Rapports HijackThis

Fanto -  
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   -
Bonjour,

Fichier log :

Logfile of random's system information tool 1.08 (written by random/random)
Run by Luc at 2011-01-21 17:02:52
Microsoft® Windows Vista(TM) Édition Familiale Basique Service Pack 2
System drive C: has 2 GB (5%) free of 33 GB
Total RAM: 765 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:05:30, on 21/01/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.7930.16406)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\COMMON~1\McAfee\MSC\McUICnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SRWare Iron\iron.exe
C:\Program Files\SRWare Iron\iron.exe
C:\Program Files\SRWare Iron\iron.exe
C:\Program Files\SRWare Iron\iron.exe
C:\Program Files\SRWare Iron\iron.exe
C:\Users\Luc\Desktop\RSIT (1).exe
C:\Program Files\trend micro\Luc.exe
C:\Program Files\SRWare Iron\iron.exe
C:\Program Files\SRWare Iron\iron.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://laposte.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110106120935.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (BthServ) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcsvc.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (Eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\irmon.dll,-2000 (Irmon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Service McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprof.dll,-246 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Service de l'Assistant Compatibilité des programmes (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe
O23 - Service: @%SystemRoot%\system32\SLUINotify.dll,-103 (SLUINotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Acquisition d'image Windows (WIA) (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Téléphonie (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe
O23 - Service: Centre de sécurité (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe

--
End of file - 18482 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\vtscheduletask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-12-19 382720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110106120935.dll [2010-10-13 73288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar BHO - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll [2010-09-22 612616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - @C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll [2010-09-22 612616]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe [2010-11-22 1193848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Windows\RtHDVCpl.exe [2006-12-01 4186112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe /a /m C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-10-23 815104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
c:\program files\real\realplayer\Update\realsched.exe [2010-12-19 274608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-18 202240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
C:\Acer\EMPOWE~1\EAPLAU~1.EXE [2006-11-21 528384]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0x95000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-01-21 17:02:55 ----D---- C:\Program Files\trend micro
2011-01-21 17:02:52 ----D---- C:\rsit
2011-01-19 22:39:49 ----A---- C:\Windows\system32\drivers\hjuwmnxx.sys
2011-01-18 21:39:32 ----A---- C:\Windows\system32\odbc32.dll
2011-01-18 21:39:26 ----A---- C:\Windows\system32\sdclt.exe
2011-01-06 21:29:42 ----D---- C:\Program Files\Thoosje Vista Tweaker
2011-01-06 21:17:37 ----D---- C:\Program Files\NeoSmart Technologies
2011-01-06 21:15:56 ----D---- C:\Windows\TweakVI
2011-01-06 21:15:56 ----D---- C:\Program Files\TweakVI
2011-01-06 20:26:43 ----D---- C:\Program Files\Windows Portable Devices
2011-01-06 18:16:08 ----D---- C:\Windows\fr
2011-01-06 18:15:03 ----A---- C:\Windows\system32\drivers\fssfltr.sys
2011-01-06 18:15:02 ----DC---- C:\Windows\system32\DRVSTORE
2011-01-06 18:11:48 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-01-06 18:06:08 ----D---- C:\Program Files\Windows Live
2011-01-06 18:04:23 ----D---- C:\Program Files\Microsoft
2011-01-06 18:04:20 ----D---- C:\Program Files\MSN Toolbar
2011-01-06 18:03:13 ----D---- C:\Program Files\Bing Bar Installer
2011-01-06 18:02:43 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-01-06 18:02:43 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-01-06 18:02:43 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-01-06 17:28:22 ----D---- C:\Program Files\Common Files\Windows Live
2011-01-06 17:27:35 ----A---- C:\Windows\system32\webservices.dll
2011-01-06 17:27:13 ----A---- C:\Windows\system32\UIAnimation.dll
2011-01-06 17:27:12 ----A---- C:\Windows\system32\UIRibbonRes.dll
2011-01-06 17:27:12 ----A---- C:\Windows\system32\UIRibbon.dll
2011-01-06 17:26:30 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2011-01-06 17:26:30 ----A---- C:\Windows\system32\wpdbusenum.dll
2011-01-06 17:26:30 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2011-01-06 17:26:28 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2011-01-06 17:26:27 ----A---- C:\Windows\system32\WpdConns.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\WPDSp.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\wpdshext.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\WpdMtpUS.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\WpdMtp.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\wpd_ci.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2011-01-06 17:26:26 ----A---- C:\Windows\system32\drivers\WpdUsb.sys
2011-01-06 17:24:42 ----A---- C:\Windows\system32\UIAutomationCore.dll
2011-01-06 17:24:42 ----A---- C:\Windows\system32\oleaccrc.dll
2011-01-06 17:24:42 ----A---- C:\Windows\system32\oleacc.dll
2011-01-06 17:23:25 ----D---- C:\Windows\system32\WindowsPowerShell
2011-01-06 17:21:42 ----A---- C:\Windows\system32\winrsmgr.dll
2011-01-06 17:21:32 ----A---- C:\Windows\system32\wsmprovhost.exe
2011-01-06 17:21:32 ----A---- C:\Windows\system32\winrshost.exe
2011-01-06 17:21:32 ----A---- C:\Windows\system32\winrs.exe
2011-01-06 17:21:31 ----A---- C:\Windows\system32\wsmplpxy.dll
2011-01-06 17:21:31 ----A---- C:\Windows\system32\winrssrv.dll
2011-01-06 17:21:29 ----A---- C:\Windows\system32\WsmRes.dll
2011-01-06 17:21:29 ----A---- C:\Windows\system32\wevtfwd.dll
2011-01-06 17:21:29 ----A---- C:\Windows\system32\wecutil.exe
2011-01-06 17:21:29 ----A---- C:\Windows\system32\wecsvc.dll
2011-01-06 17:21:29 ----A---- C:\Windows\system32\wecapi.dll
2011-01-06 17:21:29 ----A---- C:\Windows\system32\pwrshplugin.dll
2011-01-06 17:21:24 ----A---- C:\Windows\system32\winrm.vbs
2011-01-06 17:21:23 ----A---- C:\Windows\system32\WsmWmiPl.dll
2011-01-06 17:21:23 ----A---- C:\Windows\system32\WsmSvc.dll
2011-01-06 17:21:23 ----A---- C:\Windows\system32\WsmAuto.dll
2011-01-06 17:21:23 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2011-01-06 17:21:23 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2011-01-06 17:21:23 ----A---- C:\Windows\system32\winrscmd.dll
2011-01-06 15:00:28 ----A---- C:\Windows\system32\ieui.dll
2011-01-06 15:00:28 ----A---- C:\Windows\system32\ieframe.dll
2011-01-06 15:00:24 ----A---- C:\Windows\system32\mshtml.dll
2011-01-06 14:58:14 ----SHD---- C:\Windows\system32\%APPDATA%
2011-01-06 14:52:54 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2011-01-06 14:52:54 ----A---- C:\Windows\system32\PresentationHost.exe
2011-01-06 14:52:54 ----A---- C:\Windows\system32\netfxperf.dll
2011-01-06 14:52:54 ----A---- C:\Windows\system32\mscoree.dll
2011-01-06 14:52:54 ----A---- C:\Windows\system32\dfshim.dll
2011-01-06 14:45:24 ----D---- C:\Program Files\Geekbench 2.1
2011-01-06 13:28:15 ----A---- C:\Windows\system32\wmp.dll
2011-01-06 13:28:13 ----A---- C:\Windows\system32\wmploc.DLL
2011-01-06 13:27:05 ----A---- C:\Windows\system32\srvsvc.dll
2011-01-06 13:27:05 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-01-06 13:27:05 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-01-06 13:27:05 ----A---- C:\Windows\system32\drivers\srv.sys
2011-01-06 13:27:04 ----A---- C:\Windows\system32\netevent.dll
2011-01-06 13:26:33 ----A---- C:\Windows\system32\usp10.dll
2011-01-06 13:26:14 ----A---- C:\Windows\system32\schannel.dll
2011-01-06 13:26:06 ----A---- C:\Windows\system32\iccvid.dll
2011-01-06 13:26:03 ----A---- C:\Windows\system32\asycfilt.dll
2011-01-06 13:25:58 ----A---- C:\Windows\system32\ole32.dll
2011-01-06 13:24:27 ----A---- C:\Windows\system32\spoolsv.exe
2011-01-06 13:24:23 ----A---- C:\Windows\system32\win32k.sys
2011-01-06 13:24:19 ----A---- C:\Windows\system32\t2embed.dll
2011-01-06 13:24:05 ----A---- C:\Windows\system32\gameux.dll
2011-01-06 13:24:02 ----A---- C:\Windows\system32\Apphlpdm.dll
2011-01-06 13:24:01 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2011-01-06 13:23:31 ----A---- C:\Windows\system32\MP4SDECD.DLL
2011-01-06 13:23:26 ----A---- C:\Windows\system32\mfc40u.dll
2011-01-06 13:23:26 ----A---- C:\Windows\system32\mfc40.dll
2011-01-06 13:23:22 ----A---- C:\Windows\system32\rtutils.dll
2011-01-06 13:22:55 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-01-06 13:22:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-01-06 13:22:49 ----A---- C:\Windows\system32\wmpmde.dll
2011-01-06 13:21:18 ----A---- C:\Windows\system32\schedsvc.dll
2011-01-06 13:21:17 ----A---- C:\Windows\system32\taskschd.dll
2011-01-06 13:21:15 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-01-06 13:21:15 ----A---- C:\Windows\system32\taskeng.exe
2011-01-06 13:21:15 ----A---- C:\Windows\system32\taskcomp.dll
2011-01-06 13:21:02 ----A---- C:\Windows\system32\consent.exe
2011-01-06 13:20:56 ----A---- C:\Windows\system32\atmfd.dll
2011-01-06 13:20:55 ----A---- C:\Windows\system32\fontsub.dll
2011-01-06 13:20:55 ----A---- C:\Windows\system32\atmlib.dll
2011-01-06 13:20:50 ----A---- C:\Windows\system32\msxml3.dll
2011-01-06 13:20:46 ----A---- C:\Windows\system32\inetcomm.dll
2011-01-06 13:20:26 ----A---- C:\Windows\system32\tzres.dll
2011-01-06 13:19:40 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-01-06 13:19:33 ----A---- C:\Windows\system32\shell32.dll
2011-01-06 13:17:47 ----A---- C:\Windows\system32\comctl32.dll
2011-01-06 13:17:41 ----A---- C:\Windows\system32\msshsq.dll
2011-01-06 12:08:06 ----A---- C:\Windows\system32\drivers\mfewfpk.sys
2011-01-06 10:27:05 ----D---- C:\Program Files\Defraggler
2011-01-06 09:50:52 ----A---- C:\Windows\system32\webcheck.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\vbscript.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\urlmon.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\url.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-01-06 09:50:52 ----A---- C:\Windows\system32\SetDepNx.exe
2011-01-06 09:50:52 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-01-06 09:50:52 ----A---- C:\Windows\system32\pngfilt.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\msls31.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\mshtmler.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\mshtmled.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\mshta.exe
2011-01-06 09:50:52 ----A---- C:\Windows\system32\msfeedssync.exe
2011-01-06 09:50:52 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\msfeeds.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\licmgr10.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\jsproxy.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\jscript9.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\jscript.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\inseng.dll
2011-01-06 09:50:52 ----A---- C:\Windows\system32\admparse.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\occache.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\msrating.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\imgutil.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\iexpress.exe
2011-01-06 09:50:51 ----A---- C:\Windows\system32\ieUnatt.exe
2011-01-06 09:50:51 ----A---- C:\Windows\system32\iesysprep.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\iedkcs32.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\ieapfltr.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\ieakui.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\ieaksie.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\ieakeng.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\ie4uinit.exe
2011-01-06 09:50:51 ----A---- C:\Windows\system32\icardie.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\dxtrans.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\dxtmsft.dll
2011-01-06 09:50:51 ----A---- C:\Windows\system32\advpack.dll
2011-01-06 09:50:50 ----A---- C:\Windows\system32\wininet.dll
2011-01-06 09:50:50 ----A---- C:\Windows\system32\wextract.exe
2011-01-06 09:50:50 ----A---- C:\Windows\system32\iesetup.dll
2011-01-06 09:50:50 ----A---- C:\Windows\system32\iertutil.dll
2011-01-06 09:50:50 ----A---- C:\Windows\system32\iernonce.dll
2011-01-06 09:50:50 ----A---- C:\Windows\system32\iepeers.dll
2011-01-06 09:50:22 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-06 09:50:22 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-06 09:50:22 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-06 09:50:22 ----A---- C:\Windows\system32\mfmp4src.dll
2011-01-06 09:50:22 ----A---- C:\Windows\system32\MFHEAACdec.dll
2011-01-06 09:50:22 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-06 09:50:22 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-06 09:50:21 ----A---- C:\Windows\system32\MFH264Dec.dll
2011-01-06 09:50:21 ----A---- C:\Windows\system32\FntCache.dll
2011-01-06 09:50:21 ----A---- C:\Windows\system32\DWrite.dll
2011-01-06 09:50:21 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-06 09:50:21 ----A---- C:\Windows\system32\d2d1.dll
2011-01-06 09:49:27 ----A---- C:\Windows\system32\WMPhoto.dll
2011-01-06 09:49:26 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-06 09:49:26 ----A---- C:\Windows\system32\cdd.dll
2011-01-06 09:49:25 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2011-01-06 09:49:25 ----A---- C:\Windows\system32\WindowsCodecs.dll
2011-01-06 09:49:25 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2011-01-06 09:49:25 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2011-01-06 09:49:25 ----A---- C:\Windows\system32\dxdiagn.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\xpsservices.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2011-01-06 09:49:24 ----A---- C:\Windows\system32\OpcServices.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\dxgi.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\dxdiag.exe
2011-01-06 09:49:24 ----A---- C:\Windows\system32\d3d11.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\d3d10level9.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\d3d10core.dll
2011-01-06 09:49:24 ----A---- C:\Windows\system32\d3d10.dll
2011-01-06 09:48:03 ----D---- C:\Program Files\Feedback Tool
2011-01-06 09:35:53 ----D---- C:\Users\Luc\AppData\Roaming\GrabPro
2011-01-06 09:35:53 ----D---- C:\downloads
2011-01-06 09:18:31 ----D---- C:\Users\Luc\AppData\Roaming\QuickScan
2011-01-06 09:01:57 ----D---- C:\Windows\BDOSCAN8
2011-01-06 08:57:21 ----D---- C:\Program Files\VS Revo Group
2011-01-06 08:46:53 ----D---- C:\Users\Luc\AppData\Roaming\TweakNow PowerPack 2009
2011-01-06 08:46:53 ----D---- C:\Program Files\TweakNow PowerPack 2009
2011-01-06 08:04:18 ----D---- C:\Program Files\Microsoft Silverlight
2011-01-06 07:11:00 ----D---- C:\Windows\pss
2011-01-06 00:09:59 ----D---- C:\Windows\system32\eu-ES
2011-01-06 00:09:59 ----D---- C:\Windows\system32\ca-ES
2011-01-06 00:09:57 ----D---- C:\Windows\system32\vi-VN
2011-01-06 00:00:36 ----D---- C:\Windows\system32\SPReview
2011-01-05 23:40:03 ----A---- C:\Windows\system32\scavenge.dll
2011-01-05 23:39:55 ----A---- C:\Windows\system32\compcln.exe
2011-01-05 23:39:18 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-01-05 23:39:18 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-01-05 23:39:18 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-01-05 23:39:18 ----A---- C:\Windows\system32\sdohlp.dll
2011-01-05 23:39:18 ----A---- C:\Windows\system32\drivers\sdbus.sys
2011-01-05 23:39:17 ----A---- C:\Windows\system32\rtffilt.dll
2011-01-05 23:39:17 ----A---- C:\Windows\system32\rsaenh.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\scrrun.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\SCardSvr.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\scansetting.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\samsrv.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\samlib.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\rpcss.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\rpchttp.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\riched20.dll
2011-01-05 23:39:16 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2011-01-05 23:39:16 ----A---- C:\Windows\system32\drivers\rmcast.sys
2011-01-05 23:39:15 ----A---- C:\Windows\system32\scrobj.dll
2011-01-05 23:39:15 ----A---- C:\Windows\system32\scksp.dll
2011-01-05 23:39:15 ----A---- C:\Windows\system32\scesrv.dll
2011-01-05 23:39:15 ----A---- C:\Windows\system32\scecli.dll
2011-01-05 23:39:14 ----A---- C:\Windows\system32\perfdisk.dll
2011-01-05 23:39:14 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2011-01-05 23:39:14 ----A---- C:\Windows\system32\pdh.dll
2011-01-05 23:39:14 ----A---- C:\Windows\system32\drivers\pcmcia.sys
2011-01-05 23:39:14 ----A---- C:\Windows\system32\drivers\pacer.sys
2011-01-05 23:39:13 ----A---- C:\Windows\system32\powercpl.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\PNPXAssoc.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\PnPutil.exe
2011-01-05 23:39:13 ----A---- C:\Windows\system32\PnPUnattend.exe
2011-01-05 23:39:13 ----A---- C:\Windows\system32\pnpui.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\pnpsetup.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\pnidui.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\pcaui.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\p2psvc.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\P2PGraph.dll
2011-01-05 23:39:13 ----A---- C:\Windows\system32\drivers\portcls.sys
2011-01-05 23:39:13 ----A---- C:\Windows\system32\drivers\pciidex.sys
2011-01-05 23:39:13 ----A---- C:\Windows\system32\drivers\pciide.sys
2011-01-05 23:39:13 ----A---- C:\Windows\system32\drivers\pci.sys
2011-01-05 23:39:13 ----A---- C:\Windows\system32\drivers\partmgr.sys
2011-01-05 23:39:12 ----A---- C:\Windows\system32\PkgMgr.exe
2011-01-05 23:39:12 ----A---- C:\Windows\system32\pidgenx.dll
2011-01-05 23:39:12 ----A---- C:\Windows\system32\photowiz.dll
2011-01-05 23:39:12 ----A---- C:\Windows\system32\ntdll.dll
2011-01-05 23:39:12 ----A---- C:\Windows\system32\nslookup.exe
2011-01-05 23:39:12 ----A---- C:\Windows\system32\drivers\npfs.sys
2011-01-05 23:39:11 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2011-01-05 23:39:11 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-01-05 23:39:10 ----A---- C:\Windows\system32\offfilt.dll
2011-01-05 23:39:10 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2011-01-05 23:39:10 ----A---- C:\Windows\system32\nlhtml.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\osk.exe
2011-01-05 23:39:09 ----A---- C:\Windows\system32\oobefldr.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\onex.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\olepro32.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\oleprn.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\oleaut32.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\odbccp32.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\odbcconf.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\ocsetup.exe
2011-01-05 23:39:09 ----A---- C:\Windows\system32\ntprint.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\ntmarta.dll
2011-01-05 23:39:09 ----A---- C:\Windows\system32\drivers\nwifi.sys
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rastapi.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasppp.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasplap.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasmontr.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasmans.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasgcw.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasdlg.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasdial.exe
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasdiag.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\raschap.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\rasapi32.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\RacEngn.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\Query.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\qmgr.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\qedit.dll
2011-01-05 23:39:08 ----A---- C:\Windows\system32\drivers\rassstp.sys
2011-01-05 23:39:08 ----A---- C:\Windows\system32\drivers\raspppoe.sys
2011-01-05 23:39:07 ----A---- C:\Windows\system32\RelMon.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\rekeywiz.exe
2011-01-05 23:39:07 ----A---- C:\Windows\system32\regsvc.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\regapi.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\reg.exe
2011-01-05 23:39:07 ----A---- C:\Windows\system32\rdpwsx.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\rdpencom.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\prnntfy.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\printui.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\powrprof.dll
2011-01-05 23:39:07 ----A---- C:\Windows\system32\drivers\rfcomm.sys
2011-01-05 23:39:07 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2011-01-05 23:39:07 ----A---- C:\Windows\system32\drivers\rdbss.sys
2011-01-05 23:39:06 ----A---- C:\Windows\system32\qdvd.dll
2011-01-05 23:39:06 ----A---- C:\Windows\system32\QAGENTRT.DLL
2011-01-05 23:39:06 ----A---- C:\Windows\system32\puiapi.dll
2011-01-05 23:39:06 ----A---- C:\Windows\system32\psisdecd.dll
2011-01-05 23:39:06 ----A---- C:\Windows\system32\propsys.dll
2011-01-05 23:39:06 ----A---- C:\Windows\system32\propdefs.dll
2011-01-05 23:39:06 ----A---- C:\Windows\system32\profsvc.dll
2011-01-05 23:39:05 ----A---- C:\Windows\system32\PSHED.DLL
2011-01-05 23:39:03 ----A---- C:\Windows\system32\sendmail.dll
2011-01-05 23:39:00 ----A---- C:\Windows\system32\shlwapi.dll
2011-01-05 23:39:00 ----A---- C:\Windows\system32\shdocvw.dll
2011-01-05 23:38:59 ----A---- C:\Windows\system32\setupapi.dll
2011-01-05 23:38:59 ----A---- C:\Windows\system32\sethc.exe
2011-01-05 23:38:59 ----A---- C:\Windows\system32\services.exe
2011-01-05 23:38:56 ----A---- C:\Windows\system32\eapphost.dll
2011-01-05 23:38:56 ----A---- C:\Windows\system32\eappgnui.dll
2011-01-05 23:38:56 ----A---- C:\Windows\system32\drivers\ecache.sys
2011-01-05 23:38:54 ----A---- C:\Windows\system32\evr.dll
2011-01-05 23:38:54 ----A---- C:\Windows\system32\EhStorAPI.dll
2011-01-05 23:38:54 ----A---- C:\Windows\system32\eappcfg.dll
2011-01-05 23:38:54 ----A---- C:\Windows\system32\eapp3hst.dll
2011-01-05 23:38:54 ----A---- C:\Windows\system32\dwm.exe
2011-01-05 23:38:54 ----A---- C:\Windows\system32\dsprop.dll
2011-01-05 23:38:54 ----A---- C:\Windows\system32\dsound.dll
2011-01-05 23:38:54 ----A---- C:\Windows\system32\drivers\dxg.sys
2011-01-05 23:38:54 ----A---- C:\Windows\system32\drivers\Dumpata.sys
2011-01-05 23:38:53 ----A---- C:\Windows\system32\f3ahvoas.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\eudcedit.exe
2011-01-05 23:38:53 ----A---- C:\Windows\system32\esent.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\es.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\EncDec.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\emdmgmt.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\EhStorShell.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\EhStorAuthn.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\drivers\exfat.sys
2011-01-05 23:38:53 ----A---- C:\Windows\system32\dimsroam.dll
2011-01-05 23:38:53 ----A---- C:\Windows\system32\diagperf.dll
2011-01-05 23:38:53 ----A---- C:\Windows\explorer.exe
2011-01-05 23:38:52 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-01-05 23:38:52 ----A---- C:\Windows\system32\drivers\disk.sys
2011-01-05 23:38:52 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-01-05 23:38:52 ----A---- C:\Windows\system32\diskraid.exe
2011-01-05 23:38:52 ----A---- C:\Windows\system32\diskpart.exe
2011-01-05 23:38:52 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2011-01-05 23:38:52 ----A---- C:\Windows\system32\devmgr.dll
2011-01-05 23:38:51 ----A---- C:\Windows\system32\drvstore.dll
2011-01-05 23:38:51 ----A---- C:\Windows\system32\dpapimig.exe
2011-01-05 23:38:51 ----A---- C:\Windows\system32\dot3svc.dll
2011-01-05 23:38:51 ----A---- C:\Windows\system32\dot3msm.dll
2011-01-05 23:38:51 ----A---- C:\Windows\system32\dot3cfg.dll
2011-01-05 23:38:51 ----A---- C:\Windows\system32\dhcpcsvc.dll
2011-01-05 23:38:50 ----A---- C:\Windows\system32\drvinst.exe
2011-01-05 23:38:50 ----A---- C:\Windows\system32\drmv2clt.dll
2011-01-05 23:38:50 ----A---- C:\Windows\system32\drmmgrtn.dll
2011-01-05 23:38:50 ----A---- C:\Windows\system32\dnsapi.dll
2011-01-05 23:38:50 ----A---- C:\Windows\system32\dmusic.dll
2011-01-05 23:38:50 ----A---- C:\Windows\system32\dmsynth.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\iasnap.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\IasMigReader.exe
2011-01-05 23:38:49 ----A---- C:\Windows\system32\iashlpr.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\iasdatastore.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\iasads.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\iasacct.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\hbaapi.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\gpupdate.exe
2011-01-05 23:38:49 ----A---- C:\Windows\system32\gpsvc.dll
2011-01-05 23:38:49 ----A---- C:\Windows\system32\gpresult.exe
2011-01-05 23:38:49 ----A---- C:\Windows\system32\drivers\hdaudbus.sys
2011-01-05 23:38:49 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\IasMigPlugin.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\hidserv.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\hdwwiz.exe
2011-01-05 23:38:48 ----A---- C:\Windows\system32\gpapi.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\gdi32.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fontext.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\findstr.exe
2011-01-05 23:38:48 ----A---- C:\Windows\system32\feclient.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fdWSD.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fdWCN.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fdSSDP.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fdProxy.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fdeploy.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fdBthProxy.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fdBth.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\fc.exe
2011-01-05 23:38:48 ----A---- C:\Windows\system32\Faultrep.dll
2011-01-05 23:38:48 ----A---- C:\Windows\system32\drivers\hidusb.sys
2011-01-05 23:38:48 ----A---- C:\Windows\system32\drivers\hidclass.sys
2011-01-05 23:38:48 ----A---- C:\Windows\system32\drivers\fltMgr.sys
2011-01-05 23:38:48 ----A---- C:\Windows\system32\drivers\fastfat.sys
2011-01-05 23:38:47 ----A---- C:\Windows\system32\gpedit.dll
2011-01-05 23:38:46 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2011-01-05 23:38:46 ----A---- C:\Windows\system32\fundisc.dll
2011-01-05 23:38:46 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2011-01-05 23:38:46 ----A---- C:\Windows\system32\ftp.exe
2011-01-05 23:38:46 ----A---- C:\Windows\system32\fsquirt.exe
2011-01-05 23:38:45 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2011-01-05 23:38:45 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2011-01-05 23:38:45 ----A---- C:\Windows\system32\drivers\ataport.sys
2011-01-05 23:38:45 ----A---- C:\Windows\system32\drivers\atapi.sys
2011-01-05 23:38:45 ----A---- C:\Windows\system32\autoplay.dll
2011-01-05 23:38:45 ----A---- C:\Windows\system32\autofmt.exe
2011-01-05 23:38:45 ----A---- C:\Windows\system32\autoconv.exe
2011-01-05 23:38:45 ----A---- C:\Windows\system32\autochk.exe
2011-01-05 23:38:45 ----A---- C:\Windows\system32\authz.dll
2011-01-05 23:38:45 ----A---- C:\Windows\system32\authui.dll
2011-01-05 23:38:45 ----A---- C:\Windows\system32\audiosrv.dll
2011-01-05 23:38:45 ----A---- C:\Windows\system32\AudioSes.dll
2011-01-05 23:38:45 ----A---- C:\Windows\system32\audiodg.exe
2011-01-05 23:38:44 ----A---- C:\Windows\system32\drivers\bthenum.sys
2011-01-05 23:38:44 ----A---- C:\Windows\system32\drivers\bridge.sys
2011-01-05 23:38:44 ----A---- C:\Windows\system32\drivers\acpi.sys
2011-01-05 23:38:44 ----A---- C:\Windows\system32\bthci.dll
2011-01-05 23:38:44 ----A---- C:\Windows\system32\browseui.dll
2011-01-05 23:38:44 ----A---- C:\Windows\system32\brcpl.dll
2011-01-05 23:38:44 ----A---- C:\Windows\system32\blackbox.dll
2011-01-05 23:38:44 ----A---- C:\Windows\system32\bitsigd.dll
2011-01-05 23:38:44 ----A---- C:\Windows\system32\BFE.DLL
2011-01-05 23:38:44 ----A---- C:\Windows\system32\bcrypt.dll
2011-01-05 23:38:44 ----A---- C:\Windows\system32\basecsp.dll
2011-01-05 23:38:44 ----A---- C:\Windows\system32\azroles.dll
2011-01-05 23:38:43 ----A---- C:\Windows\system32\apphelp.dll
2011-01-05 23:38:43 ----A---- C:\Windows\system32\apds.dll
2011-01-05 23:38:43 ----A---- C:\Windows\system32\accessibilitycpl.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\drivers\crashdmp.sys
2011-01-05 23:38:42 ----A---- C:\Windows\system32\drivers\afd.sys
2011-01-05 23:38:42 ----A---- C:\Windows\system32\crypt32.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\credui.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\connect.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\conime.exe
2011-01-05 23:38:42 ----A---- C:\Windows\system32\comuid.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\comsvcs.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\advapi32.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\adtschema.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\adsmsext.dll
2011-01-05 23:38:42 ----A---- C:\Windows\system32\adsldpc.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2011-01-05 23:38:41 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\DevicePairing.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\DeviceEject.exe
2011-01-05 23:38:41 ----A---- C:\Windows\system32\dbgeng.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\davclnt.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\dataclen.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\d3d9.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\comdlg32.dll
2011-01-05 23:38:41 ----A---- C:\Windows\system32\cmmon32.exe
2011-01-05 23:38:41 ----A---- C:\Windows\system32\cmdial32.dll
2011-01-05 23:38:40 ----A---- C:\Windows\system32\csrstub.exe
2011-01-05 23:38:40 ----A---- C:\Windows\system32\cscript.exe
2011-01-05 23:38:40 ----A---- C:\Windows\system32\cscdll.dll
2011-01-05 23:38:40 ----A---- C:\Windows\system32\cscapi.dll
2011-01-05 23:38:40 ----A---- C:\Windows\system32\cryptui.dll
2011-01-05 23:38:40 ----A---- C:\Windows\system32\cryptsvc.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\drivers\Classpnp.sys
2011-01-05 23:38:39 ----A---- C:\Windows\system32\drivers\cdrom.sys
2011-01-05 23:38:39 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-01-05 23:38:39 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-01-05 23:38:39 ----A---- C:\Windows\system32\drivers\bthmodem.sys
2011-01-05 23:38:39 ----A---- C:\Windows\system32\clfs.sys
2011-01-05 23:38:39 ----A---- C:\Windows\system32\cipher.exe
2011-01-05 23:38:39 ----A---- C:\Windows\system32\ci.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\chtbrkr.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\chsbrkr.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\certmgr.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\CertEnrollUI.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\CertEnroll.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\certcli.dll
2011-01-05 23:38:39 ----A---- C:\Windows\system32\cbsra.exe
2011-01-05 23:38:39 ----A---- C:\Windows\system32\bthudtask.exe
2011-01-05 23:38:39 ----A---- C:\Windows\system32\bthserv.dll
2011-01-05 23:38:38 ----A---- C:\Windows\system32\msihnd.dll
2011-01-05 23:38:38 ----A---- C:\Windows\system32\msiexec.exe
2011-01-05 23:38:38 ----A---- C:\Windows\system32\msftedit.dll
2011-01-05 23:38:38 ----A---- C:\Windows\system32\msexcl40.dll
2011-01-05 23:38:38 ----A---- C:\Windows\system32\msexch40.dll
2011-01-05 23:38:38 ----A---- C:\Windows\system32\msdtctm.dll
2011-01-05 23:38:38 ----A---- C:\Windows\system32\certutil.exe
2011-01-05 23:38:38 ----A---- C:\Windows\system32\certreq.exe
2011-01-05 23:38:38 ----A---- C:\Windows\system32\certprop.dll
2011-01-05 23:38:37 ----A---- C:\Windows\system32\msi.dll
2011-01-05 23:38:37 ----A---- C:\Windows\system32\msdtcprx.dll
2011-01-05 23:38:37 ----A---- C:\Windows\system32\msctfui.dll
2011-01-05 23:38:37 ----A---- C:\Windows\system32\msctfp.dll
2011-01-05 23:38:37 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2011-01-05 23:38:37 ----A---- C:\Windows\system32\msctf.dll
2011-01-05 23:38:36 ----A---- C:\Windows\system32\msimsg.dll
2011-01-05 23:38:36 ----A---- C:\Windows\system32\MPSSVC.dll
2011-01-05 23:38:36 ----A---- C:\Windows\system32\mprapi.dll
2011-01-05 23:38:36 ----A---- C:\Windows\system32\mpr.dll
2011-01-05 23:38:35 ----A---- C:\Windows\system32\mscories.dll
2011-01-05 23:38:35 ----A---- C:\Windows\system32\mscorier.dll
2011-01-05 23:38:35 ----A---- C:\Windows\system32\mscms.dll
2011-01-05 23:38:35 ----A---- C:\Windows\system32\mscandui.dll
2011-01-05 23:38:35 ----A---- C:\Windows\system32\modemui.dll
2011-01-05 23:38:35 ----A---- C:\Windows\system32\MMDevAPI.dll
2011-01-05 23:38:35 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2011-01-05 23:38:34 ----A---- C:\Windows\system32\netplwiz.dll
2011-01-05 23:38:34 ----A---- C:\Windows\system32\netcenter.dll
2011-01-05 23:38:34 ----A---- C:\Windows\system32\netapi32.dll
2011-01-05 23:38:34 ----A---- C:\Windows\system32\ncryptui.dll
2011-01-05 23:38:34 ----A---- C:\Windows\system32\ncrypt.dll
2011-01-05 23:38:34 ----A---- C:\Windows\system32\drivers\netio.sys
2011-01-05 23:38:34 ----A---- C:\Windows\system32\drivers\netbt.sys
2011-01-05 23:38:34 ----A---- C:\Windows\system32\drivers\ndiswan.sys
2011-01-05 23:38:34 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-01-05 23:38:33 ----A---- C:\Windows\system32\netlogon.dll
2011-01-05 23:38:33 ----A---- C:\Windows\system32\NcdProp.dll
2011-01-05 23:38:33 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2011-01-05 23:38:33 ----A---- C:\Windows\system32\mtxclu.dll
A voir également:

12 réponses

Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
Bonjour,

Quel est le problème ?

Utilise l'option Nettoyer d'Ad-Remover :
http://www.teamxscript.org/adremoverTelechargement.html

Puis suis ce tutoriel :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
1
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
Ok, fais ce qui est indiqué dans mon précédent message.

"2011-01-19 22:39:49 ----A---- C:\Windows\system32\drivers\hjuwmnxx.sys"

--> Douteux ce fichier.
1
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
Fais-le scanner sur VirusTotal :
https://www.virustotal.com/gui/
1
Fanto
 
Bonjour,

Le logiciel malveillant Alureon a été détecté sur mon ordinateur.

Une procédure de détection m'a conseillé d'utiliser HijackThis et de poster les contenu des 2 fichiers textes sur ce forum.

Est ce que mon ordinateur est infecté ?

Merci pour votre support.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Fanto
 
Bonsoir,

J'ai fait un scan complet avec Malewarebytes comme vous l'avez suggéré. Il a trouvé une clé de registre infectée par Rogue.WinAntiVirus. Ci-dessous le rapport :

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5571

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.7930.16406

22/01/2011 21:46:42
mbam-log-2011-01-22 (21-46-42).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 253943
Temps écoulé: 1 heure(s), 53 minute(s), 35 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

Concernant le fichier douteux que vous avez signalé, est ce que je devrais le supprimer ?

Merci pour vos conseils.
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
Quel est le fichier détecté par ton antivirus et à quel emplacement ?
0
Fanto
 
Je parlais du fichier que vous aviez indiqué le 21 jan 2011 à 20:08 :

"2011-01-19 22:39:49 ----A---- C:\Windows\system32\drivers\hjuwmnxx.sys"

--> Douteux ce fichier.


Est ce que je devrais le supprimer ?

Merci.
0
Fanto
 
Bonsoir,

Virustotal n'a rien trouvé : voir le rapport ci-dessous.

File name: hjuwmnxx.sys
Submission date: 2011-01-24 18:28:12 (UTC)
Current status: finished
Result: 0/ 43 (0.0%)

Antivirus Version Last Update Result
AhnLab-V3 2011.01.18.00 2011.01.17 -
AntiVir 7.11.1.237 2011.01.24 -
Antiy-AVL 2.0.3.7 2011.01.18 -
Avast 4.8.1351.0 2011.01.24 -
Avast5 5.0.677.0 2011.01.24 -
AVG 10.0.0.1190 2011.01.24 -
BitDefender 7.2 2011.01.24 -
CAT-QuickHeal 11.00 2011.01.24 -
ClamAV 0.96.4.0 2011.01.24 -
Commtouch 5.2.11.5 2011.01.24 -
Comodo 7486 2011.01.24 -
DrWeb 5.0.2.03300 2011.01.24 -
Emsisoft 5.1.0.1 2011.01.24 -
eSafe 7.0.17.0 2011.01.23 -
eTrust-Vet 36.1.8116 2011.01.24 -
F-Prot 4.6.2.117 2011.01.23 -
F-Secure 9.0.16160.0 2011.01.24 -
Fortinet 4.2.254.0 2011.01.24 -
GData 21 2011.01.24 -
Ikarus T3.1.1.97.0 2011.01.24 -
Jiangmin 13.0.900 2011.01.24 -
K7AntiVirus 9.78.3635 2011.01.24 -
Kaspersky 7.0.0.125 2011.01.24 -
McAfee 5.400.0.1158 2011.01.24 -
McAfee-GW-Edition 2010.1C 2011.01.24 -
Microsoft 1.6502 2011.01.24 -
NOD32 5813 2011.01.24 -
Norman 6.06.12 2011.01.24 -
nProtect 2011-01-18.01 2011.01.18 -
Panda 10.0.2.7 2011.01.24 -
PCTools 7.0.3.5 2011.01.23 -
Prevx 3.0 2011.01.24 -
Rising 23.42.00.06 2011.01.24 -
Sophos 4.61.0 2011.01.24 -
SUPERAntiSpyware 4.40.0.1006 2011.01.24 -
Symantec 20101.3.0.103 2011.01.24 -
TheHacker 6.7.0.1.119 2011.01.24 -
TrendMicro 9.120.0.1004 2011.01.24 -
TrendMicro-HouseCall 9.120.0.1004 2011.01.24 -
VBA32 3.12.14.3 2011.01.24 -
VIPRE 8181 2011.01.24 -
ViRobot 2011.1.24.4272 2011.01.24 -
VirusBuster 13.6.162.0 2011.01.24 -

Est ce que vous pensez que mon PC est guéri ?

Merci.
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
Alureon est détecté à quel emplacement ? Quel fichier ?
0
Fanto
 
Je ne sais plus.
Apparemment, il n'y a plus de problème.
Je vous remercie pour votre support.
0
Fanto
 
Bonjour,

Le virus Alureon.h a de nouveau été détecté par Windows à l'emplacement suivant : Win32/Alureon.h

Comme la dernière fois, il a été partiellement supprimé.

Est ce que vous avez une solution pour le supprimer définitivement ?

Merci.
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 324
 
--> Fais un scan avec TDSSKiller :
https://forum.malekal.com/viewtopic.php?t=28637&start=
0