Toujours lent... surtout sur la lecture de média même sur le web et lorsque je joue à certains jeux qui ne sont pas si exigeants...
Voici le rapport Combo fix.
Je suis en vacance cette semaine, je vais peut-être faire un format malgré que ça ne me tente pas vraiment...
ComboFix 08-03-10.1 - Eric Trudel 2008-03-17 19:06:22.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.2566 [GMT -4:00]
Endroit: C:\Documents and Settings\Eric Trudel\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-17 to 2008-03-17 ))))))))))))))))))))))))))))))))))))
.
2008-03-13 13:26 . 2008-03-13 13:26 172 --a------ C:\curr_ver.tmp
2008-03-12 21:32 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-12 21:30 . 2008-03-12 21:32 <REP> d-------- C:\Program Files\Java
2008-03-12 21:30 . 2008-03-12 21:30 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-03-12 17:35 . 2008-03-17 19:13 2,050,080 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-12 17:35 . 2008-03-17 08:44 25,808 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-12 17:29 . 2008-03-12 17:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-12 17:29 . 2008-03-12 17:31 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-12 17:28 . 2007-12-13 19:27 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-03-12 17:28 . 2007-12-13 19:27 54,672 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2008-03-12 17:28 . 2007-12-13 19:27 42,384 --a------ C:\WINDOWS\zllsputility_loc040c.dll
2008-03-12 17:28 . 2007-12-13 19:27 21,904 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
2008-03-12 17:28 . 2007-12-13 19:27 17,808 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
2008-03-12 17:28 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-03-12 17:27 . 2008-03-12 17:27 <REP> d-------- C:\Program Files\Zone Labs
2008-03-12 17:26 . 2008-03-17 18:44 <REP> d-------- C:\WINDOWS\Internet Logs
2008-03-10 23:27 . 2008-03-10 23:27 <REP> d-------- C:\_OTMoveIt
2008-03-10 17:23 . 2008-03-10 17:23 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-03-10 17:21 . 2008-03-10 17:21 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-03-10 17:21 . 2008-03-10 17:21 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-03-10 17:21 . 2008-03-10 17:21 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-03-10 17:18 . 2008-03-10 17:18 <REP> d-------- C:\icom
2008-03-10 15:30 . 2008-03-10 15:30 <REP> d-------- C:\WINDOWS\system32\AGEIA
2008-03-10 15:30 . 2008-03-10 17:09 <REP> d-------- C:\Program Files\AGEIA Technologies
2008-03-10 15:27 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-03-10 15:27 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-03-10 15:27 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2008-03-10 15:27 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2008-03-10 15:27 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2008-03-10 15:27 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2008-03-10 15:27 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-03-10 15:27 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll
2008-03-09 00:19 . 2008-03-10 17:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-09 00:19 . 2008-03-09 00:19 <REP> d-------- C:\Documents and Settings\Eric Trudel\Application Data\Malwarebytes
2008-03-09 00:19 . 2008-03-09 00:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-07 21:19 . 2008-03-07 21:19 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-07 18:44 . 2008-03-10 17:22 <REP> d-------- C:\Backups
2008-03-07 18:43 . 2008-03-16 06:35 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-07 15:27 . 2008-03-10 17:11 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-03-07 15:27 . 2008-03-10 17:11 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-03-07 15:27 . 2006-01-17 09:41 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\toshiba
2008-03-07 15:27 . 2006-10-16 04:52 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intel
2008-03-07 15:24 . 2008-03-16 07:13 <REP> d-------- C:\SDFix
2008-03-04 18:53 . 2008-03-10 17:17 <REP> d-------- C:\Program Files\TalkPCR
2008-03-04 18:52 . 1998-02-06 22:37 299,520 --a------ C:\WINDOWS\uninst.exe
2008-03-04 16:19 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-04 16:19 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-04 16:19 . 2007-07-30 20:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-04 13:20 . 2008-03-10 17:17 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-04 13:16 . 2008-03-04 13:15 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-04 13:16 . 2008-03-04 13:16 2,550 --a------ C:\WINDOWS\unins000.dat
2008-03-04 13:11 . 2008-03-10 17:18 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-04 13:11 . 2008-03-10 17:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-03 22:26 . 2008-03-03 22:26 <REP> d-------- C:\Documents and Settings\Eric Trudel\Application Data\Grisoft
2008-03-03 22:25 . 2007-05-30 08:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-03 20:53 . 2008-03-03 20:53 <REP> d-------- C:\Program Files\CCleaner
2008-03-03 19:36 . 2008-03-03 19:45 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-03-03 19:35 . 2008-03-03 19:45 <REP> d-------- C:\Program Files\Windows Live
2008-03-03 19:35 . 2008-03-03 19:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-03 04:02 . 2008-03-12 01:06 <REP> d-------- C:\Program Files\PKR
2008-02-29 23:26 . 2008-02-29 23:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2008-02-23 06:46 . 2007-11-13 01:02 22,472 --a------ C:\Documents and Settings\Eric Trudel\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-10 21:22 --------- d-----w C:\Program Files\Jeux
2008-03-10 18:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-09 04:17 --------- d-----w C:\Program Files\Morpheus Ultra
2008-03-05 04:43 --------- d-----w C:\Documents and Settings\Eric Trudel\Application Data\AVG7
2008-03-04 02:26 --------- d-----w C:\Program Files\Trend Micro
2008-03-04 02:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-04 00:01 --------- d-----w C:\Program Files\Skype
2008-03-03 23:32 --------- d-----w C:\Program Files\Hewlett-Packard
2008-03-01 03:03 --------- d-----w C:\Program Files\Microsoft Games
2008-02-23 22:28 --------- d-----w C:\Documents and Settings\Eric Trudel\Application Data\U3
2008-02-14 11:24 --------- d-----w C:\Program Files\sixteen tons entertainment
2008-02-13 09:32 49,152 ----a-w C:\WINDOWS\system32\apache.dll
2008-02-03 02:34 --------- d-----w C:\Program Files\Google
2008-02-01 05:41 --------- d-----w C:\Documents and Settings\Eric Trudel\Application Data\uTorrent
2008-01-31 07:19 --------- d-----w C:\Documents and Settings\Eric Trudel\Application Data\AdobeUM
2008-01-28 20:45 --------- d-----w C:\Program Files\DAEMON Tools
2008-01-28 20:44 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-01-28 05:37 --------- d-----w C:\Documents and Settings\Eric Trudel\Application Data\DAEMON Tools
2008-01-28 05:28 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-27 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\SimCity Societies
2008-01-25 04:36 --------- d--h--r C:\Documents and Settings\Eric Trudel\Application Data\SecuROM
2008-01-25 03:05 --------- d-----w C:\Program Files\Alcohol Soft
2008-01-18 02:30 --------- d-----w C:\Program Files\Fichiers communs\DirectX
2008-01-18 02:26 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-17 02:53 --------- d-----w C:\Program Files\uTorrent
2007-01-02 03:32 47,360 ----a-w C:\Documents and Settings\Eric Trudel\Application Data\pcouffin.sys
2006-12-12 18:51 92,064 ----a-w C:\Documents and Settings\Eric Trudel\mqdmmdm.sys
2006-12-12 18:51 9,232 ----a-w C:\Documents and Settings\Eric Trudel\mqdmmdfl.sys
2006-12-12 18:51 79,328 ----a-w C:\Documents and Settings\Eric Trudel\mqdmserd.sys
2006-12-12 18:51 66,656 ----a-w C:\Documents and Settings\Eric Trudel\mqdmbus.sys
2006-12-12 18:51 6,208 ----a-w C:\Documents and Settings\Eric Trudel\mqdmcmnt.sys
2006-12-12 18:51 5,936 ----a-w C:\Documents and Settings\Eric Trudel\mqdmwhnt.sys
2006-12-12 18:51 4,048 ----a-w C:\Documents and Settings\Eric Trudel\mqdmcr.sys
2006-12-12 18:51 25,600 ----a-w C:\Documents and Settings\Eric Trudel\usbsermptxp.sys
2006-12-12 18:51 22,768 ----a-w C:\Documents and Settings\Eric Trudel\usbsermpt.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-11_ 0.14.57,64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-07 22:44:39 5,758,976 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0
/u0000001\NTUSER.DAT
+ 2008-03-16 10:36:08 5,767,168 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0
/u0000001\NTUSER.DAT
- 2008-03-07 22:44:39 45,056 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0
/u0000002\UsrClass.dat
+ 2008-03-16 10:36:08 167,936 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0
/u0000002\UsrClass.dat
+ 2008-03-05 07:36:33 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIXT\ERDNT.EXE
+ 2008-03-07 22:44:39 5,758,976 ----a-w C:\WINDOWS\ERUNT\SDFIXT\Users\[u]0
/u0000001\NTUSER.DAT
+ 2008-03-07 22:44:39 45,056 ----a-w C:\WINDOWS\ERUNT\SDFIXT\Users\[u]0
/u0000002\UsrClass.dat
- 2008-03-07 03:37:44 167,936 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2008-03-12 21:55:00 167,936 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\accicons.exe
- 2008-03-07 03:37:44 81,920 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2008-03-12 21:55:00 81,920 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2008-03-07 03:37:43 34,304 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2008-03-12 21:54:59 34,304 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2008-03-07 03:37:45 8,192 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2008-03-12 21:55:00 8,192 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-03-07 03:37:45 3,584 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2008-03-12 21:55:00 3,584 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2008-03-07 03:37:45 114,688 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2008-03-12 21:55:00 114,688 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2008-03-07 03:37:44 16,384 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2008-03-12 21:55:00 16,384 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2008-03-07 03:37:44 30,720 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\pptico.exe
+ 2008-03-12 21:55:00 30,720 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2008-03-07 03:37:45 22,528 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2008-03-12 21:55:00 22,528 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2008-03-07 03:37:43 45,056 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2008-03-12 21:54:59 45,056 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2008-03-07 03:37:43 90,112 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2008-03-12 21:54:59 90,112 ----a-r C:\WINDOWS\Installer\{9028040C-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2007-07-19 19:10:28 127,768 ----a-w C:\WINDOWS\system32\drivers\klif.sys
- 2005-06-03 07:24:06 49,248 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-02-22 05:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2005-06-03 07:24:14 49,250 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-02-22 05:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2005-06-03 08:52:56 127,078 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-02-22 06:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2007-12-13 23:26:50 796,048 ----a-w C:\WINDOWS\system32\libeay32_0.9.6l.dll
- 2008-02-04 23:09:46 18,214,008 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-03-05 16:30:54 19,148,408 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2007-12-13 23:26:56 83,432 ----a-w C:\WINDOWS\system32\vsdata.dll
+ 2007-12-13 23:27:14 394,952 ----a-w C:\WINDOWS\system32\vsdatant.sys
+ 2007-12-13 23:26:56 157,160 ----a-w C:\WINDOWS\system32\vsinit.dll
+ 2007-12-13 23:26:56 103,912 ----a-w C:\WINDOWS\system32\vsmonapi.dll
+ 2007-12-13 23:26:56 275,944 ----a-w C:\WINDOWS\system32\vspubapi.dll
+ 2007-12-13 23:26:56 71,144 ----a-w C:\WINDOWS\system32\vsregexp.dll
+ 2007-12-13 23:26:58 472,552 ----a-w C:\WINDOWS\system32\vsutil.dll
+ 2007-12-13 23:26:58 46,568 ----a-w C:\WINDOWS\system32\vswmi.dll
+ 2007-12-13 23:26:58 99,816 ----a-w C:\WINDOWS\system32\vsxml.dll
+ 2007-12-13 23:26:58 83,432 ----a-w C:\WINDOWS\system32\zlcomm.dll
+ 2007-12-13 23:26:58 71,144 ----a-w C:\WINDOWS\system32\zlcommdb.dll
+ 2007-12-13 23:26:48 370,208 ----a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-12-13 23:27:42 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\av_loc040c.dll
+ 2007-05-31 04:03:30 65,248 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\aphish.dat
+ 2006-06-30 18:47:36 21,568 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-31 04:03:16 77,824 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-31 04:03:16 110,592 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-31 04:03:16 331,776 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-31 04:03:16 38,400 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2007-07-19 19:10:32 110,360 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\w2kxp32\kl1.sys
+ 2007-07-19 19:10:32 186,128 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\w2kxp32\klif.sys
+ 2007-05-31 04:03:48 110,360 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\kl1.sys
+ 2007-07-19 19:10:28 127,768 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\klif.sys
+ 2007-05-31 04:03:50 45,056 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\regcat.exe
+ 2006-09-20 03:12:14 208,960 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\inv.dll
+ 2007-09-12 01:09:16 274,432 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2006-12-19 22:13:52 1,093,632 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-31 04:03:20 548,864 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-31 04:03:20 626,688 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll
+ 2007-05-31 04:03:18 184,320 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 04:03:22 90,112 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prremote.dll
+ 2007-09-12 01:09:16 135,168 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
+ 2006-12-19 22:13:52 200,704 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ssleay32.dll
+ 2007-12-13 23:26:48 99,816 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2007-12-13 23:27:42 17,808 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd_loc040c.dll
+ 2004-01-30 16:35:08 813,568 ----a-w C:\WINDOWS\system32\ZoneLabs\dbghelp.dll
+ 2007-12-13 23:26:50 128,480 ----a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
+ 2007-12-13 23:26:50 38,376 ----a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
+ 2007-12-13 23:26:50 321,016 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
+ 2007-12-13 23:27:44 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure_loc040c.dll
+ 2007-12-13 23:27:42 288,144 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard_loc040c.zip.dll
+ 2007-12-13 23:27:46 152,976 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\LicenseUI_loc040c.zip.dll
+ 2007-12-13 23:27:18 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
+ 2007-12-13 23:27:18 1,361,296 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
+ 2007-12-13 23:27:20 71,056 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
+ 2007-12-13 23:28:36 30,184 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2007-12-13 23:28:38 30,216 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2007-10-19 00:18:38 714,208 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
+ 2007-10-19 00:18:38 787,936 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
+ 2007-12-13 23:26:52 173,544 ----a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
+ 2007-12-13 23:27:46 17,808 ----a-w C:\WINDOWS\system32\ZoneLabs\scheduler_loc040c.dll
+ 2007-01-11 15:12:08 2,432,259 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2007-10-19 00:18:40 1,500,640 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2007-10-19 00:18:44 51,176 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
+ 2007-12-13 23:26:54 456,168 ----a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
+ 2007-12-13 23:28:38 214,528 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2007-12-13 23:28:40 3,266,040 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2007-12-13 23:27:44 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp_loc040c.dll
+ 2006-09-05 00:59:14 503,875 ----a-w C:\WINDOWS\system32\ZoneLabs\upd_core.dll
+ 2007-10-11 20:50:32 832,984 ----a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
+ 2007-12-13 23:27:10 144,936 ----a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
+ 2007-12-13 23:27:46 75,152 ----a-w C:\WINDOWS\system32\ZoneLabs\updClient_loc040c.dll
+ 2007-01-11 21:31:06 286,787 ----a-w C:\WINDOWS\system32\ZoneLabs\updtrsdk.dll
+ 2007-12-13 23:26:54 108,008 ----a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
+ 2007-12-13 23:26:56 83,432 ----a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
+ 2007-12-13 23:27:46 17,808 ----a-w C:\WINDOWS\system32\ZoneLabs\vsdb_loc040c.dll
+ 2007-12-13 23:27:10 75,304 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2007-12-13 23:27:46 46,480 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon_loc040c.dll
+ 2007-12-13 23:26:56 2,029,032 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
+ 2007-12-13 23:26:56 1,361,384 ----a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
+ 2007-12-13 23:27:46 198,032 ----a-w C:\WINDOWS\system32\ZoneLabs\vsruledb_loc040c.dll
+ 2007-12-13 23:26:58 239,080 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2007-12-13 23:27:48 17,808 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault_loc040c.dll
+ 2007-01-11 15:12:08 2,432,259 ----a-w C:\WINDOWS\system32\ZoneLabs\zlasdbup.dat
+ 2007-12-13 23:27:00 177,640 ----a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
+ 2007-12-13 23:27:00 79,344 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
+ 2007-12-13 23:27:48 17,808 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine_loc040c.dll
+ 2007-12-13 23:27:00 382,440 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2007-12-13 23:27:50 21,904 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre_loc040c.dll
+ 2007-12-13 23:27:00 120,296 ----a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
+ 2007-12-13 23:27:04 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 08:00 15360]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 17:08 65536]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-02 20:04 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 03:49 15691264 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-14 18:29 88203 C:\WINDOWS\agrsmmsg.exe]
"NDSTray.exe"="NDSTray.exe" []
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 06:20 122940]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 10:24 118784]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 13:25 73728]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 15:02 352256]
"TFncKy"="TFncKy.exe" []
"TDispVol"="TDispVol.exe" [2005-09-15 15:19 73728 C:\WINDOWS\system32\TDispVol.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 04:32 761945]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 12:37 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 11:41 602182]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-01 01:04 7557120]
"nwiz"="nwiz.exe" [2006-05-01 01:04 1519616 C:\WINDOWS\system32\nwiz.exe]
"NVRotateSysTray"="C:\WINDOWS\system32\nvsysrot.dll" [2006-05-01 01:04 49152]
"TPSMain"="TPSMain.exe" [2005-08-03 16:09 266240 C:\WINDOWS\system32\TPSMain.exe]
"CFSServ.exe"="CFSServ.exe" []
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 21:52 483328]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 12:15 579072]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 19:27 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 08:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-05 19:49 219136]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-11-09 01:10:50 25214]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2006-01-17 09:43:37 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2006-09-14 16:09 157592 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZOLL Data Retriever Service"=3 (0x3)
"ZOLL Data Relay Service"=3 (0x3)
"usnjsvc"=3 (0x3)
"gusvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Morpheus Ultra\\Morpheus.exe"=
"C:\\Program Files\\Jeux\\SWAT 4\\Content\\System\\Swat4.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Jeux\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"C:\\Program Files\\Jeux\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"C:\\Program Files\\Sling Media\\SlingPlayer\\SlingPlayer.exe"=
"C:\\Program Files\\sixteen tons entertainment\\Emergency 4\\Em4.exe"=
"C:\\Program Files\\Roger Wilco\\roger.exe"=
"C:\\Program Files\\Jeux\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Jeux\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"C:\\Program Files\\Jeux\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"C:\\Program Files\\Jeux\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Jeux\\Lost Via Domus\\Yeti_Final_Win32.exe"=
"C:\\Program Files\\Jeux\\Lost Via Domus\\gu.exe"=
"C:\\Program Files\\Jeux\\Lost Via Domus\\detection\\Launcher.exe"=
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2007-09-22 23:02]
R2 PcCGoCls;PcCGoCls.sys;C:\WINDOWS\system32\Drivers\PcCGoCls.sys [2001-11-07 13:26]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS [2004-03-23 22:12]
S3 softctrl;Software Flow Control Driver;C:\WINDOWS\system32\DRIVERS\softctrl.sys [2005-12-11 21:36]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-09-09 15:47]
S4 ZOLL Data Relay Service;ZOLL Data Relay Service;"C:\Program Files\Pinpoint Technologies, Inc\ZDR\ZOLL Data Relay Service.exe" [2007-04-23 16:02]
S4 ZOLL Data Retriever Service;ZOLL Data Retriever Service;"C:\Program Files\Pinpoint Technologies, Inc\ZDR\ZOLL Data Retriever Service.exe" [2007-04-23 16:02]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\dvdcheck.exe
\Shell\directx\command - DirectX9\dxsetup.exe
\Shell\setup\command - G:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\dvdcheck.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3b995913-dccc-11db-9099-00a0d14c2ecb}]
\Shell\AutoRun\command - semo2x.exe
\Shell\explore\Command - semo2x.exe
\Shell\open\Command - semo2x.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53c9b535-025a-11dc-90a8-00a0d14c2ecb}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-17 19:13:36
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-17 19:15:00
ComboFix2.txt 2008-03-11 04:15:43
.
2008-03-12 21:55:13 --- E O F ---