Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

Goto page : 1, 2  Next

View previous topic View next topic Go down  Message [Page 1 of 2]

1 Help for Core10k virus removal =) on Tue Nov 24, 2009 6:02 pm

Darklad


Member
Member
Hi everyone, thanks in advance for the Help you can bring me =)

Here is my Hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:55:52, on 24/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\SFR\Media Center\MediaCenter.exe
C:\Users\Daniel\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\SFR\Media Center\httpd\httpd.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\SFR\Media Center\httpd\httpd.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Logitech\SetPoint\LU\LULnchr.exe
C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe
C:\Program Files\DNA\btdna.exe
C:\Windows\system32\conime.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=0081011
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101764&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Daniel\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: McAfee Security Scan.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

--
End of file - 13176 bytes

Thanks again ...

2 Re: Help for Core10k virus removal =) on Tue Nov 24, 2009 7:27 pm

DragonMaster Jay


Site Owner
Site Owner
Please download Malwarebytes Anti-Malware from here.

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

3 Re: Help for Core10k virus removal =) on Tue Nov 24, 2009 9:48 pm

Darklad


Member
Member
Here it is:

Malwarebytes' Anti-Malware 1.41
Database version: 3225
Windows 6.0.6001 Service Pack 1

25/11/2009 03:46:17
mbam-log-2009-11-25 (03-46-17).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 295501
Time elapsed: 1 hour(s), 50 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

4 Re: Help for Core10k virus removal =) on Tue Nov 24, 2009 9:54 pm

DragonMaster Jay


Site Owner
Site Owner
Please run Trend Micro Housecall online scan.

  • Click Scan now.
  • Read and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • If confirmed that HouseCall can run on your system, under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
  • You may receive a Security Warning about the TrendMicro Java applet, click YES.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

5 Re: Help for Core10k virus removal =) on Wed Nov 25, 2009 11:44 am

Darklad


Member
Member
It is blocked on "Ouverture de Trend Micro HouseCall" ---> Opening of Trend Micro HouseCall

6 Re: Help for Core10k virus removal =) on Wed Nov 25, 2009 3:08 pm

DragonMaster Jay


Site Owner
Site Owner
Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

7 Re: Help for Core10k virus removal =) on Wed Nov 25, 2009 8:17 pm

Darklad


Member
Member
I hate to say this but, at 36% of the scan it tells me that the program has stoped functioning. Sorry about the problems ...

8 Re: Help for Core10k virus removal =) on Wed Nov 25, 2009 11:14 pm

DragonMaster Jay


Site Owner
Site Owner
Please download RootRepeal from GooglePages.com.

  • Extract the program file to your Desktop.
  • Run the program RootRepeal.exe and go to the Report tab and click on the Scan button.


  • Select ALL of the checkboxes and then click OK and it will start scanning your system.

  • If you have multiple drives you only need to check the C: drive or the one Windows is installed on.
  • When done, click on Save Report
  • Save it to the Desktop.
  • Please copy/paste the contents of the report in your next reply.

Please remove any e-mail address in the RootRepeal report (if present).

==

Please download SpiderKill by DragonMaster Jay and save it to your Desktop.
  • Right-click on SpiderKill.zip and click Extract All. Follow the prompts and read carefully, to save it to your Desktop.
  • Double-click on the SpiderKill folder, and then double-click on SpiderKill.bat and follow all the prompts in the program.
  • Within a minute, it will save its log titled SpiderKill.txt. Please post that in your next reply. You may have to use two or three posts to be able to fit the information in.


==

Please post the RootRepeal and SpiderKill logs in your next reply.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

9 Re: Help for Core10k virus removal =) on Thu Nov 26, 2009 8:42 am

Darklad


Member
Member
RootRepeal report:

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2009/11/26 13:54
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================

Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x912B4000 Size: 815104 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9EDDF000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5961-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc59aa-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc59bc-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc59cf-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc59e8-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc59f8-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5a07-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5a1f-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5a8a-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5ab2-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5ad9-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5b08-cf32-11de-bb4b-002268defea7}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3edc5b4a-cf32-11de-bb4b-002170819023}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\Users\Daniel\Documents\Mes vidéos
Status: Locked to the Windows API!

Path: C:\Windows\System32\XPSViewer\XPSVIE~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11df268b7c6d9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_abac38a907ee8801.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_4ddfc6cd11929a02.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_d088a2ec442ef17b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d218504d2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_91949b06671d08ae.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_none_10b3ea459bfee365.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_516953ad0f4d16c4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\msil_system.speech_31bf3856ad364e35_6.0.6000.16708_none_080e70cf835a2dc3\SYSTEM~1.DLL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\msil_system.speech_31bf3856ad364e35_6.0.6000.20864_none_08532cea9cac0fd7\SYSTEM~1.DLL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\67D651~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\9581C2~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\82DF71~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\0B9797~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\70862A~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\6132EF~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\CCC5E4~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\5C5472~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\731E17~1.CHM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\3E095E~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\E578B7~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\B41E33~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\7A2BFD~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\3DFD3C~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\02E7BE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\2AEECC~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_fr-fr_a409ac9a88331b9b\041628~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\67D651~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\9581C2~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\82DF71~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\0B9797~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\70862A~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\6132EF~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\CCC5E4~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\5C5472~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\731E17~1.CHM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\3E095E~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\E578B7~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\B41E33~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\7A2BFD~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\3DFD3C~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\02E7BE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\2AEECC~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_fr-fr_a4556abba17eaf10\041628~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\67D651~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\9581C2~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\82DF71~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\0B9797~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\70862A~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\6132EF~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\CCC5E4~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\5C5472~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\731E17~1.CHM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\3E095E~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\E578B7~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\B41E33~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\7A2BFD~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\3DFD3C~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\02E7BE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\2AEECC~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_fr-fr_a5fbbb768550a9f2\041628~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\67D651~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\9581C2~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\82DF71~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\0B9797~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\70862A~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\6132EF~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\CCC5E4~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\5C5472~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\731E17~1.CHM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\3E095E~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\E578B7~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\B41E33~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\7A2BFD~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\3DFD3C~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\02E7BE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\2AEECC~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_fr-fr_a66eb81f9e7f6847\041628~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\67D651~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\9581C2~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\731E17~1.CHM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\3E095E~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\E578B7~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\B41E33~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\7A2BFD~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\3DFD3C~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\02E7BE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\2AEECC~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\041628~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\5C5472~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\0B9797~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\70862A~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\6132EF~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\CCC5E4~1.INI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_fr-fr_a7f1023e826b42cf\82DF71~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\WIRELE~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\WIRELE~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\WIRELE~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\WIRELE~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\WIRELE~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6000.16720_none_f570e12815568682\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6000.20883_none_dea8f7cc2ef8cb75\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6001.18111_none_f54bc5de15a89323\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6001.22230_none_de80367a2f4e0c36\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-machine_config_ocm_b03f5f7f11d50a3a_6.0.6002.18005_none_f52661bc15faf3ee\MACHIN~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-dv_aspnetmmc_chm_res_b03f5f7f11d50a3a_6.0.6001.22230_none_ddac10e22fd3c967\DV_ASP~1.CHM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-msbuild_commontypes_schema_b03f5f7f11d50a3a_6.0.6001.22230_none_599095f00849688b\MICROS~1.XSD
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6000.16708_none_c4f661e592b1c88e\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6000.20864_none_c53b1e00ac03aaa2\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6001.18096_none_c6794ec590232523\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_reg_31bf3856ad364e35_6.0.6001.22208_none_c7663d56a8f5f949\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6000.16708_none_cab9e41b8efd69ed\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6000.20864_none_cafea036a84f4c01\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6001.18096_none_cc3cd0fb8c6ec682\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_vrg_31bf3856ad364e35_6.0.6001.22208_none_cd29bf8ca5419aa8\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6000.16708_none_f87832f6f02b1a0c\_SERVI~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6000.20864_none_f8bcef12097cfc20\_SERVI~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6001.18096_none_f9fb1fd6ed9c76a1\_SERVI~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.16708_none_74dcd7a292078251\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6000.20864_none_752193bdab596465\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.18096_none_765fc4828f78dee6\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_reg_31bf3856ad364e35_6.0.6001.22208_none_774cb313a84bb30c\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.16708_none_7aa059d88e5323b0\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6000.20864_none_7ae515f3a7a505c4\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.18096_none_7c2346b88bc48045\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_svc_perf_vrg_31bf3856ad364e35_6.0.6001.22208_none_7d103549a497546b\_SERVI~1.VRG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_end_perf_h_31bf3856ad364e35_6.0.6000.20864_none_24101549d032590a\_SERVI~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_h_31bf3856ad364e35_6.0.6001.22208_none_fae80e68066f4ac7\_SERVI~1.H
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wcf-m_svc_mod_op_perf_c_reg_31bf3856ad364e35_6.0.6001.22208_none_c8512a7445976b57\_SERVI~1.REG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_wpf-globaluserinterfacecf_31bf3856ad364e35_6.0.6001.18096_none_ada2ec92b42bf87e\GLOBAL~1.COM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6000.16720_none_b462fc0cbe880bcb\MICROS~1.XSD
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6000.20883_none_9d9b12b0d82a50be\MICROS~1.XSD
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6001.18111_none_b43de0c2beda186c\MICROS~1.XSD
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-msbuild_core_schema__b03f5f7f11d50a3a_6.0.6001.22230_none_9d72515ed87f917f\MICROS~1.XSD
SProcesses
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1224 Status: Locked to the Windows API!

Stealth Objects
-------------------
Object: Hidden Module [Name: msgslang.14.0.8089.0726.dll]
Process: msnmsgr.exe (PID: 2864) Address: 0x68610000 Size: 364544

Object: Hidden Module [Name: msgsres.dll]
Process: msnmsgr.exe (PID: 2864) Address: 0x63c30000 Size: 11403264

Object: Hidden Module [Name: msgrvsta.thm]
Process: msnmsgr.exe (PID: 2864) Address: 0x6cda0000 Size: 20480

==EOF==

10 Re: Help for Core10k virus removal =) on Thu Nov 26, 2009 8:45 am

Darklad


Member
Member
SpiderKill by DragonMaster Jay ( Oct 2009 )


Microsoft Windows [version 6.0.6001]

********************Drivers list********************


Le volume dans le lecteur C s'appelle OS
Le num‚ro de s‚rie du volume est 3606-63F0

R‚pertoire de C:\Windows\System32\Drivers

26/11/2009 13:53 .
26/11/2009 13:53 ..
12/10/2008 00:06 4ÿ673 1028_Dell_STU_1735.mrk
21/01/2008 03:23 53ÿ376 1394bus.sys
21/01/2008 03:23 266ÿ808 acpi.sys
21/01/2008 03:23 422ÿ968 adp94xx.sys
21/01/2008 03:23 300ÿ600 adpahci.sys
21/01/2008 03:23 101ÿ432 adpu160m.sys
21/01/2008 03:23 149ÿ560 adpu320.sys
21/01/2008 03:24 273ÿ920 afd.sys
21/01/2008 03:23 56ÿ376 AGP440.sys
21/01/2008 03:23 17ÿ464 aliide.sys
21/01/2008 03:23 57ÿ400 AMDAGP.SYS
21/01/2008 03:23 17ÿ976 amdide.sys
21/01/2008 03:23 41ÿ472 amdk7.sys
21/01/2008 03:23 44ÿ032 amdk8.sys
30/06/2008 11:28 170ÿ032 Apfiltr.sys
21/01/2008 03:23 79ÿ416 arc.sys
21/01/2008 03:23 79ÿ928 arcsas.sys
16/05/2008 00:16 20ÿ560 aswFsBlk.sys
16/05/2008 00:18 50ÿ768 aswMonFlt.sys
16/05/2008 00:15 23ÿ152 aswRdr.sys
16/05/2008 00:20 78ÿ416 aswSP.sys
16/05/2008 00:14 42ÿ912 aswTdi.sys
21/01/2008 03:24 17ÿ408 asyncmac.sys
12/10/2008 00:08 21ÿ560 atapi.sys
21/01/2008 03:23 110ÿ136 ataport.sys
04/05/2008 09:42 49ÿ152 ati2erec.dll
04/05/2008 09:42 3ÿ548ÿ672 atikmdag.sys
01/10/2006 22:10 328ÿ162 ativcaxx.cpa
01/10/2006 22:10 929 ativcaxx.vp
04/05/2008 09:42 2ÿ096 ativdkxx.vp
04/05/2008 09:42 2ÿ096 ativokxx.vp
04/05/2008 09:42 2ÿ096 ativpkxx.vp
04/05/2008 09:42 52ÿ400 ativvpxx.vp
21/01/2008 03:23 28ÿ216 battc.sys
05/08/2008 13:16 18ÿ424 bcm42rly.sys
05/08/2008 13:17 1ÿ207ÿ288 BCMWL6.SYS
21/01/2008 03:23 12ÿ288 bdasup.sys
21/01/2008 03:23 6ÿ144 beep.sys
21/01/2008 03:23 45ÿ568 blbdrive.sys
21/01/2008 03:23 69ÿ632 bowser.sys
02/11/2006 09:24 13ÿ568 BrFiltLo.sys
02/11/2006 09:24 5ÿ248 BrFiltUp.sys
21/01/2008 03:23 93ÿ696 bridge.sys
02/11/2006 09:25 71ÿ808 BrSerId.sys
02/11/2006 09:24 62ÿ336 BrSerWdm.sys
02/11/2006 09:24 12ÿ160 BrUsbMdm.sys
02/11/2006 09:24 11ÿ904 BrUsbSer.sys
12/10/2008 00:09 19ÿ456 bthenum.sys
21/01/2008 03:23 39ÿ936 bthmodem.sys
21/01/2008 03:23 92ÿ160 bthpan.sys
12/10/2008 00:09 220ÿ160 bthport.sys
12/10/2008 00:09 29ÿ184 BTHUSB.SYS
16/06/2008 10:24 81ÿ960 btwaudio.sys
16/06/2008 10:24 100ÿ392 btwavdt.sys
16/06/2008 10:24 29ÿ736 btwl2cap.sys
16/06/2008 10:24 17ÿ448 btwrchid.sys
21/01/2008 03:23 70ÿ144 cdfs.sys
17/10/2007 01:00 9ÿ072 cdr4_xp.sys
17/10/2007 01:00 9ÿ200 cdralw2k.sys
21/01/2008 03:23 67ÿ072 cdrom.sys
21/01/2008 03:23 35ÿ328 circlass.sys
21/01/2008 03:24 127ÿ544 Classpnp.sys
21/01/2008 03:23 14ÿ208 CmBatt.sys
21/01/2008 03:23 19ÿ000 cmdide.sys
21/01/2008 03:23 20ÿ792 compbatt.sys
21/01/2008 03:23 36ÿ408 crashdmp.sys
21/01/2008 03:23 24ÿ632 crcdisk.sys
21/01/2008 03:23 40ÿ960 crusoe.sys
21/01/2008 03:24 75ÿ264 dfsc.sys
21/01/2008 03:23 55ÿ352 disk.sys
21/01/2008 03:24 19ÿ968 Diskdump.sys
02/11/2006 10:50 71ÿ272 djsvs.sys
21/01/2008 03:23 130ÿ048 drmk.sys
21/01/2008 03:23 5ÿ632 drmkaud.sys
21/01/2008 03:24 29ÿ240 Dumpata.sys
21/01/2008 03:24 13ÿ312 dxapi.sys
21/01/2008 03:24 76ÿ288 dxg.sys
02/08/2008 02:01 625ÿ152 dxgkrnl.sys
21/01/2008 03:23 220ÿ672 e1e6032.sys
21/01/2008 03:23 118ÿ784 E1G60I32.sys
21/01/2008 03:23 143ÿ416 ecache.sys
21/01/2008 03:23 342ÿ584 elxstor.sys
21/01/2008 03:23 6ÿ656 errdev.sys
09/09/2009 17:14 etc
21/01/2008 03:25 136ÿ192 exfat.sys
21/01/2008 03:24 143ÿ360 fastfat.sys
21/01/2008 03:23 25ÿ088 fdc.sys
21/01/2008 03:24 58ÿ936 fileinfo.sys
21/01/2008 03:24 27ÿ648 filetrace.sys
19/09/2006 12:56 57ÿ656 FilterPC.bmp
30/08/2007 10:39 24ÿ995 FilterPC.jpg
21/01/2008 03:23 20ÿ480 flpydisk.sys
21/01/2008 03:24 192ÿ056 fltMgr.sys
21/01/2008 09:39 fr-FR
05/08/2009 22:48 54ÿ632 fssfltr.sys
21/01/2008 03:24 12ÿ800 fs_rec.sys
21/01/2008 03:23 101ÿ432 FWPKCLNT.SYS
21/01/2008 03:23 61ÿ496 GAGP30KX.SYS
18/05/2009 13:17 26ÿ600 GEARAspiWDM.sys
18/09/2006 22:26 3ÿ440ÿ660 gm.dls
18/09/2006 22:26 646 gmreadme.txt
21/01/2008 03:23 53ÿ760 hdaudbus.sys
02/11/2006 08:36 235ÿ520 HdAudio.sys
02/11/2006 09:55 29ÿ184 hidbth.sys
21/01/2008 03:23 38ÿ912 hidclass.sys
21/01/2008 03:23 21ÿ504 hidir.sys
21/01/2008 03:23 25ÿ472 hidparse.sys
21/01/2008 03:23 12ÿ288 hidusb.sys
21/01/2008 03:23 40ÿ504 HpCISSs.sys
21/01/2008 03:23 401ÿ408 http.sys
21/01/2008 03:23 19ÿ000 i2omgmt.sys
21/01/2008 03:23 30ÿ264 i2omp.sys
21/01/2008 03:23 54ÿ784 i8042prt.sys
13/03/2008 12:42 305ÿ176 iaStor.sys
21/01/2008 03:23 235ÿ064 iaStorV.sys
02/11/2006 10:50 41ÿ576 iirsp.sys
21/01/2008 03:23 17ÿ976 intelide.sys
21/01/2008 03:23 41ÿ472 intelppm.sys
21/01/2008 03:24 47ÿ616 ipfltdrv.sys
21/01/2008 03:23 64ÿ512 IPMIDrv.sys
21/01/2008 03:24 100ÿ864 ipnat.sys
21/01/2008 03:24 95ÿ744 irda.sys
21/01/2008 03:23 13ÿ312 irenum.sys
21/01/2008 03:23 49ÿ720 isapnp.sys
02/11/2006 10:50 35ÿ944 iteatapi.sys
14/03/2008 13:46 54ÿ784 itecir.sys
02/11/2006 10:50 35ÿ944 iteraid.sys
13/03/2008 12:41 203ÿ264 k57nd60x.sys
21/01/2008 03:23 35ÿ384 kbdclass.sys
21/01/2008 03:23 15ÿ872 kbdhid.sys
21/01/2008 03:24 148ÿ992 ks.sys
15/06/2009 19:20 439ÿ896 ksecdd.sys
29/02/2008 02:13 35ÿ344 LHidFilt.Sys
21/01/2008 03:24 47ÿ104 lltdio.sys
29/02/2008 02:13 36ÿ880 LMouFilt.Sys
21/01/2008 03:23 96ÿ312 lsi_fc.sys
21/01/2008 03:23 89ÿ656 lsi_sas.sys
21/01/2008 03:23 96ÿ312 lsi_scsi.sys
21/01/2008 03:24 84ÿ480 luafv.sys
29/02/2008 02:13 28ÿ944 LUsbFilt.sys
10/09/2009 14:53 19ÿ160 mbam.sys
10/09/2009 14:54 38ÿ224 mbamswissarmy.sys
21/01/2008 03:24 18ÿ944 mcd.sys
21/01/2008 03:23 31ÿ288 megasas.sys
21/01/2008 03:23 386ÿ616 MegaSR.sys
21/01/2008 03:24 31ÿ744 modem.sys
21/01/2008 03:23 41ÿ984 monitor.sys
21/01/2008 03:23 34ÿ360 mouclass.sys
21/01/2008 03:23 15ÿ872 mouhid.sys
21/01/2008 03:23 57ÿ400 mountmgr.sys
21/01/2008 03:23 105ÿ016 mpio.sys
21/01/2008 03:24 64ÿ000 mpsdrv.sys
02/11/2006 10:49 33ÿ384 Mraid35x.sys
21/01/2008 03:23 110ÿ080 mrxdav.sys
21/01/2008 03:24 105ÿ472 mrxsmb.sys
27/08/2008 02:05 212ÿ480 mrxsmb10.sys
21/01/2008 03:24 78ÿ848 mrxsmb20.sys
12/10/2008 00:08 28ÿ728 msahci.sys
21/01/2008 03:23 94ÿ776 msdsm.sys
21/01/2008 03:23 22ÿ528 msfs.sys
21/01/2008 03:23 3 MsftWdf_Kernel_01007_Inbox_Critical.Wdf
21/01/2008 03:23 16ÿ440 msisadrv.sys
21/01/2008 03:23 181ÿ304 msiscsi.sys
21/01/2008 03:24 8ÿ192 mskssrv.sys
21/01/2008 03:24 5ÿ888 mspclock.sys
21/01/2008 03:24 5ÿ504 mspqm.sys
21/01/2008 03:24 163ÿ384 msrpc.sys
21/01/2008 03:23 31ÿ288 mssmbios.sys
21/01/2008 03:24 6ÿ016 mstee.sys
21/01/2008 03:24 49ÿ720 mup.sys
08/02/2008 05:25 529ÿ464 ndis.sys
21/01/2008 03:24 20ÿ992 ndistapi.sys
21/01/2008 03:24 16ÿ896 ndisuio.sys
21/01/2008 03:24 121ÿ344 ndiswan.sys
21/01/2008 03:24 49ÿ664 ndproxy.sys
21/01/2008 03:24 35ÿ840 netbios.sys
21/01/2008 03:24 184ÿ320 netbt.sys
21/01/2008 03:24 223ÿ288 netio.sys
02/11/2006 10:50 45ÿ160 nfrd960.sys
21/01/2008 03:23 34ÿ816 npfs.sys
21/01/2008 03:24 16ÿ384 nsiproxy.sys
21/01/2008 03:23 1ÿ081ÿ912 ntfs.sys
02/11/2006 08:36 20ÿ608 ntrigdigi.sys
21/01/2008 03:23 4ÿ608 null.sys
21/01/2008 03:23 102ÿ968 nvraid.sys
21/01/2008 03:23 45ÿ112 nvstor.sys
21/01/2008 03:23 109ÿ112 NV_AGP.SYS
20/05/2008 03:07 148ÿ480 nwifi.sys
28/07/2008 08:14 148ÿ056 OA001Afx.sys
28/07/2008 08:14 57ÿ656 OA001PC.bmp
28/07/2008 08:14 22ÿ951 OA001PC.jpg
28/07/2008 08:14 144ÿ672 OA001Ufd.sys
18/09/2008 17:03 277ÿ440 OA001Vid.sys
21/01/2008 03:23 61ÿ952 ohci1394.sys
12/10/2008 00:09 72ÿ192 pacer.sys
02/11/2006 09:51 79ÿ360 parport.sys
21/01/2008 03:24 56ÿ376 partmgr.sys
02/11/2006 09:51 8ÿ704 parvdm.sys
21/01/2008 03:23 151ÿ096 pci.sys
21/01/2008 03:23 16ÿ440 pciide.sys
21/01/2008 03:23 45ÿ112 pciidex.sys
02/11/2006 10:51 167ÿ528 pcmcia.sys
02/11/2006 10:04 878ÿ080 PEAuth.sys
21/01/2008 03:23 167ÿ936 portcls.sys
21/01/2008 03:23 40ÿ960 processr.sys
14/11/2007 02:00 43ÿ840 pxhelp20.sys
21/01/2008 03:23 1ÿ122ÿ360 ql2300.sys
02/11/2006 10:50 106ÿ088 ql40xx.sys
21/01/2008 03:23 31ÿ232 qwavedrv.sys
21/01/2008 03:24 11ÿ776 rasacd.sys
21/01/2008 03:24 76ÿ288 rasl2tp.sys
21/01/2008 03:24 41ÿ472 raspppoe.sys
21/01/2008 03:24 62ÿ976 raspptp.sys
21/01/2008 03:25 69ÿ120 rassstp.sys
21/01/2008 03:24 224ÿ768 rdbss.sys
21/01/2008 03:24 6ÿ144 RDPCDD.sys
21/01/2008 03:23 248ÿ832 rdpdr.sys
21/01/2008 03:24 6ÿ144 RDPENCDD.sys
21/01/2008 03:24 181ÿ248 rdpwd.sys
21/01/2008 03:23 49ÿ664 rfcomm.sys
13/03/2008 12:34 46ÿ592 rimmptsk.sys
18/01/2007 19:24 26ÿ496 RimSerial.sys
13/03/2008 12:34 43ÿ008 rimsptsk.sys
13/03/2008 12:34 38ÿ400 rixdptsk.sys
12/10/2008 00:08 113ÿ664 rmcast.sys
21/01/2008 03:24 33ÿ280 RNDISMP.sys
21/01/2008 03:24 8ÿ192 rootmdm.sys
21/01/2008 03:24 60ÿ416 rspndr.sys
02/11/2006 10:50 76ÿ392 sbp2port.sys
21/01/2008 03:23 142ÿ904 scsiport.sys
21/01/2008 03:23 88ÿ576 sdbus.sys
02/11/2006 07:37 20ÿ480 secdrv.sys
02/11/2006 09:51 17ÿ920 serenum.sys
02/11/2006 09:51 83ÿ456 serial.sys
21/01/2008 03:23 19ÿ968 sermouse.sys
05/07/2006 13:39 59ÿ256 sfdrv01.sys
05/07/2006 13:46 63ÿ352 sfdrv01a.sys
21/01/2008 03:23 13ÿ312 sffdisk.sys
21/01/2008 03:23 12ÿ288 sffp_mmc.sys
21/01/2008 03:23 11ÿ776 sffp_sd.sys
14/06/2006 15:56 13ÿ680 sfhlp02.sys
02/11/2006 09:51 13ÿ312 sfloppy.sys
08/02/2007 18:44 83ÿ320 sfvfs02.sys
21/01/2008 03:23 55ÿ864 SISAGP.SYS
21/01/2008 03:23 41ÿ016 sisraid2.sys
21/01/2008 03:23 74ÿ808 sisraid4.sys
21/01/2008 03:25 66ÿ560 smb.sys
21/01/2008 03:24 17ÿ408 smclib.sys
21/01/2008 03:24 21ÿ048 spldr.sys
21/01/2008 03:24 681ÿ984 spsys.sys
16/12/2008 03:42 288ÿ768 srv.sys
14/09/2009 10:44 144ÿ896 srv2.sys
21/01/2008 03:23 98ÿ304 srvnet.sys
21/01/2008 03:24 123ÿ960 Storport.sys
21/01/2008 03:24 52ÿ992 stream.sys
25/06/2008 12:56 380ÿ928 stwrt.sys
21/01/2008 03:23 15ÿ288 swenum.sys
02/11/2006 10:50 35ÿ944 symc8xx.sys
02/11/2006 10:49 31ÿ848 sym_hi.sys
02/11/2006 10:50 34ÿ920 sym_u3.sys
21/01/2008 03:24 24ÿ576 tape.sys
14/08/2009 18:07 897ÿ608 tcpip.sys
21/01/2008 03:23 30ÿ208 tcpipreg.sys
21/01/2008 03:24 20ÿ992 tdi.sys
21/01/2008 03:24 17ÿ920 tdpipe.sys
21/01/2008 03:24 29ÿ184 tdtcp.sys
21/01/2008 03:24 71ÿ680 tdx.sys
21/01/2008 03:23 54ÿ328 termdd.sys
25/11/2009 17:07 102ÿ664 tmcomm.sys
21/01/2008 03:24 23ÿ552 tssecsrv.sys
21/01/2008 03:24 15ÿ360 TUNMP.SYS
21/01/2008 03:24 23ÿ040 tunnel.sys
21/01/2008 03:23 59ÿ448 UAGP35.SYS
21/01/2008 03:23 226ÿ816 udfs.sys
21/01/2008 03:23 60ÿ984 ULIAGPKX.SYS
21/01/2008 03:23 238ÿ648 uliahci.sys
02/11/2006 10:50 98ÿ408 ulsata.sys
21/01/2008 03:23 115ÿ816 ulsata2.sys
21/01/2008 03:23 34ÿ816 umbus.sys
12/12/2008 16:03 UMDF
21/01/2008 03:23 7ÿ680 umpass.sys
21/01/2008 03:24 15ÿ872 usb8023.sys
28/08/2009 18:42 40ÿ448 usbaapl.sys
21/01/2008 03:24 25ÿ728 USBCAMD.sys
21/01/2008 03:24 25ÿ728 USBCAMD2.sys
12/10/2008 00:15 73ÿ216 usbccgp.sys
02/11/2006 09:55 68ÿ608 usbcir.sys
12/10/2008 00:15 5ÿ888 usbd.sys
12/10/2008 00:15 39ÿ424 usbehci.sys
12/10/2008 00:15 194ÿ560 usbhub.sys
02/11/2006 09:55 19ÿ456 usbohci.sys
12/10/2008 00:15 226ÿ304 usbport.sys
02/11/2006 10:14 18ÿ944 usbprint.sys
21/01/2008 03:23 55ÿ296 USBSTOR.SYS
12/10/2008 00:15 23ÿ552 usbuhci.sys
21/01/2008 03:24 25ÿ088 vga.sys
21/01/2008 03:23 26ÿ112 vgapnp.sys
21/01/2008 03:23 56ÿ888 VIAAGP.SYS
21/01/2008 03:23 41ÿ472 viac7.sys
21/01/2008 03:23 20ÿ024 viaide.sys
21/01/2008 03:23 110ÿ080 videoprt.sys
25/07/2009 00:21 4ÿ608 vncmirror.sys
21/01/2008 03:23 52ÿ792 volmgr.sys
21/01/2008 03:24 294ÿ456 volmgrx.sys
21/01/2008 03:23 227ÿ896 volsnap.sys
21/01/2008 03:23 130ÿ616 vsmraid.sys
02/11/2006 09:52 20ÿ608 wacompen.sys
21/01/2008 03:24 62ÿ464 wanarp.sys
21/01/2008 03:24 32ÿ768 watchdog.sys
21/01/2008 03:23 22ÿ072 wd.sys
21/01/2008 03:23 503ÿ864 Wdf01000.sys
21/01/2008 03:23 35ÿ896 WdfLdr.sys
21/01/2008 03:23 11ÿ264 wmiacpi.sys
21/01/2008 03:23 17ÿ976 wmilib.sys
21/01/2008 03:23 39ÿ936 WpdUsb.sys
21/01/2008 03:24 15ÿ872 ws2ifsl.sys
21/01/2008 03:24 51ÿ200 WUDFPf.sys
21/01/2008 03:24 83ÿ328 WUDFRd.sys
315 fichier(s) 36ÿ628ÿ763 octets

R‚pertoire de C:\Windows\System32\Drivers\etc

09/09/2009 17:14 .
09/09/2009 17:14 ..
18/09/2006 22:41 761 hosts
16/03/2009 05:22 438 hosts.ics
18/09/2006 22:41 761 hosts.msn
18/09/2006 22:41 3ÿ683 lmhosts.sam
18/09/2006 22:41 407 networks
18/09/2006 22:41 1ÿ358 protocol
18/09/2006 22:41 17ÿ244 services
7 fichier(s) 24ÿ652 octets

R‚pertoire de C:\Windows\System32\Drivers\fr-FR

21/01/2008 09:39 .
21/01/2008 09:39 ..
21/01/2008 09:34 11ÿ264 acpi.sys.mui
21/01/2008 09:28 10ÿ240 afd.sys.mui
21/01/2008 09:34 3ÿ072 AGP440.sys.mui
21/01/2008 09:34 3ÿ072 AMDAGP.SYS.mui
21/01/2008 09:26 2ÿ560 amdide.sys.mui
21/01/2008 09:33 21ÿ504 amdk7.sys.mui
21/01/2008 09:33 21ÿ504 amdk8.sys.mui
21/01/2008 09:27 3ÿ584 ati2mpad.sys.mui
21/01/2008 09:30 3ÿ584 ati2mtag.sys.mui
21/01/2008 09:30 3ÿ584 atikmdag.sys.mui
21/01/2008 09:33 6ÿ144 b57nd60x.sys.mui
21/01/2008 09:34 10ÿ240 battc.sys.mui
21/01/2008 09:30 5ÿ632 bcm4sbxp.sys.mui
21/01/2008 09:26 2ÿ560 BrParwdm.sys.mui
21/01/2008 09:30 11ÿ776 BrSerId.sys.mui
21/01/2008 09:30 5ÿ120 bthpan.sys.mui
21/01/2008 09:28 7ÿ680 bthport.sys.mui
21/01/2008 09:29 3ÿ584 cmbp0wdm.sys.mui
21/01/2008 09:33 21ÿ504 crusoe.sys.mui
21/01/2008 09:29 3ÿ584 cxbp0wdm.sys.mui
21/01/2008 09:26 3ÿ584 Dot4usb.sys.mui
21/01/2008 09:26 4ÿ096 dxgkrnl.sys.mui
21/01/2008 09:33 5ÿ632 e100b325.sys.mui
21/01/2008 09:33 23ÿ552 e1e6032.sys.mui
21/01/2008 09:33 19ÿ968 E1G60I32.sys.mui
21/01/2008 09:30 6ÿ144 fltmgr.sys.mui
21/01/2008 09:26 3ÿ072 GAGP30KX.SYS.mui
21/01/2008 09:29 4ÿ096 gpr400.sys.mui
21/01/2008 09:29 4ÿ608 grserial.sys.mui
21/01/2008 09:28 3ÿ584 hidbth.sys.mui
21/01/2008 09:34 40ÿ960 http.sys.mui
21/01/2008 09:34 12ÿ288 i8042prt.sys.mui
21/01/2008 09:33 21ÿ504 intelppm.sys.mui
21/01/2008 09:29 7ÿ168 IPMIDrv.sys.mui
21/01/2008 09:28 4ÿ096 ipnat.sys.mui
21/01/2008 09:34 4ÿ608 isapnp.sys.mui
21/01/2008 09:33 5ÿ632 kbdclass.sys.mui
21/01/2008 09:33 3ÿ072 kbdhid.sys.mui
21/01/2008 09:28 11ÿ264 ltmdmnt.sys.mui
21/01/2008 09:33 7ÿ680 luafv.sys.mui
21/01/2008 09:28 4ÿ096 modem.sys.mui
21/01/2008 09:34 5ÿ632 mouclass.sys.mui
21/01/2008 09:34 3ÿ584 mouhid.sys.mui
21/01/2008 09:34 27ÿ648 mpio.sys.mui
21/01/2008 09:28 4ÿ096 msdsm.sys.mui
21/01/2008 09:34 3ÿ584 mssmbios.sys.mui
21/01/2008 09:27 77ÿ824 ntfs.sys.mui
21/01/2008 09:26 5ÿ120 ntrigdigi.sys.mui
21/01/2008 09:30 6ÿ144 nv4_mini.sys.mui
21/01/2008 09:34 3ÿ072 NV_AGP.SYS.mui
21/01/2008 09:26 12ÿ288 ohci1394.sys.mui
21/01/2008 09:29 3ÿ584 pacer.sys.mui
21/01/2008 09:26 4ÿ096 parport.sys.mui
21/01/2008 09:26 3ÿ584 parvdm.sys.mui
21/01/2008 09:34 9ÿ216 pci.sys.mui
21/01/2008 09:29 5ÿ120 pcmcia.sys.mui
21/01/2008 09:29 3ÿ072 pnpmem.sys.mui
21/01/2008 09:33 21ÿ504 processr.sys.mui
21/01/2008 09:29 4ÿ608 pscr.sys.mui
21/01/2008 09:31 3ÿ072 qwavedrv.sys.mui
21/01/2008 09:26 3ÿ584 RNDISMP.sys.mui
21/01/2008 09:29 3ÿ584 rndismpx.sys.mui
21/01/2008 09:29 4ÿ096 scmstcs.sys.mui
21/01/2008 09:29 4ÿ096 SCR111.sys.mui
21/01/2008 09:30 3ÿ584 scsiport.sys.mui
21/01/2008 09:26 12ÿ288 serial.sys.mui
21/01/2008 09:34 6ÿ656 sermouse.sys.mui
21/01/2008 09:28 3ÿ072 serscan.sys.mui
21/01/2008 09:34 3ÿ072 SISAGP.SYS.mui
21/01/2008 09:27 3ÿ072 srv.sys.mui
21/01/2008 09:29 3ÿ584 stcusb.sys.mui
21/01/2008 09:34 5ÿ632 tpm.sys.mui
21/01/2008 09:26 3ÿ072 UAGP35.SYS.mui
21/01/2008 09:34 3ÿ072 ULIAGPKX.SYS.mui
21/01/2008 09:26 3ÿ584 umbus.sys.mui
21/01/2008 09:34 3ÿ072 VIAAGP.SYS.mui
21/01/2008 09:33 21ÿ504 viac7.sys.mui
21/01/2008 09:34 40ÿ960 volsnap.sys.mui
21/01/2008 09:29 4ÿ608 wacompen.sys.mui
21/01/2008 09:29 2ÿ560 wd.sys.mui
21/01/2008 09:34 3ÿ072 wdf01000.sys.mui
21/01/2008 09:28 6ÿ656 yk60x86.sys.mui
82 fichier(s) 717ÿ824 octets

R‚pertoire de C:\Windows\System32\Drivers\UMDF

12/12/2008 16:03 .
12/12/2008 16:03 ..
21/01/2008 09:39 fr-FR
21/01/2008 03:23 220ÿ160 WpdFs.dll
21/01/2008 03:23 664ÿ576 WpdMtpDr.dll
2 fichier(s) 884ÿ736 octets

R‚pertoire de C:\Windows\System32\Drivers\UMDF\fr-FR

21/01/2008 09:39 .
21/01/2008 09:39 ..
21/01/2008 09:26 6ÿ656 WpdMtpDr.dll.mui
1 fichier(s) 6ÿ656 octets

Total des fichiers list‚sÿ:
407 fichier(s) 38ÿ262ÿ631 octets
14 R‚p(s) 112ÿ391ÿ331ÿ840 octets libres


***********************Hidden Drivers********************
Le volume dans le lecteur C s'appelle OS
Le num‚ro de s‚rie du volume est 3606-63F0

R‚pertoire de C:\Windows\System32\Drivers

11/10/2008 16:22 0 Msft_Kernel_Apfiltr_01005.Wdf
16/10/2008 12:23 0 Msft_Kernel_LMouFilt_01005.Wdf
04/10/2009 21:18 0 Msft_Kernel_LUsbFilt_01005.Wdf
20/10/2008 17:34 0 Msft_User_WpdFs_01_00_00.Wdf
08/12/2008 23:59 0 Msft_User_WpdMtpDr_01_00_00.Wdf
5 fichier(s) 0 octets
0 R‚p(s) 112ÿ391ÿ340ÿ032 octets libres

11 Re: Help for Core10k virus removal =) on Thu Nov 26, 2009 8:46 am

Darklad


Member
Member
*********************Processes*******************


PROCESS PID PRIO PATH
smss.exe 440 Normal C:\Windows\System32\smss.exe
csrss.exe 572 Normal C:\Windows\system32\csrss.exe
wininit.exe 632 High C:\Windows\system32\wininit.exe
csrss.exe 644 Normal C:\Windows\system32\csrss.exe
services.exe 680 Normal C:\Windows\system32\services.exe
lsass.exe 696 Normal C:\Windows\system32\lsass.exe
lsm.exe 704 Normal C:\Windows\system32\lsm.exe
winlogon.exe 796 High C:\Windows\system32\winlogon.exe
svchost.exe 892 Normal C:\Windows\system32\svchost.exe
svchost.exe 956 Normal C:\Windows\system32\svchost.exe
svchost.exe 992 Normal C:\Windows\System32\svchost.exe
Ati2evxx.exe 1044 Normal C:\Windows\system32\Ati2evxx.exe
svchost.exe 1068 Normal C:\Windows\System32\svchost.exe
svchost.exe 1108 Normal C:\Windows\System32\svchost.exe
svchost.exe 1120 Normal C:\Windows\system32\svchost.exe
STacSV.exe 1136 Normal C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe
SLsvc.exe 1384 Normal C:\Windows\system32\SLsvc.exe
svchost.exe 1420 Normal C:\Windows\system32\svchost.exe
Ati2evxx.exe 1488 Normal C:\Windows\system32\Ati2evxx.exe
DockLogin.exe 1536 Real Time C:\Program Files\Dell\DellDock\DockLogin.exe
svchost.exe 1604 Normal C:\Windows\system32\svchost.exe
WLTRYSVC.EXE 1732 Normal C:\Windows\System32\WLTRYSVC.EXE
aswUpdSv.exe 1776 Normal C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
ashServ.exe 1792 High C:\Program Files\Alwil Software\Avast4\ashServ.exe
spoolsv.exe 344 Normal C:\Windows\System32\spoolsv.exe
svchost.exe 388 Normal C:\Windows\system32\svchost.exe
aestsrv.exe 1484 Normal C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe
AppleMobileDeviceService.exe 1548 Normal C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
mDNSResponder.exe 1636 Normal C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe 1628 Normal C:\Windows\system32\svchost.exe
btwdins.exe 876 Normal C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
Iaantmon.exe 2076 Normal C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
svchost.exe 2124 Normal C:\Windows\system32\svchost.exe
SeaPort.exe 2232 Normal C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe 2332 Normal C:\Windows\system32\svchost.exe
svchost.exe 2360 Normal C:\Windows\System32\svchost.exe
WinVNC4.exe 2456 Normal C:\Program Files\RealVNC\VNC4\WinVNC4.exe
winvnc4.exe 2472 Normal C:\Program Files\RealVNC\VNC4\winvnc4.exe
SearchIndexer.exe 2480 Normal C:\Windows\system32\SearchIndexer.exe
ashMaiSv.exe 2596 Normal C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
ashWebSv.exe 2668 Normal C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
WUDFHost.exe 2884 Normal C:\Windows\system32\WUDFHost.exe
taskeng.exe 3180 Below Normal C:\Windows\system32\taskeng.exe
taskeng.exe 3424 Normal C:\Windows\system32\taskeng.exe
Dwm.exe 3460 High C:\Windows\system32\Dwm.exe
Explorer.EXE 3540 Normal C:\Windows\Explorer.EXE
MSASCui.exe 3804 Normal C:\Program Files\Windows Defender\MSASCui.exe
Apoint.exe 3824 Normal C:\Program Files\DellTPad\Apoint.exe
sttray.exe 3872 Normal C:\Program Files\IDT\WDM\sttray.exe
IAAnotif.exe 3940 Normal C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
WLTRAY.EXE 3952 Normal C:\Windows\System32\WLTRAY.EXE
WebcamDell.exe 4044 Normal C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
PCMService.exe 1456 Normal C:\Program Files\Dell\MediaDirect\PCMService.exe
ashDisp.exe 2208 Normal C:\Program Files\Alwil Software\Avast4\ashDisp.exe
GrooveMonitor.exe 1352 Normal C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
iTunesHelper.exe 2792 Normal C:\Program Files\iTunes\iTunesHelper.exe
GoogleToolbarNotifier.exe 676 Normal C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
msnmsgr.exe 2864 Normal C:\Program Files\Windows Live\Messenger\msnmsgr.exe
ehtray.exe 1708 Normal C:\Windows\ehome\ehtray.exe
btdna.exe 2920 Normal C:\Program Files\DNA\btdna.exe
MediaCenter.exe 3044 Normal C:\Program Files\SFR\Media Center\MediaCenter.exe
OctoshapeClient.exe 736 Normal C:\Users\Daniel\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
wmpnscfg.exe 2644 Normal C:\Program Files\Windows Media Player\wmpnscfg.exe
BTTray.exe 3092 Normal C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
SetPoint.exe 1436 Normal C:\Program Files\Logitech\SetPoint\SetPoint.exe
SSScheduler.exe 1968 Normal C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
quickset.exe 3168 Normal C:\Program Files\Dell\QuickSet\quickset.exe
bcmwltry.exe 2288 Normal C:\Windows\System32\bcmwltry.exe
MOM.exe 3360 Normal C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
ApMsgFwd.exe 1564 Normal C:\Program Files\DellTPad\ApMsgFwd.exe
wmiprvse.exe 3840 Normal C:\Windows\system32\wbem\wmiprvse.exe
ehmsas.exe 1864 Normal C:\Windows\ehome\ehmsas.exe
wmpnetwk.exe 1816 Normal C:\Program Files\Windows Media Player\wmpnetwk.exe
Apntex.exe 3888 Normal C:\Program Files\DellTPad\Apntex.exe
HidFind.exe 3916 Normal C:\Program Files\DellTPad\HidFind.exe
iPodService.exe 4584 Normal C:\Program Files\iPod\bin\iPodService.exe
KHALMNPR.EXE 4644 Normal C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
httpd.exe 4716 Normal C:\Program Files\SFR\Media Center\httpd\httpd.exe
CCC.exe 4860 Normal C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
httpd.exe 5232 Normal C:\Program Files\SFR\Media Center\httpd\httpd.exe
wlcomm.exe 5576 Normal C:\Program Files\Windows Live\Contacts\wlcomm.exe
LULnchr.exe 5736 Normal C:\Program Files\Logitech\SetPoint\LU\LULnchr.exe
LogitechUpdate.exe 5860 Normal C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe
conime.exe 5724 Normal C:\Windows\system32\conime.exe
wuauclt.exe 4688 Normal C:\Windows\system32\wuauclt.exe
firefox.exe 3652 Normal C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe 4416 Normal C:\Windows\explorer.exe
notepad.exe 5852 Normal C:\Windows\system32\notepad.exe
SearchProtocolHost.exe 7032 Idle C:\Windows\system32\SearchProtocolHost.exe
SearchFilterHost.exe 2216 Idle C:\Windows\system32\SearchFilterHost.exe
cmd.exe 7248 Normal C:\Windows\system32\cmd.exe
processes.exe 4316 Normal C:\Users\Daniel\Téléchargements\SpiderKill\SpiderKill\processes.exe


Module information for 'Explorer.EXE'(3540)
MODULE BASE SIZE PATH
Explorer.EXE 240000 2936832 C:\Windows\Explorer.EXE 6.0.6000.16386 (vista_rtm.061101-2205) Explorateur Windows
ntdll.dll 77b10000 1208320 C:\Windows\system32\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL Couche NT
kernel32.dll 776d0000 897024 C:\Windows\system32\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL du client API BASE Windows NT
ADVAPI32.dll 76820000 811008 C:\Windows\system32\ADVAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) API avancées Windows 32
RPCRT4.dll 76380000 794624 C:\Windows\system32\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Runtime d’appel de procédure distante
GDI32.dll 775f0000 307200 C:\Windows\system32\GDI32.dll 6.0.6001.18159 (vistasp1_gdr.081020-1655) GDI Client DLL
USER32.dll 777d0000 643072 C:\Windows\system32\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL client de l'API uilisateur de Windows multi-utilisateurs
msvcrt.dll 77cc0000 696320 C:\Windows\system32\msvcrt.dll 7.0.6001.18000 (longhorn_rtm.080118-1840) Windows NT CRT DLL
SHLWAPI.dll 768f0000 360448 C:\Windows\system32\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque d'utilitaires légers du Shell
SHELL32.dll 76950000 11599872 C:\Windows\system32\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL commune du shell Windows
ole32.dll 76480000 1327104 C:\Windows\system32\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Microsoft OLE pour Windows
OLEAUT32.dll 77870000 577536 C:\Windows\system32\OLEAUT32.dll 6.0.6001.18000 6.0.6001.18000
SHDOCVW.dll 6f3d0000 1077248 C:\Windows\system32\SHDOCVW.dll 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque d'objets et de contrôles de documents de l'environnement
UxTheme.dll 74f50000 258048 C:\Windows\system32\UxTheme.dll 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque de thèmes Ux Microsoft
POWRPROF.dll 75680000 106496 C:\Windows\system32\POWRPROF.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL d’assistance du profil d’alimentation
dwmapi.dll 71ee0000 49152 C:\Windows\system32\dwmapi.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft Desktop Window Manager API
gdiplus.dll 74960000 1748992 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll 5.2.6001.18175 (vistasp1_gdr.081126-1506) Microsoft GDI+
slc.dll 75c40000 237568 C:\Windows\system32\slc.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Dll de client de gestion de licences du logiciel
PROPSYS.dll 743a0000 765952 C:\Windows\system32\PROPSYS.dll 7.0.6001.16503 (longhorn(wmbla).080526-2159) Système de propriétés Microsoft
BROWSEUI.dll 6ef60000 1335296 C:\Windows\system32\BROWSEUI.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Bibliothèque de l'interface utilisateur du navigateur
IMM32.dll 777b0000 122880 C:\Windows\system32\IMM32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Multi-User Windows IMM32 API Client DLL
MSCTF.dll 76740000 819200 C:\Windows\system32\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL de MSCTF Server
DUser.dll 75270000 196608 C:\Windows\system32\DUser.dll 6.0.6000.16386 (vista_rtm.061101-2205) Windows DirectUser Engine
LPK.DLL 76810000 36864 C:\Windows\system32\LPK.DLL 6.0.6001.18000 (longhorn_rtm.080118-1840) Language Pack
USP10.dll 765d0000 512000 C:\Windows\system32\USP10.dll 1.0626.6001.18000 (longhorn_rtm.080118-1840) Uniscribe Unicode script processor
WS2_32.dll 76450000 184320 C:\Windows\system32\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Windows Socket 2.0 32-Bit DLL
NSI.dll 76650000 24576 C:\Windows\system32\NSI.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) NSI User-mode interface DLL
NTMARTA.DLL 761e0000 135168 C:\Windows\system32\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Fournisseur MARTA Windows NT
WLDAP32.dll 77c70000 303104 C:\Windows\system32\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL API LDAP Win32
PSAPI.DLL 76370000 28672 C:\Windows\system32\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Process Status Helper
SAMLIB.dll 761c0000 69632 C:\Windows\system32\SAMLIB.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) SAM Library DLL
comctl32.dll 750d0000 1695744 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll 5.82 (vista_rtm.061101-2205) Bibliothèque de contrôles communs
WindowsCodecs.dll 73f40000 733184 C:\Windows\system32\WindowsCodecs.dll 6.0.6001.22253 (vistasp1_ldr.080827-1507) Microsoft Windows Codecs Library
apphelp.dll 76160000 180224 C:\Windows\system32\apphelp.dll 6.0.6000.16386 (vista_rtm.061101-2205) Fichier DLL du client de compatibilité des applications
CLBCatQ.DLL 77640000 540672 C:\Windows\system32\CLBCatQ.DLL 2001.12.6931.18000 (longhorn_rtm.080118-1840) COM+ Configuration Catalog
GrooveShellExtensions.dll 6e170000 2224128 C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll 12.0.6421.1000 GrooveShellExtensions Module
GrooveUtil.DLL 6dd20000 991232 C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL 12.0.6423.1000 GrooveUtil Module
WININET.dll 76660000 856064 C:\Windows\system32\WININET.dll 7.00.6000.16386 (vista_rtm.061101-2205) Extensions Internet pour Win32
Normaliz.dll 77900000 12288 C:\Windows\system32\Normaliz.dll 6.0.6000.16386 (vista_rtm.061101-2205) Unicode Normalization DLL
iertutil.dll 77a40000 286720 C:\Windows\system32\iertutil.dll 7.00.6001.18319 (vistasp1_gdr.090827-0048) Run time utility for Internet Explorer
CRYPT32.dll 75c80000 987136 C:\Windows\system32\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Crypto API32
MSASN1.dll 75de0000 73728 C:\Windows\system32\MSASN1.dll 6.0.6001.18326 (vistasp1_gdr.090903-2340) ASN.1 Runtime APIs
USERENV.dll 76230000 122880 C:\Windows\system32\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205) Userenv
Secur32.dll 76210000 81920 C:\Windows\system32\Secur32.dll 6.0.6001.18272 (vistasp1_gdr.090615-0258) Security Support Provider Interface
MSVCR80.dll 73c00000 634880 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.3053_none_d08d7bba442a9b36\MSVCR80.dll 8.00.50727.3053 Microsoft® C Runtime Library
GrooveNew.DLL 6df90000 28672 C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL 12.0.6413.1000 GrooveNew Module
VERSION.dll 75a10000 32768 C:\Windows\system32\VERSION.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Version Checking and File Installation Libraries
ATL80.DLL 73bb0000 110592 C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.DLL 8.00.50727.4053 ATL Module for Windows (Unicode)
rsaenh.dll 75720000 241664 C:\Windows\system32\rsaenh.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft Enhanced Cryptographic Provider
MSImg32.dll 753b0000 20480 C:\Windows\system32\MSImg32.dll 6.0.6000.16386 (vista_rtm.061101-2205) GDIEXT Client DLL
IconCodecService.dll 6df70000 24576 C:\Windows\system32\IconCodecService.dll 6.0.6000.16386 (vista_rtm.061101-2205) Converts a PNG part of the icon to a legacy bmp icon
timedate.cpl 6dc60000 729088 C:\Windows\system32\timedate.cpl 6.0.6001.18000 (longhorn_rtm.080118-1840) Panneau de configuration Date/Heure
ATL.DLL 74320000 81920 C:\Windows\system32\ATL.DLL 3.05.2284 ATL Module for Windows XP (Unicode)
NETAPI32.dll 76020000 479232 C:\Windows\system32\NETAPI32.dll 6.0.6001.18157 (vistasp1_gdr.081015-1604) Net Win32 API DLL
OLEACC.dll 74f90000 233472 C:\Windows\system32\OLEACC.dll 4.2.5406.0 (longhorn_rtm.080118-1840) Active Accessibility Core Component
actxprxy.dll 6dba0000 339968 C:\Windows\System32\actxprxy.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) ActiveX Interface Marshaling Library
msutb.dll 6f6a0000 176128 C:\Windows\system32\msutb.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL MSUTB Server
WTSAPI32.dll 755a0000 40960 C:\Windows\system32\WTSAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows Terminal Server SDK APIs
WINBRAND.dll 757e0000 880640 C:\Windows\system32\WINBRAND.dll 6.0.6000.16386 (vista_rtm.061101-2205) Windows Branding Resources
msshsq.dll 6da10000 245760 C:\Windows\System32\msshsq.dll 7.0.6001.16503 (longhorn(wmbla).080526-2159) Structured Query
NaturalLanguage6.dll 6d870000 811008 C:\Windows\System32\NaturalLanguage6.dll 6.0.6001.18098 (vistasp1_gdr.080625-1507) Natural Language Development Platform 6
NLSData000c.dll 6d350000 2670592 C:\Windows\System32\NLSData000c.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft French Natural Language Server Data and Code
NLSLexicons000c.dll 6c750000 6242304 C:\Windows\System32\NLSLexicons000c.dll 6.0.6000.16386 (vista_rtm.061101-2205) Microsoft French Natural Language Server Data and Code
authui.dll 74cc0000 1998848 C:\Windows\system32\authui.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Interface utilisateur d’authentification Windows
LINKINFO.dll 6df80000 36864 C:\Windows\system32\LINKINFO.dll 6.0.6000.16386 (vista_rtm.061101-2205) Windows Volume Tracking
GrooveSystemServices.dll 6d950000 184320 C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll 12.0.6421.1000 GrooveSystemServices Module
GrooveMisc.dll 6d050000 1568768 C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll 12.0.6421.1000 GrooveMisc Module
msxml3.dll 71bc0000 1269760 C:\Windows\System32\msxml3.dll 8.100.4001.0 MSXML 3.0 SP10
urlmon.dll 77910000 1220608 C:\Windows\system32\urlmon.dll 7.00.6001.18000 (longhorn_rtm.080118-1840) Extensions OLE32 pour Win32
ieframe.dll 6c180000 6086656 C:\Windows\system32\ieframe.dll 7.00.6000.16386 (vista_rtm.061101-2205) Internet Explorer
WINMM.dll 752a0000 204800 C:\Windows\system32\WINMM.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL API MCI
wdmaud.drv 74370000 192512 C:\Windows\system32\wdmaud.drv 6.0.6000.16386 (vista_rtm.061101-2205) Pilote du système audio Winmm
ksuser.dll 74b40000 16384 C:\Windows\system32\ksuser.dll 6.0.6000.16386 (vista_rtm.061101-2205) User CSA Library
MMDevAPI.DLL 753e0000 159744 C:\Windows\system32\MMDevAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205) MMDevice API
AVRT.dll 75590000 28672 C:\Windows\system32\AVRT.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Multimedia Realtime Runtime
SETUPAPI.dll 77460000 1613824 C:\Windows\system32\SETUPAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Installation de L'API Windows
WINTRUST.dll 754d0000 184320 C:\Windows\system32\WINTRUST.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft Trust Verification APIs
imagehlp.dll 77c40000 167936 C:\Windows\system32\imagehlp.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows NT Image Helper
AUDIOSES.DLL 74340000 135168 C:\Windows\system32\AUDIOSES.DLL 6.0.6001.18000 (longhorn_rtm.080118-1840) Audio Session
audioeng.dll 741f0000 417792 C:\Windows\system32\audioeng.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Audio Engine
ntshrui.dll 6d5e0000 303104 C:\Windows\system32\ntshrui.dll 6.0.6000.16386 (vista_rtm.061101-2205) Extensions de l'interpréteur de commandes pour le partage
cscapi.dll 6fad0000 45056 C:\Windows\system32\cscapi.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Offline Files Win32 API
msacm32.drv 74310000 36864 C:\Windows\system32\msacm32.drv 6.0.6000.16386 (vista_rtm.061101-2205) Mappeur de sons Microsoft
MSACM32.dll 741a0000 81920 C:\Windows\system32\MSACM32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Filtre audio ACM Microsoft
midimap.dll 74300000 28672 C:\Windows\system32\midimap.dll 6.0.6000.16386 (vista_rtm.061101-2205) Microsoft MIDI Mapper
ExplorerFrame.dll 6df60000 36864 C:\Windows\system32\ExplorerFrame.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) ExplorerFrame
stobject.dll 6cfb0000 598016 C:\Windows\system32\stobject.dll 6.0.6000.16386 (vista_rtm.061101-2205) Objet du service d'environnement Systray
BatMeter.dll 6cef0000 745472 C:\Windows\system32\BatMeter.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL d'application d'assistance de Jauge de batterie
WINSTA.dll 756f0000 151552 C:\Windows\system32\WINSTA.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Winstation Library
es.dll 74000000 290816 C:\Windows\system32\es.dll 2001.12.6931.18057 (vistasp1_gdr.080417-1550) COM+
SndVolSSO.dll 74ba0000 196608 C:\Windows\System32\SndVolSSO.dll 6.0.6000.16386 (vista_rtm.061101-2205) Volume SCA
ehSSO.dll 6d9b0000 135168 C:\Windows\ehome\ehSSO.dll 6.0.6000.16386 (vista_rtm.061101-2205) Objet Service environnement Windows Media Center
HID.DLL 74190000 36864 C:\Windows\system32\HID.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque d’utilisateur HID
netshell.dll 6bb60000 3190784 C:\Windows\System32\netshell.dll 6.0.6000.16386 (vista_rtm.061101-2205) Noyau des Connexions réseau
IPHLPAPI.DLL 75be0000 102400 C:\Windows\System32\IPHLPAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205) API de l'application d'assistance IP
dhcpcsvc.DLL 75ba0000 217088 C:\Windows\System32\dhcpcsvc.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Service client DHCP
DNSAPI.dll 75e00000 180224 C:\Windows\System32\DNSAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205) DNS DLL de l'API Client
WINNSI.DLL 75b90000 28672 C:\Windows\System32\WINNSI.DLL 6.0.6001.18000 (longhorn_rtm.080118-1840) Network Store Information RPC interface
dhcpcsvc6.DLL 75b60000 135168 C:\Windows\System32\dhcpcsvc6.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Client DHCPv6
nlaapi.dll 74b30000 61440 C:\Windows\System32\nlaapi.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Network Location Awareness 2
FirewallAPI.dll 755b0000 417792 C:\Windows\system32\FirewallAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205) API du Pare-feu Windows
pnidui.dll 6bfc0000 1830912 C:\Windows\system32\pnidui.dll 6.0.6000.16386 (vista_rtm.061101-2205) Icône du système réseau
QUtil.dll 6da50000 94208 C:\Windows\system32\QUtil.dll 6.0.6000.16386 (vista_rtm.061101-2205) Utilitaires de quarantaine
wevtapi.dll 75c00000 262144 C:\Windows\system32\wevtapi.dll 6.0.6000.16386 (vista_rtm.061101-2205) API de configuration et de consommation d’événements
wlanutil.dll 73ed0000 24576 C:\Windows\system32\wlanutil.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL d’utilitaire de réseau local sans fil 802.11 pour Windows
FunDisc.dll 71fa0000 159744 C:\Windows\system32\FunDisc.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL de découverte de fonction
fdproxy.dll 74f20000 36864 C:\Windows\system32\fdproxy.dll 6.0.6000.16386 (vista_rtm.061101-2205) Function Discovery Proxy Dll
npmproxy.dll 71af0000 32768 C:\Windows\System32\npmproxy.dll 6.0.6000.16386 (vista_rtm.061101-2205) Network List Manager Proxy
Wlanapi.dll 73eb0000 73728 C:\Windows\system32\Wlanapi.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL de l’API côté client de configuration automatique WLAN Windows
OneX.DLL 73ca0000 1556480 C:\Windows\system32\OneX.DLL 6.0.6001.18000 (longhorn_rtm.080118-1840) Bibliothèque de demandeur IEEE 802.1X
eappprxy.dll 74540000 57344 C:\Windows\system32\eappprxy.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft EAPHost Peer Client DLL
eappcfg.dll 74070000 147456 C:\Windows\system32\eappcfg.dll 6.0.6000.16386 (vista_rtm.061101-2205) Configuration d’homologue EAP
bcrypt.dll 75ac0000 282624 C:\Windows\system32\bcrypt.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows Cryptographic Primitives Library
AltTab.dll 74bd0000 53248 C:\Windows\System32\AltTab.dll 6.0.6000.16386 (vista_rtm.061101-2205) Combinaison Alt Tab pour Windows Shell
wpdshserviceobj.dll 6cdf0000 143360 C:\Windows\system32\wpdshserviceobj.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows Portable Device Shell Service Object
WINHTTP.dll 72e20000 389120 C:\Windows\system32\WINHTTP.dll 6.0.6000.16386 (vista_rtm.061101-2205) Services HTTP Windows
srchadmin.dll 6cd50000 315392 C:\Windows\System32\srchadmin.dll 7.0.6001.16503 (longhorn(wmbla).080526-2159) Options d'indexation
webcheck.dll 6cdb0000 245760 C:\Windows\system32\webcheck.dll 7.00.6000.16386 (vista_rtm.061101-2205) Contrôleur de site Web
SyncCenter.dll 6b720000 2211840 C:\Windows\System32\SyncCenter.dll 6.0.6000.16386 (vista_rtm.061101-2205) Centre de synchronisation Microsoft
mssprxy.dll 71ae0000 45056 C:\Windows\system32\mssprxy.dll 7.0.6001.16503 (longhorn(wmbla).080526-2159) Microsoft Search Proxy
wscntfy.dll 6d2c0000 233472 C:\Windows\system32\wscntfy.dll 6.0.6000.16386 (vista_rtm.061101-2205) Application de notification du Centre de sécurité Windows
WSCAPI.dll 6fb90000 45056 C:\Windows\system32\WSCAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows Security Center API
QAgent.dll 6d980000 188416 C:\Windows\System32\QAgent.dll 6.0.6000.16386 (vista_rtm.061101-2205) Proxy de l’agent de quarantaine
fwpuclnt.dll 72d20000 614400 C:\Windows\System32\fwpuclnt.dll 6.0.6000.16386 (vista_rtm.061101-2205) API en mode utilisateur FWP/IPsec
SXS.DLL 760a0000 389120 C:\Windows\system32\SXS.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Fusion 2.5
imapi2.dll 6bf00000 331776 C:\Windows\system32\imapi2.dll 6.0.6000.16386 (vista_rtm.061101-2205) API de contrôle d’image v2
bthprops.cpl 723e0000 1019904 C:\Windows\system32\bthprops.cpl 6.0.6000.16386 (vista_rtm.061101-2205) Applet Panneau de configuration Bluetooth
btncopy.dll 10000000 188416 C:\Windows\system32\btncopy.dll 6.1.0.4402 BTNCopy Module
PortableDeviceTypes.dll 6ffd0000 176128 C:\Windows\system32\PortableDeviceTypes.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows Portable Device (Parameter) Types Component
PortableDeviceApi.dll 71a10000 253952 C:\Windows\system32\PortableDeviceApi.dll 6.0.6001.18160 (vistasp1_gdr.081021-1528) Windows Portable Device API Components
msiltcfg.dll 70f10000 28672 C:\Windows\system32\msiltcfg.dll 4.0.6000.16386 (vista_rtm.061101-2205) Windows Installer Configuration API Stub
msi.dll 6fd90000 2105344 C:\Windows\system32\msi.dll 4.0.6001.18000 Windows Installer
MLANG.dll 6d320000 196608 C:\Windows\system32\MLANG.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL de prise en charge multilingue
MPR.dll 75d80000 81920 C:\Windows\system32\MPR.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL de routeur de fournisseurs multiples
lgscroll.dll 10100000 57344 C:\Program Files\Logitech\SetPoint\lgscroll.dll 4.60.122 Logitech Scroll Enabler (UNICODE)
btmmhook.dll 3e40000 217088 C:\Windows\system32\btmmhook.dll 6.1.0.4402 Multimedia Keys Hook DLL
Cabinet.dll 754b0000 86016 C:\Windows\system32\Cabinet.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft® Cabinet File API
wpdshext.dll 5ef30000 2547712 C:\Windows\system32\wpdshext.dll 6.0.6000.16386 (vista_rtm.061101-2205) Extension de l’environnement des appareils mobiles
SFC.DLL 70ad0000 20480 C:\Windows\system32\SFC.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Windows File Protection
sfc_os.dll 742f0000 53248 C:\Windows\system32\sfc_os.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows File Protection
GrooveIntlResource.dll 619e0000 921600 C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll 12.0.6413.1000 GrooveIntlResource Module
MSFTEDIT.DLL 69650000 573440 C:\Windows\system32\MSFTEDIT.DLL 5.41.21.2508 Rich Text Edit Control, v4.1
dadkeyb.dll 6610000 106496 C:\Program Files\Dell\QuickSet\dadkeyb.dll 9, 0, 12, 0 dadkeyb Dynamic Link Library
mscoree.dll 73b60000 286720 C:\Windows\system32\mscoree.dll 2.0.50727.3053 (netfxsp.050727-3000) Microsoft .NET Runtime Execution Engine
Shfusion.dll 641f0000 122880 C:\Windows\Microsoft.NET\Framework\v2.0.50727\Shfusion.dll 2.0.50727.3053 (netfxsp.050727-3000) Microsoft COM Runtime Fusion Assembly Viewer
Fusion.dll 60610000 24576 C:\Windows\Microsoft.NET\Framework\v2.0.50727\Fusion.dll 2.0.50727.3053 (netfxsp.050727-3000) Assembly manager
culture.dll 60340000 32768 C:\Windows\Microsoft.NET\Framework\v2.0.50727\culture.dll 2.0.50727.3053 (netfxsp.050727-3000) Microsoft Globalization Support
ShFusRes.dll 64220000 98304 C:\Windows\Microsoft.NET\Framework\v2.0.50727\fr\ShFusRes.dll 2.0.50727.3053 (netfxsp.050727-3000) Microsoft COM Runtime Fusion Assembly Viewer Resources
COMDLG32.dll 77a90000 471040 C:\Windows\system32\COMDLG32.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL commune de boîtes de dialogues
msdmo.dll 67880000 45056 C:\Windows\system32\msdmo.dll 6.6.6001.18000 (longhorn_rtm.080118-1840) DMO Runtime
MSVCR71.dll 7c340000 352256 C:\Windows\system32\MSVCR71.dll 7.10.3052.4 Microsoft® C Runtime Library
WINSPOOL.DRV 72100000 270336 C:\Windows\system32\WINSPOOL.DRV 6.0.6001.18000 (longhorn_rtm.080118-1840) Pilote de spouleur Windows
Module information for 'explorer.exe'(4416)
MODULE BASE SIZE PATH
explorer.exe 240000 2936832 C:\Windows\explorer.exe 6.0.6000.16386 (vista_rtm.061101-2205) Explorateur Windows
ntdll.dll 77b10000 1208320 C:\Windows\system32\ntdll.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL Couche NT
kernel32.dll 776d0000 897024 C:\Windows\system32\kernel32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL du client API BASE Windows NT
ADVAPI32.dll 76820000 811008 C:\Windows\system32\ADVAPI32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) API avancées Windows 32
RPCRT4.dll 76380000 794624 C:\Windows\system32\RPCRT4.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Runtime d’appel de procédure distante
GDI32.dll 775f0000 307200 C:\Windows\system32\GDI32.dll 6.0.6001.18159 (vistasp1_gdr.081020-1655) GDI Client DLL
USER32.dll 777d0000 643072 C:\Windows\system32\USER32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL client de l'API uilisateur de Windows multi-utilisateurs
msvcrt.dll 77cc0000 696320 C:\Windows\system32\msvcrt.dll 7.0.6001.18000 (longhorn_rtm.080118-1840) Windows NT CRT DLL
SHLWAPI.dll 768f0000 360448 C:\Windows\system32\SHLWAPI.dll 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque d'utilitaires légers du Shell
SHELL32.dll 76950000 11599872 C:\Windows\system32\SHELL32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL commune du shell Windows
ole32.dll 76480000 1327104 C:\Windows\system32\ole32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Microsoft OLE pour Windows
OLEAUT32.dll 77870000 577536 C:\Windows\system32\OLEAUT32.dll 6.0.6001.18000 6.0.6001.18000
SHDOCVW.dll 6f3d0000 1077248 C:\Windows\system32\SHDOCVW.dll 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque d'objets et de contrôles de documents de l'environnement
UxTheme.dll 74f50000 258048 C:\Windows\system32\UxTheme.dll 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque de thèmes Ux Microsoft
POWRPROF.dll 75680000 106496 C:\Windows\system32\POWRPROF.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) DLL d’assistance du profil d’alimentation
dwmapi.dll 71ee0000 49152 C:\Windows\system32\dwmapi.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft Desktop Window Manager API
gdiplus.dll 74960000 1748992 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll 5.2.6001.18175 (vistasp1_gdr.081126-1506) Microsoft GDI+
slc.dll 75c40000 237568 C:\Windows\system32\slc.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Dll de client de gestion de licences du logiciel
PROPSYS.dll 743a0000 765952 C:\Windows\system32\PROPSYS.dll 7.0.6001.16503 (longhorn(wmbla).080526-2159) Système de propriétés Microsoft
BROWSEUI.dll 6ef60000 1335296 C:\Windows\system32\BROWSEUI.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Bibliothèque de l'interface utilisateur du navigateur
IMM32.dll 777b0000 122880 C:\Windows\system32\IMM32.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Multi-User Windows IMM32 API Client DLL
MSCTF.dll 76740000 819200 C:\Windows\system32\MSCTF.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL de MSCTF Server
DUser.dll 75270000 196608 C:\Windows\system32\DUser.dll 6.0.6000.16386 (vista_rtm.061101-2205) Windows DirectUser Engine
LPK.DLL 76810000 36864 C:\Windows\system32\LPK.DLL 6.0.6001.18000 (longhorn_rtm.080118-1840) Language Pack
USP10.dll 765d0000 512000 C:\Windows\system32\USP10.dll 1.0626.6001.18000 (longhorn_rtm.080118-1840) Uniscribe Unicode script processor
WS2_32.dll 76450000 184320 C:\Windows\system32\WS2_32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Windows Socket 2.0 32-Bit DLL
NSI.dll 76650000 24576 C:\Windows\system32\NSI.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) NSI User-mode interface DLL
NTMARTA.DLL 761e0000 135168 C:\Windows\system32\NTMARTA.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Fournisseur MARTA Windows NT
WLDAP32.dll 77c70000 303104 C:\Windows\system32\WLDAP32.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL API LDAP Win32
PSAPI.DLL 76370000 28672 C:\Windows\system32\PSAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Process Status Helper
SAMLIB.dll 761c0000 69632 C:\Windows\system32\SAMLIB.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) SAM Library DLL
comctl32.dll 750d0000 1695744 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll 5.82 (vista_rtm.061101-2205) Bibliothèque de contrôles communs
lgscroll.dll 10100000 57344 C:\Program Files\Logitech\SetPoint\lgscroll.dll 4.60.122 Logitech Scroll Enabler (UNICODE)
MSVCR80.dll 73c00000 634880 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.3053_none_d08d7bba442a9b36\MSVCR80.dll 8.00.50727.3053 Microsoft® C Runtime Library
CLBCatQ.DLL 77640000 540672 C:\Windows\system32\CLBCatQ.DLL 2001.12.6931.18000 (longhorn_rtm.080118-1840) COM+ Configuration Catalog
ExplorerFrame.dll 6df60000 36864 C:\Windows\system32\ExplorerFrame.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) ExplorerFrame
urlmon.dll 77910000 1220608 C:\Windows\system32\urlmon.dll 7.00.6001.18000 (longhorn_rtm.080118-1840) Extensions OLE32 pour Win32
iertutil.dll 77a40000 286720 C:\Windows\system32\iertutil.dll 7.00.6001.18319 (vistasp1_gdr.090827-0048) Run time utility for Internet Explorer
WININET.dll 76660000 856064 C:\Windows\system32\WININET.dll 7.00.6000.16386 (vista_rtm.061101-2205) Extensions Internet pour Win32
Normaliz.dll 77900000 12288 C:\Windows\system32\Normaliz.dll 6.0.6000.16386 (vista_rtm.061101-2205) Unicode Normalization DLL
rsaenh.dll 75720000 241664 C:\Windows\system32\rsaenh.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft Enhanced Cryptographic Provider
SETUPAPI.dll 77460000 1613824 C:\Windows\system32\SETUPAPI.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Installation de L'API Windows
actxprxy.dll 6dba0000 339968 C:\Windows\System32\actxprxy.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) ActiveX Interface Marshaling Library
ieframe.dll 6c180000 6086656 C:\Windows\system32\ieframe.dll 7.00.6000.16386 (vista_rtm.061101-2205) Internet Explorer
SXS.DLL 760a0000 389120 C:\Windows\system32\SXS.DLL 6.0.6000.16386 (vista_rtm.061101-2205) Fusion 2.5
btmmhook.dll 10000000 217088 C:\Windows\system32\btmmhook.dll 6.1.0.4402 Multimedia Keys Hook DLL
WindowsCodecs.dll 73f40000 733184 C:\Windows\system32\WindowsCodecs.dll 6.0.6001.22253 (vistasp1_ldr.080827-1507) Microsoft Windows Codecs Library
apphelp.dll 76160000 180224 C:\Windows\system32\apphelp.dll 6.0.6000.16386 (vista_rtm.061101-2205) Fichier DLL du client de compatibilité des applications
GrooveShellExtensions.dll 6e170000 2224128 C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll 12.0.6421.1000 GrooveShellExtensions Module
GrooveUtil.DLL 6dd20000 991232 C:\Program Files\Microsoft Office\Office12\GrooveUtil.DLL 12.0.6423.1000 GrooveUtil Module
CRYPT32.dll 75c80000 987136 C:\Windows\system32\CRYPT32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Crypto API32
MSASN1.dll 75de0000 73728 C:\Windows\system32\MSASN1.dll 6.0.6001.18326 (vistasp1_gdr.090903-2340) ASN.1 Runtime APIs
USERENV.dll 76230000 122880 C:\Windows\system32\USERENV.dll 6.0.6000.16386 (vista_rtm.061101-2205) Userenv
Secur32.dll 76210000 81920 C:\Windows\system32\Secur32.dll 6.0.6001.18272 (vistasp1_gdr.090615-0258) Security Support Provider Interface
GrooveNew.DLL 6df90000 28672 C:\Program Files\Microsoft Office\Office12\GrooveNew.DLL 12.0.6413.1000 GrooveNew Module
VERSION.dll 75a10000 32768 C:\Windows\system32\VERSION.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Version Checking and File Installation Libraries
ATL80.DLL 73bb0000 110592 C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.DLL 8.00.50727.4053 ATL Module for Windows (Unicode)
MSImg32.dll 753b0000 20480 C:\Windows\system32\MSImg32.dll 6.0.6000.16386 (vista_rtm.061101-2205) GDIEXT Client DLL
tiptsf.dll 62280000 393216 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll 6.0.6000.16386 (vista_rtm.061101-2205) Structure des services de texte du Panneau de saisie Tablet PC
GrooveIntlResource.dll 619e0000 921600 C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll 12.0.6413.1000 GrooveIntlResource Module
MSFTEDIT.DLL 69650000 573440 C:\Windows\system32\MSFTEDIT.DLL 5.41.21.2508 Rich Text Edit Control, v4.1
GrooveSystemServices.dll 6d950000 184320 C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll 12.0.6421.1000 GrooveSystemServices Module
GrooveMisc.dll 6d050000 1568768 C:\Program Files\Microsoft Office\Office12\GrooveMisc.dll 12.0.6421.1000 GrooveMisc Module
msxml3.dll 71bc0000 1269760 C:\Windows\System32\msxml3.dll 8.100.4001.0 MSXML 3.0 SP10
xmllite.dll 74c90000 192512 C:\Windows\system32\xmllite.dll 1.2.1009.0 Microsoft XmlLite Library
IconCodecService.dll 6df70000 24576 C:\Windows\system32\IconCodecService.dll 6.0.6000.16386 (vista_rtm.061101-2205) Converts a PNG part of the icon to a legacy bmp icon
thumbcache.dll 6d630000 90112 C:\Windows\system32\thumbcache.dll 6.0.6000.16386 (vista_rtm.061101-2205) Cache de miniatures Microsoft
MPR.dll 75d80000 81920 C:\Windows\system32\MPR.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL de routeur de fournisseurs multiples
ntshrui.dll 6d5e0000 303104 C:\Windows\system32\ntshrui.dll 6.0.6000.16386 (vista_rtm.061101-2205) Extensions de l'interpréteur de commandes pour le partage
NETAPI32.dll 76020000 479232 C:\Windows\system32\NETAPI32.dll 6.0.6001.18157 (vistasp1_gdr.081015-1604) Net Win32 API DLL
cscapi.dll 6fad0000 45056 C:\Windows\system32\cscapi.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Offline Files Win32 API
LINKINFO.dll 6df80000 36864 C:\Windows\system32\LINKINFO.dll 6.0.6000.16386 (vista_rtm.061101-2205) Windows Volume Tracking
PortableDeviceApi.dll 71a10000 253952 C:\Windows\system32\PortableDeviceApi.dll 6.0.6001.18160 (vistasp1_gdr.081021-1528) Windows Portable Device API Components
WINTRUST.dll 754d0000 184320 C:\Windows\system32\WINTRUST.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Microsoft Trust Verification APIs
imagehlp.dll 77c40000 167936 C:\Windows\system32\imagehlp.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows NT Image Helper
PortableDeviceTypes.dll 6ffd0000 176128 C:\Windows\system32\PortableDeviceTypes.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows Portable Device (Parameter) Types Component
AVIFIL32.dll 742d0000 102400 C:\Windows\system32\AVIFIL32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Bibliothèque d'assistance des fichiers AVI Microsoft
WINMM.dll 752a0000 204800 C:\Windows\system32\WINMM.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL API MCI
OLEACC.dll 74f90000 233472 C:\Windows\system32\OLEACC.dll 4.2.5406.0 (longhorn_rtm.080118-1840) Active Accessibility Core Component
MSACM32.dll 741a0000 81920 C:\Windows\system32\MSACM32.dll 6.0.6000.16386 (vista_rtm.061101-2205) Filtre audio ACM Microsoft
MSVFW32.dll 6d680000 143360 C:\Windows\system32\MSVFW32.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL Microsoft Video for Windows
wdmaud.drv 74370000 192512 C:\Windows\system32\wdmaud.drv 6.0.6000.16386 (vista_rtm.061101-2205) Pilote du système audio Winmm
ksuser.dll 74b40000 16384 C:\Windows\system32\ksuser.dll 6.0.6000.16386 (vista_rtm.061101-2205) User CSA Library
MMDevAPI.DLL 753e0000 159744 C:\Windows\system32\MMDevAPI.DLL 6.0.6000.16386 (vista_rtm.061101-2205) MMDevice API
AVRT.dll 75590000 28672 C:\Windows\system32\AVRT.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Multimedia Realtime Runtime
AUDIOSES.DLL 74340000 135168 C:\Windows\system32\AUDIOSES.DLL 6.0.6001.18000 (longhorn_rtm.080118-1840) Audio Session
audioeng.dll 741f0000 417792 C:\Windows\system32\audioeng.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Audio Engine
msacm32.drv 74310000 36864 C:\Windows\system32\msacm32.drv 6.0.6000.16386 (vista_rtm.061101-2205) Mappeur de sons Microsoft
midimap.dll 74300000 28672 C:\Windows\system32\midimap.dll 6.0.6000.16386 (vista_rtm.061101-2205) Microsoft MIDI Mapper
dciman32.dll 74bf0000 24576 C:\Windows\system32\dciman32.dll 6.0.6001.18272 (vistasp1_gdr.090615-0258) DCI Manager
rarext.dll 2ae0000 188416 C:\Program Files\WinRAR\rarext.dll
mbamext.dll 2aa0000 73728 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll 1, 2, 0, 0 Malwarebytes' Anti-Malware
ATL.DLL 74320000 81920 C:\Windows\system32\ATL.DLL 3.05.2284 ATL Module for Windows XP (Unicode)
syncui.dll 67470000 188416 C:\Windows\system32\syncui.dll 6.0.6000.16386 (vista_rtm.061101-2205) Porte-documents Windows
SYNCENG.dll 742a0000 90112 C:\Windows\system32\SYNCENG.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Windows Briefcase Engine
ashShell.dll 64f00000 73728 C:\Program Files\Alwil Software\Avast4\ashShell.dll 4, 8, 1201, 0 avast! Shell Extension
quartz.dll 63ab0000 1519616 C:\Windows\system32\quartz.dll 6.6.6000.16386 (vista_rtm.061101-2205) Module d'exécution DirectShow.
DXVA2.DLL 6dc00000 77824 C:\Windows\system32\DXVA2.DLL 6.0.6001.18000 (longhorn_rtm.080118-1840) DirectX Video Acceleration 2.0 DLL
mpg2splt.ax 62750000 192512 C:\Windows\System32\mpg2splt.ax 6.6.6001.18322 (vistasp1_gdr.090831-0117) DirectShow MPEG-2 Splitter.
mediametadatahandler.dll 61d50000 376832 C:\Windows\System32\mediametadatahandler.dll 6.0.6001.18000 (longhorn_rtm.080118-1840) Media Metadata Handler
WMVCore.DLL 70050000 2404352 C:\Windows\System32\WMVCore.DLL 11.0.6001.7006 (vistasp1_gdr.090609-2338) Windows Media Playback/Authoring DLL
WMASF.DLL 702e0000 233472 C:\Windows\System32\WMASF.DLL 11.0.6001.7000 (longhorn_rtm.080118-1840) Windows Media ASF DLL
qedit.dll 61c50000 520192 C:\Windows\System32\qedit.dll 6.6.6000.16386 (vista_rtm.061101-2205) Édition DirectShow.
COMDLG32.dll 77a90000 471040 C:\Windows\system32\COMDLG32.dll 6.0.6000.16386 (vista_rtm.061101-2205) DLL commune de boîtes de dialogues
devenum.dll 69600000 77824 C:\Windows\system32\devenum.dll 6.6.6000.16386 (vista_rtm.061101-2205) Énumération de périphériques.
RLOgg.ax 1c400000 503808 C:\Windows\system32\RLOgg.ax 1.0.0.2 RLOgg
MSVCR71.dll 7c340000 352256 C:\Windows\system32\MSVCR71.dll 7.10.3052.4 Microsoft® C Runtime Library
flvDX.dll 4600000 450560 C:\Windows\system32\flvDX.dll 1, 0, 0, 1 FLV Splitter
WINSPOOL.DRV 72100000 270336 C:\Windows\system32\WINSPOOL.DRV 6.0.6001.18000 (longhorn_rtm.080118-1840) Pilote de spouleur Windows
DiracSplitter.ax 5930000 462848 C:\Windows\system32\DiracSplitter.ax 1, 0, 0, 0 Dirac Splitter
RealMediaDX.ax 6210000 462848 C:\Windows\system32\RealMediaDX.ax 1, 0, 1, 1 RealMedia Splitter
MatroskaDX.ax 7090000 475136 C:\Windows\system32\MatroskaDX.ax 1, 0, 2, 9 Matroska Splitter
msmpeg2adec.dll 61be0000 409600 C:\Windows\System32\msmpeg2adec.dll 11.0.6001.7000 (lh_client_secure.071206-1753) Microsoft MPEG-1/DD Audio Decoder
aac_parser.ax 3a60000 86016 C:\Windows\system32\aac_parser.ax 1.1 Direct show parser filter for ADTS



******************************************
EOF

12 Re: Help for Core10k virus removal =) on Fri Nov 27, 2009 12:34 am

DragonMaster Jay


Site Owner
Site Owner
Please download RenewMyDNS by DragonMaster Jay.
  • Save it to your Desktop.
  • Right-click on the file and select Extract All...
  • Choose a location to save extracted files and keep pressing Next until Finish.
  • Double-click RenewMyDNS folder, then double-click RenewMyDNS.bat to start the program.
  • Follow the prompts, and when finished it will launch a log.
  • Post that log in your next reply.
  • After posting the log, delete the folder RenewMyDNS.


==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


==

Please post the logs from RenewMyDNS and Security Check. Also, please let me know how your computer is running.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

13 Re: Help for Core10k virus removal =) on Fri Nov 27, 2009 8:57 am

Darklad


Member
Member
RenewMyDNS by DragonMaster Jay
DNS Diagnostics and refresher
Version 0.1.4 - November 2009

Microsoft Windows [version 6.0.6001]


(((((((((((((((((((( Network and DNS Information ))))))))))))))))))))



Configuration IP de Windows

Nom de l'h“te . . . . . . . . . . : PC-de-Daniel
Suffixe DNS principal . . . . . . :
Type de noeud. . . . . . . . . . : Diffusion
Routage IP activ‚ . . . . . . . . : Non
Proxy WINS activ‚ . . . . . . . . : Non

Carte Ethernet Connexion r‚seau Bluetooth :

Statut du m‚dia. . . . . . . . . . . . : M‚dia d‚connect‚
Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : P‚riph‚rique Bluetooth (r‚seau personnel)
Adresse physique . . . . . . . . . . . : 00-22-68-DE-FE-A7
DHCP activ‚. . . . . . . . . . . . . . : Oui
Configuration automatique activ‚e. . . : Oui

Carte r‚seau sans fil Connexion r‚seau sans filÿ:

Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : Dell Wireless 1510 Wireless-N WLAN Mini-Card
Adresse physique . . . . . . . . . . . : 00-22-69-AB-5D-4A
DHCP activ‚. . . . . . . . . . . . . . : Oui
Configuration automatique activ‚e. . . : Oui
Adresse IPv6 de liaison locale. . : fe80::8561:c15e:8ba5:18d%12(pr‚f‚r‚)
Adresse IPv4. . . . . . . . . . . : 192.168.1.21(pr‚f‚r‚)
Masque de sous-r‚seau. . . .ÿ. . . . . : 255.255.255.0
Bail obtenu. . . . . . . . .ÿ. . . . . : jeudi 26 novembre 2009 00:16:13
Bail expirant. . . . . . . . .ÿ. . . . : samedi 28 novembre 2009 13:09:13
Passerelle par d‚faut. . . .ÿ. . . . . : 192.168.1.1
Serveur DHCP . . . . . . . . . . . . . : 192.168.1.1
Serveurs DNS. . . . . . . . . . . . . : 192.168.1.1
NetBIOS sur Tcpip. . . . . . . . . . . : Activ‚

Carte Ethernet Connexion au r‚seau local :

Statut du m‚dia. . . . . . . . . . . . : M‚dia d‚connect‚
Suffixe DNS propre … la connexion. . . : wp.shawcable.net
Description. . . . . . . . . . . . . . : Broadcom NetLink (TM) Gigabit Ethernet
Adresse physique . . . . . . . . . . . : 00-21-70-81-90-23
DHCP activ‚. . . . . . . . . . . . . . : Oui
Configuration automatique activ‚e. . . : Oui

Carte Tunnel Connexion au r‚seau local* :

Statut du m‚dia. . . . . . . . . . . . : M‚dia d‚connect‚
Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : isatap.{8130F44F-1165-49B1-8BAF-A7DCA3184CF6}
Adresse physique . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP activ‚. . . . . . . . . . . . . . : Non
Configuration automatique activ‚e. . . : Oui

Carte Tunnel Connexion au r‚seau local* 6 :

Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Adresse physique . . . . . . . . . . . : 02-00-54-55-4E-01
DHCP activ‚. . . . . . . . . . . . . . : Non
Configuration automatique activ‚e. . . : Oui
Adresse IPv6. . . . . . . . . . .ÿ: 2001:0:d5c7:a2d6:2cfe:25a8:b0ad:4ea6(pr‚f‚r‚)
Adresse IPv6 de liaison locale. . : fe80::2cfe:25a8:b0ad:4ea6%10(pr‚f‚r‚)
Passerelle par d‚faut. . . .ÿ. . . . . : ::
NetBIOS sur TCPIP. . . . . . . . . . . : D‚sactiv‚

Carte Tunnel Connexion au r‚seau local* 7 :

Statut du m‚dia. . . . . . . . . . . . : M‚dia d‚connect‚
Suffixe DNS propre … la connexion. . . :
Description. . . . . . . . . . . . . . : isatap.wp.shawcable.net
Adresse physique . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP activ‚. . . . . . . . . . . . . . : Non
Configuration automatique activ‚e. . . : Oui

(((((((((((((((((((( DNS-Fake Request Testing and Flush ))))))))))))))))))))

... Requests made were successful

Configuration IP de Windows

Cache de r‚solution DNS vid‚.


(((((((((((((((((((( Speed-test - Ping ))))))))))))))))))))


Envoi d'une requˆte 'ping' sur yahoo.com [209.131.36.159] avec 32 octets de donn‚esÿ:

R‚ponse de 209.131.36.159ÿ: octets=32 temps=175 ms TTL=50

R‚ponse de 209.131.36.159ÿ: octets=32 temps=177 ms TTL=50

R‚ponse de 209.131.36.159ÿ: octets=32 temps=184 ms TTL=50

R‚ponse de 209.131.36.159ÿ: octets=32 temps=179 ms TTL=50



Statistiques Ping pour 209.131.36.159:

Paquetsÿ: envoy‚s = 4, re‡us = 4, perdus = 0 (perte 0%),

Dur‚e approximative des boucles en millisecondes :

Minimum = 175ms, Maximum = 184ms, Moyenne = 178ms



Envoi d'une requˆte 'ping' sur geekpolice.net [74.86.239.78] avec 32 octets de donn‚esÿ:

D‚lai d'attente de la demande d‚pass‚.

D‚lai d'attente de la demande d‚pass‚.

D‚lai d'attente de la demande d‚pass‚.

D‚lai d'attente de la demande d‚pass‚.



Statistiques Ping pour 74.86.239.78:

Paquetsÿ: envoy‚s = 4, re‡us = 0, perdus = 4 (perte 100%),



Envoi d'une requˆte 'ping' sur facebook.com [69.63.187.17] avec 32 octets de donn‚esÿ:

R‚ponse de 69.63.187.17ÿ: octets=32 temps=118 ms TTL=245

R‚ponse de 69.63.187.17ÿ: octets=32 temps=123 ms TTL=245

R‚ponse de 69.63.187.17ÿ: octets=32 temps=214 ms TTL=245

R‚ponse de 69.63.187.17ÿ: octets=32 temps=124 ms TTL=245



Statistiques Ping pour 69.63.187.17:

Paquetsÿ: envoy‚s = 4, re‡us = 4, perdus = 0 (perte 0%),

Dur‚e approximative des boucles en millisecondes :

Minimum = 118ms, Maximum = 214ms, Moyenne = 144ms



Envoi d'une requˆte 'ping' sur microsoft.com [207.46.197.32] avec 32 octets de donn‚esÿ:

D‚lai d'attente de la demande d‚pass‚.

D‚lai d'attente de la demande d‚pass‚.

D‚lai d'attente de la demande d‚pass‚.

D‚lai d'attente de la demande d‚pass‚.



Statistiques Ping pour 207.46.197.32:

Paquetsÿ: envoy‚s = 4, re‡us = 0, perdus = 4 (perte 100%),


********************
EOF

14 Re: Help for Core10k virus removal =) on Fri Nov 27, 2009 9:01 am

Darklad


Member
Member
Results of screen317's Security Check version 0.99.0
Windows Vista Service Pack 1 (UAC is disabled!)
Out of date service pack!!
``````````````````````````````
Antivirus/Firewall Check:

avast! Antivirus
ESET Online Scanner v3
McAfee Security Scan
Antivirus up to date!
``````````````````````````````
Anti-malware/Other Utilities Check:

HijackThis 2.0.2
Java(TM) 6 Update 7
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 9.1 - Français
``````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSASCui.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````


My computer is running pretty much normally but it can be slow at some moments.

15 Re: Help for Core10k virus removal =) on Fri Nov 27, 2009 3:00 pm

DragonMaster Jay


Site Owner
Site Owner
Please download ATF Cleaner by Atribune.

    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, click No at the prompt.
Click Exit on the Main menu to close the program.

==

Please consider updating to Windows Vista Service Pack 2 (SP2).
Windows Vista Service Pack 2 (SP2) contains all the updates released since SP1 plus support for new types of hardware and emerging hardware standards.
It is now available via Windows Update or as a standalone installation here.

==

Please download the newest version of Java from Java.com.

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

==

In your next log, please tell me how your computer is running after doing the above steps. This is important, because any issues with updating or strange activity may be signs of more malware.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 2]

Goto page : 1, 2  Next

Permissions in this forum:
You cannot reply to topics in this forum