Voici le
log de
ComboFix:
ComboFix 09-07-04.05 - Anto2 05/07/2009 16:44.18 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.256 [GMT 2:00]
Lancé depuis: c:\documents and settings\Anto2\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Anto2\Application Data\wiaserva.log
c:\windows\Installer\1284f7.msp
c:\windows\Installer\12d7f9.msp
c:\windows\Installer\138cf1.msp
c:\windows\Installer\13dac3.msp
c:\windows\Installer\1528fe.msp
c:\windows\Installer\1543d9.msp
c:\windows\Installer\16ae5.msp
c:\windows\Installer\16e11d.msp
c:\windows\Installer\16e12c.msp
c:\windows\Installer\18e9654.msp
c:\windows\Installer\19ea990.msp
c:\windows\Installer\1aa5a7.msp
c:\windows\Installer\1c84f6.msp
c:\windows\Installer\1ca0fa.msp
c:\windows\Installer\1e2b82.msp
c:\windows\Installer\1e2b8a.msp
c:\windows\Installer\21b507.msp
c:\windows\Installer\22011.msp
c:\windows\Installer\22d6f.msp
c:\windows\Installer\23994.msp
c:\windows\Installer\241211.msp
c:\windows\Installer\2463c7d.msp
c:\windows\Installer\24688e.msp
c:\windows\Installer\24a2e.msp
c:\windows\Installer\24ced.msp
c:\windows\Installer\26330d.msp
c:\windows\Installer\27015.msp
c:\windows\Installer\2751fa.msp
c:\windows\Installer\27e6d.msp
c:\windows\Installer\2a05d.msp
c:\windows\Installer\2a166.msp
c:\windows\Installer\2a16c.msp
c:\windows\Installer\2a235a.msp
c:\windows\Installer\2a3cbe.msp
c:\windows\Installer\2aa40.msp
c:\windows\Installer\2b377.msp
c:\windows\Installer\2bdf72.msp
c:\windows\Installer\2c1cf.msp
c:\windows\Installer\2cde5.msp
c:\windows\Installer\2cf5c.msp
c:\windows\Installer\2cfd65.msp
c:\windows\Installer\2d5a5.msp
c:\windows\Installer\2d651.msp
c:\windows\Installer\2daf5.msp
c:\windows\Installer\2f5ef.msp
c:\windows\Installer\2fe8a.msp
c:\windows\Installer\2ffc2.msp
c:\windows\Installer\3012a.msp
c:\windows\Installer\30437.msp
c:\windows\Installer\30800.msp
c:\windows\Installer\30d7e.msp
c:\windows\Installer\310939.msp
c:\windows\Installer\31250.msp
c:\windows\Installer\31732.msp
c:\windows\Installer\31cef.msp
c:\windows\Installer\327cc.msp
c:\windows\Installer\32982.msp
c:\windows\Installer\329a1.msp
c:\windows\Installer\32a1e.msp
c:\windows\Installer\32cbe.msp
c:\windows\Installer\32d4b.msp
c:\windows\Installer\32e35.msp
c:\windows\Installer\33411.msp
c:\windows\Installer\334dc.msp
c:\windows\Installer\335c7.msp
c:\windows\Installer\3371e.msp
c:\windows\Installer\33b16.msp
c:\windows\Installer\33dc5.msp
c:\windows\Installer\33eee.msp
c:\windows\Installer\342b7.msp
c:\windows\Installer\34d27.msp
c:\windows\Installer\34f69.msp
c:\windows\Installer\35044.msp
c:\windows\Installer\35219.msp
c:\windows\Installer\35787.msp
c:\windows\Installer\3590e.msp
c:\windows\Installer\3596c.msp
c:\windows\Installer\35b21.msp
c:\windows\Installer\35ee17.msp
c:\windows\Installer\360c6d.msp
c:\windows\Installer\3613c.msp
c:\windows\Installer\368cd.msp
c:\windows\Installer\38b2a.msp
c:\windows\Installer\38b49.msp
c:\windows\Installer\38c34.msp
c:\windows\Installer\38cdf.msp
c:\windows\Installer\38e37.msp
c:\windows\Installer\3a51b.msp
c:\windows\Installer\3ad96.msp
c:\windows\Installer\3b2c7.msp
c:\windows\Installer\3ba58.msp
c:\windows\Installer\3bde2.msp
c:\windows\Installer\3bfa8d.msp
c:\windows\Installer\3c396b.msp
c:\windows\Installer\3c70a.msp
c:\windows\Installer\3c9aa.msp
c:\windows\Installer\3c9e8.msp
c:\windows\Installer\3d3eb.msp
c:\windows\Installer\3d8bd.msp
c:\windows\Installer\3dfb9d.msp
c:\windows\Installer\3e7b6c.msp
c:\windows\Installer\4198f.msp
c:\windows\Installer\433ce.msp
c:\windows\Installer\4456df.msp
c:\windows\Installer\46945.msp
c:\windows\Installer\47329.msp
c:\windows\Installer\484632.msp
c:\windows\Installer\49847e.msp
c:\windows\Installer\49a0a.msp
c:\windows\Installer\4abc14.msp
c:\windows\Installer\4b65c.msp
c:\windows\Installer\4c3ba.msp
c:\windows\Installer\4d916.msp
c:\windows\Installer\4e4de.msp
c:\windows\Installer\4e70b0.msp
c:\windows\Installer\51eca.msp
c:\windows\Installer\5254c8.msp
c:\windows\Installer\560fbd.msp
c:\windows\Installer\571f77.msp
c:\windows\Installer\6bdb44.msp
c:\windows\Installer\7236c5.msp
c:\windows\Installer\75e093.msp
c:\windows\Installer\7e93af.msp
c:\windows\Installer\807d5f.msp
c:\windows\Installer\80836a.msp
c:\windows\Installer\84ac89.msp
c:\windows\Installer\8bbb5c.msp
c:\windows\Installer\8eb3ad.msp
c:\windows\Installer\a7bcbc.msp
c:\windows\Installer\bfc2c2.msp
c:\windows\Installer\c2abd0.msp
c:\windows\Installer\c87b0f.msp
c:\windows\Installer\d3cbb.msp
c:\windows\Installer\d53cd.msp
c:\windows\Installer\d53d2.msp
c:\windows\Installer\e91a31.msp
c:\windows\Installer\ea8049.msp
c:\windows\Installer\eeb46.msp
c:\windows\Installer\f93e07.msp
c:\windows\Installer\ff4d4c.msp
c:\windows\Installer\WMEncoder.msi
c:\windows\system32\tftp.exe . . . est infecté!!
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-05 au 2009-07-05 ))))))))))))))))))))))))))))))))))))
.
2009-07-05 11:28 . 2009-07-05 11:28 -------- d-sh--w- c:\documents and settings\Anto2\IECompatCache
2009-07-05 11:26 . 2009-07-05 11:26 -------- d-sh--w- c:\documents and settings\Anto2\PrivacIE
2009-07-05 10:01 . 2009-07-05 10:01 -------- d-sh--w- c:\documents and settings\Anto2\IETldCache
2009-07-04 21:50 . 2009-07-04 21:50 -------- dc----w- c:\program files\MSBuild
2009-07-04 21:50 . 2009-07-04 21:50 -------- dc----w- c:\program files\Reference Assemblies
2009-07-04 21:15 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-07-04 21:12 . 2009-07-04 21:15 -------- d-----w- c:\windows\ie8updates
2009-07-04 21:07 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-07-04 21:07 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-04 21:03 . 2009-07-04 21:07 -------- dc-h--w- c:\windows\ie8
2009-07-04 20:13 . 2009-07-04 20:14 -------- dc----w- c:\program files\trend micro
2009-07-04 20:13 . 2009-07-04 20:14 -------- dc----w- C:\rsit
2009-07-03 19:39 . 2009-07-03 19:39 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-07-03 19:39 . 2007-05-02 09:11 15112 ----a-w- c:\windows\system32\drivers\ss_mdfl.sys
2009-07-03 19:39 . 2007-05-02 09:11 12424 ----a-w- c:\windows\system32\drivers\ss_whnt.sys
2009-07-03 19:39 . 2007-05-02 09:11 12424 ----a-w- c:\windows\system32\drivers\ss_wh.sys
2009-07-03 19:39 . 2007-05-02 09:11 109704 ----a-w- c:\windows\system32\drivers\ss_mdm.sys
2009-07-03 19:39 . 2007-05-02 09:11 83592 ----a-w- c:\windows\system32\drivers\ss_bus.sys
2009-07-03 19:39 . 2007-05-02 09:11 12424 ----a-w- c:\windows\system32\drivers\ss_cmnt.sys
2009-07-03 19:39 . 2007-05-02 09:11 12424 ----a-w- c:\windows\system32\drivers\ss_cm.sys
2009-07-03 19:39 . 2009-07-03 19:41 -------- dc----w- c:\program files\Samsung
2009-07-03 17:37 . 2009-07-03 17:41 -------- d-----w- c:\documents and settings\Anto2\Application Data\vlc
2009-07-03 17:36 . 2009-07-03 17:36 -------- d-----w- c:\documents and settings\Anto2\Application Data\SampleView
2009-07-03 15:35 . 2009-07-03 15:39 -------- dc----w- c:\program files\Windows Live
2009-07-02 16:27 . 2009-07-02 16:27 -------- dc----w- c:\program files\iPod
2009-07-02 16:27 . 2009-07-02 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-02 16:25 . 2009-07-02 16:25 -------- dc----w- c:\program files\Bonjour
2009-07-02 16:23 . 2009-07-02 16:24 -------- dc----w- c:\program files\QuickTime
2009-07-02 16:23 . 2009-07-02 16:23 -------- dc----w- c:\program files\Java
2009-07-02 16:19 . 2009-06-05 09:42 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-30 19:08 . 2009-06-30 19:09 -------- d-----w- c:\documents and settings\Anto2\Application Data\DeepBurner Pro
2009-06-30 16:34 . 2009-07-05 11:24 -------- dc----w- c:\program files\Spybot - Search & Destroy
2009-06-30 15:42 . 2009-06-30 15:51 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-06-30 15:23 . 2009-06-30 15:51 -------- d-----w- c:\documents and settings\Anto2\Application Data\Uniblue
2009-06-27 20:42 . 2009-06-27 20:42 -------- d-----w- c:\documents and settings\Anto2\Local Settings\Application Data\PunkBuster
2009-06-27 20:39 . 2009-07-01 10:28 -------- d-----w- c:\documents and settings\Anto2\Application Data\id Software
2009-06-27 20:34 . 2009-06-27 20:34 22328 ----a-w- c:\documents and settings\Anto2\Application Data\PnkBstrK.sys
2009-06-23 17:21 . 2009-04-22 12:27 14848 ----a-w- c:\windows\system32\EuEpmGdi.dll
2009-06-23 17:21 . 2009-06-13 17:54 1663488 ----a-w- c:\windows\system32\BootMan.exe
2009-06-23 17:21 . 2009-04-22 12:28 8704 ----a-w- c:\windows\system32\epmntdrv.sys
2009-06-23 17:21 . 2009-04-22 12:28 86408 ----a-w- c:\windows\system32\setupempdrv03.exe
2009-06-23 17:21 . 2009-04-22 12:28 3072 ----a-w- c:\windows\system32\EuGdiDrv.sys
2009-06-23 16:28 . 2009-06-23 16:28 -------- dc----w- c:\program files\Common Files
2009-06-23 15:24 . 2008-10-29 18:25 13576 ----a-w- c:\windows\system32\wnaspi32.dll
2009-06-22 20:23 . 2009-06-22 20:23 -------- dc----w- c:\program files\VideoLAN
2009-06-20 16:19 . 2009-06-20 16:19 -------- d-----w- c:\documents and settings\Anto2\Local Settings\Application Data\Help
2009-06-20 16:05 . 2009-06-20 16:05 -------- dc----w- c:\program files\PowerQuest
2009-06-16 19:51 . 2009-07-05 11:25 152576 ----a-w- c:\documents and settings\Anto2\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-11 14:19 . 2009-07-03 15:49 -------- d-----w- c:\documents and settings\Anto2\Tracing
2009-06-10 17:31 . 2009-06-19 19:48 -------- d-----w- c:\documents and settings\Anto2\Application Data\DAEMON Tools Lite
2009-06-10 06:28 . 2009-06-10 06:28 3510272 ----a-w- c:\windows\system32\nvgames.dll
2009-06-10 06:28 . 2009-06-10 06:28 5890048 ----a-w- c:\windows\system32\nvdispsr.dll
2009-06-10 06:28 . 2009-06-10 06:28 4022272 ----a-w- c:\windows\system32\nvdisps.dll
2009-06-10 06:28 . 2009-06-10 06:28 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-06-10 06:28 . 2009-06-10 06:28 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-06-10 06:28 . 2009-06-10 06:28 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-06-10 06:28 . 2009-06-10 06:28 13758464 ----a-w- c:\windows\system32\nvcpl.dll
2009-06-10 06:28 . 2009-06-10 06:28 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-06-07 19:56 . 2009-06-07 19:56 -------- d--h--w- c:\windows\PIF
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-05 11:24 . 2006-03-21 17:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-05 10:09 . 2003-01-22 01:22 571740 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-05 10:09 . 2003-01-22 01:22 113676 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-03 19:39 . 2009-04-23 10:45 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-07-03 17:35 . 2008-12-14 13:33 -------- d-----w- c:\documents and settings\Anto2\Application Data\uTorrent
2009-07-03 10:30 . 2009-01-29 18:47 -------- d-----w- c:\documents and settings\Anto2\Application Data\AdobeUM
2009-07-02 19:57 . 2007-08-08 21:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-02 16:27 . 2009-01-23 19:18 -------- dc----w- c:\program files\Fichiers communs\Apple
2009-06-28 15:43 . 2009-06-02 15:18 -------- d-----w- c:\documents and settings\Anto2\Application Data\dvdcss
2009-06-27 18:12 . 2009-01-01 19:02 0 ----a-r- c:\documents and settings\Anto2\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
2009-06-23 19:26 . 2009-06-23 19:26 0 ----a-w- c:\windows\system32\REN14.tmp
2009-06-23 19:26 . 2009-06-23 19:26 0 ----a-w- c:\windows\system32\REN13.tmp
2009-06-23 19:26 . 2009-06-23 19:26 0 ----a-w- c:\windows\system32\REN12.tmp
2009-06-23 15:28 . 2009-04-23 10:28 -------- dc----w- c:\program files\Fichiers communs\InstallShield
2009-06-22 19:50 . 2009-01-01 16:13 -------- d-----w- c:\documents and settings\Anto2\Application Data\Canneverbe_Limited
2009-06-22 17:29 . 2009-06-22 17:29 0 ----a-w- c:\windows\system32\REN35.tmp
2009-06-22 17:29 . 2009-06-22 17:29 0 ----a-w- c:\windows\system32\REN34.tmp
2009-06-22 17:29 . 2009-06-22 17:29 0 ----a-w- c:\windows\system32\REN33.tmp
2009-06-20 15:32 . 2007-04-24 14:44 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-19 18:17 . 2009-01-31 15:54 -------- dc----w- c:\program files\Goto Software
2009-06-19 18:17 . 2009-01-31 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\VadeRetro
2009-06-19 18:15 . 2009-04-23 10:45 -------- dc----w- c:\program files\GlobalSCAPE
2009-06-19 18:10 . 2008-06-21 10:35 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 09:27 . 2008-07-21 18:20 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2008-06-19 19:05 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-10 16:33 . 2009-04-30 20:02 1580550 ----a-w- c:\windows\system32\nvdata.bin
2009-06-10 16:33 . 2009-04-30 20:02 1310720 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 16:33 . 2009-03-27 08:03 671744 ----a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 16:33 . 2009-03-27 08:03 1720320 ----a-w- c:\windows\system32\nvcuda.dll
2009-06-10 16:33 . 2008-05-30 20:50 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-06-10 16:33 . 2006-10-22 10:22 815104 ----a-w- c:\windows\system32\nvapi.dll
2009-06-10 16:33 . 2006-10-22 10:22 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-06-10 16:33 . 2006-10-22 10:22 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-06-10 16:33 . 2003-01-21 18:12 9998336 ----a-w- c:\windows\system32\nvoglnt.dll
2009-06-10 16:33 . 2003-01-21 18:12 8087712 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-06-10 16:33 . 2003-01-21 18:12 5908608 ----a-w- c:\windows\system32\nv4_disp.dll
2009-06-05 15:46 . 2009-04-13 09:53 -------- d-----w- c:\documents and settings\Anto2\Application Data\HLSW
2009-06-05 11:57 . 2009-06-05 11:57 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 09:42 . 2008-08-30 10:21 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-04 17:32 . 2009-06-04 17:32 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-06-04 17:31 . 2009-06-04 17:31 -------- dc----w- c:\program files\DAEMON Tools Toolbar
2009-06-04 14:39 . 2008-05-30 20:49 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-02 15:36 . 2008-12-17 20:22 -------- d-----w- c:\documents and settings\Anto2\Application Data\InstallShield
2009-06-02 15:33 . 2009-05-03 16:05 -------- d-----w- c:\documents and settings\Anto2\Application Data\Wizards of the Coast
2009-05-29 14:34 . 2009-03-30 15:58 -------- d-----w- c:\documents and settings\Anto2\Application Data\Mumble
2009-05-27 12:45 . 2009-05-27 12:45 -------- dc----w- c:\program files\Fichiers communs\Java
2009-05-17 20:19 . 2009-05-17 20:19 272384 ----a-w- c:\documents and settings\Anto2\Application Data\Acreon\WowMatrix\Modules\curl.exe
2009-05-17 20:19 . 2009-05-17 20:19 258048 ----a-w- c:\documents and settings\Anto2\Application Data\Acreon\WowMatrix\Libraries\wmzip.dll
2009-05-17 20:19 . 2009-05-17 20:19 192512 ----a-w- c:\documents and settings\Anto2\Application Data\Acreon\WowMatrix\Libraries\wmweb.dll
2009-05-17 20:19 . 2009-05-17 20:19 -------- d-----w- c:\documents and settings\Anto2\Application Data\Acreon
2009-05-17 20:02 . 2009-05-17 20:02 -------- dc----w- c:\program files\Lavalys
2009-05-13 11:00 . 2008-12-13 11:33 116272 ----a-w- c:\documents and settings\Anto2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 05:04 . 2005-04-27 14:42 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-10 17:17 . 2005-08-07 11:40 5058 ----a-w- c:\windows\Help\hhcolreg.dat
2009-05-10 17:04 . 2008-06-26 17:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-07 16:08 . 2009-05-07 16:08 -------- dc----w- c:\program files\Avira
2009-05-07 16:08 . 2009-05-07 16:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-05-07 15:33 . 2003-02-12 20:50 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-03 16:03 . 2009-05-03 16:04 492032 ------w- c:\documents and settings\Anto2\Application Data\InstallShield Installation Information\{AF7733C1-FB0B-4FED-9730-E0433AF7A2EF}\ISSetup.dll
2009-05-03 16:03 . 2009-05-03 16:04 455600 ----a-w- c:\documents and settings\Anto2\Application Data\InstallShield Installation Information\{AF7733C1-FB0B-4FED-9730-E0433AF7A2EF}\setup.exe
2009-04-30 20:02 . 2009-04-30 20:02 806912 ----a-w- c:\windows\system32\SET28.tmp
2009-04-30 20:02 . 2009-04-30 20:02 5896320 ----a-w- c:\windows\system32\SET26.tmp
2009-04-26 18:56 . 2009-04-26 18:56 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-04-19 19:50 . 2003-02-12 19:53 1847296 ----a-w- c:\windows\system32\win32k.sys
2009-04-19 18:44 . 2006-12-18 16:48 335 -c--a-w- c:\windows\nsreg.dat
2009-04-19 18:04 . 2009-04-19 18:05 80024 ----a-w- c:\windows\system32\TXGYUploader.dll
2009-04-19 18:04 . 2009-04-19 18:05 92312 ----a-w- c:\windows\system32\QMOCameraDll.dll
2009-04-19 18:04 . 2009-04-19 18:05 260248 ----a-w- c:\windows\system32\QMO.dll
2009-04-15 14:53 . 2005-08-07 19:47 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2006-05-28 14:24 . 2006-05-28 14:24 14 --sh--w- c:\windows\mswtpdxp.dll
2006-05-28 14:25 . 2006-05-28 14:24 21 --sh--w- c:\windows\prwttrxp.dll
2005-07-29 15:24 . 2006-03-21 15:07 472 --sha-r- c:\windows\RG9taW5pcXVlIEJFRFU\l36QuqcDwrp5KHLIlIo.vbs
2005-02-22 15:55 . 2008-09-04 19:30 81920 --sh--r- c:\windows\system32\aac_parser.ax.tmp
2006-08-16 13:53 . 2008-09-04 19:30 175104 --sh--r- c:\windows\system32\CoreAAC.ax.tmp
2005-01-17 22:26 . 2008-09-04 19:30 179200 --sh--r- c:\windows\system32\DiracSplitter.ax.tmp
2006-05-28 14:24 . 2006-05-28 14:24 21 --sh--w- c:\windows\system32\dpwttaxp.dll
2006-05-03 09:06 . 2008-09-04 19:30 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2008-09-04 19:30 31232 --sh--r- c:\windows\system32\msfDX.dll
2006-05-28 14:24 . 2006-05-28 14:24 14 --sh--w- c:\windows\system32\mswtpaxp.dll
2008-03-16 12:30 . 2008-09-04 19:30 216064 --sh--r- c:\windows\system32\nbDX.dll
2005-02-12 22:00 . 2008-09-04 19:30 186880 --sh--r- c:\windows\system32\RLOgg.ax.tmp
2005-02-12 22:00 . 2008-09-04 19:30 51712 --sh--r- c:\windows\system32\RLSpeexDec.ax.tmp
2005-02-12 22:00 . 2008-09-04 19:30 67584 --sh--r- c:\windows\system32\RLTheoraDec.ax.tmp
2005-02-05 22:00 . 2008-09-04 19:30 92672 --sh--r- c:\windows\system32\RLVorbisDec.ax.tmp
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="g:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-06-10 1657376]
c:\documents and settings\Anto2\Menu D‚marrer\Programmes\D‚marrage\
rncsys32.exe [2008-4-14 21504]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-20 65588]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0?\0?A\0?A??2\0\\0t?A(\0exe.Lo\0a?A??\0??????\0?
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Assistant d'Acrobat.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Assistant d'Acrobat.lnk
backup=c:\windows\pss\Assistant d'Acrobat.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Device Detector 3.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Device Detector 3.lnk
backup=c:\windows\pss\Device Detector 3.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide du logiciel HP Image Zone.lnk
backup=c:\windows\pss\Démarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^hp center.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=c:\windows\pss\Outil de mise à jour Google.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Dominique^Menu Démarrer^Programmes^Démarrage^PrevxCSI.lnk]
path=c:\documents and settings\Dominique\Menu Démarrer\Programmes\Démarrage\PrevxCSI.lnk
backup=c:\windows\pss\PrevxCSI.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"PnkBstrA"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"NMSAccessU"=2 (0x2)
"MySql"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=2 (0x2)
"C-DillaCdaC11BA"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AntiVirService"=2 (0x2)
"AntiVirScheduler"=2 (0x2)
"a2AntiMalware"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"g:\\Program Files\\uTorrent\\uTorrent.exe"=
"g:\\Dossiers Antoni\\Dofus\\UpLauncher.exe"=
"g:\\Dossiers Antoni\\Rappelz\\Win98sUpdateUtil.exe"=
"g:\\Program Files\\Zattoo\\Zattoo2.exe"=
"g:\\Program Files\\Zattoo\\zattood.exe"=
"g:\\Program Files\\Steam\\SteamApps\\hazame93\\counter-strike source\\hl2.exe"=
"c:\\.Trash-ubuntu\\Program FilesB\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\program files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\program files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\program files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\.Trash-ubuntu\\Program FilesB\\Steam\\SteamApps\\hazame93\\counter-strike source\\hl2.exe"=
"c:\\program files\\uTorrent\\uTorrent.exe"=
"g:\\Steam\\SteamApps\\hazame93\\counter-strike source\\hl2.exe"=
"g:\\Program Files\\World of Warcraft\\WoW-3.0.8.9506-to-3.0.9.9551-frFR-downloader.exe"=
"g:\\Steam\\SteamApps\\hazame93\\half-life 2 deathmatch\\hl2.exe"=
"g:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"g:\\Steam\\SteamApps\\HAZAME93\\team fortress 2\\hl2.exe"=
"g:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\program files\\Bonjour\\mDNSResponder.exe"=
"g:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\program files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\program files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57327:TCP"= 57327:TCP:Pando Media Booster
"57327:UDP"= 57327:UDP:Pando Media Booster
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [07/05/2009 18:08 108289]
R3 BENDER;Pinnacle DV/AV Capture;c:\windows\system32\drivers\bender.sys [07/08/2005 20:12 180480]
S0 pxark;pxark;c:\windows\system32\drivers\pxark.sys --> c:\windows\system32\drivers\pxark.sys [?]
S2 AntiVirUpgradeService;Avira Upgrade Service;"c:\windows\TEMP\AVSETUP_4a02fece\basic\avupgsvc.exe" /TEMPSTART:""c:\windows\TEMP\AVSETUP_4a02fece\basic\setup.exe" /NOTEMPCLEANUP /CROSSUPGRADE" --> c:\windows\TEMP\AVSETUP_4a02fece\basic\avupgsvc.exe [?]
S3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [04/03/2006 20:47 1240576]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [23/06/2009 19:21 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [23/06/2009 19:21 3072]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4066320-E4AE-11CF-B1B0-00AA00BBAD66}]
rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\fpxpress.inf,PerUserstub
.
Contenu du dossier 'Tâches planifiées'
2009-07-05 c:\windows\Tasks\User_Feed_Synchronization-{EF4E26E6-5195-4242-BC35-B87BA6B1EB15}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Examen supplémentaire -------
.
mSearch Bar = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} -
hxxp://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-a(...)
DPF: {76EE578D-314B-4755-8365-6E1722C001A2} -
hxxp://www.bahu.com/BahuPhotoUploader.cab
DPF: {87AF076E-D86D-4E87-ADDD-F05804E1F150} -
hxxps://www.virginmega.fr/DownloadManager/Release/Prod/DownMan.cab
FF - ProfilePath - c:\documents and settings\Anto2\Application Data\Mozilla\Firefox\Profiles\gcyofpgn.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr
FF - plugin: g:\program files\Adobe\Acrobat 6.0\Acrobat\browser\nppdf32.dll
FF - plugin: g:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\nprayvplugin.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: g:\program files\VideoLAN\VLC\npvlc.dll
FF - HiddenExtension: Java Console: No Registry Reference - g:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - g:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- PARAMETRES FIREFOX ----
g:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
g:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
g:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
g:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
g:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
g:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-05 16:53
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,ad,22,28,aa,12,
8e,a5,79,c8,28,51,af,b0,29,a3,98,a4,fd,48,24,7a,4e,e5,41,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,5b,49,98,f6,9f,
eb,59,21,71,3b,04,66,8b,46,0d,96,cf,56,c1,5e,f7,71,59,99,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,0c,f5,12,dd,d7,
ce,4a,33,25,da,ec,7e,55,20,c9,26,0f,09,27,ed,83,17,14,03,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,7b,ed,63,ab,91,
22,21,8a,3e,1e,9e,e0,57,5a,93,61,b6,a8,71,55,8f,9e,2c,af,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,8a,2a,c1,31,20,
3f,43,81,cd,44,cd,b9,a6,33,6c,cd,6f,28,b6,e5,a7,84,56,ef,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,77,88,cf,cb,de,
3a,df,13,b0,18,ed,a7,3f,8d,37,a4,3d,7b,47,c0,80,ad,cd,ce,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,90,a6,e2,d0,62,
39,54,68,31,77,e1,ba,b1,f8,68,02,44,e6,03,f3,c7,f6,da,6a,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,5b,95,ca,4f,fd,
61,a3,59,83,6c,56,8b,a0,85,96,ab,45,53,8c,7d,6f,aa,5b,d3,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,d6,5b,ad,75,f7,
70,33,a1,51,fa,6e,91,28,9e,14,cc,9e,e5,2d,a9,a1,c2,79,50,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,f0,fe,d1,c2,d2,
72,49,86,b1,cd,45,5a,a8,c4,f8,b9,93,b6,47,e2,ee,a1,86,75,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,02,4b,ac,2e,10,
19,49,0d,e3,0e,66,d5,eb,bc,2f,6b,e8,60,e1,20,e6,cc,0e,7c,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:05,73,21,dd,54,d8,4a,c5,69,63,d0,98,01,
da,fd,4f,fa,ea,66,7f,d4,3b,6b,70,1c,5a,d1,35,fb,df,b8,7d,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040911900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Heure de fin: 2009-07-05 16:57
ComboFix-quarantined-files.txt 2009-07-05 14:56
ComboFix2.txt 2009-07-01 12:33
Avant-CF: 25 527 508 992 octets libres
Après-CF: 25 719 853 056 octets libres
560 --- E O F --- 2009-07-05 10:54
-->Message édité par anto100 le 05/07/2009 17:01:32<--