Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

hello, Charles,

 

plus de port ouvert tt est ok.

 

Voici le dernier Diaghelp :

 

 

catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-07-30 23:01:46

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden services & system hive ...

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]

"Epoch"=dword:00002d01

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

 

j'ai bien désinstallé mIRC ?

 

Est ce que tu avais ce problème en arrivant sur le forum ? as tu fait des modifications au niveau du fichier d'échange ?

J'avais bien ce pbl de mémoire, c'est récurrent. Je n'ai fait aucune modif sur le fichier d'échange. Je dois ??

 

Est-ce que tu peux m'expliquer comment marche secunia ??

Posté(e) (modifié)

salut :P

 

Je vais t'embêter un peu, mais le rapport DiagHelp n'est pas complêt! il ne fait pas oublier de taper sur une touche à la fin du rapport catchme, sinon le scan ne se termine pas!

Réessaie stp et poste le rapport.

J'avais bien ce pbl de mémoire, c'est récurrent. Je n'ai fait aucune modif sur le fichier d'échange. Je dois ??

D'après ce que montre le rapport WinpFind3U, le pc ne dispose que de 247,48 de ram!! >

247,48 Mb Total Physical Memory

C'est bien insuffisant pour faire fonctionner Windows XP correctement qui rame sous la barre des 512 Mo.

Ca veut dire en gros qu'il va falloir ajouter une barette de mémoire afin de parvenir au minimum vital de 512 Mo.

Il faudra voir ca sur le forum optimisation pour ca car je ne suis pas spécialiste en la matière : on t'aidera à régler la taille du fichier d'échange si nécéssaire.> http://forum.zebulon.fr/index.php?showforum=1

 

Est-ce que tu peux m'expliquer comment marche secunia ??

Désolé mais je ne l'ai jamais utilisé!! si zonk passe par là, il pourra t'en dire plus :P

Modifié par charles ingals
Posté(e)

salut charles,

je dois être vraiment nouille mais j'ai encore un rapport diaghelp incomplet.

Pourtant, j'appuie bien sur entrée (le panneau est rouge avec le nombre de fichiers cachés à la fin), ça reboote, et après j'ouvre mon rapport catchme incomplet. Je loupe une étape ??

 

Merci pour la ram je vais voir si je trouve des barettes compatibles.

 

Comment on fait pour le rapport diaghelp ??

Posté(e)

Bonjour crissou.

 

Vous devriez pouvoir retrouver ce rapport à la base de votre Disque local C:

Il porte le nom de => resultat.txt (format texte et s'ouvre avec Notepad ou Bloc-note).

 

Cordialement.

Posté(e)

Merci Jok

 

voilà donc le dernier résultat.txt.

 

DiagHelp version v1.1.2 - http://www.malekal.com

excute le 31/07/2007 à 22:49:10,48

 

 

Liste des derniers fichies modifies/crees dans windir\system32

C:\WINDOWS\System32/drivers\ssmdrv.sys -->01/03/2007 10:34:36

C:\WINDOWS\System32/drivers\tcpip6.sys -->16/08/2006 11:37:30

C:\WINDOWS\System32/drivers\srv.sys -->14/08/2006 12:34:41

C:\WINDOWS\System32/drivers\rmcast.sys -->13/07/2006 10:48:58

C:\WINDOWS\System32/drivers\rdbss.sys -->05/05/2006 11:47:57

C:\WINDOWS\System32/drivers\mrxsmb.sys -->05/05/2006 11:41:45

C:\WINDOWS\System32/drivers\tcpip.sys -->20/04/2006 13:51:50

 

C:\WINDOWS\System32\bdod.bin -->31/07/2007 22:45:06

C:\WINDOWS\System32\bdss.log -->31/07/2007 20:40:47

C:\WINDOWS\System32\PerfStringBackup.INI -->30/07/2007 23:08:50

C:\WINDOWS\System32\perfh00C.dat -->30/07/2007 23:08:50

C:\WINDOWS\System32\perfh009.dat -->30/07/2007 23:08:50

C:\WINDOWS\System32\perfc00C.dat -->30/07/2007 23:08:50

C:\WINDOWS\System32\perfc009.dat -->30/07/2007 23:08:50

C:\WINDOWS\System32\wpa.dbl -->30/07/2007 22:47:44

C:\WINDOWS\System32\spupdwxp.log -->30/07/2007 22:46:37

C:\WINDOWS\System32\FNTCACHE.DAT -->30/07/2007 22:46:03

C:\WINDOWS\System32\x -->24/07/2007 18:49:32

C:\WINDOWS\System32\swreg.exe -->22/07/2007 18:39:27

C:\WINDOWS\System32\EPPRTDRV.CAB -->14/07/2007 23:14:05

C:\WINDOWS\System32\eps_icon.avi -->14/07/2007 23:14:03

C:\WINDOWS\System32\EPSETUP.CAB -->14/07/2007 23:14:03

C:\WINDOWS\System32\EPSTP32U.CAB -->14/07/2007 23:14:00

C:\WINDOWS\System32\wmpscheme.xml -->14/07/2007 19:43:28

C:\WINDOWS\System32\$winnt$.inf -->14/07/2007 19:43:09

C:\WINDOWS\System32\$ncsp$.inf -->14/07/2007 19:26:44

C:\WINDOWS\System32\qtplugin.log -->14/07/2007 19:24:13

C:\WINDOWS\System32\MRT.exe -->28/06/2007 00:57:28

C:\WINDOWS\System32\wups.dll -->16/04/2007 22:47:36

C:\WINDOWS\System32\wuaucpl.cpl.mui -->16/04/2007 22:47:26

C:\WINDOWS\System32\wuapi.dll.mui -->16/04/2007 22:46:54

C:\WINDOWS\System32\wuaueng.dll -->16/04/2007 22:45:54

 

C:\WINDOWS\wiadebug.log -->31/07/2007 21:54:51

C:\WINDOWS\WindowsUpdate.log -->31/07/2007 19:41:01

C:\WINDOWS\ODBC.INI -->31/07/2007 15:53:00

C:\WINDOWS\win.ini -->31/07/2007 15:12:16

C:\WINDOWS.log -->31/07/2007 14:57:30

C:\WINDOWS\wiaservc.log -->31/07/2007 14:57:06

C:\WINDOWS\spupdsvc.log -->31/07/2007 14:57:04

C:\WINDOWS\bootstat.dat -->31/07/2007 14:56:49

C:\WINDOWS\ntdtcsetup.log -->30/07/2007 23:12:20

C:\WINDOWS\iis6.log -->30/07/2007 23:12:20

C:\WINDOWS\comsetup.log -->30/07/2007 23:12:20

C:\WINDOWS\tsoc.log -->30/07/2007 23:12:19

C:\WINDOWS\ocmsn.log -->30/07/2007 23:12:19

C:\WINDOWS\ocgen.log -->30/07/2007 23:12:19

C:\WINDOWS\msgsocm.log -->30/07/2007 23:12:19

 

 

Le volume dans le lecteur C s'appelle HDD

Le numéro de série du volume est 6C2E-CFA4

 

Répertoire de C:\WINDOWS\system32

 

20/08/2004 01:09 6 144 csrss.exe

1 fichier(s) 6 144 octets

0 Rép(s) 31 694 012 416 octets libres

 

Contenu de Downloaded Program Files

Le volume dans le lecteur C s'appelle HDD

Le numéro de série du volume est 6C2E-CFA4

 

Répertoire de C:\WINDOWS\Downloaded Program Files

 

23/07/2007 16:25 <REP> .

23/07/2007 16:25 <REP> ..

30/09/2002 13:03 65 desktop.ini

14/10/1997 18:52 697 DirectAnimation Java Classes.osd

20/01/2000 15:25 1 162 Microsoft XML Parser for Java.osd

11/06/2007 12:21 5 021 swflash.inf

4 fichier(s) 6 945 octets

 

Total des fichiers listés :

4 fichier(s) 6 945 octets

2 Rép(s) 31 694 012 416 octets libres

 

Recherche de rootkit! (Merci S!Ri)

 

Recherche d'infections connues

 

Export des clefs sensibles..

 

Liste des fichiers en exception sur le pare-feu XP SP2

 

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

 

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

 

Export de la clef SharedTaskScheduler

 

[sharedTaskScheduler]

"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"

"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

 

Rechercher adresses sensibles dans le fichier HOSTS...

 

 

 

Suis-je débarrassée des virus ??

Merci encore pour votre aide à tous, vous rendez l'informatique plus douce (pour des boulets comme moi, bien sûr..)

:P

Posté(e) (modifié)

salut crissou, Zonk, Jok,

 

Merci @ vous pour vos interventions :P

 

crissou : c'est beaucoup mieux! Maintenant que les porst dits critiques sont fermés, on va recommencer juste ces deux opérations afin d'éliminer l'infection pour de bon >

 

1) Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.

Déroule la liste des instructions ci-dessous :

  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

2) Utilisation de WinPFind3U >

  • Ouvre le dossier WinPFind3U et double clique sur le fichier WinPFind3U.exe pour lancer le programme.
  • Sous le groupe Files Created Within sélectionne 30 days
  • Sous le groupe Files Modified Within sélectionne 30 days
  • Sous le groupe String Search sélectionne Non-Microsoft
  • Sous le groupe Additional Scans coche les cases >
    Reg- Security Settings
    Reg- Uninstall List
  • A présent clique sur le bouton Run Scan dans la barre d'outils
  • Lorsque le scan est terminé,le bloc-notes s'ouvre et affiche le rapport.
  • Clique sur le menu "Format" et assure toi que la case "Retour automatique à la ligne" ne soit pas cochée.
  • Copie/Colle le contenu du rapport dans ta prochaine réponse.

Deux étapes déjà faites mais qui sont nécéssaires afin de voir si l'infection n'est pas revenue (c'est parfois coriace!) >

 

Quand tu auras le temps (que tu n'utilises pas le pc) fais ce scan en ligne >

 

Fais un scan en ligne avec Panda :

http://www.pandasoftware.fr/Activescan/Activescan.html .

Et poste le rapport qu'il t'affichera à la fin, pour cela, assure toi que IE est correctement configuré pour le scan en ligne comme indiqué ici : http://www.malekal.com/scan_Av_en_ligne.html#mozTocId898809 .

Si tu n'y arrives pas, le tuto est : http://www.malekal.com/scan_Av_en_ligne.html#mozTocId237368

 

Tu n'es pas obligé de donner ton email, tu peux utiliser une adresse jetable si tu le souhaites : http://www.jetable.org/fr/index

 

Poste stp les rapports suivants :

 

- le rapport de SDFix

- le rapport qui se trouve dans le dossier WinPFind3u( c'est un rapport qui a pour nom la date du jour\mois\année\heure).

-le rapport du scan en ligne.

 

allez courage c'est presque terminé :P

Modifié par charles ingals
Posté(e)

Salut,

 

Voila le Report.txt

 

 

SDFix: Version 1.94

 

Run by romestan on 01/08/2007 at 19:58

 

Microsoft Windows XP [version 5.1.2600]

 

Running From: C:\SDFix

 

Safe Mode:

Checking Services:

 

 

Restoring Windows Registry Values

Restoring Windows Default Hosts File

Restoring Missing Security Center Service

Restoring Missing SharedAccess Service

 

Rebooting...

 

 

Normal Mode:

Checking Files:

 

No Trojan Files Found

 

 

 

 

Removing Temp Files...

 

ADS Check:

 

C:\WINDOWS

No streams found.

 

C:\WINDOWS\system32

No streams found.

 

C:\WINDOWS\system32\svchost.exe

No streams found.

 

C:\WINDOWS\system32\ntoskrnl.exe

No streams found.

 

 

 

Final Check:

 

Remaining Services:

------------------

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

 

Remaining Files:

---------------

 

 

Files with Hidden Attributes:

 

C:\Documents and Settings\romestan\Bureau\WinPFind3u\MovedFiles\WINDOWS\2pack.exe

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0004.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0284.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0292.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL1758.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3125.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3375.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3690.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Peyrolles\~WRL0796.tmp

C:\Documents and Settings\romestan\Mes documents\Mes fichiers\tsouin tsouin\~WRL3039.tmp

C:\WINDOWS\system32\config\DEFAULT.tmp.LOG

C:\WINDOWS\system32\config\SAM.tmp.LOG

C:\WINDOWS\system32\config\SECURITY.tmp.LOG

C:\WINDOWS\system32\config\SOFTWARE.tmp.LOG

C:\WINDOWS\system32\config\SYSTEM.tmp.LOG

 

Finished

 

Hijackthis :

 

Logfile of HijackThis v1.99.1

Scan saved at 20:16:38, on 01/08/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe

C:\Program Files\Softwin\BitDefender10\vsserv.exe

C:\WINDOWS\system32\notepad.exe

C:\Program Files\Softwin\BitDefender10\bdmcon.exe

C:\Program Files\Softwin\BitDefender10\bdagent.exe

C:\WINDOWS\system32\devldr32.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\notepad.exe

C:\Documents and Settings\romestan\Bureau\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg

O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)

O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)

O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)

O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

 

le rapport windfind qui s'est ouvert ds le bloc-notes (pas de fichier avec date et heure ??)

 

WinPFind3 logfile created on: 01/08/2007 21:10:05

WinPFind3U by OldTimer - Version 1.0.39 Folder = C:\Documents and Settings\romestan\Bureau\WinPFind3u\

Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)

Internet Explorer (Version = 6.0.2900.2180)

 

247,48 Mb Total Physical Memory | 124,10 Mb Available Physical Memory | 50,14% Memory free

508,30 Mb Paging File | 121,07 Mb Available in Paging File | 23,82% Paging File free

Paging file location(s): C:\pagefile.sys 144 288;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 35,25 Gb Total Space | 29,35 Gb Free Space | 83,27% Space Free

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

 

Computer Name: SN200412170005

Current User Name: romestan

Logged in as Administrator.

Current Boot Mode: Normal

 

 

[Processes - Non-Microsoft Only]

bdagent.exe -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ]

bdmcon.exe -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ]

bdss.exe -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 19/01/2007 16:12:56 | Attr = ]

devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Modified Date = 23/08/2001 17:47:34 | Attr = ]

livesrv.exe -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 18 | Size = 237568 bytes | Modified Date = 14/07/2007 21:33:04 | Attr = ]

slserv.exe -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ]

vsserv.exe -> %ProgramFiles%\Softwin\BitDefender10\vsserv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 1, 147 | Size = 462848 bytes | Modified Date = 14/07/2007 21:32:52 | Attr = ]

winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.38.0 | Size = 322048 bytes | Modified Date = 23/06/2007 15:15:54 | Attr = ]

xcommsvr.exe -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ]

 

[Win32 Services - Non-Microsoft Only]

(bdss) BitDefender Scan Server [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 19/01/2007 16:12:56 | Attr = ]

(dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 225280 bytes | Modified Date = 20/08/2004 01:09:52 | Attr = ]

(LIVESRV) BitDefender Desktop Update Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 18 | Size = 237568 bytes | Modified Date = 14/07/2007 21:33:04 | Attr = ]

(SLService) SmartLinkService [Win32_Own | Auto | Running] -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ]

(VSSERV) BitDefender Virus Shield [Win32_Own | Auto | Running] -> %ProgramFiles%\Softwin\BitDefender10\vsserv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 1, 147 | Size = 462848 bytes | Modified Date = 14/07/2007 21:32:52 | Attr = ]

(XCOMM) BitDefender Communicator [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ]

 

[Registry - Non-Microsoft Only]

< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->

BDAgent -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ]

BDMCon -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ]

< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->

IMAIL -> Installed = 1 ->

MAPI -> Installed = 1 ->

MSFS -> Installed = 1 ->

< AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->

*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->

sockspy.dll -> %System32%\sockspy.dll -> [Ver = | Size = 73728 bytes | Modified Date = 26/01/2006 20:19:52 | Attr = ]

< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->

< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->

igfxcui -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Modified Date = 13/12/2002 07:09:16 | Attr = ]

< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoCDBurning -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->

< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 36 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> ÿÿÿÿ ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->

< HOSTS File > (686 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->

127.0.0.1 localhost -> ->

< Internet Explorer Settings > -> ->

HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome ->

HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->

HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Start Page -> about:blank ->

HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->

HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->

HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->

HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKCU: Start Page -> http://www.google.fr/ ->

HKCU: ProxyEnable -> 0 ->

< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

msn.com [ - ] -> ->

< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %SystemDrive%\APPS\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 16/04/2001 16:39:02 | Attr = ]

{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 31/05/2005 01:04:00 | Attr = ]

{549B5CA7-4A86-11D7-A4DF-000874180BB3} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found

{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found

< Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->

{32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found

< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->

E&xporter vers Microsoft Excel -> -> File not found

< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform ->

SV1 -> ->

< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->

{9112AFD1-4BD4-4285-AFE7-48BFAE17DD2B} -> (Intel® PRO/100 VE Network Connection) ->

{E54B0B60-E0CA-4847-99A6-8BF3DB3AF3F9} -> () ->

{EA06B917-0C19-44AD-88F2-6A85EFDA9002} -> (Carte réseau 1394) ->

< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->

ipp -> Reg Data - Key not found -> File not found

msdaipp -> Reg Data - Key not found -> File not found

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->

{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab ->

DirectAnimation Java Classes -> - CodeBase = file://C:\WINDOWS\Java\classes\dajava.cab ->

Microsoft XML Parser for Java -> - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab ->

 

 

[Registry - Additional Scans - Non-Microsoft Only]

< Security Settings > -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 3 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> Rpcss; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfère des fichiers en tâche de fond en utilisant la bande passante du réseau lors de ses périodes d'inactivité. Si le service est arrêté, des fonctionnalités telles que Windows Update et MSN Explorer ne pourront plus télécharger automatiquement des programmes et d'autres informations. Si ce service est désactivé, tous les services qui en dépendent explicitement peuvent présenter des problèmes de transfert de fichiers s'ils ne disposent pas d'un mécanisme sûr de remplacement pour transférer les fichier ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\FailureActions ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINDOWS\System32\qmgr.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 2276 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 0 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{8AD6DD74-8038-4A9C-93E1-EF429F4F5416} -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{2F5A5EAE-C9EE-4099-A0E3-AB75B1617E66} -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> Root\LEGACY_SHAREDACCESS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Active le téléchargement et l'installation de mises à jour Windows critiques. Si le service est désactivé, le système d'exploitation peut être mis à jour manuellement sur le site Web de Windows Update. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\System32\wuauserv.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->

< Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->

{1D643CD0-4DD6-11D7-A4E0-000874180BB3} -> Microsoft Money ->

{22524CA1-515C-4153-9807-52AE65F73B5F} -> BitDefender Antivirus Plus v10 ->

{350C940c-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP ->

{8855FF30-19CE-4CB1-A654-87B38369CCE1} -> Sonic RecordNow DX ->

{8C64E149-54BA-11D6-91B1-00500462BE80} -> Extension Système de Microsoft Money ->

{9111040C-6000-11D3-8CFE-0050048383C9} -> Microsoft Office XP Professional ->

EPSON Printer and Utilities -> EPSON Logiciel imprimante ->

EPSON Scanner -> EPSON Scan ->

EVEREST Home Edition_is1 -> EVEREST Home Edition v2.20 ->

Free.fr -> Free - Kit de connexion ->

HijackThis -> HijackThis 1.99.1 ->

KB873339 -> Correctif Windows XP - KB873339 ->

KB885835 -> Correctif Windows XP - KB885835 ->

KB885836 -> Correctif Windows XP - KB885836 ->

KB888302 -> Correctif Windows XP - KB888302 ->

KB890046 -> Mise à jour de sécurité pour Windows XP (KB890046) ->

KB890859 -> Correctif Windows XP - KB890859 ->

KB891781 -> Correctif Windows XP - KB891781 ->

KB893756 -> Mise à jour de sécurité pour Windows XP (KB893756) ->

KB893803v2 -> Windows Installer 3.1 (KB893803) ->

KB896358 -> Mise à jour de sécurité pour Windows XP (KB896358) ->

KB896423 -> Mise à jour de sécurité pour Windows XP (KB896423) ->

KB896424 -> Mise à jour de sécurité pour Windows XP (KB896424) ->

KB896428 -> Mise à jour de sécurité pour Windows XP (KB896428) ->

KB898458 -> Mise à jour de sécurité pour Step by Step Interactive Training (KB898458) ->

KB898461 -> Mise à jour pour Windows XP (KB898461) ->

KB899587 -> Mise à jour de sécurité pour Windows XP (KB899587) ->

KB899591 -> Mise à jour de sécurité pour Windows XP (KB899591) ->

KB900725 -> Mise à jour de sécurité pour Windows XP (KB900725) ->

KB901017 -> Mise à jour de sécurité pour Windows XP (KB901017) ->

KB901214 -> Mise à jour de sécurité pour Windows XP (KB901214) ->

KB902400 -> Mise à jour de sécurité pour Windows XP (KB902400) ->

KB904706 -> Mise à jour de sécurité pour Windows XP (KB904706) ->

KB905414 -> Mise à jour de sécurité pour Windows XP (KB905414) ->

KB905749 -> Mise à jour de sécurité pour Windows XP (KB905749) ->

KB908519 -> Mise à jour de sécurité pour Windows XP (KB908519) ->

KB908531 -> Mise à jour pour Windows XP (KB908531) ->

KB910437 -> Mise à jour pour Windows XP (KB910437) ->

KB911280 -> Mise à jour pour Windows XP (KB911280) ->

KB911562 -> Mise à jour de sécurité pour Windows XP (KB911562) ->

KB911564 -> Mise à jour de sécurité pour Lecteur Windows Media (KB911564) ->

KB911565 -> Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565) ->

KB911927 -> Mise à jour de sécurité pour Windows XP (KB911927) ->

KB912919 -> Mise à jour de sécurité pour Windows XP (KB912919) ->

KB913580 -> Mise à jour de sécurité pour Windows XP (KB913580) ->

KB914388 -> Mise à jour de sécurité pour Windows XP (KB914388) ->

KB914389 -> Mise à jour de sécurité pour Windows XP (KB914389) ->

KB917344 -> Mise à jour de sécurité pour Windows XP (KB917344) ->

KB917422 -> Mise à jour de sécurité pour Windows XP (KB917422) ->

KB917734_WMP8 -> Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734) ->

KB917953 -> Mise à jour de sécurité pour Windows XP (KB917953) ->

KB919007 -> Mise à jour de sécurité pour Windows XP (KB919007) ->

KB920670 -> Mise à jour de sécurité pour Windows XP (KB920670) ->

KB920683 -> Mise à jour de sécurité pour Windows XP (KB920683) ->

KB920685 -> Mise à jour de sécurité pour Windows XP (KB920685) ->

KB921398 -> Mise à jour de sécurité pour Windows XP (KB921398) ->

KB921883 -> Mise à jour de sécurité pour Windows XP (KB921883) ->

KB922616 -> Mise à jour de sécurité pour Windows XP (KB922616) ->

KB922819 -> Mise à jour de sécurité pour Windows XP (KB922819) ->

KB923191 -> Mise à jour de sécurité pour Windows XP (KB923191) ->

KB923414 -> Mise à jour de sécurité pour Windows XP (KB923414) ->

KB924191 -> Mise à jour de sécurité pour Windows XP (KB924191) ->

KB924496 -> Mise à jour de sécurité pour Windows XP (KB924496) ->

PROSet -> Intel® PRO Ethernet Adapter and Software ->

ShockwaveFlash -> Adobe Flash Player 9 ActiveX ->

SigmaTel C-Major -> SigmaTel C-Major Audio ->

Spybot - Search & Destroy_is1 -> Spybot - Search & Destroy 1.4 ->

T r o j a n R e m o v e r_is1 -> Trojan Remover 6.6.1 ->

Windows XP Service Pack -> Windows XP Service Pack 2 ->

 

[Files/Folders - Created Within 30 days]

1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Created Date = 16/07/2007 21:54:49 | Attr = ]

APPS -> %SystemDrive%\APPS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = ]

Bases -> %SystemDrive%\Bases -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ]

BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Created Date = 14/07/2007 18:22:08 | Attr = RHS]

cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 14/07/2007 18:21:59 | Attr = RHS]

ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 27/07/2007 21:12:03 | Attr = ]

DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Created Date = 14/07/2007 16:58:00 | Attr = H ]

Downloads -> %SystemDrive%\Downloads -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ]

DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = H ]

hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Created Date = 02/01/1601 23:00:00 | Attr = HS]

hijackthis -> %SystemDrive%\hijackthis -> [Folder | Created Date = 16/07/2007 16:20:33 | Attr = ]

IO.SYS -> %SystemDrive%\IO.SYS -> [Ver = | Size = 0 bytes | Created Date = 29/07/2007 00:35:50 | Attr = RHS]

Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Created Date = 17/07/2007 14:33:51 | Attr = ]

MSDOS.SYS -> %SystemDrive%\MSDOS.SYS -> [Ver = | Size = 0 bytes | Created Date = 29/07/2007 00:35:50 | Attr = RHS]

PNP -> %SystemDrive%\PNP -> [Folder | Created Date = 14/07/2007 16:58:46 | Attr = H ]

QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 27/07/2007 21:14:55 | Attr = ]

RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 14/07/2007 18:26:49 | Attr = HS]

SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 29/07/2007 00:26:53 | Attr = ]

UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Created Date = 14/07/2007 17:00:32 | Attr = ]

$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 23/07/2007 15:14:30 | Attr = H ]

$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Created Date = 24/07/2007 09:09:56 | Attr = H ]

$NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [Folder | Created Date = 30/07/2007 20:45:23 | Attr = H ]

$NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Created Date = 16/07/2007 21:54:19 | Attr = H ]

$NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Created Date = 23/07/2007 15:15:23 | Attr = H ]

$NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Created Date = 16/07/2007 21:55:00 | Attr = H ]

$NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Created Date = 16/07/2007 21:58:45 | Attr = H ]

$NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Created Date = 24/07/2007 09:10:50 | Attr = H ]

$NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Created Date = 30/07/2007 21:15:52 | Attr = H ]

$NtUninstallKB873339_0$ -> %SystemRoot%\$NtUninstallKB873339_0$ -> [Folder | Created Date = 27/07/2007 19:17:16 | Attr = H ]

$NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Created Date = 30/07/2007 21:16:20 | Attr = H ]

$NtUninstallKB885835_0$ -> %SystemRoot%\$NtUninstallKB885835_0$ -> [Folder | Created Date = 24/07/2007 09:13:43 | Attr = H ]

$NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Created Date = 30/07/2007 21:17:18 | Attr = H ]

$NtUninstallKB885836_0$ -> %SystemRoot%\$NtUninstallKB885836_0$ -> [Folder | Created Date = 27/07/2007 19:18:50 | Attr = H ]

$NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Created Date = 30/07/2007 21:17:34 | Attr = H ]

$NtUninstallKB888302_0$ -> %SystemRoot%\$NtUninstallKB888302_0$ -> [Folder | Created Date = 27/07/2007 19:10:47 | Attr = H ]

$NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Created Date = 30/07/2007 21:17:50 | Attr = H ]

$NtUninstallKB890046_0$ -> %SystemRoot%\$NtUninstallKB890046_0$ -> [Folder | Created Date = 27/07/2007 19:13:09 | Attr = H ]

$NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Created Date = 30/07/2007 21:18:07 | Attr = H ]

$NtUninstallKB890859_0$ -> %SystemRoot%\$NtUninstallKB890859_0$ -> [Folder | Created Date = 27/07/2007 19:05:53 | Attr = H ]

$NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Created Date = 30/07/2007 21:18:32 | Attr = H ]

$NtUninstallKB891781_0$ -> %SystemRoot%\$NtUninstallKB891781_0$ -> [Folder | Created Date = 27/07/2007 19:13:29 | Attr = H ]

$NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Created Date = 30/07/2007 21:18:48 | Attr = H ]

$NtUninstallKB893756_0$ -> %SystemRoot%\$NtUninstallKB893756_0$ -> [Folder | Created Date = 27/07/2007 19:17:41 | Attr = H ]

$NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Created Date = 30/07/2007 21:19:04 | Attr = H ]

$NtUninstallKB896358_0$ -> %SystemRoot%\$NtUninstallKB896358_0$ -> [Folder | Created Date = 24/07/2007 09:08:53 | Attr = H ]

$NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Created Date = 30/07/2007 21:19:20 | Attr = H ]

$NtUninstallKB896423_0$ -> %SystemRoot%\$NtUninstallKB896423_0$ -> [Folder | Created Date = 24/07/2007 09:11:28 | Attr = H ]

$NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Created Date = 30/07/2007 21:19:39 | Attr = H ]

$NtUninstallKB896424_0$ -> %SystemRoot%\$NtUninstallKB896424_0$ -> [Folder | Created Date = 24/07/2007 09:12:09 | Attr = H ]

$NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Created Date = 30/07/2007 21:20:42 | Attr = H ]

$NtUninstallKB896428_0$ -> %SystemRoot%\$NtUninstallKB896428_0$ -> [Folder | Created Date = 27/07/2007 19:09:15 | Attr = H ]

$NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Created Date = 24/07/2007 09:08:17 | Attr = H ]

$NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Created Date = 23/07/2007 15:19:50 | Attr = H ]

$NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Created Date = 30/07/2007 21:21:09 | Attr = H ]

$NtUninstallKB899587_0$ -> %SystemRoot%\$NtUninstallKB899587_0$ -> [Folder | Created Date = 24/07/2007 09:14:38 | Attr = H ]

$NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Created Date = 30/07/2007 21:21:28 | Attr = H ]

$NtUninstallKB899591_0$ -> %SystemRoot%\$NtUninstallKB899591_0$ -> [Folder | Created Date = 24/07/2007 09:12:26 | Attr = H ]

$NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Created Date = 30/07/2007 21:21:48 | Attr = H ]

$NtUninstallKB900725_0$ -> %SystemRoot%\$NtUninstallKB900725_0$ -> [Folder | Created Date = 23/07/2007 15:19:20 | Attr = H ]

$NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Created Date = 30/07/2007 21:22:19 | Attr = H ]

$NtUninstallKB901017_0$ -> %SystemRoot%\$NtUninstallKB901017_0$ -> [Folder | Created Date = 27/07/2007 19:18:06 | Attr = H ]

$NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Created Date = 30/07/2007 21:22:37 | Attr = H ]

$NtUninstallKB901214_0$ -> %SystemRoot%\$NtUninstallKB901214_0$ -> [Folder | Created Date = 27/07/2007 19:11:50 | Attr = H ]

$NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Created Date = 30/07/2007 21:25:40 | Attr = H ]

$NtUninstallKB902400_0$ -> %SystemRoot%\$NtUninstallKB902400_0$ -> [Folder | Created Date = 27/07/2007 19:13:58 | Attr = H ]

$NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Created Date = 23/07/2007 15:22:42 | Attr = H ]

$NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Created Date = 30/07/2007 21:26:09 | Attr = H ]

$NtUninstallKB905414_0$ -> %SystemRoot%\$NtUninstallKB905414_0$ -> [Folder | Created Date = 23/07/2007 15:22:05 | Attr = H ]

$NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Created Date = 27/07/2007 19:15:19 | Attr = H ]

$NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Created Date = 30/07/2007 21:26:35 | Attr = H ]

$NtUninstallKB905749_0$ -> %SystemRoot%\$NtUninstallKB905749_0$ -> [Folder | Created Date = 27/07/2007 19:09:32 | Attr = H ]

$NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Created Date = 30/07/2007 21:27:03 | Attr = H ]

$NtUninstallKB908519_0$ -> %SystemRoot%\$NtUninstallKB908519_0$ -> [Folder | Created Date = 27/07/2007 19:08:53 | Attr = H ]

$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Created Date = 30/07/2007 21:27:33 | Attr = H ]

$NtUninstallKB908531_0$ -> %SystemRoot%\$NtUninstallKB908531_0$ -> [Folder | Created Date = 23/07/2007 15:17:02 | Attr = H ]

$NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Created Date = 30/07/2007 21:27:52 | Attr = H ]

$NtUninstallKB910437_0$ -> %SystemRoot%\$NtUninstallKB910437_0$ -> [Folder | Created Date = 27/07/2007 19:15:45 | Attr = H ]

$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Created Date = 30/07/2007 21:28:10 | Attr = H ]

$NtUninstallKB911280_0$ -> %SystemRoot%\$NtUninstallKB911280_0$ -> [Folder | Created Date = 24/07/2007 09:11:47 | Attr = H ]

$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Created Date = 30/07/2007 21:28:27 | Attr = H ]

$NtUninstallKB911562_0$ -> %SystemRoot%\$NtUninstallKB911562_0$ -> [Folder | Created Date = 27/07/2007 19:17:29 | Attr = H ]

$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Created Date = 23/07/2007 15:27:02 | Attr = H ]

$NtUninstallKB911565$ -> %SystemRoot%\$NtUninstallKB911565$ -> [Folder | Created Date = 30/07/2007 22:11:28 | Attr = H ]

$NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Created Date = 27/07/2007 19:09:51 | Attr = H ]

$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Created Date = 30/07/2007 21:28:42 | Attr = H ]

$NtUninstallKB911927_0$ -> %SystemRoot%\$NtUninstallKB911927_0$ -> [Folder | Created Date = 24/07/2007 09:13:01 | Attr = H ]

$NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Created Date = 30/07/2007 21:29:02 | Attr = H ]

$NtUninstallKB912919_0$ -> %SystemRoot%\$NtUninstallKB912919_0$ -> [Folder | Created Date = 27/07/2007 19:10:26 | Attr = H ]

$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Created Date = 30/07/2007 21:29:18 | Attr = H ]

$NtUninstallKB913580_0$ -> %SystemRoot%\$NtUninstallKB913580_0$ -> [Folder | Created Date = 23/07/2007 15:16:12 | Attr = H ]

$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Created Date = 30/07/2007 21:29:35 | Attr = H ]

$NtUninstallKB914388_0$ -> %SystemRoot%\$NtUninstallKB914388_0$ -> [Folder | Created Date = 27/07/2007 19:12:50 | Attr = H ]

$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Created Date = 30/07/2007 21:29:51 | Attr = H ]

$NtUninstallKB914389_0$ -> %SystemRoot%\$NtUninstallKB914389_0$ -> [Folder | Created Date = 27/07/2007 19:07:38 | Attr = H ]

$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Created Date = 30/07/2007 21:30:07 | Attr = H ]

$NtUninstallKB917344_0$ -> %SystemRoot%\$NtUninstallKB917344_0$ -> [Folder | Created Date = 27/07/2007 19:12:27 | Attr = H ]

$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Created Date = 30/07/2007 21:30:23 | Attr = H ]

$NtUninstallKB917422_0$ -> %SystemRoot%\$NtUninstallKB917422_0$ -> [Folder | Created Date = 27/07/2007 19:11:24 | Attr = H ]

$NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Created Date = 23/07/2007 15:21:35 | Attr = H ]

$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Created Date = 30/07/2007 21:30:39 | Attr = H ]

$NtUninstallKB917953_0$ -> %SystemRoot%\$NtUninstallKB917953_0$ -> [Folder | Created Date = 27/07/2007 19:12:08 | Attr = H ]

$NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Created Date = 27/07/2007 19:16:08 | Attr = H ]

$NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Created Date = 23/07/2007 15:17:53 | Attr = H ]

$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Created Date = 30/07/2007 21:31:08 | Attr = H ]

$NtUninstallKB919007_0$ -> %SystemRoot%\$NtUninstallKB919007_0$ -> [Folder | Created Date = 23/07/2007 15:23:17 | Attr = H ]

$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Created Date = 30/07/2007 21:31:25 | Attr = H ]

$NtUninstallKB920670_0$ -> %SystemRoot%\$NtUninstallKB920670_0$ -> [Folder | Created Date = 23/07/2007 15:25:55 | Attr = H ]

$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Created Date = 30/07/2007 21:31:49 | Attr = H ]

$NtUninstallKB920683_0$ -> %SystemRoot%\$NtUninstallKB920683_0$ -> [Folder | Created Date = 23/07/2007 15:14:33 | Attr = H ]

$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Created Date = 30/07/2007 21:32:07 | Attr = H ]

$NtUninstallKB920685_0$ -> %SystemRoot%\$NtUninstallKB920685_0$ -> [Folder | Created Date = 27/07/2007 19:17:54 | Attr = H ]

$NtUninstallKB921398$ -> %SystemRoot%\$NtUninstallKB921398$ -> [Folder | Created Date = 30/07/2007 22:12:08 | Attr = H ]

$NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Created Date = 30/07/2007 21:32:25 | Attr = H ]

$NtUninstallKB921883_0$ -> %SystemRoot%\$NtUninstallKB921883_0$ -> [Folder | Created Date = 27/07/2007 19:18:37 | Attr = H ]

$NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Created Date = 30/07/2007 21:32:42 | Attr = H ]

$NtUninstallKB922616_0$ -> %SystemRoot%\$NtUninstallKB922616_0$ -> [Folder | Created Date = 24/07/2007 09:12:44 | Attr = H ]

$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Created Date = 30/07/2007 21:33:02 | Attr = H ]

$NtUninstallKB922819_0$ -> %SystemRoot%\$NtUninstallKB922819_0$ -> [Folder | Created Date = 24/07/2007 09:14:16 | Attr = H ]

$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Created Date = 30/07/2007 21:33:18 | Attr = H ]

$NtUninstallKB923191_0$ -> %SystemRoot%\$NtUninstallKB923191_0$ -> [Folder | Created Date = 23/07/2007 15:20:15 | Attr = H ]

$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Created Date = 30/07/2007 21:33:35 | Attr = H ]

$NtUninstallKB923414_0$ -> %SystemRoot%\$NtUninstallKB923414_0$ -> [Folder | Created Date = 24/07/2007 09:13:19 | Attr = H ]

$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Created Date = 30/07/2007 21:33:50 | Attr = H ]

$NtUninstallKB924191_0$ -> %SystemRoot%\$NtUninstallKB924191_0$ -> [Folder | Created Date = 27/07/2007 19:20:18 | Attr = H ]

$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Created Date = 30/07/2007 21:34:06 | Attr = H ]

$NtUninstallKB924496_0$ -> %SystemRoot%\$NtUninstallKB924496_0$ -> [Folder | Created Date = 27/07/2007 19:16:58 | Attr = H ]

$NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Created Date = 24/07/2007 09:10:31 | Attr = H ]

$NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Created Date = 14/07/2007 18:11:50 | Attr = H ]

$NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Created Date = 14/07/2007 18:12:01 | Attr = H ]

$NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Created Date = 14/07/2007 18:12:09 | Attr = H ]

$NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Created Date = 14/07/2007 18:12:15 | Attr = H ]

$NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Created Date = 14/07/2007 18:12:22 | Attr = H ]

$NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Created Date = 14/07/2007 18:12:28 | Attr = H ]

$NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Created Date = 14/07/2007 18:12:34 | Attr = H ]

AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Created Date = 14/07/2007 18:23:10 | Attr = ]

catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ]

CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Created Date = 14/07/2007 22:12:46 | Attr = ]

Drivers -> %SystemRoot%\Drivers -> [Folder | Created Date = 14/07/2007 18:15:46 | Attr = ]

EHome -> %SystemRoot%\EHome -> [Folder | Created Date = 30/07/2007 20:45:11 | Attr = ]

erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 27/07/2007 21:18:34 | Attr = ]

ERUNT -> %SystemRoot%\ERUNT -> [Folder | Created Date = 29/07/2007 00:35:30 | Attr = ]

Favoris -> %SystemRoot%\Favoris -> [Folder | Created Date = 28/07/2007 10:00:25 | Attr = R ]

imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Created Date = 27/07/2007 19:06:32 | Attr = ]

jautoexp.dat -> %SystemRoot%\jautoexp.dat -> [Ver = | Size = 6550 bytes | Created Date = 23/07/2007 15:24:39 | Attr = ]

Minidump -> %SystemRoot%\Minidump -> [Folder | Created Date = 26/07/2007 22:17:32 | Attr = ]

Modio -> %SystemRoot%\Modio -> [Folder | Created Date = 14/07/2007 18:12:58 | Attr = ]

NEC.BMP -> %SystemRoot%\NEC.BMP -> [Ver = | Size = 149262 bytes | Created Date = 14/07/2007 18:15:08 | Attr = ]

nircmd.exe -> %SystemRoot%\nircmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ]

ODBC.INI -> %SystemRoot%\ODBC.INI -> [Ver = | Size = 385 bytes | Created Date = 31/07/2007 14:53:00 | Attr = ]

peernet -> %SystemRoot%\peernet -> [Folder | Created Date = 30/07/2007 21:04:15 | Attr = ]

Profiles -> %SystemRoot%\Profiles -> [Folder | Created Date = 14/07/2007 18:23:11 | Attr = ]

provisioning -> %SystemRoot%\provisioning -> [Folder | Created Date = 30/07/2007 21:04:12 | Attr = ]

pss -> %SystemRoot%\pss -> [Folder | Created Date = 24/07/2007 10:09:04 | Attr = ]

RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Created Date = 14/07/2007 18:15:32 | Attr = ]

REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Created Date = 14/07/2007 18:29:00 | Attr = ]

RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Created Date = 14/07/2007 18:26:20 | Attr = ]

ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [Folder | Created Date = 30/07/2007 20:57:29 | Attr = ]

ShellNew -> %SystemRoot%\ShellNew -> [Folder | Created Date = 31/07/2007 14:50:22 | Attr = ]

sl.lng -> %SystemRoot%\sl.lng -> [Ver = | Size = 49354 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

SmCfg.exe -> %SystemRoot%\SmCfg.exe -> [Ver = 2, 80, 1, 0 | Size = 61440 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Created Date = 14/07/2007 18:26:48 | Attr = ]

SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:11:09 | Attr = ]

unvise32qt.exe -> %SystemRoot%\unvise32qt.exe -> MindVision [Ver = 2.8.3 | Size = 86016 bytes | Created Date = 14/07/2007 18:24:04 | Attr = ]

WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Created Date = 30/07/2007 21:07:58 | Attr = ]

$ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Created Date = 14/07/2007 18:26:44 | Attr = ]

amr_cpl.dll -> %System32%\amr_cpl.dll -> [Ver = 2, 81, 0, 0 | Size = 139264 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Created Date = 14/07/2007 19:20:20 | Attr = ]

bits -> %System32%\bits -> [Folder | Created Date = 24/07/2007 09:10:54 | Attr = ]

ctwdm32.dll -> %System32%\ctwdm32.dll -> Creative Technology Ltd. [Ver = 5.0.0.2001 | Size = 4096 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

devcon32.dll -> %System32%\devcon32.dll -> Creative Technology Ltd. [Ver = 4.06.651 | Size = 256512 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Created Date = 14/07/2007 22:14:02 | Attr = ]

EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ]

EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ]

EPSTP32U.DAT -> %System32%\EPSTP32U.DAT -> [Ver = | Size = 6390 bytes | Created Date = 14/07/2007 22:14:00 | Attr = R ]

eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Created Date = 14/07/2007 22:14:03 | Attr = ]

esccmd.dll -> %System32%\esccmd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 22528 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ]

escimgd.dll -> %System32%\escimgd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 46080 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ]

escwiad.dll -> %System32%\escwiad.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 29696 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ]

E_DCINST.DLL -> %System32%\E_DCINST.DLL -> SEIKO EPSON CORP. [Ver = 1, 0, 0, 1 | Size = 31744 bytes | Created Date = 15/07/2007 08:55:22 | Attr = ]

E_FBCB9EE.DLL -> %System32%\E_FBCB9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 2, 0, 0, 27 | Size = 64000 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ]

E_FBCH9EE.DLL -> %System32%\E_FBCH9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 1, 1, 0, 0 | Size = 34304 bytes | Created Date = 15/07/2007 08:55:16 | Attr = ]

E_FLM9EE.DLL -> %System32%\E_FLM9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 5, 1, 0, 0 | Size = 79654 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ]

hccutils.dll -> %System32%\hccutils.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

iAlmCoIn_0_v9.dll -> %System32%\iAlmCoIn_0_v9.dll -> Intel Corporation [Ver = 1.00.1000.1 | Size = 61440 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmdd5.dll -> %System32%\ialmdd5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 435266 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmdev5.dll -> %System32%\ialmdev5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 192507 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmdnt5.dll -> %System32%\ialmdnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 114236 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmgdev.dll -> %System32%\ialmgdev.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 188416 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmgicd.dll -> %System32%\ialmgicd.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 1859584 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmrem.dll -> %System32%\ialmrem.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 57344 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmrnt5.dll -> %System32%\ialmrnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 33792 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxcfg.exe -> %System32%\igfxcfg.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 483328 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxcpl.cpl -> %System32%\igfxcpl.cpl -> Intel Corporation [Ver = 3,0,0,1992 | Size = 94208 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdev.dll -> %System32%\igfxdev.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 147456 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdgps.dll -> %System32%\igfxdgps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 45056 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdiag.exe -> %System32%\igfxdiag.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxdo.dll -> %System32%\igfxdo.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxeud.dll -> %System32%\igfxeud.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 221184 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxexps.dll -> %System32%\igfxexps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 32768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxext.exe -> %System32%\igfxext.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhara.lhp -> %System32%\igfxhara.lhp -> [Ver = | Size = 55633 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxharb.lhp -> %System32%\igfxharb.lhp -> [Ver = | Size = 55654 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhchs.lhp -> %System32%\igfxhchs.lhp -> [Ver = | Size = 55426 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhcht.lhp -> %System32%\igfxhcht.lhp -> [Ver = | Size = 56139 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhcsy.lhp -> %System32%\igfxhcsy.lhp -> [Ver = | Size = 58343 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhdan.lhp -> %System32%\igfxhdan.lhp -> [Ver = | Size = 56933 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhdeu.lhp -> %System32%\igfxhdeu.lhp -> [Ver = | Size = 58017 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhell.lhp -> %System32%\igfxhell.lhp -> [Ver = | Size = 58791 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxheng.lhp -> %System32%\igfxheng.lhp -> [Ver = | Size = 55186 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhenu.lhp -> %System32%\igfxhenu.lhp -> [Ver = | Size = 55002 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhesp.lhp -> %System32%\igfxhesp.lhp -> [Ver = | Size = 56980 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhfin.lhp -> %System32%\igfxhfin.lhp -> [Ver = | Size = 57762 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhfra.lhp -> %System32%\igfxhfra.lhp -> [Ver = | Size = 56829 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhfrc.lhp -> %System32%\igfxhfrc.lhp -> [Ver = | Size = 56735 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhheb.lhp -> %System32%\igfxhheb.lhp -> [Ver = | Size = 61249 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhhun.lhp -> %System32%\igfxhhun.lhp -> [Ver = | Size = 59369 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhita.lhp -> %System32%\igfxhita.lhp -> [Ver = | Size = 56548 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhjpn.lhp -> %System32%\igfxhjpn.lhp -> [Ver = | Size = 57858 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhk.dll -> %System32%\igfxhk.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 118784 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhkor.lhp -> %System32%\igfxhkor.lhp -> [Ver = | Size = 63399 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhnld.lhp -> %System32%\igfxhnld.lhp -> [Ver = | Size = 57353 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhnor.lhp -> %System32%\igfxhnor.lhp -> [Ver = | Size = 56813 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhplk.lhp -> %System32%\igfxhplk.lhp -> [Ver = | Size = 58108 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhptb.lhp -> %System32%\igfxhptb.lhp -> [Ver = | Size = 56119 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhptg.lhp -> %System32%\igfxhptg.lhp -> [Ver = | Size = 56649 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhrus.lhp -> %System32%\igfxhrus.lhp -> [Ver = | Size = 58767 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhsve.lhp -> %System32%\igfxhsve.lhp -> [Ver = | Size = 56636 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhtha.lhp -> %System32%\igfxhtha.lhp -> [Ver = | Size = 59797 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxhtrk.lhp -> %System32%\igfxhtrk.lhp -> [Ver = | Size = 57768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxpph.dll -> %System32%\igfxpph.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 204800 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrara.lrc -> %System32%\igfxrara.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrarb.lrc -> %System32%\igfxrarb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrchs.lrc -> %System32%\igfxrchs.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrcht.lrc -> %System32%\igfxrcht.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrcsy.lrc -> %System32%\igfxrcsy.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrdan.lrc -> %System32%\igfxrdan.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrdeu.lrc -> %System32%\igfxrdeu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

igfxrell.lrc -> %System32%\igfxrell.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 163840 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxreng.lrc -> %System32%\igfxreng.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrenu.lrc -> %System32%\igfxrenu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxres.dll -> %System32%\igfxres.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:17:29 | Attr = ]

igfxresp.lrc -> %System32%\igfxresp.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxress.dll -> %System32%\igfxress.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 503808 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrfin.lrc -> %System32%\igfxrfin.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrfra.lrc -> %System32%\igfxrfra.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrfrc.lrc -> %System32%\igfxrfrc.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrheb.lrc -> %System32%\igfxrheb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrhun.lrc -> %System32%\igfxrhun.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrita.lrc -> %System32%\igfxrita.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrjpn.lrc -> %System32%\igfxrjpn.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrkor.lrc -> %System32%\igfxrkor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrnld.lrc -> %System32%\igfxrnld.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrnor.lrc -> %System32%\igfxrnor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrplk.lrc -> %System32%\igfxrplk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrptb.lrc -> %System32%\igfxrptb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrptg.lrc -> %System32%\igfxrptg.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrrus.lrc -> %System32%\igfxrrus.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrsve.lrc -> %System32%\igfxrsve.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrtha.lrc -> %System32%\igfxrtha.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxrtrk.lrc -> %System32%\igfxrtrk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxsrvc.dll -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

igfxtray.exe -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

javasup.vxd -> %System32%\javasup.vxd -> [Ver = | Size = 7315 bytes | Created Date = 23/07/2007 15:24:40 | Attr = ]

minirec.exe -> %System32%\minirec.exe -> SmartLink [Ver = 1.0 (8.1.2001) | Size = 163840 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

mpeg2data.ax -> %System32%\mpeg2data.ax -> [Ver = | Size = 118272 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

msdvbnp.ax -> %System32%\msdvbnp.ax -> [Ver = | Size = 56832 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

ntio.sys -> %System32%\ntio.sys -> [Ver = | Size = 34000 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio404.sys -> %System32%\ntio404.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio411.sys -> %System32%\ntio411.sys -> [Ver = | Size = 35648 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio412.sys -> %System32%\ntio412.sys -> [Ver = | Size = 35424 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

ntio804.sys -> %System32%\ntio804.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ]

PreInstall -> %System32%\PreInstall -> [Folder | Created Date = 23/07/2007 15:19:56 | Attr = ]

psisdecd.dll -> %System32%\psisdecd.dll -> [Ver = | Size = 363520 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

psisrndr.ax -> %System32%\psisrndr.ax -> [Ver = | Size = 33280 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ]

QuickTime -> %System32%\QuickTime -> [Folder | Created Date = 14/07/2007 18:23:54 | Attr = ]

ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Created Date = 14/07/2007 18:13:07 | Attr = ]

sblfx.dll -> %System32%\sblfx.dll -> Creative Technology Ltd. [Ver = 5.12.01.3210 | Size = 495616 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

secupd.dat -> %System32%\secupd.dat -> [Ver = | Size = 4569 bytes | Created Date = 29/07/2007 20:02:52 | Attr = ]

secupd.sig -> %System32%\secupd.sig -> [Ver = | Size = 7208 bytes | Created Date = 29/07/2007 20:02:52 | Attr = ]

sfman32.dll -> %System32%\sfman32.dll -> Creative Technology Ltd. [Ver = 4.06.501 | Size = 51200 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

slcpappl.chm -> %System32%\slcpappl.chm -> [Ver = | Size = 136104 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

slcpappl.cpl -> %System32%\slcpappl.cpl -> SmartLink [Ver = 2, 92, 0, 2 | Size = 339968 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

SLLights.dll -> %System32%\SLLights.dll -> [Ver = 2, 0, 9, 9 | Size = 405504 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

slmh.cab -> %System32%\slmh.cab -> [Ver = | Size = 351388 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

slmh.exe -> %System32%\slmh.exe -> SmartLink [Ver = 2, 92, 0, 3 | Size = 372736 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:12:20 | Attr = ]

swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ]

swsc.exe -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.0 | Size = 370688 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ]

swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ]

unacev2.dll -> %System32%\unacev2.dll -> [Ver = | Size = 75264 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

UNRAR3.dll -> %System32%\UNRAR3.dll -> [Ver = | Size = 153088 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

vfind.exe -> %System32%\vfind.exe -> [Ver = | Size = 49152 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ]

zonedoff.reg -> %System32%\zonedoff.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:19 | Attr = ]

zonedon.reg -> %System32%\zonedon.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:20 | Attr = ]

ztvunace26.dll -> %System32%\ztvunace26.dll -> [Ver = | Size = 77312 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

ztvunrar36.dll -> %System32%\ztvunrar36.dll -> [Ver = | Size = 162304 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ]

2gmgsmt.sf2 -> %System32%\drivers\2gmgsmt.sf2 -> [Ver = | Size = 2104298 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

a302.sys -> %System32%\drivers\a302.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a303.sys -> %System32%\drivers\a303.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 27703 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a304.sys -> %System32%\drivers\a304.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 45111 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a305.sys -> %System32%\drivers\a305.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a306.sys -> %System32%\drivers\a306.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 16439 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a307.sys -> %System32%\drivers\a307.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20535 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a308.sys -> %System32%\drivers\a308.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a309.sys -> %System32%\drivers\a309.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 25655 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a310.sys -> %System32%\drivers\a310.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 32823 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a311.sys -> %System32%\drivers\a311.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 31799 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a312.sys -> %System32%\drivers\a312.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a313.sys -> %System32%\drivers\a313.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 35895 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

a314.sys -> %System32%\drivers\a314.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 17463 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ctlfacem.sys -> %System32%\drivers\ctlfacem.sys -> Creative Technology Ltd. [Ver = 5.12.01.2108 built by: WinDDK | Size = 6912 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

ctljystk.sys -> %System32%\drivers\ctljystk.sys -> Creative Technology Ltd. [Ver = 5.1.2501.0 built by: WinDDK | Size = 3712 bytes | Created Date = 14/07/2007 18:08:52 | Attr = ]

emu10k1m.sys -> %System32%\drivers\emu10k1m.sys -> Creative Technology Ltd. [Ver = 5.12.01.3300 built by: WinDDK | Size = 283904 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

fbxusb.sys -> %System32%\drivers\fbxusb.sys -> FreeBox SA [Ver = 1.2.0.0 | Size = 18848 bytes | Created Date = 14/07/2007 19:31:27 | Attr = R ]

ialmkchw.sys -> %System32%\drivers\ialmkchw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 78144 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmnt5.sys -> %System32%\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 87579 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

ialmsbw.sys -> %System32%\drivers\ialmsbw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 108480 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ]

KProcCheck.sys -> %System32%\drivers\KProcCheck.sys -> [Ver = | Size = 4096 bytes | Created Date = 26/07/2007 22:17:01 | Attr = ]

netwlan5.img -> %System32%\drivers\netwlan5.img -> [Ver = | Size = 67866 bytes | Created Date = 29/07/2007 20:02:52 | Attr = ]

sfmanm.sys -> %System32%\drivers\sfmanm.sys -> Creative Technology Ltd. [Ver = 4.10.3300 | Size = 36480 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ]

ssmdrv.sys -> %System32%\drivers\ssmdrv.sys -> Avira GmbH [Ver = 7.0.1.1 | Size = 28352 bytes | Created Date = 14/07/2007 18:50:45 | Attr = ]

vch.sys -> %System32%\drivers\vch.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20021 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

wa301a.sys -> %System32%\drivers\wa301a.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

wa301b.sys -> %System32%\drivers\wa301b.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ]

winddx.sys -> %System32%\drivers\winddx.sys -> Smart Link Ltd. [Ver = 2.80.02 | Size = 42328 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ]

 

[Files/Folders - Modified Within 30 days]

1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Modified Date = 16/07/2007 22:56:28 | Attr = ]

APPS -> %SystemDrive%\APPS -> [Folder | Modified Date = 14/07/2007 19:24:22 | Attr = ]

Bases -> %SystemDrive%\Bases -> [Folder | Modified Date = 17/07/2007 15:36:36 | Attr = ]

BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Modified Date = 14/07/2007 19:17:44 | Attr = RHS]

BOOT.INI -> %SystemDrive%\BOOT.INI -> [Ver = | Size = 291 bytes | Modified Date = 30/07/2007 22:08:26 | Attr = RHS]

cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 14/07/2007 19:22:10 | Attr = RHS]

ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 27/07/2007 22:29:28 | Attr = ]

DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Modified Date = 14/07/2007 17:58:00 | Attr = H ]

Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 14/07/2007 19:43:22 | Attr = ]

Downloads -> %SystemDrive%\Downloads -> [Folder | Modified Date = 26/07/2007 15:49:52 | Attr = ]

DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Modified Date = 14/07/2007 19:44:30 | Attr = H ]

hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Modified Date = 01/08/2007 20:04:48 | Attr = HS]

hijackthis -> %SystemDrive%\hijackthis -> [Folder | Modified Date = 16/07/2007 18:17:02 | Attr = ]

IO.SYS -> %SystemDrive%\IO.SYS -> [Ver = | Size = 0 bytes | Modified Date = 29/07/2007 01:35:52 | Attr = RHS]

Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Modified Date = 18/07/2007 09:48:56 | Attr = ]

MSDOS.SYS -> %SystemDrive%\MSDOS.SYS -> [Ver = | Size = 0 bytes | Modified Date = 29/07/2007 01:35:52 | Attr = RHS]

NTDETECT.COM -> %SystemDrive%\NTDETECT.COM -> [Ver = | Size = 47564 bytes | Modified Date = 30/07/2007 21:51:50 | Attr = RHS]

PNP -> %SystemDrive%\PNP -> [Folder | Modified Date = 14/07/2007 17:58:46 | Attr = H ]

Program Files -> %ProgramFiles% -> [Folder | Modified Date = 31/07/2007 22:01:20 | Attr = R ]

QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 27/07/2007 22:14:56 | Attr = ]

RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 14/07/2007 20:12:42 | Attr = HS]

SDFix -> %SystemDrive%\SDFix -> [Folder | Modified Date = 01/08/2007 20:06:54 | Attr = ]

System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 30/07/2007 22:46:06 | Attr = HS]

UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Modified Date = 14/07/2007 18:00:32 | Attr = ]

WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 01/08/2007 20:05:32 | Attr = ]

$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 01/08/2007 11:23:00 | Attr = H ]

$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Modified Date = 24/07/2007 10:10:04 | Attr = H ]

$NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [Folder | Modified Date = 30/07/2007 21:50:26 | Attr = H ]

$NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Modified Date = 16/07/2007 22:54:20 | Attr = H ]

$NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Modified Date = 23/07/2007 16:15:26 | Attr = H ]

$NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Modified Date = 27/07/2007 20:18:26 | Attr = H ]

$NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Modified Date = 16/07/2007 22:58:52 | Attr = H ]

$NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Modified Date = 24/07/2007 10:10:54 | Attr = H ]

$NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Modified Date = 30/07/2007 22:15:54 | Attr = H ]

$NtUninstallKB873339_0$ -> %SystemRoot%\$NtUninstallKB873339_0$ -> [Folder | Modified Date = 27/07/2007 20:17:18 | Attr = H ]

$NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Modified Date = 30/07/2007 22:16:22 | Attr = H ]

$NtUninstallKB885835_0$ -> %SystemRoot%\$NtUninstallKB885835_0$ -> [Folder | Modified Date = 24/07/2007 10:13:46 | Attr = H ]

$NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Modified Date = 30/07/2007 22:17:20 | Attr = H ]

$NtUninstallKB885836_0$ -> %SystemRoot%\$NtUninstallKB885836_0$ -> [Folder | Modified Date = 27/07/2007 20:18:52 | Attr = H ]

$NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Modified Date = 30/07/2007 22:17:36 | Attr = H ]

$NtUninstallKB888302_0$ -> %SystemRoot%\$NtUninstallKB888302_0$ -> [Folder | Modified Date = 27/07/2007 20:10:50 | Attr = H ]

$NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Modified Date = 30/07/2007 22:17:52 | Attr = H ]

$NtUninstallKB890046_0$ -> %SystemRoot%\$NtUninstallKB890046_0$ -> [Folder | Modified Date = 27/07/2007 20:13:12 | Attr = H ]

$NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Modified Date = 30/07/2007 22:18:10 | Attr = H ]

$NtUninstallKB890859_0$ -> %SystemRoot%\$NtUninstallKB890859_0$ -> [Folder | Modified Date = 27/07/2007 20:05:56 | Attr = H ]

$NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Modified Date = 30/07/2007 22:18:34 | Attr = H ]

$NtUninstallKB891781_0$ -> %SystemRoot%\$NtUninstallKB891781_0$ -> [Folder | Modified Date = 27/07/2007 20:13:30 | Attr = H ]

$NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Modified Date = 30/07/2007 22:18:50 | Attr = H ]

$NtUninstallKB893756_0$ -> %SystemRoot%\$NtUninstallKB893756_0$ -> [Folder | Modified Date = 27/07/2007 20:17:44 | Attr = H ]

$NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Modified Date = 30/07/2007 22:19:06 | Attr = H ]

$NtUninstallKB896358_0$ -> %SystemRoot%\$NtUninstallKB896358_0$ -> [Folder | Modified Date = 24/07/2007 10:08:56 | Attr = H ]

$NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Modified Date = 30/07/2007 22:19:22 | Attr = H ]

$NtUninstallKB896423_0$ -> %SystemRoot%\$NtUninstallKB896423_0$ -> [Folder | Modified Date = 24/07/2007 10:11:30 | Attr = H ]

$NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Modified Date = 30/07/2007 22:19:42 | Attr = H ]

$NtUninstallKB896424_0$ -> %SystemRoot%\$NtUninstallKB896424_0$ -> [Folder | Modified Date = 24/07/2007 10:12:12 | Attr = H ]

$NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Modified Date = 30/07/2007 22:20:44 | Attr = H ]

$NtUninstallKB896428_0$ -> %SystemRoot%\$NtUninstallKB896428_0$ -> [Folder | Modified Date = 27/07/2007 20:09:18 | Attr = H ]

$NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Modified Date = 24/07/2007 10:08:20 | Attr = H ]

$NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Modified Date = 23/07/2007 16:19:52 | Attr = H ]

$NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Modified Date = 30/07/2007 22:21:12 | Attr = H ]

$NtUninstallKB899587_0$ -> %SystemRoot%\$NtUninstallKB899587_0$ -> [Folder | Modified Date = 24/07/2007 10:14:42 | Attr = H ]

$NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Modified Date = 30/07/2007 22:21:30 | Attr = H ]

$NtUninstallKB899591_0$ -> %SystemRoot%\$NtUninstallKB899591_0$ -> [Folder | Modified Date = 24/07/2007 10:12:30 | Attr = H ]

$NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Modified Date = 30/07/2007 22:21:50 | Attr = H ]

$NtUninstallKB900725_0$ -> %SystemRoot%\$NtUninstallKB900725_0$ -> [Folder | Modified Date = 23/07/2007 16:19:22 | Attr = H ]

$NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Modified Date = 30/07/2007 22:22:22 | Attr = H ]

$NtUninstallKB901017_0$ -> %SystemRoot%\$NtUninstallKB901017_0$ -> [Folder | Modified Date = 27/07/2007 20:18:08 | Attr = H ]

$NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Modified Date = 30/07/2007 22:22:40 | Attr = H ]

$NtUninstallKB901214_0$ -> %SystemRoot%\$NtUninstallKB901214_0$ -> [Folder | Modified Date = 27/07/2007 20:11:52 | Attr = H ]

$NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Modified Date = 30/07/2007 22:25:44 | Attr = H ]

$NtUninstallKB902400_0$ -> %SystemRoot%\$NtUninstallKB902400_0$ -> [Folder | Modified Date = 27/07/2007 20:14:02 | Attr = H ]

$NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Modified Date = 23/07/2007 16:22:44 | Attr = H ]

$NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Modified Date = 30/07/2007 22:26:12 | Attr = H ]

$NtUninstallKB905414_0$ -> %SystemRoot%\$NtUninstallKB905414_0$ -> [Folder | Modified Date = 23/07/2007 16:22:08 | Attr = H ]

$NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Modified Date = 27/07/2007 20:15:22 | Attr = H ]

$NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Modified Date = 30/07/2007 22:26:38 | Attr = H ]

$NtUninstallKB905749_0$ -> %SystemRoot%\$NtUninstallKB905749_0$ -> [Folder | Modified Date = 27/07/2007 20:09:34 | Attr = H ]

$NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Modified Date = 30/07/2007 22:27:06 | Attr = H ]

$NtUninstallKB908519_0$ -> %SystemRoot%\$NtUninstallKB908519_0$ -> [Folder | Modified Date = 27/07/2007 20:08:56 | Attr = H ]

$NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Modified Date = 30/07/2007 22:27:36 | Attr = H ]

$NtUninstallKB908531_0$ -> %SystemRoot%\$NtUninstallKB908531_0$ -> [Folder | Modified Date = 23/07/2007 16:17:04 | Attr = H ]

$NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Modified Date = 30/07/2007 22:27:54 | Attr = H ]

$NtUninstallKB910437_0$ -> %SystemRoot%\$NtUninstallKB910437_0$ -> [Folder | Modified Date = 27/07/2007 20:15:48 | Attr = H ]

$NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Modified Date = 30/07/2007 22:28:14 | Attr = H ]

$NtUninstallKB911280_0$ -> %SystemRoot%\$NtUninstallKB911280_0$ -> [Folder | Modified Date = 24/07/2007 10:11:50 | Attr = H ]

$NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Modified Date = 30/07/2007 22:28:30 | Attr = H ]

$NtUninstallKB911562_0$ -> %SystemRoot%\$NtUninstallKB911562_0$ -> [Folder | Modified Date = 27/07/2007 20:17:32 | Attr = H ]

$NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Modified Date = 23/07/2007 16:27:04 | Attr = H ]

$NtUninstallKB911565$ -> %SystemRoot%\$NtUninstallKB911565$ -> [Folder | Modified Date = 30/07/2007 23:11:30 | Attr = H ]

$NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Modified Date = 27/07/2007 20:09:56 | Attr = H ]

$NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Modified Date = 30/07/2007 22:28:46 | Attr = H ]

$NtUninstallKB911927_0$ -> %SystemRoot%\$NtUninstallKB911927_0$ -> [Folder | Modified Date = 24/07/2007 10:13:04 | Attr = H ]

$NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Modified Date = 30/07/2007 22:29:04 | Attr = H ]

$NtUninstallKB912919_0$ -> %SystemRoot%\$NtUninstallKB912919_0$ -> [Folder | Modified Date = 27/07/2007 20:10:28 | Attr = H ]

$NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Modified Date = 30/07/2007 22:29:20 | Attr = H ]

$NtUninstallKB913580_0$ -> %SystemRoot%\$NtUninstallKB913580_0$ -> [Folder | Modified Date = 23/07/2007 16:16:16 | Attr = H ]

$NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Modified Date = 30/07/2007 22:29:38 | Attr = H ]

$NtUninstallKB914388_0$ -> %SystemRoot%\$NtUninstallKB914388_0$ -> [Folder | Modified Date = 27/07/2007 20:12:52 | Attr = H ]

$NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Modified Date = 30/07/2007 22:29:54 | Attr = H ]

$NtUninstallKB914389_0$ -> %SystemRoot%\$NtUninstallKB914389_0$ -> [Folder | Modified Date = 27/07/2007 20:07:42 | Attr = H ]

$NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Modified Date = 30/07/2007 22:30:10 | Attr = H ]

$NtUninstallKB917344_0$ -> %SystemRoot%\$NtUninstallKB917344_0$ -> [Folder | Modified Date = 27/07/2007 20:12:30 | Attr = H ]

$NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Modified Date = 30/07/2007 22:30:26 | Attr = H ]

$NtUninstallKB917422_0$ -> %SystemRoot%\$NtUninstallKB917422_0$ -> [Folder | Modified Date = 27/07/2007 20:11:28 | Attr = H ]

$NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Modified Date = 23/07/2007 16:21:38 | Attr = H ]

$NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Modified Date = 30/07/2007 22:30:42 | Attr = H ]

$NtUninstallKB917953_0$ -> %SystemRoot%\$NtUninstallKB917953_0$ -> [Folder | Modified Date = 27/07/2007 20:12:10 | Attr = H ]

$NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Modified Date = 27/07/2007 20:16:10 | Attr = H ]

$NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Modified Date = 23/07/2007 16:18:04 | Attr = H ]

$NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Modified Date = 30/07/2007 22:31:10 | Attr = H ]

$NtUninstallKB919007_0$ -> %SystemRoot%\$NtUninstallKB919007_0$ -> [Folder | Modified Date = 23/07/2007 16:23:20 | Attr = H ]

$NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Modified Date = 30/07/2007 22:31:28 | Attr = H ]

$NtUninstallKB920670_0$ -> %SystemRoot%\$NtUninstallKB920670_0$ -> [Folder | Modified Date = 23/07/2007 16:25:58 | Attr = H ]

$NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Modified Date = 30/07/2007 22:31:52 | Attr = H ]

$NtUninstallKB920683_0$ -> %SystemRoot%\$NtUninstallKB920683_0$ -> [Folder | Modified Date = 23/07/2007 16:14:36 | Attr = H ]

$NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Modified Date = 30/07/2007 22:32:10 | Attr = H ]

$NtUninstallKB920685_0$ -> %SystemRoot%\$NtUninstallKB920685_0$ -> [Folder | Modified Date = 27/07/2007 20:17:56 | Attr = H ]

$NtUninstallKB921398$ -> %SystemRoot%\$NtUninstallKB921398$ -> [Folder | Modified Date = 30/07/2007 23:12:10 | Attr = H ]

$NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Modified Date = 30/07/2007 22:32:28 | Attr = H ]

$NtUninstallKB921883_0$ -> %SystemRoot%\$NtUninstallKB921883_0$ -> [Folder | Modified Date = 27/07/2007 20:18:40 | Attr = H ]

$NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Modified Date = 30/07/2007 22:32:44 | Attr = H ]

$NtUninstallKB922616_0$ -> %SystemRoot%\$NtUninstallKB922616_0$ -> [Folder | Modified Date = 24/07/2007 10:12:46 | Attr = H ]

$NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Modified Date = 30/07/2007 22:33:04 | Attr = H ]

$NtUninstallKB922819_0$ -> %SystemRoot%\$NtUninstallKB922819_0$ -> [Folder | Modified Date = 24/07/2007 10:14:18 | Attr = H ]

$NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Modified Date = 30/07/2007 22:33:22 | Attr = H ]

$NtUninstallKB923191_0$ -> %SystemRoot%\$NtUninstallKB923191_0$ -> [Folder | Modified Date = 23/07/2007 16:20:18 | Attr = H ]

$NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Modified Date = 30/07/2007 22:33:38 | Attr = H ]

$NtUninstallKB923414_0$ -> %SystemRoot%\$NtUninstallKB923414_0$ -> [Folder | Modified Date = 24/07/2007 10:13:22 | Attr = H ]

$NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Modified Date = 30/07/2007 22:33:52 | Attr = H ]

$NtUninstallKB924191_0$ -> %SystemRoot%\$NtUninstallKB924191_0$ -> [Folder | Modified Date = 27/07/2007 20:20:20 | Attr = H ]

$NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Modified Date = 30/07/2007 22:34:08 | Attr = H ]

$NtUninstallKB924496_0$ -> %SystemRoot%\$NtUninstallKB924496_0$ -> [Folder | Modified Date = 27/07/2007 20:17:02 | Attr = H ]

$NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Modified Date = 24/07/2007 10:10:34 | Attr = H ]

$NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Modified Date = 14/07/2007 19:11:52 | Attr = H ]

$NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Modified Date = 14/07/2007 19:12:02 | Attr = H ]

$NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Modified Date = 14/07/2007 19:12:10 | Attr = H ]

$NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Modified Date = 14/07/2007 19:12:16 | Attr = H ]

$NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Modified Date = 14/07/2007 19:12:24 | Attr = H ]

$NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Modified Date = 14/07/2007 19:12:30 | Attr = H ]

$NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Modified Date = 14/07/2007 19:12:36 | Attr = H ]

AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Modified Date = 14/07/2007 19:23:18 | Attr = ]

AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 30/07/2007 22:46:02 | Attr = ]

bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 01/08/2007 20:04:54 | Attr = S]

catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Modified Date = 20/07/2007 00:47:24 | Attr = ]

CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Modified Date = 14/07/2007 23:12:48 | Attr = ]

Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 30/07/2007 22:48:44 | Attr = ]

Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 23/07/2007 16:25:26 | Attr = S]

Drivers -> %SystemRoot%\Drivers -> [Folder | Modified Date = 14/07/2007 19:15:48 | Attr = ]

EHome -> %SystemRoot%\EHome -> [Folder | Modified Date = 30/07/2007 21:45:12 | Attr = ]

erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 27/07/2007 22:18:36 | Attr = ]

ERUNT -> %SystemRoot%\ERUNT -> [Folder | Modified Date = 29/07/2007 01:35:32 | Attr = ]

Favoris -> %SystemRoot%\Favoris -> [Folder | Modified Date = 01/08/2007 14:20:44 | Attr = R ]

Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 31/07/2007 15:59:20 | Attr = R S]

Help -> %SystemRoot%\Help -> [Folder | Modified Date = 30/07/2007 22:05:28 | Attr = ]

ime -> %SystemRoot%\ime -> [Folder | Modified Date = 30/07/2007 22:05:10 | Attr = ]

imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 30/07/2007 23:11:48 | Attr = ]

inf -> %SystemRoot%\inf -> [Folder | Modified Date = 01/08/2007 11:23:56 | Attr = H ]

Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 01/08/2007 19:52:08 | Attr = HS]

Media -> %SystemRoot%\Media -> [Folder | Modified Date = 30/07/2007 22:04:14 | Attr = ]

Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 31/07/2007 22:51:30 | Attr = ]

Modio -> %SystemRoot%\Modio -> [Folder | Modified Date = 14/07/2007 19:13:00 | Attr = ]

msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 30/07/2007 22:46:02 | Attr = ]

ODBC.INI -> %SystemRoot%\ODBC.INI -> [Ver = | Size = 385 bytes | Modified Date = 31/07/2007 15:53:02 | Attr = ]

peernet -> %SystemRoot%\peernet -> [Folder | Modified Date = 30/07/2007 22:04:16 | Attr = ]

Profiles -> %SystemRoot%\Profiles -> [Folder | Modified Date = 14/07/2007 19:23:12 | Attr = ]

provisioning -> %SystemRoot%\provisioning -> [Folder | Modified Date = 30/07/2007 22:04:14 | Attr = ]

pss -> %SystemRoot%\pss -> [Folder | Modified Date = 24/07/2007 11:09:06 | Attr = ]

RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Modified Date = 14/07/2007 19:15:34 | Attr = ]

Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 14/07/2007 19:42:14 | Attr = ]

REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Modified Date = 14/07/2007 19:29:02 | Attr = ]

RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Modified Date = 14/07/2007 19:26:26 | Attr = ]

security -> %SystemRoot%\security -> [Folder | Modified Date = 31/07/2007 23:10:50 | Attr = ]

ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [Folder | Modified Date = 30/07/2007 21:57:30 | Attr = ]

setupapi.log.0.old -> %SystemRoot%\setupapi.log.0.old -> [Ver = | Size = 1595275 bytes | Modified Date = 16/07/2007 22:55:14 | Attr = ]

ShellNew -> %SystemRoot%\ShellNew -> [Folder | Modified Date = 31/07/2007 15:51:36 | Attr = ]

smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Modified Date = 14/07/2007 19:26:50 | Attr = ]

SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:30 | Attr = ]

srchasst -> %SystemRoot%\srchasst -> [Folder | Modified Date = 30/07/2007 21:56:38 | Attr = ]

system -> %SystemRoot%\system -> [Folder | Modified Date = 31/07/2007 15:47:46 | Attr = ]

system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 231 bytes | Modified Date = 14/07/2007 19:29:10 | Attr = ]

system32 -> %System32% -> [Folder | Modified Date = 01/08/2007 20:07:18 | Attr = ]

Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 01/08/2007 21:06:58 | Attr = ]

twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 14/07/2007 23:13:24 | Attr = ]

Web -> %SystemRoot%\Web -> [Folder | Modified Date = 30/07/2007 21:52:18 | Attr = R ]

win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 635 bytes | Modified Date = 01/08/2007 11:23:30 | Attr = ]

WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 30/07/2007 22:06:04 | Attr = ]

WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Modified Date = 30/07/2007 22:48:02 | Attr = ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 26/07/2007 17:49:30 | Attr = H ]

$ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Modified Date = 14/07/2007 19:26:46 | Attr = ]

$winnt$.inf -> %System32%\$winnt$.inf -> [Ver = | Size = 497 bytes | Modified Date = 14/07/2007 19:43:10 | Attr = ]

bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Modified Date = 01/08/2007 21:06:38 | Attr = ]

bits -> %System32%\bits -> [Folder | Modified Date = 24/07/2007 10:10:56 | Attr = ]

CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 30/07/2007 23:12:02 | Attr = ]

CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 01/08/2007 11:22:36 | Attr = ]

Com -> %System32%\Com -> [Folder | Modified Date = 30/07/2007 22:25:50 | Attr = ]

config -> %System32%\config -> [Folder | Modified Date = 27/07/2007 22:18:42 | Attr = ]

dllcache -> %System32%\dllcache -> [Folder | Modified Date = 30/07/2007 23:12:14 | Attr = RHS]

drivers -> %System32%\drivers -> [Folder | Modified Date = 30/07/2007 22:45:58 | Attr = ]

EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Modified Date = 14/07/2007 23:14:06 | Attr = ]

EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ]

EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Modified Date = 14/07/2007 23:14:02 | Attr = ]

eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ]

FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 112584 bytes | Modified Date = 31/07/2007 22:51:22 | Attr = ]

Macromed -> %System32%\Macromed -> [Folder | Modified Date = 14/07/2007 19:24:36 | Attr = ]

mui -> %System32%\mui -> [Folder | Modified Date = 30/07/2007 22:05:10 | Attr = ]

npp -> %System32%\npp -> [Folder | Modified Date = 30/07/2007 21:56:42 | Attr = ]

oobe -> %System32%\oobe -> [Folder | Modified Date = 30/07/2007 22:05:22 | Attr = ]

perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 39992 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ]

perfc00C.dat -> %System32%\perfc00C.dat -> [Ver = | Size = 48616 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ]

perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 311604 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ]

perfh00C.dat -> %System32%\perfh00C.dat -> [Ver = | Size = 367658 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ]

PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 775034 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ]

PreInstall -> %System32%\PreInstall -> [Folder | Modified Date = 23/07/2007 16:19:58 | Attr = ]

QuickTime -> %System32%\QuickTime -> [Folder | Modified Date = 14/07/2007 19:24:06 | Attr = ]

ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 30/07/2007 21:50:50 | Attr = ]

Restore -> %System32%\Restore -> [Folder | Modified Date = 30/07/2007 21:56:42 | Attr = ]

Setup -> %System32%\Setup -> [Folder | Modified Date = 30/07/2007 22:05:12 | Attr = ]

SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:22 | Attr = ]

swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ]

usmt -> %System32%\usmt -> [Folder | Modified Date = 30/07/2007 21:55:04 | Attr = ]

wbem -> %System32%\wbem -> [Folder | Modified Date = 30/07/2007 22:46:42 | Attr = ]

wmpscheme.xml -> %System32%\wmpscheme.xml -> [Ver = | Size = 25065 bytes | Modified Date = 14/07/2007 19:43:30 | Attr = ]

wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1170 bytes | Modified Date = 30/07/2007 22:47:46 | Attr = ]

etc -> %System32%\drivers\etc -> [Folder | Modified Date = 01/08/2007 19:59:38 | Attr = ]

 

[File String Scan - Non-Microsoft Only]

PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41131 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ]

UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ]

winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ]

PTech , -> %System32%\drivers\mtlstrm.sys -> [Ver = 3.00.01 | Size = 1805544 bytes | Modified Date = 18/04/2002 09:58:02 | Attr = ]

 

< End of report >

 

je lance panda et je reposte,

@+

 

Posté(e)

Hello;

j'arrive pas à telecharger Activescan :P . Je reessaierai demain. En plus, j'ai encore un message virus de bit defender, d'un certain GenericMalware.

Je te poste un hijackthis au cas où.

Je vais me changer les idées, là, je sature.

A+

 

Logfile of HijackThis v1.99.1

Scan saved at 22:23:36, on 01/08/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe

C:\Program Files\Softwin\BitDefender10\bdmcon.exe

C:\Program Files\Softwin\BitDefender10\bdagent.exe

C:\WINDOWS\system32\devldr32.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe

C:\Program Files\Softwin\BitDefender10\vsserv.exe

C:\Program Files\internet explorer\iexplore.exe

C:\Documents and Settings\romestan\Bureau\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg

O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)

O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)

O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)

O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

Posté(e)

salut crissou,

 

Je regarde tes rapports et te dis ce qu'il en est :P

 

Si le scan Panda pose problème, essaie celui ci quand tu peux >

  • Fais un scan en ligne Kaspersky avec Internet Explorer :
  • Clique sur bouton-scann1.jpg
  • Clique maintenant sur J'accepte.
  • Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
  • Patiente pendant l'installation des Mises à jour.
  • Choisis par la suite l'analyse du Poste de travail
  • Sauvegarde puis colle le rapport généré en fin d'analyse.

AIDE : Configurer le contrôle des ActiveX

Note : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", vas dans Ajout/Suppression de programmes et désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...