ComboFix 11-04-30.02 - Sofyen 01/05/2011 2:46.2.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1014.509 [GMT 2:00]
Lancé depuis: c:\documents and settings\Sofyen\Bureau\asdehi22.exe
AV: *Disabled/Outdated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Antivirus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FW: *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-04-01 au 2011-05-01 ))))))))))))))))))))))))))))))))))))
.
.
2011-05-01 00:33 . 2011-05-01 00:35 -------- d-----w- C:\32788R22FWJFW
2011-04-30 23:14 . 2011-05-01 00:23 -------- d-----w- C:\asdehi22
2011-04-30 15:23 . 2011-04-30 15:23 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-04-30 15:17 . 2011-04-30 15:23 -------- d-----w- c:\program files\ZHPDiag
2011-04-29 17:44 . 2011-04-29 17:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Evonsoft
2011-04-29 17:44 . 2011-04-29 18:14 -------- d-----w- c:\program files\Advanced System Restore
2011-04-29 17:29 . 2011-05-01 00:42 -------- d-----w- c:\windows\system32\CatRoot2
2011-04-28 16:43 . 2011-04-28 16:43 -------- d-----w- c:\program files\iPod
2011-04-28 16:42 . 2011-04-28 16:44 -------- d-----w- c:\program files\iTunes
2011-04-28 16:31 . 2011-04-28 16:31 -------- d-----w- c:\program files\Bonjour
2011-04-25 21:50 . 2011-04-25 21:53 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2011-04-25 21:26 . 2011-04-25 21:27 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Deployment
2011-04-20 16:48 . 2011-04-20 16:48 -------- d-----w- c:\program files\GIMP-2.0
2011-04-14 01:39 . 2011-04-14 01:39 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 14:20 . 2011-04-06 14:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 14:20 . 2011-04-06 14:20 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-06 12:57 . 2011-04-06 12:57 -------- d-----w- c:\documents and settings\Sofyen\Local Settings\Application Data\Mozilla
2011-04-06 12:36 . 2011-04-06 12:36 -------- d-----w- c:\program files\MSN Toolbar
2011-04-06 12:35 . 2011-04-06 12:35 -------- d-----w- c:\program files\Microsoft Silverlight
2011-04-06 12:34 . 2011-04-06 12:36 -------- d-----w- c:\program files\Bing Bar Installer
2011-04-05 18:02 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-05 18:02 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-05 18:02 . 2011-04-05 18:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-04 12:36 . 2011-04-04 12:36 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-18 10:23 . 2010-05-20 16:09 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-02-23 15:04 . 2010-10-24 19:51 40648 ----a-w- c:\windows\avastSS.scr
2011-02-23 15:04 . 2009-01-18 16:14 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2011-03-15 17:50 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-23 14:56 . 2009-01-18 16:15 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2009-01-18 16:15 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2009-01-18 16:15 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-02-23 14:55 . 2009-01-18 16:15 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-02-23 14:55 . 2009-01-18 16:15 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:54 . 2009-01-18 16:15 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-02-23 14:54 . 2009-01-18 16:15 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-21 18:37 . 2008-12-06 00:42 86576 ----a-w- c:\documents and settings\Sofyen\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
2011-02-21 18:37 . 2008-12-06 00:42 392728 ----a-w- c:\documents and settings\Sofyen\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
2011-02-21 18:37 . 2008-12-06 00:42 132672 ----a-w- c:\documents and settings\Sofyen\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
2011-02-18 14:36 . 2009-09-17 07:45 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 14:36 . 2009-09-17 07:45 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2008-12-30 20:14 . 2008-12-30 20:14 5935104 ----a-w- c:\program files\Trust WB-1200p Mini Webcam.msi
2011-04-29 14:23 . 2011-04-06 12:53 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-01_00.17.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-01 00:42 . 2011-05-01 00:42 16384 c:\windows\Temp\Perflib_Perfdata_428.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PMX Daemon"="ICO.EXE" [2007-03-08 49152]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-06 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-10-06 94208]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2010-03-12 202256]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 243544]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Sofyen^Menu Démarrer^Programmes^Démarrage^Desktop Manager.lnk]
path=c:\documents and settings\Sofyen\Menu Démarrer\Programmes\Démarrage\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Sofyen^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Sofyen\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2008-10-24 07:14 206112 ----a-w- c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-14 09:32 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
2006-07-13 05:25 57344 ----a-w- c:\program files\Lexmark 1200 Series\lxczbmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-16 21:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-26 16:05 15026056 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 03:19 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-03-12 19:31 202256 ----a-w- c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-12-09 10:45 74752 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\TeamScripT 4.1\\mirc.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Fichiers communs\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:TCP port 443 ooVoo
"443:UDP"= 443:UDP:UDP port 443 ooVoo
"37674:TCP"= 37674:TCP:TCP port 37674 ooVoo
"37674:UDP"= 37674:UDP:UDP port 37674 ooVoo
"37675:UDP"= 37675:UDP:UDP port 37675 ooVoo
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [11/05/2010 17:51 64288]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [15/03/2011 19:50 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [18/01/2009 18:15 301528]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18/01/2009 18:15 19544]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/08/2010 14:15 2146496]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys --> c:\windows\system32\drivers\nmwcdnsu.sys [?]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys --> c:\windows\system32\drivers\nmwcdnsuc.sys [?]
S3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [24/02/2005 13:29 611584]
.
Contenu du dossier 'Tâches planifiées'
.
2011-03-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 16:22]
.
2011-04-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2011-05-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
2011-05-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1715567821-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
2011-04-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
2011-04-28 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1715567821-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyOverride = <local>;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: {DAF7E6E7-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - c:\documents and settings\Sofyen\Application Data\Mozilla\Firefox\Profiles\ybrsvy82.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-01 03:03
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: Hitachi_ rev.P22O -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x863D05B9]<<
c:\docume~1\Sofyen\LOCALS~1\Temp\catchme.sys
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x863d6938]; MOV EAX, [0x863d69b4]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x86D65AB8]
3 CLASSPNP[0xF7670FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x86D55638]
\Driver\iastor[0x86D773A8] -> IRP_MJ_CREATE -> 0x863D05B9
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x132; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-1 -> \??\IDE#DiskHitachi_HDS721616PLA380_________________P22OA92A#4&3836d654&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312499998 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,49,d8,11,ad,50,d0,ea,4e,9b,21,f5,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,49,d8,11,ad,50,d0,ea,4e,9b,21,f5,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="CEBA85C8E4AECAD8DFD5AD30272B771CA43EC783EF0CA6214D473221BFF7DFD21F8DBF95DB593605F87B2BC356C587C1DC9A9B60A23F3FEC91BE35B4BB3E3937CDF13BBDDB8A26597841430FC4EF8A2979CAF88D11B1447693A6EFF7A1E02B3C559982C18BEEB5251A964A3529A136D5159A1FF224C92592ECC9A9372AD4FDAC75688671952723455E1E782D3E4862DA10882E4EC85FF2AC03238B9294001B682D7A19F229C65530062DEB42C4C68C628FC8AA2DEEC2E2C277E32601A03E9263C51BF241775652ED9950A29200EF55A97B4380750C3450E5B4F0EA4895DC16A3C74DAFA738FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808FEBC9E127BECC74CC038D530D6EB3452BA7FD869164D6794C322893A560782D966887DA9E41FED076742FDF9085B89D4C82CC9521F2EEDC894D42D070F3B9AF7B18D2E08F9C5D504771A10DFC41ACC1C22E923C0669413178B6166A51632E517B5B8F47FB33448C0AB60C9709553E8822A7ECFA01AFE5BEC217B3E9888B4A3937917D131CC5D8A8AB519410F74C24667610919368B93F6D843F5D52536F1E9D0F7D65683B097B736406D9C620A8A262EBA4ADB88425BE87155CDDCD2237CA0B220492BA081203C19672798D5362E9BBEA12589E47AC4884D2C9E9A6F0A4B84A454678C771595DA8EB83807198A160A0572A4285AA49E030B12ABE90E553727136DCBC73A75FAA7743A32491ECC8E30EFFDF4513E63A0D64AC5D93700A67FEBEFB4B4405DDF388F2E644F5B1D79471BF3896731A78DE3582FF73487E251C78C316A05EE1DC5184D21A06A4611BC572D08CDEF89F3AFE5AFE34FE7EE8FDE1416CFC0445D75CCCAF4B9D1832CB87CB41DA87728AEC209065714E6C618AA8CD0E74ADE9C2DAACD636A654A3EC0184BBBF655A84C0B770D8C21704B464297C8CB38A1DF5D8E4156D8689753E1CCF4762E9811753E1C3BE3212F2EFE02BD7FB937905BD279CA842908FBC6A7DB2CDB7B2FB5E368837279E7D079847736F3CF37284B813B08BB81BA2E08EC773B4E1A8CC8D2597CC2B2E2298E4C3220C5DBBA4E9B1A231044D28B34EFC109673538459165CC81A3C998EAEA2FC7F6D5370633BF6E03CEBA8B91B8F4D5B21F8F9F8233A357D1EE428A6ECAA56BDD966B3214747E63DD9C1C628F628CC839B3FBF6D9FE1251E4BA3398977D0461585AA5063C7A3421D625076E7827C11A07D1AC5B7D075FECDC7FC12E8844E692530F40A4C7073E326F8641FB0CE88D7C21891412C170C125E35EAE26C923DEE43B0668A4171FAB04FC6207F79B4E9D0761EB1C800F21A3DC79F83004FA61379FD792BFBD9A8B42E826DE0877114053B5F790213462452456EFF76F6BCA8C68713F0EDC50D959F898EA24E4B0E5"
.
Heure de fin: 2011-05-01 03:11:25
ComboFix-quarantined-files.txt 2011-05-01 01:11
ComboFix2.txt 2011-05-01 00:22
.
Avant-CF: 23 241 101 312 octets libres
Après-CF: 23 233 224 704 octets libres
.
- - End Of File - - 06F91D4F6B1A11EF57AF22B9D9AAD420