Hi Gringo and thanks for your reply.
I will stop using code boxes for now.
Regarding the attachment, I had attached it as requested in the "Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help" topic found at
http://www.bleepingcomputer.com/forums/topic34773.html . In retrospect, I have to admit that I'm not sure why I zipped it. :/ I must have thought I had been instructed to do so, but it obviously isn't the case.
Anyway, let's start with checkup.txt. Ugly, but whatever.
Results of screen317's Security Check version 0.99.42
Windows 7 x64
(UAC is disabled!) Out of date service pack!! Internet Explorer 9
``````````````Antivirus/Firewall Check:`````````````` Windows Security Center service is not running! This report may not be accurate! WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` ControlSpy
Malwarebytes Anti-Malware version 1.61.0.1400
Java 6 Update 26
Java version out of Date! Adobe Reader 9
Adobe Reader out of Date! Mozilla Firefox 12.0
Firefox out of Date! Google Chrome 19.0.1084.52
Google Chrome 19.0.1084.56
````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: =
````````````````````End of Log`````````````````````` I'll take care of these things tomorrow. Firefox could not update itself during the infection as mentioned in the original post.
Combofix had a little trouble running. 10 minutes after the NSIS part ended, nothing would show up. I fired up Process Explorer to find that its process was suspended, as if it had hit a breakpoint. I resumed it and it started scanning. Also, pev.3XE (I think) crashed during stage 4.
However, it did run, and here's the log.
ComboFix 12-06-28.03 - Carl Tessier 2012-06-28 23:31:52.1.2 - x64
Microsoft Windows 7 Édition Intégrale 6.1.7600.0.1252.2.1033.18.4091.2272 [GMT -4:00]
Lancé depuis: c:\users\Carl Tessier\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\explorer
c:\program files (x86)\explorer\AddressParser\AddressParserConfiguration.xml
c:\program files (x86)\explorer\AddressParser\parser_andorra.xml
c:\program files (x86)\explorer\AddressParser\parser_austria.xml
c:\program files (x86)\explorer\AddressParser\parser_belgium.xml
c:\program files (x86)\explorer\AddressParser\parser_canada.xml
c:\program files (x86)\explorer\AddressParser\parser_denmark.xml
c:\program files (x86)\explorer\AddressParser\parser_france.xml
c:\program files (x86)\explorer\AddressParser\parser_germany.xml
c:\program files (x86)\explorer\AddressParser\parser_ireland.xml
c:\program files (x86)\explorer\AddressParser\parser_italy.xml
c:\program files (x86)\explorer\AddressParser\parser_liechtenstein.xml
c:\program files (x86)\explorer\AddressParser\parser_luxembourg.xml
c:\program files (x86)\explorer\AddressParser\parser_monaco.xml
c:\program files (x86)\explorer\AddressParser\parser_netherlands.xml
c:\program files (x86)\explorer\AddressParser\parser_norway.xml
c:\program files (x86)\explorer\AddressParser\parser_portugal.xml
c:\program files (x86)\explorer\AddressParser\parser_spain.xml
c:\program files (x86)\explorer\AddressParser\parser_sweden.xml
c:\program files (x86)\explorer\AddressParser\parser_switzerland.xml
c:\program files (x86)\explorer\AddressParser\parser_uk.xml
c:\program files (x86)\explorer\AddressParser\parser_usa.xml
c:\program files (x86)\explorer\basemaps\basemaps.de.xml
c:\program files (x86)\explorer\basemaps\basemaps.es.xml
c:\program files (x86)\explorer\basemaps\basemaps.fr.xml
c:\program files (x86)\explorer\basemaps\basemaps.ja-jp.xml
c:\program files (x86)\explorer\basemaps\basemaps.xml
c:\program files (x86)\explorer\basemaps\basemaps.zh-CN.xml
c:\program files (x86)\explorer\basemaps\Server\basemap0.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap0.png
c:\program files (x86)\explorer\basemaps\Server\basemap1.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap1.png
c:\program files (x86)\explorer\basemaps\Server\basemap10.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap10.png
c:\program files (x86)\explorer\basemaps\Server\basemap11.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap11.png
c:\program files (x86)\explorer\basemaps\Server\basemap2.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap2.png
c:\program files (x86)\explorer\basemaps\Server\basemap3.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap3.png
c:\program files (x86)\explorer\basemaps\Server\basemap4.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap4.png
c:\program files (x86)\explorer\basemaps\Server\basemap5.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap5.png
c:\program files (x86)\explorer\basemaps\Server\basemap6.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap6.png
c:\program files (x86)\explorer\basemaps\Server\basemap7.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap7.png
c:\program files (x86)\explorer\basemaps\Server\basemap8.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap8.png
c:\program files (x86)\explorer\basemaps\Server\basemap9.nmf
c:\program files (x86)\explorer\basemaps\Server\basemap9.png
c:\program files (x86)\explorer\basemaps\Server\basemaps.de.xml
c:\program files (x86)\explorer\basemaps\Server\basemaps.es.xml
c:\program files (x86)\explorer\basemaps\Server\basemaps.fr.xml
c:\program files (x86)\explorer\basemaps\Server\basemaps.ja-jp.xml
c:\program files (x86)\explorer\basemaps\Server\basemaps.xml
c:\program files (x86)\explorer\basemaps\Server\basemaps.zh-CN.xml
c:\program files (x86)\explorer\bin\3dAnalystUtil.dll
c:\program files (x86)\explorer\bin\3DSymbols.dll
c:\program files (x86)\explorer\bin\3DSymbolsLib.dll
c:\program files (x86)\explorer\bin\AfCore.dll
c:\program files (x86)\explorer\bin\AfUtil.dll
c:\program files (x86)\explorer\bin\AGSClient.dll
c:\program files (x86)\explorer\bin\aibase.dll
c:\program files (x86)\explorer\bin\aifeat.dll
c:\program files (x86)\explorer\bin\AISClient.dll
c:\program files (x86)\explorer\bin\AISGlobalLib.dll
c:\program files (x86)\explorer\bin\aishape.dll
c:\program files (x86)\explorer\bin\Animation.dll
c:\program files (x86)\explorer\bin\AnnoLayer.dll
c:\program files (x86)\explorer\bin\Annotation.dll
c:\program files (x86)\explorer\bin\AnnotationLib.dll
c:\program files (x86)\explorer\bin\AoInitializer.dll
c:\program files (x86)\explorer\bin\AppInitializerLib.dll
c:\program files (x86)\explorer\bin\ApplicationConfigurationManager.exe
c:\program files (x86)\explorer\bin\ArcGISExplorer.ISCConfig
c:\program files (x86)\explorer\bin\atl71.dll
c:\program files (x86)\explorer\bin\BasemapLayer.dll
c:\program files (x86)\explorer\bin\BasicRasterPicture.dll
c:\program files (x86)\explorer\bin\BGLAPI.dll
c:\program files (x86)\explorer\bin\BGLAPILib.dll
c:\program files (x86)\explorer\bin\BGLFontEngine.dll
c:\program files (x86)\explorer\bin\BGLGeomChestLib.dll
c:\program files (x86)\explorer\bin\BGLGeometricEffects.dll
c:\program files (x86)\explorer\bin\BGLImageCoders.dll
c:\program files (x86)\explorer\bin\BGLRasterizerLib.dll
c:\program files (x86)\explorer\bin\BGLRasterizerSW.dll
c:\program files (x86)\explorer\bin\BGLSymbols.dll
c:\program files (x86)\explorer\bin\BGLSymbolsLib.dll
c:\program files (x86)\explorer\bin\BGLToGDIHelper.dll
c:\program files (x86)\explorer\bin\bin.zreg
c:\program files (x86)\explorer\bin\CacheRasterDB.dll
c:\program files (x86)\explorer\bin\CadastralFabric.dll
c:\program files (x86)\explorer\bin\CadastralFabricLayer.dll
c:\program files (x86)\explorer\bin\CadEngine.dll
c:\program files (x86)\explorer\bin\CadFDB.dll
c:\program files (x86)\explorer\bin\CadLayer.dll
c:\program files (x86)\explorer\bin\CadWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\Camera.dll
c:\program files (x86)\explorer\bin\CartoControlsLib.dll
c:\program files (x86)\explorer\bin\CartoConverter.dll
c:\program files (x86)\explorer\bin\CartoXLib.dll
c:\program files (x86)\explorer\bin\CIM.dll
c:\program files (x86)\explorer\bin\CIMLib.dll
c:\program files (x86)\explorer\bin\Color.dll
c:\program files (x86)\explorer\bin\ComplexSymbols.dll
c:\program files (x86)\explorer\bin\CompressedDataFile.dll
c:\program files (x86)\explorer\bin\Configuration\CATID\esri.catid.ecfg
c:\program files (x86)\explorer\bin\Configuration\CLSID\esri.clsid.ecfg
c:\program files (x86)\explorer\bin\DADFLib.dll
c:\program files (x86)\explorer\bin\DaeFile.dll
c:\program files (x86)\explorer\bin\DataConverterLib.dll
c:\program files (x86)\explorer\bin\dbghelp.dll
c:\program files (x86)\explorer\bin\de\ApplicationConfigurationManager.resources.dll
c:\program files (x86)\explorer\bin\de\DADFRes.dll
c:\program files (x86)\explorer\bin\de\ESRI.ArcGISExplorer.Application.resources.dll
c:\program files (x86)\explorer\bin\de\ESRI.ArcGISExplorer.MapCenter.resources.dll
c:\program files (x86)\explorer\bin\de\ESRI.ArcGISExplorer.resources.dll
c:\program files (x86)\explorer\bin\de\ResToolkitPro.dll
c:\program files (x86)\explorer\bin\DECoreLib.dll
c:\program files (x86)\explorer\bin\DFORRT.DLL
c:\program files (x86)\explorer\bin\Display.dll
c:\program files (x86)\explorer\bin\DisplayFeedback.dll
c:\program files (x86)\explorer\bin\DisplayGraph.dll
c:\program files (x86)\explorer\bin\DisplayLib.dll
c:\program files (x86)\explorer\bin\DistributedGeodbLib.dll
c:\program files (x86)\explorer\bin\DynamicDisplay.dll
c:\program files (x86)\explorer\bin\e3.config.xml
c:\program files (x86)\explorer\bin\E3.exe
c:\program files (x86)\explorer\bin\E3.exe.config
c:\program files (x86)\explorer\bin\E3Control.dll
c:\program files (x86)\explorer\bin\E3EmailHelper.exe
c:\program files (x86)\explorer\bin\EngineGraphics.dll
c:\program files (x86)\explorer\bin\EnginePackager.dll
c:\program files (x86)\explorer\bin\es\ApplicationConfigurationManager.resources.dll
c:\program files (x86)\explorer\bin\es\DADFRes.dll
c:\program files (x86)\explorer\bin\es\ESRI.ArcGISExplorer.Application.resources.dll
c:\program files (x86)\explorer\bin\es\ESRI.ArcGISExplorer.MapCenter.resources.dll
c:\program files (x86)\explorer\bin\es\ESRI.ArcGISExplorer.resources.dll
c:\program files (x86)\explorer\bin\es\ResToolkitPro.dll
c:\program files (x86)\explorer\bin\ESRI.ArcGIS.Utilities.Compression.dll
c:\program files (x86)\explorer\bin\ESRI.ArcGISExplorer.Application.dll
c:\program files (x86)\explorer\bin\ESRI.ArcGISExplorer.dll
c:\program files (x86)\explorer\bin\ESRI.ArcGISExplorer.MapCenter.dll
c:\program files (x86)\explorer\bin\ESRI.DADF.Core.dll
c:\program files (x86)\explorer\bin\ESRI.DADF.dll
c:\program files (x86)\explorer\bin\esrizip.exe
c:\program files (x86)\explorer\bin\Export.dll
c:\program files (x86)\explorer\bin\ExtTopoEngine.dll
c:\program files (x86)\explorer\bin\FdaCore.dll
c:\program files (x86)\explorer\bin\FdaCoreLib.dll
c:\program files (x86)\explorer\bin\FdaRel.dll
c:\program files (x86)\explorer\bin\FeatureDataConverter.dll
c:\program files (x86)\explorer\bin\FeatureDataElements.dll
c:\program files (x86)\explorer\bin\FeatureLayer.dll
c:\program files (x86)\explorer\bin\FeatureLayerLib.dll
c:\program files (x86)\explorer\bin\FgdbRasterDB.dll
c:\program files (x86)\explorer\bin\FgdbUtilLib.dll
c:\program files (x86)\explorer\bin\FileDataElements.dll
c:\program files (x86)\explorer\bin\FileDBCoreLib.dll
c:\program files (x86)\explorer\bin\FileGDB.dll
c:\program files (x86)\explorer\bin\FileGDBWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\fr\ApplicationConfigurationManager.resources.dll
c:\program files (x86)\explorer\bin\fr\DADFRes.dll
c:\program files (x86)\explorer\bin\fr\ESRI.ArcGISExplorer.Application.resources.dll
c:\program files (x86)\explorer\bin\fr\ESRI.ArcGISExplorer.MapCenter.resources.dll
c:\program files (x86)\explorer\bin\fr\ESRI.ArcGISExplorer.resources.dll
c:\program files (x86)\explorer\bin\fr\ResToolkitPro.dll
c:\program files (x86)\explorer\bin\FunctionRasterDB.dll
c:\program files (x86)\explorer\bin\gdal16.dll
c:\program files (x86)\explorer\bin\GdalRasterDB.dll
c:\program files (x86)\explorer\bin\GdbCatalog.dll
c:\program files (x86)\explorer\bin\GdbCore.dll
c:\program files (x86)\explorer\bin\GdbCoreLib.dll
c:\program files (x86)\explorer\bin\GdbNet.dll
c:\program files (x86)\explorer\bin\GdbTopo.dll
c:\program files (x86)\explorer\bin\GeoDataExtraction.dll
c:\program files (x86)\explorer\bin\GeoDataServer.dll
c:\program files (x86)\explorer\bin\GeoDataTransfer.dll
c:\program files (x86)\explorer\bin\Geometry.dll
c:\program files (x86)\explorer\bin\GeoprocessingLib.dll
c:\program files (x86)\explorer\bin\GeoProcessor.dll
c:\program files (x86)\explorer\bin\GeoRSSPlugin.dll
c:\program files (x86)\explorer\bin\glew32.dll
c:\program files (x86)\explorer\bin\Globe.dll
c:\program files (x86)\explorer\bin\GlobeCamera.dll
c:\program files (x86)\explorer\bin\GlobeClient.dll
c:\program files (x86)\explorer\bin\GlobeCoreLib.dll
c:\program files (x86)\explorer\bin\GlobeDisplay.dll
c:\program files (x86)\explorer\bin\GlobeLayers.dll
c:\program files (x86)\explorer\bin\GlobeServer.dll
c:\program files (x86)\explorer\bin\GlobeServerLayer.dll
c:\program files (x86)\explorer\bin\GlobeViewerCoreLib.dll
c:\program files (x86)\explorer\bin\GPClient.dll
c:\program files (x86)\explorer\bin\GpObjects.dll
c:\program files (x86)\explorer\bin\GpPythonCore.dll
c:\program files (x86)\explorer\bin\GPRasterFunctions.dll
c:\program files (x86)\explorer\bin\GraphicElements.dll
c:\program files (x86)\explorer\bin\hd420m.dll
c:\program files (x86)\explorer\bin\hdf5dll.dll
c:\program files (x86)\explorer\bin\hm420m.dll
c:\program files (x86)\explorer\bin\icudt40.dll
c:\program files (x86)\explorer\bin\icuin40.dll
c:\program files (x86)\explorer\bin\icuio40.dll
c:\program files (x86)\explorer\bin\icule40.dll
c:\program files (x86)\explorer\bin\icuuc40.dll
c:\program files (x86)\explorer\bin\ImageAccessLib.dll
c:\program files (x86)\explorer\bin\ImageClient.dll
c:\program files (x86)\explorer\bin\ImageServer.dll
c:\program files (x86)\explorer\bin\ImageServerLayer.dll
c:\program files (x86)\explorer\bin\IMSConnector.dll
c:\program files (x86)\explorer\bin\ImsFDB.dll
c:\program files (x86)\explorer\bin\IMSLayer.dll
c:\program files (x86)\explorer\bin\IMSLayerLib.dll
c:\program files (x86)\explorer\bin\IMSServiceLib.dll
c:\program files (x86)\explorer\bin\ImsWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\InMemoryWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\InputDevice3Dx.dll
c:\program files (x86)\explorer\bin\ja-JP\ApplicationConfigurationManager.resources.dll
c:\program files (x86)\explorer\bin\ja-JP\DADFRes.dll
c:\program files (x86)\explorer\bin\ja-JP\ESRI.ArcGISExplorer.Application.resources.dll
c:\program files (x86)\explorer\bin\ja-JP\ESRI.ArcGISExplorer.MapCenter.resources.dll
c:\program files (x86)\explorer\bin\ja-JP\ESRI.ArcGISExplorer.resources.dll
c:\program files (x86)\explorer\bin\ja-JP\ResToolkitPro.dll
c:\program files (x86)\explorer\bin\kdu61.dll
c:\program files (x86)\explorer\bin\KmlLayer.dll
c:\program files (x86)\explorer\bin\LabelPlacement.dll
c:\program files (x86)\explorer\bin\Layer.dll
c:\program files (x86)\explorer\bin\LayerLib.dll
c:\program files (x86)\explorer\bin\lcms117lib.dll
c:\program files (x86)\explorer\bin\libcollada14dom21.dll
c:\program files (x86)\explorer\bin\libcurl.dll
c:\program files (x86)\explorer\bin\lti_dsdk_dll.dll
c:\program files (x86)\explorer\bin\Map.dll
c:\program files (x86)\explorer\bin\MapClient.dll
c:\program files (x86)\explorer\bin\MapDB.dll
c:\program files (x86)\explorer\bin\MapElements.dll
c:\program files (x86)\explorer\bin\MaplexEngineLib.dll
c:\program files (x86)\explorer\bin\MapLib.dll
c:\program files (x86)\explorer\bin\MappingCore.dll
c:\program files (x86)\explorer\bin\MappingCoreLib.dll
c:\program files (x86)\explorer\bin\MappingServicesLib.dll
c:\program files (x86)\explorer\bin\MapServer.dll
c:\program files (x86)\explorer\bin\MapServerLayer.dll
c:\program files (x86)\explorer\bin\Marker3DFile.dll
c:\program files (x86)\explorer\bin\MessageSupport.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.ATL\atl90.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.ATL\Microsoft.VC90.ATL.manifest
c:\program files (x86)\explorer\bin\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest
c:\program files (x86)\explorer\bin\Microsoft.VC90.CRT\msvcm90.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.CRT\msvcp90.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.CRT\msvcr90.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFC\mfc90.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFC\mfc90u.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFC\mfcm90.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFC\mfcm90u.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFC\Microsoft.VC90.MFC.manifest
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90CHS.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90CHT.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90DEU.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90ENU.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90ESN.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90ESP.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90FRA.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90ITA.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90JPN.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\MFC90KOR.dll
c:\program files (x86)\explorer\bin\Microsoft.VC90.MFCLOC\Microsoft.VC90.MFCLOC.manifest
c:\program files (x86)\explorer\bin\Microsoft.VC90.OPENMP\Microsoft.VC90.OpenMP.manifest
c:\program files (x86)\explorer\bin\Microsoft.VC90.OPENMP\vcomp90.dll
c:\program files (x86)\explorer\bin\MosaicDB.dll
c:\program files (x86)\explorer\bin\msvcp71.dll
c:\program files (x86)\explorer\bin\msvcr71.dll
c:\program files (x86)\explorer\bin\Navigation.dll
c:\program files (x86)\explorer\bin\NetEngine80.dll
c:\program files (x86)\explorer\bin\Network.dll
c:\program files (x86)\explorer\bin\NetworkAnalystSolvers.dll
c:\program files (x86)\explorer\bin\NetworkDataset.dll
c:\program files (x86)\explorer\bin\OGCClient.dll
c:\program files (x86)\explorer\bin\OutputLib.dll
c:\program files (x86)\explorer\bin\PageLayout.dll
c:\program files (x86)\explorer\bin\pe.dll
c:\program files (x86)\explorer\bin\PlugInDataSource.dll
c:\program files (x86)\explorer\bin\PlugInWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\PrintOut.dll
c:\program files (x86)\explorer\bin\RasterAnalysisUtilLib.dll
c:\program files (x86)\explorer\bin\RasterCatalog.dll
c:\program files (x86)\explorer\bin\RasterCoreLib.dll
c:\program files (x86)\explorer\bin\RasterDB.dll
c:\program files (x86)\explorer\bin\RasterEngine.dll
c:\program files (x86)\explorer\bin\RasterFormats.dat
c:\program files (x86)\explorer\bin\RasterGraphicElements.dll
c:\program files (x86)\explorer\bin\RasterIO.dll
c:\program files (x86)\explorer\bin\RasterLayer.dll
c:\program files (x86)\explorer\bin\RasterRenderer.dll
c:\program files (x86)\explorer\bin\RasterWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\Renderers.dll
c:\program files (x86)\explorer\bin\RepresentationDB.dll
c:\program files (x86)\explorer\bin\RepresentationEffects.dll
c:\program files (x86)\explorer\bin\RepresentationLayer.dll
c:\program files (x86)\explorer\bin\RepresentationLib.dll
c:\program files (x86)\explorer\bin\RepresentationSymbols.dll
c:\program files (x86)\explorer\bin\SceneFilters.dll
c:\program files (x86)\explorer\bin\SceneGraph.dll
c:\program files (x86)\explorer\bin\sdcdbx.dll
c:\program files (x86)\explorer\bin\SDCPlugIn.dll
c:\program files (x86)\explorer\bin\sde.dll
c:\program files (x86)\explorer\bin\SdeFDB.dll
c:\program files (x86)\explorer\bin\SdeRasterDB.dll
c:\program files (x86)\explorer\bin\sdesetup.dll
c:\program files (x86)\explorer\bin\SdeWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\ServerStyleGallery.dll
c:\program files (x86)\explorer\bin\sg.dll
c:\program files (x86)\explorer\bin\ShapefileFDB.dll
c:\program files (x86)\explorer\bin\ShapefileWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\SimpleDataConverter.dll
c:\program files (x86)\explorer\bin\StyleGalleryClasses.dll
c:\program files (x86)\explorer\bin\SystemUIUtil.dll
c:\program files (x86)\explorer\bin\Terrain.dll
c:\program files (x86)\explorer\bin\TerrainLayer.dll
c:\program files (x86)\explorer\bin\TextureCookerService.exe
c:\program files (x86)\explorer\bin\TinDb.dll
c:\program files (x86)\explorer\bin\TinEngine.dll
c:\program files (x86)\explorer\bin\TinLayer.dll
c:\program files (x86)\explorer\bin\TinRenderer.dll
c:\program files (x86)\explorer\bin\TinWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\ViewerCoreLib.dll
c:\program files (x86)\explorer\bin\VpfFDB.dll
c:\program files (x86)\explorer\bin\VpfWorkspaceFactory.dll
c:\program files (x86)\explorer\bin\WebServices.dll
c:\program files (x86)\explorer\bin\WMSLayer.dll
c:\program files (x86)\explorer\bin\xerces-c_2_7.dll
c:\program files (x86)\explorer\bin\XmlSupport.dat
c:\program files (x86)\explorer\bin\XMLSupport.dll
c:\program files (x86)\explorer\bin\zh-CN\applicationconfigurationmanager.resources.dll
c:\program files (x86)\explorer\bin\zh-CN\DADFRes.dll
c:\program files (x86)\explorer\bin\zh-CN\ESRI.ArcGISExplorer.Application.resources.dll
c:\program files (x86)\explorer\bin\zh-CN\ESRI.ArcGISExplorer.MapCenter.resources.dll
c:\program files (x86)\explorer\bin\zh-CN\ESRI.ArcGISExplorer.resources.dll
c:\program files (x86)\explorer\bin\zh-CN\ResToolkitPro.dll
c:\program files (x86)\explorer\bin\zlib1.dll
c:\program files (x86)\explorer\bin\zlibwapi.dll
c:\program files (x86)\explorer\ColorProfiles\esriGray22.icc
c:\program files (x86)\explorer\ColorProfiles\Lab2Lab.icm
c:\program files (x86)\explorer\ColorProfiles\sRGB_IEC61966-2-1_noBPC.icc
c:\program files (x86)\explorer\ColorProfiles\USWebCoatedSWOP.icc
c:\program files (x86)\explorer\ColorProfiles\Xyz2Xyz.icm
c:\program files (x86)\explorer\com\com.zreg
c:\program files (x86)\explorer\com\esriE3.olb
c:\program files (x86)\explorer\license\ExplorerEnglishLicense.pdf
c:\program files (x86)\explorer\license\ExplorerFrenchLicense.pdf
c:\program files (x86)\explorer\license\ExplorerGermanLicense.pdf
c:\program files (x86)\explorer\license\ExplorerJapaneseLicense.pdf
c:\program files (x86)\explorer\license\ExplorerSimplChineseLicense.pdf
c:\program files (x86)\explorer\license\ExplorerSpanishLicense.pdf
c:\program files (x86)\explorer\PackageTemplates\ArcGISExplorer.stylesheet
c:\program files (x86)\explorer\PackageTemplates\Package931.template
c:\program files (x86)\explorer\pedata\gdaldata\coordinate_axis.csv
c:\program files (x86)\explorer\pedata\gdaldata\cubewerx_extra.wkt
c:\program files (x86)\explorer\pedata\gdaldata\ecw_cs.dat
c:\program files (x86)\explorer\pedata\gdaldata\ellipsoid.csv
c:\program files (x86)\explorer\pedata\gdaldata\epsg.wkt
c:\program files (x86)\explorer\pedata\gdaldata\esri_extra.wkt
c:\program files (x86)\explorer\pedata\gdaldata\gcs.csv
c:\program files (x86)\explorer\pedata\gdaldata\gdal_datum.csv
c:\program files (x86)\explorer\pedata\gdaldata\gdalicon.png
c:\program files (x86)\explorer\pedata\gdaldata\pcs.csv
c:\program files (x86)\explorer\pedata\gdaldata\prime_meridian.csv
c:\program files (x86)\explorer\pedata\gdaldata\projop_wparm.csv
c:\program files (x86)\explorer\pedata\gdaldata\s57attributes.csv
c:\program files (x86)\explorer\pedata\gdaldata\s57expectedinput.csv
c:\program files (x86)\explorer\pedata\gdaldata\s57objectclasses.csv
c:\program files (x86)\explorer\pedata\gdaldata\seed_2d.dgn
c:\program files (x86)\explorer\pedata\gdaldata\seed_3d.dgn
c:\program files (x86)\explorer\pedata\gdaldata\stateplane.csv
c:\program files (x86)\explorer\pedata\gdaldata\unit_of_measure.csv
c:\program files (x86)\explorer\plugins\explorerCore.ecfg
c:\program files (x86)\explorer\schemas\ExplorerAddIn.xsd
c:\program files (x86)\explorer\schemas\ExplorerGeometry.xsd
c:\program files (x86)\explorer\schemas\NmfDocument.xsd
c:\program files (x86)\explorer\Styles\default.css
c:\program files (x86)\explorer\Styles\Directions\CheckeredFlag16.png
c:\program files (x86)\explorer\Styles\Directions\GreenFlag16.png
c:\program files (x86)\explorer\Styles\Directions\Print16.png
c:\program files (x86)\explorer\Styles\ExplorerColors.de.xml
c:\program files (x86)\explorer\Styles\ExplorerColors.es.xml
c:\program files (x86)\explorer\Styles\ExplorerColors.fr.xml
c:\program files (x86)\explorer\Styles\ExplorerColors.ja-JP.xml
c:\program files (x86)\explorer\Styles\ExplorerColors.xml
c:\program files (x86)\explorer\Styles\ExplorerColors.zh-CN.xml
c:\program files (x86)\explorer\Styles\ExplorerSymbols.de.xml
c:\program files (x86)\explorer\Styles\ExplorerSymbols.es.xml
c:\program files (x86)\explorer\Styles\ExplorerSymbols.fr.xml
c:\program files (x86)\explorer\Styles\ExplorerSymbols.ja-JP.xml
c:\program files (x86)\explorer\Styles\ExplorerSymbols.xml
c:\program files (x86)\explorer\Styles\ExplorerSymbols.zh-CN.xml
c:\program files (x86)\explorer\Styles\kml.css
c:\program files (x86)\explorer\Styles\KMLIcons\american-flag.png
c:\program files (x86)\explorer\Styles\KMLIcons\arrow.png
c:\program files (x86)\explorer\Styles\KMLIcons\asian-flag.png
c:\program files (x86)\explorer\Styles\KMLIcons\auto-service.png
c:\program files (x86)\explorer\Styles\KMLIcons\auto.png
c:\program files (x86)\explorer\Styles\KMLIcons\bang.png
c:\program files (x86)\explorer\Styles\KMLIcons\bars.png
c:\program files (x86)\explorer\Styles\KMLIcons\building.png
c:\program files (x86)\explorer\Styles\KMLIcons\coffee_house_16.png
c:\program files (x86)\explorer\Styles\KMLIcons\crosshair.png
c:\program files (x86)\explorer\Styles\KMLIcons\dining.png
c:\program files (x86)\explorer\Styles\KMLIcons\dining_16.png
c:\program files (x86)\explorer\Styles\KMLIcons\dot.png
c:\program files (x86)\explorer\Styles\KMLIcons\fast-food.png
c:\program files (x86)\explorer\Styles\KMLIcons\four-dollars.png
c:\program files (x86)\explorer\Styles\KMLIcons\french-flag.png
c:\program files (x86)\explorer\Styles\KMLIcons\hand.png
c:\program files (x86)\explorer\Styles\KMLIcons\high_res_places.png
c:\program files (x86)\explorer\Styles\KMLIcons\highway_16.png
c:\program files (x86)\explorer\Styles\KMLIcons\italian-flag.png
c:\program files (x86)\explorer\Styles\KMLIcons\large_traffic_count_16.png
c:\program files (x86)\explorer\Styles\KMLIcons\mexican-flag.png
c:\program files (x86)\explorer\Styles\KMLIcons\misc_dining.png
c:\program files (x86)\explorer\Styles\KMLIcons\note.png
c:\program files (x86)\explorer\Styles\KMLIcons\one-dollar.png
c:\program files (x86)\explorer\Styles\KMLIcons\palette-2.png
c:\program files (x86)\explorer\Styles\KMLIcons\palette-3.png
c:\program files (x86)\explorer\Styles\KMLIcons\palette-4.png
c:\program files (x86)\explorer\Styles\KMLIcons\palette-5.png
c:\program files (x86)\explorer\Styles\KMLIcons\parks.png
c:\program files (x86)\explorer\Styles\KMLIcons\recreation.png
c:\program files (x86)\explorer\Styles\KMLIcons\school_16.png
c:\program files (x86)\explorer\Styles\KMLIcons\search.png
c:\program files (x86)\explorer\Styles\KMLIcons\streamed_layer.png
c:\program files (x86)\explorer\Styles\KMLIcons\streamed_layers.png
c:\program files (x86)\explorer\Styles\KMLIcons\terrain_16.png
c:\program files (x86)\explorer\Styles\KMLIcons\three-dollars.png
c:\program files (x86)\explorer\Styles\KMLIcons\transportation.png
c:\program files (x86)\explorer\Styles\KMLIcons\two-dollars.png
c:\program files (x86)\explorer\Styles\KMLIcons\webcam_16.png
c:\program files (x86)\explorer\Styles\SlideTitleStyles.de.xml
c:\program files (x86)\explorer\Styles\SlideTitleStyles.es.xml
c:\program files (x86)\explorer\Styles\SlideTitleStyles.fr.xml
c:\program files (x86)\explorer\Styles\SlideTitleStyles.ja-JP.xml
c:\program files (x86)\explorer\Styles\SlideTitleStyles.xml
c:\program files (x86)\explorer\Styles\SlideTitleStyles.zh-CN.xml
c:\program files (x86)\explorer\Styles\StyleSheet.xsl
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\ATM.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Bank.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Bell.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Cemetery.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\City.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Clue.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Crowd.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\GhostTown.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Horn.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Housing.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\MailPost.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Office.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\Radioactive.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\School.png
c:\program files (x86)\explorer\Styles\SymbolImages\Civic\StarsStripes.png
c:\program files (x86)\explorer\Styles\SymbolImages\Flag\CheckeredFlag.png
c:\program files (x86)\explorer\Styles\SymbolImages\Flag\GreenFlag.png
c:\program files (x86)\explorer\Styles\SymbolImages\Flag\RedFlag.png
c:\program files (x86)\explorer\Styles\SymbolImages\Flag\WhiteFlag.png
c:\program files (x86)\explorer\Styles\SymbolImages\Flag\YellowFlag.png
c:\program files (x86)\explorer\Styles\SymbolImages\Health\AidStation.png
c:\program files (x86)\explorer\Styles\SymbolImages\Health\Ambulance.png
c:\program files (x86)\explorer\Styles\SymbolImages\Health\Doctor.png
c:\program files (x86)\explorer\Styles\SymbolImages\Health\Health.png
c:\program files (x86)\explorer\Styles\SymbolImages\Health\Hospital.png
c:\program files (x86)\explorer\Styles\SymbolImages\Health\Pharmacy.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\AmberBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\BlackBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\BlueBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\BoatsKeepOut.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\ControlledArea.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\Danger.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\DiverDown.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\GreenBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\GreenDiamondDaymark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\GreenRedBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\GreenSquareDaymark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\GreenWhiteBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\OrangeBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\PersonOverboard.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\RadioBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\RedBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\RedDiamondDaymark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\RedGreenBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\RedSquareDaymark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\RedTriangleDaymark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\RedWhiteBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\SkullandCrossbones.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\UnderwaterOperations.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\VioletBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\WhiteBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\WhiteDiamondDaymark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\WhiteGreenBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\WhiteRedBeacon.png
c:\program files (x86)\explorer\Styles\SymbolImages\Marine\Wreck.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\ArrowYellow.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Capital1.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Capital2.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\CircleX.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\CrossHair.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Populated1.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Populated2.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Populated3.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Populated4.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Populated5.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Populated6.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Populated7.png
c:\program files (x86)\explorer\Styles\SymbolImages\Placemark\Star.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\AmusementPark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Bar.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Camera.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\CameraWeb.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\CellPhone.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Coffee.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Dam.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\DepartmentStore.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Dining.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\DrinkingWater.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\FastFood.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\FitnessCenter.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Forest.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Globe.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Information.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\InformationQuestion.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\LandLine.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Light.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\LiveShow.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Mine.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\MovieTheater.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Museum.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\News.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Note.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\OilWell.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Pizza.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Pub.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Question.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\RealEstate.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Reservoir.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Restroom.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Shopping.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Shower.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Stadium.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\TowerShort.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\TowerTall.png
c:\program files (x86)\explorer\Styles\SymbolImages\Points of Interest\Zoo.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\Burglary.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\FireFighter.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\FireStation.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\FireTruck.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\Homicide.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\Police.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\PoliceCar.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\PoliceOfficer.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\PoliceStation.png
c:\program files (x86)\explorer\Styles\SymbolImages\Public Safety\Theft.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\BlackPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\BluePushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\BrownPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\GrayPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\GreenPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\LightBluePushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\OrangePushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\PinkPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\PurplePushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\RedPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\SpringGreenPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\WhitePushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Pushpin\YellowPushpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Beach.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\BoatLaunch.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Bowling.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Camping.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Deer.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Fishing.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Geocache.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\GeocacheFound.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Gliding.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Golf.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Hiking.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Mountain.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Park.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\RestArea.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\RVPark.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\SkyDiving.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Sports.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\Swimming.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\TrackBack.png
c:\program files (x86)\explorer\Styles\SymbolImages\Recreation\WaterSkiing.png
c:\program files (x86)\explorer\Styles\SymbolImages\Sphere\BlueSphere.png
c:\program files (x86)\explorer\Styles\SymbolImages\Sphere\GreenSphere.png
c:\program files (x86)\explorer\Styles\SymbolImages\Sphere\OrangeSphere.png
c:\program files (x86)\explorer\Styles\SymbolImages\Sphere\PurpleSphere.png
c:\program files (x86)\explorer\Styles\SymbolImages\Sphere\RedSphere.png
c:\program files (x86)\explorer\Styles\SymbolImages\Sphere\YellowSphere.png
c:\program files (x86)\explorer\Styles\SymbolImages\Square\BlackWaypoint.png
c:\program files (x86)\explorer\Styles\SymbolImages\Square\BlueWaypoint.png
c:\program files (x86)\explorer\Styles\SymbolImages\Square\WhiteWaypoint.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\BlackStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\BlueStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\BrownStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\GrayStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\GreenStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\LightBlueStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\OrangeStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\PinkStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\PurpleStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\RedStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\SpringGreenStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\WhiteStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Stickpin\YellowStickpin.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transparent\Transparent.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Airplane.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\AirStrip.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Breakdown.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Bus.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarGreenBack.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarGreenFront.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarRedBack.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarRedFront.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarRental.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarRepair.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarYellowBack.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\CarYellowFront.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\ConvenienceStore.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Crossing.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Fuel.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\HelicopterGreen.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\HelicopterRed.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\HelicopterYellow.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Landingpad.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Lodging.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\MileMarker.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\MountainPass.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Overpass.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Parking.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\PrivateField.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\RoadClosure.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\RoadWork.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Sailing.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Scales.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Seaplane.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Tank.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Toll.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\TrafficAccident.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Tunnel.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\Ultralight.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\WarningRed.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\WarningYellow.png
c:\program files (x86)\explorer\Styles\SymbolImages\Transportation\YellowSemiTractor.png
c:\program files (x86)\explorer\Styles\SymbolImages\Weather\Cloudy.png
c:\program files (x86)\explorer\Styles\SymbolImages\Weather\HeatAdvisory.png
c:\program files (x86)\explorer\Styles\SymbolImages\Weather\Lightning.png
c:\program files (x86)\explorer\Styles\SymbolImages\Weather\PartlySunny.png
c:\program files (x86)\explorer\Styles\SymbolImages\Weather\Rain.png
c:\program files (x86)\explorer\Styles\SymbolImages\Weather\Snow.png
c:\program files (x86)\explorer\Styles\SymbolImages\Weather\Sunny.png
c:\program files (x86)\explorer\Styles\Template.ncfg
c:\program files (x86)\explorer\TilingSchemes\ArcGIS_Online_Bing_Maps_Google_Maps.xml
c:\program files (x86)\explorer\TilingSchemes\GoogleMapsVersions.xml
c:\program files (x86)\explorer\TilingSchemes\Yahoo.xml
c:\users\Carl Tessier\AppData\Local\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}
c:\users\Carl Tessier\AppData\Local\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\@
c:\users\Carl Tessier\AppData\Local\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\n
c:\users\Carl Tessier\AppData\Local\assembly\tmp
c:\users\Carl Tessier\AppData\Local\assembly\tmp\N1BIIT75\__AssemblyInfo__.ini
c:\users\Carl Tessier\AppData\Local\assembly\tmp\N1BIIT75\AddinExpress.WD.2005.DLL
c:\users\Carl Tessier\AppData\Local\Temp\aprob.dll
c:\users\CARLTE~1\AppData\Local\Temp\aprob.dll
c:\windows\7Loader.TAG
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\@
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\L\00000004.@
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\L\201d3dde
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\L\55490ac4
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\U\00000004.@
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\U\00000008.@
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\U\000000cb.@
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\U\80000000.@
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\U\80000032.@
c:\windows\Installer\{0bc26a33-65fe-93e0-8e88-9d220af6ad54}\U\80000064.@
c:\windows\iun6002.exe
c:\windows\My.ini
c:\windows\system32\drivers\etc\lmhosts
c:\windows\SysWow64\DEBUG.log
c:\windows\SysWow64\html
c:\windows\SysWow64\html\calendar.html
c:\windows\SysWow64\html\calendarbottom.html
c:\windows\SysWow64\html\calendartop.html
c:\windows\SysWow64\html\crystalexportdialog.htm
c:\windows\SysWow64\html\crystalprinthost.html
c:\windows\SysWow64\images
c:\windows\SysWow64\images\toolbar\calendar.gif
c:\windows\SysWow64\images\toolbar\crlogo.gif
c:\windows\SysWow64\images\toolbar\export.gif
c:\windows\SysWow64\images\toolbar\export_over.gif
c:\windows\SysWow64\images\toolbar\exportd.gif
c:\windows\SysWow64\images\toolbar\First.gif
c:\windows\SysWow64\images\toolbar\first_over.gif
c:\windows\SysWow64\images\toolbar\Firstd.gif
c:\windows\SysWow64\images\toolbar\gotopage.gif
c:\windows\SysWow64\images\toolbar\gotopage_over.gif
c:\windows\SysWow64\images\toolbar\gotopaged.gif
c:\windows\SysWow64\images\toolbar\grouptree.gif
c:\windows\SysWow64\images\toolbar\grouptree_over.gif
c:\windows\SysWow64\images\toolbar\grouptreed.gif
c:\windows\SysWow64\images\toolbar\grouptreepressed.gif
c:\windows\SysWow64\images\toolbar\Last.gif
c:\windows\SysWow64\images\toolbar\last_over.gif
c:\windows\SysWow64\images\toolbar\Lastd.gif
c:\windows\SysWow64\images\toolbar\Next.gif
c:\windows\SysWow64\images\toolbar\next_over.gif
c:\windows\SysWow64\images\toolbar\Nextd.gif
c:\windows\SysWow64\images\toolbar\Prev.gif
c:\windows\SysWow64\images\toolbar\prev_over.gif
c:\windows\SysWow64\images\toolbar\Prevd.gif
c:\windows\SysWow64\images\toolbar\print.gif
c:\windows\SysWow64\images\toolbar\print_over.gif
c:\windows\SysWow64\images\toolbar\printd.gif
c:\windows\SysWow64\images\toolbar\Refresh.gif
c:\windows\SysWow64\images\toolbar\refresh_over.gif
c:\windows\SysWow64\images\toolbar\refreshd.gif
c:\windows\SysWow64\images\toolbar\Search.gif
c:\windows\SysWow64\images\toolbar\search_over.gif
c:\windows\SysWow64\images\toolbar\searchd.gif
c:\windows\SysWow64\images\toolbar\up.gif
c:\windows\SysWow64\images\toolbar\up_over.gif
c:\windows\SysWow64\images\toolbar\upd.gif
c:\windows\SysWow64\images\tree\begindots.gif
c:\windows\SysWow64\images\tree\beginminus.gif
c:\windows\SysWow64\images\tree\beginplus.gif
c:\windows\SysWow64\images\tree\blank.gif
c:\windows\SysWow64\images\tree\blankdots.gif
c:\windows\SysWow64\images\tree\dots.gif
c:\windows\SysWow64\images\tree\lastdots.gif
c:\windows\SysWow64\images\tree\lastminus.gif
c:\windows\SysWow64\images\tree\lastplus.gif
c:\windows\SysWow64\images\tree\Magnify.gif
c:\windows\SysWow64\images\tree\minus.gif
c:\windows\SysWow64\images\tree\minusbox.gif
c:\windows\SysWow64\images\tree\plus.gif
c:\windows\SysWow64\images\tree\plusbox.gif
c:\windows\SysWow64\images\tree\singleminus.gif
c:\windows\SysWow64\images\tree\singleplus.gif
F:\autorun.inf
.
c:\windows\system32\services.exe . . . est infecté!!
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_{79007602-0CDB-4405-9DBF-1257BB3226EE}
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-05-28 au 2012-06-29 ))))))))))))))))))))))))))))))))))))
.
.
2012-06-29 03:52 . 2012-06-29 03:52 -------- d-----w- c:\users\TrackitWeb\AppData\Local\temp
2012-06-29 03:52 . 2012-06-29 03:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-29 03:52 . 2012-06-29 03:52 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp
2012-06-27 05:17 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
2012-06-27 05:17 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-06-25 19:05 . 2012-06-25 19:05 -------- d-----w- c:\users\Carl Tessier\AppData\Roaming\Malwarebytes
2012-06-25 19:05 . 2012-06-25 19:05 -------- d-----w- c:\programdata\Malwarebytes
2012-06-25 19:05 . 2012-06-25 19:05 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-06-25 19:05 . 2012-04-04 19:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-23 02:56 . 2012-06-23 02:56 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-06-18 22:41 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-18 22:41 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-18 22:41 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-18 22:41 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-18 22:40 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-18 22:40 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-18 22:40 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-18 22:39 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-18 22:39 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-15 22:45 . 2012-06-15 22:45 -------- d-----w- c:\users\Carl Tessier\AppData\Local\Macromedia
2012-06-12 22:33 . 2012-06-12 22:33 -------- d-----w- c:\program files (x86)\Common Files\Software Update Utility
2012-06-07 01:00 . 2012-06-07 01:00 -------- d-----w- c:\users\Carl Tessier\AppData\Roaming\GitHub
2012-06-07 01:00 . 2012-06-07 01:08 -------- d-----w- c:\users\Carl Tessier\AppData\Local\GitHub
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-23 02:47 . 2012-04-05 22:44 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-23 02:47 . 2011-05-16 22:08 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-09 04:38 . 2009-05-30 22:42 165232 ---ha-w- c:\users\Carl Tessier\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2012-06-09 01:39 . 2009-10-22 15:23 2485760 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2012-05-30 01:18 . 2012-05-30 01:18 62464 ---ha-w- c:\windows\system32\findup1664.dll
2012-05-06 05:32 . 2012-05-07 02:19 4474880 ----a-w- c:\windows\SysWow64\QtCored4.dll
2012-05-06 05:32 . 2012-05-07 02:19 2562560 ----a-w- c:\windows\SysWow64\QtCore4.dll
2012-05-06 05:31 . 2012-05-07 02:19 596480 ----a-w- c:\windows\SysWow64\QtXmld4.dll
2012-05-06 05:31 . 2012-05-07 02:19 5961728 ----a-w- c:\windows\SysWow64\QtXmlPatternsd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 355840 ----a-w- c:\windows\SysWow64\QtXml4.dll
2012-05-06 05:31 . 2012-05-07 02:19 2634752 ----a-w- c:\windows\SysWow64\QtXmlPatterns4.dll
2012-05-06 05:31 . 2012-05-07 02:19 23985664 ----a-w- c:\windows\SysWow64\QtWebKitd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 525824 ----a-w- c:\windows\SysWow64\QtSvgd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 341504 ----a-w- c:\windows\SysWow64\QtSqld4.dll
2012-05-06 05:31 . 2012-05-07 02:19 283136 ----a-w- c:\windows\SysWow64\QtSvg4.dll
2012-05-06 05:31 . 2012-05-07 02:19 201728 ----a-w- c:\windows\SysWow64\QtSql4.dll
2012-05-06 05:31 . 2012-05-07 02:19 195584 ----a-w- c:\windows\SysWow64\QtTestd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 13110784 ----a-w- c:\windows\SysWow64\QtWebKit4.dll
2012-05-06 05:31 . 2012-05-07 02:19 109056 ----a-w- c:\windows\SysWow64\QtTest4.dll
2012-05-06 05:31 . 2012-05-07 02:19 1042432 ----a-w- c:\windows\SysWow64\QtScriptToolsd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 6948864 ----a-w- c:\windows\SysWow64\QtScriptd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 583168 ----a-w- c:\windows\SysWow64\QtScriptTools4.dll
2012-05-06 05:31 . 2012-05-07 02:19 1341440 ----a-w- c:\windows\SysWow64\QtScript4.dll
2012-05-06 05:31 . 2012-05-07 02:19 840192 ----a-w- c:\windows\SysWow64\QtHelpd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 778752 ----a-w- c:\windows\SysWow64\QtOpenGL4.dll
2012-05-06 05:31 . 2012-05-07 02:19 433152 ----a-w- c:\windows\SysWow64\QtHelp4.dll
2012-05-06 05:31 . 2012-05-07 02:19 230912 ----a-w- c:\windows\SysWow64\QtMultimediad4.dll
2012-05-06 05:31 . 2012-05-07 02:19 1760256 ----a-w- c:\windows\SysWow64\QtNetworkd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 1428992 ----a-w- c:\windows\SysWow64\QtOpenGLd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 114176 ----a-w- c:\windows\SysWow64\QtMultimedia4.dll
2012-05-06 05:31 . 2012-05-07 02:19 1037312 ----a-w- c:\windows\SysWow64\QtNetwork4.dll
2012-05-06 05:31 . 2012-05-07 02:19 14874112 ----a-w- c:\windows\SysWow64\QtGuid4.dll
2012-05-06 05:31 . 2012-05-07 02:19 8569856 ----a-w- c:\windows\SysWow64\QtGui4.dll
2012-05-06 05:31 . 2012-05-07 02:19 7275520 ----a-w- c:\windows\SysWow64\QtDesignerd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 3890176 ----a-w- c:\windows\SysWow64\QtDesignerComponentsd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 1926144 ----a-w- c:\windows\SysWow64\QtDesignerComponents4.dll
2012-05-06 05:31 . 2012-05-07 02:19 4900864 ----a-w- c:\windows\SysWow64\QtDeclaratived4.dll
2012-05-06 05:31 . 2012-05-07 02:19 4704768 ----a-w- c:\windows\SysWow64\QtDesigner4.dll
2012-05-06 05:31 . 2012-05-07 02:19 2576384 ----a-w- c:\windows\SysWow64\QtDeclarative4.dll
2012-05-06 05:31 . 2012-05-07 02:19 872448 ----a-w- c:\windows\SysWow64\QtCLucene4.dll
2012-05-06 05:31 . 2012-05-07 02:19 2257920 ----a-w- c:\windows\SysWow64\QtCLucened4.dll
2012-05-06 05:31 . 2012-05-07 02:19 3857408 ----a-w- c:\windows\SysWow64\Qt3Supportd4.dll
2012-05-06 05:31 . 2012-05-07 02:19 2395136 ----a-w- c:\windows\SysWow64\Qt3Support4.dll
2012-05-06 05:31 . 2009-06-02 11:03 517632 ----a-w- c:\windows\SysWow64\phonond4.dll
2012-05-06 05:31 . 2009-06-02 04:49 270848 ----a-w- c:\windows\SysWow64\phonon4.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-07-14 . 50BEA589F7D7958BDD2528A8F69D05CC . 329216 . . [6.1.7600.16385] .. c:\windows\system32\services.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~2\Yahoo!\MESSEN~1\YahooMessenger.exe" [2012-02-23 6591800]
"Aim"="c:\program files (x86)\AIM\aim.exe" [2012-05-30 4331392]
"FeedDemon"="c:\program files (x86)\FeedDemon\FeedDemon.exe" [2010-12-16 7503360]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2011-09-18 1242448]
"Facebook Update"="c:\users\Carl Tessier\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-04-11 137536]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-06-05 17344176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-11-11 442536]
"googletalk"="c:\program files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-07-29 128296]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2009-09-13 103768]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"Client Access Service"="c:\program files (x86)\IBM\Client Access\cwbsvstr.exe" [2007-12-11 14848]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"PlusService"="c:\program files (x86)\Yuna Software\Messenger Plus!\PlusService.exe" [2012-02-27 801792]
"vmware-tray"="c:\program files (x86)\VMware\VMware Workstation\vmware-tray.exe" [2011-08-22 103536]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-11-13 421736]
"LogitechCommunicationsManager"="c:\program files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-03-06 488984]
"LogitechQuickCamRibbon"="c:\program files (x86)\Labtec\WebCam10\WebCam10.exe" [2007-03-06 1060376]
"MessengerPlusForSkypeService"="c:\program files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [2012-03-21 119296]
.
c:\users\Carl Tessier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
Facebook Messenger.lnk - c:\users\Carl Tessier\AppData\Local\Facebook\Messenger\2.1.4554.0\FacebookMessenger.exe [2012-6-20 209920]
OneNote 2010 - Capture d’écran et lancement.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
HotSync Manager.lnk - c:\program files (x86)\palmOne\Hotsync.exe [2004-6-9 471040]
Zend Controller.lnk - c:\program files (x86)\Zend\ZendServer\bin\zendcontroller.exe [2010-11-30 249336]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-6 1312096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate1c9ee03c2a0f134;Service Google Update (gupdate1c9ee03c2a0f134);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-06-15 133104]
R2 MSSQL$TRACKIT;SQL Server (TRACKIT);c:\program files (x86)\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [x]
R2 MSSQL$TRACKIT_1;SQL Server (TRACKIT_1);c:\program files (x86)\Microsoft SQL Server\MSSQL.3\MSSQL\Binn\sqlservr.exe [x]
R2 MSSQL$TRACKIT_2;SQL Server (TRACKIT_2);c:\program files (x86)\Microsoft SQL Server\MSSQL.4\MSSQL\Binn\sqlservr.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-05 160944]
R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2011-08-22 11837440]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-12-10 1038088]
R3 gupdatem;Service Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-06-15 133104]
R3 LVcKap64;Logitech AEC Driver;c:\windows\system32\DRIVERS\LVcKap64.sys [2007-03-06 1029024]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2011-08-02 22528]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 PORTMON;PORTMON;c:\program files (x86)\Sysinternals\PORTMSYS.SYS [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-08-02 51712]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys [2011-07-15 46384]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-08-12 61976]
R4 RsFx0105;RsFx0105 Driver;c:\windows\system32\DRIVERS\RsFx0105.sys [2011-09-23 311144]
R4 SQLAgent$SQL2008;SQL Server Agent (SQL2008);c:\program files\Microsoft SQL Server\MSSQL10.SQL2008\MSSQL\Binn\SQLAGENT.EXE [2011-09-23 431464]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-02-06 54480]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2009-09-08 87600]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 203264]
S2 AsnaAssist;ASNA Assist;c:\program files (x86)\ASNA\ASNA Services\AsnaSvcHost.exe [2008-12-10 114688]
S2 AsnaRegistrar;ASNA Registrar;c:\program files (x86)\ASNA\ASNA Services\AsnaSvcHost.exe [2008-12-10 114688]
S2 DataGate Server;DataGate Server;c:\program files (x86)\ASNA\DataGate Server\8.1\dgServer.exe [2008-12-04 2080768]
S2 DB2MGMTSVC_DB2COPY1;DB2 Management Service (DB2COPY1);c:\program files (x86)\IBM\SQLLIB\BIN\db2mgmtsvc.exe [2009-04-04 38688]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 MsgPlusService;Messenger Plus! Service;c:\program files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe [2012-03-21 119296]
S2 MSSQL$SQL2008;SQL Server (SQL2008);c:\program files\Microsoft SQL Server\MSSQL10.SQL2008\MSSQL\Binn\sqlservr.exe [2011-09-23 58345832]
S2 MSSQL$TRACKIT_3;SQL Server (TRACKIT_3);c:\program files (x86)\Microsoft SQL Server\MSSQL.5\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S2 ReportServer$SQL2008;SQL Server Reporting Services (SQL2008);c:\program files\Microsoft SQL Server\MSRS10.SQL2008\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2011-09-23 2084712]
S2 sesvc;ShadowExplorer Service;c:\program files (x86)\ShadowExplorer\sesvc.exe [2011-01-03 9216]
S2 TeamViewer4;TeamViewer 4;c:\program files (x86)\TeamViewer\Version4\TeamViewer_Service.exe [2009-10-07 185640]
S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-02-11 172328]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files (x86)\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-22 846448]
S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-10-28 160704]
S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848]
S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\DRIVERS\LVUSBS64.sys [2007-03-06 58400]
S3 MSSQLFDLauncher$SQL2008;SQL Full-text Filter Daemon Launcher (SQL2008);c:\program files\Microsoft SQL Server\MSSQL10.SQL2008\MSSQL\Binn\fdlauncher.exe [2008-07-10 34840]
S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;c:\windows\system32\DRIVERS\OA008Ufd.sys [2009-03-06 159840]
S3 OA008Vid;Creative Camera OA008 Function Driver;c:\windows\system32\DRIVERS\OA008Vid.sys [2009-05-06 313696]
S3 PsxDrv;PsxDrv;c:\windows\system32\drivers\psxdrv.sys [2009-07-13 10240]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Contenu du dossier 'Tâches planifiées'
.
2012-06-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3585025520-255359423-1373225610-1000Core.job
- c:\users\Carl Tessier\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-05 23:42]
.
2012-06-29 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3585025520-255359423-1373225610-1000UA.job
- c:\users\Carl Tessier\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-04-05 23:42]
.
2012-06-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-15 01:36]
.
2012-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-06-15 21:53]
.
2012-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-06-15 21:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Carl Tessier\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 22:55 97032 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCCCATS"="c:\windows\system32\spool\DRIVERS\x64\3\DLCCtime.dll" [2006-02-24 28672]
"QuickSet"="c:\program files\Dell\QuickSet\QuickSet.exe" [2008-09-26 2041112]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-01-21 487424]
"combofix"="c:\combofix\CF26280.3XE" [2009-07-14 344576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = local;*.local
IE: Ajouter la cible du lien à un fichier PDF existant - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à un fichier PDF existant - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: S'abonner avec RSS Bandit - c:\users\Carl Tessier\AppData\Roaming\RssBandit\iecontext_subscribebandit.htm
IE: Se&nd to OneNote - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: Sothink SWF Catcher - c:\program files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
LSP: mswsock.dll
LSP: %SystemRoot%\system32\vsocklib.dll
Trusted Zone: cascades.com\norampac.trackit
Trusted Zone: gouv.qc.ca\www.mtqsignalisation.mtq
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{47738D2D-5792-416D-84E8-D96A2C801C31}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{47738D2D-5792-416D-84E8-D96A2C801C31}\14D6472716B634F6E6E6563647: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{47738D2D-5792-416D-84E8-D96A2C801C31}\6574E4564777F627B6: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{47738D2D-5792-416D-84E8-D96A2C801C31}\86F6D6561313: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{47738D2D-5792-416D-84E8-D96A2C801C31}\E4544574541425: NameServer = 8.8.8.8,8.8.4.4
DPF: {576756A1-D97C-45D0-A945-0324019A131E} - hxxp://ti9-testsvr.norampac.com/tiweb70/downloads/BOSIActiveXGrid.cab
DPF: {6AF2E1A7-A16E-4503-A440-07CA49122CCE} - hxxp://ti9-testsvr.norampac.com/tiweb70/downloads/BOSIActiveXMemoControl.cab
FF - ProfilePath - c:\users\Carl Tessier\AppData\Roaming\Mozilla\Firefox\Profiles\h8fonhha.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: network.proxy.socks - 66.167.100.59
FF - prefs.js: network.proxy.socks_port - 6649
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
FF - user.js: zend.ZDE_Path - c:\program files (x86)\Zend\Zend Studio - 7.0.2\ZendStudio.exe
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.ytff.general.dontshowhpoffer, true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-Daemon for Mouse Suite - c:\program files\Lenovo\Lenovo Mouse Suite\ICO.EXE
HKLM-Run-adsdl - c:\users\CARLTE~1\AppData\Local\Temp\adsdl.dll
HKLM-Run-aprob - c:\users\CARLTE~1\AppData\Local\Temp\aprob.dll
.
.
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-3585025520-255359423-1373225610-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¨*i%c%]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3585025520-255359423-1373225610-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*¨*i%c%\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3585025520-255359423-1373225610-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c% Ò*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3585025520-255359423-1373225610-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c% Ò*\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3585025520-255359423-1373225610-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*i%ì*Ñ*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3585025520-255359423-1373225610-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*i%ì*Ñ*\OpenWithList]
@Class="Shell"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ASNA\Shared\Security Provider*Wrong guess again!]
"<No Name>"="{19A41F22-0413-4A77-826C-6A2CB6B47708}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]
@Denied: (A) (Everyone)
"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]
"Key"="ActionsPane"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
"Key"="ActionsPane3"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\SUA\usr\sbin\init
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Borland\InterBase\bin\ibguard.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\windows\SysWOW64\vmnat.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files (x86)\VMware\VMware Workstation\vmware-authd.exe
c:\windows\SysWOW64\vmnetdhcp.exe
c:\program files (x86)\Borland\InterBase\bin\ibserver.exe
c:\program files (x86)\Google\Update\1.3.21.111\GoogleCrashHandler.exe
c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe
c:\windows\SysWOW64\inetsrv\w3wp.exe
c:\program files (x86)\Citrix\ICA Client\wfcrun32.exe
c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe
c:\program files (x86)\Common Files\LogiShrd\LComMgr\LVComSX.exe
.
**************************************************************************
.
Heure de fin: 2012-06-29 00:19:49 - La machine a redémarré
ComboFix-quarantined-files.txt 2012-06-29 04:19
.
Avant-CF: 65 195 401 216 octets libres
Après-CF: 66 785 902 592 octets libres
.
- - End Of File - - 413978AFE3B4AA92A14AF2B4F6F7C3A5
Just FYI, in my case, "C:\Program Files (x86)\explorer" was legit; it was ArcGIS Explorer, a GIS mapping application. I do understand why it looked suspicious though.
There does not seem to be anything wrong with HTTPS anymore. Chrome does accept Google's certificate now, which would indicate that no one is in the middle of the conversation.
If any symptom reappears, I'll let you know.