08-27 13:22 5942272 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.22918_none_f6b3057751153c65\mshtml.dll
  • 2009-10-14 15:54 . 2009-08-27 05:18 5940224 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18828_none_f61e98c037ffb88c\mshtml.dll
  • 2009-10-14 15:54 . 2009-08-27 13:29 1209344 c:\windows\winsxs\x86_microsoft-windows-i…ersandsecurityzones_31bf3856ad364e35_8.0.6001.22918_none_98530ab705b5ac9c\urlmon.dll
  • 2009-10-14 15:54 . 2009-08-27 05:22 1208832 c:\windows\winsxs\x86_microsoft-windows-i…ersandsecurityzones_31bf3856ad364e35_8.0.6001.18828_none_97be9dffeca028c3\urlmon.dll
  • 2009-08-01 09:38 . 2009-07-21 21:52 1208832 c:\windows\System32\urlmon.dll
  • 2009-10-14 15:54 . 2009-08-27 05:22 1208832 c:\windows\System32\urlmon.dll
  • 2006-11-02 10:22 . 2009-10-14 17:22 6029312 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
  • 2009-10-14 15:54 . 2009-08-27 05:18 5940224 c:\windows\System32\mshtml.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 1985536 c:\windows\System32\iertutil.dll
  • 2009-08-01 09:38 . 2009-07-21 21:47 1985536 c:\windows\System32\iertutil.dll
  • 2009-10-14 16:19 . 2009-09-04 06:59 5812544 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
  • 2009-08-04 04:30 . 2009-03-30 04:42 5812544 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
  • 2009-10-14 16:19 . 2009-09-04 06:58 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
  • 2009-08-04 04:30 . 2009-03-30 04:42 4550656 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 3314176 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c681da7e1c7b648cb456f2d90e7c50fe\WindowsBase.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 7868416 c:\windows\assembly\NativeImages_v2.0.50727_32\System\13cce38e8de5fd54853390e4e98abd0e\System.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 5450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\99e7927ccb9099e607035349814d4cf6\System.Xml.ni.dll
  • 2009-10-14 17:13 . 2009-10-14 17:13 1911296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\1f48aa633e1390542786d1f4aadf4d9c\System.Workflow.Runtime.ni.dll
  • 2009-10-14 17:13 . 2009-10-14 17:13 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\ea04089f9339c24a5b9049f225d644d6\System.Workflow.ComponentModel.ni.dll
  • 2009-10-14 17:13 . 2009-10-14 17:13 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\d0cab30213f071a1d29756cc384b1c40\System.Workflow.Activities.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\57e722244d3b48cb92b340bc92d7a191\System.Drawing.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\4edeee9bfffbaea5bc43ebdac1db3580\System.Deployment.ni.dll
  • 2009-10-14 17:13 . 2009-10-14 17:13 6621696 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\74114632794c536c35d28a5c60f694ab\System.Data.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\84b5a57d2a24d4fdda2f25e93fdd4c65\System.Data.SqlXml.ni.dll
  • 2009-08-04 04:30 . 2009-03-30 04:42 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
  • 2009-10-14 16:19 . 2009-09-04 06:58 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
  • 2009-10-14 15:54 . 2009-08-27 13:21 11069952 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.22918_none_48125f7add0aca92\ieframe.dll
  • 2009-10-14 15:54 . 2009-08-27 05:17 11069440 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18828_none_477df2c3c3f546b9\ieframe.dll
  • 2006-11-02 10:24 . 2009-10-02 18:01 25198016 c:\windows\System32\mrt.exe
  • 2009-10-14 15:54 . 2009-08-27 05:17 11069440 c:\windows\System32\ieframe.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 12430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\425e95df110b77abad261a46fca54e99\System.Windows.Forms.ni.dll
  • 2009-10-14 17:13 . 2009-10-14 17:13 10683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\1097f0aba9cd9bdb9295ab05ca7e68b8\System.Design.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 14327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\394fd96b27f367e6ffb13bc8c35fdcb2\PresentationFramework.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 12216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\bfbe98e8737c97d8c938275ceca2b1d8\PresentationCore.ni.dll
  • 2009-10-14 17:12 . 2009-10-14 17:12 11490816 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\894183c0c47bd4772fbfad4c1a7e3b71\mscorlib.ni.dll
  • 2009-08-01 09:22 . 2009-10-14 16:19 154412164 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
    .
    – Instantané actualisé –
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2009-07-29 39408]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-08-11 274224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-19 1008184]
“NVRaidService”=“c:\windows\system32\nvraidservice.exe” [2008-11-12 203296]
“Google Quick Search Box”=“c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe” [2009-07-29 122368]
“UnlockerAssistant”=“c:\program files\Unlocker\UnlockerAssistant.exe” [2008-05-02 15872]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2009-03-27 13687328]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2009-03-27 92704]
“AVP”=“c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe” [2009-07-29 208616]
“RtHDVCpl”=“RtHDVCpl.exe” - c:\windows\RtHDVCpl.exe [2008-03-26 5369856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r ??\L:\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe”

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“NBKeyScan”=“c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”
“NeroFilterCheck”=c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
“DisableMonitoring”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“FirewallOverride”=dword:00000001
“VistaSp2”=hex(b):44,80,42,13,be,14,ca,01

[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{9832D154-5445-41C0-BDA3-431397305320}”= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
“{C92D6446-3FEF-4AD5-95E2-BD11762B9BEC}”= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/2008 18:29 33808]
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [13/10/2009 16:01 28544]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/2008 17:28 20496]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [25/09/2009 21:59 604488]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [26/06/2009 22:55 66080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
“c:\windows\System32\rundll32.exe” “c:\windows\System32\iedkcs32.dll”,BrandIEActiveSetup SIGNUP
.
Contenu du dossier ‘Tâches planifiées’

2009-10-14 c:\windows\Tasks\GlaryInitialize.job

  • c:\program files\Glary Utilities\initialize.exe [2009-10-11 17:27]

2009-10-14 c:\windows\Tasks\Maintenance en 1 clic.job

  • c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 09:00]

2009-10-14 c:\windows\Tasks\User_Feed_Synchronization-{4D3A81A7-DADD-4A40-8576-479C1871638B}.job

  • c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = www.google.fr…
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - download.eset.com…
    .

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés:


.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker3”

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
“Version”=“1.0”
.
Heure de fin: 2009-10-14 19:26
ComboFix-quarantined-files.txt 2009-10-14 17:26
ComboFix2.txt 2009-10-14 16:05
ComboFix3.txt 2009-10-13 20:22

Avant-CF: 264 005 828 608 octets libres
Après-CF: 263 982 043 136 octets libres

Current=1 Default=1 Failed=0 LastKnownGood=1 Sets=1,2,3,4
432 — E O F — 2009-10-14 16:20


VOICI LE SCAN DE MALWARE BYTES:Malwarebytes' Anti-Malware 1.41 Version de la base de données: 2953 Windows 6.0.6002 Service Pack 2

14/10/2009 19:43:40
mbam-log-2009-10-14 (19-43-40).txt

Type de recherche: Examen rapide
Eléments examinés: 84453
Temps écoulé: 2 minute(s), 55 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

bonjour,voici le resultat du scan.j ai installer ToolsCleaner,dans mes documents et non sur le bureau…j espere ne pas avoir fait de betises…je me demande pourquoi kaspersky n a pas arreter l infection???ENCORE UN GRAND MERCI POUR LE COUP DE MAIN!
C:\Combofix.txt: trouvé !
C:\Qoobox: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Qoobox\Quarantine\catchme.log: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\gauthier\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
C:\Users\gauthier\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\Users\gauthier\Documents\SmitFraudfix: trouvé !
C:\Users\gauthier\Mes documents\SmitFraudfix: trouvé !