Bonjour, j'ai exactement le même problème...
EI rame à fond... et je crois que des Email son envoyés avec mon adresse... car j'ai 80 mail "invalides" en retour depuis hier.
pareil, Malwarbytes me trouve 2 trojan qui soit disant supprime... mais il les retrouve à chaque fois...
voici mon rapport
merci de votre aide
ComboFix 07-08-09.3 - "Taxi16" 2008-10-15 10:14:57.3 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.3.1252.1.1036.18.153 [GMT 2:00]
((((((((((((((((((((((((( Files Created from 2008-09-15 to 2008-10-15 )))))))))))))))))))))))))))))))
2008-10-15 06:07 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 06:07 2,191,232 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 06:07 2,147,328 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 06:07 2,068,096 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 06:07 2,025,984 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 06:07 1,846,528 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-14 19:41 87,228 --a------ C:\WINDOWS\system32\perfc040.dat
2008-10-14 19:41 499,136 --a------ C:\WINDOWS\system32\perfh040.dat
2008-10-14 11:26 <REP> d-------- C:\DOCUME~1\Taxi16\APPLIC~1\Uniblue
2008-09-27 11:57 0 --a------ C:\WINDOWS\system32\MX_SHARE.DAT
2008-09-27 11:57 <REP> d-------- C:\WINDOWS\system32\drivers\BurnProf
2008-09-27 11:57 <REP> d-------- C:\WINDOWS\system32\BurnProf
2008-09-27 11:39 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-09-27 11:37 81,920 --a------ C:\WINDOWS\system32\DLLCPY32.dll
2008-09-27 11:37 77,824 --a------ C:\WINDOWS\system32\mplaw7.dll
2008-09-27 11:37 77,824 --a------ C:\WINDOWS\system32\mplaa6.dll
2008-09-27 11:37 65,536 --a------ C:\WINDOWS\system32\mplapx.dll
2008-09-27 11:37 65,536 --a------ C:\WINDOWS\system32\mplam6.dll
2008-09-27 11:37 65,536 --a------ C:\WINDOWS\system32\DLLPTL32.dll
2008-09-27 11:37 61,440 --a------ C:\WINDOWS\system32\DLLCDF32.dll
2008-09-27 11:37 57,344 --a------ C:\WINDOWS\system32\DLLTPO32.dll
2008-09-27 11:37 53,248 --a------ C:\WINDOWS\system32\DLLPRJ32.dll
2008-09-27 11:37 49,152 --a------ C:\WINDOWS\system32\DLLPRF32.dll
2008-09-27 11:37 49,152 --a------ C:\WINDOWS\system32\DLLIO32.dll
2008-09-27 11:37 45,056 --a------ C:\WINDOWS\system32\DLLIMG32.dll
2008-09-27 11:37 401,408 --a------ C:\WINDOWS\system32\DLLAV32.dll
2008-09-27 11:37 40,960 --a------ C:\WINDOWS\system32\DLLRD32.dll
2008-09-27 11:37 36,864 --a------ C:\WINDOWS\system32\DLLPNT32.dll
2008-09-27 11:37 32,768 --a------ C:\WINDOWS\system32\STRING32.dll
2008-09-27 11:37 32,768 --a------ C:\WINDOWS\system32\DLLMSC32.dll
2008-09-27 11:37 32,768 --a------ C:\WINDOWS\system32\DLLISO32.dll
2008-09-27 11:37 32,768 --a------ C:\WINDOWS\system32\DLLDIR32.dll
2008-09-27 11:37 24,576 --a------ C:\WINDOWS\system32\TTIC32.dll
2008-09-27 11:37 24,576 --a------ C:\WINDOWS\system32\TTI32.dll
2008-09-27 11:37 24,576 --a------ C:\WINDOWS\system32\DLLIX.dll
2008-09-27 11:37 19,968 --a------ C:\WINDOWS\system32\cpuinf32.dll
2008-09-27 11:37 188,416 --a------ C:\WINDOWS\system32\DLLRES32.dll
2008-09-27 11:37 155,648 --a------ C:\WINDOWS\system32\DLLDEV32.dll
2008-09-27 11:37 143,360 --a------ C:\WINDOWS\system32\DLLDRV32.dll
2008-09-27 11:37 114,688 --a------ C:\WINDOWS\system32\DLLCDA32.dll
2008-09-27 11:37 1,650,688 --a------ C:\WINDOWS\system32\mplva6.dll
2008-09-27 11:37 1,581,056 --a------ C:\WINDOWS\system32\mplvw7.dll
2008-09-27 11:37 1,552,384 --a------ C:\WINDOWS\system32\mplvm6.dll
2008-09-27 11:37 1,122,304 --a------ C:\WINDOWS\system32\mplvpx.dll
2008-09-27 11:36 <REP> d-------- C:\Program Files\Fichiers communs\MAGIX Shared
2008-09-27 11:35 85,504 --a------ C:\WINDOWS\system32\HtmlWH.dll
2008-09-27 11:35 49,152 --a------ C:\WINDOWS\system32\INETWH32.dll
2008-09-27 11:35 458,752 --a------ C:\WINDOWS\system32\mgxoschk.dll
2008-09-27 11:35 1,089,536 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2008-09-27 11:35 <REP> d-------- C:\WINDOWS\system32\MAGIX
2008-09-27 11:35 <REP> d-------- C:\MAGIX
2008-09-27 11:12 19,584 --a------ C:\WINDOWS\system32\drivers\emAudio.sys
2008-09-27 11:12 <REP> d-------- C:\Program Files\Pinnacle
2008-09-27 11:11 9,739 --a------ C:\WINDOWS\system32\emUSD.dll
2008-09-27 11:11 61,440 --a------ C:\WINDOWS\system32\PCLECoInst.dll
2008-09-27 11:11 5,245 --a------ C:\WINDOWS\system32\drivers\emFilter.sys
2008-09-27 11:11 45,056 --a------ C:\WINDOWS\system32\emVFW.dll
2008-09-27 11:11 4,493 --a------ C:\WINDOWS\system32\drivers\emScan.sys
2008-09-27 11:11 24,269 --a------ C:\WINDOWS\system32\drivers\emStream.sys
2008-09-27 11:11 17,808 --a------ C:\WINDOWS\system32\emYUV.dll
2008-09-27 11:11 153,088 --a------ C:\Program Files\UNWISE.EXE
2008-09-27 11:11 100,957 --a------ C:\WINDOWS\system32\drivers\emDevice.sys
2008-09-27 11:11 <REP> d-------- C:\Drivers
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-10-15 07:30 --------- d-------- C:\DOCUME~1\Taxi16\APPLIC~1\OpenOffice.org2
2008-10-12 21:27 50176 -rahs---- C:\WINDOWS\system32\userinit.exe
2008-10-11 18:15 --------- d-------- C:\Program Files\eMule
2008-10-03 19:12 6066176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-21 19:40 152 --a------ C:\DOCUME~1\Taxi16\APPLIC~1\wklnhst.dat
2008-09-15 17:26 1846528 --a------ C:\WINDOWS\system32\win32k.sys
2008-09-15 15:39 --------- d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-10 20:59 --------- d-------- C:\Program Files\Microsoft Works
2008-09-10 00:04 38528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-10 00:03 17200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-08 12:41 333824 --a------ C:\WINDOWS\system32\drivers\srv.sys
2008-09-07 13:40 --------- d-------- C:\DOCUME~1\Taxi16\APPLIC~1\WinFF
2008-09-07 13:24 --------- d-------- C:\Program Files\WinFF
2008-09-07 13:15 --------- d-------- C:\Program Files\Free Audio Pack
2008-09-06 13:22 --------- d--h----- C:\Program Files\InstallShield Installation Information
2008-09-06 13:22 --------- d-------- C:\Program Files\GpsPrevent
2008-08-27 11:11 3593216 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-26 10:11 826368 --a--c--- C:\WINDOWS\system32\dllcache\wininet.dll
2008-08-26 10:11 671232 --a--c--- C:\WINDOWS\system32\dllcache\mstime.dll
2008-08-26 10:11 63488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-26 10:11 52224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-26 10:11 477696 --a--c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2008-08-26 10:11 459264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-26 10:11 44544 --a--c--- C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-08-26 10:11 44544 -----c--- C:\WINDOWS\system32\dllcache\iernonce.dll
2008-08-26 10:11 384512 -----c--- C:\WINDOWS\system32\dllcache\iedkcs32.dll
2008-08-26 10:11 383488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-26 10:11 347136 --a--c--- C:\WINDOWS\system32\dllcache\dxtmsft.dll
2008-08-26 10:11 27648 --a--c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2008-08-26 10:11 267776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-26 10:11 233472 -----c--- C:\WINDOWS\system32\dllcache\webcheck.dll
2008-08-26 10:11 230400 -----c--- C:\WINDOWS\system32\dllcache\ieaksie.dll
2008-08-26 10:11 214528 --a--c--- C:\WINDOWS\system32\dllcache\dxtrans.dll
2008-08-26 10:11 193024 --a--c--- C:\WINDOWS\system32\dllcache\msrating.dll
2008-08-26 10:11 153088 -----c--- C:\WINDOWS\system32\dllcache\ieakeng.dll
2008-08-26 10:11 133120 --a--c--- C:\WINDOWS\system32\dllcache\extmgr.dll
2008-08-26 10:11 124928 -----c--- C:\WINDOWS\system32\dllcache\advpack.dll
2008-08-26 10:11 1159680 --a--c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2008-08-26 10:11 105984 -----c--- C:\WINDOWS\system32\dllcache\url.dll
2008-08-26 10:11 102912 -----c--- C:\WINDOWS\system32\dllcache\occache.dll
2008-08-25 21:36 --------- d-------- C:\Program Files\Reallusion
2008-08-25 10:39 70656 -----c--- C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-25 10:38 13824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-24 12:01 --------- d-------- C:\Program Files\Microsoft Silverlight
2008-08-23 07:56 635848 -----c--- C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 07:54 161792 --a--c--- C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-16 11:19 --------- d-------- C:\Program Files\Messenger
2008-08-14 12:04 138496 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-08-07 09:44 87228 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-08-07 09:44 499136 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-08-06 18:15 89168 --a------ C:\WINDOWS\hpoins06.dat
2008-08-06 00:40 64280 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-07-18 22:10 94920 --a--c--- C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 22:10 94920 --a------ C:\WINDOWS\system32\cdm.dll
2008-07-18 22:10 53448 --a--c--- C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 22:10 53448 --a------ C:\WINDOWS\system32\wuauclt.exe
2008-07-18 22:10 45768 --a------ C:\WINDOWS\system32\wups2.dll
2008-07-18 22:10 36552 --a--c--- C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 22:10 36552 --a------ C:\WINDOWS\system32\wups.dll
2008-07-18 22:09 563912 --a--c--- C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 22:09 563912 --a------ C:\WINDOWS\system32\wuapi.dll
2008-07-18 22:09 325832 --a--c--- C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 22:09 325832 --a------ C:\WINDOWS\system32\wucltui.dll
2008-07-18 22:09 205000 --a--c--- C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 22:09 205000 --a------ C:\WINDOWS\system32\wuweb.dll
2008-07-18 22:09 1811656 --a--c--- C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 22:09 1811656 --a------ C:\WINDOWS\system32\wuaueng.dll
2008-07-18 22:07 270880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-18 22:07 210976 --a------ C:\WINDOWS\system32\muweb.dll
2008-01-29 17:11 88864 --a------ C:\DOCUME~1\Taxi16\APPLIC~1\GDIPFONTCACHEV1.DAT
2005-05-11 23:36 12288 --a------ C:\WINDOWS\Fonts.\RandFont.dll
2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-06 15:35]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 04:34 C:\WINDOWS\system32\bthprops.cpl]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 00:14]
"Opware15"="C:\Program Files\ScanSoft\OmniPage15.0\Opware15.exe" [2005-09-26 18:21]
"PDF3 Registry Controller"="C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\\RegistryController.exe" [2005-08-25 10:33]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 16:57]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 19:19]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12]
"OSSelectorReinstall"="C:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe" [2007-03-09 18:02]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2004-04-06 19:05]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2004-04-23 11:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 20:03]
"H/PC Connection Agent"="C:\PROGRA~1\MI3AA1~1\wcescomm.exe" [2006-11-13 15:07]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-02-07 11:47]
"1&1 EasyLogin"="C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe" [2008-02-27 18:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33]
"Uniblue RegistryBooster 2009"="C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ClearRecentDocsOnExit"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsHistory"=1 (0x1)
"ClearRecentDocsOnExit"=0100000000000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 16:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R2 WSearch;Recherche Windows;C:\WINDOWS\system32\SearchIndexer.exe /Embedding
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys
R3 atinrvxx;ATI WDM Rage Theater Video;C:\WINDOWS\system32\DRIVERS\atinrvxx.sys
R3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
R3 MVDCODEC;ATI WDM Specialized MVD Codec;C:\WINDOWS\system32\DRIVERS\atinmdxx.sys
R3 PID_08A0;QuickCam IM(PID_08A0);C:\WINDOWS\system32\DRIVERS\LV302AV.SYS
R3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys
R3 Slntamr;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys
R3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
R3 VHidMinidrv;Bluetooth HID Device Service;C:\WINDOWS\system32\drivers\VHIDMini.sys
R3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\ZDPNDIS5.SYS
S3 DCamUSBEMPIA;Dazzle DVC90 Video Device;C:\WINDOWS\system32\DRIVERS\emDevice.sys
S3 Dot3svc;Configuration automatique de réseau câblé;C:\WINDOWS\System32\svchost.exe -k dot3svc
S3 EapHost;Service Protocole EAP (Extensible Authentication Protocol);C:\WINDOWS\System32\svchost.exe -k eapsvcs
S3 emAudio;Dazzle DVC90 Audio Device;C:\WINDOWS\system32\drivers\emAudio.sys
S3 FiltUSBEMPIA;USB Device Lower Filter;C:\WINDOWS\system32\DRIVERS\emFilter.sys
S3 hkmsvc;Service Gestion des clés et des certificats d'intégrité;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
S3 napagent;Agent de protection d'accès réseau;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM);C:\WINDOWS\system32\DRIVERS\rfcomm.sys
S3 ScanUSBEMPIA;USB Still Image Capture Device;C:\WINDOWS\system32\DRIVERS\emScan.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys
S3 usb_rndisx;USB RNDIS Adapter;C:\WINDOWS\system32\DRIVERS\usb8023x.sys
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys
S3 V90drv;v90drv;C:\WINDOWS\system32\DRIVERS\v90drv.sys
S3 wceusbsh;Windows CE USB Serial Host Driver;C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
S3 Wdf01000;Wdf01000;C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\C:\WINDOWS\System32\ZDCndis5.SYS
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1083eab8-e7a8-11dc-8178-0060b3eb3df0}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{95f838bb-db4b-11dc-8165-0060b3eb3df0}]
AutoRun\command- F:\InstallTomTomHOME.exe
*Newly Created Service* - ZDPNDIS5
Contents of the 'Scheduled Tasks' folder
2008-10-14 15:31:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-15 10:21:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\\xd8\x2022\x20ac|\xff\xff\xff\xff\22\x2022\x20ac|\xf9\x20229~\2]
"C040710900063D11C8EF10054038389C"="C?\WINDOWS\system32\FM20ENU.DLL"
scanning hidden files ...
**************************************************************************
Completion time: 2008-10-15 10:24:18