Voilà le rapport (la console a été installée !) :
ComboFix 09-07-05.04 - Dad 07/07/2009 8:59.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1023.652 [GMT 2:00]
Lancé depuis: c:\documents and settings\Dad\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Dad\Bureau\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
AV: avast! antivirus 4.8.1335 [VPS 090706-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Fichiers communs\download
c:\program files\Internet Explorer\fxavx.ini
c:\windows\Installer\1c112e.msi
c:\windows\Installer\eda878.msi
c:\windows\patch.exe
c:\windows\system32\uninstall.exe
T:\INSTALL.EXE
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-07 au 2009-07-07 ))))))))))))))))))))))))))))))))))))
.
2009-07-06 16:22 . 2009-07-06 16:22 -------- d-----w- c:\program files\AskBardis
2009-07-06 16:15 . 2009-07-06 16:15 -------- d-----w- C:\_OTM
2009-07-06 12:20 . 2009-07-06 12:20 -------- d-----w- c:\documents and settings\Dad\Application Data\Malwarebytes
2009-07-06 12:19 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-06 12:19 . 2009-07-06 12:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-06 12:19 . 2009-07-06 12:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-06 12:19 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-04 12:53 . 2009-07-04 12:57 -------- d-----w- C:\ToolBar SD
2009-07-02 05:29 . 2009-07-02 05:29 -------- d-----w- c:\windows\system32\Adobe
2009-07-01 05:45 . 2009-07-01 05:45 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-06-30 08:09 . 2009-06-30 08:09 -------- d-----w- C:\NRH
2009-06-30 07:57 . 2009-06-30 07:58 -------- d-----w- c:\program files\FormatFactory
2009-06-27 17:58 . 2009-06-27 17:58 10684866 ----a-w- c:\documents and settings\Dad\Application Data\Azureus\plugins\azump\mplayer.exe
2009-06-27 13:41 . 2009-06-27 13:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-06-27 13:41 . 2009-07-01 12:40 -------- d-----w- c:\documents and settings\Dad\Application Data\Azureus
2009-06-27 13:39 . 2009-06-27 13:39 -------- d-----w- c:\program files\Vuze
2009-06-22 15:47 . 2009-06-22 15:47 -------- d-----w- C:\rsit
2009-06-22 15:39 . 2009-06-22 15:39 -------- d-----w- c:\program files\CCleaner
2009-06-22 15:07 . 2009-06-22 15:07 578560 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-06-22 15:03 . 2009-06-22 15:03 -------- d-----w- c:\windows\ERUNT
2009-06-22 14:53 . 2009-06-22 15:29 -------- d-----w- C:\SDFix
2009-06-12 06:41 . 2009-06-12 06:41 2496 ----a-w- c:\documents and settings\Dad\Local Settings\Application Data\d3d8caps.dat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-07 05:43 . 2004-12-22 08:42 3044 ----a-w- c:\windows\system32\d3d8caps.dat
2009-07-06 05:56 . 2007-02-08 09:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-30 16:19 . 2008-11-18 08:29 -------- d-----w- c:\documents and settings\Dad\Application Data\Canon
2009-06-30 10:23 . 2008-12-28 14:26 -------- d-----w- c:\program files\MediaCoder
2009-06-29 06:21 . 2005-03-28 10:24 2608 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-23 16:28 . 2008-12-13 11:05 -------- d-----w- c:\program files\AVS4YOU
2009-06-22 15:44 . 2005-11-16 11:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-22 14:42 . 2005-11-16 11:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-22 05:29 . 2006-07-27 14:25 -------- d-----w- c:\program files\SpeedFan
2009-06-20 05:33 . 2005-12-13 17:16 -------- d-----w- c:\program files\Google
2009-06-17 13:00 . 2006-05-25 09:28 -------- d-----w- c:\program files\ImageCollection
2009-06-15 16:04 . 2007-02-02 15:00 -------- d-----w- c:\documents and settings\Dad\Application Data\XnView
2009-05-31 15:58 . 2009-03-03 07:47 -------- d-----w- c:\program files\Celtx
2009-05-27 05:38 . 2006-12-15 16:33 -------- d-----w- c:\program files\DivX
2009-05-27 05:37 . 2009-05-27 05:37 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-05-20 18:42 . 2005-11-12 17:40 63128 ----a-w- c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 14:09 . 2009-05-19 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2009-05-19 14:09 . 2006-11-12 14:50 -------- d-----w- c:\documents and settings\Dad\Application Data\Ahead
2009-05-15 06:15 . 2006-11-10 11:32 -------- d-----w- c:\program files\a-squared Free
2009-05-07 15:43 . 2001-09-28 12:00 347136 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:45 . 2005-10-21 15:50 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:45 . 2004-08-19 23:09 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 20:09 . 2001-09-28 12:00 1846784 ----a-w- c:\windows\system32\win32k.sys
2009-04-16 09:36 . 2001-09-28 12:00 71248 ----a-w- c:\windows\system32\perfc00C.dat
2009-04-16 09:36 . 2001-09-28 12:00 458230 ----a-w- c:\windows\system32\perfh00C.dat
2009-04-15 15:17 . 2004-03-06 02:17 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2006-11-20 16:58 . 2006-11-20 16:58 604 ---ha-w- c:\program files\STLL Notifier
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2006-05-29 14:40 . 2007-05-30 16:59 7296000 ----a-w- c:\program files\mozilla firefox\plugins\libvlc.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
2007-10-19 10:33 . 2006-12-13 13:37 502012205 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-03 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"Google Update"="c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-17 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Matrox Powerdesk"="c:\windows\system32\PDesk\PDesk.exe" [2006-03-02 684032]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-12 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Dad\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Pense-Bete.lnk - c:\bureaudad\Pense-Bete.mdb [2006-12-18 593920]
SpamPal.lnk - c:\program files\SpamPal\spampal.exe [2005-10-24 387616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FileZilla\\FileZilla.exe"=
"c:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"=
"c:\\Program Files\\GeneWeb-4.10\\gw\\gwd.exe"=
"c:\\Program Files\\GeneWeb-4.10\\gw\\gwsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\program files\adslTV\adsltv.exe"= c:\program files\adslTV\adsltv.exe:212.27.38.253/255.255.255.255:Enabled:adsltv
"c:\\Program Files\\adslTV\\vlc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Canon\\DV Messenger\\DV Messenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\EXCEL.EXE"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30/03/2008 07:59 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/03/2008 07:59 20560]
S2 gupdate1c9be69df746cc4;Google Update Service (gupdate1c9be69df746cc4);c:\program files\Google\Update\GoogleUpdate.exe [16/04/2009 10:03 133104]
S3 CrystalSysInfo;CrystalSysInfo;c:\program files\MediaCoder\SysInfo.sys [25/09/2007 16:59 15152]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\drivers\fbxusb32.sys [15/03/2006 09:49 21344]
S3 G550DH;G550DH;c:\windows\system32\drivers\g550dhm.sys [28/09/2001 20:13 324747]
S3 Netlddcncfkf;Netlddcncfkf; [x]
S3 Sedesfendihn;Sedesfendihn;c:\windows\system32\ie4uinit.exe [30/03/2005 15:25 70656]
S3 Swrelik2_ipn;Swrelik2_ipn; [x]
S3 UtilNT;UtilNT;c:\windows\system32\drivers\utilnt.sys [23/12/2004 09:29 5533]
S3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;c:\windows\system32\drivers\yukonx86.sys [28/12/2005 10:15 176256]
.
Contenu du dossier 'Tâches planifiées'
2006-03-05 c:\windows\Tasks\11h.job
- c:\documents and settings\Dad\Mes documents\11h.mp3 [2006-01-16 08:32]
2009-07-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-08 10:59]
2009-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-16 08:03]
2009-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-16 08:03]
2009-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1614895754-839522115-1003Core.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-17 06:55]
2009-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1614895754-839522115-1003UA.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-17 06:55]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKU-Default-Run-MS Unix Binary - msnq3insller.exe
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/webhp?hl=fr&btnG=Recherche+Google&lr=lang_fr
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {9F0E992E-FD38-4377-9B61-82D331D6A2FE} = 212.27.54.252,212.27.53.252
TCP: {C1F436FD-00DA-4216-A5E8-6489D92E66C4} = 212.27.54.252,212.27.53.252
DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
DPF: {826287F8-454E-11D9-ADFE-00062919A34C} - hxxp://express.foto.com/activeX/newUploadFotoCom.CAB
DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} - hxxp://register.tiscali.fr/configurateur/AccountHelper.cab
DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} - hxxp://asp06.photoprintit.de/microsite/1156/defaults/activex/ImageUploader3.cab
FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\wvmfste1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/webhp?source=ig&hl=fr&rlz=&btnG=Recherche+Google&lr=lang_fr
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-07 09:04
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-117609710-1614895754-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,d5,9e,e0,f0,f4,
cc,47,d1,c8,28,51,af,b0,29,a3,98,b5,b2,82,ad,f0,14,95,47,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,4b,ce,72,4d,fd,
02,08,91,71,3b,04,66,8b,46,0d,96,db,42,8a,94,8c,0b,67,fc,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,f7,19,a9,43,5b,
a6,f1,1f,25,da,ec,7e,55,20,c9,26,24,f2,64,77,18,95,9b,8a,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,88,f2,f6,82,50,
82,f8,16,3e,1e,9e,e0,57,5a,93,61,a7,ca,05,9e,6e,38,cb,70,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,f3,38,d7,a2,60,
28,07,ad,cd,44,cd,b9,a6,33,6c,cd,24,e4,44,be,c0,5a,24,8f,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,68,f5,7b,80,3b,
89,22,5f,b0,18,ed,a7,3f,8d,37,a4,3f,08,41,15,28,00,fe,25,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,1c,dc,e3,96,af,
c8,46,a0,31,77,e1,ba,b1,f8,68,02,c4,11,e6,4c,7a,eb,89,a9,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:74,4b,ed,b3,1a,ec,f4,4c,e2,d8,9d,ff,d1,f8,42,36,36,3e,40,73,6c,
eb,bf,9b,fe,c2,5d,c4,ca,12,30,b0,7e,d6,9e,cd,f7,01,33,57,74,12,51,f5,6d,17,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,42,b7,9e,cf,12,
7c,8e,16,83,6c,56,8b,a0,85,96,ab,66,db,9e,a9,03,1a,4a,3d,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,1e,50,20,53,ed,
e4,d5,cc,51,fa,6e,91,28,9e,14,cc,ba,61,63,94,91,5a,71,da,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,a0,f9,21,1e,c1,
f0,5f,6a,b1,cd,45,5a,a8,c4,f8,b9,11,1d,88,ec,44,83,c2,4c,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,9d,12,d4,e8,ef,
ed,9a,dd,e3,0e,66,d5,eb,bc,2f,6b,8c,29,73,e2,3c,a4,98,8e,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,e6,6d,88,ea,46,
82,9b,e7,fa,ea,66,7f,d4,3b,6b,70,4f,89,99,5d,36,7d,cf,43,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
@Denied: (Full) (LocalSystem)
"OOBETimer"=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:74,4b,ed,b3,1a,ec,f4,4c,e2,d8,9d,ff,d1,f8,42,36,36,3e,40,73,6c,
eb,bf,9b,fe,c2,5d,c4,ca,12,30,b0,7e,d6,9e,cd,f7,01,33,57,74,12,51,f5,6d,17,\
.
Heure de fin: 2009-07-07 9:06
ComboFix-quarantined-files.txt 2009-07-07 07:06
Avant-CF: 42 314 194 944 octets libres
Après-CF: 43 003 068 416 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Pro, le Vrai" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Putain ! c'est quand y deconne !(Mode sans Echec)" /fastdetect /safeboot:minimal
281 --- E O F --- 2009-06-12 05:48
" Je sais pas tout, mais vous allez m'aider !"