helluin Posté(e) le 8 décembre 2008 Partager Posté(e) le 8 décembre 2008 Bonjour, J'ai un souci depuis quelques temps avec mon PC sous XP SP3. Le lancement de toute application .exe génère un message d'erreur "application win32 invalide". Je pensais à un virus ou trojan mais ça ne semble pas être le cas (voir ici ce qu'il en était : http://www.pcentraide.com/index.php?showtopic=105410 ) Ce qui m'étonne c'est la ressemblance avec le cas évoqué par campif ici : http://www.pcinpact.com/forum/index.php?sh...83&hl=win32 Je veux bien suivre la procédure qu'il utilise mais je ne sais pas interpréter les résultats des scans. Une bonne âme pour me prendre en main et revoir avec moi les possibilités de remise en route ? Merci, Arnaud. Lien vers le commentaire Partager sur d’autres sites More sharing options...
noisette Posté(e) le 8 décembre 2008 Partager Posté(e) le 8 décembre 2008 Salut, télécharge Hijackthis, et fait un scan avec: poste ensuite le rapport dans la centralisation Hijackthis. (cf ma signature) Lien vers le commentaire Partager sur d’autres sites More sharing options...
helluin Posté(e) le 8 décembre 2008 Auteur Partager Posté(e) le 8 décembre 2008 salut. voilà c'est fait, en mode sans échec. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:25:36, on 08/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Safe mode with network support Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ntvdm.exe C:\WINDOWS\system32\cmd.exe C:\DOCUME~1\Arnaud\BUREAU\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\Arnaud\Bureau\Spybot\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\OneTouch.exe O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\Arnaud\BUREAU\HijackThis.exe /startupscan O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: RICOH Gate La.lnk = ? O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = ? O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\DOCUME~1\Arnaud\Bureau\Spybot\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\DOCUME~1\Arnaud\Bureau\Spybot\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Arnaud/LOCALS~1/Temp/msohtml1/01/clip_image002.gif -- End of file - 9301 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 9 décembre 2008 Partager Posté(e) le 9 décembre 2008 Salut , le rapport Hijackthis doit être créé en mode normal ! Désinstalle Spybot , Avast et autres joyeusetés ... Lance Clean v2.0 , procédure 1 . Redémarre le pc . Lance une analyse complète avec MBAM , puis poste le rapport créé. ... vise ma signature pour les programmes à utiliser Lien vers le commentaire Partager sur d’autres sites More sharing options...
helluin Posté(e) le 9 décembre 2008 Auteur Partager Posté(e) le 9 décembre 2008 voilà désactivation, lancement du clean2.0 et lancement de mbam. Le rapport de mbam : Malwarebytes' Anti-Malware 1.31 Version de la base de données: 1478 Windows 5.1.2600 Service Pack 3 09/12/2008 21:08:38 mbam-log-2008-12-09 (21-08-31).txt Type de recherche: Examen complet (C:\|D:\|) Eléments examinés: 104383 Temps écoulé: 46 minute(s), 27 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 1 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): C:\clean.cmd (Trojan.Agent) -> No action taken. Le rapport hijackthis, refait après en mode normal pour info : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:17:06, on 09/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\lxcrcoms.exe C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Maxtor\Utils\SyncServices.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\ntvdm.exe C:\WINDOWS\system32\cmd.exe C:\DOCUME~1\Arnaud\BUREAU\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\OneTouch.exe O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Documents and Settings\Arnaud\Bureau\malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\Arnaud\BUREAU\HijackThis.exe /startupscan O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: RICOH Gate La.lnk = ? O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = ? O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O24 - Desktop Component 0: (no name) - (no file) O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/Arnaud/LOCALS~1/Temp/msohtml1/01/clip_image002.gif -- End of file - 9048 bytes Voilà, merci de ton aide si tu comprends ce qui se passe. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 10 décembre 2008 Partager Posté(e) le 10 décembre 2008 Désinstalle Windows Defender . Coche et fix checked toutes les lignes 04 avec Hijackthis. Redémarre le pc . Installe Antivir. Lien vers le commentaire Partager sur d’autres sites More sharing options...
helluin Posté(e) le 10 décembre 2008 Auteur Partager Posté(e) le 10 décembre 2008 comment je désactive windows defender ? Je n'ai pas accès aux options du panneaux de configuration, toujours le même message "pas une application win32 valide" Pour contourner ce phénomène avec les autres programmes, je les lance depuis la fenêtre d'exécution en prenant soin de les installer sur le bureau (plus facile à retrouver) mais là, je bloque. Quelle ligne de commande taper à l'écran pour activer la désinstallation de windows defender ? Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 10 décembre 2008 Partager Posté(e) le 10 décembre 2008 Lance ComboFix et poste le rapport créé ( n'installe pas la console de récupération ) http://www.bleepingcomputer.com/combofix/f...iliser-combofix Lien vers le commentaire Partager sur d’autres sites More sharing options...
helluin Posté(e) le 11 décembre 2008 Auteur Partager Posté(e) le 11 décembre 2008 ok, voilà le rapport fait par combofix : ComboFix 08-12-09.03 - Arnaud 2008-12-11 12:00:42.2 - NTFSx86 Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1647 [GMT 1:00] Lancé depuis: c:\docume~1\Arnaud\BUREAU\Cofix.exe * Un nouveau point de restauration a été créé . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . C:\InfoSat.txt c:\windows\system32\tmp.reg . ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-11 au 2008-12-11 )))))))))))))))))))))))))))))))))))) . 2008-12-11 11:26 . 2008-12-11 11:57 <REP> d-------- C:\ComboFix 2008-12-09 19:38 . 2006-03-02 13:00 19,456 --a--c--- c:\windows\system32\dllcache\cprofile.exe 2008-12-09 19:38 . 2006-03-02 13:00 19,456 --a------ c:\windows\system32\cprofile.exe 2008-12-09 18:56 . 2008-12-02 12:35 254,604 --a------ C:\clean.cmd 2008-12-02 11:42 . 2008-12-02 11:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Maxtor 2008-12-02 11:39 . 2008-12-02 11:40 <REP> d-------- c:\progra~1\Maxtor 2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\progra~1\FICHIE~1\Crystal Decisions 2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\documents and settings\All Users\Application Data\InstallShield 2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\docume~1\Arnaud\Application Data\InstallShield 2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\docume~1\Arnaud\Application Data\InstallShield 2008-12-01 18:23 . 2008-12-01 18:24 0 --a------ c:\documents and settings\SFC 2008-12-01 16:14 . 2008-12-01 16:19 <REP> d-------- c:\windows\BDOSCAN8 2008-12-01 15:59 . 2008-12-10 23:31 1,393 --a------ c:\windows\imsins.BAK 2008-12-01 15:54 . 2008-10-16 21:18 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll 2008-11-29 15:10 . 2008-11-29 15:10 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2008-11-29 15:10 . 2008-11-29 15:10 <REP> d-------- c:\docume~1\Arnaud\Application Data\Malwarebytes 2008-11-29 15:10 . 2008-11-29 15:10 <REP> d-------- c:\docume~1\Arnaud\Application Data\Malwarebytes 2008-11-29 15:10 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-11-29 15:10 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-11-28 23:13 . 2008-11-29 00:18 <REP> d-------- c:\progra~1\FindyKill 2008-11-28 21:29 . 2008-11-28 21:33 <REP> d-------- C:\Co-Fix 2008-11-25 20:35 . 2008-12-08 23:27 664 --a------ c:\windows\system32\d3d9caps.dat 2008-11-25 20:25 . 2008-11-25 20:27 <REP> d-------- C:\copie de sauvegarde déplantage 2008-11-25 19:42 . 2008-11-25 19:42 <REP> d-------- C:\SmitfraudFix 2008-11-22 11:06 . 2008-11-22 13:42 <REP> d-------- c:\documents and settings\Arnaud\.housecall6.6 2008-11-12 20:13 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-11-12 20:12 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-11 11:01 --------- d-----w c:\progra~1\Fichiers communs 2008-12-11 10:46 0 ----a-w c:\windows\system32\drivers\lvuvc.hs 2008-12-09 18:37 --------- d-----w c:\progra~1\Lexmark 2400 Series 2008-12-09 18:37 --------- d-----w c:\docume~1\Arnaud\Application Data\Skype 2008-12-09 18:37 --------- d-----w c:\docume~1\Arnaud\Application Data\Skype 2008-12-09 17:02 --------- d-----w c:\progra~1\Alwil Software 2008-12-09 11:05 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2008-12-08 21:15 --------- d-----w c:\progra~1\lx_cats 2008-12-02 10:40 --------- d--h--w c:\progra~1\InstallShield Installation Information 2008-11-28 21:31 --------- d-----w c:\progra~1\Spybot - Search & Destroy 2008-11-21 14:29 --------- d-----w c:\docume~1\Arnaud\Application Data\skypePM 2008-11-21 14:29 --------- d-----w c:\docume~1\Arnaud\Application Data\skypePM 2008-11-08 12:27 --------- d-----w c:\progra~1\VersalSoft 2008-11-08 12:27 --------- d-----w c:\progra~1\Universal 2008-11-08 12:25 --------- d-----w c:\progra~1\CesarFTP 2008-11-07 11:26 --------- d-----w c:\progra~1\FICHIE~1\Adobe 2008-11-04 17:40 --------- d-----w c:\progra~1\CDBurnerXP Pro 3 2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll 2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll 2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys 2008-04-08 13:08 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat 2007-03-17 12:03 24,192 ----a-w c:\documents and settings\Arnaud\usbsermptxp.sys 2007-03-17 12:03 22,768 ----a-w c:\documents and settings\Arnaud\usbsermpt.sys 2006-02-23 13:52 280,576 ----a-w c:\windows\inf\TEW-421PC\MRV8335XP.sys 2006-02-23 13:52 280,576 ----a-w c:\windows\inf\TEW-421PC\MRV8335.sys 2006-02-23 13:52 212,992 ----a-w c:\windows\inf\TEW-421PC\CopyWHQLDriver.exe 2001-03-28 10:02 122,880 ----a-w c:\windows\inf\Agfa\message.exe . ((((((((((((((((((((((((((((( snapshot@2008-11-28_21.32.32,04 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-01 15:16:36 45,056 ----a-w c:\windows\BDOSCAN8\avxdisk.dll + 2008-12-01 15:16:36 10,240 ----a-w c:\windows\BDOSCAN8\avxs.dll + 2008-12-01 15:16:36 27,136 ----a-w c:\windows\BDOSCAN8\avxt.dll + 2008-12-01 15:16:38 102,400 ----a-w c:\windows\BDOSCAN8\bdcore.dll + 2006-05-25 00:21:00 118,784 ----a-w c:\windows\BDOSCAN8\bdupd.dll + 2006-05-25 00:21:14 53,248 ----a-w c:\windows\BDOSCAN8\ipsupd.dll + 2008-12-01 15:16:38 142,848 ----a-w c:\windows\BDOSCAN8\libfn.dll + 2008-12-01 15:16:36 86,016 ----a-w c:\windows\BDOSCAN8\librtvr.dll + 2006-05-25 00:22:06 53,248 ----a-w c:\windows\bdoscandel.exe + 2008-04-14 02:33:18 61,440 -c----w c:\windows\ie7\admparse.dll + 2008-04-14 02:33:18 101,888 -c----w c:\windows\ie7\advpack.dll + 2006-06-02 19:32:20 33,792 -c----w c:\windows\ie7\custsat.dll + 2008-04-14 02:33:23 357,888 -c----w c:\windows\ie7\dxtmsft.dll + 2008-04-14 02:33:23 205,312 -c----w c:\windows\ie7\dxtrans.dll + 2008-04-14 02:33:24 55,808 -c----w c:\windows\ie7\extmgr.dll + 2008-04-14 02:33:26 38,912 -c----w c:\windows\ie7\hmmapi.dll + 2008-04-14 02:34:06 34,304 -c----w c:\windows\ie7\ie4uinit.exe + 2008-04-14 02:33:26 143,360 -c----w c:\windows\ie7\ieakeng.dll + 2008-04-14 02:33:26 221,184 -c----w c:\windows\ie7\ieaksie.dll + 2006-03-02 12:00:00 245,760 -c----w c:\windows\ie7\ieakui.dll + 2008-04-14 02:33:26 323,584 -c----w c:\windows\ie7\iedkcs32.dll + 2008-04-14 02:34:06 18,432 -c----w c:\windows\ie7\iedw.exe + 2008-04-14 02:33:26 251,904 -c----w c:\windows\ie7\iepeers.dll + 2008-04-14 02:33:26 49,152 -c----w c:\windows\ie7\iernonce.dll + 2008-04-14 02:33:26 63,488 -c----w c:\windows\ie7\iesetup.dll + 2008-04-14 02:34:06 93,184 -c----w c:\windows\ie7\iexplore.exe + 2008-04-14 02:33:26 35,840 -c----w c:\windows\ie7\imgutil.dll + 2008-04-14 02:33:27 96,768 -c----w c:\windows\ie7\inseng.dll + 2008-04-14 02:33:27 15,872 -c----w c:\windows\ie7\jsproxy.dll + 2008-04-14 02:33:28 22,528 -c----w c:\windows\ie7\licmgr10.dll + 2008-04-14 02:34:12 29,184 -c----w c:\windows\ie7\mshta.exe + 2008-08-20 05:10:12 3,088,896 -c----w c:\windows\ie7\mshtml.dll + 2008-04-14 02:33:31 449,024 -c----w c:\windows\ie7\mshtmled.dll + 2008-04-14 01:56:24 57,344 -c----w c:\windows\ie7\mshtmler.dll + 2006-03-02 12:00:00 146,432 -c----w c:\windows\ie7\msls31.dll + 2008-04-14 02:33:32 146,432 -c----w c:\windows\ie7\msrating.dll + 2008-04-14 02:33:33 532,480 -c----w c:\windows\ie7\mstime.dll + 2008-04-14 02:33:38 97,280 -c----w c:\windows\ie7\occache.dll + 2008-04-14 02:33:38 39,424 -c----w c:\windows\ie7\pngfilt.dll + 2007-09-26 17:34:42 33,472 -c----w c:\windows\ie7\spuninst\iecustom.dll + 2007-09-26 17:32:30 66,048 -c--a-w c:\windows\ie7\spuninst\ieResetIcons.exe + 2006-09-06 16:43:28 216,800 -c----w c:\windows\ie7\spuninst\spuninst.exe + 2006-09-06 16:43:30 394,976 -c----w c:\windows\ie7\spuninst\updspapi.dll + 2008-04-14 02:33:48 37,888 -c----w c:\windows\ie7\url.dll + 2008-08-20 05:10:11 620,544 -c----w c:\windows\ie7\urlmon.dll + 2008-04-14 02:33:48 851,968 -c----w c:\windows\ie7\vgx.dll + 2008-04-14 02:33:48 281,600 -c----w c:\windows\ie7\webcheck.dll + 2008-08-20 05:10:11 670,208 -c----w c:\windows\ie7\wininet.dll + 2007-03-06 01:34:38 216,800 -c----w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe + 2007-03-06 01:35:47 394,976 -c----w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll + 2007-08-13 17:54:10 765,952 -c----w c:\windows\ie7updates\KB938127-v2-IE7\vgx.dll + 2007-08-13 17:39:00 123,904 -c----w c:\windows\ie7updates\KB956390-IE7\advpack.dll + 2007-08-13 17:39:00 123,904 -c----w c:\windows\ie7updates\KB956390-IE7\advpack.dll.000 + 2007-08-13 17:35:46 346,624 -c----w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll + 2007-08-13 17:35:46 346,624 -c----w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll.000 + 2007-08-13 17:35:38 214,528 -c----w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll + 2007-08-13 17:35:38 214,528 -c----w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll.000 + 2007-08-13 17:54:10 131,584 -c----w c:\windows\ie7updates\KB956390-IE7\extmgr.dll + 2007-08-13 17:54:10 131,584 -c----w c:\windows\ie7updates\KB956390-IE7\extmgr.dll.000 + 2007-08-13 17:36:26 61,952 -c----w c:\windows\ie7updates\KB956390-IE7\icardie.dll + 2007-08-13 17:39:06 54,784 -c----w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe + 2007-08-13 17:39:06 54,784 -c----w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe.000 + 2007-08-13 17:39:26 152,064 -c----w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll + 2007-08-13 17:39:26 152,064 -c----w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll.000 + 2007-08-13 17:39:54 229,376 -c----w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll + 2007-08-13 17:39:54 229,376 -c----w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll.000 + 2007-08-13 16:56:54 161,792 -c----w c:\windows\ie7updates\KB956390-IE7\ieakui.dll + 2007-02-12 15:10:12 2,451,312 -c----w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dat + 2007-07-11 11:27:48 383,488 -c----w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dll + 2007-08-13 17:39:50 382,976 -c----w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll + 2007-08-13 17:39:50 382,976 -c----w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll.000 + 2007-08-13 17:54:10 6,049,280 -c----w c:\windows\ie7updates\KB956390-IE7\ieframe.dll + 2007-08-13 17:39:10 43,008 -c----w c:\windows\ie7updates\KB956390-IE7\iernonce.dll + 2007-08-13 17:39:10 43,008 -c----w c:\windows\ie7updates\KB956390-IE7\iernonce.dll.000 + 2007-08-13 17:34:04 266,752 -c----w c:\windows\ie7updates\KB956390-IE7\iertutil.dll + 2007-08-13 17:39:10 13,312 -c----w c:\windows\ie7updates\KB956390-IE7\ieudinit.exe + 2007-08-13 17:54:10 27,136 -c----w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll + 2007-08-13 17:54:10 27,136 -c----w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll.000 + 2007-08-13 17:54:10 458,752 -c----w c:\windows\ie7updates\KB956390-IE7\msfeeds.dll + 2007-08-13 17:54:10 50,688 -c----w c:\windows\ie7updates\KB956390-IE7\msfeedsbs.dll + 2007-08-13 17:54:12 3,578,368 -c----w c:\windows\ie7updates\KB956390-IE7\mshtml.dll + 2007-08-13 17:54:10 475,648 -c----w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll + 2007-08-13 17:54:10 475,648 -c----w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll.000 + 2007-08-13 17:44:26 192,000 -c----w c:\windows\ie7updates\KB956390-IE7\msrating.dll + 2007-08-13 17:44:26 192,000 -c----w c:\windows\ie7updates\KB956390-IE7\msrating.dll.000 + 2007-08-13 17:54:10 670,720 -c----w c:\windows\ie7updates\KB956390-IE7\mstime.dll + 2007-08-13 17:54:10 670,720 -c----w c:\windows\ie7updates\KB956390-IE7\mstime.dll.000 + 2007-08-13 17:44:06 101,376 -c----w c:\windows\ie7updates\KB956390-IE7\occache.dll + 2007-08-13 17:44:06 101,376 -c----w c:\windows\ie7updates\KB956390-IE7\occache.dll.000 + 2007-08-13 17:36:12 44,544 -c----w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll + 2007-08-13 17:36:12 44,544 -c----w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll.000 + 2007-03-06 01:34:38 216,800 -c----w c:\windows\ie7updates\KB956390-IE7\spuninst\spuninst.exe + 2007-03-06 01:35:48 394,976 -c----w c:\windows\ie7updates\KB956390-IE7\spuninst\updspapi.dll + 2007-08-13 17:44:30 105,984 -c----w c:\windows\ie7updates\KB956390-IE7\url.dll + 2007-08-13 17:44:30 105,984 -c----w c:\windows\ie7updates\KB956390-IE7\url.dll.000 + 2007-08-13 17:54:10 1,162,240 -c----w c:\windows\ie7updates\KB956390-IE7\urlmon.dll + 2007-08-13 17:54:10 231,424 -c----w c:\windows\ie7updates\KB956390-IE7\webcheck.dll + 2007-08-13 17:54:10 231,424 -c----w c:\windows\ie7updates\KB956390-IE7\webcheck.dll.000 + 2007-08-13 17:54:10 818,688 -c----w c:\windows\ie7updates\KB956390-IE7\wininet.dll + 2008-08-26 08:11:45 124,928 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll + 2008-08-26 08:11:45 347,136 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll + 2008-08-26 08:11:45 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll + 2008-08-26 08:11:45 133,120 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll + 2008-08-26 08:11:45 63,488 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll + 2008-08-25 08:39:40 70,656 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe + 2008-08-26 08:11:45 153,088 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll + 2008-08-26 08:11:45 230,400 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll + 2008-08-23 05:54:51 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll + 2008-08-26 08:11:46 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll + 2008-08-26 08:11:46 384,512 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll + 2008-10-03 17:12:27 6,066,176 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll + 2008-08-26 08:11:48 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll + 2008-08-26 08:11:48 267,776 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll + 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe + 2008-08-23 05:56:15 635,848 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe + 2008-08-26 08:11:49 27,648 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll + 2008-08-26 08:11:49 459,264 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll + 2008-08-26 08:11:49 52,224 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll + 2008-08-27 13:41:52 3,593,216 -c----w c:\windows\ie7updates\KB958215-IE7\mshtml.dll + 2008-08-26 08:11:52 477,696 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll + 2008-08-26 08:11:52 193,024 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll + 2008-08-26 08:11:52 671,232 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll + 2008-08-26 08:11:52 102,912 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll + 2008-08-26 08:11:52 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll + 2007-03-06 01:34:38 216,800 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe + 2007-03-06 01:35:48 394,976 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll + 2008-08-26 08:11:52 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll + 2008-08-26 08:11:53 1,159,680 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll + 2008-08-26 08:11:53 233,472 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll + 2008-08-26 08:11:54 826,368 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll - 2008-11-12 22:25:32 593,920 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe + 2008-12-10 22:32:08 593,920 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe - 2008-11-12 22:25:32 12,288 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe + 2008-12-10 22:32:08 12,288 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe - 2008-11-12 22:25:32 86,016 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe + 2008-12-10 22:32:08 86,016 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe - 2008-11-12 22:25:32 135,168 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe + 2008-12-10 22:32:08 135,168 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe - 2008-11-12 22:25:32 11,264 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2008-12-10 22:32:08 11,264 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe - 2008-11-12 22:25:32 27,136 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2008-12-10 22:32:08 27,136 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe - 2008-11-12 22:25:33 4,096 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2008-12-10 22:32:08 4,096 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe - 2008-11-12 22:25:33 794,624 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe + 2008-12-10 22:32:08 794,624 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe - 2008-11-12 22:25:32 249,856 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe + 2008-12-10 22:32:08 249,856 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe - 2008-11-12 22:25:32 61,440 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe + 2008-12-10 22:32:08 61,440 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe - 2008-11-12 22:25:33 23,040 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe + 2008-12-10 22:32:08 23,040 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2008-11-12 22:25:32 286,720 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe + 2008-12-10 22:32:08 286,720 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe - 2008-11-12 22:25:32 409,600 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe + 2008-12-10 22:32:08 409,600 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe + 2008-12-02 10:40:44 45,056 ----a-r c:\windows\Installer\{9C3F9580-F5CF-4288-894E-9FF0EB24A21C}\NewShortcut2_9C3F9580F5CF4288894E9FF0EB24A21C.exe + 2008-12-02 10:39:54 65,536 ----a-r c:\windows\Installer\{FF268652-B3E8-494F-8343-1FC6DD0FF523}\NewShortcut2_60EEB642E9E045A2A676B9D8FE17C4A9.exe + 2008-12-02 10:39:54 65,536 ----a-r c:\windows\Installer\{FF268652-B3E8-494F-8343-1FC6DD0FF523}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe - 2008-04-14 02:33:18 61,440 ----a-w c:\windows\system32\admparse.dll + 2007-08-13 17:39:20 71,680 ----a-w c:\windows\system32\admparse.dll - 2008-04-14 02:33:18 101,888 ----a-w c:\windows\system32\advpack.dll + 2008-10-16 20:18:31 124,928 ----a-w c:\windows\system32\advpack.dll - 2007-03-17 10:37:37 262,144 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat + 2008-12-09 18:38:48 8,192 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat + 2007-08-13 17:39:20 71,680 -c----w c:\windows\system32\dllcache\admparse.dll + 2008-10-16 20:18:31 124,928 -c----w c:\windows\system32\dllcache\advpack.dll + 2006-09-23 12:12:56 1,022,976 -c----w c:\windows\system32\dllcache\browseui.dll + 2007-08-13 17:42:54 17,408 -c----w c:\windows\system32\dllcache\corpol.dll - 2006-06-02 19:32:20 33,792 -c--a-w c:\windows\system32\dllcache\custsat.dll + 2007-08-13 17:54:10 33,792 -c--a-w c:\windows\system32\dllcache\custsat.dll + 2008-10-16 20:18:31 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll + 2008-10-16 20:18:31 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll + 2008-10-16 20:18:31 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll + 2008-10-23 12:36:51 286,720 -c----w c:\windows\system32\dllcache\gdi32.dll + 2007-08-13 17:18:02 60,416 -c----w c:\windows\system32\dllcache\hmmapi.dll + 2008-10-16 13:12:20 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe + 2008-10-16 20:18:32 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll + 2008-10-16 20:18:32 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll - 2006-03-02 12:00:00 245,760 -c--a-w c:\windows\system32\dllcache\ieakui.dll + 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll - 2007-04-03 04:36:20 2,453,952 -c----w c:\windows\system32\dllcache\ieapfltr.dat + 2007-04-17 09:32:38 2,455,488 -c----w c:\windows\system32\dllcache\ieapfltr.dat - 2007-04-03 14:29:23 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll + 2008-10-16 20:18:32 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll + 2008-10-16 20:18:32 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll + 2007-08-13 17:44:02 69,120 -c----w c:\windows\system32\dllcache\iedw.exe + 2007-08-13 17:45:18 78,336 -c----w c:\windows\system32\dllcache\ieencode.dll - 2007-02-27 13:25:31 6,054,400 -c----w c:\windows\system32\dllcache\ieframe.dll + 2008-10-16 20:18:35 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll + 2007-08-13 17:54:10 191,488 -c----w c:\windows\system32\dllcache\iepeers.dll + 2008-10-16 20:18:35 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll - 2007-02-27 13:25:34 266,752 -c----w c:\windows\system32\dllcache\iertutil.dll + 2008-10-16 20:18:35 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll + 2007-08-13 17:39:12 55,296 -c----w c:\windows\system32\dllcache\iesetup.dll - 2007-02-27 08:20:47 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe + 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe + 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe + 2007-08-13 17:36:06 36,352 -c----w c:\windows\system32\dllcache\imgutil.dll + 2007-08-13 17:39:02 92,672 -c----w c:\windows\system32\dllcache\inseng.dll + 2008-10-16 20:18:36 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll + 2007-08-13 17:44:18 40,960 -c----w c:\windows\system32\dllcache\licmgr10.dll - 2006-10-18 18:03:58 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe + 2008-06-18 00:09:22 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe - 2007-02-27 13:25:46 458,752 -c----w c:\windows\system32\dllcache\msfeeds.dll + 2008-10-16 20:18:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll - 2007-02-27 13:25:46 51,712 -c----w c:\windows\system32\dllcache\msfeedsbs.dll + 2008-10-16 20:18:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll + 2007-08-13 17:32:30 45,568 -c----w c:\windows\system32\dllcache\mshta.exe - 2008-08-20 05:10:12 3,088,896 -c----w c:\windows\system32\dllcache\mshtml.dll + 2008-10-17 00:48:40 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll + 2008-10-16 20:18:40 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll + 2007-08-13 17:01:12 48,128 -c----w c:\windows\system32\dllcache\mshtmler.dll - 2006-03-02 12:00:00 146,432 -c--a-w c:\windows\system32\dllcache\msls31.dll + 2007-08-13 17:54:10 156,160 -c--a-w c:\windows\system32\dllcache\msls31.dll + 2008-10-16 20:18:40 193,024 -c----w c:\windows\system32\dllcache\msrating.dll + 2008-10-16 20:18:41 671,232 -c----w c:\windows\system32\dllcache\mstime.dll + 2008-10-16 20:18:41 102,912 -c----w c:\windows\system32\dllcache\occache.dll + 2008-10-16 20:18:41 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll + 2008-04-14 02:34:19 153,088 -c--a-w c:\windows\system32\dllcache\regedit.exe + 2006-09-23 12:12:56 474,624 -c----w c:\windows\system32\dllcache\shlwapi.dll - 2008-04-14 02:33:46 246,814 -c--a-w c:\windows\system32\dllcache\strmdll.dll + 2008-10-03 10:03:53 247,326 -c--a-w c:\windows\system32\dllcache\strmdll.dll + 2008-04-14 02:34:25 347,136 -c--a-w c:\windows\system32\dllcache\tourstrt.exe + 2008-10-16 20:18:41 105,984 -c----w c:\windows\system32\dllcache\url.dll - 2008-08-20 05:10:11 620,544 -c----w c:\windows\system32\dllcache\urlmon.dll + 2008-10-16 20:18:42 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll + 2008-05-27 17:25:06 765,952 -c----w c:\windows\system32\dllcache\vgx.dll + 2008-10-16 20:18:42 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll - 2008-08-20 05:10:11 670,208 -c----w c:\windows\system32\dllcache\wininet.dll + 2008-10-16 20:18:43 826,368 -c----w c:\windows\system32\dllcache\wininet.dll - 2006-10-18 19:47:20 937,984 -c--a-w c:\windows\system32\dllcache\WMNetMgr.dll + 2008-06-18 04:03:08 938,496 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll - 2006-10-18 19:47:22 2,450,944 -c--a-w c:\windows\system32\dllcache\wmvcore.dll + 2008-06-18 04:03:14 2,458,112 -c--a-w c:\windows\system32\dllcache\WMVCore.dll - 2008-04-14 02:33:23 357,888 ----a-w c:\windows\system32\dxtmsft.dll + 2008-10-16 20:18:31 347,136 ------w c:\windows\system32\dxtmsft.dll - 2008-04-14 02:33:23 205,312 ----a-w c:\windows\system32\dxtrans.dll + 2008-10-16 20:18:31 214,528 ------w c:\windows\system32\dxtrans.dll - 2008-04-14 02:33:24 55,808 ----a-w c:\windows\system32\extmgr.dll + 2008-10-16 20:18:31 133,120 ------w c:\windows\system32\extmgr.dll - 2008-10-15 13:06:21 183,424 ----a-w c:\windows\system32\FNTCACHE.DAT + 2008-12-01 17:15:37 183,424 ----a-w c:\windows\system32\FNTCACHE.DAT + 2008-10-16 20:18:32 63,488 ----a-w c:\windows\system32\icardie.dll - 2008-04-14 02:34:06 34,304 ----a-w c:\windows\system32\ie4uinit.exe + 2008-10-16 13:12:20 70,656 ------w c:\windows\system32\ie4uinit.exe - 2008-04-14 02:33:26 143,360 ----a-w c:\windows\system32\ieakeng.dll + 2008-10-16 20:18:32 153,088 ------w c:\windows\system32\ieakeng.dll - 2008-04-14 02:33:26 221,184 ----a-w c:\windows\system32\ieaksie.dll + 2008-10-16 20:18:32 230,400 ------w c:\windows\system32\ieaksie.dll - 2006-03-02 12:00:00 245,760 ----a-w c:\windows\system32\ieakui.dll + 2008-10-15 07:04:53 161,792 ------w c:\windows\system32\ieakui.dll + 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\system32\ieapfltr.dat + 2008-10-16 20:18:32 383,488 ----a-w c:\windows\system32\ieapfltr.dll - 2008-04-14 02:33:26 323,584 ----a-w c:\windows\system32\iedkcs32.dll + 2008-10-16 20:18:32 384,512 ------w c:\windows\system32\iedkcs32.dll + 2008-10-16 20:18:35 6,066,176 ----a-w c:\windows\system32\ieframe.dll - 2008-04-14 02:33:26 251,904 ----a-w c:\windows\system32\iepeers.dll + 2007-08-13 17:54:10 191,488 ----a-w c:\windows\system32\iepeers.dll - 2008-04-14 02:33:26 49,152 ----a-w c:\windows\system32\iernonce.dll + 2008-10-16 20:18:35 44,544 ------w c:\windows\system32\iernonce.dll + 2008-10-16 20:18:35 267,776 ----a-w c:\windows\system32\iertutil.dll - 2008-04-14 02:33:26 63,488 ----a-w c:\windows\system32\iesetup.dll + 2007-08-13 17:39:12 55,296 ----a-w c:\windows\system32\iesetup.dll - 2007-02-27 08:20:47 13,824 ----a-w c:\windows\system32\ieudinit.exe + 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe + 2007-08-13 17:54:10 180,736 ------w c:\windows\system32\ieui.dll - 2008-04-14 02:33:26 35,840 ----a-w c:\windows\system32\imgutil.dll + 2007-08-13 17:36:06 36,352 ----a-w c:\windows\system32\imgutil.dll - 2008-04-14 02:33:27 96,768 ----a-w c:\windows\system32\inseng.dll + 2007-08-13 17:39:02 92,672 ----a-w c:\windows\system32\inseng.dll - 2008-04-14 02:33:27 15,872 ----a-w c:\windows\system32\jsproxy.dll + 2008-10-16 20:18:36 27,648 ------w c:\windows\system32\jsproxy.dll - 2007-02-15 17:01:04 1,476,992 ----a-w c:\windows\system32\LegitCheckControl.dll + 2008-03-20 17:06:36 1,480,232 ----a-w c:\windows\system32\LegitCheckControl.dll - 2008-04-14 02:33:28 22,528 ----a-w c:\windows\system32\licmgr10.dll + 2007-08-13 17:44:18 40,960 ----a-w c:\windows\system32\licmgr10.dll - 2006-10-18 18:03:58 100,864 ----a-w c:\windows\system32\logagent.exe + 2008-06-18 00:09:22 100,864 ----a-w c:\windows\system32\logagent.exe + 2008-11-03 15:10:26 17,318,336 ----a-w c:\windows\system32\MRT.exe + 2008-10-16 20:18:37 459,264 ----a-w c:\windows\system32\msfeeds.dll + 2008-10-16 20:18:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll + 2007-08-13 17:36:40 12,288 ------w c:\windows\system32\msfeedssync.exe - 2008-04-14 02:34:12 29,184 ----a-w c:\windows\system32\mshta.exe + 2007-08-13 17:32:30 45,568 ----a-w c:\windows\system32\mshta.exe - 2008-08-20 05:10:12 3,088,896 ----a-w c:\windows\system32\mshtml.dll + 2008-10-17 00:48:40 3,593,216 ----a-w c:\windows\system32\mshtml.dll - 2008-04-14 02:33:31 449,024 ----a-w c:\windows\system32\mshtmled.dll + 2008-10-16 20:18:40 477,696 ------w c:\windows\system32\mshtmled.dll - 2008-04-14 01:56:24 57,344 ----a-w c:\windows\system32\mshtmler.dll + 2007-08-13 17:01:12 48,128 ----a-w c:\windows\system32\mshtmler.dll - 2006-03-02 12:00:00 146,432 ----a-w c:\windows\system32\msls31.dll + 2007-08-13 17:54:10 156,160 ----a-w c:\windows\system32\msls31.dll - 2008-04-14 02:33:32 146,432 ----a-w c:\windows\system32\msrating.dll + 2008-10-16 20:18:40 193,024 ------w c:\windows\system32\msrating.dll - 2008-04-14 02:33:33 532,480 ----a-w c:\windows\system32\mstime.dll + 2008-10-16 20:18:41 671,232 ------w c:\windows\system32\mstime.dll - 2008-04-14 02:33:38 97,280 ----a-w c:\windows\system32\occache.dll + 2008-10-16 20:18:41 102,912 ------w c:\windows\system32\occache.dll - 2008-04-14 02:33:38 39,424 ----a-w c:\windows\system32\pngfilt.dll + 2008-10-16 20:18:41 44,544 ------w c:\windows\system32\pngfilt.dll - 2008-07-08 13:03:54 18,296 ------w c:\windows\system32\spmsg.dll + 2007-11-30 11:19:06 18,296 ------w c:\windows\system32\spmsg.dll - 2008-04-14 02:34:25 60,416 ------w c:\windows\system32\tzchange.exe + 2008-10-23 10:06:59 62,976 ------w c:\windows\system32\tzchange.exe - 2008-04-14 02:33:48 37,888 ----a-w c:\windows\system32\url.dll + 2008-10-16 20:18:41 105,984 ----a-w c:\windows\system32\url.dll - 2008-08-20 05:10:11 620,544 ----a-w c:\windows\system32\urlmon.dll + 2008-10-16 20:18:42 1,160,192 ----a-w c:\windows\system32\urlmon.dll - 2008-04-14 02:33:48 281,600 ----a-w c:\windows\system32\webcheck.dll + 2008-10-16 20:18:42 233,472 ----a-w c:\windows\system32\webcheck.dll + 2007-08-13 17:45:16 206,336 ------w c:\windows\system32\WinFXDocObj.exe - 2006-10-18 19:47:20 937,984 ----a-w c:\windows\system32\WMNetMgr.dll + 2008-06-18 04:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll - 2006-10-18 19:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll + 2008-06-18 04:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll - 2008-11-28 20:32:22 53,248 ----a-w c:\windows\temp\catchme.dll + 2008-12-11 11:01:22 53,248 ----a-w c:\windows\temp\catchme.dll + 2006-12-01 21:56:00 96,256 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll + 2006-12-01 21:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll + 2006-12-01 21:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll + 2006-12-01 21:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll + 2006-12-01 23:25:52 1,101,824 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll + 2006-12-01 23:25:56 1,093,120 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll + 2006-12-01 23:25:58 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll + 2006-12-01 23:26:00 57,856 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll + 2006-12-01 23:08:00 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll + 2006-12-01 23:08:00 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll + 2006-12-01 23:08:00 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll + 2006-12-01 23:08:00 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll + 2006-12-01 23:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll + 2006-12-01 23:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll + 2006-12-01 23:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll + 2006-12-01 23:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll + 2006-12-01 23:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll + 2006-12-01 23:46:44 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll . -- Instantané actualisé -- . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HijackThis startup scan"="c:\docume~1\Arnaud\BUREAU\HijackThis.exe" [2008-12-08 401720] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] "DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WUAppSetup"="c:\program files\Fichiers communs\logishrd\WUApp32.exe" [2007-02-03 430080] c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\ Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-17 110592] RICOH Gate La.lnk - c:\program files\Caplio Software\RGateLXP.exe [2008-07-12 364544] Wireless Configuration Utility HW.51.lnk - c:\windows\Installer\{29F15D3F-5B37-44DB-BB89-390B3AD1404E}\NewShortcut1.exe [2007-03-16 40960] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3acm"= c:\windows\system32\l3codecp.acm "msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm "msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm "msacm.mpegacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "c:\\Program Files\\ESTsoft\\ALFTP\\ALFTP.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Download Express\\dep.exe"= "c:\\WINDOWS\\system32\\lxcrcoms.exe"= "c:\\Program Files\\Pando Networks\\Pando\\pando.exe"= "c:\\Program Files\\Caplio Software\\RGateLXP.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "58791:TCP"= 58791:TCP:Pando P2P TCP Listening Port "58791:UDP"= 58791:UDP:Pando P2P UDP Listening Port "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592] S3 XDva032;XDva032;\??\c:\windows\system32\XDva032.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a4d9871-d3d6-11db-ba20-b7da0c0d6f55}] \Shell\AutoRun\command - setup.exe . Contenu du dossier 'Tâches planifiées' 2008-12-11 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20] . . ------- Examen supplémentaire ------- . uStart Page = about:blank IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Télécharger en utilisant Download &Express - c:\program files\Download Express\Add_Url.htm Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll c:\windows\bdoscandellang.ini - c:\windows\bdoscandel.exe c:\windows\Downloaded Program Files\live.ini c:\windows\Downloaded Program Files\scanoptions.tsi c:\windows\Downloaded Program Files\lang.ini c:\windows\Downloaded Program Files\ipsupd.dll c:\windows\Downloaded Program Files\bdupd.dll c:\windows\Downloaded Program Files\libfn.dll c:\windows\Downloaded Program Files\bdcore.dll c:\windows\Downloaded Program Files\oscan8.ocx O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab c:\windows\Downloaded Program Files\oscan8.inf FireFox -: Profile - c:\docume~1\Arnaud\Application Data\Mozilla\Firefox\Profiles\73a94nep.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - FF -: plugin - c:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll FF -: plugin - c:\program files\DivX\DivX Web Player\npdivx32.dll FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava11.dll FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava12.dll FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava13.dll FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava14.dll FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava32.dll FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjpi160_07.dll FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npoji610.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdivx32.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npnul32.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPOFFICE.DLL FF -: plugin - c:\program files\Mozilla Firefox\plugins\nppdf32.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\nppl3260.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\nprjplug.dll FF -: plugin - c:\program files\Mozilla Firefox\plugins\nprpjplug.dll FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin.dll FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin2.dll FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin3.dll FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin4.dll FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin5.dll FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin6.dll FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin7.dll FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll FF -: plugin - c:\program files\Windows Media Player\npdrmv2.dll FF -: plugin - c:\program files\Windows Media Player\npdsplay.dll FF -: plugin - c:\program files\Windows Media Player\npwmsdrm.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-11 12:01:22 Windows 5.1.2600 Service Pack 3 NTFS Recherche de processus cachés ... Recherche d'éléments en démarrage automatique cachés ... Recherche de fichiers cachés ... Scan terminé avec succès Fichiers cachés: 0 ************************************************************************** . --------------------- DLLs chargées dans les processus actifs --------------------- - - - - - - - > 'winlogon.exe'(880) c:\windows\system32\MrvGINA.dll . Heure de fin: 2008-12-11 12:02:44 ComboFix-quarantined-files.txt 2008-12-11 11:01:45 Avant-CF: 23 084 789 760 octets libres Après-CF: 23,076,642,816 octets libres WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect 568 --- E O F --- 2008-12-10 22:32:19 Merci. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 11 décembre 2008 Partager Posté(e) le 11 décembre 2008 Encore des erreurs ? Lien vers le commentaire Partager sur d’autres sites More sharing options...
helluin Posté(e) le 11 décembre 2008 Auteur Partager Posté(e) le 11 décembre 2008 Ca n'a rien changé. La situation est la même. Lien vers le commentaire Partager sur d’autres sites More sharing options...
XZombi Posté(e) le 11 décembre 2008 Partager Posté(e) le 11 décembre 2008 As-tu essayé ça ? C'est pas très long à essayer. http://windowsxp.mvps.org/exefile.htm Lien vers le commentaire Partager sur d’autres sites More sharing options...
helluin Posté(e) le 11 décembre 2008 Auteur Partager Posté(e) le 11 décembre 2008 WHA HEY GURU ! Bon ben ça a marché. Tout est revenu dans l'ordre. J'en ai profité pour installer antivir. Merci beaucoup pour le coup de main. Arnaud Lien vers le commentaire Partager sur d’autres sites More sharing options...
XZombi Posté(e) le 11 décembre 2008 Partager Posté(e) le 11 décembre 2008 Fait plaisir ! Lien vers le commentaire Partager sur d’autres sites More sharing options...
Messages recommandés
Archivé
Ce sujet est désormais archivé et ne peut plus recevoir de nouvelles réponses.