Le Rapport:
ComboFix 09-08-06.01 - Emilie 07/08/2009 6:21.1.2 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.3.1252.33.1036.18.511.195 [GMT 2:00]
Running from: c:documents and settingsEmilieBureauComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:windowsInstaller20975.msi
c:windowsInstaller70bc5.msp
c:windowsInstaller70c4d.msp
c:windowsInstallerdd09f.msp
c:windowsInstallerde2c.msi
c:windowsInstallerf25cdc.msi
c:windowsInstallerWinRMSrv.msi
c:windowsInstallerWMEncoder.msi
c:windowssystem32prqss.bak1
c:windowssystem32prqss.bak2
c:windowssystem32prqss.ini
c:windowssystem32
naph.dll
c:windowssystem32uninstall.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Legacy_MICROSOFT_GENUINE_UPDATE_ADVANTAGE
((((((((((((((((((((((((( Files Created from 2009-07-07 to 2009-08-07 )))))))))))))))))))))))))))))))
.
2009-08-06 16:31 . 2009-07-26 14:57 177520 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006NAVENG32.DLL
2009-08-06 16:31 . 2009-07-26 14:57 1181040 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006NAVEX32A.DLL
2009-08-06 16:31 . 2009-07-26 08:00 87888 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006NAVENG.SYS
2009-08-06 16:31 . 2009-07-26 08:00 875728 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006NAVEX15.SYS
2009-08-06 16:31 . 2009-07-26 14:57 371248 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006EECTRL.SYS
2009-08-06 16:31 . 2009-07-26 14:57 101936 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006ERASER.SYS
2009-08-06 16:31 . 2009-07-26 14:57 259368 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006ECMSVR32.DLL
2009-08-06 16:31 . 2009-07-26 14:57 2414128 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsVirusDefs20090806.006CCERASER.DLL
2009-08-05 19:23 . 2009-08-03 11:36 38160 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2009-08-05 19:23 . 2009-08-03 11:36 19096 ----a-w- c:windowssystem32driversmbam.sys
2009-08-05 19:23 . 2009-08-05 19:23 -------- d-----w- c:program filesMalwarebytes' Anti-Malware
2009-08-02 18:24 . 2009-08-02 18:26 -------- dc-h--w- c:windowsie8
2009-07-31 04:43 . 2009-07-11 19:34 276344 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090730.003IDSXpx86.sys
2009-07-31 04:43 . 2009-07-11 19:34 293424 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090730.003IDSvix86.sys
2009-07-31 04:43 . 2009-07-11 19:34 533880 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090730.003Scxpx86.dll
2009-07-31 04:43 . 2009-07-11 19:34 451960 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090730.003IDSxpx86.dll
2009-07-31 04:43 . 2009-07-11 19:34 397360 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090730.003IDSviA64.sys
2009-07-29 04:54 . 2009-07-03 16:57 55296 -c----w- c:windowssystem32dllcachemsfeedsbs.dll
2009-07-29 04:54 . 2009-07-03 16:57 594432 -c----w- c:windowssystem32dllcachemsfeeds.dll
2009-07-28 04:33 . 2009-07-11 19:34 276344 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090722.001IDSXpx86.sys
2009-07-28 04:33 . 2009-07-11 19:34 533880 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090722.001Scxpx86.dll
2009-07-28 04:33 . 2009-07-11 19:34 293424 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090722.001IDSvix86.sys
2009-07-28 04:33 . 2009-07-11 19:34 451960 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090722.001IDSxpx86.dll
2009-07-28 04:33 . 2009-07-11 19:34 397360 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090722.001IDSviA64.sys
2009-07-26 14:57 . 2009-07-26 14:57 36400 ----a-r- c:windowssystem32driversSymIM.sys
2009-07-26 14:57 . 2009-07-26 14:57 1290592 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonSyKnAppSSyKnAppS.dll
2009-07-26 14:57 . 2009-07-26 14:57 136840 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonSyKnAppSpatch25.dll
2009-07-26 14:57 . 2009-07-26 14:57 796016 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonCLTcltLMSx.dll
2009-07-26 14:56 . 2009-07-26 14:56 -------- d-----w- c:windowssystem32driversNAV
2009-07-26 14:56 . 2009-07-26 14:57 -------- d-----w- c:program filesNorton AntiVirus
2009-07-26 14:56 . 2009-07-26 14:56 -------- d-----w- c:program filesWindows Sidebar
2009-07-26 14:48 . 2009-07-26 14:56 -------- d-----w- c:documents and settingsAll UsersApplication DataNorton
2009-07-26 14:48 . 2009-07-26 14:48 -------- d-----w- c:documents and settingsAll UsersApplication DataNortonInstaller
2009-07-26 14:48 . 2009-07-26 14:48 -------- d-----w- c:program filesNortonInstaller
2009-07-26 14:31 . 2009-07-26 14:31 -------- d-----w- c:documents and settingsAll UsersSymantec Temporary Files
2009-07-11 19:34 . 2009-07-11 19:34 276344 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefsBinHubIDSXpx86.sys
2009-07-11 19:34 . 2009-07-11 19:34 293424 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefsBinHubIDSvix86.sys
2009-07-11 19:34 . 2009-07-11 19:34 533880 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefsBinHubScxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 451960 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefsBinHubIDSxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 397360 ----a-w- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefsBinHubIDSviA64.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 04:34 . 2004-03-20 09:43 -------- d-----w- c:documents and settingsAll UsersApplication DataSymantec
2009-07-26 15:10 . 2004-03-20 09:43 -------- d-----w- c:program filesFichiers communsSymantec Shared
2009-07-26 14:57 . 2004-03-20 09:43 -------- d-----w- c:program filesSymantec
2009-07-26 14:57 . 2009-07-26 14:57 805 ----a-w- c:windowssystem32driversSYMEVENT.INF
2009-07-26 14:57 . 2009-07-26 14:57 7386 ----a-w- c:windowssystem32driversSYMEVENT.CAT
2009-07-26 14:57 . 2004-03-20 09:44 60808 ----a-w- c:windowssystem32S32EVNT1.DLL
2009-07-26 14:57 . 2004-03-20 09:44 124464 ----a-w- c:windowssystem32driversSYMEVENT.SYS
2009-07-26 14:57 . 2009-08-07 04:30 165240 ----a-r- c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonIPSFFPlgncomponentsIPSFFPl.dll
2009-07-04 10:03 . 2009-07-04 10:03 0 ---ha-w- c:windowssystem32driversMsft_Kernel_NuidFltr_01005.Wdf
2009-07-04 10:03 . 2009-07-04 10:03 0 ---ha-w- c:windowssystem32driversMsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-03 16:57 . 2004-07-07 16:59 915456 ----a-w- c:windowssystem32wininet.dll
2009-06-25 19:32 . 2009-06-25 19:32 -------- d-----w- c:documents and settingsEmilieApplication DataMalwarebytes
2009-06-25 19:32 . 2009-06-25 19:32 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes
2009-06-16 14:40 . 2003-04-09 23:41 119808 ----a-w- c:windowssystem32 2embed.dll
2009-06-16 14:40 . 2003-04-09 23:40 81920 ----a-w- c:windowssystem32fontsub.dll
2009-06-03 19:10 . 2003-05-30 08:00 1297408 ----a-w- c:windowssystem32quartz.dll
2006-06-23 15:57 . 2006-06-23 15:57 278528 ----a-w- c:program filesFichiers communsFDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"WMPNSCFG"="c:program filesWindows Media PlayerWMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="c:windowsSystem32NvCpl.dll" [2003-04-02 4616192]
"ezShieldProtector for Px"="c:windowsSystem32ezSP_Px.exe" [2002-08-20 40960]
"QuickTime Task"="c:program filesQuickTimeqttask.exe" [2006-02-15 155648]
"itype"="c:program filesMicrosoft IntelliType Proitype.exe" [2006-07-07 576320]
"IntelliPoint"="c:program filesMicrosoft IntelliPointipoint.exe" [2006-07-07 600896]
"LifeCam"="c:program filesMicrosoft LifeCamLifeExp.exe" [2007-05-17 279912]
"Adobe Reader Speed Launcher"="c:program filesAdobeReader 8.0ReaderReader_sl.exe" [2008-01-11 39792]
"CanonMyPrinter"="c:program filesCanonMyPrinterBJMyPrt.exe" [2007-04-04 1603152]
"ArcSoft Connection Service"="c:program filesFichiers communsArcSoftConnection ServiceBinACDaemon.exe" [2008-04-17 98616]
"EEventManager"="c:progra~1EPSONS~1EVENTM~1EEventManager.exe" [2008-05-07 591696]
"SunJavaUpdateSched"="c:program filesJavajre6injusched.exe" [2009-03-09 148888]
"nwiz"="nwiz.exe" - c:windowssystem32
wiz.exe [2003-04-02 323584]
"AGRSMMSG"="AGRSMMSG.exe" - c:windowsAGRSMMSG.exe [2003-02-14 88107]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowsSystem32CTFMON.EXE" [2008-04-14 15360]
c:documents and settingsEmilieMenu D,marrerProgrammesD,marrage
PowerReg Scheduler.exe [2004-9-17 225280]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalSymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusOverride"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"c:\Program Files\IncrediMail\bin\ImpCnt.exe"=
"c:\Program Files\Messenger\msmsgs.exe"=
"d:\Program Files\eMule\emule.exe"=
"c:\Program Files\Microsoft LifeCam\LifeCam.exe"=
"c:\Program Files\Microsoft LifeCam\LifeExp.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\Program Files\MSN Messenger\msnmsgr.exe"=
"c:\Program Files\MSN Messenger\livecall.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5905:TCP"= 5905:TCP:vnc
R0 SymEFA;Symantec Extended File Attributes;c:windowssystem32driversNAV1005000.086SymEFA.sys [26/07/2009 16:57 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:windowssystem32driversNAV1005000.086BHDrvx86.sys [26/07/2009 16:57 258608]
R1 ccHP;Symantec Hash Provider;c:windowssystem32driversNAV1005000.086cchpx86.sys [26/07/2009 16:57 482352]
R1 IDSxpx86;IDSxpx86;c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonDefinitionsIPSDefs20090730.003IDSXpx86.sys [31/07/2009 06:43 276344]
R2 Norton AntiVirus;Norton AntiVirus;c:program filesNorton AntiVirusEngine16.5.0.134ccSvcHst.exe [26/07/2009 16:57 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:program filesFichiers communsSymantec SharedEENGINEEraserUtilRebootDrv.sys [26/07/2009 17:07 101936]
R3 MSHUSBVideo;NX6000/NX3000/VX7000 Filter Driver;c:windowssystem32drivers
x6000.sys [28/12/2007 10:18 34136]
R3 RTL8187B;TG123g USB Wireless Adapter;c:windowssystem32driversRTL8187B.sys [15/08/2008 16:18 264576]
S3 ca506aaf;ADS USB Audio Filter Driver (WDM);c:windowssystem32driversca506aaf.sys [17/09/2004 16:04 14273]
S3 SPCA506AV;USB Instant VCD;c:windowssystem32driversCA506AV.SYS [17/09/2004 16:04 178835]
.
- - - - ORPHANS REMOVED - - - -
BHO-{7CF444BC-D58E-4D05-BC61-ECA2D44EB9D6} - (no file)
Toolbar-Locked - (no file)
HKU-Default-Run-ALUAlert - c:program filesSymantecLiveUpdateALUNotify.exe
Notify-ssqrp - c:windowssystem32ssqrp.dll
Notify-nnnlkhg - nnnlkhg.dll
.
------- Supplementary Scan -------
.
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
DPF: DirectAnimation Java Classes -
file://c:windowsJavaclassesdajava.cab
DPF: Microsoft XML Parser for Java -
file://c:windowsJavaclassesxmldso.cab
FF - ProfilePath - c:documents and settingsEmilieApplication DataMozillaFirefoxProfiles5kfz3b6m.default
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage -
hxxp://orange.fr
FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt ... =MIMWA1&q=
FF - component: c:documents and settingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NortonIPSFFPlgncomponentsIPSFFPl.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-07 06:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001ServicesNorton AntiVirus]
"ImagePath"=""c:program filesNorton AntiVirusEngine16.5.0.134ccSvcHst.exe" /s "Norton AntiVirus" /m "c:program filesNorton AntiVirusEngine16.5.0.134diMaster.dll" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{47629D4B-2AD3-4e50-B716-A66C15C63153}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,b4,df,52,22,a4,
f1,96,21,e2,63,26,f1,3f,c8,ff,68,50,e4,84,48,69,f2,ec,00,e2,63,26,f1,3f,c8,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{604BB98A-A94F-4a5c-A67C-D8D3582C741C}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,5c,89,4f,27,e1,
6b,b0,97,6a,9c,d6,61,af,45,84,18,e3,06,32,a2,8b,fe,91,68,6a,9c,d6,61,af,45,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{684373FB-9CD8-4e47-B990-5A4466C16034}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,a0,1c,41,7b,41,
65,8f,97,ff,7c,85,e0,43,d4,0e,fe,01,0f,cc,1c,78,40,d7,b3,ff,7c,85,e0,43,d4,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{74554CCD-F60F-4708-AD98-D0152D08C8B9}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,33,e3,67,62,25,
28,ee,51,86,8c,21,01,be,91,eb,e7,43,c9,4c,98,a4,52,c0,cf,86,8c,21,01,be,91,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{7EB537F9-A916-4339-B91B-DED8E83632C0}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,69,22,9b,f1,6e,
fe,83,5c,f5,1d,4d,73,a8,13,5c,05,51,f3,66,c4,36,8a,7c,84,f5,1d,4d,73,a8,13,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{948395E8-7A56-4fb1-843B-3E52D94DB145}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,fd,52,84,95,36,
5d,71,90,df,20,58,62,78,6b,cf,c8,72,79,6f,19,b5,0e,0e,37,df,20,58,62,78,6b,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,e4,29,b7,2e,cd,
e7,5c,56,fb,a7,78,e6,12,2f,9a,ea,62,16,42,c8,29,01,84,48,fb,a7,78,e6,12,2f,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{DE5654CA-EB84-4df9-915B-37E957082D6D}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:aa,52,c6,00,84,3c,26,64,f9,a6,83,97,af,
d9,34,27,01,3a,48,fc,e8,04,4a,f1,78,4a,85,c5,e3,77,ec,51,01,3a,48,fc,e8,04,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{E39C35E8-7488-4926-92B2-2F94619AC1A5}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,56,ed,59,e7,dc,
4e,13,c0,f6,0f,4e,58,98,5b,89,c9,c9,77,70,f3,4c,6d,9c,2c,f6,0f,4e,58,98,5b,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,b2,ee,00,f8,06,
f8,b4,c6,3d,ce,ea,26,2d,45,aa,78,0d,e1,95,64,c3,54,e4,30,3d,ce,ea,26,2d,45,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,2e,17,2f,a2,49,
b8,91,a8,2a,b7,cc,b5,b9,7f,41,e7,58,43,b0,11,41,62,67,bb,2a,b7,cc,b5,b9,7f,
[HKEY_LOCAL_MACHINEsoftwareClassesCLSID{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\WINDOWS\system32\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,ee,47,9e,2b,63,
7a,87,70,6c,43,2d,1e,aa,22,2f,9c,8e,17,e9,3f,35,e9,92,0c,6c,43,2d,1e,aa,22,
[HKEY_LOCAL_MACHINEsoftwareMicrosoftWindowsCurrentVersionInstallerUserDataLocalSystemComponentsØ.€|yyyy.€|ù.9~*]
"C040110900063D11C8EF10054038389C"="C?\WINDOWS\system32\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2812)
c:windowssystem32webcheck.dll
c:progra~1FICHIE~1MICROS~1WEBCOM~110OWC10.DLL
c:program filesFichiers communsMicrosoft SharedWeb Components101036OWCI10.DLL
c:progra~1FICHIE~1MICROS~1WEBCOM~111OWC11.DLL
c:program filesFichiers communsMicrosoft SharedWeb Components111036OWCI11.DLL
c:windowssystem32msls31.dll
c:windowssystem32eappprxy.dll
c:windowssystem32WPDShServiceObj.dll
c:windowssystem32PortableDeviceTypes.dll
c:windowssystem32PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:program filesFichiers communsArcSoftConnection ServiceBinACService.exe
c:windowssystem32driversCDAC11BA.EXE
c:program filesCanonIJPLMijplmsvc.exe
c:program filesJavajre6injqs.exe
c:program filesFichiers communsMicrosoft SharedVS7DEBUGMDM.EXE
c:program filesMicrosoft LifeCamMSCamS32.exe
c:windowssystem32
vsvc32.exe
c:program filesWindows Media Playerwmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-08-07 6:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-07 04:35
Pre-Run: 10 537 799 680 octets libres
Post-Run: 10 998 882 304 octets libres
269 --- E O F --- 2009-07-29 04:59