ComboFix 09-03-28.06 - Simon 2009-03-29 22:25:36.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3326.2248 [GMT 2:00]
Lancé depuis: c:\users\Simon\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\Simon\Desktop\CFScript.txt
FW: ZoneAlarm Firewall *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Privacy center\agent.exe\
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-29 ))))))))))))))))))))))))))))))))))))
.
2009-03-29 14:24 . 2009-03-29 14:26 <REP> d-------- C:\rsit
2009-03-29 13:44 . 2009-03-29 13:44 <REP> d-------- c:\users\Simon\AppData\Roaming\Privacy center
2009-03-29 13:44 . 2009-03-29 16:03 <REP> d-------- c:\program files\Privacy center
2009-03-29 13:36 . 2009-03-29 14:58 <REP> d-------- c:\program files\EoRezo
2009-03-21 12:07 . 2009-03-21 13:02 <REP> d-------- c:\program files\Dofus
2009-03-19 09:52 . 2009-03-25 15:03 20,225 --a------ c:\windows\System32\SFP
2009-03-18 13:35 . 2009-03-18 13:35 <REP> d-------- c:\users\Serge\AppData\Roaming\Snappy Fax Archives
2009-03-18 13:34 . 2009-03-19 09:55 <REP> d-------- c:\users\Serge\AppData\Roaming\Snappy Fax
2009-03-18 13:34 . 2009-03-18 13:34 <REP> d-------- c:\program files\Snappy Fax Version 4
2009-03-18 13:34 . 2007-04-11 15:38 26,112 --a------ c:\windows\System32\sfppm.dll
2009-03-18 13:05 . 2009-03-18 13:06 <REP> d-------- c:\users\All Users\tpfmon
2009-03-18 13:05 . 2009-03-18 13:06 <REP> d-------- c:\programdata\tpfmon
2009-03-18 13:05 . 2009-03-18 13:05 <REP> d-------- c:\program files\Alliance MCA
2009-03-14 20:09 . 2009-03-14 20:09 <REP> d-------- c:\users\All Users\Messenger Plus!
2009-03-14 20:09 . 2009-03-14 20:09 <REP> d-------- c:\programdata\Messenger Plus!
2009-03-14 17:14 . 2009-03-28 23:30 <REP> d-------- c:\users\All Users\Google Updater
2009-03-14 17:14 . 2009-03-28 23:30 <REP> d-------- c:\programdata\Google Updater
2009-03-14 16:59 . 2009-03-29 21:25 118,448 --a------ c:\windows\System32\GDIPFONTCACHEV1.DAT
2009-03-14 14:01 . 2009-03-14 14:03 <REP> d-------- c:\users\Simon\AppData\Roaming\U3
2009-03-11 21:41 . 2009-03-11 21:40 64,160 --a------ c:\windows\System32\drivers\Lbd.sys
2009-03-11 20:52 . 2008-06-20 03:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-03-11 20:52 . 2008-06-20 03:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-03-11 20:52 . 2008-06-20 03:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-03-11 20:52 . 2008-06-20 03:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-03-11 20:52 . 2008-06-20 03:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-03-11 20:52 . 2008-06-20 03:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-03-11 20:52 . 2008-06-20 03:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-03-11 20:52 . 2008-06-20 03:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-03-11 20:47 . 2008-07-27 20:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-03-11 20:47 . 2008-07-27 20:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-03-11 20:47 . 2008-07-27 20:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-03-11 20:46 . 2008-07-27 20:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-03-11 20:46 . 2008-07-27 20:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-03-11 08:57 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 08:57 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 08:57 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 08:57 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 08:56 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 08:56 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-09 22:08 . 2009-03-09 22:08 <REP> d-------- c:\users\Simon\AppData\Roaming\SolidDocuments
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 20:28 352,615 ---ha-w c:\windows\system32\drivers\vsconfig.xml
2009-03-29 19:12 524,288 --sha-w c:\users\Invité\NTUSER.DAT
2009-03-29 19:12 524,288 --sha-w c:\users\Invité\NTUSER.DAT
2009-03-29 12:59 --------- d-----w c:\program files\Trend Micro
2009-03-29 12:55 --------- d-----w c:\users\Simon\AppData\Roaming\EoRezo
2009-03-29 12:46 --------- d-----w c:\program files\DivX
2009-03-29 12:46 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-03-14 18:04 --------- d-----w c:\program files\Messenger Plus! Live
2009-03-14 17:51 --------- d-----w c:\program files\Google
2009-03-11 22:41 --------- d-----w c:\program files\Windows Mail
2009-03-11 19:41 15,688 ----a-w c:\windows\System32\lsdelete.exe
2009-03-04 21:36 --------- d-----w c:\users\Simon\AppData\Roaming\dvdcss
2009-02-26 14:02 118,448 ----a-w c:\users\Serge\AppData\Roaming\GDIPFONTCACHEV1.DAT
2009-02-23 23:18 --------- dc-h--w c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-23 23:17 --------- d-----w c:\program files\Lavasoft
2009-02-23 23:01 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-23 15:28 --------- d-----w c:\program files\Microsoft
2009-02-21 10:56 5,538,894 ----a-w c:\windows\Internet Logs\tvDebug.zip
2009-02-14 21:35 --------- d-----w c:\programdata\eMule
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-08 18:53 --------- d-----w c:\program files\myBabylon_English
2009-02-06 17:52 49,504 ----a-w c:\windows\System32\sirenacm.dll
2009-01-27 17:19 113,312 ----a-w c:\users\Simon\AppData\Roaming\GDIPFONTCACHEV1.DAT
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2009-01-07 20:44 126,464 ----a-w c:\windows\Internet Logs\xDB698B.tmp
2009-01-07 20:44 1,967,616 ----a-w c:\windows\Internet Logs\xDB6A47.tmp
2009-01-05 16:54 3,122,176 ----a-w c:\windows\Internet Logs\xDB5ACC.tmp
2008-04-05 10:09 174 --sha-w c:\program files\desktop.ini
2008-04-12 21:27 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-12 21:27 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-12 21:27 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot_2009-03-29_20.47.43,79 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-29 18:42:51 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 20:28:30 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 20:28:30 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 18:42:46 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 20:28:30 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 20:28:30 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-29 18:41:19 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-29 20:28:09 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-29 18:41:19 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-29 20:28:09 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-29 18:41:19 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-29 20:28:09 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-29 18:25:51 101,052 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-29 18:48:34 101,052 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-29 18:25:51 123,350 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-03-29 18:48:34 123,350 ----a-w c:\windows\System32\perfc00C.dat
- 2009-03-29 18:25:51 586,980 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-29 18:48:34 586,980 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-29 18:25:51 669,328 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-03-29 18:48:34 669,328 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-29 18:43:33 10,730 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-980281660-3623804645-3202006737-1003_UserData.bin
+ 2009-03-29 20:30:06 11,010 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-980281660-3623804645-3202006737-1003_UserData.bin
- 2009-03-29 18:43:33 72,622 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-29 20:30:06 72,766 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2008-08-21 00:03 1780248 --a------ c:\program files\myBabylon_English\tbmyBa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\program files\myBabylon_English\tbmyBa.dll" [2008-08-21 1780248]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\program files\myBabylon_English\tbmyBa.dll" [2008-08-21 1780248]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-14 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-11 515416]
"Snappy Fax Printer Agent"="c:\program files\Snappy Fax Version 4\sfpagent.exe" [2007-04-11 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SoftwareHelper"="c:\users\Simon\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe" [2008-12-09 368224]
c:\users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "c:\progra~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Reine^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Reine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Serge^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ORAHSSSessionManager]
--a------ 2007-12-12 09:50 107248 c:\program files\OrangeHSS\SessionManager\SessionManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-11-16 13:01 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-18 23:33 202240 c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{14B849A4-AB58-4FF8-9519-C458304EDE10}"= UDP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"{BDCC77A1-DAB2-47D5-957B-A674126B888D}"= TCP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"{DD23DEDA-D2DD-4E19-9A01-D19907B46120}"= UDP:c:\program files\eMule\emule.exe:eMule
"{C566C38F-0444-49F0-83CE-298B93AB1326}"= TCP:c:\program files\eMule\emule.exe:eMule
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-03-11 64160]
R2 SCPDFV4ReadSpool;SolidConverterPDFv4ReadSpool;c:\windows\Installer\MSI6150.tmp [2009-01-06 189688]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\atl01v32.sys [2008-04-05 48128]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007, 0.1.12.1;c:\windows\System32\drivers\libusb0.sys [2008-11-16 28672]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [2008-09-13 28224]
S3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr61.sys [2007-05-11 357376]
S4 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-06 33752]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{32e4d3cd-a4d1-11dd-85c7-001e8c547df6}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2009-03-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-11 21:37]
2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 19:23]
2009-03-29 c:\windows\Tasks\User_Feed_Synchronization-{6769D966-70CB-4CBB-B3B6-2F240B12C33F}.job
- c:\windows\system32\msfeedssync.exe [2008-01-18 23:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://lo.st#home
mWindow Title =
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
Trusted Zone: mappy.com
Trusted Zone: orange.fr
Trusted Zone: voila.fr\rw.search.ke
Trusted Zone: weborama.fr\orange
DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} - hxxps://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} - hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerVistaADP-1.1.cab
FF - ProfilePath - c:\users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\gmha1iuf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://lo.st#home
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-29 22:28:51
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\windows\TEMP\TMP00000003921F42CECA081610 524288 bytes executable
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\conime.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Heure de fin: 2009-03-29 22:34:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-29 20:34:05
ComboFix2.txt 2009-03-29 18:57:36
ComboFix3.txt 2009-03-29 18:48:54
ComboFix4.txt 2009-03-29 13:26:36
Avant-CF: 317 219 815 424 octets libres
Après-CF: 319,502,831,616 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4,22
262 --- E O F --- 2009-03-26 17:26:07