Rapport
Combofix :
ComboFix 10-06-27.03 - Arnovero 27/06/2010 23:44:14.1.4 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3327.2405 [GMT 2:00]
Lancé depuis: c:\documents and settings\Arnovero\Bureau\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Arnovero\Local Settings\Application Data\Bron.tok-10-27
c:\documents and settings\Arnovero\Local Settings\Application Data\Bron.tok.A10.em.bin
c:\documents and settings\Arnovero\Local Settings\Application Data\Kosong.Bron.Tok.txt
c:\documents and settings\Arnovero\Local Settings\Application Data\ListHost10.txt
c:\documents and settings\Arnovero\Local Settings\Application Data\lsass.exe
c:\documents and settings\Arnovero\Local Settings\Application Data\services.exe
c:\documents and settings\Arnovero\Local Settings\Application Data\Update.10.Bron.Tok.bin
c:\documents and settings\Arnovero\Local Settings\Application Data\winlogon.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-05-27 au 2010-06-27 ))))))))))))))))))))))))))))))))))))
.
2010-06-27 20:39 . 2010-06-27 20:39 -------- d-----w- c:\program files\Trend Micro
2010-06-27 20:16 . 2010-06-27 20:16 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-06-27 20:16 . 2010-06-27 20:16 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-06-27 20:16 . 2010-06-27 20:16 -------- d-----r- c:\documents and settings\LocalService\Favoris
2010-06-27 20:16 . 2010-06-27 20:16 -------- d--h--w- c:\windows\PIF
2010-06-27 20:12 . 2005-09-16 22:20 87768 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-06-27 20:12 . 2005-09-16 22:20 108168 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-06-27 20:12 . 2010-06-27 20:27 -------- d-----w- c:\program files\Symantec
2010-06-27 20:12 . 2010-06-27 20:20 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2010-06-27 20:03 . 2010-06-27 20:15 -------- d-----w- c:\documents and settings\Arnovero\Local Settings\Application Data\Loc.Mail.Bron.Tok
2010-06-27 20:03 . 2010-06-27 20:03 -------- d-----w- c:\documents and settings\Arnovero\Local Settings\Application Data\Ok-SendMail-Bron-tok
2010-06-19 07:13 . 2010-06-19 07:13 -------- d-----w- c:\documents and settings\Arnovero\Application Data\Skypad
2010-06-19 07:13 . 2007-09-25 17:12 2453504 ---ha-w- c:\documents and settings\Arnovero\Application Data\Skypad\tmp\SkypadMain.exe
2010-06-19 07:13 . 2007-09-25 17:12 2453504 ---ha-w- c:\documents and settings\Arnovero\Application Data\Skypad\SkypadMain.exe
2010-06-19 07:13 . 2007-05-16 21:13 143360 ---ha-w- c:\documents and settings\Arnovero\Application Data\Skypad\tmp\TaskKeyHook.dll
2010-06-19 07:13 . 2007-05-16 21:13 143360 ------w- c:\documents and settings\Arnovero\Application Data\Skypad\TaskKeyHook.dll
2010-06-19 07:13 . 2005-05-31 16:13 249856 ---ha-w- c:\documents and settings\Arnovero\Application Data\Skypad\tmp\IMailDll.dll
2010-06-19 07:13 . 2005-05-31 16:13 249856 ------w- c:\documents and settings\Arnovero\Application Data\Skypad\IMailDll.dll
2010-06-19 07:13 . 2002-08-19 11:19 397856 ---ha-w- c:\documents and settings\Arnovero\Application Data\Skypad\XceedZip.dll
2010-06-19 07:13 . 2002-08-19 11:19 397856 ---ha-w- c:\documents and settings\Arnovero\Application Data\Skypad\tmp\XceedZip.dll
2010-06-09 16:29 . 2010-06-09 16:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Danware Data
2010-06-09 16:09 . 2010-05-06 10:33 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 15:10 . 2010-06-09 15:10 -------- d-----w- c:\documents and settings\Arnovero\Local Settings\Application Data\Conference Client
2010-06-09 15:09 . 2010-06-09 15:10 -------- d-----w- c:\documents and settings\Arnovero\Local Settings\Application Data\Radvision
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-27 21:41 . 2008-10-21 13:46 -------- d-----w- c:\program files\Symantec AntiVirus
2010-06-27 20:12 . 2008-10-21 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-06-27 20:09 . 2010-03-24 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-06-27 20:01 . 2010-03-24 20:49 2568656 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-06-26 17:07 . 2004-08-05 12:00 77998 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-26 17:07 . 2004-08-05 12:00 494382 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-23 16:28 . 2008-10-22 18:39 -------- d-----w- c:\documents and settings\Arnovero\Application Data\Canon
2010-06-16 12:16 . 2009-05-30 16:26 21840 ----atw- c:\windows\system32\SIntfNT.dll
2010-06-16 12:16 . 2009-05-30 16:26 17212 ----atw- c:\windows\system32\SIntf32.dll
2010-06-16 12:16 . 2009-05-30 16:26 12067 ----atw- c:\windows\system32\SIntf16.dll
2010-06-05 11:49 . 2010-05-24 10:19 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-30 16:16 . 2009-11-08 15:11 -------- d-----w- c:\program files\Messenger Plus! Live
2010-05-23 15:50 . 2010-05-27 17:23 73216 ----a-w- c:\documents and settings\Arnovero\Application Data\Mozilla\Firefox\Profiles\mdfxs4ib.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
2010-05-16 06:47 . 2010-05-16 06:47 -------- d-----w- c:\program files\Fichiers communs\Java
2010-05-16 06:47 . 2010-05-16 06:47 503808 ----a-w- c:\documents and settings\Arnovero\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-66decc0d-n\msvcp71.dll
2010-04-03 11:20 . 2010-04-03 11:20 1025992 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\SecurityScan_Release.exe
2010-03-30 22:16 . 2010-03-30 22:16 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-30 22:10 . 2010-03-30 22:10 295264 ----a-w- c:\windows\system32\PresentationHost.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OSDOverLayIcon]
@="{8129812F-4AF8-4A47-85A5-D995B505880C}"
[HKEY_CLASSES_ROOT\CLSID\{8129812F-4AF8-4A47-85A5-D995B505880C}]
2009-04-16 14:32 53248 ----a-w- c:\program files\mes données\OSDExtension.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-12-20 16860672]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2007-12-10 1412608]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"ASUS Energy Saving"="c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe" [2008-01-24 1352192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-11 13520896]
"nwiz"="nwiz.exe" [2008-03-11 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-11 86016]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-12-04 406016]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2007-03-12 569344]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]
"CANAL+ CANALSAT A LA DEMANDE"="c:\program files\Canal+\CANAL+ CANALSAT A LA DEMANDE\Launcher.exe" [2010-01-12 163928]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-12-21 48800]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-05-27 85744]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2006-04-09 18:59 24674 ----a-w- c:\windows\system32\ckpNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 00:38 34672 ----a-w- c:\program files\Adobe\Reader\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2007-10-11 06:45 31232 ----a-w- c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
2004-01-14 01:10 409600 ----a-w- c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SERVICE.EXE"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.EXE"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SCC.EXE"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.EXE"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_DIAGNOSTICS.EXE"=
"c:\\Program Files\\Hercules\\DualPix Exchange\\Station2.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Softwares\\NETOP\\Teacher\\ntchw32.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
R1 CbFs;CbFs;c:\windows\system32\drivers\cbfs32.sys [01/06/2009 23:48 137384]
R2 CanalPlus.VOD;CanalPlus.VOD;c:\program files\Canal+\CANAL+ CANALSAT A LA DEMANDE\VOD\CanalPlus.VOD.exe [28/04/2009 17:33 188416]
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [21/10/2008 16:18 36400]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\drivers\vnasc.sys [21/10/2008 16:19 109072]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [21/10/2008 16:18 671472]
R3 BENDER;Pinnacle DV/AV Capture;c:\windows\system32\drivers\bender.sys [21/10/2008 19:45 180480]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [27/06/2010 22:15 102448]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [21/10/2008 16:19 2234320]
S3 camfilt2;camfilt2;c:\windows\system32\drivers\camfilt2.sys [21/10/2008 20:43 94208]
S3 OPTENET_FILTER;Orange Contrôle Parental;c:\program files\Controle Parental\bin\optproxy.exe --> c:\program files\Controle Parental\bin\optproxy.exe [?]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [31/07/2009 08:12 341504]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/05/2006 05:51 169200]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [27/12/2008 19:15 436096]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [12/02/2010 21:34 99152]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
.
Contenu du dossier 'Tâches planifiées'
2010-06-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-06-27 c:\windows\Tasks\User_Feed_Synchronization-{05C5DBA7-4CB1-4553-8689-A72CE15A2233}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr/
uInternet Connection Wizard,ShellNext = iexplore
IE: ajouter cette page à vos favoris Orange - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\addfavorites.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: envoyer le texte sélectionné par sms - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\sendsmsselectedtext.html
IE: envoyer par sms - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\sendsms.html
IE: envoyer un mail - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\sendmail.html
IE: orange.fr - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\orange.html
IE: rechercher le texte sélectionné - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\selectedsearch.html
IE: traduire la page - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\translate.html
IE: traduire le texte sélectionné - c:\documents and settings\Arnovero\Application Data\Orange\MessengerByOrange\translateSelectedText.html
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
FF - ProfilePath - c:\documents and settings\Arnovero\Application Data\Mozilla\Firefox\Profiles\mdfxs4ib.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
FF - prefs.js: keyword.URL - hxxp://rws.search.ke.voila.fr/RW/S/opensearch_orange?rdata=
FF - component: c:\documents and settings\Arnovero\Application Data\Mozilla\Firefox\Profiles\mdfxs4ib.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Adobe\Reader\Reader\browser\nppdf32.dll
FF - plugin: c:\program files\Canal+\CANAL+ CANALSAT A LA DEMANDE\VOD\npCpVod.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-CUCore Agent - c:\documents and settings\Arnovero\Local Settings\Application Data\Radvision\Conference Client\7.11.3.317\ConfAgent.exe
HKLM-Run-EoEngine - (no file)
MSConfigStartUp-ASUS SmartDoctor - c:\program files\ASUS\SmartDoctor\SmartDoctor.exe
MSConfigStartUp-Omnipage - c:\program files\ScanSoft\OmniPageSE\opware32.exe
MSConfigStartUp-SoftwareHelper - c:\documents and settings\Arnovero\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
AddRemove-Macromedia Shockwave Player - c:\windows\system32\Macromed\SHOCKW~1\UNWISE.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-27 23:46
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2010-06-27 23:47:45
ComboFix-quarantined-files.txt 2010-06-27 21:47
Avant-CF: 51 517 112 320 octets libres
Après-CF: 51 972 902 912 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 3653F7D908FC39F3B0DACDC05E085E5A