Bon alors voila pour combofix, seul hic ayant pourtant désactivé toute mes protections il me dis que elle ne le sont pas toute, j'essaye donc d'annuler en fermant la page mais combofix démarre quand même ce qui me donne ce rapport ...
ComboFix 09-12-26.05 - SébNoHair 27/12/2009 21:24:07.1.2 - x86
Lancé depuis: c:\users\SébNoHair\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1169 [VPS 090226-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1169 [VPS 090226-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\dllhst3g.exe
c:\windows\system\sessmgr.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-27 au 2009-12-27 ))))))))))))))))))))))))))))))))))))
.
2009-12-27 20:36 . 2009-12-27 20:36 -------- d-----w- c:\users\SBNOHA~2\AppData\Local\temp
2009-12-27 20:36 . 2009-12-27 20:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-27 18:39 . 2009-12-27 18:39 -------- d-----w- C:\_OTM
2009-12-27 10:23 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-27 10:23 . 2009-12-27 10:23 -------- d-----w- c:\programdata\Malwarebytes
2009-12-27 10:23 . 2009-12-27 10:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-27 10:23 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-27 09:35 . 2009-12-27 19:38 -------- d-----w- c:\program files\trend micro
2009-12-27 09:35 . 2009-12-27 09:35 -------- d-----w- C:\rsit
2009-12-26 19:40 . 2009-04-14 07:03 304640 ----a-w- c:\programdata\EPSON\EPSON Stylus SX400 Series\Language\040c.E_DIX0RE.DLL
2009-12-26 19:35 . 2008-02-07 05:03 56320 ----a-w- c:\programdata\EPSON\EPSON Stylus SX400 Series\Language\040c.E_S9E0G7.DLL
2009-12-26 19:35 . 2007-12-17 03:00 143872 ----a-w- c:\programdata\EPSON\EPW!3 SSRP\E_S40ST7.EXE
2009-12-26 19:35 . 2007-01-11 03:02 113664 ----a-w- c:\programdata\EPSON\EPW!3 SSRP\E_S40RP7.EXE
2009-12-26 19:35 . 2008-05-26 07:03 212480 ----a-w- c:\programdata\EPSON\EPSON Stylus SX400 Series\Language\040c.E_DI0EEE.DLL
2009-12-26 19:30 . 2007-04-10 00:06 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
2009-12-26 19:30 . 2007-12-07 01:08 86528 ----a-w- c:\windows\system32\E_FLBEGE.DLL
2009-12-26 19:30 . 2007-12-07 01:01 78848 ----a-w- c:\windows\system32\E_FD4BEGE.DLL
2009-12-26 18:05 . 2009-12-26 18:05 -------- d-----w- c:\programdata\UDL
2009-12-26 17:57 . 2008-05-06 16:39 382240 ------w- c:\windows\system32\UninstMFP.exe
2009-12-26 17:57 . 2007-05-20 19:45 417792 ------w- c:\windows\system32\ServoApp.exe
2009-12-26 17:57 . 2007-05-06 20:44 34944 ----a-w- c:\windows\system32\drivers\mfpec.sys
2009-12-26 17:57 . 2006-10-20 01:57 10240 ----a-w- c:\windows\system32\drivers\mfpvbus.sys
2009-12-26 17:57 . 2006-09-21 20:35 151552 ------w- c:\windows\system32\ddschk.dll
2009-12-26 17:57 . 2007-01-09 22:36 10880 ----a-w- c:\windows\system32\drivers\mfpcomp.sys
2009-12-26 17:57 . 2006-09-21 23:13 200704 ----a-w- c:\windows\system32\mfpcoins.dll
2009-12-26 17:57 . 2009-12-26 17:57 -------- d-----w- c:\program files\MFP Server
2009-12-26 17:53 . 2007-07-12 23:00 71680 ----a-w- c:\windows\system32\escwiad.dll
2009-12-18 12:04 . 2009-12-26 19:35 -------- d-----w- c:\programdata\EPSON
2009-12-18 12:02 . 2009-12-26 18:03 -------- d-----w- c:\program files\epson
2009-12-11 22:48 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-11 22:48 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-11 22:48 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-08 13:01 . 2009-12-08 13:01 -------- d-----w- c:\program files\AutoHotkey
2009-12-07 14:26 . 2009-12-27 12:45 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-12-07 14:26 . 2009-12-07 14:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-06 21:17 . 2009-12-06 21:28 -------- d-----w- c:\program files\JMCAssemblageGsm
2009-12-05 22:21 . 2009-12-05 22:21 -------- d-----w- c:\program files\MarkAnyContentSAFER
2009-12-05 21:43 . 2009-12-05 21:43 -------- d-----w- c:\programdata\PC Suite
2009-12-05 21:16 . 2008-07-03 00:48 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2009-12-05 21:15 . 2007-05-02 15:31 90624 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-12-05 21:15 . 2009-12-05 21:15 -------- d-----w- c:\program files\DIFX
2009-12-05 21:15 . 2007-09-17 14:53 21632 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-12-05 19:52 . 2009-12-05 21:16 -------- d-----w- c:\program files\Samsung
2009-12-01 14:24 . 2009-12-01 14:24 -------- d-----w- c:\program files\WinPcap
2009-11-29 20:38 . 2009-11-16 11:25 17224 ----a-w- c:\windows\system32\authuitu.dll
2009-11-29 20:38 . 2009-11-16 11:25 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-11-29 20:38 . 2009-11-29 20:38 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-27 20:21 . 2009-02-26 17:31 28219 ----a-w- c:\programdata\nvModes.dat
2009-12-27 20:20 . 2009-01-16 16:45 45056 ----a-w- c:\windows\system32\acovcnt.exe
2009-12-27 18:42 . 2009-03-01 20:04 -------- d-----w- c:\program files\DNA
2009-12-27 09:38 . 2008-04-16 11:16 672322 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-27 09:38 . 2008-04-16 11:16 124434 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-26 18:03 . 2009-01-16 14:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-10 10:35 . 2009-01-16 14:12 -------- d-----w- c:\programdata\Microsoft Help
2009-12-07 12:11 . 2009-03-08 21:33 -------- d-----w- c:\program files\Java
2009-12-05 22:20 . 2007-10-25 16:26 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-12-05 21:15 . 2009-12-05 19:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-05 19:52 . 2009-12-05 19:52 -------- d-----w- c:\program files\MarkAny
2009-11-29 20:38 . 2009-10-31 09:31 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-11-29 20:38 . 2009-10-31 09:31 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-11-24 23:54 . 2009-02-27 07:55 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:49 . 2009-02-27 07:56 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-02-27 07:56 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-02-27 07:56 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-21 06:40 . 2009-12-10 10:29 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-10 10:29 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-10 10:29 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-10 10:29 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 15:47 . 2009-11-18 15:47 -------- d-----w- c:\program files\iTunes
2009-11-18 15:47 . 2009-11-18 15:47 -------- d-----w- c:\program files\iPod
2009-11-18 15:47 . 2009-02-27 19:12 -------- d-----w- c:\program files\Common Files\Apple
2009-11-18 15:34 . 2009-11-18 15:34 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-11 10:00 . 2009-11-11 10:00 -------- d-----w- c:\program files\Electronic Arts
2009-11-11 09:51 . 2009-11-11 09:50 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-11-11 09:51 . 2009-11-11 09:51 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-11 09:50 . 2009-11-11 09:49 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-11-10 22:39 . 2009-11-09 21:18 -------- d-----w- c:\program files\IDoser v4
2009-11-07 09:10 . 2009-09-12 18:34 -------- d-----w- c:\program files\Dofus
2009-11-07 08:43 . 2009-06-16 10:17 -------- d-----w- c:\program files\FlashGet
2009-11-07 08:42 . 2009-01-16 15:25 -------- d-----w- c:\program files\Google
2009-11-05 17:28 . 2009-11-05 17:28 913280 ----a-w- c:\users\Public\MyWebTattoo.exe
2009-11-05 12:26 . 2009-02-26 08:48 -------- d-----w- c:\program files\Messenger Plus! Live
2009-11-02 19:42 . 2009-10-03 09:05 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 14:11 . 2009-07-19 12:39 -------- d-----w- c:\program files\Free Video Converter
2009-11-01 11:49 . 2009-02-25 20:29 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-31 09:31 . 2009-10-31 09:31 -------- d-----w- c:\programdata\TuneUp Software
2009-10-31 09:30 . 2009-10-31 09:30 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2009-10-30 20:17 . 2009-09-21 14:35 -------- d-----w- c:\programdata\Skype
2009-10-29 09:17 . 2009-11-25 20:19 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-22 08:18 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-12 12:10 . 2009-02-25 20:21 102240 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-11 03:17 . 2009-03-08 21:33 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-07 11:36 . 2009-12-10 10:29 243712 ----a-w- c:\windows\system32\rastls.dll
2008-07-02 03:28 . 2008-07-02 03:28 61440 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2008-05-22 17:35 . 2008-05-22 17:35 51962 ----a-w- c:\program files\Common Files\banner.jpg
2007-06-12 18:34 . 2007-06-12 18:34 35822 ----a-w- c:\program files\Common Files\ASPG_icon.ico
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-07 323392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-12-05 102400]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-26 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-26 92704]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-12 98304]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-12 6265376]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-06-25 159744]
"ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2009-01-16 47672]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2009-01-16 33136]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Server Application"="c:\windows\system32\ServoApp.exe" [2007-05-20 417792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Esent Utl"="c:\users\SBNOHA~1\AppData\Roaming\esentutl.exe" [2009-09-28 61440]
c:\users\S‚bNoHair\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\SébNoHair\AppData\Local\Google\Update\GoogleUpdate.exe" /c
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):a0,b1,87,37,f1,52,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1765232804-4017979392-2551784716-1000]
"EnableNotificationsRef"=dword:00000001
R0 lullaby;lullaby;c:\windows\System32\drivers\lullaby.sys [16/01/2009 17:31 15416]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [27/02/2009 08:56 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [27/02/2009 08:56 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [27/02/2009 08:55 53328]
R2 FsUsbExService;FsUsbExService;c:\windows\System32\FsUsbExService.Exe [05/12/2009 20:53 233472]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\System32\FsUsbExDisk.Sys [05/12/2009 20:53 36608]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\System32\drivers\SiSGB6.sys [16/11/2007 05:09 48128]
R3 WUSBVBus;MFP Server Detector;c:\windows\System32\drivers\mfpvbus.sys [26/12/2009 18:57 10240]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [11/11/2009 10:51 691696]
S2 ALIWEHCD;MFP Server Enhanced Controller;c:\windows\System32\drivers\mfpec.sys [26/12/2009 18:57 34944]
S3 AliWGP;Composite Device;c:\windows\System32\drivers\mfpcomp.sys [26/12/2009 18:57 10880]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [29/06/2007 01:01 42512]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - FSUSBEXDISK
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 18:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://google.fr/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
uInternet Settings,ProxyOverride = *.local
IE: &Search - ?p=ZJman000
IE: Analyser avec LeechGet - file://c:\program files\LeechGet 2009\\Parser.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Télécharger en utilisant l'assistant LeechGet - file://c:\program files\LeechGet 2009\\Wizard.html
IE: Télécharger en utilisant LeechGet - file://c:\program files\LeechGet 2009\\AddUrl.html
FF - ProfilePath - c:\users\SébNoHair\AppData\Roaming\Mozilla\Firefox\Profiles\l5bfz51v.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 600000
FF - user.js: nglayout.initialpaint.delay - 600
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Explorer_Run-DllHst - c:\users\SBNOHA~1\LOCALS~1\APPLIC~1\dllhst3g.exe
HKLM-Explorer_Run-Cisvc - c:\users\SBNOHA~1\LOCALS~1\APPLIC~1\MICROS~1\cisvc.exe
HKCU-Explorer_Run-DllHst - c:\users\SBNOHA~1\AppData\Roaming\dllhst3g.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-27 21:36
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
C:\ADSM_PData_0150
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1765232804-4017979392-2551784716-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{474A373C-28A4-61C9-C7B2-DEDAEB4F129A}*]
"maldjopkpohjcammdcfdkgoilm"=hex:6b,61,62,62,66,6d,6e,6f,66,6f,6f,63,67,62,6d,
69,63,6e,6c,6a,65,66,00,67
"nafdhnganijcocahmpbihgpfdemm"=hex:6a,61,61,62,66,6f,6c,6b,64,6d,67,64,6e,6e,
6e,6a,6f,70,65,64,00,00
"abbdcpbgnmddpfffdbmngcbieammcknlhn"=hex:61,61,00,74
"macdoidjpacgolceamacokgkaf"=hex:61,61,00,74
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2009-12-27 21:39:54
ComboFix-quarantined-files.txt 2009-12-27 20:39
Avant-CF: 57 115 148 288 octets libres
Après-CF: 56 821 800 960 octets libres
- - End Of File - - AC230853A2C52FAEA283D4F502A1987B