Oui j'ai supprimé tout ce que malwarebyte a trouvé et j'ai redémarré.
J'ai désinstallé spyware doctor et fait toutes les mises à jour
Voici le rapport Combofix :
ComboFix 09-02-04.04 - Shinobi 2009-02-05 13:08:32.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2047.1590 [GMT 1:00]
Lancé depuis: c:\documents and settings\Shinobi\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
FW: Sunbelt Personal Firewall *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users.WINDOWS\Application Data\CrucialSoft Ltd
C:\InfoSat.txt
c:\windows\system32\AJlRqBeg.ini
c:\windows\system32\dceKnnnn.ini
c:\windows\system32\dceKnnnn.ini2
c:\windows\system32\geBqrSKE.dll
c:\windows\system32\urqQjjif.dll
c:\windows\system32\YHkUtBeg.ini
c:\windows\system32\YHkUtBeg.ini2
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-05 au 2009-02-05 ))))))))))))))))))))))))))))))))))))
.
2009-02-05 11:13 . 2009-02-05 11:17 11,776 --a----t- c:\windows\system32\TASKMAN_.exe
2009-02-05 11:12 . 2009-02-05 11:33 <REP> d-------- C:\rsit
2009-02-05 10:11 . 2009-02-05 10:11 <REP> d-------- c:\documents and settings\Shinobi\Application Data\Sunbelt
2009-02-05 10:11 . 2009-02-05 10:11 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Sunbelt
2009-02-05 09:00 . 2009-02-05 09:00 <REP> d-------- c:\documents and settings\NetworkService.AUTORITE NT\Application Data\Webroot
2009-02-05 08:34 . 2009-02-05 08:34 <REP> d-------- c:\documents and settings\Shinobi\Application Data\Lavasoft
2009-02-05 08:33 . 2009-02-05 08:33 <REP> d-------- c:\program files\Webroot
2009-02-05 08:33 . 2009-02-05 08:33 <REP> d-------- c:\documents and settings\LocalService.AUTORITE NT\Application Data\Webroot
2009-02-05 08:33 . 2009-02-05 08:33 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Webroot
2009-02-05 08:33 . 2007-03-01 19:54 144,960 --a------ c:\windows\system32\drivers\ssidrv.sys
2009-02-05 08:33 . 2007-03-01 19:54 22,080 --a------ c:\windows\system32\drivers\sshrmd.sys
2009-02-05 08:33 . 2007-03-01 19:54 21,056 --a------ c:\windows\system32\drivers\sskbfd.sys
2009-02-05 08:33 . 2007-03-01 19:54 20,544 --a------ c:\windows\system32\drivers\SSFS0509.sys
2009-02-05 08:32 . 2009-02-05 08:32 <REP> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-02-05 08:32 . 2009-02-05 09:52 <REP> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-02-05 08:32 . 2009-02-05 08:32 <REP> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-02-05 08:32 . 2009-02-05 08:32 <REP> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-02-05 08:32 . 2009-02-05 08:32 164 --a------ C:\install.dat
2009-02-05 08:25 . 2009-02-05 10:11 <REP> d-------- c:\program files\Hitman Pro
2009-02-05 08:12 . 2009-02-05 08:12 <REP> d-------- c:\program files\Trend Micro
2009-02-05 07:27 . 2008-06-21 04:54 65,576 --a------ c:\windows\system32\drivers\SbFwIm.sys
2009-02-05 07:26 . 2009-02-05 10:11 <REP> d-------- c:\program files\Sunbelt Software
2009-02-05 07:26 . 2008-10-31 07:09 270,888 -ra------ c:\windows\system32\drivers\SbFw.sys
2009-02-05 06:48 . 2009-02-05 06:49 4,507 --a------ c:\windows\imsins.BAK
2009-02-05 03:28 . 2009-02-05 07:12 81,984 --a------ c:\windows\system32\bdod.bin
2009-02-05 03:25 . 2009-02-05 07:12 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2009-02-05 03:24 . 2009-02-05 07:13 <REP> d-------- c:\program files\Fichiers communs\Softwin
2009-02-05 02:56 . 2009-02-05 02:56 56,320 --a------ c:\windows\system32\tuvUoPgf.dll.vir
2009-02-05 01:39 . 2009-02-05 01:49 <REP> d-------- c:\program files\BHODemon 2
2009-02-05 01:31 . 2009-02-05 01:31 <REP> d-------- C:\VundoFix Backups
2009-02-04 23:31 . 2009-02-05 01:03 153 --a------ c:\windows\wininit.ini
2009-02-04 11:38 . 2009-02-05 08:30 <REP> d-------- c:\program files\Lavasoft
2009-02-04 11:31 . 2009-02-05 08:31 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-02-04 11:23 . 2006-11-17 09:46 96,256 --a------ c:\windows\system32\CddbLangE.dll
2009-02-04 09:49 . 2009-02-04 09:49 <REP> d-------- c:\windows\system32\Kaspersky Lab
2009-02-04 09:33 . 2009-02-04 09:33 <REP> d-------- c:\program files\Avira
2009-02-04 08:19 . 2009-02-04 08:34 <REP> d-------- C:\Combo-Fix
2009-02-04 07:09 . 2009-02-04 07:09 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-04 07:09 . 2008-09-08 00:16 38,528 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 07:09 . 2008-09-08 00:16 17,200 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-04 07:05 . 2009-02-04 07:07 <REP> d-------- c:\program files\Registry Repair
2009-02-04 06:45 . 2009-02-05 11:17 69,120 --a----t- c:\documents and settings\Shinobi\notepad.exe
2009-01-31 20:25 . 2009-01-31 20:25 5,632 --ahs---- c:\windows\Thumbs.db
2009-01-22 13:05 . 2009-01-22 13:05 <REP> d-------- c:\windows\Logs
2009-01-17 05:44 . 2009-01-17 05:44 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
2009-01-15 06:09 . 2009-01-15 06:45 <REP> d-------- c:\program files\ICCup
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-05 12:03 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-02-05 09:02 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-02-05 06:13 --------- d-----w c:\program files\Utilitaires
2009-02-05 06:13 --------- d-----w c:\program files\DivX
2009-02-04 23:40 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-02-04 22:31 --------- d-----w c:\program files\Enigma Software Group
2009-02-04 08:33 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Avira
2009-02-03 10:48 --------- d-----w c:\documents and settings\Shinobi\Application Data\ppStream
2009-02-03 06:19 304,052 ----atw c:\windows\system32\notepad.exe
2009-02-03 05:58 --------- d-----w c:\documents and settings\Shinobi\Application Data\uTorrent
2009-01-23 17:32 --------- d-----w c:\documents and settings\Shinobi\Application Data\FileZilla
2009-01-22 11:53 --------- d-----w c:\program files\Jeux
2009-01-17 02:34 --------- d-----w c:\program files\Autodesk
2009-01-08 19:05 --------- d-----w c:\program files\Fichiers communs\Blizzard Entertainment
2009-01-03 16:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\PPLiveVA
2009-01-03 16:02 --------- d-----w c:\documents and settings\Shinobi\Application Data\PPLiveVA
2009-01-03 15:51 --------- d-----w c:\program files\PPStream
2008-12-22 21:05 --------- d-----w c:\documents and settings\Shinobi\Application Data\vlc
2008-12-20 17:31 --------- d-----w c:\program files\Chaoslauncher
2008-12-14 18:51 --------- d-----w c:\program files\Messenger Plus! Live
2008-12-06 00:36 --------- d-----w c:\program files\Craft Animations
2008-12-05 04:05 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS
2008-12-05 04:03 --------- d-----w c:\documents and settings\Shinobi\Application Data\ProxyCap
2008-11-11 14:28 98,304 ----a-w c:\windows\system32\CmdLineExt.dll
2007-12-20 17:45 22,328 ----a-w c:\documents and settings\Shinobi\Application Data\PnkBstrK.sys
2007-12-08 06:50 22,328 ----a-w c:\documents and settings\Administrateur\Application Data\PnkBstrK.sys
.
------- Sigcheck -------
2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2006-02-14 20:56 359808 667192a11db19f36624119c0dd4de4f2 c:\windows\$NtUninstallKB941644$\tcpip.sys
2008-08-06 04:25 360064 01307b76a916a8f6d1f1452744ba7ad6 c:\windows\system32\backup\tcpip.sys
2007-10-30 18:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\system32\dllcache\tcpip.sys
2007-10-30 18:20 360064 34a663e7f74ae8b2c992c2513343477e c:\windows\system32\drivers\tcpip.sys
2006-03-09 09:25 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe
2007-07-30 19:19 68440 84d9a61860272d6177d46c86b8431557 c:\windows\system32\wuauclt.exe
2007-07-30 19:19 68440 84d9a61860272d6177d46c86b8431557 c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-04 8491008]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-02 185896]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 262401]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-01 4865600]
"SBAMTray"="c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe" [2008-08-26 677160]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Config"="c:\windows\system32\run.cmd" [2006-02-14 248]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-19 44544]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
WiFi Station pour Livebox.lnk - c:\program files\Drivers\Hercules\WiFi Station\WiFi Station pour Livebox\WifiStationLB.exe [2008-10-26 721408]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoStrCmpLogical"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Fichiers communs\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"VIDC.XFR1"= xfcodec.dll
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\[u]0/uautocheck autochk *\[u]0/ulsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^WiFi Station pour Livebox.lnk]
backup=c:\windows\pss\WiFi Station pour Livebox.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"DisablePagingExecutive"=dword:00000001
"SecondLevelDataCache"=dword:00000200
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Logiciels 3D\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\DAUM\\PotPlayer\\daumvsvr.exe"=
"c:\\Program Files\\DAUM\\PotPlayer\\PotPlayer.exe"=
"c:\\PROGRA~1\\DAUM\\POTPLA~1\\PotPlayer.exe"=
"c:\\Program Files\\PPStream\\PPStream.exe"=
"c:\\Program Files\\PPStream\\PPSAP.exe"=
"c:\\Program Files\\DAUM\\PotPlayer\\PotPlayerMini.exe"=
"c:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\NexonUS\\NGM\\NGM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3681:TCP"= 3681:TCP:messenger
"7881:TCP"= 7881:TCP:messenger
"8337:TCP"= 8337:TCP:messenger
"3532:TCP"= 3532:TCP:messenger
"2381:TCP"= 2381:TCP:messenger
"5836:TCP"= 5836:TCP:messenger
"5672:TCP"= 5672:TCP:messenger
"2787:TCP"= 2787:TCP:messenger
"6814:TCP"= 6814:TCP:messenger
"5448:TCP"= 5448:TCP:messenger
"8622:TCP"= 8622:TCP:messenger
"8557:TCP"= 8557:TCP:messenger
"4137:TCP"= 4137:TCP:messenger
"8118:TCP"= 8118:TCP:messenger
"1888:TCP"= 1888:TCP:messenger
"2854:TCP"= 2854:TCP:messenger
"4434:TCP"= 4434:TCP:messenger
"3515:TCP"= 3515:TCP:messenger
"4363:TCP"= 4363:TCP:messenger
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [2007-12-17 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [2007-12-17 52224]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [2009-02-05 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [2008-06-21 66600]
R2 PD91Agent;PD91Agent;c:\program files\Utilitaires\Raxco\PerfectDisk2008\PD91Agent.exe [2008-09-09 693512]
R2 SBAMSvc;Sunbelt VIPRE Antivirus Service;c:\program files\Sunbelt Software\CounterSpy\SBAMSvc.exe [2008-08-26 869672]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [2009-02-05 65576]
S2 sfmgr;CaReTaKeR-CT NetMgr 1.2.1;c:\program files\Logiciels 3D\Autodesk\3ds Max 9\plugins\Brazil\sfmgr1_2_1\sfmgr.exe --> c:\program files\Logiciels 3D\Autodesk\3ds Max 9\plugins\Brazil\sfmgr1_2_1\sfmgr.exe [?]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S3 GOBBLER;GOBBLER;\??\c:\windows\system32\drivers\GOBBLER.SYS --> c:\windows\system32\drivers\GOBBLER.SYS [?]
S3 PD91Engine;PD91Engine;c:\program files\Utilitaires\Raxco\PerfectDisk2008\PD91Engine.exe [2008-09-09 906504]
S3 PD91VMDefrag;PD91VMDefrag;c:\program files\Utilitaires\Raxco\PerfectDisk2008\PD91VMDefrag.exe [2008-02-29 226568]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2007-11-06 87848]
S3 WZCOOK;WEP/WPA-PMK key recovery service;"c:\documents and settings\Shinobi\Bureau\WinAircrack\WinAircrackPack\wzcook.exe" --> c:\documents and settings\Shinobi\Bureau\WinAircrack\WinAircrackPack\wzcook.exe [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4bc909aa-ad56-11dc-ba9f-00196639a9f3}]
\Shell\AutoRun\command - G:\SETUP.EXE
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mSearchMigratedDefaultURL = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mSearchURL = hxxp://www.google.com/
IE: &Download with &DAP - c:\program files\Utilitaires\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\Utilitaires\DAP\dapextie2.htm
IE: Tout télécharger avec NetXfer - c:\program files\Utilitaires\Xi\NetXfer\NetXfer\NXAddList.html
IE: Télécharger avec NetXfer - c:\program files\Utilitaires\Xi\NetXfer\NetXfer\NXAddLink.html
Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\UTILIT~1\DAP\dapie.dll
Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\UTILIT~1\DAP\dapie.dll
DPF: {688C15EE-9C38-471D-9E46-BB842E30246F} - hxxp://www.playple.com/liveviewer/cab/NChat7.cab
DPF: {8EEB54D5-CC70-40E4-B015-AC478C02ECC8} - hxxp://www.playple.com/liveviewer/cab/SLViewer.cab
FF - ProfilePath - c:\documents and settings\Shinobi\Application Data\Mozilla\Firefox\Profiles\3r624dtn.default\
FF - prefs.js: browser.startup.homepage - google.fr
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Logiciels 2D\Adobe\Reader 8.0\Reader\browser\nppdf32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-05 13:15:21
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1659004503-838170752-725345543-1003\SOFTWARE\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d0,55,84,8a,33,30,28,34,67,55,6d,fc,95,7f,80,da,d4,2f,f7,11,b1,d6,9c,
2f,73,c5,70,20,d9,35,ab,0e,85,bc,50,3b,7b,17,09,24,99,0f,5a,db,d3,f2,3d,8d,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\klogon.dll
c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll
c:\program files\fichiers communs\logishrd\bluetooth\LBTServ.dll
c:\windows\system32\WRLogonNTF.dll
- - - - - - - > 'explorer.exe'(1260)
c:\windows\system32\ntshrui.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\DCPFLICS\DCPFLICS.exe
c:\program files\Logiciels 3D\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
c:\program files\Logiciels 3D\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
c:\program files\Utilitaires\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\program files\Sunbelt Software\Personal Firewall\SbPFCl.exe
.
**************************************************************************
.
Heure de fin: 2009-02-05 13:21:39 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-02-05 12:21:33
ComboFix2.txt 2009-02-04 07:34:09
Avant-CF: 5 425 856 512 octets libres
Après-CF: 5,780,627,456 octets libres
278 --- E O F --- 2008-02-05 02:05:00