ComboFix 08-11-16.01 - 260708 2008-11-16 22:58:09.1 - NTFSx86
Microsoft® Windows Vista™ Edition Familiale Premium 6.0.6001.1.1252.1.1036.18.927 [GMT 1:00]
Lancé depuis: C:Users260708DesktopComboFix.exe
Commutateurs utilisés :: C:Users260708DesktopCFScript.txt
* Un nouveau point de restauration a été créé
* Resident AV is active
FILE ::
C:Users260708AppDataLocalTempgrptsyfw.dll
C:Users260708AppDataLocalTemphgGaaWon.dll
C:Users260708AppDataLocalTemp
nnMEWMg.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-16 au 2008-11-16 ))))))))))))))))))))))))))))))))))))
.
2008-11-13 23:30 . 2008-11-13 23:30 <REP> d-------- C:UsersAll UsersMalwarebytes
2008-11-13 23:30 . 2008-11-13 23:30 <REP> d-------- C:Users260708AppDataRoamingMalwarebytes
2008-11-13 23:30 . 2008-11-13 23:30 <REP> d-------- C:ProgramDataMalwarebytes
2008-11-13 23:30 . 2008-11-13 23:30 <REP> d-------- C:Program FilesMalwarebytes' Anti-Malware
2008-11-13 23:30 . 2008-10-22 16:10 38,496 --a------ C:WindowsSystem32driversmbamswissarmy.sys
2008-11-13 23:30 . 2008-10-22 16:10 15,504 --a------ C:WindowsSystem32driversmbam.sys
2008-11-13 17:41 . 2008-11-13 17:41 <REP> d-------- C:Program FilesCommon FilesPCSuite
2008-11-13 17:41 . 2008-11-13 17:41 <REP> d-------- C:Program FilesCommon FilesNokia
2008-11-13 17:28 . 2008-09-10 04:40 1,334,272 --a------ C:WindowsSystem32msxml6.dll
2008-11-13 17:28 . 2008-09-05 06:14 1,191,936 --a------ C:WindowsSystem32msxml3.dll
2008-11-13 17:28 . 2008-08-27 02:05 212,480 --a------ C:WindowsSystem32driversmrxsmb10.sys
2008-11-12 19:16 . 2008-11-12 19:16 <REP> d-------- C:Users260708AppDataRoamingdvdcss
2008-11-11 17:16 . 2008-11-12 17:53 51,792 --a------ C:WindowsSystem32driversaswMonFlt.sys
2008-11-04 22:02 . 2008-06-24 13:45 1,414,440 --a------ C:WindowsSystem32ShellManager310E2D762.dll
2008-11-04 22:02 . 2008-06-23 17:36 773,120 --a------ C:WindowsSystem32NEROINSTAEC43759.DB
2008-11-04 22:01 . 2008-11-04 22:01 0 --a------ C:WindowsIrremote.ini
2008-11-04 20:35 . 2008-11-04 20:35 <REP> d-------- C:Users260708AppDataRoamingNero
2008-11-04 20:32 . 2008-11-04 22:18 <REP> d-------- C:UsersAll UsersNero
2008-11-04 20:32 . 2008-11-04 22:18 <REP> d-------- C:ProgramDataNero
2008-11-04 20:32 . 2008-11-04 20:32 <REP> d-------- C:Program FilesNero
2008-11-04 20:32 . 2008-11-04 22:20 <REP> d-------- C:Program FilesCommon FilesNero
2008-11-02 13:30 . 2008-11-02 13:30 <REP> d-------- C:Users260708AppDataRoamingTemplate
2008-11-02 13:30 . 2008-11-02 14:16 90 --a------ C:Users260708AppDataRoamingwklnhst.dat
2008-11-01 15:06 . 2008-11-01 15:06 <REP> d-------- C:Program FilesAudacity
2008-11-01 13:04 . 2008-11-01 13:04 0 --ah----- C:WindowsSystem32driversMsft_User_PCCSWpdDriver_01_05_00.Wdf
2008-11-01 13:04 . 2008-11-01 13:04 0 --ah----- C:WindowsSystem32driversMsft_Kernel_ccdcmb_01005.Wdf
2008-11-01 13:03 . 2008-11-01 13:04 <REP> d-------- C:UsersAll UsersPC Suite
2008-11-01 13:03 . 2008-11-01 13:05 <REP> d-------- C:Users260708AppDataRoamingPC Suite
2008-11-01 13:03 . 2008-11-01 13:04 <REP> d-------- C:Users260708AppDataRoamingNokia
2008-11-01 13:03 . 2008-11-01 13:04 <REP> d-------- C:ProgramDataPC Suite
2008-11-01 13:01 . 2008-11-01 13:01 <REP> d-------- C:Program FilesDIFX
2008-11-01 13:01 . 2007-09-17 15:53 21,632 --a------ C:WindowsSystem32driverspccsmcfd.sys
2008-11-01 13:00 . 2008-11-01 13:01 <REP> d----c--- C:WindowsSystem32DRVSTORE
2008-11-01 13:00 . 2008-11-01 13:00 <REP> d-------- C:Program FilesPC Connectivity Solution
2008-11-01 12:57 . 2008-11-13 17:41 <REP> d-------- C:Program FilesNokia
2008-11-01 12:57 . 2008-05-07 07:38 90,624 --a------ C:WindowsSystem32
mwcdcls.dll
2008-11-01 12:56 . 2008-11-12 18:22 <REP> d-------- C:UsersAll UsersInstallations
2008-11-01 12:56 . 2008-11-12 18:22 <REP> d-------- C:ProgramDataInstallations
2008-10-30 22:04 . 2008-10-30 22:04 <REP> d-------- C:Users260708AppDataRoamingApple Computer
2008-10-29 22:53 . 2008-10-29 22:53 <REP> d--hsc--- C:Program FilesCommon FilesWindowsLiveInstaller
2008-10-29 22:52 . 2008-10-29 22:52 <REP> d-------- C:UsersAll UsersWLInstaller
2008-10-29 22:52 . 2008-10-29 22:52 <REP> d-------- C:ProgramDataWLInstaller
2008-10-29 22:52 . 2008-10-29 22:54 <REP> d-------- C:Program FilesWindows Live
2008-10-29 20:07 . 2008-07-31 02:13 4,240,384 --a------ C:WindowsSystem32GameUXLegacyGDFs.dll
2008-10-29 20:07 . 2008-03-08 05:21 1,695,744 --a------ C:WindowsSystem32gameux.dll
2008-10-29 20:07 . 2008-06-19 04:31 361,984 --a------ C:WindowsSystem32IPSECSVC.DLL
2008-10-29 20:07 . 2008-07-31 04:32 28,160 --a------ C:WindowsSystem32Apphlpdm.dll
2008-10-29 20:06 . 2008-04-26 09:26 891,448 --a------ C:WindowsSystem32drivers cpip.sys
2008-10-29 20:06 . 2008-04-12 04:32 784,896 --a------ C:WindowsSystem32
pcrt4.dll
2008-10-29 20:06 . 2008-08-05 10:49 428,544 --a------ C:WindowsSystem32EncDec.dll
2008-10-29 20:06 . 2008-08-05 10:49 293,376 --a------ C:WindowsSystem32psisdecd.dll
2008-10-29 20:06 . 2008-08-05 10:48 217,088 --a------ C:WindowsSystem32psisrndr.ax
2008-10-29 20:06 . 2008-08-05 10:48 177,664 --a------ C:WindowsSystem32mpg2splt.ax
2008-10-29 20:06 . 2008-08-05 10:48 80,896 --a------ C:WindowsSystem32MSNP.ax
2008-10-29 20:06 . 2008-04-05 02:21 72,192 --a------ C:WindowsSystem32driverspacer.sys
2008-10-29 20:06 . 2008-04-23 05:41 57,856 --a------ C:WindowsSystem32MSDvbNP.ax
2008-10-29 20:06 . 2008-04-05 04:34 15,360 --a------ C:WindowsSystem32pacerprf.dll
2008-10-29 20:04 . 2008-06-26 04:29 303,616 --a------ C:WindowsSystem32wmpeffects.dll
2008-10-29 20:04 . 2008-04-18 06:48 269,312 --a------ C:WindowsSystem32es.dll
2008-10-29 20:03 . 2008-06-26 02:45 12,240,896 --a------ C:WindowsSystem32NlsLexicons0007.dll
2008-10-29 20:03 . 2008-06-26 02:45 2,644,480 --a------ C:WindowsSystem32NlsLexicons0009.dll
2008-10-29 20:03 . 2008-09-18 03:16 2,032,640 --a------ C:WindowsSystem32win32k.sys
2008-10-29 20:03 . 2008-06-26 04:29 801,280 --a------ C:WindowsSystem32NaturalLanguage6.dll
2008-10-29 19:52 . 2008-02-29 08:11 988,216 --a------ C:WindowsSystem32winload.exe
2008-10-29 19:52 . 2008-02-29 08:11 927,288 --a------ C:WindowsSystem32winresume.exe
2008-10-29 19:52 . 2008-02-22 06:05 615,992 --a------ C:WindowsSystem32ci.dll
2008-10-29 19:52 . 2008-02-29 07:53 378,368 --a------ C:WindowsSystem32srcore.dll
2008-10-29 19:52 . 2008-02-29 05:12 318,464 --a------ C:WindowsSystem32
strui.exe
2008-10-29 19:52 . 2008-02-29 07:53 46,592 --a------ C:WindowsSystem32setbcdlocale.dll
2008-10-29 19:52 . 2008-02-29 07:53 40,960 --a------ C:WindowsSystem32srclient.dll
2008-10-29 19:52 . 2008-02-29 08:14 19,000 --a------ C:WindowsSystem32kd1394.dll
2008-10-29 19:52 . 2008-02-29 05:12 14,848 --a------ C:WindowsSystem32srdelayed.exe
2008-10-29 19:52 . 2008-02-29 07:35 6,656 --a------ C:WindowsSystem32kbd106n.dll
2008-10-29 19:51 . 2008-02-22 05:57 295,936 --a------ C:WindowsSystem32gdi32.dll
2008-10-29 19:51 . 2008-08-27 02:06 288,768 --a------ C:WindowsSystem32driverssrv.sys
2008-10-29 19:51 . 2008-09-18 05:56 147,456 --a------ C:WindowsSystem32Faultrep.dll
2008-10-29 19:51 . 2008-09-18 05:56 125,952 --a------ C:WindowsSystem32wersvc.dll
2008-10-29 19:50 . 2008-08-02 02:01 625,152 --a------ C:WindowsSystem32driversdxgkrnl.sys
2008-10-29 19:50 . 2008-06-26 04:29 565,248 --a------ C:WindowsSystem32emdmgmt.dll
2008-10-29 19:50 . 2008-08-12 04:39 443,392 --a------ C:WindowsSystem32win32spl.dll
2008-10-29 19:50 . 2008-05-20 03:07 148,480 --a------ C:WindowsSystem32drivers
wifi.sys
2008-10-29 19:50 . 2008-06-26 04:29 45,056 --a------ C:WindowsSystem32dataclen.dll
2008-10-29 19:50 . 2008-08-02 04:26 36,864 --a------ C:WindowsSystem32cdd.dll
2008-10-29 19:49 . 2008-05-08 22:59 430,080 --a------ C:WindowsSystem32vbscript.dll
2008-10-29 19:49 . 2008-05-08 22:59 180,224 --a------ C:WindowsSystem32scrobj.dll
2008-10-29 19:49 . 2008-05-08 22:59 172,032 --a------ C:WindowsSystem32scrrun.dll
2008-10-29 19:49 . 2008-05-08 22:59 155,648 --a------ C:WindowsSystem32wscript.exe
2008-10-29 19:49 . 2008-05-08 22:58 135,168 --a------ C:WindowsSystem32wshom.ocx
2008-10-29 19:49 . 2008-05-08 22:58 135,168 --a------ C:WindowsSystem32cscript.exe
2008-10-29 19:49 . 2008-05-10 02:33 113,664 --a------ C:WindowsSystem32drivers
mcast.sys
2008-10-29 19:49 . 2008-05-08 22:59 90,112 --a------ C:WindowsSystem32wshext.dll
2008-10-29 19:49 . 2006-11-28 21:46 28,224 --a------ C:WindowsSystem32driversPCAMp50.sys
2008-10-29 19:49 . 2006-11-28 21:46 27,072 --a------ C:WindowsSystem32driversPCASp50.sys
2008-10-29 19:48 . 2008-09-18 06:09 3,601,464 --a------ C:WindowsSystem32
tkrnlpa.exe
2008-10-29 19:48 . 2008-09-18 06:09 3,549,240 --a------ C:WindowsSystem32
toskrnl.exe
2008-10-29 19:48 . 2008-04-26 09:08 1,314,816 --a------ C:WindowsSystem32quartz.dll
2008-10-29 19:48 . 2008-04-10 06:12 738,304 --a------ C:WindowsSystem32inetcomm.dll
2008-10-29 19:46 . 2007-09-25 19:31 65,536 --a------ C:WindowsSystem32Autodial2000.dll
2008-10-29 19:44 . 2003-03-19 06:20 1,060,864 --a------ C:WindowsSystem32MFC71.dll
2008-10-29 19:44 . 2003-09-16 09:07 499,712 --a------ C:WindowsSystem32msvcp71.dll
2008-10-29 19:44 . 2003-02-21 13:42 348,160 --a------ C:WindowsSystem32MSVCR71.dll
2008-10-29 19:44 . 2003-03-19 04:05 89,088 --a------ C:WindowsSystem32atl71.dll
2008-10-29 19:44 . 2008-07-16 02:32 2,048 --a------ C:WindowsSystem32 zres.dll
2008-10-29 19:43 . 2008-10-02 02:32 1,383,424 --a------ C:WindowsSystem32mshtml.tlb
2008-10-29 19:43 . 2008-10-02 04:49 827,392 --a------ C:WindowsSystem32wininet.dll
2008-10-29 19:41 . 2008-05-27 05:59 106,605 --a------ C:WindowsSystem32StructuredQuerySchema.bin
2008-10-29 19:41 . 2008-05-27 05:59 18,904 --a------ C:WindowsSystem32StructuredQuerySchemaTrivial.bin
2008-10-29 19:41 . 2008-05-27 06:17 11,776 --a------ C:WindowsSystem32msshooks.dll
2008-10-29 19:40 . 2008-10-29 19:40 <REP> d-------- C:Program FilesSecuritoo
2008-10-29 18:59 . 2008-10-29 18:59 <REP> d-------- C:Program FilesAlwil Software
2008-10-29 18:41 . 2008-10-29 19:49 <REP> d-------- C:Program FilesOrange
2008-10-29 18:41 . 2008-10-29 18:41 <REP> d-------- C:Program FilesCommon FilesFrance Telecom
2008-10-29 18:36 . 2008-10-29 18:36 <REP> d-------- C:Users260708AppDataRoamingInstallShield
2008-10-29 18:36 . 2008-10-29 18:36 <REP> d-------- C:Program FilesSAGEM
2008-10-29 18:31 . 2008-10-29 18:31 <REP> d-------- C:UsersAll UsersAzureus
2008-10-29 18:31 . 2008-11-16 23:02 <REP> d-------- C:Users260708AppDataRoamingAzureus
2008-10-29 18:31 . 2008-10-29 18:31 <REP> d-------- C:ProgramDataAzureus
2008-10-29 18:31 . 2008-11-02 14:18 <REP> d-------- C:Program FilesAzureus
2008-10-29 18:31 . 2008-10-29 18:31 <REP> d-------- C:Program FilesAskSBar
2008-10-29 18:29 . 2008-10-29 22:54 <REP> d-------- C:Program FilesMSN Messenger
2008-10-29 18:10 . 2008-10-29 22:45 <REP> d-------- C:Program FilesQuickTime
2008-10-29 18:08 . 2008-10-29 18:08 <REP> d-------- C:Users260708AppDataRoamingvlc
2008-10-29 18:08 . 2008-10-29 22:45 <REP> d-------- C:Program FilesApple Software Update
2008-10-29 18:07 . 2008-10-29 22:45 <REP> d-------- C:UsersAll UsersApple Computer
2008-10-29 18:07 . 2008-10-29 22:45 <REP> d-------- C:ProgramDataApple Computer
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 02:10 --------- d-----w C:Program FilesGoogle
2008-11-14 02:02 --------- d-----w C:ProgramDataMicrosoft Help
2008-10-31 21:47 --------- d-----w C:Program FilesWindows Mail
2008-10-30 03:31 --------- d-----w C:Program FilesBurnInTest
2008-10-29 19:08 --------- d-----w C:Program FilesPicasa2
2008-10-29 18:58 --------- d-----w C:Program FilesMcAfee
2008-10-29 17:36 --------- d--h--w C:Program FilesInstallShield Installation Information
2008-10-29 17:05 --------- d---a-w C:ProgramDataTEMP
2008-09-30 15:43 1,286,152 ----a-w C:WindowsSystem32msxml4.dll
2008-01-21 02:43 174 --sha-w C:Program Filesdesktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"TOSCDSPD"="C:Program FilesTOSHIBATOSCDSPDTOSCDSPD.exe" [2007-12-29 09:06 430080]
"PC Suite Tray"="C:Program FilesNokiaNokia PC Suite 7PCSuite.exe" [2008-10-02 07:00 1124352]
"WMPNSCFG"="C:Program FilesWindows Media PlayerWMPNSCFG.exe" [2008-01-21 03:25 202240]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:Program FilesCommon FilesNeroLibNMIndexStoreSvr.exe" [2008-06-24 16:06 1840424]
"ehTray.exe"="C:WindowsehomeehTray.exe" [2008-01-21 03:25 125952]
"Nokia.PCSync"="C:Program FilesNokiaNokia PC Suite 7PCSync2.exe" [2008-06-17 16:00 1249280]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"SunJavaUpdateSched"="C:Program FilesJavajre1.6.0_04injusched.exe" [2007-12-14 02:42 144784]
"Adobe Reader Speed Launcher"="C:Program FilesAdobeReader 8.0ReaderReader_sl.exe" [2007-05-11 03:06 40048]
"mcagent_exe"="C:Program FilesMcAfee.comAgentmcagent.exe" [2007-08-03 22:33 582992]
"Desktop SMS"="C:Program FilesIDMDesktop SMSDesktopSMS.exe" [2007-06-18 10:51 1507328]
"Google Desktop Search"="C:Program FilesGoogleGoogle Desktop SearchGoogleDesktop.exe" [2008-02-18 16:18 1836544]
"topi"="C:Program FilesTOSHIBAToshiba Online Product Information opi.exe" [2007-07-10 09:24 581632]
"StartCCC"="C:Program FilesATI TechnologiesATI.ACECore-StaticCLIStart.exe" [2006-11-10 11:35 90112]
"SynTPEnh"="C:Program FilesSynapticsSynTPSynTPEnh.exe" [2007-11-29 17:58 1029416]
"Camera Assistant Software"="C:Program FilesCamera Assistant Software for Toshiba raybar.exe" [2007-10-25 16:41 413696]
"TPwrMain"="C:Program FilesTOSHIBAPower SaverTPwrMain.EXE" [2008-01-17 15:27 431456]
"HSON"="C:Program FilesTOSHIBATBSHSON.exe" [2007-10-31 22:01 54608]
"SmoothView"="C:Program FilesToshibaSmoothViewSmoothView.exe" [2008-01-25 10:22 509816]
"00TCrdMain"="C:Program FilesTOSHIBAFlashCardsTCrdMain.exe" [2008-01-22 13:25 712704]
"Toshiba Registration"="C:Program FilesToshibaRegistrationToshibaRegistration.exe" [2007-05-04 11:05 571024]
"SystrayORAHSS"="C:Program FilesOrangeSystraySystrayApp.exe" [2007-09-25 20:08 94208]
"ORAHSSSessionManager"="C:Program FilesOrangeSessionManagerSessionManager.exe" [2007-09-25 19:10 102400]
"QuickTime Task"="C:Program FilesQuickTimeqttask.exe" [2006-09-01 15:57 282624]
"NBKeyScan"="C:Program FilesNeroNero8Nero BackItUpNBKeyScan.exe" [2008-06-08 09:31 2221352]
"avast!"="C:PROGRA~1ALWILS~1Avast4ashDisp.exe" [2008-11-12 17:54 81000]
"NDSTray.exe"="NDSTray.exe" [BU]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"Picasa Media Detector"="C:Program FilesPicasa2PicasaMediaDetector.exe" [2008-02-26 02:23 443968]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=C:PROGRA~1GoogleGOOGLE~3GOEC62~1.DLL
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"msacm.dvacm"= C:PROGRA~1COMMON~1ULEADS~1viodvacm.acm
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringMcAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicyDomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyFirewallRules]
"{749D0E7F-1FB9-47C2-9CBF-6FC155B13BE7}"= Profile=Private|Profile=Public|C:Program FilesCommon FilesMcafeeMNAMcNaSvc.exe:McAfee Network Agent
"{FC05447A-D300-407B-AE26-40533E552F10}"= UDP:C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE:Microsoft Office OneNote
"{6062A136-093B-4946-BB91-BC0D98695D22}"= TCP:C:Program FilesMicrosoft OfficeOffice12ONENOTE.EXE:Microsoft Office OneNote
"{D20A6DAE-1C37-4DED-BAA5-E6E6E23FAD4B}"= UDP:C:Program FilesMSN Messengermsnmsgr.exe:MSN Messenger 7.5
"{D66A00BA-A389-49B2-8FCA-B7837148D1B3}"= TCP:C:Program FilesMSN Messengermsnmsgr.exe:MSN Messenger 7.5
"{DD7CC3B1-6DB2-4E37-A7FB-8CE12608FBAF}"= UDP:C:Program FilesMSN Messengermsnmsgr.exe:MSN Messenger 7.5
"{BB7C7B22-7EE9-40AF-B287-A4551E2BD8AB}"= TCP:C:Program FilesMSN Messengermsnmsgr.exe:MSN Messenger 7.5
"{3472E1C0-CA2D-481C-9F1B-4FF1D7DEFEBE}"= UDP:C:Program FilesMSN Messengermsnmsgr.exe:MSN Messenger 7.5
"{09852B05-3F91-4592-9E00-D76DE108DB2D}"= TCP:C:Program FilesMSN Messengermsnmsgr.exe:MSN Messenger 7.5
"{D2D500EA-3FCA-4DBC-9AF0-6E23D070B927}"= C:Program FilesWindows LiveMessengerlivecall.exe:Windows Live Messenger (Phone)
[HKLM~servicessharedaccessparametersfirewallpolicyPublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfileAuthorizedApplicationsList]
"C:\Program Files\Orange\Connectivity\ConnectivityManager.exe"= C:Program FilesOrangeConnectivityConnectivityManager.exe:*:enabled:CSS
R1 aswSP;avast! Self Protection;C:Windowssystem32driversaswSP.sys [2008-11-11 17:16:28 110160]
R2 aswFsBlk;aswFsBlk;C:Windowssystem32DRIVERSaswFsBlk.sys [2008-11-11 17:16:28 20560]
R2 aswMonFlt;aswMonFlt;C:Windowssystem32DRIVERSaswMonFlt.sys [2008-11-11 17:16:12 51792]
R2 ConfigFree Service;ConfigFree Service;"C:Program FilesTOSHIBAConfigFreeCFSvcs.exe" [2007-12-25 13:07:14 40960]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;"C:Program FilesTOSHIBASMARTLogServiceTosIPCSrv.exe" [2007-12-03 16:03:52 126976]
R3 atikmdag;atikmdag;C:Windowssystem32DRIVERSatikmdag.sys [2008-02-18 15:36:35 3483648]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;C:Windowssystem32driversCHDART.sys [2008-02-18 14:57:36 187904]
R3 O2MDRDR;O2MDRDR;C:Windowssystem32DRIVERSo2media.sys [2008-01-15 10:34:58 48472]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:Windowssystem32DriversPCASp50.sys [2008-10-29 19:49:12 27072]
R3 QIOMem;Generic IO & Memory Access;C:Windowssystem32DRIVERSQIOMem.sys [2007-04-09 16:13:00 8192]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:Windowssystem32DriversPCAMp50.sys [2008-10-29 19:49:12 28224]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:Windowssystem32driverserrdev.sys [2008-01-21 04:13:20 6656]
S4 MegaSR;MegaSR;C:Windowssystem32driversmegasr.sys [2008-01-21 04:10:19 386616]
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-10-30 C:WindowsTasksAppleSoftwareUpdate.job
- C:Program FilesApple Software UpdateSoftwareUpdate.exe [2006-08-29 14:21]
2008-02-26 C:WindowsTasksMcDefragTask.job
- c:PROGRA~1mcafeemqcQcConsol.exe [2007-12-04 13:32]
2008-02-26 C:WindowsTasksMcQcTask.job
- c:PROGRA~1mcafeemqcQcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-ITSecMng - C:Program FilesTOSHIBABluetooth Toshiba StackItSecMng.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-16 23:19:34
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
TOSCDSPD = C:Program FilesTOSHIBATOSCDSPDTOSCDSPD.exe?/i??????G?u????P???x????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:WindowsExplorer.exe
-> C:Program FilesIDMDesktop SMSoehook.dll
.
Heure de fin: 2008-11-16 23:20:58
ComboFix-quarantined-files.txt 2008-11-16 22:20:30
Avant-CF: 29 061 332 992 octets libres
Après-CF: 29,062,098,944 octets libres
260 --- E O F --- 2008-11-14 02:04:22
Le rapport virustotal C:Program FilesNokiaNokia PC Suite 7PcSync2.exe.
Fichier PcSync2.exe reçu le 2008.08.24 11:35:03 (CET)Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.8.21.0 2008.08.22 -
AntiVir 7.8.1.23 2008.08.23 -
Authentium 5.1.0.4 2008.08.24 -
Avast 4.8.1195.0 2008.08.23 -
AVG 8.0.0.161 2008.08.23 -
BitDefender 7.2 2008.08.24 -
CAT-QuickHeal 9.50 2008.08.22 -
ClamAV 0.93.1 2008.08.24 -
DrWeb 4.44.0.09170 2008.08.24 -
eSafe 7.0.17.0 2008.08.21 -
eTrust-Vet 31.6.6044 2008.08.23 -
Ewido 4.0 2008.08.23 -
F-Prot 4.4.4.56 2008.08.24 -
F-Secure 7.60.13501.0 2008.08.24 -
Fortinet 3.14.0.0 2008.08.24 -
GData 2.0.7306.1023 2008.08.20 -
Ikarus T3.1.1.34.0 2008.08.24 -
K7AntiVirus 7.10.427 2008.08.23 -
Kaspersky 7.0.0.125 2008.08.24 -
McAfee 5368 2008.08.22 -
Microsoft 1.3807 2008.08.24 -
NOD32v2 3382 2008.08.23 -
Norman 5.80.02 2008.08.22 -
Panda 9.0.0.4 2008.08.23 -
PCTools 4.4.2.0 2008.08.23 -
Prevx1 V2 2008.08.24 -
Rising 20.58.52.00 2008.08.24 -
Sophos 4.32.0 2008.08.24 -
Sunbelt 3.1.1575.1 2008.08.23 -
Symantec 10 2008.08.24 -
TheHacker 6.3.0.6.060 2008.08.23 -
TrendMicro 8.700.0.1004 2008.08.23 -
VBA32 3.12.8.4 2008.08.23 -
ViRobot 2008.8.22.1346 2008.08.22 -
VirusBuster 4.5.11.0 2008.08.23 -
Webwasher-Gateway 6.6.2 2008.08.24 -
Information additionnelle
File size: 1249280 bytes
MD5...: 457c3dd5f4655eb0f1a564110319b9d0
SHA1..: 20b51e6007c1c2a3634c8d4ff08a4fb332eaabcd
SHA256: e80b8bdc1b7110754654e9458322a07f69c866d3a3dee9f13411a26ee4742d5d
SHA512: 2afb028053cb80d66725f438cb4e999d794b4f6f7af47c69c88d774565843834<BR>c3cc3338a344041b29b4c0dc9b9618055439f8695a122453b5a176c71f8f2bee
PEiD..: -
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x4e0f3a<BR>timedatestamp.....: 0x4857d191 (Tue Jun 17 15:00:33 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0xef495 0xf0000 6.07 316d74a7f5b09ea0b5653801ba90185f<BR>.rdata 0xf1000 0x3ae66 0x3b000 4.21 c67754711c573e5b55355c1b4959a60a<BR>.data 0x12c000 0x31c8 0x1000 0.82 108513314efaee8225df6679502cee48<BR>.rsrc 0x130000 0x3ff0 0x4000 5.49 faf47894d43ae17b4c79797efd155745<BR><BR>( 16 imports ) <BR>> NGSCM.DLL: __0CNBitmapUtil@@QAE@XZ, __0CCSDWrapper@@QAE@XZ, __0CCSDWrapperListener@@QAE@XZ, __1CCSDWrapper@@UAE@XZ, _Initialize@CCSDWrapper@@QAEJPAUHWND__@@@Z, _SetSupportedDevices@CCSDWrapper@@QAEXPBG@Z, _SetSelectionMode@CCSDWrapper@@QAEXK@Z, _AddListener@CCSDWrapper@@QAEXPAVCCSDWrapperListener@@@Z, _GetResourceInstance@CNbuuLib@@SAPAUHINSTANCE__@@XZ, _NGSCM_LoadString@@YAHIPAGH@Z, __0CNbuuGraphics@@QAE@PAUHDC__@@@Z, _DrawImage@CNbuuGraphics@@QAEXPAVCNbuuBitmap@@HH@Z, __1CNbuuGraphics@@UAE@XZ, __0CRTLHelper@@QAE@PBG@Z, _FlipDialog@CRTLHelper@@QAEPAUDLGTEMPLATE@@PAUHINSTANCE__@@I@Z, __1CRTLHelper@@UAE@XZ, __1CNbuuBitmap@@UAE@XZ, _NGSCM_GetCommonNLR@@YAPAUHINSTANCE__@@XZ, __0CNbuuBitmap@@QAE@XZ, _LoadFromRes@CNbuuBitmap@@QAEXPAUHINSTANCE__@@I@Z, __0CNbuuSplashScreen@@QAE@PAUHINSTANCE__@@I@Z, _Show@CNbuuSplashScreen@@QAEHI@Z, _Hide@CNbuuSplashScreen@@QAEHI@Z, __1CNbuuSplashScreen@@UAE@XZ, _PcsInitializeWER@@YAHXZ, __0CNbuuTabSkin@@QAE@XZ, __0CNbuuTabCtrl@@QAE@XZ, __0CNbuuStepBarCtrl@@QAE@XZ, __1CNbuuTabSkin@@UAE@XZ, __1CNbuuTabCtrl@@UAE@XZ, __1CNbuuStepBarCtrl@@UAE@XZ, _TranslateMenuAccelerator@CNbuuWindowBackgroundCtrl@@QAEHPAUtagMSG@@@Z, __1CNbuuStaticCtrl@@UAE@XZ, __1CNbuuComboBoxCtrl@@UAE@XZ, __1CNbuuCheckButtonCtrl@@UAE@XZ, __1CNbuuCommonButtonCtrl@@UAE@XZ, _GetMenuHandle@CNbuuWindowBackgroundCtrl@@QAEPAUHMENU__@@XZ, __1CNbuuStaticBitmapSkin@@UAE@XZ, __0CNbuuStaticBitmapSkin@@QAE@XZ, _Load@CNbuuStaticBitmapSkin@@UAEXXZ, _Unload@CNbuuStaticBitmapSkin@@UAEXXZ, _IsValid@_$CNbuuBaseSkinImpl@VCNbuuStaticBitmapSkin@@VCNbuuStaticBitmapSkinDef@@@@UAE_NXZ, _Draw@CNbuuStaticBitmapSkin@@UAEXPAVCNbuuWindow@@PAVCNbuuGraphics@@HH@Z, _Validate@CNbuuStaticBitmapSkin@@UAEXXZ, _SetSkinDef@_$CNbuuBaseSkinImpl@VCNbuuStaticBitmapSkin@@VCNbuuStaticBitmapSkinDef@@@@UAEXVCNbuuStaticBitmapSkinDef@@@Z, __0CNbuuCheckButtonCtrl@@QAE@XZ, __0CNbuuStaticCtrl@@QAE@XZ, _SetTextColor@CNbuuStaticCtrl@@QAEXK@Z, __0CNbuuCommonButtonCtrl@@QAE@XZ, _SetTooltip@_$CNbuuButtonImpl@VCNbuuCommonButtonSkin@@@@QAEXPAG@Z, _NGSCM_GetCommonNGR@@YAPAUHINSTANCE__@@XZ, _SetResourceInstance@CNbuuLib@@SAXPAUHINSTANCE__@@@Z, _Init@CNbuuLib@@SAXPAUHINSTANCE__@@0@Z, _SetLayout@CNbuuLib@@SAKK@Z, _PcsLoadFont@@YAXPAUtagLOGFONTW@@@Z, __0CNbuuWindowBackgroundSkin@@QAE@XZ, __0CNbuuWindowBackgroundCtrl@@QAE@XZ, __1CNbuuWindowBackgroundSkin@@UAE@XZ, __1CNbuuWindowBackgroundCtrl@@UAE@XZ, __0CNbuuComboBoxCtrl@@QAE@XZ, _CreateBackBuffer@CNbuuBackBuffer@@UAEXHHPAVCNbuuGraphics@@@Z, _RemoveListener@CCSDWrapper@@QAEXPAVCCSDWrapperListener@@@Z, _Terminate@CCSDWrapper@@QAEXXZ, _SelectDevice@CCSDWrapper@@QAEJKH@Z, _SelectDevice@CCSDWrapper@@QAEJH@Z, _GetSupportedDeviceCount@CCSDWrapper@@QAEHXZ, __1CPNGAnimation@@UAE@XZ, __0CPNGAnimation@@QAE@XZ, __1CPCSL2InfoReader@@QAE@XZ, _Show@CNbuuCommonMessageBox@@SAHPAUHWND__@@PBG1I@Z, _ReadPCSL@CPCSL2InfoReader@@QAEHPAG@Z, __0CPCSL2InfoReader@@QAE@XZ, _GetUIManufacturer@CPCSL2InfoReader@@QAEPBGXZ, _PCSL_GetVariantID@CPCSL2InfoReader@@QAEGXZ, _GetNextPhoneManufacturer@CPCSL2InfoReader@@QAEPBGXZ, __1CNBitmapUtil@@QAE@XZ, _GetNumberOfPhoneManufacturers@CPCSL2InfoReader@@QAEHXZ, _GetFirstPhoneManufacturer@CPCSL2InfoReader@@QAEPBGXZ, _DrawParentBackBuffer@CNbuuBackBuffer@@UAEXPAUHDC__@@UtagRECT@@@Z, _DrawBackBufferPart@CNbuuBackBuffer@@UAEXPAUHDC__@@UtagRECT@@11@Z, _DrawBackBuffer@CNbuuBackBuffer@@UAEXPAUHDC__@@UtagRECT@@1@Z, _DeleteBackBuffer@CNbuuBackBuffer@@UAEXXZ<BR>> VERSION.dll: GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW<BR>> ConnAPI.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> PSAPI.DLL: EnumProcessModules, GetModuleFileNameExW<BR>> gdiplus.dll: GdiplusStartup, GdiplusShutdown<BR>> MFC71U.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> MSVCR71.dll: _wmakepath, wcslen, _time64, _localtime64, strcpy, strlen, iswascii, iswpunct, iswspace, towupper, wcsftime, wcscmp, _wsetlocale, strtoul, wcscat, _CxxThrowException, free, _wcsdup, _wtoi, wcstok, wcsstr, floor, wcsncpy, strncpy, swprintf, memcmp, fabs, wcsncat, strncat, sprintf, wcschr, _wtol, localtime, gmtime, time, _tzset, _mktime64, _gmtime64, _c_exit, _exit, _XcptFilter, _cexit, exit, _wcmdln, _amsg_exit, __wgetmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, __1type_info@@UAE@XZ, __dllonexit, _onexit, _terminate@@YAXXZ, __security_error_handler, _controlfp, wcscpy, _except_handler3, wcstol, ceil, wcstoul, _wsplitpath, _purecall, div, memcpy, __CxxFrameHandler, memset<BR>> KERNEL32.dll: FileTimeToLocalFileTime, FileTimeToSystemTime, GetTimeZoneInformation, FindResourceExW, CreateMutexW, CreateFileMappingW, QueryPerformanceCounter, UnmapViewOfFile, GetEnvironmentVariableW, SetEnvironmentVariableW, GetCurrentDirectoryW, SetCurrentDirectoryW, GetFullPathNameW, lstrcpyW, CopyFileW, SystemTimeToFileTime, CompareFileTime, GetModuleHandleW, DeleteFileW, MoveFileW, MultiByteToWideChar, LocalFileTimeToFileTime, GetTickCount, OpenEventW, CreateEventW, ExpandEnvironmentStringsW, LoadLibraryExW, GetModuleFileNameW, GetProcAddress, Sleep, LoadLibraryW, FindResourceW, LoadResource, LockResource, SizeofResource, FreeResource, FreeLibrary, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, LCMapStringW, GetLongPathNameW, LoadLibraryA, WaitForSingleObject, ExitThread, CreateEventA, OpenEventA, CreateThread, GetModuleHandleA, GetStartupInfoW, WideCharToMultiByte, ExitProcess, GetVersionExA, MapViewOfFile, GetVersionExW, InitializeCriticalSection, SetEvent, ResetEvent, WaitForMultipleObjects, CreateToolhelp32Snapshot, Process32FirstW, GetACP, GetLastError, CreateDirectoryW, GetPrivateProfileStringW, Process32NextW, CloseHandle, OpenProcess<BR>> USER32.dll: GetActiveWindow, IsWindowEnabled, GetSubMenu, InsertMenuW, LoadMenuW, SendMessageCallbackW, GetWindowInfo, GetDoubleClickTime, CheckMenuItem, GetMenuDefaultItem, PostQuitMessage, IsWindow, GetFocus, DialogBoxIndirectParamW, GetPropW, SetPropW, OffsetRect, DrawTextW, EndDialog, SetWindowPos, SetClassLongW, GetClassLongW, GetMonitorInfoW, MonitorFromRect, GetSysColor, ClientToScreen, InflateRect, GetClientRect, GetDC, SetActiveWindow, SetCapture, ReleaseCapture, wsprintfW, MsgWaitForMultipleObjects, GetWindowTextW, MessageBoxW, wvsprintfW, GetDesktopWindow, MoveWindow, GetParent, ScreenToClient, TranslateMessage, DispatchMessageW, SendMessageW, GetClassNameW, GetWindowThreadProcessId, PostMessageW, EnumWindows, KillTimer, GetWindowRect, SetTimer, EnableWindow, EnumChildWindows, LockWindowUpdate, MapWindowPoints, GetDlgItem, IsWindowVisible, GetSystemMetrics, RegisterWindowMessageW, FindWindowW, SystemParametersInfoW, PtInRect, LoadCursorW, SetCursor, IsZoomed, IsIconic, GetMenuItemID, GetMenuItemCount, SetMenuDefaultItem, EnableMenuItem, ReleaseDC, GetWindowLongW, SetWindowTextW, GetWindowTextLengthW, SetFocus, PeekMessageW, GetCursorPos, WinHelpW, LoadStringW, DestroyIcon, GetNextDlgTabItem, MessageBeep, ShowWindow, SetForegroundWindow, GetMenuState, LoadIconW, InvalidateRect<BR>> GDI32.dll: GetObjectW, GetTextExtentPoint32W, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, SetTextColor, SetBkMode, SelectObject, DeleteObject, GetStockObject, CreateFontIndirectW, Ellipse<BR>> ADVAPI32.dll: RegCreateKeyExW, RegCloseKey, RegQueryValueExW, RegEnumKeyW, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExW, RegOpenKeyExW, RegSetValueExW, RegDeleteValueW, RegDeleteKeyW<BR>> SHELL32.dll: SHGetDesktopFolder, Shell_NotifyIconW, SHBrowseForFolderW, SHGetPathFromIDListW, SHGetSpecialFolderPathW, ShellExecuteW, SHGetFolderPathW, SHGetMalloc, SHGetFolderLocation<BR>> COMCTL32.dll: ImageList_ReplaceIcon<BR>> SHLWAPI.dll: StrRetToBufW, PathIsNetworkPathW<BR>> ole32.dll: CoGetInterfaceAndReleaseStream, CoUninitialize, OleUninitialize, CLSIDFromString, CoMarshalInterThreadInterfaceInStream, CoTaskMemFree, StringFromCLSID, CreateStreamOnHGlobal, CoCreateInstance, CoInitialize, OleInitialize<BR>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR><BR>( 0 exports ) <BR>
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.8.21.0 2008.08.22 -
AntiVir 7.8.1.23 2008.08.23 -
Authentium 5.1.0.4 2008.08.24 -
Avast 4.8.1195.0 2008.08.23 -
AVG 8.0.0.161 2008.08.23 -
BitDefender 7.2 2008.08.24 -
CAT-QuickHeal 9.50 2008.08.22 -
ClamAV 0.93.1 2008.08.24 -
DrWeb 4.44.0.09170 2008.08.24 -
eSafe 7.0.17.0 2008.08.21 -
eTrust-Vet 31.6.6044 2008.08.23 -
Ewido 4.0 2008.08.23 -
F-Prot 4.4.4.56 2008.08.24 -
F-Secure 7.60.13501.0 2008.08.24 -
Fortinet 3.14.0.0 2008.08.24 -
GData 2.0.7306.1023 2008.08.20 -
Ikarus T3.1.1.34.0 2008.08.24 -
K7AntiVirus 7.10.427 2008.08.23 -
Kaspersky 7.0.0.125 2008.08.24 -
McAfee 5368 2008.08.22 -
Microsoft 1.3807 2008.08.24 -
NOD32v2 3382 2008.08.23 -
Norman 5.80.02 2008.08.22 -
Panda 9.0.0.4 2008.08.23 -
PCTools 4.4.2.0 2008.08.23 -
Prevx1 V2 2008.08.24 -
Rising 20.58.52.00 2008.08.24 -
Sophos 4.32.0 2008.08.24 -
Sunbelt 3.1.1575.1 2008.08.23 -
Symantec 10 2008.08.24 -
TheHacker 6.3.0.6.060 2008.08.23 -
TrendMicro 8.700.0.1004 2008.08.23 -
VBA32 3.12.8.4 2008.08.23 -
ViRobot 2008.8.22.1346 2008.08.22 -
VirusBuster 4.5.11.0 2008.08.23 -
Webwasher-Gateway 6.6.2 2008.08.24 -
Information additionnelle
File size: 1249280 bytes
MD5...: 457c3dd5f4655eb0f1a564110319b9d0
SHA1..: 20b51e6007c1c2a3634c8d4ff08a4fb332eaabcd
SHA256: e80b8bdc1b7110754654e9458322a07f69c866d3a3dee9f13411a26ee4742d5d
SHA512: 2afb028053cb80d66725f438cb4e999d794b4f6f7af47c69c88d774565843834<BR>c3cc3338a344041b29b4c0dc9b9618055439f8695a122453b5a176c71f8f2bee
PEiD..: -
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x4e0f3a<BR>timedatestamp.....: 0x4857d191 (Tue Jun 17 15:00:33 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0xef495 0xf0000 6.07 316d74a7f5b09ea0b5653801ba90185f<BR>.rdata 0xf1000 0x3ae66 0x3b000 4.21 c67754711c573e5b55355c1b4959a60a<BR>.data 0x12c000 0x31c8 0x1000 0.82 108513314efaee8225df6679502cee48<BR>.rsrc 0x130000 0x3ff0 0x4000 5.49 faf47894d43ae17b4c79797efd155745<BR><BR>( 16 imports ) <BR>> NGSCM.DLL: __0CNBitmapUtil@@QAE@XZ, __0CCSDWrapper@@QAE@XZ, __0CCSDWrapperListener@@QAE@XZ, __1CCSDWrapper@@UAE@XZ, _Initialize@CCSDWrapper@@QAEJPAUHWND__@@@Z, _SetSupportedDevices@CCSDWrapper@@QAEXPBG@Z, _SetSelectionMode@CCSDWrapper@@QAEXK@Z, _AddListener@CCSDWrapper@@QAEXPAVCCSDWrapperListener@@@Z, _GetResourceInstance@CNbuuLib@@SAPAUHINSTANCE__@@XZ, _NGSCM_LoadString@@YAHIPAGH@Z, __0CNbuuGraphics@@QAE@PAUHDC__@@@Z, _DrawImage@CNbuuGraphics@@QAEXPAVCNbuuBitmap@@HH@Z, __1CNbuuGraphics@@UAE@XZ, __0CRTLHelper@@QAE@PBG@Z, _FlipDialog@CRTLHelper@@QAEPAUDLGTEMPLATE@@PAUHINSTANCE__@@I@Z, __1CRTLHelper@@UAE@XZ, __1CNbuuBitmap@@UAE@XZ, _NGSCM_GetCommonNLR@@YAPAUHINSTANCE__@@XZ, __0CNbuuBitmap@@QAE@XZ, _LoadFromRes@CNbuuBitmap@@QAEXPAUHINSTANCE__@@I@Z, __0CNbuuSplashScreen@@QAE@PAUHINSTANCE__@@I@Z, _Show@CNbuuSplashScreen@@QAEHI@Z, _Hide@CNbuuSplashScreen@@QAEHI@Z, __1CNbuuSplashScreen@@UAE@XZ, _PcsInitializeWER@@YAHXZ, __0CNbuuTabSkin@@QAE@XZ, __0CNbuuTabCtrl@@QAE@XZ, __0CNbuuStepBarCtrl@@QAE@XZ, __1CNbuuTabSkin@@UAE@XZ, __1CNbuuTabCtrl@@UAE@XZ, __1CNbuuStepBarCtrl@@UAE@XZ, _TranslateMenuAccelerator@CNbuuWindowBackgroundCtrl@@QAEHPAUtagMSG@@@Z, __1CNbuuStaticCtrl@@UAE@XZ, __1CNbuuComboBoxCtrl@@UAE@XZ, __1CNbuuCheckButtonCtrl@@UAE@XZ, __1CNbuuCommonButtonCtrl@@UAE@XZ, _GetMenuHandle@CNbuuWindowBackgroundCtrl@@QAEPAUHMENU__@@XZ, __1CNbuuStaticBitmapSkin@@UAE@XZ, __0CNbuuStaticBitmapSkin@@QAE@XZ, _Load@CNbuuStaticBitmapSkin@@UAEXXZ, _Unload@CNbuuStaticBitmapSkin@@UAEXXZ, _IsValid@_$CNbuuBaseSkinImpl@VCNbuuStaticBitmapSkin@@VCNbuuStaticBitmapSkinDef@@@@UAE_NXZ, _Draw@CNbuuStaticBitmapSkin@@UAEXPAVCNbuuWindow@@PAVCNbuuGraphics@@HH@Z, _Validate@CNbuuStaticBitmapSkin@@UAEXXZ, _SetSkinDef@_$CNbuuBaseSkinImpl@VCNbuuStaticBitmapSkin@@VCNbuuStaticBitmapSkinDef@@@@UAEXVCNbuuStaticBitmapSkinDef@@@Z, __0CNbuuCheckButtonCtrl@@QAE@XZ, __0CNbuuStaticCtrl@@QAE@XZ, _SetTextColor@CNbuuStaticCtrl@@QAEXK@Z, __0CNbuuCommonButtonCtrl@@QAE@XZ, _SetTooltip@_$CNbuuButtonImpl@VCNbuuCommonButtonSkin@@@@QAEXPAG@Z, _NGSCM_GetCommonNGR@@YAPAUHINSTANCE__@@XZ, _SetResourceInstance@CNbuuLib@@SAXPAUHINSTANCE__@@@Z, _Init@CNbuuLib@@SAXPAUHINSTANCE__@@0@Z, _SetLayout@CNbuuLib@@SAKK@Z, _PcsLoadFont@@YAXPAUtagLOGFONTW@@@Z, __0CNbuuWindowBackgroundSkin@@QAE@XZ, __0CNbuuWindowBackgroundCtrl@@QAE@XZ, __1CNbuuWindowBackgroundSkin@@UAE@XZ, __1CNbuuWindowBackgroundCtrl@@UAE@XZ, __0CNbuuComboBoxCtrl@@QAE@XZ, _CreateBackBuffer@CNbuuBackBuffer@@UAEXHHPAVCNbuuGraphics@@@Z, _RemoveListener@CCSDWrapper@@QAEXPAVCCSDWrapperListener@@@Z, _Terminate@CCSDWrapper@@QAEXXZ, _SelectDevice@CCSDWrapper@@QAEJKH@Z, _SelectDevice@CCSDWrapper@@QAEJH@Z, _GetSupportedDeviceCount@CCSDWrapper@@QAEHXZ, __1CPNGAnimation@@UAE@XZ, __0CPNGAnimation@@QAE@XZ, __1CPCSL2InfoReader@@QAE@XZ, _Show@CNbuuCommonMessageBox@@SAHPAUHWND__@@PBG1I@Z, _ReadPCSL@CPCSL2InfoReader@@QAEHPAG@Z, __0CPCSL2InfoReader@@QAE@XZ, _GetUIManufacturer@CPCSL2InfoReader@@QAEPBGXZ, _PCSL_GetVariantID@CPCSL2InfoReader@@QAEGXZ, _GetNextPhoneManufacturer@CPCSL2InfoReader@@QAEPBGXZ, __1CNBitmapUtil@@QAE@XZ, _GetNumberOfPhoneManufacturers@CPCSL2InfoReader@@QAEHXZ, _GetFirstPhoneManufacturer@CPCSL2InfoReader@@QAEPBGXZ, _DrawParentBackBuffer@CNbuuBackBuffer@@UAEXPAUHDC__@@UtagRECT@@@Z, _DrawBackBufferPart@CNbuuBackBuffer@@UAEXPAUHDC__@@UtagRECT@@11@Z, _DrawBackBuffer@CNbuuBackBuffer@@UAEXPAUHDC__@@UtagRECT@@1@Z, _DeleteBackBuffer@CNbuuBackBuffer@@UAEXXZ<BR>> VERSION.dll: GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW<BR>> ConnAPI.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> PSAPI.DLL: EnumProcessModules, GetModuleFileNameExW<BR>> gdiplus.dll: GdiplusStartup, GdiplusShutdown<BR>> MFC71U.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> MSVCR71.dll: _wmakepath, wcslen, _time64, _localtime64, strcpy, strlen, iswascii, iswpunct, iswspace, towupper, wcsftime, wcscmp, _wsetlocale, strtoul, wcscat, _CxxThrowException, free, _wcsdup, _wtoi, wcstok, wcsstr, floor, wcsncpy, strncpy, swprintf, memcmp, fabs, wcsncat, strncat, sprintf, wcschr, _wtol, localtime, gmtime, time, _tzset, _mktime64, _gmtime64, _c_exit, _exit, _XcptFilter, _cexit, exit, _wcmdln, _amsg_exit, __wgetmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, __1type_info@@UAE@XZ, __dllonexit, _onexit, _terminate@@YAXXZ, __security_error_handler, _controlfp, wcscpy, _except_handler3, wcstol, ceil, wcstoul, _wsplitpath, _purecall, div, memcpy, __CxxFrameHandler, memset<BR>> KERNEL32.dll: FileTimeToLocalFileTime, FileTimeToSystemTime, GetTimeZoneInformation, FindResourceExW, CreateMutexW, CreateFileMappingW, QueryPerformanceCounter, UnmapViewOfFile, GetEnvironmentVariableW, SetEnvironmentVariableW, GetCurrentDirectoryW, SetCurrentDirectoryW, GetFullPathNameW, lstrcpyW, CopyFileW, SystemTimeToFileTime, CompareFileTime, GetModuleHandleW, DeleteFileW, MoveFileW, MultiByteToWideChar, LocalFileTimeToFileTime, GetTickCount, OpenEventW, CreateEventW, ExpandEnvironmentStringsW, LoadLibraryExW, GetModuleFileNameW, GetProcAddress, Sleep, LoadLibraryW, FindResourceW, LoadResource, LockResource, SizeofResource, FreeResource, FreeLibrary, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, LCMapStringW, GetLongPathNameW, LoadLibraryA, WaitForSingleObject, ExitThread, CreateEventA, OpenEventA, CreateThread, GetModuleHandleA, GetStartupInfoW, WideCharToMultiByte, ExitProcess, GetVersionExA, MapViewOfFile, GetVersionExW, InitializeCriticalSection, SetEvent, ResetEvent, WaitForMultipleObjects, CreateToolhelp32Snapshot, Process32FirstW, GetACP, GetLastError, CreateDirectoryW, GetPrivateProfileStringW, Process32NextW, CloseHandle, OpenProcess<BR>> USER32.dll: GetActiveWindow, IsWindowEnabled, GetSubMenu, InsertMenuW, LoadMenuW, SendMessageCallbackW, GetWindowInfo, GetDoubleClickTime, CheckMenuItem, GetMenuDefaultItem, PostQuitMessage, IsWindow, GetFocus, DialogBoxIndirectParamW, GetPropW, SetPropW, OffsetRect, DrawTextW, EndDialog, SetWindowPos, SetClassLongW, GetClassLongW, GetMonitorInfoW, MonitorFromRect, GetSysColor, ClientToScreen, InflateRect, GetClientRect, GetDC, SetActiveWindow, SetCapture, ReleaseCapture, wsprintfW, MsgWaitForMultipleObjects, GetWindowTextW, MessageBoxW, wvsprintfW, GetDesktopWindow, MoveWindow, GetParent, ScreenToClient, TranslateMessage, DispatchMessageW, SendMessageW, GetClassNameW, GetWindowThreadProcessId, PostMessageW, EnumWindows, KillTimer, GetWindowRect, SetTimer, EnableWindow, EnumChildWindows, LockWindowUpdate, MapWindowPoints, GetDlgItem, IsWindowVisible, GetSystemMetrics, RegisterWindowMessageW, FindWindowW, SystemParametersInfoW, PtInRect, LoadCursorW, SetCursor, IsZoomed, IsIconic, GetMenuItemID, GetMenuItemCount, SetMenuDefaultItem, EnableMenuItem, ReleaseDC, GetWindowLongW, SetWindowTextW, GetWindowTextLengthW, SetFocus, PeekMessageW, GetCursorPos, WinHelpW, LoadStringW, DestroyIcon, GetNextDlgTabItem, MessageBeep, ShowWindow, SetForegroundWindow, GetMenuState, LoadIconW, InvalidateRect<BR>> GDI32.dll: GetObjectW, GetTextExtentPoint32W, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, SetTextColor, SetBkMode, SelectObject, DeleteObject, GetStockObject, CreateFontIndirectW, Ellipse<BR>> ADVAPI32.dll: RegCreateKeyExW, RegCloseKey, RegQueryValueExW, RegEnumKeyW, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyExW, RegOpenKeyExW, RegSetValueExW, RegDeleteValueW, RegDeleteKeyW<BR>> SHELL32.dll: SHGetDesktopFolder, Shell_NotifyIconW, SHBrowseForFolderW, SHGetPathFromIDListW, SHGetSpecialFolderPathW, ShellExecuteW, SHGetFolderPathW, SHGetMalloc, SHGetFolderLocation<BR>> COMCTL32.dll: ImageList_ReplaceIcon<BR>> SHLWAPI.dll: StrRetToBufW, PathIsNetworkPathW<BR>> ole32.dll: CoGetInterfaceAndReleaseStream, CoUninitialize, OleUninitialize, CLSIDFromString, CoMarshalInterThreadInterfaceInStream, CoTaskMemFree, StringFromCLSID, CreateStreamOnHGlobal, CoCreateInstance, CoInitialize, OleInitialize<BR>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR><BR>( 0 exports ) <BR>
[quote]Fichier PCSuite.exe reçu le 2008.11.12 23:38:55 (CET)Antivirus Version Dernière mise à jour Résultat
SHA512: 87c5b201f8dd2746ca318a7232c1a52328c7482207fc127d5e2ae33178dab98a<BR>d71619641aa988a5ea1c903d3a8d289297621661690863123f54c2c367ce874c
TrID..: File type identification<BR>Win32 Executable MS Visual C++ (generic) (65.2%)<BR>Win32 Executable Generic (14.7%)<BR>Win32 Dynamic Link Library (generic) (13.1%)<BR>Generic Win/DOS Executable (3.4%)<BR>DOS Executable Generic (3.4%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x4a8e51<BR>timedatestamp.....: 0x48e44763 (Thu Oct 02 04:00:35 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0xc2b8a 0xc2c00 6.08 1842debe8e07b56beb13391f8908949b<BR>.rdata 0xc4000 0x4aeee 0x4b000 5.76 78842f672d250988599ba0b073024fba<BR>.data 0x10f000 0x2a88 0x2200 4.65 b4a17948e6cdad6e8146e9f2fa513fcc<BR>.rsrc 0x112000 0x246c 0x2600 4.86 5bcf2963552a8dbab9771bc29d4fb676<BR><BR>( 17 imports ) <BR>> QtCore4.dll: _contains@QString@@QBE_AVQBool@@ABV1@W4CaseSensitivity@Qt@@@Z, _separator@QDir@@SA_AVQChar@@XZ, _fromLocalFile@QUrl@@SA_AV1@ABVQString@@@Z, __0QUrl@@QAE@ABV0@@Z, _append@QString@@QAEAAV1@VQChar@@@Z, _endsWith@QString@@QBE_NABVQChar@@W4CaseSensitivity@Qt@@@Z, _retrieveData@QMimeData@@MBE_AVQVariant@@ABVQString@@W4Type@2@@Z, _formats@QMimeData@@UBE_AVQStringList@@XZ, _hasFormat@QMimeData@@UBE_NABVQString@@@Z, _setUrls@QMimeData@@QAEXABV_$QList@VQUrl@@@@@Z, __1QMimeData@@UAE@XZ, __0QMimeData@@QAE@XZ, _qt_metacall@QMimeData@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QMimeData@@UAEPAXPBD@Z, _metaObject@QMimeData@@UBEPBUQMetaObject@@XZ, _link@QFile@@SA_NABVQString@@0@Z, _remove@QFile@@SA_NABVQString@@@Z, _exists@QFile@@SA_NABVQString@@@Z, _manhattanLength@QPoint@@QBEHXZ, __YQString@@QAEAAV0@PBD@Z, _property@QObject@@QBE_AVQVariant@@PBD@Z, _contains@QRect@@QBE_NABVQPoint@@_N@Z, _compare@QString@@QBEHABV1@@Z, _release@QSemaphore@@QAEXH@Z, _acquire@QSemaphore@@QAEXH@Z, __0QSemaphore@@QAE@H@Z, _currentDate@QDate@@SA_AV1@XZ, __1QDateTime@@QAE@XZ, __0QDateTime@@QAE@ABVQDate@@ABVQTime@@W4TimeSpec@Qt@@@Z, _number@QString@@SA_AV1@HH@Z, _fromString@QTime@@SA_AV1@ABVQString@@0@Z, _toString@QTime@@QBE_AVQString@@ABV2@@Z, _minute@QTime@@QBEHXZ, _hour@QTime@@QBEHXZ, _shared_null@QHashData@@2U1@A, _addMonths@QDate@@QBE_AV1@H@Z, _addDays@QDate@@QBE_AV1@H@Z, _weekNumber@QDate@@QBEHPAH@Z, _daysInMonth@QDate@@QBEHXZ, _dayOfWeek@QDate@@QBEHXZ, _day@QDate@@QBEHXZ, _month@QDate@@QBEHXZ, _year@QDate@@QBEHXZ, __0QDate@@QAE@HHH@Z, _nextNode@QHashData@@SAPAUNode@1@PAU21@@Z, _destroyAndFree@QHashData@@QAEXXZ, _detach_helper@QHashData@@QAEPAU1@P6AXPAUNode@1@PAX@ZH@Z, _freeNode@QHashData@@QAEXPAX@Z, _allocateNode@QHashData@@QAEPAXXZ, _mightGrow@QHashData@@QAEXXZ, _QStringList_filter@QtPrivate@@YA_AVQStringList@@PBV2@ABVQString@@W4CaseSensitivity@Qt@@@Z, _currentDateTime@QDateTime@@SA_AV1@XZ, __MQDateTime@@QBE_NABV0@@Z, _time@QDateTime@@QBE_AVQTime@@XZ, _date@QDateTime@@QBE_AVQDate@@XZ, _secsTo@QTime@@QBEHABV1@@Z, _addSecs@QTime@@QBE_AV1@H@Z, __0QVariant@@QAE@_N@Z, _toUTC@QDateTime@@QBE_AV1@XZ, _split@QString@@QBE_AVQStringList@@ABVQRegExp@@W4SplitBehavior@1@@Z, _startsWith@QString@@QBE_NABV1@W4CaseSensitivity@Qt@@@Z, _toBool@QVariant@@QBE_NXZ, _endInsertRows@QAbstractItemModel@@IAEXXZ, _beginInsertRows@QAbstractItemModel@@IAEXABVQModelIndex@@HH@Z, _installEventFilter@QObject@@QAEXPAV1@@Z, _erase@QListData@@QAEPAPAXPAPAX@Z, _startsWith@QString@@QBE_NABVQChar@@W4CaseSensitivity@Qt@@@Z, __0QVariant@@QAE@ABV0@@Z, _section@QString@@QBE_AV1@VQChar@@HHV_$QFlags@W4SectionFlag@QString@@@@@Z, _mid@QString@@QBE_AV1@HH@Z, _indexOf@QString@@QBEHVQChar@@HW4CaseSensitivity@Qt@@@Z, _currentTime@QTime@@SA_AV1@XZ, _toStdWString@QString@@QBE_AV_$basic_string@GU_$char_traits@G@std@@V_$allocator@G@2@@std@@XZ, _toUpper@QChar@@QBE_AV1@XZ, _replace@QString@@QAEAAV1@HHVQChar@@@Z, _event@QSettings@@MAE_NPAVQEvent@@@Z, _qt_metacall@QSettings@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QSettings@@UAEPAXPBD@Z, _metaObject@QSettings@@UBEPBUQMetaObject@@XZ, _cap@QRegExp@@QAE_AVQString@@H@Z, _indexIn@QRegExp@@QBEHABVQString@@HW4CaretMode@1@@Z, _arg@QString@@QBE_AV1@ABV1@00@Z, _arg@QString@@QBE_AV1@ABV1@0@Z, _arg@QString@@QBE_AV1@HHHABVQChar@@@Z, _headerData@QAbstractItemModel@@UBE_AVQVariant@@HW4Orientation@Qt@@H@Z, _hasChildren@QAbstractListModel@@EBE_NABVQModelIndex@@@Z, _columnCount@QAbstractListModel@@EBEHABVQModelIndex@@@Z, _parent@QAbstractListModel@@EBE_AVQModelIndex@@ABV2@@Z, _dropMimeData@QAbstractListModel@@UAE_NPBVQMimeData@@W4DropAction@Qt@@HHABVQModelIndex@@@Z, _index@QAbstractListModel@@UBE_AVQModelIndex@@HHABV2@@Z, __1QAbstractListModel@@UAE@XZ, __0QAbstractListModel@@QAE@PAVQObject@@@Z, _arg@QString@@QBE_AV1@NHDHABVQChar@@@Z, _toDouble@QVariant@@QBENPA_N@Z, __0QVariant@@QAE@N@Z, __8QVariant@@QBE_NABV0@@Z, _clear@QString@@QAEXXZ, _right@QString@@QBE_AV1@H@Z, __0QString@@QAE@VQChar@@@Z, _sleep@QThread@@KAXK@Z, _isRunning@QThread@@QBE_NXZ, _writeData@QProcess@@MAE_JPBD_J@Z, _readData@QProcess@@MAE_JPAD_J@Z, _setupChildProcess@QProcess@@MAEXXZ, _atEnd@QProcess@@UBE_NXZ, _close@QProcess@@UAEXXZ, _canReadLine@QProcess@@UBE_NXZ, _isSequential@QProcess@@UBE_NXZ, _bytesToWrite@QProcess@@UBE_JXZ, _bytesAvailable@QProcess@@UBE_JXZ, _waitForBytesWritten@QProcess@@UAE_NH@Z, _waitForReadyRead@QProcess@@UAE_NH@Z, _start@QProcess@@QAEXABVQString@@ABVQStringList@@V_$QFlags@W4OpenModeFlag@QIODevice@@@@@Z, _qt_metacall@QProcess@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QProcess@@UAEPAXPBD@Z, _metaObject@QProcess@@UBEPBUQMetaObject@@XZ, _qMemSet@@YAPAXPAXHI@Z, _exists@QDir@@QBE_NABVQString@@@Z, _mkpath@QDir@@QBE_NABVQString@@@Z, _qRealloc@@YAPAXPAXI@Z, _readLineData@QIODevice@@MAE_JPAD_J@Z, _reset@QIODevice@@UAE_NXZ, _seek@QIODevice@@UAE_N_J@Z, _size@QIODevice@@UBE_JXZ, _pos@QIODevice@@UBE_JXZ, _open@QIODevice@@UAE_NV_$QFlags@W4OpenModeFlag@QIODevice@@@@@Z, _qMalloc@@YAPAXI@Z, __0QTime@@QAE@HHHH@Z, _shared_null@QVectorData@@2U1@A, _qHash@@YAIABVQString@@@Z, _grow@QVectorData@@SAHHHH_N@Z, _malloc@QVectorData@@SAPAU1@HHHPAU1@@Z, _toString@QDateTime@@QBE_AVQString@@ABV2@@Z, _indexOf@QString@@QBEHABVQRegExp@@H@Z, _toLocalTime@QDateTime@@QBE_AV1@XZ, _insert@QString@@QAEAAV1@HABV1@@Z, _count@QString@@QBEHABV1@W4CaseSensitivity@Qt@@@Z, __1QObject@@UAE@XZ, __0QObject@@QAE@PAV0@@Z, _node_delete@QMapData@@QAEXQAPAUNode@1@HPAU21@@Z, _entryInfoList@QDir@@QBE_AV_$QList@VQFileInfo@@@@V_$QFlags@W4Filter@QDir@@@@V_$QFlags@W4SortFlag@QDir@@@@@Z, __0QByteArray@@QAE@PBDH@Z, _number@QString@@SA_AV1@KH@Z, _fromUtf16@QString@@SA_AV1@PBGH@Z, _size@QFile@@UBE_JXZ, __0QFileInfo@@QAE@ABV0@@Z, __1QMutexLocker@@QAE@XZ, __0QMutexLocker@@QAE@PAVQMutex@@@Z, __1QByteArray@@QAE@XZ, _quit@QThread@@QAEXXZ, _append@QListData@@QAEPAPAXABU1@@Z, _convertSeparators@QDir@@SA_AVQString@@ABV2@@Z, _toString@QUrl@@QBE_AVQString@@V_$QFlags@W4FormattingOption@QUrl@@@@@Z, _toLocalFile@QUrl@@QBE_AVQString@@XZ, _arg@QString@@QBE_AV1@_JHHABVQChar@@@Z, _urls@QMimeData@@QBE_AV_$QList@VQUrl@@@@XZ, _resolve@QLibrary@@QAEPAXPBD@Z, __1QLibrary@@UAE@XZ, __0QLibrary@@QAE@ABVQString@@PAVQObject@@@Z, _arg@QString@@QBE_AV1@IHHABVQChar@@@Z, __1QSemaphore@@QAE@XZ, _append@_$QVector@VQPoint@@@@QAEXABVQPoint@@@Z, __1_$QVector@VQPoint@@@@QAE@XZ, __0_$QVector@VQPoint@@@@QAE@XZ, _terminate@QThread@@QAEXXZ, _isFinished@QThread@@QBE_NXZ, _elapsed@QTime@@QBEHXZ, _start@QTime@@QAEXXZ, _wakeOne@QWaitCondition@@QAEXXZ, _wait@QWaitCondition@@QAE_NPAVQMutex@@K@Z, __1QWaitCondition@@QAE@XZ, __0QWaitCondition@@QAE@XZ, _msleep@QThread@@KAXK@Z, _fromNativeSeparators@QDir@@SA_AVQString@@ABV2@@Z, _absolutePath@QFileInfo@@QBE_AVQString@@XZ, _baseName@QFileInfo@@QBE_AVQString@@XZ, _QStringList_contains@QtPrivate@@YA_AVQBool@@PBVQStringList@@ABVQString@@W4CaseSensitivity@Qt@@@Z, _fromStdWString@QString@@SA_AV1@ABV_$basic_string@GU_$char_traits@G@std@@V_$allocator@G@2@@std@@@Z, _toAscii@QString@@QBE_AVQByteArray@@XZ, _remove@QFile@@QAE_NXZ, _setFileName@QFile@@QAEXABVQString@@@Z, __0QFile@@QAE@XZ, _write@QIODevice@@QAE_JABVQByteArray@@@Z, _qt_metacall@QThread@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QThread@@UAEPAXPBD@Z, _metaObject@QThread@@UBEPBUQMetaObject@@XZ, _dirName@QDir@@QBE_AVQString@@XZ, _home@QDir@@SA_AV1@XZ, _applicationDirPath@QCoreApplication@@SA_AVQString@@XZ, _completeBaseName@QFileInfo@@QBE_AVQString@@XZ, _load@QTranslator@@QAE_NABVQString@@000@Z, _isEmpty@QTranslator@@UBE_NXZ, _translate@QTranslator@@UBE_AVQString@@PBD00@Z, __1QTranslator@@UAE@XZ, __0QTranslator@@QAE@PAVQObject@@@Z, _exists@QDir@@QBE_NXZ, _waitForBytesWritten@QIODevice@@UAE_NH@Z, _waitForReadyRead@QIODevice@@UAE_NH@Z, _canReadLine@QIODevice@@UBE_NXZ, _bytesToWrite@QIODevice@@UBE_JXZ, _bytesAvailable@QIODevice@@UBE_JXZ, _toDouble@QString@@QBENPA_N@Z, _readLineData@QFile@@MAE_JPAD_J@Z, _writeData@QFile@@MAE_JPBD_J@Z, _readData@QFile@@MAE_JPAD_J@Z, _fileEngine@QFile@@UBEPAVQAbstractFileEngine@@XZ, _atEnd@QFile@@UBE_NXZ, _seek@QFile@@UAE_N_J@Z, _pos@QFile@@UBE_JXZ, _close@QFile@@UAEXXZ, _open@QFile@@UAE_NV_$QFlags@W4OpenModeFlag@QIODevice@@@@@Z, _isSequential@QFile@@UBE_NXZ, _fileName@QFile@@QBE_AVQString@@XZ, _qt_metacall@QFile@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QFile@@UAEPAXPBD@Z, _metaObject@QFile@@UBEPBUQMetaObject@@XZ, _absolutePath@QDir@@QBE_AVQString@@XZ, __0QByteArray@@QAE@PBD@Z, _close@QBuffer@@UAEXXZ, _open@QBuffer@@UAE_NV_$QFlags@W4OpenModeFlag@QIODevice@@@@@Z, __1QBuffer@@UAE@XZ, __0QBuffer@@QAE@PAVQObject@@@Z, _size@QFileInfo@@QBE_JXZ, _isDir@QFileInfo@@QBE_NXZ, _suffix@QFileInfo@@QBE_AVQString@@XZ, _setFileName@QLibrary@@QAEXABVQString@@@Z, _isLoaded@QLibrary@@QBE_NXZ, _load@QLibrary@@QAE_NXZ, __0QLibrary@@QAE@PAVQObject@@@Z, _setData@QBuffer@@QAEXPBDH@Z, _temp@QDir@@SA_AV1@XZ, _data@QByteArray@@QAEPADXZ, __1QTextStream@@UAE@XZ, __0QTextStream@@QAE@PAVQIODevice@@@Z, _data@QModelIndex@@QBE_AVQVariant@@H@Z, _addYears@QDate@@QBE_AV1@H@Z, _available@QSemaphore@@QBEHXZ, _exit@QThread@@QAEXH@Z, _exitCode@QProcess@@QBEHXZ, _waitForFinished@QProcess@@QAE_NH@Z, _waitForStarted@QProcess@@QAE_NH@Z, _activate@QMetaObject@@SAXPAVQObject@@PBU1@HPAPAX@Z, _staticMetaObject@QThread@@2UQMetaObject@@B, _qt_metacall@QAbstractItemModel@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QAbstractItemModel@@UAEPAXPBD@Z, _staticMetaObject@QAbstractItemModel@@2UQMetaObject@@B, _qt_metacall@QObject@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QObject@@UAEPAXPBD@Z, _activate@QMetaObject@@SAXPAVQObject@@PBU1@HHPAPAX@Z, _qt_metacall@QTranslator@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QTranslator@@UAEPAXPBD@Z, _staticMetaObject@QTranslator@@2UQMetaObject@@B, _qt_metacall@QAbstractListModel@@UAEHW4Call@QMetaObject@@HPAPAX@Z, _qt_metacast@QAbstractListModel@@UAEPAXPBD@Z, _staticMetaObject@QAbstractListModel@@2UQMetaObject@@B, _qUnregisterResourceData@@YA_NHPBE00@Z, _qRegisterResourceData@@YA_NHPBE00@Z, _append@QListData@@QAEPAPAXXZ, _detach2@QListData@@QAEPAUData@1@XZ, _tempPath@QDir@@SA_AVQString@@XZ, __1QUrl@@QAE@XZ, __0QUrl@@QAE@ABVQString@@@Z, __MQString@@QBE_NABV0@@Z, __8QString@@QBE_NABV0@@Z, _createData@QMapData@@SAPAU1@XZ, _continueFreeData@QMapData@@QAEXH@Z, _node_create@QMapData@@QAEPAUNode@1@QAPAU21@H@Z, _start@QThread@@QAEXW4Priority@1@@Z, _setInterval@QTimer@@QAEXH@Z, _start@QTimer@@QAEXXZ, __0QChar@@QAE@UQLatin1Char@@@Z, __4QString@@QAEAAV0@PBD@Z, _prepend@QString@@QAEAAV1@PBD@Z, _append@QString@@QAEAAV1@PBD@Z, __9QString@@QBE_NPBD@Z, _toWCharArray@QString@@QBEHPAG@Z, _replace@QString@@QAEAAV1@HHABV1@@Z, _remove@QString@@QAEAAV1@HH@Z, _remove@QString@@QAEAAV1@ABV1@W4CaseSensitivity@Qt@@@Z, _lastIndexOf@QString@@QBEHABV1@HW4CaseSensitivity@Qt@@@Z, _indexOf@QString@@QBEHABV1@HW4CaseSensitivity@Qt@@@Z, _exists@QFile@@QBE_NXZ, __1QFile@@UAE@XZ, __0QFile@@QAE@ABVQString@@@Z, _shared_null@QMapData@@2U1@A, _childGroups@QSettings@@QBE_AVQStringList@@XZ, _allKeys@QSettings@@QBE_AVQStringList@@XZ, _toInt@QVariant@@QBEHPA_N@Z, _parent@QModelIndex@@QBE_AV1@XZ, __0QVariant@@QAE@XZ, __0QVariant@@QAE@ABVQString@@@Z, __0QVariant@@QAE@PBD@Z, __0QSettings@@QAE@PAVQObject@@@Z, _setValue@QSettings@@QAEXABVQString@@ABVQVariant@@@Z, _value@QSettings@@QBE_AVQVariant@@ABVQString@@ABV2@@Z, _self@QCoreApplication@@0PAV1@A, _qFree@@YAXPAX@Z, _connectSlotsByName@QMetaObject@@SAXPAVQObject@@@Z, _arg@QString@@QBE_AV1@ABV1@HABVQChar@@@Z, _trimmed@QString@@QBE_AV1@XZ, _append@QString@@QAEAAV1@ABV1@@Z, _split@QString@@QBE_AVQStringList@@ABV1@W4SplitBehavior@1@W4CaseSensitivity@Qt@@@Z, _fromUtf8@QString@@SA_AV1@PBDH@Z, __1QModelIndex@@QAE@XZ, _cast@QMetaObject@@QBEPAVQObject@@PAV2@@Z, _reset@QAbstractItemModel@@IAEXXZ, _revert@QAbstractItemModel@@UAEXXZ, _submit@QAbstractItemModel@@UAE_NXZ, _dataChanged@QAbstractItemModel@@IAEXABVQModelIndex@@0@Z, _span@QAbstractItemModel@@UBE_AVQSize@@ABVQModelIndex@@@Z, _match@QAbstractItemModel@@UBE_AV_$QList@VQModelIndex@@@@ABVQModelIndex@@HABVQVariant@@HV_$QFlags@W4MatchFlag@Qt@@@@@Z, _buddy@QAbstractItemModel@@UBE_AVQModelIndex@@ABV2@@Z, _sort@QAbstractItemModel@@UAEXHW4SortOrder@Qt@@@Z, _flags@QAbstractItemModel@@UBE_AV_$QFlags@W4ItemFlag@Qt@@@@ABVQModelIndex@@@Z, _canFetchMore@QAbstractItemModel@@UBE_NABVQModelIndex@@@Z, _fetchMore@QAbstractItemModel@@UAEXABVQModelIndex@@@Z, _removeColumns@QAbstractItemModel@@UAE_NHHABVQModelIndex@@@Z, _removeRows@QAbstractItemModel@@UAE_NHHABVQModelIndex@@@Z, _insertColumns@QAbstractItemModel@@UAE_NHHABVQModelIndex@@@Z, _insertRows@QAbstractItemModel@@UAE_NHHABVQModelIndex@@@Z, _supportedDropActions@QAbstractItemModel@@UBE_AV_$QFlags@W4DropAction@Qt@@@@XZ, _dropMimeData@QAbstractItemModel@@UAE_NPBVQMimeData@@W4DropAction@Qt@@HHABVQModelIndex@@@Z, _mimeData@QAbstractItemModel@@UBEPAVQMimeData@@ABV_$QList@VQModelIndex@@@@@Z, _mimeTypes@QAbstractItemModel@@UBE_AVQStringList@@XZ, _setItemData@QAbstractItemModel@@UAE_NABVQModelIndex@@ABV_$QMap@HVQVariant@@@@@Z, _itemData@QAbstractItemModel@@UBE_AV_$QMap@HVQVariant@@@@ABVQModelIndex@@@Z, _setHeaderData@QAbstractItemModel@@UAE_NHW4Orientation@Qt@@ABVQVariant@@H@Z, _setData@QAbstractItemModel@@UAE_NABVQModelIndex@@ABVQVariant@@H@Z, _hasChildren@QAbstractItemModel@@UBE_NABVQModelIndex@@@Z, __1QAbstractItemModel@@UAE@XZ, __0QAbstractItemModel@@QAE@PAVQObject@@@Z, _registerType@QMetaType@@SAHPBDP6AXPAX@ZP6APAXPBX@Z@Z, _wait@QThread@@QAE_NK@Z, __1QThread@@UAE@XZ, __0QThread@@QAE@PAVQObject@@@Z, _remove@QListData@@QAEXH@Z, _digitValue@QChar@@QBEHXZ, _WindowsVersion@QSysInfo@@2W4WinVersion@1@B, _entryList@QDir@@QBE_AVQStringList@@V_$QFlags@W4Filter@QDir@@@@V_$QFlags@W4SortFlag@QDir@@@@@Z, _setNameFilters@QDir@@QAEXABVQStringList@@@Z, __1QDir@@QAE@XZ, __0QDir@@QAE@ABVQString@@@Z, _processEvents@QCoreApplication@@SAXV_$QFlags@W4ProcessEventsFlag@QEventLoop@@@@@Z, _compare@QString@@QBEHABV1@W4CaseSensitivity@Qt@@@Z, _left@QString@@QBE_AV1@H@Z, _staticMetaObject@QObject@@2UQMetaObject@@B, _isFile@QFileInfo@@QBE_NXZ, _fileName@QFileInfo@@QBE_AVQString@@XZ, _absoluteFilePath@QFileInfo@@QBE_AVQString@@XZ, _exists@QFileInfo@@QBE_NXZ, __1QFileInfo@@QAE@XZ, __0QFileInfo@@QAE@ABVQString@@@Z, __0QFileInfo@@QAE@ABVQDir@@ABVQString@@@Z, _unlock@QMutex@@QAEXXZ, _lock@QMutex@@QAEXXZ, __1QMutex@@QAE@XZ, __0QMutex@@QAE@W4RecursionMode@0@@Z, _shared_null@QString@@0UData@1@A, _exactMatch@QRegExp@@QBE_NABVQString@@@Z, __1QRegExp@@QAE@XZ, __0QRegExp@@QAE@ABVQString@@W4CaseSensitivity@Qt@@W4PatternSyntax@0@@Z, __0QVariant@@QAE@ABVQSize@@@Z, _createIndex@QAbstractItemModel@@IBE_AVQModelIndex@@HHH@Z, _createIndex@QAbstractItemModel@@IBE_AVQModelIndex@@HHPAX@Z, _applicationFilePath@QCoreApplication@@SA_AVQString@@XZ, _translate@QCoreApplication@@SA_AVQString@@PBD00W4Encoding@1@@Z, _shared_null@QListData@@2UData@1@A, _toNativeSeparators@QDir@@SA_AVQString@@ABV2@@Z, _objectName@QObject@@QBE_AVQString@@XZ, _setObjectName@QObject@@QAEXABVQString@@@Z, _disconnect@QObject@@SA_NPBV1@PBD01@Z, _setProperty@QObject@@QAE_NPBDABVQVariant@@@Z, __YQString@@QAEAAV0@ABV0@@Z, __0QString@@QAE@PBD@Z, __0QString@@QAE@ABV0@@Z, __0QString@@QAE@XZ, __1QString@@QAE@XZ, __8QString@@QBE_NPBD@Z, __0QVariant@@QAE@H@Z, __1QVariant@@QAE@XZ, _toString@QVariant@@QBE_AVQString@@XZ, __0QSettings@@QAE@ABVQString@@W4Format@0@PAVQObject@@@Z, __1QSettings@@UAE@XZ, _remove@QSettings@@QAEXABVQString@@@Z, _contains@QSettings@@QBE_NABVQString@@@Z, _tr@QMetaObject@@QBE_AVQString@@PBD0@Z, __4QString@@QAEAAV0@ABV0@@Z, _chop@QString@@QAEXH@Z, _lastIndexOf@QString@@QBEHVQChar@@HW4CaseSensitivity@Qt@@@Z, _endsWith@QString@@QBE_NABV1@W4CaseSensitivity@Qt@@@Z, _toLower@QString@@QBE_AV1@XZ, _replace@QString@@QAEAAV1@ABV1@0W4CaseSensitivity@Qt@@@Z, _utf16@QString@@QBEPBGXZ, _fromAscii@QString@@SA_AV1@PBDH@Z, _fromWCharArray@QString@@SA_AV1@PBGH@Z, _toInt@QString@@QBEHPA_NH@Z, _setOrganizationName@QCoreApplication@@SAXABVQString@@@Z, _setApplicationName@QCoreApplication@@SAXABVQString@@@Z, _installTranslator@QCoreApplication@@SAXPAVQTranslator@@@Z, _winEventFilter@QCoreApplication@@UAE_NPAUtagMSG@@PAJ@Z, _quit@QCoreApplication@@SAXXZ, __0QChar@@QAE@D@Z, __0QProcess@@QAE@PAVQObject@@@Z, __1QProcess@@UAE@XZ, _startDetached@QProcess@@SA_NABVQString@@@Z, _event@QObject@@UAE_NPAVQEvent@@@Z, _eventFilter@QObject@@UAE_NPAV1@PAVQEvent@@@Z, _connect@QObject@@SA_NPBV1@PBD01W4ConnectionType@Qt@@@Z, _timerEvent@QObject@@MAEXPAVQTimerEvent@@@Z, _childEvent@QObject@@MAEXPAVQChildEvent@@@Z, _qWinMain@@YAXPAUHINSTANCE__@@0PADHAAHAAV_$QVector@PAD@@@Z, __4QByteArray@@QAEAAV0@PBD@Z, __4QByteArray@@QAEAAV0@ABV0@@Z, _toLocal8Bit@QString@@QBE_AVQByteArray@@XZ, __0QByteArray@@QAE@XZ, _customEvent@QObject@@MAEXPAVQEvent@@@Z, _connectNotify@QObject@@MAEXPBD@Z, _disconnectNotify@QObject@@MAEXPBD@Z, _metaObject@QTimer@@UBEPBUQMetaObject@@XZ, _qt_metacast@QTimer@@UAEPAXPBD@Z, _qt_metacall@QTimer@@UAEHW4Call@QMetaObject@@HPAPAX@Z, __0QTimer@@QAE@PAVQObject@@@Z, __1QTimer@@UAE@XZ, _start@QTimer@@QAEXH@Z, _stop@QTimer@@QAEXXZ, _timerEvent@QTimer@@MAEXPAVQTimerEvent@@@Z, _qFatal@@YAXPBDZZ, _startDetached@QProcess@@SA_NABVQString@@ABVQStringList@@@Z<BR>> QtGui4.dll: _windowTitle@QWidget@@QBE_AVQString@@XZ, _setWindowTitle@QWidget@@QAEXABVQString@@@Z, _setMaximumWidth@QWidget@@QAEXH@Z, _setMinimumWidth@QWidget@@QAEXH@Z, _setMinimumSize@QWidget@@QAEXHH@Z, _style@QWidge