

Matia60
Membres-
Compteur de contenus
21 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par Matia60
-
Merci pour votre analyse qui me rassure. Je regarderai plus tard pour l'optimisation et les vérifications de sécurité.
-
Merci pour votre réponse, Tout est vite désuet maintenant... Heureusement que les forums comme celui-ci existent! Voici le rapport de ZHPDiag : Cordialement.
-
Re, J'ai fait un nouveau scan HiJackThis en réinstallant une version plus récente je crois (v2.0.4). Pour rappel, Google est très lent sur mon PC, notamment il met un temps fou à me donner la main pour pianoter mon texte dans la barre de recherche lorsqu'il commence à me proposer des intitulés de recherche. Voici ci-dessous le rapport avec la version plus récente de HiJackThis. Pour info, Malwarebytes et McAfee (tous les deux mis à jour) ne trouvent rien d'anormal. Merci par avance pour votre aide. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:56:53, on 02/09/2011 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.19120) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\conime.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\OrangeHSS\Launcher\Launcher.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\DellTPad\HidFind.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Users\MOI\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\OrangeHSS\systray\systrayapp.exe C:\Program Files\OrangeHSS\Deskboard\deskboard.exe C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\Macromed\Flash\FlashUtil10s_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Page initiale personnalisée R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN : Hotmail, Messenger, Bing, Actualité et Sport R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110516224350.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [CanalPlayer] "C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe" O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [badoo Desktop] "C:\ProgramData\Badoo\Badoo Desktop\1.1.101.725\Badoo.Desktop.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user') O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\MOI\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll O15 - Trusted Zone: *.canalplay.com O15 - Trusted Zone: *.canalplusactive.com O15 - Trusted Zone: http://*.mappy.com O15 - Trusted Zone: http://*.orange.fr O15 - Trusted Zone: Orange : téléphones, forfaits, Internet, actualité, sport, video O15 - Trusted Zone: http://orange.weborama.fr O15 - Trusted Zone: *.canalplay.com (HKLM) O15 - Trusted Zone: *.canalplusactive.com (HKLM) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://stream.pussyharem.com/stream/mmp3.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\aestsrv.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe O23 - Service: @%SystemRoot%\system32\dhcpcsvc.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\emdmgmt.dll,-1000 (EMDMgmt) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (Eventlog) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - Unknown owner - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-200 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe O23 - Service: Service McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\netprof.dll,-246 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe O23 - Service: @%SystemRoot%\system32\SLUINotify.dll,-103 (SLUINotify) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\STacSV.exe O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe -- End of file - 27880 bytes
-
Bonjour à tous, Je trouve que Google sur mon PC est très lent, notamment il met un temps fou à me donner la main pour pianoter mon texte dans la barre de recherche lorsqu'il commence à me proposer des intitulés de recherche. J'ai fait un scan avec HiJackThis dont voici le rapport ci-dessous. Y a t'il quelqu'un qui puisse me dire si il y a un truc qui semble bizarre? Merci par avance. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:31:21, on 01/09/2011 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.19120) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\system32\conime.exe C:\Program Files\OrangeHSS\Launcher\Launcher.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Users\MOI\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe C:\Windows\ehome\ehmsas.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\OrangeHSS\systray\systrayapp.exe C:\Program Files\OrangeHSS\Deskboard\deskboard.exe C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe C:\Windows\system32\wuauclt.exe C:\PROGRA~1\COMMON~1\McAfee\MSC\McUICnt.exe C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe C:\Windows\system32\Macromed\Flash\FlashUtil10s_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\MOI\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Page initiale personnalisée R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN : Hotmail, Messenger, Bing, Actualité et Sport R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110516224350.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2 O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [CanalPlayer] "C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [badoo Desktop] "C:\ProgramData\Badoo\Badoo Desktop\1.1.101.725\Badoo.Desktop.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user') O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\MOI\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll O13 - Gopher Prefix: O15 - Trusted Zone: *.canalplay.com O15 - Trusted Zone: *.canalplusactive.com O15 - Trusted Zone: http://*.mappy.com O15 - Trusted Zone: http://*.orange.fr O15 - Trusted Zone: Orange : téléphones, forfaits, Internet, actualité, sport, video O15 - Trusted Zone: http://orange.weborama.fr O15 - Trusted Zone: *.canalplay.com (HKLM) O15 - Trusted Zone: *.canalplusactive.com (HKLM) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://stream.pussyharem.com/stream/mmp3.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\aestsrv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe O23 - Service: Service McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE -- End of file - 14709 bytes
-
Gestionnaire des tâches iexplore.exe
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Ok merci bonne soirée -
Gestionnaire des tâches iexplore.exe
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Re Apollo, Effectivement c'est mieux. Je ferai les mises à jour recommandées plus tard. J'en ai encore pour quelque temps avec McAfee. Est-ce que ca peut causer des conflits d'avoir Antivir + McAfee? Merci pour ton aide. -
Gestionnaire des tâches iexplore.exe
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Bonsoir et merci pour la réponse. Voici le rapport de MBAM : Malwarebytes' Anti-Malware 1.41 Version de la base de données: 3224 Windows 6.0.6002 Service Pack 2 24/11/2009 22:10:47 mbam-log-2009-11-24 (22-10-47).txt Type de recherche: Examen complet (C:\|D:\|E:\|F:\|) Eléments examinés: 233661 Temps écoulé: 1 hour(s), 26 minute(s), 19 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 1 Clé(s) du Registre infectée(s): 9 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 1 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): C:\Windows\System32\ae92979.dll (Trojan.BHO) -> Delete on reboot. Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\TypeLib\{dd695d24-5382-3389-911a-ec4630233000} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{30c8d130-bc9d-3ece-87d8-e184372c3480} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3793cf0a-3133-3190-8005-da6d230159f6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\{3793cf0a-3133-3190-8005-da6d230159f6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3793cf0a-3133-3190-8005-da6d230159f6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3793cf0a-3133-3190-8005-da6d230159f6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\D (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\D.1 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe (Security.Hijack) -> Quarantined and deleted successfully. Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): C:\Windows\System32\ae92979.dll (Trojan.BHO) -> Delete on reboot. J'ai redémarré mon PC et lancé Hijackthis, dont voici le rapport : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:15:36, on 24/11/2009 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18828) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\conime.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\System32\mobsync.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\OrangeHSS\Launcher\Launcher.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Users\MATIA\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\OrangeHSS\systray\systrayapp.exe C:\Program Files\OrangeHSS\Deskboard\deskboard.exe C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe C:\Users\MATIA\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=3081231 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.ke.voila.fr/S/voila?kw= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=3081231 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2 O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [CanalPlayer] C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user') O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\MATIA\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll O13 - Gopher Prefix: O15 - Trusted Zone: *.canalplay.com O15 - Trusted Zone: *.canalplusactive.com O15 - Trusted Zone: http://*.mappy.com O15 - Trusted Zone: http://*.orange.fr O15 - Trusted Zone: http://rw.search.ke.voila.fr O15 - Trusted Zone: http://orange.weborama.fr O15 - Trusted Zone: *.canalplay.com (HKLM) O15 - Trusted Zone: *.canalplusactive.com (HKLM) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\aestsrv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE -- End of file - 11098 bytes Quelle est la suite? -
Gestionnaire des tâches iexplore.exe
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Personne pour m'aider? -
Gestionnaire des tâches iexplore.exe
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Voici le rapport Hijack : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:15:15, on 23/11/2009 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18828) Boot mode: Normal Running processes: c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\ehome\ehtray.exe C:\Program Files\OrangeHSS\Launcher\Launcher.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Users\MATIA\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\conime.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe C:\Program Files\OrangeHSS\systray\systrayapp.exe C:\Program Files\OrangeHSS\Deskboard\deskboard.exe C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files\Windows Live\Toolbar\wltuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\MATIA\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=3081231 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.ke.voila.fr/S/voila?kw= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=3081231 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: D - {3793CF0A-3133-3190-8005-DA6D230159F6} - C:\Windows\system32\ae92979.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2 O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [CanalPlayer] C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user') O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\MATIA\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll O13 - Gopher Prefix: O15 - Trusted Zone: *.canalplay.com O15 - Trusted Zone: *.canalplusactive.com O15 - Trusted Zone: http://*.mappy.com O15 - Trusted Zone: http://*.orange.fr O15 - Trusted Zone: http://rw.search.ke.voila.fr O15 - Trusted Zone: http://orange.weborama.fr O15 - Trusted Zone: *.canalplay.com (HKLM) O15 - Trusted Zone: *.canalplusactive.com (HKLM) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\aestsrv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE -- End of file - 12025 bytes -
Bonjour à tous, J'ai depuis quelques temps remarqué que j'ai de nombreuses lignes iexplore.exe qui sont dans mon gestionnaire des tâches bien que je ne suis pas connecté à internet. Quelquefois ca m'empeche d'ouvrir internet explorer car il y 20 ou 30 iexplore.exe actifs! J'ai McAfee mis à jour mais il ne détecte rien d'anormal. Quelqu'un peut m'aider? Merci par avance.
-
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Re, Je suis toujourq bloqué avec ComboFix. j'ai tenté de l'éxécuter avec ta procédure mais cela n'a pas marché : il fait son point de restauration, puis la fenêtre reste vide (j'ai laissé 20 minutes et RIEN ne se passe) . J'ai fait également un scan avec ewido micro-scanner. Je ne sais pas quoi éliminer. Voici le rapport : __________________________________________________ ewido anti-spyware online scanner http://www.ewido.net __________________________________________________ Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\COM+.log:mdgfrp Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\COM+.log:nectjz Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\COM+.log:oldsxz Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\COM+.log:soaygo Risk: High Name: Downloader.Agent.bc Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\COM+.log:szgcd Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\COM+.log:upqcyu Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\comsetup.log:omiqpn Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\comsetup.log:poehnj Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\comsetup.log:rntkci Risk: High Name: Downloader.Agent.al Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\DtcInstall.log:kqtge Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\DtcInstall.log:qkasqa Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\DtcInstall.log:xsyfbg Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\DtcInstall.log:zzbclw Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\ocgen.log:sjmsfd Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\ocgen.log:wbwush Risk: High Name: Downloader.WinShow.ak Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\ocgen.log:xbcmvz Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\OEWABLog.txt:esczvo Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\OEWABLog.txt:rehxhn Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\OEWABLog.txt:uokyfe Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\OEWABLog.txt:yoxhec Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt:lnisit Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.1:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.1:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.1:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.1:lnisit Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.2:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.2:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.2:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.2:lnisit Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.3:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.3:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.3:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.3:lnisit Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.4:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.4:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.4:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.4:lnisit Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.5:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.5:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.5:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.5:lnisit Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.6:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.6:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.6:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.6:lnisit Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.7:afuze Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.7:cptctg Risk: High Name: Downloader.Small.ajr Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.7:eyypq Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\SchedLgU.Txt.7:lnisit Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setupact.log:ccgvct Risk: High Name: Downloader.Agent.kd Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setupact.log:lgwrm Risk: High Name: Adware.SearchPage Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setupact.log:nvhodd Risk: Medium Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setupact.log:wbsmvq Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setupact.log:yekpiq Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setupact.log:yuizdo Risk: High Name: Downloader.Agent.al Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuperr.log:dblhja Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuperr.log:diijhy Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuperr.log:uvxzeh Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuperr.log:yydvmj Risk: High Name: Downloader.Agent.al Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuplog.txt:delwgl Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuplog.txt:ocdrxb Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuplog.txt:pagaux Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\setuplog.txt:vhllfg Risk: High Name: Downloader.Agent.al Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\svcpack.log:blwzyy Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\svcpack.log:ejtoyy Risk: High Name: Downloader.Agent.ap Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\svcpack.log:fgizt Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\svcpack.log:kxdyaf Risk: High Name: Downloader.Agent.bc Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\svcpack.log:pyiqi Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\svcpack.log:utlnma Risk: High Name: Downloader.Agent.bq Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\svcpack.log:yobsee Risk: High Name: Trojan.Agent.bi Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups\wmsetup.log:rjqvbc Risk: High Name: Trojan.Small Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP645\A0345972.exe Risk: High Name: Downloader.WinShow.az Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP646\A0351200.dll Risk: High Name: Trojan.Small Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP647\A0353308.exe Risk: High Name: Trojan.Small Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP648\A0357951.exe Risk: High Name: Downloader.WinShow.az Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP649\A0359313.dll Risk: High Name: Trojan.Small Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP650\A0364084.exe Risk: High Name: Backdoor.IRCBot.bc Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP650\A0370003.exe Risk: High Name: Trojan.VB.btz Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP650\A0370004.exe Risk: High Name: Backdoor.IRCBot.bc Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP650\A0371866.exe Risk: High Name: Trojan.VB.btz Path: C:\System Volume Information\_restore{90760DB4-9C40-4122-9ED5-679FF4BACE7E}\RP650\A0372361.exe Risk: High -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
1. J'ai relancé Combobix et de nouveau il bloque. Il a commencé a lister, a trouvé un élément, et puis j'ai laissé 20 minutes et RIEN ne se passe... J'ai pourtant au préalable désactivé tea timer (càd décoché tea timer actif dans spybot), désactivé Norton et fermer ZoneAlarm! Je n'arrive à rien avec ComboFix!!!!! 2. Veux-tu que je relance DiagHelp pour uploader C:\upload_moi_NOM-R23KDENUGXQ.tar.gz ?????? -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
1. J'ai effectivement uploadé le rapport à malekal 2. Voici le rapport de F-Sexure (apparemment il n'a rien trouvé): 02/24/08 17:47:40 [info]: BlackLight Engine 1.0.67 initialized 02/24/08 17:47:40 [info]: OS: 5.1 build 2600 () 02/24/08 17:47:40 [Note]: 7019 4 02/24/08 17:47:40 [Note]: 7005 0 02/24/08 17:47:47 [Note]: 7006 0 02/24/08 17:47:47 [Note]: 7011 1472 02/24/08 17:47:47 [Note]: 7026 0 02/24/08 17:47:47 [Note]: 7026 0 02/24/08 17:48:09 [Note]: FSRAW library version 1.7.1024 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:31:42 [Note]: 2000 1012 02/24/08 18:32:27 [Note]: 7007 0 3. Voici le rapport de SDFix : SDFix: Version 1.146 Run by ANDRE Mathias on 2008-02-24 at 18:55 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Checking Services : Killing PID 676 'rxjddnvj.exe' Restoring Windows Registry Values Restoring Windows Default Hosts File Restoring Default Desktop Wallpaper Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\SYSTEM32_2817~1.EXE - Deleted C:\WINDOWS\SYSTEM32_3879~1.EXE - Deleted C:\WINDOWS\SYSTEM32_4605~1.EXE - Deleted C:\WINDOWS\SYSTEM32_4959~1.EXE - Deleted C:\WINDOWS\SYSTEM32_8522~1.EXE - Deleted C:\WINDOWS\SYSTEM32\APIBM.EXE - Deleted C:\WINDOWS\SYSTEM32\APIFU.EXE - Deleted C:\WINDOWS\SYSTEM32\APIPT.EXE - Deleted C:\WINDOWS\SYSTEM32\APPLF32.EXE - Deleted C:\WINDOWS\SYSTEM32\APPWB32.EXE - Deleted C:\WINDOWS\SYSTEM32\ATLEQ32.EXE - Deleted C:\WINDOWS\SYSTEM32\ATLNU.EXE - Deleted C:\WINDOWS\SYSTEM32\CRYE.EXE - Deleted C:\WINDOWS\SYSTEM32\IDLESERV.EXE - Deleted C:\WINDOWS\SYSTEM32\IEJK.EXE - Deleted C:\WINDOWS\SYSTEM32\IEMA.EXE - Deleted C:\WINDOWS\SYSTEM32\IEUT.EXE - Deleted C:\WINDOWS\SYSTEM32\IPHN.EXE - Deleted C:\WINDOWS\SYSTEM32\MSBD.EXE - Deleted C:\WINDOWS\SYSTEM32\MSIM.EXE - Deleted C:\WINDOWS\SYSTEM32\MSLK32.EXE - Deleted C:\WINDOWS\SYSTEM32\MSORCL32.EXE - Deleted C:\WINDOWS\SYSTEM32\MSTS32.EXE - Deleted C:\WINDOWS\SYSTEM32\MSXY.EXE - Deleted C:\WINDOWS\SYSTEM32\NETSF.EXE - Deleted C:\WINDOWS\SYSTEM32\NETTM32.EXE - Deleted C:\WINDOWS\SYSTEM32\NETXU32.EXE - Deleted C:\WINDOWS\SYSTEM32\NTAV32.EXE - Deleted C:\WINDOWS\SYSTEM32\NTFA32.EXE - Deleted C:\WINDOWS\SYSTEM32\NTZD.EXE - Deleted C:\WINDOWS\SYSTEM32\NUSRMGR.EXE - Deleted C:\WINDOWS\SYSTEM32\SDKTU.EXE - Deleted C:\WINDOWS\SYSTEM32\SYSCM.EXE - Deleted C:\WINDOWS\SYSTEM32\SYSGP.EXE - Deleted C:\WINDOWS\SYSTEM32\SYSIJ32.EXE - Deleted C:\WINDOWS\SYSTEM32\WINTT.EXE - Deleted C:\WINDOWS\SYSTEM32\WINZA32.EXE - Deleted C:\WINDOWS\SYSTEM32\ADDAW32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDAX.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDAZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDBA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDBI.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDBI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDBN.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDBW.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDBX.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDBY.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDCD.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDCH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDCI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDCK.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDCT.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDCZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDDF.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDDF32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDDK.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDDL.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDDQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDDZ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDEH.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDEI.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDEM32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDEX.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFC.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFF.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFG.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFN.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDFS32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDGL.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDGN.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDGW32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDHB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDHE.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDHH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDHL.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDHO.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDHX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDIC32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDIR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDIX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDJC32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDJE.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDJG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDJK32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDJM32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDJQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKI.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKK.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKL32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKO32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKP.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKU.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDKX.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLD32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLM.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLN32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLR.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLS.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDLY32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDMH.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDMV32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDNG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDNJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDNN.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDNO.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDNZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOH.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOL.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOM32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOO.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOS32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOV32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOY32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDOZ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDPE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDPG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDPN32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDPT.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDPT32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDPX.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDPZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDQA.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDQD32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDQM.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDQM32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDQU32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDRF32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDRJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDRK32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDRO.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDRU32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDRV32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDSJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDSL.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDSM.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDSQ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDST32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDSV32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDSZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDTD32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDTG.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDTH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDTP32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDUB.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDUI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDUO32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDUQ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDUR.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDUT.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDUT32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDVA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDVB.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDVE.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDVN.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDVV.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDVZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWI.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWQ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWV.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDWW32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDXA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDXB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDXN32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDXU32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDYI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDYJ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDYK32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDYV.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDYZ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDZI.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDZQ.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDZQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDZW.DLL - Deleted C:\WINDOWS\SYSTEM32\ADDZX32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAB.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAC.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAK.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAR.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIAV.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBA.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBB.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBF.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBG.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBL32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBO32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBS32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIBX32.DLL - Deleted C:\WINDOWS\SYSTEM32\APICB32.DLL - Deleted C:\WINDOWS\SYSTEM32\APICH32.DLL - Deleted C:\WINDOWS\SYSTEM32\APICI.DLL - Deleted C:\WINDOWS\SYSTEM32\APICJ.DLL - Deleted C:\WINDOWS\SYSTEM32\APICM32.DLL - Deleted C:\WINDOWS\SYSTEM32\APICN.DLL - Deleted C:\WINDOWS\SYSTEM32\APICY.DLL - Deleted C:\WINDOWS\SYSTEM32\APIDC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIDE32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIDR.DLL - Deleted C:\WINDOWS\SYSTEM32\APIDR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIDT.DLL - Deleted C:\WINDOWS\SYSTEM32\APIDZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIEH.DLL - Deleted C:\WINDOWS\SYSTEM32\APIEK.DLL - Deleted C:\WINDOWS\SYSTEM32\APIEN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIEO32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIEP.DLL - Deleted C:\WINDOWS\SYSTEM32\APIET32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIFB.DLL - Deleted C:\WINDOWS\SYSTEM32\APIFF32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIFI.DLL - Deleted C:\WINDOWS\SYSTEM32\APIFL32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIFO.DLL - Deleted C:\WINDOWS\SYSTEM32\APIFP32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIFQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGC.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGG.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGJ.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGO.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGO32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGS32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGU32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIGY.DLL - Deleted C:\WINDOWS\SYSTEM32\APIHJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIHN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIHO32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIIA.DLL - Deleted C:\WINDOWS\SYSTEM32\APIIC.DLL - Deleted C:\WINDOWS\SYSTEM32\APIIN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIIV.DLL - Deleted C:\WINDOWS\SYSTEM32\APIIX.DLL - Deleted C:\WINDOWS\SYSTEM32\APIJA32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIJZ.DLL - Deleted C:\WINDOWS\SYSTEM32\APIKC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIKE32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIKP32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIKU.DLL - Deleted C:\WINDOWS\SYSTEM32\APIKZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APILD.DLL - Deleted C:\WINDOWS\SYSTEM32\APILD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APILE.DLL - Deleted C:\WINDOWS\SYSTEM32\APILG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APILJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APILM.DLL - Deleted C:\WINDOWS\SYSTEM32\APILM32.DLL - Deleted C:\WINDOWS\SYSTEM32\APILU.DLL - Deleted C:\WINDOWS\SYSTEM32\APILW32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIMC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIME.DLL - Deleted C:\WINDOWS\SYSTEM32\APIMS.DLL - Deleted C:\WINDOWS\SYSTEM32\APIMT.DLL - Deleted C:\WINDOWS\SYSTEM32\APIMT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIMU32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIMV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIMW32.DLL - Deleted C:\WINDOWS\SYSTEM32\APINA32.DLL - Deleted C:\WINDOWS\SYSTEM32\APINF.DLL - Deleted C:\WINDOWS\SYSTEM32\APING.DLL - Deleted C:\WINDOWS\SYSTEM32\APINI32.DLL - Deleted C:\WINDOWS\SYSTEM32\APINS32.DLL - Deleted C:\WINDOWS\SYSTEM32\APINZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIOB32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIOF32.DLL - Deleted C:\WINDOWS\SYSTEM32\APION32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIPD.DLL - Deleted C:\WINDOWS\SYSTEM32\APIPP.DLL - Deleted C:\WINDOWS\SYSTEM32\APIPQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIPV.DLL - Deleted C:\WINDOWS\SYSTEM32\APIPZ.DLL - Deleted C:\WINDOWS\SYSTEM32\APIQA.DLL - Deleted C:\WINDOWS\SYSTEM32\APIQD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIQG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIQK.DLL - Deleted C:\WINDOWS\SYSTEM32\APIQN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIQU.DLL - Deleted C:\WINDOWS\SYSTEM32\APIQW32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRA.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRO.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRU.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRY32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIRZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APISA32.DLL - Deleted C:\WINDOWS\SYSTEM32\APISB.DLL - Deleted C:\WINDOWS\SYSTEM32\APISD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APISF32.DLL - Deleted C:\WINDOWS\SYSTEM32\APISJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APISK.DLL - Deleted C:\WINDOWS\SYSTEM32\APISO.DLL - Deleted C:\WINDOWS\SYSTEM32\APISO32.DLL - Deleted C:\WINDOWS\SYSTEM32\APISV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APISY.DLL - Deleted C:\WINDOWS\SYSTEM32\APITD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APITG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APITU32.DLL - Deleted C:\WINDOWS\SYSTEM32\APITV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APITX32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIUA.DLL - Deleted C:\WINDOWS\SYSTEM32\APIUI.DLL - Deleted C:\WINDOWS\SYSTEM32\APIUJ.DLL - Deleted C:\WINDOWS\SYSTEM32\APIUR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIUT.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVH32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVI32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVM.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVM32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVU32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVW32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIVZ.DLL - Deleted C:\WINDOWS\SYSTEM32\APIWC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIWL.DLL - Deleted C:\WINDOWS\SYSTEM32\APIWM.DLL - Deleted C:\WINDOWS\SYSTEM32\APIWO.DLL - Deleted C:\WINDOWS\SYSTEM32\APIWS.DLL - Deleted C:\WINDOWS\SYSTEM32\APIWW.DLL - Deleted C:\WINDOWS\SYSTEM32\APIWX32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXB32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXH.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXH32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXI32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXK32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXO.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXU32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIXZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIYA32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIYL32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIYM32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIYN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIYR.DLL - Deleted C:\WINDOWS\SYSTEM32\APIYX.DLL - Deleted C:\WINDOWS\SYSTEM32\APIZB32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIZE.DLL - Deleted C:\WINDOWS\SYSTEM32\APIZI.DLL - Deleted C:\WINDOWS\SYSTEM32\APIZI32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIZM32.DLL - Deleted C:\WINDOWS\SYSTEM32\APIZY32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPAA.DLL - Deleted C:\WINDOWS\SYSTEM32\APPAA32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPAB.DLL - Deleted C:\WINDOWS\SYSTEM32\APPAF32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPAG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPAK.DLL - Deleted C:\WINDOWS\SYSTEM32\APPAO.DLL - Deleted C:\WINDOWS\SYSTEM32\APPBA.DLL - Deleted C:\WINDOWS\SYSTEM32\APPBB.DLL - Deleted C:\WINDOWS\SYSTEM32\APPBG.DLL - Deleted C:\WINDOWS\SYSTEM32\APPBN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPBP.DLL - Deleted C:\WINDOWS\SYSTEM32\APPBV.DLL - Deleted C:\WINDOWS\SYSTEM32\APPCB.DLL - Deleted C:\WINDOWS\SYSTEM32\APPCB32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPCD.DLL - Deleted C:\WINDOWS\SYSTEM32\APPCR.DLL - Deleted C:\WINDOWS\SYSTEM32\APPCS32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDA.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDE.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDH.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDH32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDM32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDO.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDP.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDU32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPDW.DLL - Deleted C:\WINDOWS\SYSTEM32\APPEE32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPEN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPET32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPEZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPFE.DLL - Deleted C:\WINDOWS\SYSTEM32\APPFO.DLL - Deleted C:\WINDOWS\SYSTEM32\APPFP32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPFT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPFU.DLL - Deleted C:\WINDOWS\SYSTEM32\APPFX.DLL - Deleted C:\WINDOWS\SYSTEM32\APPFZ.DLL - Deleted C:\WINDOWS\SYSTEM32\APPGF32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPGM.DLL - Deleted C:\WINDOWS\SYSTEM32\APPGP32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPGY.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHB32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHF.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHF32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHO32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHP.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHW.DLL - Deleted C:\WINDOWS\SYSTEM32\APPHZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPIS32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPIT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJC.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJE32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJI32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJL.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJM.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJP32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJS.DLL - Deleted C:\WINDOWS\SYSTEM32\APPJZ.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKA.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKE.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKF32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKH.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKK.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKM.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKO.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKP32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPKZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPLC.DLL - Deleted C:\WINDOWS\SYSTEM32\APPLG32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPLR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPLS32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPLV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPLX.DLL - Deleted C:\WINDOWS\SYSTEM32\APPMJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPML.DLL - Deleted C:\WINDOWS\SYSTEM32\APPML32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPMO32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPMU32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPMW.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNA.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNI.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNL32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNO.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNP32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNU.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNX32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNY.DLL - Deleted C:\WINDOWS\SYSTEM32\APPNZ.DLL - Deleted C:\WINDOWS\SYSTEM32\APPOD.DLL - Deleted C:\WINDOWS\SYSTEM32\APPOD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPOH32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPOI.DLL - Deleted C:\WINDOWS\SYSTEM32\APPOJ.DLL - Deleted C:\WINDOWS\SYSTEM32\APPOK32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPOW32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPA.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPE.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPE32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPG.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPJ.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPO.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPP.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPR.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPW.DLL - Deleted C:\WINDOWS\SYSTEM32\APPPX.DLL - Deleted C:\WINDOWS\SYSTEM32\APPQA32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPQE32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPQF.DLL - Deleted C:\WINDOWS\SYSTEM32\APPQP.DLL - Deleted C:\WINDOWS\SYSTEM32\APPQT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPQV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPQZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPRD.DLL - Deleted C:\WINDOWS\SYSTEM32\APPRE.DLL - Deleted C:\WINDOWS\SYSTEM32\APPRN.DLL - Deleted C:\WINDOWS\SYSTEM32\APPRY.DLL - Deleted C:\WINDOWS\SYSTEM32\APPRZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPSD.DLL - Deleted C:\WINDOWS\SYSTEM32\APPSE.DLL - Deleted C:\WINDOWS\SYSTEM32\APPSE32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPSL32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPSO.DLL - Deleted C:\WINDOWS\SYSTEM32\APPSQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPSV32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTB.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTD.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTF.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTH32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTK32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTS.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTX32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPTY32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPUG.DLL - Deleted C:\WINDOWS\SYSTEM32\APPUL32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPUS32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPUT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPUY32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPVC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPVT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPVX32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPWD.DLL - Deleted C:\WINDOWS\SYSTEM32\APPWJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPWY.DLL - Deleted C:\WINDOWS\SYSTEM32\APPWY32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXC32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXE.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXH.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXI32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXJ.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPXZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYB.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYD32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYI32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYR.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYT32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYV.DLL - Deleted C:\WINDOWS\SYSTEM32\APPYZ.DLL - Deleted C:\WINDOWS\SYSTEM32\APPZA.DLL - Deleted C:\WINDOWS\SYSTEM32\APPZC.DLL - Deleted C:\WINDOWS\SYSTEM32\APPZN32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPZP.DLL - Deleted C:\WINDOWS\SYSTEM32\APPZR32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPZY32.DLL - Deleted C:\WINDOWS\SYSTEM32\APPZZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLAB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLAD.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLAE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLAF32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLAL32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLAM32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBH.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBO32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBT.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBW.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBX.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLBZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLCH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLCK.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLCL.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLCM.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLCU.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLCV.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLCZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLDB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLDD32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLDG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLEA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLEB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLEE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLEG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLEJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLEL32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLER.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLET.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLET32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLEV32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFC.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFF.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFH.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFJ.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFN.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFO.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFQ.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFT.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLFT32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLGB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLGK32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLGS32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLGV32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLGX.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLGZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLHD32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLHG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLHR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLHS.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLHS32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLHW.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLHX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLID32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLIP32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLIT.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLIW.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLIX.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLIY.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLIY32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJF.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJK.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJP.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJU32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJW32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLJX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLKH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLKI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLKM32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLKN32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLLA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLLC32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLLL32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLLW.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLME.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLMN32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLMP.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLMV.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLMX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLMZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNA.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNC.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNC32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNK.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNL.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNP32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNR.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNV.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNX.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLNZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLOI.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLOJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLOP.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLOT.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLOX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLOZ.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLOZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPC.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPJ.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPL32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPT.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPU.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLPX.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLQC.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLQM.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLQP.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLQQ.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLQX.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLQY.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLRD32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLRM.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLRR.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLRT.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLRU.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLRX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSC.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSD.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSK.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSS.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSV.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSW32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSY.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLSZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLTG32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLTJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLTM.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLTS.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLTU32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLUB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLUI32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLUJ.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLUO.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLUR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLUU.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLVE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLVQ.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLVR.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLVY32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLVZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLWA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLWC32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLWJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLWU32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLWZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLXC32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLXN32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLXO.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLXR32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLXT.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLXT32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLXX32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLYA32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLYB32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLYE.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLYE32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLYH32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLYN32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLZK32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLZP32.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLZX.DLL - Deleted C:\WINDOWS\SYSTEM32\ATLZZ.DLL - Deleted C:\WINDOWS\SYSTEM32\BIKGZ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRAC32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRAI32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRAK.DLL - Deleted C:\WINDOWS\SYSTEM32\CRAL32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRAS.DLL - Deleted C:\WINDOWS\SYSTEM32\CRAT.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBA.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBG32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBM.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBM32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBN32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBO.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBO32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRBR32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRCG32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRCH32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRCM32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRCO32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRCR32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRCT32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDE.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDE32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDF32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDL32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDR.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDS32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDT.DLL - Deleted C:\WINDOWS\SYSTEM32\CRDX32.DLL - Deleted C:\WINDOWS\SYSTEM32\CREB.DLL - Deleted C:\WINDOWS\SYSTEM32\CREC32.DLL - Deleted C:\WINDOWS\SYSTEM32\CREG32.DLL - Deleted C:\WINDOWS\SYSTEM32\CREK.DLL - Deleted C:\WINDOWS\SYSTEM32\CREL.DLL - Deleted C:\WINDOWS\SYSTEM32\CREQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRES32.DLL - Deleted C:\WINDOWS\SYSTEM32\CREX32.DLL - Deleted C:\WINDOWS\SYSTEM32\CREY32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRFD32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRFF32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRFP.DLL - Deleted C:\WINDOWS\SYSTEM32\CRFP32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGB.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGB32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGJ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGP.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGP32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGR.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGT32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRGW32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHB32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHD32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHN32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHO.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHP32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHU32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHV.DLL - Deleted C:\WINDOWS\SYSTEM32\CRHZ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRIA.DLL - Deleted C:\WINDOWS\SYSTEM32\CRID.DLL - Deleted C:\WINDOWS\SYSTEM32\CRII.DLL - Deleted C:\WINDOWS\SYSTEM32\CRII32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRIJ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRIL.DLL - Deleted C:\WINDOWS\SYSTEM32\CRIN.DLL - Deleted C:\WINDOWS\SYSTEM32\CRJD.DLL - Deleted C:\WINDOWS\SYSTEM32\CRJF.DLL - Deleted C:\WINDOWS\SYSTEM32\CRJH.DLL - Deleted C:\WINDOWS\SYSTEM32\CRJL.DLL - Deleted C:\WINDOWS\SYSTEM32\CRJO.DLL - Deleted C:\WINDOWS\SYSTEM32\CRJU.DLL - Deleted C:\WINDOWS\SYSTEM32\CRJV32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRKG.DLL - Deleted C:\WINDOWS\SYSTEM32\CRKG32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRKI32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRKO32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRKY.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLE.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLF.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLF32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLH32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLK.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLT32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLU.DLL - Deleted C:\WINDOWS\SYSTEM32\CRLX.DLL - Deleted C:\WINDOWS\SYSTEM32\CRMF.DLL - Deleted C:\WINDOWS\SYSTEM32\CRMF32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRMG32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRMW32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRNK32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRNU.DLL - Deleted C:\WINDOWS\SYSTEM32\CRNV.DLL - Deleted C:\WINDOWS\SYSTEM32\CRNW.DLL - Deleted C:\WINDOWS\SYSTEM32\CRNW32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRNZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CROG32.DLL - Deleted C:\WINDOWS\SYSTEM32\CROH32.DLL - Deleted C:\WINDOWS\SYSTEM32\CROI.DLL - Deleted C:\WINDOWS\SYSTEM32\CROJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CROQ.DLL - Deleted C:\WINDOWS\SYSTEM32\CROR.DLL - Deleted C:\WINDOWS\SYSTEM32\CROT.DLL - Deleted C:\WINDOWS\SYSTEM32\CROT32.DLL - Deleted C:\WINDOWS\SYSTEM32\CROW.DLL - Deleted C:\WINDOWS\SYSTEM32\CROX.DLL - Deleted C:\WINDOWS\SYSTEM32\CROY32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRPA.DLL - Deleted C:\WINDOWS\SYSTEM32\CRPC32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRPH.DLL - Deleted C:\WINDOWS\SYSTEM32\CRPH32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRPJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRPS.DLL - Deleted C:\WINDOWS\SYSTEM32\CRPZ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQB32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQD32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQG.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQH.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQI.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQI32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQK.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQN.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQU.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQU32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRQV32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRG32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRH.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRM32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRO.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRO32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRP32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRQ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRT32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRRV.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSA.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSB32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSD32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSF32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSI32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSO.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSW.DLL - Deleted C:\WINDOWS\SYSTEM32\CRSY32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTC.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTH32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTI32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTL32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTN32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTX32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRTY.DLL - Deleted C:\WINDOWS\SYSTEM32\CRUL32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRUN.DLL - Deleted C:\WINDOWS\SYSTEM32\CRUR.DLL - Deleted C:\WINDOWS\SYSTEM32\CRUV32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRVA.DLL - Deleted C:\WINDOWS\SYSTEM32\CRVC32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRVF32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRVI.DLL - Deleted C:\WINDOWS\SYSTEM32\CRVL32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRVN32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRVX.DLL - Deleted C:\WINDOWS\SYSTEM32\CRWG.DLL - Deleted C:\WINDOWS\SYSTEM32\CRWM.DLL - Deleted C:\WINDOWS\SYSTEM32\CRWP32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRWQ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRWU.DLL - Deleted C:\WINDOWS\SYSTEM32\CRWW.DLL - Deleted C:\WINDOWS\SYSTEM32\CRXA32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRXM.DLL - Deleted C:\WINDOWS\SYSTEM32\CRXS32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRXT.DLL - Deleted C:\WINDOWS\SYSTEM32\CRXX32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRXY32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYC.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYE.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYK32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYM.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYR.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYR32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRYT32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRZB32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRZJ.DLL - Deleted C:\WINDOWS\SYSTEM32\CRZS32.DLL - Deleted C:\WINDOWS\SYSTEM32\CRZY32.DLL - Deleted C:\WINDOWS\SYSTEM32\CTAMQ.DLL - Deleted C:\WINDOWS\SYSTEM32\CXBFA.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AB.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AB32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AD.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AD32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AK32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AM.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AS.DLL - Deleted C:\WINDOWS\SYSTEM32\D3AY32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3BB.DLL - Deleted C:\WINDOWS\SYSTEM32\D3BH32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3BR.DLL - Deleted C:\WINDOWS\SYSTEM32\D3BV.DLL - Deleted C:\WINDOWS\SYSTEM32\D3BW.DLL - Deleted C:\WINDOWS\SYSTEM32\D3CC32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3CD.DLL - Deleted C:\WINDOWS\SYSTEM32\D3CJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3CR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DD.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DE.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DE32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DI32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DK32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DN32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3DW32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3EE32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3EQ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3ET32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3EV32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3FK32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3FN.DLL - Deleted C:\WINDOWS\SYSTEM32\D3FS.DLL - Deleted C:\WINDOWS\SYSTEM32\D3FV32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3GG.DLL - Deleted C:\WINDOWS\SYSTEM32\D3GH32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3GQ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3GS.DLL - Deleted C:\WINDOWS\SYSTEM32\D3GS32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3GU32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3GX32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3HB32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3HF.DLL - Deleted C:\WINDOWS\SYSTEM32\D3HI.DLL - Deleted C:\WINDOWS\SYSTEM32\D3HQ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3HR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3HX32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3IA.DLL - Deleted C:\WINDOWS\SYSTEM32\D3IA32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3IE32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3IR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3IV32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JB.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JB32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JC32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JG32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JH.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JI32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JJ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JK.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JM.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3JU.DLL - Deleted C:\WINDOWS\SYSTEM32\D3KD.DLL - Deleted C:\WINDOWS\SYSTEM32\D3KE32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3KI32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3KM32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3KP32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3KQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3KU.DLL - Deleted C:\WINDOWS\SYSTEM32\D3LG32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3LO32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3LP.DLL - Deleted C:\WINDOWS\SYSTEM32\D3LR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3LU32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3LX.DLL - Deleted C:\WINDOWS\SYSTEM32\D3LX32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3MB32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3ME.DLL - Deleted C:\WINDOWS\SYSTEM32\D3MH.DLL - Deleted C:\WINDOWS\SYSTEM32\D3MI32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3MJ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3MM.DLL - Deleted C:\WINDOWS\SYSTEM32\D3MS32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3MU.DLL - Deleted C:\WINDOWS\SYSTEM32\D3NC.DLL - Deleted C:\WINDOWS\SYSTEM32\D3NC32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3ND32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3NF32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3NH32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3NI32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3NR.DLL - Deleted C:\WINDOWS\SYSTEM32\D3NT.DLL - Deleted C:\WINDOWS\SYSTEM32\D3OA32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3OB.DLL - Deleted C:\WINDOWS\SYSTEM32\D3OE32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3OL.DLL - Deleted C:\WINDOWS\SYSTEM32\D3OR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3OS32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3OU32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3PD.DLL - Deleted C:\WINDOWS\SYSTEM32\D3PI.DLL - Deleted C:\WINDOWS\SYSTEM32\D3PO.DLL - Deleted C:\WINDOWS\SYSTEM32\D3PT32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3PU32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3PW32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3QO32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3QP.DLL - Deleted C:\WINDOWS\SYSTEM32\D3QQ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3QR.DLL - Deleted C:\WINDOWS\SYSTEM32\D3QS.DLL - Deleted C:\WINDOWS\SYSTEM32\D3QT.DLL - Deleted C:\WINDOWS\SYSTEM32\D3QU32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3RF.DLL - Deleted C:\WINDOWS\SYSTEM32\D3RS.DLL - Deleted C:\WINDOWS\SYSTEM32\D3RU.DLL - Deleted C:\WINDOWS\SYSTEM32\D3RW.DLL - Deleted C:\WINDOWS\SYSTEM32\D3SJ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3SN32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3SU.DLL - Deleted C:\WINDOWS\SYSTEM32\D3TD32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3TI32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3TN.DLL - Deleted C:\WINDOWS\SYSTEM32\D3TR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3TW.DLL - Deleted C:\WINDOWS\SYSTEM32\D3TY32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3UB.DLL - Deleted C:\WINDOWS\SYSTEM32\D3UQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VC.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VD.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VD32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VH.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VN.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VR.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VV.DLL - Deleted C:\WINDOWS\SYSTEM32\D3VZ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3WC.DLL - Deleted C:\WINDOWS\SYSTEM32\D3WI.DLL - Deleted C:\WINDOWS\SYSTEM32\D3WR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3WW.DLL - Deleted C:\WINDOWS\SYSTEM32\D3XA.DLL - Deleted C:\WINDOWS\SYSTEM32\D3XG.DLL - Deleted C:\WINDOWS\SYSTEM32\D3XO32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3XS32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3XU32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3XV32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3XZ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YC.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YI.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YI32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YK.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YL32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YQ.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YR32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YS.DLL - Deleted C:\WINDOWS\SYSTEM32\D3YX.DLL - Deleted C:\WINDOWS\SYSTEM32\D3ZH.DLL - Deleted C:\WINDOWS\SYSTEM32\D3ZK32.DLL - Deleted C:\WINDOWS\SYSTEM32\D3ZL32.DLL - Deleted C:\WINDOWS\SYSTEM32\DLFUU.DLL - Deleted C:\WINDOWS\SYSTEM32\EUCDJ.DLL - Deleted C:\WINDOWS\SYSTEM32\EYOZR.DLL - Deleted C:\WINDOWS\SYSTEM32\FLOJD.DLL - Deleted C:\WINDOWS\SYSTEM32\FPGRT.DLL - Deleted C:\WINDOWS\SYSTEM32\FRWXL.DLL - Deleted C:\WINDOWS\SYSTEM32\HPNFN.DLL - Deleted C:\WINDOWS\SYSTEM32\HYVGK.DLL - Deleted C:\WINDOWS\SYSTEM32\IAXAL.DLL - Deleted C:\WINDOWS\SYSTEM32\IEAA.DLL - Deleted C:\WINDOWS\SYSTEM32\IEAB.DLL - Deleted C:\WINDOWS\SYSTEM32\IEAD.DLL - Deleted C:\WINDOWS\SYSTEM32\IEAF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEAO.DLL - Deleted C:\WINDOWS\SYSTEM32\IEAS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBA.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBG.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBH.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBL.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBM.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEBX.DLL - Deleted C:\WINDOWS\SYSTEM32\IECD.DLL - Deleted C:\WINDOWS\SYSTEM32\IECF.DLL - Deleted C:\WINDOWS\SYSTEM32\IECF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IECK.DLL - Deleted C:\WINDOWS\SYSTEM32\IECL32.DLL - Deleted C:\WINDOWS\SYSTEM32\IECM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IECP.DLL - Deleted C:\WINDOWS\SYSTEM32\IECR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IECU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IECV.DLL - Deleted C:\WINDOWS\SYSTEM32\IECW32.DLL - Deleted C:\WINDOWS\SYSTEM32\IECX.DLL - Deleted C:\WINDOWS\SYSTEM32\IECZ.DLL - Deleted C:\WINDOWS\SYSTEM32\IEDB32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEDD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEDF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEDH.DLL - Deleted C:\WINDOWS\SYSTEM32\IEDM.DLL - Deleted C:\WINDOWS\SYSTEM32\IEDV32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEEG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEEM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEEN.DLL - Deleted C:\WINDOWS\SYSTEM32\IEEQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEEV32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEEY.DLL - Deleted C:\WINDOWS\SYSTEM32\IEEZ.DLL - Deleted C:\WINDOWS\SYSTEM32\IEFA.DLL - Deleted C:\WINDOWS\SYSTEM32\IEFD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEFF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEFG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEFI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEFU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEFZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGL.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGP32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGT.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGU.DLL - Deleted C:\WINDOWS\SYSTEM32\IEGX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEHD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEHL32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEHM.DLL - Deleted C:\WINDOWS\SYSTEM32\IEHP32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEHQ.DLL - Deleted C:\WINDOWS\SYSTEM32\IEHW.DLL - Deleted C:\WINDOWS\SYSTEM32\IEHW32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEIE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEIF.DLL - Deleted C:\WINDOWS\SYSTEM32\IEIJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEIN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEIX.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJB32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJF.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJL.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJN.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJP32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJU.DLL - Deleted C:\WINDOWS\SYSTEM32\IEJY.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKE.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKP.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEKV32.DLL - Deleted C:\WINDOWS\SYSTEM32\IELI.DLL - Deleted C:\WINDOWS\SYSTEM32\IELJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IELQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IELY32.DLL - Deleted C:\WINDOWS\SYSTEM32\IELZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMC32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMP32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMS.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMW32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMZ.DLL - Deleted C:\WINDOWS\SYSTEM32\IEMZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IENC32.DLL - Deleted C:\WINDOWS\SYSTEM32\IENG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IENL32.DLL - Deleted C:\WINDOWS\SYSTEM32\IENN.DLL - Deleted C:\WINDOWS\SYSTEM32\IENR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IENV.DLL - Deleted C:\WINDOWS\SYSTEM32\IEOA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEOF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEOG.DLL - Deleted C:\WINDOWS\SYSTEM32\IEOJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEON.DLL - Deleted C:\WINDOWS\SYSTEM32\IEOT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEPT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEPW.DLL - Deleted C:\WINDOWS\SYSTEM32\IEQA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEQD.DLL - Deleted C:\WINDOWS\SYSTEM32\IEQQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEQR.DLL - Deleted C:\WINDOWS\SYSTEM32\IEQW.DLL - Deleted C:\WINDOWS\SYSTEM32\IEQW32.DLL - Deleted C:\WINDOWS\SYSTEM32\IERE.DLL - Deleted C:\WINDOWS\SYSTEM32\IERF.DLL - Deleted C:\WINDOWS\SYSTEM32\IERG.DLL - Deleted C:\WINDOWS\SYSTEM32\IERU.DLL - Deleted C:\WINDOWS\SYSTEM32\IERW32.DLL - Deleted C:\WINDOWS\SYSTEM32\IESA.DLL - Deleted C:\WINDOWS\SYSTEM32\IESM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IESS.DLL - Deleted C:\WINDOWS\SYSTEM32\IESU.DLL - Deleted C:\WINDOWS\SYSTEM32\IESU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IESV32.DLL - Deleted C:\WINDOWS\SYSTEM32\IESZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IETK.DLL - Deleted C:\WINDOWS\SYSTEM32\IETK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IETQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IETR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IETT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEUI.DLL - Deleted C:\WINDOWS\SYSTEM32\IEUI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEUP32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEUT.DLL - Deleted C:\WINDOWS\SYSTEM32\IEUU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVG.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVH32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVI.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVP.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVP32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEVX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEWD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEWE.DLL - Deleted C:\WINDOWS\SYSTEM32\IEWE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEWG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEWK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEWP.DLL - Deleted C:\WINDOWS\SYSTEM32\IEWY32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEXA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEXB.DLL - Deleted C:\WINDOWS\SYSTEM32\IEXJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEXM.DLL - Deleted C:\WINDOWS\SYSTEM32\IEXT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEXU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEXY.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYH.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYK.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYL32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYN.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEYU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEZA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEZD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEZG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEZK.DLL - Deleted C:\WINDOWS\SYSTEM32\IEZM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IEZS.DLL - Deleted C:\WINDOWS\SYSTEM32\INTR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPAE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPAK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPAM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPAN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPAO.DLL - Deleted C:\WINDOWS\SYSTEM32\IPAR.DLL - Deleted C:\WINDOWS\SYSTEM32\IPAX.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBC32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBF.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBJ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBQ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBY.DLL - Deleted C:\WINDOWS\SYSTEM32\IPBY32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPCD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPCT.DLL - Deleted C:\WINDOWS\SYSTEM32\IPCT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPCZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDA.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDC.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDQ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPDY.DLL - Deleted C:\WINDOWS\SYSTEM32\IPEA.DLL - Deleted C:\WINDOWS\SYSTEM32\IPEA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPEE.DLL - Deleted C:\WINDOWS\SYSTEM32\IPEH32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPES32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPEV.DLL - Deleted C:\WINDOWS\SYSTEM32\IPEX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPEY.DLL - Deleted C:\WINDOWS\SYSTEM32\IPFN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPFQ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPFQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPFS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPGG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPGI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPGJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPGY.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHB.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHB32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHQ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHU.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHW.DLL - Deleted C:\WINDOWS\SYSTEM32\IPHY.DLL - Deleted C:\WINDOWS\SYSTEM32\IPIA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPIB.DLL - Deleted C:\WINDOWS\SYSTEM32\IPIK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPIM.DLL - Deleted C:\WINDOWS\SYSTEM32\IPIN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPJD.DLL - Deleted C:\WINDOWS\SYSTEM32\IPJG.DLL - Deleted C:\WINDOWS\SYSTEM32\IPJJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPJO.DLL - Deleted C:\WINDOWS\SYSTEM32\IPJS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPKI.DLL - Deleted C:\WINDOWS\SYSTEM32\IPKL.DLL - Deleted C:\WINDOWS\SYSTEM32\IPKO32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPKR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPKU.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLD.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLF.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLH32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLL.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLS.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLU.DLL - Deleted C:\WINDOWS\SYSTEM32\IPLW32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPMA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPMB32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPME.DLL - Deleted C:\WINDOWS\SYSTEM32\IPMN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPMS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPMW32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPMX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPNG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPNM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPNO.DLL - Deleted C:\WINDOWS\SYSTEM32\IPNZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOA.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPON.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOO.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOO32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOR.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOU.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPOY32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPPC32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPPH32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPPL32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPPO32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPPR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPPX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQD.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQL.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQN32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPQS.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRC32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRE.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRH32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRL.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRM32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRP.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRU.DLL - Deleted C:\WINDOWS\SYSTEM32\IPRY.DLL - Deleted C:\WINDOWS\SYSTEM32\IPSD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPSO.DLL - Deleted C:\WINDOWS\SYSTEM32\IPTC32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPTQ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPTT32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPTX.DLL - Deleted C:\WINDOWS\SYSTEM32\IPTX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPTZ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUB32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUE.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUF.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUI32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUV32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPUX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPVD.DLL - Deleted C:\WINDOWS\SYSTEM32\IPVF32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPVN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPVR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPVS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPVW.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWC.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWK.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWO.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWP32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWR32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWT.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWU32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWY.DLL - Deleted C:\WINDOWS\SYSTEM32\IPWY32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPXA32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPXG32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPXJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPXK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPXQ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPXX32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPYE.DLL - Deleted C:\WINDOWS\SYSTEM32\IPYE32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPYH32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPYJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPYN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPZD32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPZJ.DLL - Deleted C:\WINDOWS\SYSTEM32\IPZK32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPZN.DLL - Deleted C:\WINDOWS\SYSTEM32\IPZS32.DLL - Deleted C:\WINDOWS\SYSTEM32\IPZZ.DLL - Deleted C:\WINDOWS\SYSTEM32\IRZDS.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAAC.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAAP32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAAR32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAAX.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAAZ.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABA32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABB32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABE32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABI.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABK32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABM.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABS.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABT.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVABU32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACB.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACH.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACL32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACS32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACU32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACV32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACX.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACX32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVACY.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVADC32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVADD.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVADE32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVADF.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVADZ.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEB32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEC.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEG32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEH.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEO.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEO32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAEZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAFT32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAFU32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAGB.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAGD32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAGO.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAGP32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAHA.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAHB.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAHC.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAHH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAHI32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAHY.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAIA.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAIB.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAII.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAIT32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAIU32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAIW.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAIZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAJB32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAJI32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAJO.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAJU.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAJW.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAKC32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAKE32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAKK32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAKP.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAKP32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAKW.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAKW32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVALS32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVALT.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVALU.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVALX32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVALY32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAMB32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAMM.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAMS32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAMZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVANH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVANJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVANW.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAOH.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAOH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAOJ.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAOQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAOS.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAOV.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPC32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPI.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPN32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPP32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPV.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPV32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAPY.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQA.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQB32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQC.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQC32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQF.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQJ.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQL32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQX.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAQX32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVARE32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVARJ.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVARK.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVARK32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVARP.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVARZ.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVASA.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVASC.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVASF32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVASK32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVASM32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVASX.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVATA32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVATE32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVATG32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVATO32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVATS.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVATS32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVATX.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUC32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUE.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUF32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUG.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUH.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUI32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUJ.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAUR32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAVH.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAVH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWC32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWE.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWE32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWF.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWG.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWI.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAWO.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAXG.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAXH.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAXH32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAYF32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAYH.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAYM32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAYN.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAYP.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAYX.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAYX32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZA.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZG32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZK.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZP32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZV.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZV32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZX.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZY32.DLL - Deleted C:\WINDOWS\SYSTEM32\JAVAZZ.DLL - Deleted C:\WINDOWS\SYSTEM32\JMZPK.DLL - Deleted C:\WINDOWS\SYSTEM32\KBYGY.DLL - Deleted C:\WINDOWS\SYSTEM32\KHGXP.DLL - Deleted C:\WINDOWS\SYSTEM32\KTKCL.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCAD.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCAI.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCAO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCAU32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCAX32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCAY32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCAZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCBC32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCBE32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCBH.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCBK.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCBV.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCBW32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCBY.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCCA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCCJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCCK32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCCO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCCW.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCDD.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCDF.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCDI.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCDI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCDJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCDL32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCDY32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCEA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCEH.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCEI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCEN32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCET.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCFL32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCFS32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGA.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGB32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGM32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGU32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGZ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCGZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCHC32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCHD32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCHE.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCHO.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCHQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCHT.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCHZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIC32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIF32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIK.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIT.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIW.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCIY.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCJA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCJE.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCJN.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCJS.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCJZ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCKD32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCKI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCKM.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCKO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCKT.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCLA.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCLD32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCLJ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCLN.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCLQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCMA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCMB.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCMF.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCMF32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCMI.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCMZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCNJ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCNP.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCNP32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCNU.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCNY32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCOI.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCOL32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCOY32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCPG32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCPH.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCPH32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCPO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCPU32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQB.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQD.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQG32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQK32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQP32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQS.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQV.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQZ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCQZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCRF.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCRK32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCRL.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCRP.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCRX.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCSB32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCSD.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCSH32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCSP.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCSQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCSS.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCTA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCTI.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCTX32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCUA.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCUE32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCUN.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCUS32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCUV.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCUW.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCUZ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCVB32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCVD.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCVG32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCVH.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCVI.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCVT32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCWK32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCWP.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCWS.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCWU32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCWW.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCWY32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCXH32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCXM.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCXP.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCXS32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCXT32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCXV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCXW32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYH32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYK.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYL32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYN32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCYW.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCZE32.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCZG.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCZH.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCZM.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCZR.DLL - Deleted C:\WINDOWS\SYSTEM32\MFCZT.DLL - Deleted C:\WINDOWS\SYSTEM32\MSAA.DLL - Deleted C:\WINDOWS\SYSTEM32\MSAD32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSAI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSAJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSAQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSAY.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBB32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBD.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBD32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBF32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBT.DLL - Deleted C:\WINDOWS\SYSTEM32\MSBW32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCK.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCP32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCW.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCW32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCX32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSCY32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDD32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDF.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDM.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDP.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDP32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDU32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDW.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDW32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSDZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSEC32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSEO.DLL - Deleted C:\WINDOWS\SYSTEM32\MSEO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSEP32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSEQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSER32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSEW32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSEZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSFI.DLL - Deleted C:\WINDOWS\SYSTEM32\MSFO.DLL - Deleted C:\WINDOWS\SYSTEM32\MSFS32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSFU.DLL - Deleted C:\WINDOWS\SYSTEM32\MSFW.DLL - Deleted C:\WINDOWS\SYSTEM32\MSGG.DLL - Deleted C:\WINDOWS\SYSTEM32\MSGM32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSGT.DLL - Deleted C:\WINDOWS\SYSTEM32\MSGV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSHE32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSHI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSHQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSHT.DLL - Deleted C:\WINDOWS\SYSTEM32\MSIG.DLL - Deleted C:\WINDOWS\SYSTEM32\MSIL.DLL - Deleted C:\WINDOWS\SYSTEM32\MSIM.DLL - Deleted C:\WINDOWS\SYSTEM32\MSIP.DLL - Deleted C:\WINDOWS\SYSTEM32\MSJA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSJJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSJK32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSJO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSJS.DLL - Deleted C:\WINDOWS\SYSTEM32\MSJU.DLL - Deleted C:\WINDOWS\SYSTEM32\MSJX32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSKF32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSKH.DLL - Deleted C:\WINDOWS\SYSTEM32\MSKJ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSKN.DLL - Deleted C:\WINDOWS\SYSTEM32\MSKT32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSKZ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSLF.DLL - Deleted C:\WINDOWS\SYSTEM32\MSLT.DLL - Deleted C:\WINDOWS\SYSTEM32\MSMA.DLL - Deleted C:\WINDOWS\SYSTEM32\MSMC32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSME32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSMI.DLL - Deleted C:\WINDOWS\SYSTEM32\MSMJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSMK.DLL - Deleted C:\WINDOWS\SYSTEM32\MSML32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSMQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSMQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSNJ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSNM.DLL - Deleted C:\WINDOWS\SYSTEM32\MSNM32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSNR32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSNU32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSNV.DLL - Deleted C:\WINDOWS\SYSTEM32\MSOC.DLL - Deleted C:\WINDOWS\SYSTEM32\MSOF.DLL - Deleted C:\WINDOWS\SYSTEM32\MSOI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSOO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSOZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPG32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPJ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPK.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPM32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPO32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPR.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPT32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSPY32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSQI.DLL - Deleted C:\WINDOWS\SYSTEM32\MSQI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSQM.DLL - Deleted C:\WINDOWS\SYSTEM32\MSQM32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSQN.DLL - Deleted C:\WINDOWS\SYSTEM32\MSQR32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSQV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSRB.DLL - Deleted C:\WINDOWS\SYSTEM32\MSRE32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSRQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSRR.DLL - Deleted C:\WINDOWS\SYSTEM32\MSRS.DLL - Deleted C:\WINDOWS\SYSTEM32\MSRZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSE32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSF32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSN.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSN32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSU32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSSV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTA.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTB.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTD32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTF32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTJ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTM.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTT32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTW.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTY.DLL - Deleted C:\WINDOWS\SYSTEM32\MSTZ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUB.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUG.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUH32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUK.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUK32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUL32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUN.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUP32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUR32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSUX32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVC.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVF.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVL.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVL32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVN.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVP32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVQ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVS.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVS32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVU.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVX32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSVZ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSWD.DLL - Deleted C:\WINDOWS\SYSTEM32\MSWE.DLL - Deleted C:\WINDOWS\SYSTEM32\MSWQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSWW.DLL - Deleted C:\WINDOWS\SYSTEM32\MSWX.DLL - Deleted C:\WINDOWS\SYSTEM32\MSWZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSXE.DLL - Deleted C:\WINDOWS\SYSTEM32\MSXH.DLL - Deleted C:\WINDOWS\SYSTEM32\MSXM.DLL - Deleted C:\WINDOWS\SYSTEM32\MSXN.DLL - Deleted C:\WINDOWS\SYSTEM32\MSXO.DLL - Deleted C:\WINDOWS\SYSTEM32\MSXV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSYG32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSYI32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSYO.DLL - Deleted C:\WINDOWS\SYSTEM32\MSYP.DLL - Deleted C:\WINDOWS\SYSTEM32\MSYV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSYX32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZA32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZB32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZC.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZF32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZG.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZH.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZH32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZJ.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZK32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZL32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZN32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZP.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZV.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZV32.DLL - Deleted C:\WINDOWS\SYSTEM32\MSZZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\MVSXL.DLL - Deleted C:\WINDOWS\SYSTEM32\NETAA.DLL - Deleted C:\WINDOWS\SYSTEM32\NETAJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETAP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETAR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETAX.DLL - Deleted C:\WINDOWS\SYSTEM32\NETAY.DLL - Deleted C:\WINDOWS\SYSTEM32\NETBH.DLL - Deleted C:\WINDOWS\SYSTEM32\NETBP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETBR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETBS32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETBT.DLL - Deleted C:\WINDOWS\SYSTEM32\NETBX.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCB.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCI.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCR.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCS.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCU.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCV32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETCZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETDB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETDE32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETDI32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETDK.DLL - Deleted C:\WINDOWS\SYSTEM32\NETDL.DLL - Deleted C:\WINDOWS\SYSTEM32\NETDT32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETDY32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETED32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEE.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEG.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEL.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEW.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEY.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETEZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETFD.DLL - Deleted C:\WINDOWS\SYSTEM32\NETFL32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETFS32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETFZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETGA.DLL - Deleted C:\WINDOWS\SYSTEM32\NETGH.DLL - Deleted C:\WINDOWS\SYSTEM32\NETGM.DLL - Deleted C:\WINDOWS\SYSTEM32\NETGU.DLL - Deleted C:\WINDOWS\SYSTEM32\NETGU32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETGW.DLL - Deleted C:\WINDOWS\SYSTEM32\NETHD.DLL - Deleted C:\WINDOWS\SYSTEM32\NETHE32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETHJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETHL.DLL - Deleted C:\WINDOWS\SYSTEM32\NETHP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETHR.DLL - Deleted C:\WINDOWS\SYSTEM32\NETHV.DLL - Deleted C:\WINDOWS\SYSTEM32\NETIG.DLL - Deleted C:\WINDOWS\SYSTEM32\NETII.DLL - Deleted C:\WINDOWS\SYSTEM32\NETIJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETIP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETIQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETIR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETIS.DLL - Deleted C:\WINDOWS\SYSTEM32\NETIZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJA.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJC32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJE.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJF.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJM.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJP.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJW.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETJZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKC32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKE32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKI32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKK.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKM32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKV32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETKX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLL.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLL32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLM.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLN.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLN32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLO.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLT.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLU.DLL - Deleted C:\WINDOWS\SYSTEM32\NETLX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMD.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMG.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETML32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMS.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMW.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETMZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETNC32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETNF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETNG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETNI.DLL - Deleted C:\WINDOWS\SYSTEM32\NETNS.DLL - Deleted C:\WINDOWS\SYSTEM32\NETNX.DLL - Deleted C:\WINDOWS\SYSTEM32\NETOF.DLL - Deleted C:\WINDOWS\SYSTEM32\NETOH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETOL.DLL - Deleted C:\WINDOWS\SYSTEM32\NETON.DLL - Deleted C:\WINDOWS\SYSTEM32\NETON32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETOS32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETOT.DLL - Deleted C:\WINDOWS\SYSTEM32\NETOW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPG.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPI.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPK.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPM32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPO32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPS.DLL - Deleted C:\WINDOWS\SYSTEM32\NETPX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETQA.DLL - Deleted C:\WINDOWS\SYSTEM32\NETQF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETQH.DLL - Deleted C:\WINDOWS\SYSTEM32\NETQM.DLL - Deleted C:\WINDOWS\SYSTEM32\NETQX.DLL - Deleted C:\WINDOWS\SYSTEM32\NETQX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRA.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRE.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRF.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRK.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRL32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRN.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRN32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRV.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETRY.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSI.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSM32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSP.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSQ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETST.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSV.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSW.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETSY32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETTF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETTG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETTJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETTK.DLL - Deleted C:\WINDOWS\SYSTEM32\NETTV32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETTW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUE.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUE32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUM32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUN32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUP.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUQ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUY32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETUZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETVF.DLL - Deleted C:\WINDOWS\SYSTEM32\NETVF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETVH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETVK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETVN.DLL - Deleted C:\WINDOWS\SYSTEM32\NETVY.DLL - Deleted C:\WINDOWS\SYSTEM32\NETWV.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXI32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXK.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXL.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXN32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXO.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXW.DLL - Deleted C:\WINDOWS\SYSTEM32\NETXZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETYC.DLL - Deleted C:\WINDOWS\SYSTEM32\NETYI.DLL - Deleted C:\WINDOWS\SYSTEM32\NETYJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETYP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETYQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETYU.DLL - Deleted C:\WINDOWS\SYSTEM32\NETZC.DLL - Deleted C:\WINDOWS\SYSTEM32\NETZF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETZK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETZO32.DLL - Deleted C:\WINDOWS\SYSTEM32\NETZQ.DLL - Deleted C:\WINDOWS\SYSTEM32\NETZR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAC32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAE32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAL.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAO32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAT.DLL - Deleted C:\WINDOWS\SYSTEM32\NTAX.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBL32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBN.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBU32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTBX.DLL - Deleted C:\WINDOWS\SYSTEM32\NTCD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTCF.DLL - Deleted C:\WINDOWS\SYSTEM32\NTCG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTCK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTCM.DLL - Deleted C:\WINDOWS\SYSTEM32\NTCT.DLL - Deleted C:\WINDOWS\SYSTEM32\NTDG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTDO32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTDT.DLL - Deleted C:\WINDOWS\SYSTEM32\NTDV32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTDW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTDZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTEH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTEZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTFD.DLL - Deleted C:\WINDOWS\SYSTEM32\NTFK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTFN32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTFY.DLL - Deleted C:\WINDOWS\SYSTEM32\NTFY32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTGH.DLL - Deleted C:\WINDOWS\SYSTEM32\NTGJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTGL.DLL - Deleted C:\WINDOWS\SYSTEM32\NTGM.DLL - Deleted C:\WINDOWS\SYSTEM32\NTGX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTHB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTHD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTHH.DLL - Deleted C:\WINDOWS\SYSTEM32\NTHM.DLL - Deleted C:\WINDOWS\SYSTEM32\NTHR.DLL - Deleted C:\WINDOWS\SYSTEM32\NTIF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTIP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTIV.DLL - Deleted C:\WINDOWS\SYSTEM32\NTJD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTJF.DLL - Deleted C:\WINDOWS\SYSTEM32\NTJG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTJP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTJR.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKI.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKQ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKS.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKV.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKW.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKX.DLL - Deleted C:\WINDOWS\SYSTEM32\NTKZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLC.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLH.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLN.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLN32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLT.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTLZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTMM.DLL - Deleted C:\WINDOWS\SYSTEM32\NTMO32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTMU.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNB32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNC32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTND32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNM32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNP.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNQ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNT32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTNW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTOE.DLL - Deleted C:\WINDOWS\SYSTEM32\NTOO.DLL - Deleted C:\WINDOWS\SYSTEM32\NTOR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTOX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTOZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTPC32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTPE32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTPG.DLL - Deleted C:\WINDOWS\SYSTEM32\NTPK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTPQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTPZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTQD.DLL - Deleted C:\WINDOWS\SYSTEM32\NTQF.DLL - Deleted C:\WINDOWS\SYSTEM32\NTQS.DLL - Deleted C:\WINDOWS\SYSTEM32\NTQZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTRD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTRG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTRJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTRV.DLL - Deleted C:\WINDOWS\SYSTEM32\NTRW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTSD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTSK.DLL - Deleted C:\WINDOWS\SYSTEM32\NTSK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTSU32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTSX32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTSY32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTC.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTD.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTI.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTN.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTO.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTS32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTT.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTU32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTTV32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUC32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUD.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUI.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUQ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUS32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUT32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUW32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTUZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTVI.DLL - Deleted C:\WINDOWS\SYSTEM32\NTVK32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTVN32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTVO32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTVS32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTVU32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWC.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWD32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWH.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWM.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWN.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWQ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWT.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWW.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWY.DLL - Deleted C:\WINDOWS\SYSTEM32\NTWZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXE32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXF32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXG32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXS.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXT32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTXW.DLL - Deleted C:\WINDOWS\SYSTEM32\NTYA32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTYT.DLL - Deleted C:\WINDOWS\SYSTEM32\NTYY32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTYZ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZH32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZJ.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZK.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZP32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZR32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZS32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZT32.DLL - Deleted C:\WINDOWS\SYSTEM32\NTZU.DLL - Deleted C:\WINDOWS\SYSTEM32\OHAJB.DLL - Deleted C:\WINDOWS\SYSTEM32\OPERM.DLL - Deleted C:\WINDOWS\SYSTEM32\PINPZ.DLL - Deleted C:\WINDOWS\SYSTEM32\PVGNX.DLL - Deleted C:\WINDOWS\SYSTEM32\QKRPV.DLL - Deleted C:\WINDOWS\SYSTEM32\QPRFA.DLL - Deleted C:\WINDOWS\SYSTEM32\RNAPH.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKAF.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKAM.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKAN32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKAO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKAR.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBE.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBM32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBN.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBR.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBV32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBX.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKBY.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKCI.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKCK32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKCL.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKCQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKCW.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKCZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKDA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKDD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKDG32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKEB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKED32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKEE.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKEE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKEH32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKER.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKET32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKEU32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKEW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKEX.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKFD.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKFE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKFO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKGA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKGX.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKHH.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKHK.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKHM32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKHU.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKIB.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKIH32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKIL32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKIM.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKIP32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKIQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJC32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJG.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJK.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJM32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJO.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJP.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJR.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJU32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJW.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKJZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKKD.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKKD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKKN.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKKO.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKKQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKLD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKLS32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKLT32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKLU.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKLV.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKLY.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKLZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKMA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKME32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKMK.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKMK32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKMX32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKMZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNA.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNL.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNL32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNT.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNW.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKNY.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKOF.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKOF32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKOH.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKOI.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKOL32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKON.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKON32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPI32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPJ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPK.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPM.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPT.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPU.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPV.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKPZ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQE.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQG.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQO.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQW.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQX32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQY32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKQZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKRQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKRW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSG32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSK.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSP32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSU.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKSW.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTH.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTM.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTU.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTV32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKTY.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKUL32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVC.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVH32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVN.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVT.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVV32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKVZ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKWE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKWK.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKWL.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKWM.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKWS.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKWW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKWX.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXC.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXD.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXF.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXM.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXS.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXX.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKXZ.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYA.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYN32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYO.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYT32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYV.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYX.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKYZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKZC.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKZE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKZG.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKZG32.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKZU.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKZV.DLL - Deleted C:\WINDOWS\SYSTEM32\SDKZW.DLL - Deleted C:\WINDOWS\SYSTEM32\SWTSL.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAA.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAC32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAD.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAG.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAM.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAN32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAO.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAT32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAV.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAV32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSAW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBF.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBL32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBN.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBP.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBP32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBR32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBS32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBX32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSBZ.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCH32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCI.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCL32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCN.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSCR32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSDO.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSDO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSDT.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSDW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSDZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSEB.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSEB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSED32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSEE.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSEL.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSEP32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSEQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSER32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSET32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSEU32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSFA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSFC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSFW.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSGA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSGM32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSGO.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSGV.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSHB.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSHD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSIE.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSIH.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSIQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSIR.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSIS.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSIU.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSJC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSJR.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSJS32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSJV.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSKE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSKF32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSKJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSKR.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSKX.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSLC32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSLD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSLE32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSLP.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSLS.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSLS32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSMC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSMC32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSME.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSMG32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSMI.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSML.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSMQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSMU.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSMV.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSNC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSNF.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSNW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOA.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOB.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOG.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOO.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOR32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSOX.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPD.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPE.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPH32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPM.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPS32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPU32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSPV.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQF.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQI.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQI32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQK.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQM.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQT32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQV.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSQV32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSRA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSRB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSRC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSRG32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSRO32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSRP.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSRU32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSSG.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSSL.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSSN32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSTB.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSTD.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSTF.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSTW32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSTY.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSUB32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSUJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSUK.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSUQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVA.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVB.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVF.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVH.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVP32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVQ.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVW.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSVZ.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSWD32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSWF.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSWH.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSWP32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSWV32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSWY32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXF32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXK.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXK32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXM32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXN.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXR.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXT32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSXY.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSYA.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSYL.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSYN32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZA32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZC.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZC32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZG32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZH.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZK.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZM.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZM32.DLL - Deleted C:\WINDOWS\SYSTEM32\SYSZP.DLL - Deleted C:\WINDOWS\SYSTEM32\TAULL.DLL - Deleted C:\WINDOWS\SYSTEM32\TPFQI.DLL - Deleted C:\WINDOWS\SYSTEM32\TPOWG.DLL - Deleted C:\WINDOWS\SYSTEM32\TXTMN.DLL - Deleted C:\WINDOWS\SYSTEM32\UMPFZ.DLL - Deleted C:\WINDOWS\SYSTEM32\USER_32.DLL - Deleted C:\WINDOWS\SYSTEM32\VAFUF.DLL - Deleted C:\WINDOWS\SYSTEM32\VTNPF.DLL - Deleted C:\WINDOWS\SYSTEM32\VUFIL.DLL - Deleted C:\WINDOWS\SYSTEM32\WINAB.DLL - Deleted C:\WINDOWS\SYSTEM32\WINAF32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINAH32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINAU32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBA.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBD.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBF.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBG32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBO.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBO32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBS.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBX.DLL - Deleted C:\WINDOWS\SYSTEM32\WINBZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINCM32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINDH32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINDI32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINDJ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINDJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINDP32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINDU32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINEB32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINED.DLL - Deleted C:\WINDOWS\SYSTEM32\WINED32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINEO32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINES.DLL - Deleted C:\WINDOWS\SYSTEM32\WINEX.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFA.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFA32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFL.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFO.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFS32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFU.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFW.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFW32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINFX32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINGP32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINGW32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINGZ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINHC.DLL - Deleted C:\WINDOWS\SYSTEM32\WINHF.DLL - Deleted C:\WINDOWS\SYSTEM32\WINHO32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINHR.DLL - Deleted C:\WINDOWS\SYSTEM32\WINID.DLL - Deleted C:\WINDOWS\SYSTEM32\WINIE.DLL - Deleted C:\WINDOWS\SYSTEM32\WINIH32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINIK32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINIM32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINIW32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINIX32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJE.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJE32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJH.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJI.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJI32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJJ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJO.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJQ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJS.DLL - Deleted C:\WINDOWS\SYSTEM32\WINJW32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINKA.DLL - Deleted C:\WINDOWS\SYSTEM32\WINKB.DLL - Deleted C:\WINDOWS\SYSTEM32\WINKE.DLL - Deleted C:\WINDOWS\SYSTEM32\WINKF.DLL - Deleted C:\WINDOWS\SYSTEM32\WINKT32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINKZ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINLE32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINLH.DLL - Deleted C:\WINDOWS\SYSTEM32\WINLV32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINLZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINMD.DLL - Deleted C:\WINDOWS\SYSTEM32\WINMG.DLL - Deleted C:\WINDOWS\SYSTEM32\WINMN.DLL - Deleted C:\WINDOWS\SYSTEM32\WINMP.DLL - Deleted C:\WINDOWS\SYSTEM32\WINMY32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINNJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINNM.DLL - Deleted C:\WINDOWS\SYSTEM32\WINNN32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINNX.DLL - Deleted C:\WINDOWS\SYSTEM32\WINNY32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOA32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOD32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOG.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOG32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOQ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOU32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOV.DLL - Deleted C:\WINDOWS\SYSTEM32\WINOX32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINPA.DLL - Deleted C:\WINDOWS\SYSTEM32\WINPD32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINPM.DLL - Deleted C:\WINDOWS\SYSTEM32\WINPP.DLL - Deleted C:\WINDOWS\SYSTEM32\WINPT.DLL - Deleted C:\WINDOWS\SYSTEM32\WINPX32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINQB32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINQD.DLL - Deleted C:\WINDOWS\SYSTEM32\WINQF.DLL - Deleted C:\WINDOWS\SYSTEM32\WINQG32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINQH.DLL - Deleted C:\WINDOWS\SYSTEM32\WINQH32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINRA32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINRE.DLL - Deleted C:\WINDOWS\SYSTEM32\WINRF32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINRK32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINRS32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINSJ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINSJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINSN.DLL - Deleted C:\WINDOWS\SYSTEM32\WINSR32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINST.DLL - Deleted C:\WINDOWS\SYSTEM32\WINSZ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINSZ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINTL.DLL - Deleted C:\WINDOWS\SYSTEM32\WINTN.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUG32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUH.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUI32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUO.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUR32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUS.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUW.DLL - Deleted C:\WINDOWS\SYSTEM32\WINUY.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVJ32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVN32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVO.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVO32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVP32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVQ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVU32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVX.DLL - Deleted C:\WINDOWS\SYSTEM32\WINVY32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINWA.DLL - Deleted C:\WINDOWS\SYSTEM32\WINWC32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINWH.DLL - Deleted C:\WINDOWS\SYSTEM32\WINWS.DLL - Deleted C:\WINDOWS\SYSTEM32\WINWV32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXA.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXE32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXH.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXN32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXO.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXR32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXS.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXT.DLL - Deleted C:\WINDOWS\SYSTEM32\WINXZ.DLL - Deleted C:\WINDOWS\SYSTEM32\WINYD.DLL - Deleted C:\WINDOWS\SYSTEM32\WINYM32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINZI32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINZR.DLL - Deleted C:\WINDOWS\SYSTEM32\WINZS32.DLL - Deleted C:\WINDOWS\SYSTEM32\WINZV.DLL - Deleted C:\WINDOWS\SYSTEM32\WKKAW.DLL - Deleted C:\WINDOWS\SYSTEM32\XHLGL.DLL - Deleted C:\WINDOWS\SYSTEM32\XKLKD.DLL - Deleted C:\WINDOWS\SYSTEM32\ZMXQW.DLL - Deleted C:\WINDOWS\SYSTEM32\ZXJIR.DLL - Deleted C:\WINDOWS\764.exe - Deleted C:\WINDOWS\7search.dll - Deleted C:\WINDOWS\absolute key logger.lnk - Deleted C:\WINDOWS\aconti.exe - Deleted C:\WINDOWS\aconti.ini - Deleted C:\WINDOWS\aconti.log - Deleted C:\WINDOWS\aconti.sdb - Deleted C:\WINDOWS\acontidialer.txt - Deleted C:\WINDOWS\adbar.dll - Deleted C:\WINDOWS\cbinst$.exe - Deleted C:\WINDOWS\daxtime.dll - Deleted C:\WINDOWS\default.htm - Deleted C:\WINDOWS\dp0.dll - Deleted C:\WINDOWS\eventlowg.dll - Deleted C:\WINDOWS\fhfmm.exe - Deleted C:\WINDOWS\fhfmm-Uninstaller.exe - Deleted C:\WINDOWS\flt.dll - Deleted C:\WINDOWS\hcwprn.exe - Deleted C:\WINDOWS\hotporn.exe - Deleted C:\WINDOWS\ie_32.exe - Deleted C:\WINDOWS\iexplorr23.dll - Deleted C:\WINDOWS\jd2002.dll - Deleted C:\WINDOWS\kkcomp$.exe - Deleted C:\WINDOWS\kkcomp.dll - Deleted C:\WINDOWS\kkcomp.exe - Deleted C:\WINDOWS\kvnab$.exe - Deleted C:\WINDOWS\kvnab.dll - Deleted C:\WINDOWS\kvnab.exe - Deleted C:\WINDOWS\liqad$.exe - Deleted C:\WINDOWS\liqad.dll - Deleted C:\WINDOWS\liqad.exe - Deleted C:\WINDOWS\liqui.dll - Deleted C:\WINDOWS\liqui.exe - Deleted C:\WINDOWS\liqui-Uninstaller.exe - Deleted C:\WINDOWS\MSPF.EXE - Deleted C:\WINDOWS\ngd.dll - Deleted C:\WINDOWS\pbar.dll - Deleted C:\WINDOWS\pbsysie.dll - Deleted C:\WINDOWS\settn.dll - Deleted C:\WINDOWS\spredirect.dll - Deleted C:\WINDOWS\system32\.exe - Deleted C:\WINDOWS\system32\msbd32.dll - Deleted C:\WINDOWS\system32\msnmcgrs.exe - Deleted C:\WINDOWS\system32\nusrmgr.exe - Deleted C:\WINDOWS\system32\rxjddnvj.exe - Deleted C:\WINDOWS\system32\sysmu.dll - Deleted C:\WINDOWS\wbeCheck.exe - Deleted C:\WINDOWS\wbeInst$.exe - Deleted C:\WINDOWS\xadbrk.dll - Deleted C:\WINDOWS\xadbrk.exe - Deleted C:\WINDOWS\xadbrk_.exe - Deleted C:\WINDOWS\xxxvideo.exe - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-24 19:12:12 Windows 5.1.2600 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... C:\WINDOWS\n_hvxqok.txt:uxziyw 66048 bytes executable C:\WINDOWS\lhxtu.dat:meedgi 66048 bytes executable C:\WINDOWS\qlovf.dat:fxuofu 66048 bytes executable C:\WINDOWS\_delis32(10).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(11).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(12).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(13).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(14).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(15).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(16).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(17).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(18).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(19).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(2).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(20).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(21).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(22).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(3).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(4).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(5).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(6).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(7).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(.ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(9).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32.ini:dkazum 66048 bytes executable C:\WINDOWS\_delis32.ini:fhizth 66048 bytes executable C:\WINDOWS\_delis32.ini:gdyaux 66048 bytes executable C:\WINDOWS\_delis32.ini:gkmtbz 66048 bytes executable C:\WINDOWS\_delis32.ini:hkneoz 66048 bytes executable C:\WINDOWS\_delis32.ini:jfdxfw 66048 bytes executable C:\WINDOWS\_delis32.ini:lkwexi 66048 bytes executable C:\WINDOWS\_delis32.ini:mzezwn 66048 bytes executable C:\WINDOWS\_delis32.ini:odidrg 66048 bytes executable C:\WINDOWS\_delis32.ini:olywgw 66048 bytes executable C:\WINDOWS\_delis32.ini:pfwvde 66048 bytes executable C:\WINDOWS\_delis32.ini:qfvvfv 66048 bytes executable C:\WINDOWS\_delis32.ini:qxfhis 66048 bytes executable C:\WINDOWS\_delis32.ini:rcbzsv 66048 bytes executable C:\WINDOWS\_delis32.ini:sbsfph 66048 bytes executable C:\WINDOWS\_delis32.ini:sznkuc 66048 bytes executable C:\WINDOWS\_delis32.ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32.ini:yzefls 66048 bytes executable C:\WINDOWS\_delis32.ini:zxczup 66048 bytes executable C:\WINDOWS\Windows Update.log:kcvph 56832 bytes executable C:\WINDOWS\regedit.exe:dtlfl 56832 bytes executable C:\WINDOWS\explorer.scf:lwzex 56832 bytes executable C:\WINDOWS\n_ramwhu.dat:iiqbjg 66560 bytes executable C:\WINDOWS\n_raohwf.txt:fgelog 66048 bytes executable C:\WINDOWS\tobhv.log:viuxiv 66048 bytes executable C:\WINDOWS\myuwh.log:jfznya 64000 bytes executable scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 59 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Thu 2 Jun 2005 83,456 ..SHR --- "C:\Program Files\roia\eumn.exe" Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy release\SDUpdate.exe" Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy release\SpybotSD.exe" Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy release\TeaTimer.exe" Mon 16 Jan 2006 9,625 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys" Mon 14 Feb 2005 64,000 A.SH. --- "C:\WINDOWS\system32\lyrub.dll" Wed 1 Jun 2005 34,304 ..SHR --- "C:\WINDOWS\system32\shdocpa.dll" Tue 1 Feb 2005 413,696 ..SHR --- "C:\WINDOWS\system32\??xplore.exe" Tue 21 Sep 2004 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Sat 8 Apr 2006 401 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv13.bak" Mon 3 Oct 2005 20,480 ...H. --- "C:\Documents and Settings\ANDRE Mathias\Bureau\emploi\~WRL0285.tmp" Mon 3 Oct 2005 20,480 ...H. --- "C:\Documents and Settings\ANDRE Mathias\Bureau\emploi\~WRL2604.tmp" Tue 21 Sep 2004 4,348 ...H. --- "C:\Documents and Settings\ANDRE Mathias\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak" Sat 1 Dec 2007 401 A..H. --- "C:\Documents and Settings\ANDRE Mathias\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak" Sun 16 Jul 2006 488 A.SH. --- "C:\Documents and Settings\ANDRE Mathias\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak" Finished! 4. J'ai relance HJT dont voici le rapport : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:34, on 2008-02-24 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file) O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file) O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file) O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file) O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file) O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file) O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file) O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file) O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file) O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file) O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file) O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file) O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file) O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file) O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file) O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file) O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file) O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file) O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Sites Perso - {06FE5D05-8F11-11d2-804F-00105A133818} - http://compaqnet.ifrance.com/heberg/accueil (file missing) O9 - Extra 'Tools' menuitem: Compaq France - {06FE5D05-8F11-11d2-804F-00105A133818} - http://compaqnet.ifrance.com/heberg/accueil (file missing) O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.fr O15 - Trusted Zone: *.frame.crazywinnings.com O15 - Trusted Zone: *.static.topconverting.com O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://encyclo.voila.fr/JS/tdserver.cab O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\bqnuisbj.exe O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095757728839 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EBE7BF9F-63BF-420E-9F0C-0AF2B928FDBB}: NameServer = 80.10.246.134 80.10.246.7 O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 7412 bytes 5. L'infection smitfraud est apparemment éliminé je n'ai plus de fenêtres intempestives et mon gestionnaire des tâches est ré-activé. -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
1. Je suis conscient que je ne suis pas un cas facile pour toi. 2. Je te remercie du temps que tu m'accordes. 3. J'ai lancé DiagHelp et j'ai ENFIN un rapport complet : DiagHelp version v1.4 - http://www.malekal.com excute le 2008-02-24 à 15:55:12.95 Liste des derniers fichies modifies/crees dans windir\system32 et prefetch C:\WINDOWS\System32\drivers\gmer.sys -->2008-02-24 15:05:33 C:\WINDOWS\System32\drivers\cdralw2k.sys -->2005-08-20 12:53:55 C:\WINDOWS\System32\drivers\wpdusb.sys -->2005-01-28 00:36:24 C:\WINDOWS\System32\drivers\symtdi.sys -->2005-01-21 22:31:50 C:\WINDOWS\System32\drivers\symredrv.sys -->2005-01-21 22:31:48 C:\WINDOWS\System32\drivers\symids.sys -->2005-01-21 22:31:46 C:\WINDOWS\System32\drivers\symndis.sys -->2005-01-21 22:31:44 C:\WINDOWS\default.htm -->2008-02-24 15:54:44 C:\WINDOWS\ModemLog_Conexant Intl HSFi V92 MiniPCI Modem.txt -->2008-02-24 15:53:46 C:\WINDOWS\gmer.ini -->2008-02-24 15:20:21 C:\WINDOWS\WindowsUpdate.log -->2008-02-24 15:18:18 C:\WINDOWS.log -->2008-02-24 15:18:18 C:\WINDOWS\wiaservc.log -->2008-02-24 15:17:47 C:\WINDOWS\wiadebug.log -->2008-02-24 15:17:47 C:\WINDOWS\bootstat.dat -->2008-02-24 15:17:41 C:\WINDOWS\SchedLgU.Txt -->2008-02-24 15:16:49 C:\WINDOWS\gmer_uninstall.cmd -->2008-02-24 15:05:33 C:\WINDOWS\gmer.dll -->2008-02-24 15:05:33 C:\WINDOWS\PSEXESVC.EXE -->2008-02-24 13:19:51 C:\WINDOWS\eventlowg.dll -->2008-02-24 12:48:20 C:\WINDOWS\liqui.exe -->2008-02-24 12:48:19 C:\WINDOWS\liqui-Uninstaller.exe -->2008-02-24 12:48:17 winlogon.exe Verified: Signed svchost.exe Verified: Signed ws2_32.dll Verified: Signed user32.dll Verified: Signed tcpip.sys Verified: Signed ndis.sys Verified: Signed null.sys Verified: Signed ListDLLs v2.25 - DLL lister for Win9x/NT Copyright © 1997-2004 Mark Russinovich Sysinternals - www.sysinternals.com ------------------------------------------------------------------------------ explorer.exe pid: 1472 Command line: C:\WINDOWS\Explorer.EXE Base Size Version Path 0x01000000 0xf8000 6.00.2600.0000 C:\WINDOWS\Explorer.EXE 0x77be0000 0x53000 7.00.2600.0000 C:\WINDOWS\system32\msvcrt.dll 0x77290000 0x64000 6.00.2750.0167 C:\WINDOWS\system32\SHLWAPI.dll 0x77390000 0x7fd000 6.00.2750.0166 C:\WINDOWS\system32\SHELL32.dll 0x770e0000 0x8b000 3.50.5014.0000 C:\WINDOWS\system32\OLEAUT32.dll 0x71500000 0xfd000 6.00.2737.1600 C:\WINDOWS\System32\BROWSEUI.dll 0x71700000 0x148000 6.00.2750.0167 C:\WINDOWS\System32\SHDOCVW.dll 0x5b090000 0x34000 6.00.2600.0000 C:\WINDOWS\System32\UxTheme.dll 0x71950000 0xe4000 6.00.2600.0000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll 0x77300000 0x8b000 5.82.2600.0000 C:\WINDOWS\system32\comctl32.dll 0x63000000 0x96000 6.00.2737.0800 C:\WINDOWS\system32\wininet.dll 0x76250000 0x8a000 5.131.2600.1123 C:\WINDOWS\system32\CRYPT32.dll 0x1a400000 0x7b000 6.00.2745.2300 C:\WINDOWS\system32\urlmon.dll 0x7c620000 0x81000 2001.12.4414.0053 C:\WINDOWS\System32\CLBCATQ.DLL 0x77000000 0xd4000 2001.12.4414.0042 C:\WINDOWS\System32\COMRes.dll 0x5b950000 0x71000 6.00.2600.0000 C:\WINDOWS\System32\themeui.dll 0x5ce30000 0x69000 6.00.2600.0000 C:\WINDOWS\System32\shimgvw.dll 0x70d00000 0x191000 5.01.3102.1360 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.1360_x-ww_24a2ed47\gdiplus.dll 0x746e0000 0x8f000 6.00.2600.0000 C:\WINDOWS\System32\mlang.dll 0x63580000 0x2a8000 6.00.2745.2800 C:\WINDOWS\System32\mshtml.dll 0x6bd00000 0xd000 0.01.0002.0001 C:\WINDOWS\System32\SYNCOR11.DLL 0x76ac0000 0x15000 3.00.9238.0000 C:\WINDOWS\System32\ATL.DLL 0x76390000 0x1fb000 2.00.2600.0000 C:\WINDOWS\System32\msi.dll 0x025f0000 0x8e000 6.00.2715.0400 C:\WINDOWS\System32\shdoclc.dll 0x74630000 0x27000 3.10.0349.0000 C:\WINDOWS\System32\MSLS31.DLL 0x74aa0000 0x43000 6.00.2600.0000 C:\WINDOWS\System32\webcheck.dll 0x74a60000 0x9000 6.00.2600.0000 C:\WINDOWS\System32\BatMeter.dll 0x74a40000 0x7000 6.00.2600.0000 C:\WINDOWS\System32\POWRPROF.dll 0x723a0000 0x13000 6.00.2600.0000 C:\WINDOWS\System32\browselc.dll 0x02c60000 0x185000 1.05.0000.0011 C:\PROGRA~1\SPYBOT~2\SDHelper.dll 0x76340000 0x46000 6.00.2600.0000 C:\WINDOWS\system32\comdlg32.dll 0x5f140000 0x1a000 5.00.5014.0000 C:\WINDOWS\System32\olepro32.dll 0x65f00000 0x7000 6.00.2600.0000 C:\WINDOWS\System32\jsproxy.dll 0x1f7b0000 0x31000 3.520.7713.0000 C:\WINDOWS\System32\ODBC32.dll 0x1f850000 0x18000 3.520.7713.0000 C:\WINDOWS\System32\odbcint.dll 0x0ffd0000 0x22000 5.01.2518.0000 C:\WINDOWS\System32\Rsaenh.dll 0x00d60000 0x2b000 C:\Program Files\WinRAR\rarext.dll 0x10000000 0x1a000 8.00.0007.0017 C:\Program Files\Norton AntiVirus\NavShExt.dll 0x76010000 0x61000 6.00.8972.0000 C:\WINDOWS\System32\MSVCP60.dll 0x00d90000 0x8000 1.00.0000.0001 C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx 0x32520000 0x12000 10.00.2609.0000 C:\Program Files\Microsoft Office\Office10\msohev.dll 0x76be0000 0x2b000 5.131.2600.0000 C:\WINDOWS\System32\WINTRUST.dll ListDLLs v2.25 - DLL lister for Win9x/NT Copyright © 1997-2004 Mark Russinovich Sysinternals - www.sysinternals.com ------------------------------------------------------------------------------ winlogon.exe pid: 516 Command line: winlogon.exe Base Size Version Path 0x01000000 0x6f000 \??\C:\WINDOWS\system32\winlogon.exe 0x77be0000 0x53000 7.00.2600.0000 C:\WINDOWS\system32\msvcrt.dll 0x76250000 0x8a000 5.131.2600.1123 C:\WINDOWS\system32\CRYPT32.dll 0x77390000 0x7fd000 6.00.2750.0166 C:\WINDOWS\system32\SHELL32.dll 0x77290000 0x64000 6.00.2750.0167 C:\WINDOWS\system32\SHLWAPI.dll 0x77300000 0x8b000 5.82.2600.0000 C:\WINDOWS\system32\COMCTL32.dll 0x1f7b0000 0x31000 3.520.7713.0000 C:\WINDOWS\system32\ODBC32.dll 0x76340000 0x46000 6.00.2600.0000 C:\WINDOWS\system32\comdlg32.dll 0x007a0000 0xe4000 6.00.2600.0000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll 0x1f850000 0x18000 3.520.7713.0000 C:\WINDOWS\system32\odbcint.dll 0x76b70000 0x1f000 6.00.2600.0000 C:\WINDOWS\system32\SHSVCS.dll 0x76be0000 0x2b000 5.131.2600.0000 C:\WINDOWS\system32\WINTRUST.dll 0x5b090000 0x34000 6.00.2600.0000 C:\WINDOWS\system32\uxtheme.dll 0x6bd00000 0xd000 0.01.0002.0001 C:\WINDOWS\system32\SYNCOR11.DLL 0x0ffd0000 0x22000 5.01.2518.0000 C:\WINDOWS\System32\Rsaenh.dll 0x77000000 0xd4000 2001.12.4414.0042 C:\WINDOWS\system32\COMRes.dll 0x770e0000 0x8b000 3.50.5014.0000 C:\WINDOWS\system32\OLEAUT32.dll 0x7c620000 0x81000 2001.12.4414.0053 C:\WINDOWS\system32\CLBCATQ.DLL Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 4857-861D Répertoire de C:\WINDOWS\system32 2001-08-28 15:00 4,096 csrss.exe 1 fichier(s) 4,096 octets 0 Rép(s) 6,333,386,752 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 4857-861D Répertoire de C:\WINDOWS\Downloaded Program Files 2008-02-22 20:20 <REP> . 2008-02-22 20:20 <REP> .. 2004-05-11 11:55 1,277,992 Banksht2.dll 2002-07-12 15:58 65 desktop.ini 2005-12-08 12:46 1,271 erma.inf 2004-06-01 14:39 2,140 MediaTicketsInstaller.INF 2004-04-06 19:03 172,072 MessengerStatsPAClient.dll 2000-01-20 14:25 1,162 Microsoft XML Parser for Java.osd 2005-03-14 12:39 227 MsnMessengerSetupDownloader.inf 2005-03-17 13:48 113,152 MsnMessengerSetupDownloader.ocx 2002-05-29 22:12 9,488 sporder.dll 2006-11-09 13:36 5,019 swflash.inf 1998-09-25 11:06 685 tdserver.inf 1998-09-24 16:24 111,616 tdserver.ocx 2002-10-27 18:32 3,036 wmv9dmo.inf 2005-03-04 11:11 2,371 wmvadvd.inf 2004-08-03 13:51 293 wuweb.inf 2004-08-17 13:58 227 ysbactivex.inf 2004-11-17 22:44 114,728 Zintro.ocx 17 fichier(s) 1,815,544 octets Total des fichiers listés : 17 fichier(s) 1,815,544 octets 2 Rép(s) 6,333,374,464 octets libres Recherche de rootkit! (Merci S!Ri) Recherche d'infections connues Export des clefs sensibles.. Liste des fichiers en exception sur le pare-feu XP SP2 Export de la clef SharedTaskScheduler [sharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" exports des policies REGEDIT4 [system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 Export des clefs sensibles.. Rechercher adresses sensibles dans le fichier HOSTS... 127.0.0.1 www.activexupdate.com 127.0.0.1 activexupdate.com 127.0.0.1 www.avpcheckupdate.com 127.0.0.1 avpcheckupdate.com 127.0.0.1 client.exeupdate.com 127.0.0.1 www.eupdatepage.com 127.0.0.1 eupdatepage.com 127.0.0.1 www.exeupdate.com 127.0.0.1 exeupdate.com 127.0.0.1 www.hotwinupdates.com 127.0.0.1 hotwinupdates.com 127.0.0.1 www.lavasoftupdate.com 127.0.0.1 lavasoftupdate.com 127.0.0.1 www.malwarewipeupdate.com 127.0.0.1 malwarewipeupdate.com 127.0.0.1 www.msupdate.net 127.0.0.1 msupdate.net 127.0.0.1 www.msupdater.net 127.0.0.1 msupdater.net 127.0.0.1 www.necessaryupdates.com 127.0.0.1 necessaryupdates.com 127.0.0.1 newupdates.lzio.com 127.0.0.1 redirect.msupdate.net 127.0.0.1 search.keyword.exeupdate.com 127.0.0.1 www.securityupdatesite.com 127.0.0.1 securityupdatesite.com 127.0.0.1 settings.updatemysettings.com 127.0.0.1 www.spyaxeupdate.com 127.0.0.1 spyaxeupdate.com 127.0.0.1 www.spyfalconupdate.com 127.0.0.1 spyfalconupdate.com 127.0.0.1 www.systemupdates.net 127.0.0.1 systemupdates.net 127.0.0.1 trial.updates.winsoftware.com 127.0.0.1 update.680180.net 127.0.0.1 www.updatemysettings.com 127.0.0.1 updatemysettings.com 127.0.0.1 updates.spywarequake.com 127.0.0.1 www.urgentsystemupdate.biz 127.0.0.1 urgentsystemupdate.biz 127.0.0.1 www.urgentsystemupdate.com 127.0.0.1 urgentsystemupdate.com 127.0.0.1 windupdates.com 127.0.0.1 www.pandaantivirus-2007.com 127.0.0.1 pandaantivirus-2007.com 127.0.0.1 www.pandadownload-now.com 127.0.0.1 pandadownload-now.com 127.0.0.1 www.panda-hq.com 127.0.0.1 panda-hq.com catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-24 15:56:31 Windows 5.1.2600 NTFS scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... C:\WINDOWS\n_hvxqok.txt:uxziyw 66048 bytes executable C:\WINDOWS\lhxtu.dat:meedgi 66048 bytes executable C:\WINDOWS\qlovf.dat:fxuofu 66048 bytes executable C:\WINDOWS\_delis32(10).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(11).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(12).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(13).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(14).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(15).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(16).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(17).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(18).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(19).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(2).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(20).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(21).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(22).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(3).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(4).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(5).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(6).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(7).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(.ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32(9).ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32.ini:dkazum 66048 bytes executable C:\WINDOWS\_delis32.ini:fhizth 66048 bytes executable C:\WINDOWS\_delis32.ini:gdyaux 66048 bytes executable C:\WINDOWS\_delis32.ini:gkmtbz 66048 bytes executable C:\WINDOWS\_delis32.ini:hkneoz 66048 bytes executable C:\WINDOWS\_delis32.ini:jfdxfw 66048 bytes executable C:\WINDOWS\_delis32.ini:lkwexi 66048 bytes executable C:\WINDOWS\_delis32.ini:mzezwn 66048 bytes executable C:\WINDOWS\_delis32.ini:odidrg 66048 bytes executable C:\WINDOWS\_delis32.ini:olywgw 66048 bytes executable C:\WINDOWS\_delis32.ini:pfwvde 66048 bytes executable C:\WINDOWS\_delis32.ini:qfvvfv 66048 bytes executable C:\WINDOWS\_delis32.ini:qxfhis 66048 bytes executable C:\WINDOWS\_delis32.ini:rcbzsv 66048 bytes executable C:\WINDOWS\_delis32.ini:sbsfph 66048 bytes executable C:\WINDOWS\_delis32.ini:sznkuc 66048 bytes executable C:\WINDOWS\_delis32.ini:vtmtui 66560 bytes executable C:\WINDOWS\_delis32.ini:yzefls 66048 bytes executable C:\WINDOWS\_delis32.ini:zxczup 66048 bytes executable C:\WINDOWS\Windows Update.log:kcvph 56832 bytes executable C:\WINDOWS\regedit.exe:dtlfl 56832 bytes executable C:\WINDOWS\explorer.scf:lwzex 56832 bytes executable C:\WINDOWS\n_ramwhu.dat:iiqbjg 66560 bytes executable C:\WINDOWS\n_raohwf.txt:fgelog 66048 bytes executable C:\WINDOWS\tobhv.log:viuxiv 66048 bytes executable C:\WINDOWS\myuwh.log:jfznya 64000 bytes executable scan completed successfully hidden services: 0 hidden files: 50 KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg) Process list by traversal of KiWaitListHead 4 - System 492 - csrss.exe 516 - winlogon.exe 560 - services.exe 572 - lsass.exe 788 - svchost.exe 1072 - iexplore.exe 1420 - rxjddnvj.exe 1472 - explorer.exe 1556 - cmd.exe Total number of processes = 10 NOTE: Under WinXP, this will not show all processes. KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg) Driver/Module list by traversal of PsLoadedModuleList 804D0000 - \WINDOWS\system32\ntoskrnl.exe 8069D000 - \WINDOWS\system32\hal.dll F9D53000 - \WINDOWS\system32\KDCOM.DLL F9C63000 - \WINDOWS\system32\BOOTVID.dll F9806000 - ACPI.sys F9D55000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS F9853000 - pci.sys F9863000 - isapnp.sys F9C67000 - compbatt.sys F9C6B000 - \WINDOWS\System32\DRIVERS\BATTC.SYS F9D57000 - viaide.sys F9AD3000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS F97E9000 - pcmcia.sys F9873000 - MountMgr.sys F97CA000 - ftdisk.sys F9C6F000 - ACPIEC.sys F9E1B000 - \WINDOWS\System32\DRIVERS\OPRGHDLR.SYS F9ADB000 - PartMgr.sys F9883000 - VolSnap.sys F97B4000 - atapi.sys F9893000 - disk.sys F98A3000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS F97A2000 - sr.sys F978E000 - KSecDD.sys F970F000 - Ntfs.sys F96E7000 - NDIS.sys F9AE3000 - viaagp.sys F96CD000 - Mup.sys F9953000 - \SystemRoot\System32\DRIVERS\amdk7.sys F9CFF000 - \SystemRoot\System32\DRIVERS\CmBatt.sys F9658000 - \SystemRoot\System32\DRIVERS\s3gnbm.sys F9963000 - \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS F9B13000 - \SystemRoot\System32\DRIVERS\fdc.sys F9645000 - \SystemRoot\System32\DRIVERS\parport.sys F9973000 - \SystemRoot\System32\DRIVERS\i8042prt.sys F960A000 - \SystemRoot\System32\DRIVERS\SynTP.sys F9D67000 - \SystemRoot\System32\DRIVERS\USBD.SYS F9B1B000 - \SystemRoot\System32\DRIVERS\mouclass.sys F9B23000 - \SystemRoot\System32\DRIVERS\eaps2kbd.sys F9B2B000 - \SystemRoot\System32\DRIVERS\kbdclass.sys F9B33000 - \SystemRoot\system32\drivers\ImapiRox.sys F9983000 - \SystemRoot\System32\Drivers\Cdr4_xp.SYS F9993000 - \SystemRoot\System32\DRIVERS\cdrom.sys F99A3000 - \SystemRoot\System32\DRIVERS\redbook.sys F95E9000 - \SystemRoot\System32\DRIVERS\ks.sys F9B3B000 - \SystemRoot\System32\Drivers\Cdralw2k.SYS F95D5000 - \SystemRoot\System32\Drivers\pwd_2K.SYS F9B43000 - \SystemRoot\System32\DRIVERS\usbuhci.sys F95B6000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS F9549000 - \SystemRoot\system32\drivers\smwdm.sys F9F00000 - \SystemRoot\system32\drivers\SENSUPGD.SYS F9528000 - \SystemRoot\system32\drivers\portcls.sys F99B3000 - \SystemRoot\system32\drivers\drmk.sys F8F17000 - \SystemRoot\System32\DRIVERS\basic2.sys F99C3000 - \SystemRoot\System32\DRIVERS\SOAR.SYS F99D3000 - \SystemRoot\System32\DRIVERS\rksample.sys F8E90000 - \SystemRoot\System32\DRIVERS\HSF_CNXT.sys F8E6A000 - \SystemRoot\System32\DRIVERS\AmosNt.SYS F9B4B000 - \SystemRoot\System32\Drivers\Modem.SYS F9B53000 - \SystemRoot\System32\DRIVERS\RTL8139.SYS F9F0A000 - \SystemRoot\System32\DRIVERS\audstub.sys F99E3000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys F9D0B000 - \SystemRoot\System32\DRIVERS\ndistapi.sys F8E54000 - \SystemRoot\System32\DRIVERS\ndiswan.sys F99F3000 - \SystemRoot\System32\DRIVERS\raspppoe.sys F9A03000 - \SystemRoot\System32\DRIVERS\raspptp.sys F9D0F000 - \SystemRoot\System32\DRIVERS\TDI.SYS F8E43000 - \SystemRoot\System32\DRIVERS\psched.sys F9A13000 - \SystemRoot\System32\DRIVERS\msgpc.sys F9B5B000 - \SystemRoot\System32\DRIVERS\ptilink.sys F9B63000 - \SystemRoot\System32\DRIVERS\raspti.sys F9A23000 - \SystemRoot\System32\DRIVERS\termdd.sys F9F15000 - \SystemRoot\System32\DRIVERS\swenum.sys F8D81000 - \SystemRoot\System32\DRIVERS\update.sys F9B6B000 - \SystemRoot\System32\Drivers\mmc_2K.SYS F9A33000 - \SystemRoot\System32\Drivers\NDProxy.SYS F9B7B000 - \SystemRoot\System32\DRIVERS\flpydisk.sys F9A73000 - \SystemRoot\System32\DRIVERS\usbhub.sys F9D3B000 - \SystemRoot\System32\DRIVERS\hidusb.sys F9AA3000 - \SystemRoot\System32\DRIVERS\HIDCLASS.SYS F9B83000 - \SystemRoot\System32\DRIVERS\HIDPARSE.SYS F9D3F000 - \SystemRoot\System32\DRIVERS\mouhid.sys F9D69000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS F9E26000 - \SystemRoot\System32\Drivers\Null.SYS F9D6B000 - \SystemRoot\System32\Drivers\Beep.SYS F9B9B000 - \SystemRoot\System32\drivers\vga.sys F9D6D000 - \SystemRoot\System32\Drivers\mnmdd.SYS F9D6F000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys F7C6D000 - \SystemRoot\System32\Drivers\cdudf_xp.SYS F9BA3000 - \SystemRoot\System32\Drivers\Msfs.SYS F9BAB000 - \SystemRoot\System32\Drivers\Npfs.SYS F7C28000 - \SystemRoot\System32\Drivers\UdfReadr_xp.SYS F9694000 - \SystemRoot\System32\DRIVERS\rasacd.sys F9AB3000 - \SystemRoot\System32\DRIVERS\ipsec.sys F7B9E000 - \SystemRoot\System32\DRIVERS\tcpip.sys F7B5E000 - \SystemRoot\System32\Drivers\SYMTDI.SYS F7B44000 - \??\C:\Program Files\Symantec\SYMEVENT.SYS F7B1F000 - \SystemRoot\System32\DRIVERS\netbt.sys F7AC5000 - \SystemRoot\System32\vsdatant.sys F9AC3000 - \SystemRoot\System32\DRIVERS\wanarp.sys F98C3000 - \SystemRoot\System32\DRIVERS\netbios.sys F79D5000 - \SystemRoot\System32\DRIVERS\rdbss.sys F7975000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys F98D3000 - \SystemRoot\System32\Drivers\Fips.SYS F7951000 - \SystemRoot\System32\Drivers\Fastfat.SYS F793B000 - \SystemRoot\System32\Drivers\dump_atapi.sys F9D7B000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS BF800000 - \??\C:\WINDOWS\system32\win32k.sys F8D4C000 - \??\C:\WINDOWS\system32\watchdog.sys BFF80000 - \SystemRoot\System32\drivers\dxg.sys F9F44000 - \SystemRoot\System32\drivers\dxgthk.sys BF993000 - \SystemRoot\System32\s3gnb.dll F48DA000 - \SystemRoot\System32\drivers\afd.sys F495E000 - \SystemRoot\System32\DRIVERS\ndisuio.sys F46CF000 - \SystemRoot\System32\DRIVERS\mrxdav.sys F9DA9000 - \SystemRoot\System32\Drivers\ParVdm.SYS F4892000 - \SystemRoot\System32\DRIVERS\cnxtdiag.sys F4660000 - \SystemRoot\System32\DRIVERS\fallback.sys F4644000 - \SystemRoot\System32\DRIVERS\fsksnt.sys F47E2000 - \??\C:\WINDOWS\System32\hfupxdmg.wfv F45E4000 - \SystemRoot\System32\DRIVERS\k56nt.sys F458B000 - \SystemRoot\System32\DRIVERS\faxnt.sys F486A000 - \SystemRoot\System32\DRIVERS\tonesnt.sys F4514000 - \SystemRoot\System32\DRIVERS\srv.sys F449B000 - \SystemRoot\System32\DRIVERS\v124nt.sys F47FA000 - \SystemRoot\system32\drivers\sysaudio.sys F4354000 - \SystemRoot\system32\drivers\wdmaud.sys F3E4D000 - \SystemRoot\system32\drivers\kmixer.sys F3E38000 - \SystemRoot\System32\DRIVERS\gmer.sys F3F40000 - \SystemRoot\System32\DRIVERS\asyncmac.sys F9E5E000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys Total number of drivers = 131 Liste des programmes installes Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX ANPSEDIC Archiveur WinRAR ArcSoft PhotoBase ArcSoft PhotoStudio 2000 Barre d'outils MSN Canon S300 Canon ScanGear Toolbox 3.0 Compaq Wallpaper Correctif Windows XP - Article Base de Connaissances 834707 Correctif Windows XP - KB823559 Correctif Windows XP - KB828741 Correctif Windows XP - KB833987 Correctif Windows XP - KB834707 Correctif Windows XP - KB835732 Correctif Windows XP - KB840987 Correctif Windows XP - KB841356 Correctif Windows XP - KB841533 Correctif Windows XP - KB842773 Correctif Windows XP - KB867282 Correctif Windows XP - KB873333 Correctif Windows XP - KB873339 Correctif Windows XP - KB873376 Correctif Windows XP - KB885250 Correctif Windows XP - KB885835 Correctif Windows XP - KB885836 Correctif Windows XP - KB885884 Correctif Windows XP - KB886185 Correctif Windows XP - KB887472 Correctif Windows XP - KB887742 Correctif Windows XP - KB887822 Correctif Windows XP - KB888113 Correctif Windows XP - KB888302 Correctif Windows XP - KB890047 Correctif Windows XP - KB890175 Correctif Windows XP - KB891781 CVitae Easy CD Creator 5 Basic HijackThis 2.0.2 J2SE Runtime Environment 5.0 Update 2 Labtec WebCam Lecteur Windows Media 10 LiveReg (Symantec Corporation) LiveUpdate 2.5 (Symantec Corporation) Logitech IM Video Companion Macromedia Shockwave Player Memup Qoolqee Messager Wanadoo Microsoft Office XP Professional avec FrontPage NetWaiting Norton AntiVirus 2002 Norton WMI Update OmniPage Pro 9.0 Package du correctif Windows XP [voir Q329115 pour plus de détails] QuickTime RealPlayer S3 Graphics Utilities Scan Manager 5.2 SoundMAXWDM Spybot - Search & Destroy Spybot - Search & Destroy 1.5.2.20 Symantec Network Drivers Update Synaptics TouchPad Twister and Utilities VideoLAN VLC media player 0.7.2 WebFldrs XP Windows Live Messenger Windows Live Sign-in Assistant Windows Media Format Runtime Windows XP Hotfix - KB821557 Windows XP Hotfix (SP1) [see Q315403 for more information] Windows XP Hotfix (SP1) [see Q329048 for more information] Windows XP Hotfix (SP1) [see Q329390 for more information] Windows XP Hotfix (SP1) [see Q329441 for more information] Windows XP Hotfix (SP1) [see Q329834 for more information] Windows XP Hotfix (SP1) Q329170 Windows XP Hotfix (SP1) Q810577 Windows XP Hotfix (SP1) Q810833 Windows XP Hotfix (SP1) Q815021 Windows XP Hotfix (SP1) Q817606 ZoneAlarm Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 4857-861D Répertoire de C:\Program Files 2008-02-22 17:34 <REP> . 2008-02-22 17:34 <REP> .. 2005-02-12 09:23 <REP> A9Tech 2004-09-23 14:40 <REP> Adaptec 2002-07-12 16:36 <REP> Adobe 2002-07-12 16:32 <REP> Analog Devices 2005-12-20 20:44 <REP> ANPSEDIC 2004-12-05 18:30 <REP> APDFPRP 2004-11-20 11:25 <REP> ArcSoft 2004-11-20 11:26 <REP> Caere 2004-11-20 11:28 <REP> Canon 2004-10-09 12:36 <REP> Common files 2002-07-12 16:50 <REP> CompaqNET.fr 2002-07-12 15:56 <REP> ComPlus Applications 2006-03-30 19:27 <REP> CVitae 2006-01-18 13:17 <REP> DivX 2006-02-11 14:39 <REP> eMule 2006-02-21 20:01 <REP> Fichiers communs 2002-07-12 16:54 <REP> Infoflash France 2005-06-02 22:52 <REP> Internet Explorer 2004-09-21 09:45 <REP> InterVideo 2005-03-28 22:22 <REP> IrfanView 2005-05-16 07:22 <REP> Java 2006-01-30 11:33 <REP> Labtec 2006-01-30 11:44 <REP> Logitech 2004-11-20 10:11 <REP> MB Softs 2005-12-23 20:09 <REP> Memup 2004-09-20 20:39 <REP> Messager Wanadoo 2005-06-02 22:48 <REP> messenger 2002-07-12 16:01 <REP> microsoft frontpage 2004-09-26 16:56 <REP> Microsoft Office 2005-06-02 22:52 <REP> Movie Maker 2004-12-30 23:55 <REP> MSN Apps 2002-07-12 15:55 <REP> MSN Gaming Zone 2007-09-14 02:57 <REP> MSN Messenger 2005-06-02 22:52 <REP> NetMeeting 2002-07-12 16:52 <REP> NetWaiting 2005-01-16 14:56 <REP> Norton AntiVirus 2004-09-24 23:09 <REP> Opera 2005-06-02 22:52 <REP> Outlook Express 2007-11-25 12:26 <REP> pdf995 2004-09-25 20:08 <REP> QuickTime 2004-09-25 19:45 <REP> Real 2005-06-02 23:25 <REP> roia 2002-07-12 16:34 <REP> S3Inc 2005-02-01 17:11 <REP> SearchRelevancy 2008-02-09 14:27 <REP> Spybot - Search & Destroy 2008-02-09 15:16 <REP> Spybot - Search & Destroy release 2002-07-12 16:32 <REP> Staccato 2005-02-07 19:26 <REP> Symantec 2004-09-30 11:59 <REP> SymNetDrv 2002-07-12 16:51 <REP> Synaptics 2008-02-22 17:34 <REP> Trend Micro 2006-02-15 20:25 <REP> Trisnap Technologies 2004-09-21 08:34 <REP> VideoLAN 2005-06-04 11:45 <REP> Wanadoo 2004-11-20 10:33 <REP> Windows AdControl 2005-06-07 20:04 <REP> Windows Media Player 2005-06-02 22:52 <REP> Windows NT 2005-02-01 17:11 <REP> Windows SyncroAd 2005-05-28 16:42 <REP> WinRAR 2002-07-12 16:01 <REP> xerox 2002-07-12 16:50 <REP> Your Application Name 2005-02-06 10:44 <REP> Zone Labs 0 fichier(s) 0 octets 64 Rép(s) 6,333,689,856 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 4857-861D Répertoire de C:\Program Files\fichiers communs 2006-02-21 20:01 <REP> . 2006-02-21 20:01 <REP> .. 2005-08-20 12:53 <REP> Adaptec Shared 2004-09-21 22:22 <REP> Adobe 2004-11-20 11:27 <REP> Caere 2004-09-26 16:57 <REP> Designer 2005-08-13 12:48 <REP> InstallShield 2005-05-16 07:19 <REP> Java 2004-11-20 12:08 <REP> Logitech 2007-09-14 03:00 <REP> Microsoft Shared 2002-07-12 15:57 <REP> MSSoap 2002-07-12 16:49 <REP> ODBC 2004-09-25 19:46 <REP> Real 2002-07-12 15:57 <REP> Services 2002-07-12 16:49 <REP> SpeechEngines 2005-03-10 20:44 <REP> Symantec Shared 2005-06-02 22:52 <REP> System 2004-09-25 19:46 <REP> xing shared 0 fichier(s) 0 octets 18 Rép(s) 6,333,689,856 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 4857-861D Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders 2004-09-26 16:57 <REP> . 2004-09-26 16:57 <REP> .. 2004-09-21 09:50 <REP> 1033 2004-09-26 16:57 <REP> 1036 2001-02-15 04:45 1,318,912 MSONSEXT.DLL 2001-02-13 07:23 58,784 MSOSV.DLL 1999-06-03 13:09 122,937 MSOWS409.DLL 2001-03-07 08:00 127,033 MSOWS40c.DLL 2000-08-06 08:04 401,462 MSVCP60.DLL 2001-01-22 02:25 69,632 PKMAXCTL.DLL 2001-01-22 02:25 872,448 PKMCDO.DLL 2001-01-22 02:25 159,744 PKMCORE.DLL 2001-02-07 08:59 106,496 PKMFORMS.DLL 2001-02-12 03:03 684,032 PKMRES.DLL 2001-01-22 02:25 28,672 PKMSSTLB.DLL 2001-01-22 02:25 40,960 PKMTEMPL.DLL 2001-01-22 02:25 24,576 PKMTRACE.DLL 2001-01-22 02:25 86,016 PKMWS.DLL 2001-01-22 02:25 237,568 PROMDEMO.DLL 2001-01-22 02:25 184,320 SECMGR.DLL 2001-01-22 02:25 323,584 VAIDDMGR.DLL 2001-01-22 02:25 32,768 VAIMEM.DLL 18 fichier(s) 4,879,944 octets 4 Rép(s) 6,333,685,760 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 4857-861D Répertoire de C:\Program Files\common files 2004-10-09 12:36 <REP> . 2004-10-09 12:36 <REP> .. 0 fichier(s) 0 octets 2 Rép(s) 6,333,685,760 octets libres Le volume dans le lecteur C n'a pas de nom. Le numéro de série du volume est 4857-861D Répertoire de C:\ 2005-02-10 20:27 9,445 gqndhgxp.exe 2005-02-06 09:37 9,445 yla.exe 2 fichier(s) 18,890 octets 0 Rép(s) 6,333,685,760 octets libres c:\Documents and Settings\All Users\Bureau\spybotsd152.exe c:\Documents and Settings\ANDRE Mathias\Application Data\Microsoft\Installer\{5A682D37-E093-40A0-BF74-A4A6D1861B92}\ARPPRODUCTICON.exe c:\Documents and Settings\ANDRE Mathias\Application Data\Microsoft\Installer\{5A682D37-E093-40A0-BF74-A4A6D1861B92}\NewShortcut1_5A682D37E09340A0BF74A4A6D1861B92_1.exe c:\Documents and Settings\ANDRE Mathias\Application Data\Microsoft\Installer\{5A682D37-E093-40A0-BF74-A4A6D1861B92}\NewShortcut2_5A682D37E09340A0BF74A4A6D1861B92_1.exe c:\Documents and Settings\ANDRE Mathias\Application Data\Microsoft\Installer\{5A682D37-E093-40A0-BF74-A4A6D1861B92}\NewShortcut3_5A682D37E09340A0BF74A4A6D1861B92_1.exe c:\Documents and Settings\ANDRE Mathias\Bureau\HJTInstall.exe c:\Documents and Settings\ANDRE Mathias\Bureau\zaSetup_fr.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\catchme.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\diff.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\dumphive.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\FilesInfoCmd.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\find2.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\Fport.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\grep.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\gzip.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\KProcCheck.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\LFiles.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\LISTDLLS.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\md5sums.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\pslist.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\sigcheck.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\streams.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\swreg.exe c:\Documents and Settings\ANDRE Mathias\Bureau\DiagHelp\tar.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\gspot\gspot.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\logiciels\apdfprp\setup.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\logiciels\gspot\gspot.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\logiciels\guitard pro\acordeur\BudgoTuner.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\logiciels\Media Player Classic\mplayerc.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\logiciels\VirtualDub-1.5.10\auxsetup.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\logiciels\VirtualDub-1.5.10\VirtualDub.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\Media Player Classic\mplayerc.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\VirtualDub-1.5.10\auxsetup.exe c:\Documents and Settings\ANDRE Mathias\Mes documents\VirtualDub-1.5.10\VirtualDub.exe c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll c:\Documents and Settings\ANDRE Mathias\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll ****** Fin du rapport DiagHelp Veuillez svp envoyer le fichier C:\upload_moi_NOM-R23KDENUGXQ.tar.gz a l'adresse http://upload.malekal.com -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
1. J'ai supprimé ComboFix 2. J'ai lancé Gmer, il a commencé le scan puis s'est arrêté : Gmer a rencontré un problème et doit fermer. 3. J'ai rallumé le pc, relancé Gmer. Idem mais j'ai quand même pu copier rapport au moment du bug de gmer : GMER 1.0.14.14116 - http://www.gmer.net Rootkit scan 2008-02-24 15:22:57 Windows 5.1.2600 ---- System - GMER 1.0.14 ---- SSDT FFA4C910 ZwConnectPort SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateFile [0xF7ADDB70] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateKey [0xF7AF6944] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteFile [0xF7ADE180] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteKey [0xF7AF7330] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteValueKey [0xF7AF7100] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwLoadKey [0xF7AF74F0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenFile [0xF7ADDFD0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwReplaceKey [0xF7AF77C0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRestoreKey [0xF7AF7A50] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetInformationFile [0xF7ADE2F0] SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetValueKey [0xF7AF6EA0] ---- Kernel code sections - GMER 1.0.14 ---- .text ntdll.dll!NtClose 77F4B458 5 Bytes JMP 72049770 .text ntdll.dll!NtCreateFile 77F4B518 5 Bytes JMP 7204A570 .text ntdll.dll!NtCreateKey 77F4B558 5 Bytes JMP 7204ADA0 .text ntdll.dll!NtCreateProcess 77F4B5B8 5 Bytes JMP 7204AE30 .text ntdll.dll!NtCreateProcessEx 77F4B5C8 5 Bytes JMP 7204AF60 .text ntdll.dll!NtCreateSection 77F4B5E8 5 Bytes JMP 72049A40 .text ntdll.dll!NtLoadDriver 77F4B8D8 5 Bytes JMP 7204A1E0 .text ntdll.dll!NtSetValueKey 77F4C238 5 Bytes JMP 7204AD10 .text ntdll.dll!NtWriteFile 77F4C3E8 5 Bytes JMP 7204A3D0 ---- User code sections - GMER 1.0.14 ---- .text C:\Gmer\gmer.exe[976] kernel32.dll!CopyFileExA 77E6A1B0 1 Byte [ E9 ] .text C:\Gmer\gmer.exe[976] kernel32.dll!CopyFileExA + 2 77E6A1B2 3 Bytes [ D3, 1D, FA ] ---- Kernel IAT/EAT - GMER 1.0.14 ---- IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F7AE5C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F7AE5AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F7AE5590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F7AE5700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F7AE5700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F7AE5590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F7AE5C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F7AE5AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F7AE5590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F7AE5C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F7AE5AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F7AE5700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F7AE5C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F7AE5590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F7AE5AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F7AE5700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F7AE5590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F7AE5AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F7AE5C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [F7B03980] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F7AE5590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F7AE5700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F7AE5C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F7AE5AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [F7ADE630] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [F7ADE580] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [F7ADE6F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [F7ADE4A0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ---- Devices - GMER 1.0.14 ---- AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
J'ai toujours le même problème. 1. J'ai supprimé les dossiers combofix sur C: et l'éxécutable s'est bloqué et ne commence même pas à supprimer des fichiers. 2. Ensuite, j'ai re désinstallé combofix en supprimant le dossier et aussi QooBox (après consultation sur le net). J'ai re-lancé combofix, il fait son point de restauration (qu'il n'avait pas fait lors de la 1ère tentative), commence une liste de suppression de fichiers/dossiers infectés puis se bloque, le pc ne fait plus rien... Je ne sais plus quoi faire avec ce combofix....... -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Lorsque j'éxécute ComboFix /u je suis dirigé sur le dossier C:\ComboFix. Est-ce que je dois supprimer les fichiers contenus dans ce dossier? Egalement, lorsque j'avais ré-essayé de lancer combofix en revenant au point de restauration, plusieurs dossiers ont été créés : ComboFix(2), ComboFix(3) et ComboFix(4). Dois-je tout supprimer? -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Voici le rapport de HJT : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:13, on 2008-02-24 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\rxjddnvj.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\rxjddnvj.exe, O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file) O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file) O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file) O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file) O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file) O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file) O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file) O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file) O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file) O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file) O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file) O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file) O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file) O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file) O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file) O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file) O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file) O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file) O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file) O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Sites Perso - {06FE5D05-8F11-11d2-804F-00105A133818} - http://compaqnet.ifrance.com/heberg/accueil (file missing) O9 - Extra 'Tools' menuitem: Compaq France - {06FE5D05-8F11-11d2-804F-00105A133818} - http://compaqnet.ifrance.com/heberg/accueil (file missing) O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.fr O15 - Trusted Zone: *.frame.crazywinnings.com O15 - Trusted Zone: *.static.topconverting.com O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://encyclo.voila.fr/JS/tdserver.cab O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\bqnuisbj.exe O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095757728839 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EBE7BF9F-63BF-420E-9F0C-0AF2B928FDBB}: NameServer = 80.10.246.134 80.10.246.7 O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 7169 bytes -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
J'ai lancé HJt et j'ai coché les éléments que vous m'avez cités. Ensuite j'ai éxécuté combofix, mais le scan n'aboutit pas. La suppression de fichiers/dossiers s'arrête et plus rien ne se passe pendant 1/2 heure, donc j'éteins le pc... J'ai essayé plusieurs fois de revenir au point de restauration que combofix crée, puis de le relancer mais à chaque fois le scan n'aboutit pas. Que dois-je faire? -
Infection Smitfraud
Matia60 a répondu à un(e) sujet de Matia60 dans Analyses et éradication malwares
Re, Merci pour votre réponse rapide. Voici le résultat du scan : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:35:03, on 22/02/2008 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rxjddnvj.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\svcnut32.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\??xplore.exe C:\WINDOWS\System32\msnmcgrs.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdocpa.dll/blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://shdocpa.dll/asst.htm F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\rxjddnvj.exe, O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file) O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file) O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file) O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file) O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file) O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file) O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file) O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file) O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file) O2 - BHO: (no name) - {75BC0FE9-0320-B195-F169-906263F5741D} - C:\WINDOWS\system32\atlsp.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file) O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file) O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file) O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file) O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file) O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file) O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file) O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file) O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file) O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [FastStart] C:\WINDOWS\system32\svcnut32.exe home O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [strmsnnrs] msnmcgrs.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\RunServices: [strmsnnrs] msnmcgrs.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Hbryerz] C:\WINDOWS\system32\??xplore.exe O4 - HKCU\..\Run: [strmsnnrs] msnmcgrs.exe O4 - HKCU\..\Run: [iMC] C:\Program Files\FriendFinder\FriendFinder Messenger 40\imc.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy release\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Sites Perso - {06FE5D05-8F11-11d2-804F-00105A133818} - http://compaqnet.ifrance.com/heberg/accueil (file missing) O9 - Extra 'Tools' menuitem: Compaq France - {06FE5D05-8F11-11d2-804F-00105A133818} - http://compaqnet.ifrance.com/heberg/accueil (file missing) O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.fr O15 - Trusted Zone: *.frame.crazywinnings.com O15 - Trusted Zone: *.static.topconverting.com O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://encyclo.voila.fr/JS/tdserver.cab O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\bqnuisbj.exe O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.75tz.com/codac/inst2_ax.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095757728839 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EBE7BF9F-63BF-420E-9F0C-0AF2B928FDBB}: NameServer = 80.10.246.5 80.10.246.136 O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 9035 bytes -
Bonjour à tous, J'ai récemment été infecté par smitfraud. Spybot me l'a détecté mais il est incapable de le supprimer. Après quelques recherches sur le net, j'ai téléchargé un petit éxécutable smitfraudfix. D'après la procédure, j'ai donc commencé par l'étape 1 (recherche d'infections) et après on me conseille de poster le contenu du rapport avant de continuer...le voici donc : SmitFraudFix v2.292 Rapport fait à 13:27:54,15, 22/02/2008 Executé à partir de C:\Documents and Settings\ANDRE Mathias\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT Le type du système de fichiers est NTFS Fix executé en mode normal »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rxjddnvj.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\svcnut32.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\qttask.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ANDRE Mathias »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ANDRE Mathias\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ANDREM~1\Favoris »»»»»»»»»»»»»»»»»»»»»»»» Bureau »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll »»»»»»»»»»»»»»»»»»»»»»»» Fin Merci par avance pour votre aide sur l'interprétation de ce rapport et sur la marche à suivre.