Voila j'ai fait ce que vous m'avez demandé
Le rapport nous donne sa :
ComboFix 09-02-19.01 - Bonne année 2009-02-21 23:04:37.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.1.1252.1.1036.18.1535.1115 [GMT 1:00]
Lancé depuis: c:\documents and settings\Bonne année\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-21 au 2009-02-21 ))))))))))))))))))))))))))))))))))))
.
2009-02-20 21:55 . 2009-02-20 21:55 <REP> d-------- c:\program files\Skype
2009-02-20 21:55 . 2009-02-20 21:55 <REP> d-------- c:\program files\Fichiers communs\Skype
2009-02-19 13:26 . 2009-02-19 13:26 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-19 13:26 . 2009-02-19 13:26 <REP> d-------- c:\documents and settings\Bonne année\Application Data\Malwarebytes
2009-02-19 13:26 . 2009-02-19 13:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-19 13:26 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-19 13:26 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-17 18:21 . 2005-03-02 19:21 562,176 --a--c--- c:\windows\system32\dllcache\user32.dll
2009-02-17 18:20 . 2009-02-17 18:20 <REP> d-------- c:\windows\ERUNT
2009-02-17 18:15 . 2009-02-17 18:27 <REP> d-------- C:\SDFix
2009-02-17 14:05 . 2009-02-17 14:06 <REP> d-------- c:\program files\Pando Networks
2009-02-17 11:56 . 2009-02-17 11:56 <REP> d-------- c:\program files\Audacity
2009-02-16 21:52 . 2009-02-16 21:52 0 --a------ c:\windows\mngui.INI
2009-02-16 14:03 . 2009-02-16 14:03 <REP> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-15 08:55 . 2009-02-15 08:55 24,576 --a------ C:\U.MSNFix
2009-02-14 19:16 . 2009-02-14 19:16 <REP> d-------- c:\windows\Logs
2009-02-14 19:07 . 2009-02-14 19:08 <REP> d-------- c:\documents and settings\Bonne année\Application Data\Sony Setup
2009-02-14 19:06 . 2009-02-14 19:06 <REP> d-------- c:\program files\Sony Setup
2009-02-11 18:38 . 2009-02-11 18:38 45,056 -r-hs---- c:\windows\winlogox.exe
2009-02-11 17:58 . 2009-02-11 17:58 24,576 --a------ c:\windows\taskmgr.MSNFix
2009-02-09 20:54 . 2004-07-17 11:40 19,528 --a------ c:\windows\[u]0/u03321_.tmp
2009-02-09 14:04 . 2009-02-09 14:04 25,873 --a------ c:\windows\system32\30.scr
2009-02-09 13:49 . 2009-02-09 13:49 26,017 --a------ c:\windows\system32\40.scr
2009-02-09 13:44 . 2009-02-09 14:01 26,017 --a------ c:\windows\system32\28.scr
2009-02-09 13:42 . 2009-02-09 13:42 24,577 --a------ c:\windows\system32\71.scr
2009-02-09 13:39 . 2009-02-09 13:39 25,957 --a------ c:\windows\system32\70.scr
2009-02-09 12:38 . 2009-02-09 12:38 26,017 --a------ c:\windows\system32\65.scr
2009-02-09 12:32 . 2009-02-09 12:32 25,957 --a------ c:\windows\system32\21.scr
2009-02-08 22:37 . 2004-07-17 11:40 19,528 --a------ c:\windows\[u]0/u02416_.tmp
2009-02-08 22:30 . 2004-07-17 11:40 19,528 --a------ c:\windows\[u]0/u03586_.tmp
2009-02-08 22:25 . 2009-02-08 22:25 25,873 --a------ c:\windows\system32\[u]0/u4.scr
2009-02-08 22:16 . 2004-01-10 06:11 26,112 --a------ c:\windows\system32\xpsp1hfm.exe
2009-02-08 22:15 . 2009-02-08 22:15 25,873 --a------ c:\windows\system32\33.scr
2009-02-08 22:15 . 2009-02-08 22:15 25,873 --a------ c:\windows\system32\20.scr
2009-02-08 22:14 . 2009-02-08 22:14 25,873 --a------ c:\windows\system32\77.scr
2009-02-08 22:14 . 2009-02-08 22:14 25,873 --a------ c:\windows\system32\75.scr
2009-02-08 22:05 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-08 22:05 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-08 21:13 . 2009-02-08 21:13 233,272 --a------ c:\windows\system32\bt.exe
2009-02-08 20:46 . 2009-02-08 20:46 <REP> d-------- c:\program files\ahead
2009-02-08 20:46 . 2009-02-08 20:46 <REP> d-------- c:\documents and settings\Bonne année\WINDOWS
2009-02-08 20:46 . 2009-02-08 20:46 <REP> d-------- c:\documents and settings\Bonne année\WINDOWS
2009-02-08 20:46 . 1996-02-08 09:54 284,160 --a------ c:\windows\unin040c.exe
2009-02-08 16:21 . 2009-02-16 21:45 <REP> d-------- c:\windows\fix
2009-02-08 11:50 . 2009-02-08 22:14 25,873 --a------ c:\windows\system32\82.scr
2009-02-08 11:46 . 2009-02-09 12:49 25,957 --a------ c:\windows\system32\80.scr
2009-02-08 11:17 . 2009-02-08 11:17 25,733 --a------ c:\windows\system32\38.scr
2009-02-08 10:26 . 2009-02-08 10:26 120 --a------ c:\windows\system32\smczzhn.bat
2009-02-06 12:02 . 2009-02-06 12:02 44,018 --a------ c:\windows\system32\mdm.MSNFix
2009-02-02 22:56 . 2009-02-17 14:04 <REP> d-------- c:\program files\Free Audio Pack
2009-02-02 22:56 . 2004-03-09 00:00 662,288 --a------ c:\windows\system32\MSCOMCT2.OCX
2009-02-02 22:56 . 2004-03-09 00:00 224,016 --a------ c:\windows\system32\TABCTL32.OCX
2009-02-02 22:56 . 1998-06-24 01:00 164,144 --a------ c:\windows\system32\COMCT232.OCX
2009-02-02 22:56 . 2004-03-09 00:00 152,848 --a------ c:\windows\system32\COMDLG32.OCX
2009-02-02 22:56 . 1998-07-13 00:00 141,312 --a------ c:\windows\system32\MSCMCFR.DLL
2009-02-02 22:56 . 2000-10-01 20:00 119,568 --a------ c:\windows\system32\VB6FR.DLL
2009-02-02 22:56 . 2000-05-22 16:58 115,920 --a------ c:\windows\system32\msinet.OCX
2009-02-02 22:56 . 1999-03-25 20:00 101,888 --a------ c:\windows\system32\VB6STKIT.DLL
2009-02-02 22:56 . 1998-07-13 00:00 59,904 --a------ c:\windows\system32\Mscc2fr.dll
2009-02-02 22:56 . 1998-07-12 20:00 32,768 --a------ c:\windows\system32\CMDLGFR.DLL
2009-02-02 22:56 . 1998-07-13 00:00 21,504 --a------ c:\windows\system32\TABCTFR.DLL
2009-02-02 22:56 . 1998-07-13 00:00 15,360 --a------ c:\windows\system32\inetfr.DLL
2009-01-31 22:02 . 2009-02-14 18:21 <REP> d-------- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-01-25 12:57 . 2008-09-24 10:40 4,122,368 -ra------ c:\windows\system32\drivers\alcxwdm.sys
2009-01-25 12:57 . 2007-04-16 15:28 577,536 --a------ c:\windows\soundman.exe
2009-01-25 12:57 . 2002-08-29 02:01 134,272 --a------ c:\windows\system32\drivers\portcls.sys
2009-01-25 12:57 . 2002-08-29 02:01 134,272 --a--c--- c:\windows\system32\dllcache\portcls.sys
2009-01-25 12:57 . 2002-08-29 02:13 131,712 --a------ c:\windows\system32\drivers\ks.sys
2009-01-25 12:57 . 2002-08-29 02:13 131,712 --a--c--- c:\windows\system32\dllcache\ks.sys
2009-01-25 12:57 . 2002-08-29 01:32 57,856 --a------ c:\windows\system32\drivers\drmk.sys
2009-01-25 12:57 . 2002-08-29 01:32 57,856 --a--c--- c:\windows\system32\dllcache\drmk.sys
2009-01-25 12:57 . 2006-08-01 15:02 49,152 --a------ c:\windows\system32\ChCfg.exe
2009-01-25 12:57 . 2002-08-29 01:32 44,416 --a------ c:\windows\system32\drivers\stream.sys
2009-01-25 12:57 . 2002-08-29 01:32 44,416 --a--c--- c:\windows\system32\dllcache\stream.sys
2009-01-25 12:56 . 2009-01-25 12:56 <REP> d-------- c:\program files\Realtek AC97
2009-01-25 12:56 . 2006-07-31 11:27 217,088 --a------ c:\windows\Alcrmv.exe
2009-01-24 13:48 . 2009-02-21 22:57 <REP> d-------- c:\program files\Steam
2009-01-22 14:00 . 2006-09-04 07:24 1,351,680 -----c--- c:\windows\system32\dllcache\shdocvw.dll
2009-01-22 14:00 . 2006-09-04 07:24 1,027,584 -----c--- c:\windows\system32\dllcache\browseui.dll
2009-01-22 12:21 . 2006-07-14 16:36 519,168 -----c--- c:\windows\system32\dllcache\hhctrl.ocx
2009-01-21 10:55 . 2006-07-14 16:56 307,200 -----c--- c:\windows\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-21 22:01 --------- d-----w c:\documents and settings\Bonne année\Application Data\Skype
2009-02-21 21:38 --------- d-----w c:\program files\BitComet
2009-02-21 16:57 --------- d-----w c:\documents and settings\Bonne année\Application Data\skypePM
2009-02-21 13:26 --------- d-----w c:\program files\MiniLyrics
2009-02-20 20:55 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-16 13:49 --------- d-----w c:\program files\MSN Messenger
2009-02-07 10:32 135,168 ----a-w c:\windows\system32\sfc_os.dll
2009-01-28 21:41 --------- d-----w c:\program files\DivX
2009-01-25 10:55 --------- d-----w c:\program files\ma-config.com
2009-01-25 10:55 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-01-20 17:24 --------- d-----w c:\program files\FileZilla
2009-01-19 17:59 --------- d-----w c:\documents and settings\Bonne année\Application Data\Teleca
2009-01-18 18:29 --------- d-----w c:\documents and settings\Bonne année\Application Data\Sony Ericsson
2009-01-18 18:17 --------- d-----w c:\program files\Fichiers communs\Teleca Shared
2009-01-18 18:17 --------- d-----w c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-01-18 18:16 --------- d-----w c:\program files\Sony Ericsson
2009-01-18 18:16 --------- d-----w c:\program files\Fichiers communs\Sony Ericsson Shared
2009-01-18 18:16 --------- d-----w c:\documents and settings\All Users\Application Data\Teleca
2009-01-12 20:14 --------- d-----w c:\program files\Microsoft.NET
2009-01-12 19:18 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-11 13:25 --------- d--h--w c:\documents and settings\All Users\Application Data\CanonBJ
2009-01-10 20:34 --------- d-----w c:\documents and settings\Bonne année\Application Data\Apple Computer
2009-01-10 13:22 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-01-09 19:21 --------- d-----w c:\program files\ESET
2009-01-09 19:21 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-01-04 19:28 --------- d-----w c:\documents and settings\Bonne année\Application Data\Sony Corporation
2009-01-04 17:27 --------- d-----w c:\program files\Sony
2009-01-04 17:26 --------- d-----w c:\documents and settings\All Users\Application Data\Sony Corporation
2009-01-04 17:25 --------- d-----w c:\program files\Fichiers communs\Sony Shared
2009-01-04 16:29 --------- d-----w c:\program files\Guitar Pro 5
2009-01-04 16:28 --------- d-----w c:\program files\MagicISO
2009-01-04 14:42 --------- d-----w c:\program files\Google
2009-01-04 14:00 --------- d-----w c:\program files\QuickTime
2009-01-04 14:00 --------- d-----w c:\program files\iTunes
2009-01-04 14:00 --------- d-----w c:\program files\iPod
2009-01-04 14:00 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-04 13:59 --------- d-----w c:\program files\Apple Software Update
2009-01-04 12:23 --------- d-----w c:\documents and settings\Bonne année\Application Data\InterTrust
2009-01-04 12:22 --------- d-----w c:\program files\Creative
2009-01-04 12:13 60,416 ----a-w c:\windows\ALCFDRTM.EXE
2009-01-02 13:42 --------- dc----w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-01-02 13:42 --------- d-----w c:\program files\Mirage-Team Decoder Pack
2009-01-02 13:42 --------- d-----w c:\program files\K-Lite Codec Pack
2009-01-02 13:34 --------- d-----w c:\program files\Services en ligne
2009-01-02 13:24 --------- d-----w c:\program files\Ontrack
2009-01-02 13:14 --------- d-----w c:\documents and settings\Bonne année\Application Data\Uniblue
2009-01-02 13:13 --------- d-----w c:\documents and settings\Bonne année\Application Data\MSN6
2009-01-01 16:13 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2009-01-01 15:57 --------- d-----w c:\program files\Winamp
2009-01-01 15:56 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-01 15:56 --------- d-----w c:\documents and settings\Bonne année\Application Data\Media Player Classic
2009-01-01 15:45 --------- d-----w c:\program files\Webteh
2009-01-01 15:44 99,970 ----a-w c:\windows\UninstallFirefox.exe
2009-01-01 15:39 --------- d-----w c:\program files\Realtek Sound Manager
2009-01-01 15:39 --------- d-----w c:\program files\AvRack
2009-01-01 15:38 --------- d-----w c:\program files\Marvell
2009-01-01 15:38 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-01-01 15:36 --------- d-----w c:\program files\Intel
2009-01-01 14:56 --------- d-----w c:\program files\Sygate
2009-01-01 14:56 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-01 14:56 --------- d-----w c:\program files\Alwil Software
2009-01-01 14:43 --------- d-----w c:\program files\microsoft frontpage
2008-12-08 11:53 57,344 ----a-w c:\windows\system32\ff_vfw.dll
2008-12-07 18:08 795,648 ----a-w c:\windows\system32\xvidcore.dll
2008-12-07 18:08 130,048 ----a-w c:\windows\system32\xvidvfw.dll
2008-12-17 23:04 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-17 23:04 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-17 23:04 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-17 23:04 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-17 23:04 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\ctfmon.exe" [2002-08-29 13312]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-01 21898024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2002-08-28 208953]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-28 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-28 455168]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2005-09-27 2635472]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-09-20 4583424]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-09-20 86016]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-02-13 35328]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"nwiz"="nwiz.exe" [2004-09-20 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2002-08-29 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-03-14 19:05 257088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-02-16 10:54 282624 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2007-01-26 13:36 495616 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-07-01 34312]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
R3 ZSMC302;VIMICRO USB PC Camera;c:\windows\system32\drivers\usbVM31b.sys [2009-01-12 90568]
S2 NirSoft Service Controler;NirSoft Service Controler;"c:\windows\system32\drivers\NirCmd.exe" --> c:\windows\system32\drivers\NirCmd.exe [?]
S2 WMISYNC;Wmi Sync Manager;"c:\windows\system\wmisync.exe" --> c:\windows\system\wmisync.exe [?]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-01-24 216232]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\system32\drivers\sea1bus.sys [2009-01-18 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\system32\drivers\sea1mdfl.sys [2009-01-18 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\system32\drivers\sea1mdm.sys [2009-01-18 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\sea1mgmt.sys [2009-01-18 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\system32\drivers\sea1nd5.sys [2009-01-18 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\system32\drivers\sea1obex.sys [2009-01-18 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\system32\drivers\sea1unic.sys [2009-01-18 90800]
.
Contenu du dossier 'Tâches planifiées'
2009-02-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Microsoft Msn Messenger - c:\windows\System32\msmsgs.exe
HKCU-Run-Microsoft Visual Debuger - c:\windows\System32\mdm.exe
HKCU-Run-Microsft managr - c:\windows\taskmgr.exe
HKLM-Run-Microsoft Visual Debuger - c:\windows\System32\mdm.exe
HKLM-Run-Microsft managr - c:\windows\taskmgr.exe
HKU-Default-Run-Microsoft Msn Messenger - c:\windows\System32\msmsgs.exe
HKU-Default-Run-Microsoft Visual Debuger - c:\windows\System32\mdm.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Tout télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Télécharger toutes les vidéos avec BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
FF - ProfilePath - c:\documents and settings\Bonne année\Application Data\Mozilla\Firefox\Profiles\ztroql2j.default\
FF - prefs.js: browser.search.selectedEngine - Recherche de vidéos YouTube
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\Bonne année\Application Data\Mozilla\Firefox\Profiles\ztroql2j.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-21 23:05:46
Windows 5.1.2600 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\x2æwÿÿÿÿ_åwÿcÑw*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\ODBC32.dll
c:\windows\System32\msctfime.ime
- - - - - - - > 'lsass.exe'(784)
c:\windows\System32\dssenh.dll
.
Heure de fin: 2009-02-21 23:06:51
ComboFix-quarantined-files.txt 2009-02-21 22:06:49
Avant-CF: 4 943 642 624 octets libres
Après-CF: 5,001,318,400 octets libres
263 --- E O F --- 2009-02-20 19:26:30