Aller au contenu

[XP] [résolu] application win32 invalide


helluin

Messages recommandés

Bonjour,

J'ai un souci depuis quelques temps avec mon PC sous XP SP3.

Le lancement de toute application .exe génère un message d'erreur "application win32 invalide". Je pensais à un virus ou trojan mais ça ne semble pas être le cas (voir ici ce qu'il en était : http://www.pcentraide.com/index.php?showtopic=105410 )

Ce qui m'étonne c'est la ressemblance avec le cas évoqué par campif ici : http://www.pcinpact.com/forum/index.php?sh...83&hl=win32

Je veux bien suivre la procédure qu'il utilise mais je ne sais pas interpréter les résultats des scans.

Une bonne âme pour me prendre en main et revoir avec moi les possibilités de remise en route ?

Merci, Arnaud.

Lien vers le commentaire
Partager sur d’autres sites

salut.

voilà c'est fait, en mode sans échec.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:25:36, on 08/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Boot mode: Safe mode with network support

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ntvdm.exe

C:\WINDOWS\system32\cmd.exe

C:\DOCUME~1\Arnaud\BUREAU\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\DOCUME~1\Arnaud\Bureau\Spybot\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe

O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect

O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"

O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"

O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s

O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\OneTouch.exe

O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\Arnaud\BUREAU\HijackThis.exe /startupscan

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: RICOH Gate La.lnk = ?

O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = ?

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\DOCUME~1\Arnaud\Bureau\Spybot\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\DOCUME~1\Arnaud\Bureau\Spybot\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL

O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe

O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe

O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe

O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Arnaud/LOCALS~1/Temp/msohtml1/01/clip_image002.gif

--

End of file - 9301 bytes

Lien vers le commentaire
Partager sur d’autres sites

Salut ,

le rapport Hijackthis doit être créé en mode normal !

Désinstalle Spybot , Avast et autres joyeusetés ...

Lance Clean v2.0 , procédure 1 .

Redémarre le pc .

Lance une analyse complète avec MBAM , puis poste le rapport créé.

... vise ma signature pour les programmes à utiliser :D

Lien vers le commentaire
Partager sur d’autres sites

voilà désactivation, lancement du clean2.0 et lancement de mbam.

Le rapport de mbam :

Malwarebytes' Anti-Malware 1.31

Version de la base de données: 1478

Windows 5.1.2600 Service Pack 3

09/12/2008 21:08:38

mbam-log-2008-12-09 (21-08-31).txt

Type de recherche: Examen complet (C:\|D:\|)

Eléments examinés: 104383

Temps écoulé: 46 minute(s), 27 second(s)

Processus mémoire infecté(s): 0

Module(s) mémoire infecté(s): 0

Clé(s) du Registre infectée(s): 0

Valeur(s) du Registre infectée(s): 0

Elément(s) de données du Registre infecté(s): 0

Dossier(s) infecté(s): 0

Fichier(s) infecté(s): 1

Processus mémoire infecté(s):

(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):

(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):

(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):

(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):

(Aucun élément nuisible détecté)

Dossier(s) infecté(s):

(Aucun élément nuisible détecté)

Fichier(s) infecté(s):

C:\clean.cmd (Trojan.Agent) -> No action taken.

Le rapport hijackthis, refait après en mode normal pour info :

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:17:06, on 09/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\lxcrcoms.exe

C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\Explorer.EXE

C:\Program Files\Maxtor\Utils\SyncServices.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\ntvdm.exe

C:\WINDOWS\system32\cmd.exe

C:\DOCUME~1\Arnaud\BUREAU\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe

O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect

O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"

O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"

O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s

O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\OneTouch.exe

O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Documents and Settings\Arnaud\Bureau\malware\mbamgui.exe /install /silent

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\Arnaud\BUREAU\HijackThis.exe /startupscan

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 10.5.1.2023 (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: RICOH Gate La.lnk = ?

O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = ?

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Télécharger en utilisant Download &Express - C:\Program Files\Download Express\Add_Url.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL

O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe

O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe

O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe

O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O24 - Desktop Component 0: (no name) - (no file)

O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/Arnaud/LOCALS~1/Temp/msohtml1/01/clip_image002.gif

--

End of file - 9048 bytes

Voilà, merci de ton aide si tu comprends ce qui se passe.

Lien vers le commentaire
Partager sur d’autres sites

comment je désactive windows defender ?

Je n'ai pas accès aux options du panneaux de configuration, toujours le même message "pas une application win32 valide"

Pour contourner ce phénomène avec les autres programmes, je les lance depuis la fenêtre d'exécution en prenant soin de les installer sur le bureau (plus facile à retrouver) mais là, je bloque. Quelle ligne de commande taper à l'écran pour activer la désinstallation de windows defender ?

Lien vers le commentaire
Partager sur d’autres sites

ok, voilà le rapport fait par combofix :

ComboFix 08-12-09.03 - Arnaud 2008-12-11 12:00:42.2 - NTFSx86

Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1647 [GMT 1:00]

Lancé depuis: c:\docume~1\Arnaud\BUREAU\Cofix.exe

* Un nouveau point de restauration a été créé

.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\InfoSat.txt

c:\windows\system32\tmp.reg

.

((((((((((((((((((((((((((((( Fichiers créés du 2008-11-11 au 2008-12-11 ))))))))))))))))))))))))))))))))))))

.

2008-12-11 11:26 . 2008-12-11 11:57 <REP> d-------- C:\ComboFix

2008-12-09 19:38 . 2006-03-02 13:00 19,456 --a--c--- c:\windows\system32\dllcache\cprofile.exe

2008-12-09 19:38 . 2006-03-02 13:00 19,456 --a------ c:\windows\system32\cprofile.exe

2008-12-09 18:56 . 2008-12-02 12:35 254,604 --a------ C:\clean.cmd

2008-12-02 11:42 . 2008-12-02 11:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Maxtor

2008-12-02 11:39 . 2008-12-02 11:40 <REP> d-------- c:\progra~1\Maxtor

2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\progra~1\FICHIE~1\Crystal Decisions

2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\documents and settings\All Users\Application Data\InstallShield

2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\docume~1\Arnaud\Application Data\InstallShield

2008-12-02 11:39 . 2008-12-02 11:39 <REP> d-------- c:\docume~1\Arnaud\Application Data\InstallShield

2008-12-01 18:23 . 2008-12-01 18:24 0 --a------ c:\documents and settings\SFC

2008-12-01 16:14 . 2008-12-01 16:19 <REP> d-------- c:\windows\BDOSCAN8

2008-12-01 15:59 . 2008-12-10 23:31 1,393 --a------ c:\windows\imsins.BAK

2008-12-01 15:54 . 2008-10-16 21:18 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll

2008-11-29 15:10 . 2008-11-29 15:10 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2008-11-29 15:10 . 2008-11-29 15:10 <REP> d-------- c:\docume~1\Arnaud\Application Data\Malwarebytes

2008-11-29 15:10 . 2008-11-29 15:10 <REP> d-------- c:\docume~1\Arnaud\Application Data\Malwarebytes

2008-11-29 15:10 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-11-29 15:10 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-11-28 23:13 . 2008-11-29 00:18 <REP> d-------- c:\progra~1\FindyKill

2008-11-28 21:29 . 2008-11-28 21:33 <REP> d-------- C:\Co-Fix

2008-11-25 20:35 . 2008-12-08 23:27 664 --a------ c:\windows\system32\d3d9caps.dat

2008-11-25 20:25 . 2008-11-25 20:27 <REP> d-------- C:\copie de sauvegarde déplantage

2008-11-25 19:42 . 2008-11-25 19:42 <REP> d-------- C:\SmitfraudFix

2008-11-22 11:06 . 2008-11-22 13:42 <REP> d-------- c:\documents and settings\Arnaud\.housecall6.6

2008-11-12 20:13 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-11-12 20:12 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-11 11:01 --------- d-----w c:\progra~1\Fichiers communs

2008-12-11 10:46 0 ----a-w c:\windows\system32\drivers\lvuvc.hs

2008-12-09 18:37 --------- d-----w c:\progra~1\Lexmark 2400 Series

2008-12-09 18:37 --------- d-----w c:\docume~1\Arnaud\Application Data\Skype

2008-12-09 18:37 --------- d-----w c:\docume~1\Arnaud\Application Data\Skype

2008-12-09 17:02 --------- d-----w c:\progra~1\Alwil Software

2008-12-09 11:05 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2008-12-08 21:15 --------- d-----w c:\progra~1\lx_cats

2008-12-02 10:40 --------- d--h--w c:\progra~1\InstallShield Installation Information

2008-11-28 21:31 --------- d-----w c:\progra~1\Spybot - Search & Destroy

2008-11-21 14:29 --------- d-----w c:\docume~1\Arnaud\Application Data\skypePM

2008-11-21 14:29 --------- d-----w c:\docume~1\Arnaud\Application Data\skypePM

2008-11-08 12:27 --------- d-----w c:\progra~1\VersalSoft

2008-11-08 12:27 --------- d-----w c:\progra~1\Universal

2008-11-08 12:25 --------- d-----w c:\progra~1\CesarFTP

2008-11-07 11:26 --------- d-----w c:\progra~1\FICHIE~1\Adobe

2008-11-04 17:40 --------- d-----w c:\progra~1\CDBurnerXP Pro 3

2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll

2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll

2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll

2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll

2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys

2008-04-08 13:08 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat

2007-03-17 12:03 24,192 ----a-w c:\documents and settings\Arnaud\usbsermptxp.sys

2007-03-17 12:03 22,768 ----a-w c:\documents and settings\Arnaud\usbsermpt.sys

2006-02-23 13:52 280,576 ----a-w c:\windows\inf\TEW-421PC\MRV8335XP.sys

2006-02-23 13:52 280,576 ----a-w c:\windows\inf\TEW-421PC\MRV8335.sys

2006-02-23 13:52 212,992 ----a-w c:\windows\inf\TEW-421PC\CopyWHQLDriver.exe

2001-03-28 10:02 122,880 ----a-w c:\windows\inf\Agfa\message.exe

.

((((((((((((((((((((((((((((( snapshot@2008-11-28_21.32.32,04 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-12-01 15:16:36 45,056 ----a-w c:\windows\BDOSCAN8\avxdisk.dll

+ 2008-12-01 15:16:36 10,240 ----a-w c:\windows\BDOSCAN8\avxs.dll

+ 2008-12-01 15:16:36 27,136 ----a-w c:\windows\BDOSCAN8\avxt.dll

+ 2008-12-01 15:16:38 102,400 ----a-w c:\windows\BDOSCAN8\bdcore.dll

+ 2006-05-25 00:21:00 118,784 ----a-w c:\windows\BDOSCAN8\bdupd.dll

+ 2006-05-25 00:21:14 53,248 ----a-w c:\windows\BDOSCAN8\ipsupd.dll

+ 2008-12-01 15:16:38 142,848 ----a-w c:\windows\BDOSCAN8\libfn.dll

+ 2008-12-01 15:16:36 86,016 ----a-w c:\windows\BDOSCAN8\librtvr.dll

+ 2006-05-25 00:22:06 53,248 ----a-w c:\windows\bdoscandel.exe

+ 2008-04-14 02:33:18 61,440 -c----w c:\windows\ie7\admparse.dll

+ 2008-04-14 02:33:18 101,888 -c----w c:\windows\ie7\advpack.dll

+ 2006-06-02 19:32:20 33,792 -c----w c:\windows\ie7\custsat.dll

+ 2008-04-14 02:33:23 357,888 -c----w c:\windows\ie7\dxtmsft.dll

+ 2008-04-14 02:33:23 205,312 -c----w c:\windows\ie7\dxtrans.dll

+ 2008-04-14 02:33:24 55,808 -c----w c:\windows\ie7\extmgr.dll

+ 2008-04-14 02:33:26 38,912 -c----w c:\windows\ie7\hmmapi.dll

+ 2008-04-14 02:34:06 34,304 -c----w c:\windows\ie7\ie4uinit.exe

+ 2008-04-14 02:33:26 143,360 -c----w c:\windows\ie7\ieakeng.dll

+ 2008-04-14 02:33:26 221,184 -c----w c:\windows\ie7\ieaksie.dll

+ 2006-03-02 12:00:00 245,760 -c----w c:\windows\ie7\ieakui.dll

+ 2008-04-14 02:33:26 323,584 -c----w c:\windows\ie7\iedkcs32.dll

+ 2008-04-14 02:34:06 18,432 -c----w c:\windows\ie7\iedw.exe

+ 2008-04-14 02:33:26 251,904 -c----w c:\windows\ie7\iepeers.dll

+ 2008-04-14 02:33:26 49,152 -c----w c:\windows\ie7\iernonce.dll

+ 2008-04-14 02:33:26 63,488 -c----w c:\windows\ie7\iesetup.dll

+ 2008-04-14 02:34:06 93,184 -c----w c:\windows\ie7\iexplore.exe

+ 2008-04-14 02:33:26 35,840 -c----w c:\windows\ie7\imgutil.dll

+ 2008-04-14 02:33:27 96,768 -c----w c:\windows\ie7\inseng.dll

+ 2008-04-14 02:33:27 15,872 -c----w c:\windows\ie7\jsproxy.dll

+ 2008-04-14 02:33:28 22,528 -c----w c:\windows\ie7\licmgr10.dll

+ 2008-04-14 02:34:12 29,184 -c----w c:\windows\ie7\mshta.exe

+ 2008-08-20 05:10:12 3,088,896 -c----w c:\windows\ie7\mshtml.dll

+ 2008-04-14 02:33:31 449,024 -c----w c:\windows\ie7\mshtmled.dll

+ 2008-04-14 01:56:24 57,344 -c----w c:\windows\ie7\mshtmler.dll

+ 2006-03-02 12:00:00 146,432 -c----w c:\windows\ie7\msls31.dll

+ 2008-04-14 02:33:32 146,432 -c----w c:\windows\ie7\msrating.dll

+ 2008-04-14 02:33:33 532,480 -c----w c:\windows\ie7\mstime.dll

+ 2008-04-14 02:33:38 97,280 -c----w c:\windows\ie7\occache.dll

+ 2008-04-14 02:33:38 39,424 -c----w c:\windows\ie7\pngfilt.dll

+ 2007-09-26 17:34:42 33,472 -c----w c:\windows\ie7\spuninst\iecustom.dll

+ 2007-09-26 17:32:30 66,048 -c--a-w c:\windows\ie7\spuninst\ieResetIcons.exe

+ 2006-09-06 16:43:28 216,800 -c----w c:\windows\ie7\spuninst\spuninst.exe

+ 2006-09-06 16:43:30 394,976 -c----w c:\windows\ie7\spuninst\updspapi.dll

+ 2008-04-14 02:33:48 37,888 -c----w c:\windows\ie7\url.dll

+ 2008-08-20 05:10:11 620,544 -c----w c:\windows\ie7\urlmon.dll

+ 2008-04-14 02:33:48 851,968 -c----w c:\windows\ie7\vgx.dll

+ 2008-04-14 02:33:48 281,600 -c----w c:\windows\ie7\webcheck.dll

+ 2008-08-20 05:10:11 670,208 -c----w c:\windows\ie7\wininet.dll

+ 2007-03-06 01:34:38 216,800 -c----w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe

+ 2007-03-06 01:35:47 394,976 -c----w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll

+ 2007-08-13 17:54:10 765,952 -c----w c:\windows\ie7updates\KB938127-v2-IE7\vgx.dll

+ 2007-08-13 17:39:00 123,904 -c----w c:\windows\ie7updates\KB956390-IE7\advpack.dll

+ 2007-08-13 17:39:00 123,904 -c----w c:\windows\ie7updates\KB956390-IE7\advpack.dll.000

+ 2007-08-13 17:35:46 346,624 -c----w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll

+ 2007-08-13 17:35:46 346,624 -c----w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll.000

+ 2007-08-13 17:35:38 214,528 -c----w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll

+ 2007-08-13 17:35:38 214,528 -c----w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll.000

+ 2007-08-13 17:54:10 131,584 -c----w c:\windows\ie7updates\KB956390-IE7\extmgr.dll

+ 2007-08-13 17:54:10 131,584 -c----w c:\windows\ie7updates\KB956390-IE7\extmgr.dll.000

+ 2007-08-13 17:36:26 61,952 -c----w c:\windows\ie7updates\KB956390-IE7\icardie.dll

+ 2007-08-13 17:39:06 54,784 -c----w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe

+ 2007-08-13 17:39:06 54,784 -c----w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe.000

+ 2007-08-13 17:39:26 152,064 -c----w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll

+ 2007-08-13 17:39:26 152,064 -c----w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll.000

+ 2007-08-13 17:39:54 229,376 -c----w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll

+ 2007-08-13 17:39:54 229,376 -c----w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll.000

+ 2007-08-13 16:56:54 161,792 -c----w c:\windows\ie7updates\KB956390-IE7\ieakui.dll

+ 2007-02-12 15:10:12 2,451,312 -c----w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dat

+ 2007-07-11 11:27:48 383,488 -c----w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dll

+ 2007-08-13 17:39:50 382,976 -c----w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll

+ 2007-08-13 17:39:50 382,976 -c----w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll.000

+ 2007-08-13 17:54:10 6,049,280 -c----w c:\windows\ie7updates\KB956390-IE7\ieframe.dll

+ 2007-08-13 17:39:10 43,008 -c----w c:\windows\ie7updates\KB956390-IE7\iernonce.dll

+ 2007-08-13 17:39:10 43,008 -c----w c:\windows\ie7updates\KB956390-IE7\iernonce.dll.000

+ 2007-08-13 17:34:04 266,752 -c----w c:\windows\ie7updates\KB956390-IE7\iertutil.dll

+ 2007-08-13 17:39:10 13,312 -c----w c:\windows\ie7updates\KB956390-IE7\ieudinit.exe

+ 2007-08-13 17:54:10 27,136 -c----w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll

+ 2007-08-13 17:54:10 27,136 -c----w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll.000

+ 2007-08-13 17:54:10 458,752 -c----w c:\windows\ie7updates\KB956390-IE7\msfeeds.dll

+ 2007-08-13 17:54:10 50,688 -c----w c:\windows\ie7updates\KB956390-IE7\msfeedsbs.dll

+ 2007-08-13 17:54:12 3,578,368 -c----w c:\windows\ie7updates\KB956390-IE7\mshtml.dll

+ 2007-08-13 17:54:10 475,648 -c----w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll

+ 2007-08-13 17:54:10 475,648 -c----w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll.000

+ 2007-08-13 17:44:26 192,000 -c----w c:\windows\ie7updates\KB956390-IE7\msrating.dll

+ 2007-08-13 17:44:26 192,000 -c----w c:\windows\ie7updates\KB956390-IE7\msrating.dll.000

+ 2007-08-13 17:54:10 670,720 -c----w c:\windows\ie7updates\KB956390-IE7\mstime.dll

+ 2007-08-13 17:54:10 670,720 -c----w c:\windows\ie7updates\KB956390-IE7\mstime.dll.000

+ 2007-08-13 17:44:06 101,376 -c----w c:\windows\ie7updates\KB956390-IE7\occache.dll

+ 2007-08-13 17:44:06 101,376 -c----w c:\windows\ie7updates\KB956390-IE7\occache.dll.000

+ 2007-08-13 17:36:12 44,544 -c----w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll

+ 2007-08-13 17:36:12 44,544 -c----w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll.000

+ 2007-03-06 01:34:38 216,800 -c----w c:\windows\ie7updates\KB956390-IE7\spuninst\spuninst.exe

+ 2007-03-06 01:35:48 394,976 -c----w c:\windows\ie7updates\KB956390-IE7\spuninst\updspapi.dll

+ 2007-08-13 17:44:30 105,984 -c----w c:\windows\ie7updates\KB956390-IE7\url.dll

+ 2007-08-13 17:44:30 105,984 -c----w c:\windows\ie7updates\KB956390-IE7\url.dll.000

+ 2007-08-13 17:54:10 1,162,240 -c----w c:\windows\ie7updates\KB956390-IE7\urlmon.dll

+ 2007-08-13 17:54:10 231,424 -c----w c:\windows\ie7updates\KB956390-IE7\webcheck.dll

+ 2007-08-13 17:54:10 231,424 -c----w c:\windows\ie7updates\KB956390-IE7\webcheck.dll.000

+ 2007-08-13 17:54:10 818,688 -c----w c:\windows\ie7updates\KB956390-IE7\wininet.dll

+ 2008-08-26 08:11:45 124,928 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll

+ 2008-08-26 08:11:45 347,136 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll

+ 2008-08-26 08:11:45 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll

+ 2008-08-26 08:11:45 133,120 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll

+ 2008-08-26 08:11:45 63,488 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll

+ 2008-08-25 08:39:40 70,656 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe

+ 2008-08-26 08:11:45 153,088 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll

+ 2008-08-26 08:11:45 230,400 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll

+ 2008-08-23 05:54:51 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll

+ 2008-08-26 08:11:46 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll

+ 2008-08-26 08:11:46 384,512 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll

+ 2008-10-03 17:12:27 6,066,176 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll

+ 2008-08-26 08:11:48 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll

+ 2008-08-26 08:11:48 267,776 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll

+ 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe

+ 2008-08-23 05:56:15 635,848 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe

+ 2008-08-26 08:11:49 27,648 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll

+ 2008-08-26 08:11:49 459,264 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll

+ 2008-08-26 08:11:49 52,224 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll

+ 2008-08-27 13:41:52 3,593,216 -c----w c:\windows\ie7updates\KB958215-IE7\mshtml.dll

+ 2008-08-26 08:11:52 477,696 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll

+ 2008-08-26 08:11:52 193,024 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll

+ 2008-08-26 08:11:52 671,232 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll

+ 2008-08-26 08:11:52 102,912 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll

+ 2008-08-26 08:11:52 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll

+ 2007-03-06 01:34:38 216,800 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe

+ 2007-03-06 01:35:48 394,976 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll

+ 2008-08-26 08:11:52 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll

+ 2008-08-26 08:11:53 1,159,680 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll

+ 2008-08-26 08:11:53 233,472 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll

+ 2008-08-26 08:11:54 826,368 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll

- 2008-11-12 22:25:32 593,920 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe

+ 2008-12-10 22:32:08 593,920 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe

- 2008-11-12 22:25:32 12,288 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe

+ 2008-12-10 22:32:08 12,288 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe

- 2008-11-12 22:25:32 86,016 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe

+ 2008-12-10 22:32:08 86,016 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe

- 2008-11-12 22:25:32 135,168 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe

+ 2008-12-10 22:32:08 135,168 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe

- 2008-11-12 22:25:32 11,264 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe

+ 2008-12-10 22:32:08 11,264 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe

- 2008-11-12 22:25:32 27,136 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe

+ 2008-12-10 22:32:08 27,136 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe

- 2008-11-12 22:25:33 4,096 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe

+ 2008-12-10 22:32:08 4,096 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe

- 2008-11-12 22:25:33 794,624 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe

+ 2008-12-10 22:32:08 794,624 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe

- 2008-11-12 22:25:32 249,856 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe

+ 2008-12-10 22:32:08 249,856 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe

- 2008-11-12 22:25:32 61,440 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe

+ 2008-12-10 22:32:08 61,440 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe

- 2008-11-12 22:25:33 23,040 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe

+ 2008-12-10 22:32:08 23,040 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe

- 2008-11-12 22:25:32 286,720 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe

+ 2008-12-10 22:32:08 286,720 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe

- 2008-11-12 22:25:32 409,600 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe

+ 2008-12-10 22:32:08 409,600 ----a-r c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe

+ 2008-12-02 10:40:44 45,056 ----a-r c:\windows\Installer\{9C3F9580-F5CF-4288-894E-9FF0EB24A21C}\NewShortcut2_9C3F9580F5CF4288894E9FF0EB24A21C.exe

+ 2008-12-02 10:39:54 65,536 ----a-r c:\windows\Installer\{FF268652-B3E8-494F-8343-1FC6DD0FF523}\NewShortcut2_60EEB642E9E045A2A676B9D8FE17C4A9.exe

+ 2008-12-02 10:39:54 65,536 ----a-r c:\windows\Installer\{FF268652-B3E8-494F-8343-1FC6DD0FF523}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe

- 2008-04-14 02:33:18 61,440 ----a-w c:\windows\system32\admparse.dll

+ 2007-08-13 17:39:20 71,680 ----a-w c:\windows\system32\admparse.dll

- 2008-04-14 02:33:18 101,888 ----a-w c:\windows\system32\advpack.dll

+ 2008-10-16 20:18:31 124,928 ----a-w c:\windows\system32\advpack.dll

- 2007-03-17 10:37:37 262,144 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat

+ 2008-12-09 18:38:48 8,192 ----a-w c:\windows\system32\config\systemprofile\ntuser.dat

+ 2007-08-13 17:39:20 71,680 -c----w c:\windows\system32\dllcache\admparse.dll

+ 2008-10-16 20:18:31 124,928 -c----w c:\windows\system32\dllcache\advpack.dll

+ 2006-09-23 12:12:56 1,022,976 -c----w c:\windows\system32\dllcache\browseui.dll

+ 2007-08-13 17:42:54 17,408 -c----w c:\windows\system32\dllcache\corpol.dll

- 2006-06-02 19:32:20 33,792 -c--a-w c:\windows\system32\dllcache\custsat.dll

+ 2007-08-13 17:54:10 33,792 -c--a-w c:\windows\system32\dllcache\custsat.dll

+ 2008-10-16 20:18:31 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll

+ 2008-10-16 20:18:31 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll

+ 2008-10-16 20:18:31 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll

+ 2008-10-23 12:36:51 286,720 -c----w c:\windows\system32\dllcache\gdi32.dll

+ 2007-08-13 17:18:02 60,416 -c----w c:\windows\system32\dllcache\hmmapi.dll

+ 2008-10-16 13:12:20 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe

+ 2008-10-16 20:18:32 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll

+ 2008-10-16 20:18:32 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll

- 2006-03-02 12:00:00 245,760 -c--a-w c:\windows\system32\dllcache\ieakui.dll

+ 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll

- 2007-04-03 04:36:20 2,453,952 -c----w c:\windows\system32\dllcache\ieapfltr.dat

+ 2007-04-17 09:32:38 2,455,488 -c----w c:\windows\system32\dllcache\ieapfltr.dat

- 2007-04-03 14:29:23 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll

+ 2008-10-16 20:18:32 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll

+ 2008-10-16 20:18:32 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll

+ 2007-08-13 17:44:02 69,120 -c----w c:\windows\system32\dllcache\iedw.exe

+ 2007-08-13 17:45:18 78,336 -c----w c:\windows\system32\dllcache\ieencode.dll

- 2007-02-27 13:25:31 6,054,400 -c----w c:\windows\system32\dllcache\ieframe.dll

+ 2008-10-16 20:18:35 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll

+ 2007-08-13 17:54:10 191,488 -c----w c:\windows\system32\dllcache\iepeers.dll

+ 2008-10-16 20:18:35 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll

- 2007-02-27 13:25:34 266,752 -c----w c:\windows\system32\dllcache\iertutil.dll

+ 2008-10-16 20:18:35 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll

+ 2007-08-13 17:39:12 55,296 -c----w c:\windows\system32\dllcache\iesetup.dll

- 2007-02-27 08:20:47 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe

+ 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe

+ 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe

+ 2007-08-13 17:36:06 36,352 -c----w c:\windows\system32\dllcache\imgutil.dll

+ 2007-08-13 17:39:02 92,672 -c----w c:\windows\system32\dllcache\inseng.dll

+ 2008-10-16 20:18:36 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll

+ 2007-08-13 17:44:18 40,960 -c----w c:\windows\system32\dllcache\licmgr10.dll

- 2006-10-18 18:03:58 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe

+ 2008-06-18 00:09:22 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe

- 2007-02-27 13:25:46 458,752 -c----w c:\windows\system32\dllcache\msfeeds.dll

+ 2008-10-16 20:18:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll

- 2007-02-27 13:25:46 51,712 -c----w c:\windows\system32\dllcache\msfeedsbs.dll

+ 2008-10-16 20:18:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll

+ 2007-08-13 17:32:30 45,568 -c----w c:\windows\system32\dllcache\mshta.exe

- 2008-08-20 05:10:12 3,088,896 -c----w c:\windows\system32\dllcache\mshtml.dll

+ 2008-10-17 00:48:40 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll

+ 2008-10-16 20:18:40 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll

+ 2007-08-13 17:01:12 48,128 -c----w c:\windows\system32\dllcache\mshtmler.dll

- 2006-03-02 12:00:00 146,432 -c--a-w c:\windows\system32\dllcache\msls31.dll

+ 2007-08-13 17:54:10 156,160 -c--a-w c:\windows\system32\dllcache\msls31.dll

+ 2008-10-16 20:18:40 193,024 -c----w c:\windows\system32\dllcache\msrating.dll

+ 2008-10-16 20:18:41 671,232 -c----w c:\windows\system32\dllcache\mstime.dll

+ 2008-10-16 20:18:41 102,912 -c----w c:\windows\system32\dllcache\occache.dll

+ 2008-10-16 20:18:41 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll

+ 2008-04-14 02:34:19 153,088 -c--a-w c:\windows\system32\dllcache\regedit.exe

+ 2006-09-23 12:12:56 474,624 -c----w c:\windows\system32\dllcache\shlwapi.dll

- 2008-04-14 02:33:46 246,814 -c--a-w c:\windows\system32\dllcache\strmdll.dll

+ 2008-10-03 10:03:53 247,326 -c--a-w c:\windows\system32\dllcache\strmdll.dll

+ 2008-04-14 02:34:25 347,136 -c--a-w c:\windows\system32\dllcache\tourstrt.exe

+ 2008-10-16 20:18:41 105,984 -c----w c:\windows\system32\dllcache\url.dll

- 2008-08-20 05:10:11 620,544 -c----w c:\windows\system32\dllcache\urlmon.dll

+ 2008-10-16 20:18:42 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll

+ 2008-05-27 17:25:06 765,952 -c----w c:\windows\system32\dllcache\vgx.dll

+ 2008-10-16 20:18:42 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll

- 2008-08-20 05:10:11 670,208 -c----w c:\windows\system32\dllcache\wininet.dll

+ 2008-10-16 20:18:43 826,368 -c----w c:\windows\system32\dllcache\wininet.dll

- 2006-10-18 19:47:20 937,984 -c--a-w c:\windows\system32\dllcache\WMNetMgr.dll

+ 2008-06-18 04:03:08 938,496 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll

- 2006-10-18 19:47:22 2,450,944 -c--a-w c:\windows\system32\dllcache\wmvcore.dll

+ 2008-06-18 04:03:14 2,458,112 -c--a-w c:\windows\system32\dllcache\WMVCore.dll

- 2008-04-14 02:33:23 357,888 ----a-w c:\windows\system32\dxtmsft.dll

+ 2008-10-16 20:18:31 347,136 ------w c:\windows\system32\dxtmsft.dll

- 2008-04-14 02:33:23 205,312 ----a-w c:\windows\system32\dxtrans.dll

+ 2008-10-16 20:18:31 214,528 ------w c:\windows\system32\dxtrans.dll

- 2008-04-14 02:33:24 55,808 ----a-w c:\windows\system32\extmgr.dll

+ 2008-10-16 20:18:31 133,120 ------w c:\windows\system32\extmgr.dll

- 2008-10-15 13:06:21 183,424 ----a-w c:\windows\system32\FNTCACHE.DAT

+ 2008-12-01 17:15:37 183,424 ----a-w c:\windows\system32\FNTCACHE.DAT

+ 2008-10-16 20:18:32 63,488 ----a-w c:\windows\system32\icardie.dll

- 2008-04-14 02:34:06 34,304 ----a-w c:\windows\system32\ie4uinit.exe

+ 2008-10-16 13:12:20 70,656 ------w c:\windows\system32\ie4uinit.exe

- 2008-04-14 02:33:26 143,360 ----a-w c:\windows\system32\ieakeng.dll

+ 2008-10-16 20:18:32 153,088 ------w c:\windows\system32\ieakeng.dll

- 2008-04-14 02:33:26 221,184 ----a-w c:\windows\system32\ieaksie.dll

+ 2008-10-16 20:18:32 230,400 ------w c:\windows\system32\ieaksie.dll

- 2006-03-02 12:00:00 245,760 ----a-w c:\windows\system32\ieakui.dll

+ 2008-10-15 07:04:53 161,792 ------w c:\windows\system32\ieakui.dll

+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\system32\ieapfltr.dat

+ 2008-10-16 20:18:32 383,488 ----a-w c:\windows\system32\ieapfltr.dll

- 2008-04-14 02:33:26 323,584 ----a-w c:\windows\system32\iedkcs32.dll

+ 2008-10-16 20:18:32 384,512 ------w c:\windows\system32\iedkcs32.dll

+ 2008-10-16 20:18:35 6,066,176 ----a-w c:\windows\system32\ieframe.dll

- 2008-04-14 02:33:26 251,904 ----a-w c:\windows\system32\iepeers.dll

+ 2007-08-13 17:54:10 191,488 ----a-w c:\windows\system32\iepeers.dll

- 2008-04-14 02:33:26 49,152 ----a-w c:\windows\system32\iernonce.dll

+ 2008-10-16 20:18:35 44,544 ------w c:\windows\system32\iernonce.dll

+ 2008-10-16 20:18:35 267,776 ----a-w c:\windows\system32\iertutil.dll

- 2008-04-14 02:33:26 63,488 ----a-w c:\windows\system32\iesetup.dll

+ 2007-08-13 17:39:12 55,296 ----a-w c:\windows\system32\iesetup.dll

- 2007-02-27 08:20:47 13,824 ----a-w c:\windows\system32\ieudinit.exe

+ 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe

+ 2007-08-13 17:54:10 180,736 ------w c:\windows\system32\ieui.dll

- 2008-04-14 02:33:26 35,840 ----a-w c:\windows\system32\imgutil.dll

+ 2007-08-13 17:36:06 36,352 ----a-w c:\windows\system32\imgutil.dll

- 2008-04-14 02:33:27 96,768 ----a-w c:\windows\system32\inseng.dll

+ 2007-08-13 17:39:02 92,672 ----a-w c:\windows\system32\inseng.dll

- 2008-04-14 02:33:27 15,872 ----a-w c:\windows\system32\jsproxy.dll

+ 2008-10-16 20:18:36 27,648 ------w c:\windows\system32\jsproxy.dll

- 2007-02-15 17:01:04 1,476,992 ----a-w c:\windows\system32\LegitCheckControl.dll

+ 2008-03-20 17:06:36 1,480,232 ----a-w c:\windows\system32\LegitCheckControl.dll

- 2008-04-14 02:33:28 22,528 ----a-w c:\windows\system32\licmgr10.dll

+ 2007-08-13 17:44:18 40,960 ----a-w c:\windows\system32\licmgr10.dll

- 2006-10-18 18:03:58 100,864 ----a-w c:\windows\system32\logagent.exe

+ 2008-06-18 00:09:22 100,864 ----a-w c:\windows\system32\logagent.exe

+ 2008-11-03 15:10:26 17,318,336 ----a-w c:\windows\system32\MRT.exe

+ 2008-10-16 20:18:37 459,264 ----a-w c:\windows\system32\msfeeds.dll

+ 2008-10-16 20:18:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll

+ 2007-08-13 17:36:40 12,288 ------w c:\windows\system32\msfeedssync.exe

- 2008-04-14 02:34:12 29,184 ----a-w c:\windows\system32\mshta.exe

+ 2007-08-13 17:32:30 45,568 ----a-w c:\windows\system32\mshta.exe

- 2008-08-20 05:10:12 3,088,896 ----a-w c:\windows\system32\mshtml.dll

+ 2008-10-17 00:48:40 3,593,216 ----a-w c:\windows\system32\mshtml.dll

- 2008-04-14 02:33:31 449,024 ----a-w c:\windows\system32\mshtmled.dll

+ 2008-10-16 20:18:40 477,696 ------w c:\windows\system32\mshtmled.dll

- 2008-04-14 01:56:24 57,344 ----a-w c:\windows\system32\mshtmler.dll

+ 2007-08-13 17:01:12 48,128 ----a-w c:\windows\system32\mshtmler.dll

- 2006-03-02 12:00:00 146,432 ----a-w c:\windows\system32\msls31.dll

+ 2007-08-13 17:54:10 156,160 ----a-w c:\windows\system32\msls31.dll

- 2008-04-14 02:33:32 146,432 ----a-w c:\windows\system32\msrating.dll

+ 2008-10-16 20:18:40 193,024 ------w c:\windows\system32\msrating.dll

- 2008-04-14 02:33:33 532,480 ----a-w c:\windows\system32\mstime.dll

+ 2008-10-16 20:18:41 671,232 ------w c:\windows\system32\mstime.dll

- 2008-04-14 02:33:38 97,280 ----a-w c:\windows\system32\occache.dll

+ 2008-10-16 20:18:41 102,912 ------w c:\windows\system32\occache.dll

- 2008-04-14 02:33:38 39,424 ----a-w c:\windows\system32\pngfilt.dll

+ 2008-10-16 20:18:41 44,544 ------w c:\windows\system32\pngfilt.dll

- 2008-07-08 13:03:54 18,296 ------w c:\windows\system32\spmsg.dll

+ 2007-11-30 11:19:06 18,296 ------w c:\windows\system32\spmsg.dll

- 2008-04-14 02:34:25 60,416 ------w c:\windows\system32\tzchange.exe

+ 2008-10-23 10:06:59 62,976 ------w c:\windows\system32\tzchange.exe

- 2008-04-14 02:33:48 37,888 ----a-w c:\windows\system32\url.dll

+ 2008-10-16 20:18:41 105,984 ----a-w c:\windows\system32\url.dll

- 2008-08-20 05:10:11 620,544 ----a-w c:\windows\system32\urlmon.dll

+ 2008-10-16 20:18:42 1,160,192 ----a-w c:\windows\system32\urlmon.dll

- 2008-04-14 02:33:48 281,600 ----a-w c:\windows\system32\webcheck.dll

+ 2008-10-16 20:18:42 233,472 ----a-w c:\windows\system32\webcheck.dll

+ 2007-08-13 17:45:16 206,336 ------w c:\windows\system32\WinFXDocObj.exe

- 2006-10-18 19:47:20 937,984 ----a-w c:\windows\system32\WMNetMgr.dll

+ 2008-06-18 04:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll

- 2006-10-18 19:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll

+ 2008-06-18 04:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll

- 2008-11-28 20:32:22 53,248 ----a-w c:\windows\temp\catchme.dll

+ 2008-12-11 11:01:22 53,248 ----a-w c:\windows\temp\catchme.dll

+ 2006-12-01 21:56:00 96,256 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll

+ 2006-12-01 21:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll

+ 2006-12-01 21:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll

+ 2006-12-01 21:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll

+ 2006-12-01 23:25:52 1,101,824 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll

+ 2006-12-01 23:25:56 1,093,120 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll

+ 2006-12-01 23:25:58 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll

+ 2006-12-01 23:26:00 57,856 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll

+ 2006-12-01 23:08:00 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll

+ 2006-12-01 23:08:00 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll

+ 2006-12-01 23:08:00 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll

+ 2006-12-01 23:08:00 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll

+ 2006-12-01 23:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll

+ 2006-12-01 23:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll

+ 2006-12-01 23:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll

+ 2006-12-01 23:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll

+ 2006-12-01 23:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll

+ 2006-12-01 23:46:44 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll

.

-- Instantané actualisé --

.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HijackThis startup scan"="c:\docume~1\Arnaud\BUREAU\HijackThis.exe" [2008-12-08 401720]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"WUAppSetup"="c:\program files\Fichiers communs\logishrd\WUApp32.exe" [2007-02-03 430080]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-17 110592]

RICOH Gate La.lnk - c:\program files\Caplio Software\RGateLXP.exe [2008-07-12 364544]

Wireless Configuration Utility HW.51.lnk - c:\windows\Installer\{29F15D3F-5B37-44DB-BB89-390B3AD1404E}\NewShortcut1.exe [2007-03-16 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.l3acm"= c:\windows\system32\l3codecp.acm

"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm

"msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm

"msacm.mpegacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

"c:\\Program Files\\ESTsoft\\ALFTP\\ALFTP.exe"=

"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Download Express\\dep.exe"=

"c:\\WINDOWS\\system32\\lxcrcoms.exe"=

"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=

"c:\\Program Files\\Caplio Software\\RGateLXP.exe"=

"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager

"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager

"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"58791:TCP"= 58791:TCP:Pando P2P TCP Listening Port

"58791:UDP"= 58791:UDP:Pando P2P UDP Listening Port

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]

S3 XDva032;XDva032;\??\c:\windows\system32\XDva032.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a4d9871-d3d6-11db-ba20-b7da0c0d6f55}]

\Shell\AutoRun\command - setup.exe

.

Contenu du dossier 'Tâches planifiées'

2008-12-11 c:\windows\Tasks\MP Scheduled Scan.job

- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

.

.

------- Examen supplémentaire -------

.

uStart Page = about:blank

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: Télécharger en utilisant Download &Express - c:\program files\Download Express\Add_Url.htm

Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll

Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll

Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll

c:\windows\bdoscandellang.ini - c:\windows\bdoscandel.exe

c:\windows\Downloaded Program Files\live.ini

c:\windows\Downloaded Program Files\scanoptions.tsi

c:\windows\Downloaded Program Files\lang.ini

c:\windows\Downloaded Program Files\ipsupd.dll

c:\windows\Downloaded Program Files\bdupd.dll

c:\windows\Downloaded Program Files\libfn.dll

c:\windows\Downloaded Program Files\bdcore.dll

c:\windows\Downloaded Program Files\oscan8.ocx

O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}

hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab

c:\windows\Downloaded Program Files\oscan8.inf

FireFox -: Profile - c:\docume~1\Arnaud\Application Data\Mozilla\Firefox\Profiles\73a94nep.default\

FireFox -: prefs.js - STARTUP.HOMEPAGE -

FF -: plugin - c:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll

FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll

FF -: plugin - c:\program files\DivX\DivX Web Player\npdivx32.dll

FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava11.dll

FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava12.dll

FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava13.dll

FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava14.dll

FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjava32.dll

FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npjpi160_07.dll

FF -: plugin - c:\program files\Java\jre1.6.0_07\bin\npoji610.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdivx32.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npnul32.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPOFFICE.DLL

FF -: plugin - c:\program files\Mozilla Firefox\plugins\nppdf32.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\nppl3260.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\nprjplug.dll

FF -: plugin - c:\program files\Mozilla Firefox\plugins\nprpjplug.dll

FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin.dll

FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin2.dll

FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin3.dll

FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin4.dll

FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin5.dll

FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin6.dll

FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin7.dll

FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll

FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll

FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll

FF -: plugin - c:\program files\Windows Media Player\npdrmv2.dll

FF -: plugin - c:\program files\Windows Media Player\npdsplay.dll

FF -: plugin - c:\program files\Windows Media Player\npwmsdrm.dll

.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-11 12:01:22

Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès

Fichiers cachés: 0

**************************************************************************

.

--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(880)

c:\windows\system32\MrvGINA.dll

.

Heure de fin: 2008-12-11 12:02:44

ComboFix-quarantined-files.txt 2008-12-11 11:01:45

Avant-CF: 23 084 789 760 octets libres

Après-CF: 23,076,642,816 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

568 --- E O F --- 2008-12-10 22:32:19

Merci.

Lien vers le commentaire
Partager sur d’autres sites

Archivé

Ce sujet est désormais archivé et ne peut plus recevoir de nouvelles réponses.

×
×
  • Créer...