Salut je vais poster le raport
ComboFix 08-11-16.01 - Administrateur 2008-11-17 14:10:41.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.725 [GMT 1:00]
Lancé depuis: e:\documents and settings\Administrateur\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\recycler\AmericanOnLine.exe
c:\recycler\RECYCLER .exe
C:\zPharaoh.exe
D:\Autorun.inf
d:\recycler\Crack_GoogleEarthPro.exe
d:\recycler\RECYCLER .exe
d:\recycler\RECYCLER .exe
D:\zPharaoh.exe
E:\autorun.inf
e:\documents and settings\Administrateur\Application Data\tazebama
e:\documents and settings\Administrateur\Application Data\tazebama\tazebama.log
e:\documents and settings\Administrateur\Application Data\tazebama\zPharaoh.dat
e:\windows\IE4 Error Log.txt
E:\zPharaoh.exe
.
---- Previous Run -------
.
C:\Autorun.inf
c:\recycler\Crack_GoogleEarthPro.exe
c:\recycler\RECYCLER .exe
C:\zPharaoh.exe
D:\Autorun.inf
d:\recycler\Office2007 Serial.txt.exe
d:\recycler\RECYCLER .exe
D:\zPharaoh.exe
E:\Autorun.inf
e:\documents and settings\Administrateur\Application Data\tazebama
e:\documents and settings\Administrateur\Application Data\tazebama\tazebama.log
e:\documents and settings\Administrateur\Application Data\tazebama\zPharaoh.dat
e:\documents and settings\Administrateur\Local Settings\Application Data\ieeiwsc.dat
e:\documents and settings\Administrateur\Local Settings\Application Data\ieeiwsc.exe
e:\documents and settings\Administrateur\Local Settings\Application Data\ieeiwsc_nav.dat
e:\documents and settings\Administrateur\Local Settings\Application Data\ieeiwsc_navps.dat
e:\documents and settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer
e:\documents and settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Conditions générales.url
e:\documents and settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Confidentialité.url
e:\documents and settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Désinstaller.lnk
e:\documents and settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\WebMediaPlayer.lnk
e:\documents and settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Website.url
e:\program files\webmediaplayer
e:\program files\webmediaplayer\resources\wmp_translation_file.xml
e:\program files\webmediaplayer\skins\classic.skn
e:\program files\webmediaplayer\sqlite3.dll
e:\program files\webmediaplayer\uninst.exe
e:\program files\webmediaplayer\WebMediaPlayer.exe
e:\windows\IE4 Error Log.txt
e:\windows\system32\MSINET.oca
E:\zPharaoh.exe
G:\autorun.inf
G:\zPharaoh.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-17 au 2008-11-17 ))))))))))))))))))))))))))))))))))))
.
2008-11-17 14:18 . 2008-11-17 14:19 <REP> d-------- e:\documents and settings\Administrateur\Application Data\tazebama
2008-11-17 14:18 . 2008-11-17 14:18 155,011 -r-hs---- E:\zPharaoh.exe
2008-11-17 14:11 . 2008-11-17 14:19 126 -r-hs---- E:\autorun.inf
2008-11-17 13:09 . 2008-11-17 14:18 154,751 --a------ e:\documents and settings\hook.dl_
2008-11-17 12:38 . 2008-11-17 13:45 <REP> d-------- e:\program files\Navilog1
2008-11-13 20:00 . 2008-11-14 20:02 54,156 --ah----- e:\windows\QTFont.qfn
2008-11-13 20:00 . 2008-11-13 20:00 1,409 --a------ e:\windows\QTFont.for
2008-11-13 19:53 . 2008-11-13 20:12 <REP> d-------- e:\documents and settings\Administrateur\Application Data\Ulead Systems
2008-11-13 19:09 . 2008-11-13 19:49 <REP> d-------- e:\documents and settings\All Users\Application Data\{AB3EC276-D261-4943-A921-1CC1C6799AED}
2008-11-13 18:48 . 2008-11-13 18:48 <REP> d-------- e:\program files\SmartSound Software
2008-11-13 18:48 . 2008-11-13 18:48 <REP> d-------- e:\program files\QuickTime
2008-11-13 18:48 . 2008-11-13 18:48 <REP> d-------- e:\documents and settings\All Users\Application Data\SmartSound Software Inc
2008-11-13 18:48 . 2008-11-13 18:48 <REP> d-------- e:\documents and settings\All Users\Application Data\Apple Computer
2008-11-13 18:47 . 2008-11-13 18:47 <REP> d-------- e:\program files\Windows Media Components
2008-11-13 18:47 . 2008-11-13 18:47 <REP> d-------- e:\program files\Fichiers communs\InterVideo
2008-11-13 18:47 . 2008-11-13 18:47 <REP> d-------- e:\documents and settings\All Users\Application Data\InterVideo
2008-11-13 18:47 . 2007-03-06 11:58 210,456 --a------ e:\windows\system32\IVIresizeW7.dll
2008-11-13 18:47 . 2007-03-06 11:58 206,360 --a------ e:\windows\system32\IVIresizeA6.dll
2008-11-13 18:47 . 2007-03-06 11:58 198,168 --a------ e:\windows\system32\IVIresizeP6.dll
2008-11-13 18:47 . 2007-03-06 11:58 198,168 --a------ e:\windows\system32\IVIresizeM6.dll
2008-11-13 18:47 . 2007-03-06 11:58 194,072 --a------ e:\windows\system32\IVIresizePX.dll
2008-11-13 18:47 . 2007-03-06 11:58 26,136 --a------ e:\windows\system32\IVIresize.dll
2008-11-13 18:46 . 2008-11-13 18:46 <REP> d-------- e:\program files\Ulead Systems
2008-11-13 18:46 . 2008-11-13 18:47 <REP> d-------- e:\program files\Fichiers communs\Ulead Systems
2008-11-13 18:46 . 2008-11-13 19:53 <REP> d-------- e:\documents and settings\All Users\Application Data\Ulead Systems
2008-11-13 18:32 . 2008-11-13 18:37 293 --a------ e:\windows\TEXTWARE.INI
2008-11-13 18:31 . 2008-11-13 18:31 <REP> d-------- e:\program files\TEXTware
2008-11-13 18:30 . 2008-11-13 18:31 <REP> d-------- e:\program files\Cambridge
2008-11-13 18:30 . 2000-12-13 16:47 1,046,288 --a------ e:\windows\system32\msjet35.dll
2008-11-13 18:30 . 2001-05-08 15:59 747,104 --a------ e:\windows\system32\Atx45.ocx
2008-11-13 18:30 . 1996-11-08 02:48 368,912 --a------ e:\windows\system32\vbar332.dll
2008-11-13 18:30 . 1995-07-25 09:00 200,704 --a------ e:\windows\system32\threed32.ocx
2008-11-13 18:30 . 2000-05-22 00:00 198,848 --a------ e:\windows\system32\MCI32.OCX
2008-11-13 18:30 . 2000-12-13 16:47 123,664 --a------ e:\windows\system32\MSJINT35.DLL
2008-11-13 18:30 . 1995-07-25 09:00 78,848 --a------ e:\windows\system32\MSOUTL32.OCX
2008-11-13 18:30 . 2001-04-17 14:17 74,752 --a------ e:\windows\system32\ATX45PIC.dll
2008-11-13 18:30 . 1996-09-10 23:33 48,640 --a------ e:\windows\system32\INETWH32.DLL
2008-11-13 18:30 . 1999-11-23 02:28 25,600 --a------ e:\windows\system32\Atx45ole.dll
2008-11-13 18:30 . 2000-12-13 16:47 24,848 --a------ e:\windows\system32\MSJTER35.DLL
2008-11-13 16:59 . 2008-11-14 20:21 <REP> d-------- e:\program files\Save
2008-11-13 16:58 . 2008-11-13 16:58 <REP> d-------- E:\My Downloads
2008-11-13 15:19 . 2008-11-13 15:19 <REP> d-------- e:\documents and settings\All Users\Application Data\7399
2008-11-13 14:58 . 2008-09-25 14:20 483,328 --a------ e:\windows\system32\actskn45.ocx
2008-11-13 14:45 . 2008-11-13 14:45 <REP> d-------- e:\program files\Pivot Stickfigure Animator
2008-11-13 14:18 . 2008-11-13 14:59 <REP> d-------- e:\program files\BearShare Applications
2008-11-13 13:32 . 2008-11-13 16:59 <REP> d-------- e:\program files\WeatherCast
2008-11-12 20:44 . 2005-05-03 11:43 131,072 -r------- e:\windows\Alcmtr.exe
2008-11-12 20:30 . 2008-11-12 20:36 4,716 --a------ e:\windows\gdrv.sys
2008-11-11 21:01 . 2008-11-11 21:01 <REP> d-------- e:\program files\Trend Micro
2008-11-11 15:55 . 2008-11-12 16:05 <REP> d-------- e:\program files\AutoTyping Pro
2008-11-11 15:55 . 2008-11-11 15:55 0 --a------ e:\windows\system32\8012173.maz
2008-11-11 11:46 . 2008-11-12 16:06 <REP> d-------- e:\program files\Algematics
2008-11-09 22:09 . 2008-11-09 22:09 <REP> d-------- e:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-11-07 21:56 . 2008-11-11 13:18 121 --a------ e:\windows\bdagent.INI
2008-11-07 21:27 . 2008-11-17 14:18 154,751 --a------ e:\documents and settings\tazebama.dl_
2008-11-07 21:27 . 2008-11-17 14:18 32,768 --a------ e:\documents and settings\tazebama.dll
2008-11-07 21:25 . 2008-11-07 21:25 73,216 --a------ E:\RCX224.tmp
2008-11-07 15:26 . 2008-11-07 15:26 <REP> d-------- e:\program files\BitDefender
2008-11-07 15:26 . 2008-11-11 13:15 81,984 --a------ e:\windows\system32\bdod.bin
2008-11-07 15:25 . 2008-11-11 13:18 <REP> d-------- e:\program files\Fichiers communs\BitDefender
2008-11-03 21:20 . 2008-11-03 21:20 <REP> d-------- e:\program files\Fichiers communs\Windows Live
2008-11-03 16:56 . 2008-11-09 21:00 <REP> d-------- e:\program files\honestech Video Editor 7.0 Trial
2008-10-31 15:56 . 2008-10-31 15:56 <REP> d-------- e:\documents and settings\Administrateur\Application Data\ICQ Toolbar
2008-10-31 15:55 . 2008-10-31 15:55 <REP> d-------- E:\Temp
2008-10-31 15:54 . 2008-11-09 20:59 <REP> d-------- e:\program files\ICQToolbar
2008-10-31 15:53 . 2008-11-09 20:58 <REP> d-------- e:\program files\ICQLite
2008-10-31 14:07 . 2008-10-31 14:07 <REP> d-------- e:\windows\Applian FLV Player
2008-10-31 14:07 . 2008-10-31 14:07 <REP> d-------- e:\program files\FLV Player
2008-10-31 14:07 . 2008-10-31 14:10 1,107,968 --a------ e:\program files\FLV PlayerFCSetup.exe
2008-10-30 21:13 . 2008-10-30 21:13 <REP> d-------- e:\documents and settings\All Users\SonicStage
2008-10-30 21:11 . 2001-09-13 02:15 90,112 --------- e:\windows\snymsico.dll
2008-10-30 21:11 . 2002-08-08 15:51 38,951 --------- e:\windows\system32\drivers\NETMDUSB.sys
2008-10-30 21:11 . 2005-10-31 10:46 36,679 --------- e:\windows\system32\drivers\NETMD052.sys
2008-10-30 21:11 . 2003-11-10 12:31 36,232 --------- e:\windows\system32\drivers\NETMD033.sys
2008-10-30 21:11 . 2003-04-01 18:55 35,319 --------- e:\windows\system32\drivers\NETMD031.sys
2008-10-30 21:10 . 2008-10-30 21:11 <REP> d-------- e:\program files\Sony
2008-10-30 21:10 . 2008-10-30 21:10 <REP> d-------- e:\documents and settings\All Users\Application Data\Sony Corporation
2008-10-30 21:09 . 2008-10-30 21:09 <REP> d-------- e:\program files\Fichiers communs\Sony Shared
2008-10-30 21:09 . 2008-10-30 21:13 <REP> d-------- e:\documents and settings\Administrateur\Application Data\Sony Corporation
2008-10-27 19:11 . 2008-10-27 19:11 385 --a------ e:\windows\ODBC.INI
2008-10-27 19:10 . 2008-10-27 19:10 <REP> d-------- e:\program files\Microsoft.NET
2008-10-27 19:10 . 2007-04-09 13:23 28,040 --a------ e:\windows\system32\mdimon.dll
2008-10-27 19:09 . 2008-10-27 19:10 <REP> d-------- e:\windows\SHELLNEW
2008-10-27 19:09 . 2008-11-08 13:13 <REP> d-------- e:\program files\Microsoft Works
2008-10-25 12:29 . 2008-10-27 12:53 <REP> d-------- e:\windows\system32\CatRoot_bak
2008-10-25 11:05 . 2008-08-14 14:44 2,182,400 -----c--- e:\windows\system32\dllcache\ntoskrnl.exe
2008-10-25 11:05 . 2008-08-14 14:44 2,138,112 -----c--- e:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-25 11:05 . 2008-08-14 14:44 2,059,776 -----c--- e:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-25 11:05 . 2008-08-14 14:44 2,017,792 -----c--- e:\windows\system32\dllcache\ntkrpamp.exe
2008-10-25 10:50 . 2008-06-14 18:59 272,768 --------- e:\windows\system32\drivers\bthport.sys
2008-10-25 10:50 . 2008-06-14 18:59 272,768 -----c--- e:\windows\system32\dllcache\bthport.sys
2008-10-25 10:37 . 2007-07-30 18:19 271,224 --a------ e:\windows\system32\mucltui.dll
2008-10-25 10:37 . 2007-07-30 18:19 207,736 --a------ e:\windows\system32\muweb.dll
2008-10-25 10:37 . 2007-07-30 18:18 30,072 --a------ e:\windows\system32\mucltui.dll.mui
2008-10-25 10:11 . 2008-11-04 12:01 <REP> d--h----- e:\windows\$hf_mig$
2008-10-24 15:05 . 2008-11-08 20:37 <REP> d-------- e:\documents and settings\Administrateur\Contacts
2008-10-24 15:04 . 2008-10-24 15:04 <REP> d----c--- e:\windows\system32\DRVSTORE
2008-10-24 14:59 . 2008-10-24 15:03 <REP> d--hsc--- e:\program files\Fichiers communs\WindowsLiveInstaller
2008-10-24 14:58 . 2008-11-05 11:38 <REP> d-------- e:\program files\Windows Live
2008-10-24 14:58 . 2008-10-24 14:58 <REP> d-------- e:\documents and settings\All Users\Application Data\WLInstaller
2008-10-24 11:01 . 2008-10-24 11:01 <REP> d-------- e:\windows\nview
2008-10-24 11:01 . 2007-11-12 05:51 356,352 --a------ e:\windows\system32\nvudisp.exe
2008-10-24 11:01 . 2008-10-24 11:01 161,961 --a------ e:\windows\system32\nvapps.xml
2008-10-24 11:01 . 2007-11-12 05:51 17,737 --a------ e:\windows\system32\nvdisp.nvu
2008-10-24 11:00 . 2007-11-12 07:03 356,352 --a------ e:\windows\system32\NVUNINST.EXE
2008-10-23 17:14 . 2008-10-23 17:44 <REP> d-------- e:\program files\BitComet
2008-10-23 17:09 . 2008-10-23 17:09 <REP> d-------- e:\documents and settings\All Users\Application Data\wmp
2008-10-23 15:51 . 2008-10-23 15:51 <REP> d--hs---- E:\$RECYCLE.BIN
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 13:18 --------- d-----w e:\documents and settings\Administrateur\Application Data\DMCache
2008-11-14 20:33 --------- d-----w e:\documents and settings\Administrateur\Application Data\Skype
2008-11-14 17:33 --------- d-----w e:\documents and settings\Administrateur\Application Data\skypePM
2008-11-14 13:40 --------- d-----w e:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-13 17:47 --------- d--h--w e:\program files\InstallShield Installation Information
2008-11-13 15:58 --------- d-----w e:\program files\BearShare
2008-11-12 19:44 --------- d-----w e:\program files\Realtek
2008-11-12 19:40 218,479 ------w e:\windows\system32\HdAShCut.exe
2008-11-12 15:07 --------- d-----w e:\program files\Google
2008-11-11 18:52 925,039 ----a-w e:\windows\pchealth\helpctr\binaries\helpctr.exe
2008-11-11 18:52 317,295 ----a-w e:\windows\pchealth\helpctr\binaries\msconfig.exe
2008-11-08 12:07 925,039 ----a-w e:\windows\pchealth\helpctr\binaries\helpctr.exe.tmp
2008-11-08 12:07 317,295 ----a-w e:\windows\pchealth\helpctr\binaries\msconfig.exe.tmp
2008-11-01 10:31 --------- d-----w e:\program files\Internet Download Manager
2008-10-30 11:38 --------- d-----w e:\documents and settings\Administrateur\Application Data\IDM
2008-10-24 14:41 --------- d-----w e:\program files\Ubisoft
2008-09-15 15:39 1,846,144 ----a-w e:\windows\system32\win32k.sys
2008-09-12 10:44 206,256 ----a-w e:\windows\system32\idmmbc.dll
2008-08-20 05:37 663,552 ----a-w e:\windows\system32\wininet.dll
.
[code]<pre>
----a-w 216,581 2008-11-14 10:37:12 e:\documents and settings\Administrateur\Bureau\Nouveau dossier (3)\HASNI\HASNI .exe
</pre>/code
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="e:\program files\Internet Download Manager\IDMan.exe" [2008-11-17 2828575]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2007-11-12 8523776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"msacm.dvacm"= e:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= e:\progra~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= e:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\BearShare\\BearShare.exe"=
"e:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=
"e:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= e:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe
"e:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\WINDOWS\\SkyTel.EXE"=
"e:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=
"e:\\WINDOWS\\system32\\nwiz.exe"=
"e:\\WINDOWS\\ALCMTR.EXE"=
"e:\\WINDOWS\\RTHDCPL.EXE"=
"e:\\Program Files\\Ubisoft\\Register\\schedule.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\Fichiers communs\\Microsoft Shared\\Windows Live\\WLLoginProxy.exe"=
"e:\\WINDOWS\\system32\\ctfmon.exe"=
"e:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"e:\\Program Files\\QuickTime\\qttask.exe"=
"e:\\Program Files\\Save\\Save.exe"=
"e:\\WINDOWS\\system32\\WgaTray.exe"=
"e:\\Program Files\\Ulead Systems\\Ulead VideoStudio 11\\uvPL.exe"=
"e:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe"=
"e:\\WINDOWS\\NOTEPAD.EXE"=
"e:\\ComboFix\\hidec.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20908:TCP"= 20908:TCP:BitComet 20908 TCP
"20908:UDP"= 20908:UDP:BitComet 20908 UDP
R3 aic32p;aic32p;\??\e:\windows\system32\drivers\orkemn.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f3a7f6f-af4f-11dd-8891-001d7dc87805}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ca39094-b238-11dd-88a6-001d7dc87805}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5fe9fa0c-a44a-11dd-8865-001d7dc87805}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{818e0e10-9aaa-11db-883d-001d7dc87805}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-17 14:18:17
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
e:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
e:\windows\system32\nvsvc32.exe
e:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
e:\windows\system32\wdfmgr.exe
e:\windows\system32\wscntfy.exe
e:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Heure de fin: 2008-11-17 14:20:46 - La machine a redémarré [Administrateur]
ComboFix-quarantined-files.txt 2008-11-17 13:20:43
Avant-CF: 52,544,954,368 octets libres
Après-CF: 52,467,499,008 octets libres
285 --- E O F --- 2008-11-11 10:29:57