
Voici le rapport :
ComboFix 08-11-18.A2 - dias 2008-11-19 22:45:55.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.528 [GMT 1:00]
Lancé depuis: N:\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
[COLOR=RED]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/COLOR]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\INSTALL.LOG
c:\windows\IE4 Error Log.txt
c:\windows\system32\aqoxgkap.ini
c:\windows\system32\cfyjpz.dll
c:\windows\system32\dgqaqp.dll
c:\windows\system32\dxnhbgkn.dll
c:\windows\system32\eprnraws.dll
c:\windows\system32\gapdrycj.dll
c:\windows\system32\leufeldi.ini
c:\windows\system32\lqjwujus.ini
c:\windows\system32\MSINET.oca
c:\windows\system32\neyxaq.dll
c:\windows\system32\pXycJkkj.ini
c:\windows\system32\pXycJkkj.ini2
c:\windows\system32\soyfonvy.dll
c:\windows\system32\spyfbqht.ini
c:\windows\system32\tcpottoa.ini
c:\windows\system32\tvopvb.dll
c:\windows\system32\witsmxdb.dll
c:\windows\system32\yjkaoy.dll
----- BITS: Il y a peut-être des sites infectés -----
hxxp://www.mp3codec.net
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-19 au 2008-11-19 ))))))))))))))))))))))))))))))))))))
.
2008-11-19 12:40 . 2008-11-19 12:40 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-19 12:40 . 2008-11-19 12:40 <REP> d-------- c:\documents and settings\dias\Application Data\Malwarebytes
2008-11-19 12:40 . 2008-11-19 12:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-19 12:40 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-19 12:40 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-18 23:26 . 2008-11-18 23:26 <REP> d-------- C:\VundoFix Backups
2008-11-18 19:41 . 2008-11-18 19:40 104,448 --a------ c:\windows\system32\hphfsz.VIR
2008-11-16 21:27 . 2008-11-17 23:25 <REP> d-------- c:\program files\a-squared Free
2008-11-16 19:32 . 2008-11-19 13:01 <REP> d-------- c:\program files\Spyware Doctor
2008-11-16 19:32 . 2008-11-16 19:32 <REP> d-------- c:\documents and settings\dias\Application Data\PC Tools
2008-11-16 19:32 . 2008-11-19 20:12 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-16 19:32 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2008-11-16 19:32 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2008-11-16 19:32 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2008-11-16 19:32 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2008-11-16 10:58 . 2008-11-16 10:58 70,656 --------- c:\windows\system32\xsbgrrgh.dll
2008-11-15 19:32 . 2008-11-15 20:55 <REP> d-------- c:\windows\BDOSCAN8
2008-11-15 19:14 . 2008-11-15 19:14 102,664 --a------ c:\windows\system32\drivers\tmcomm.sys
2008-11-15 19:13 . 2008-11-15 19:14 <REP> d-------- c:\documents and settings\dias\.housecall6.6
2008-11-13 22:57 . 2008-11-13 22:57 <REP> d-------- c:\program files\Avira
2008-11-13 22:57 . 2008-11-13 22:57 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-13 22:47 . 2008-11-13 22:47 <REP> d-------- c:\program files\Trend Micro
2008-11-11 14:22 . 2008-11-11 14:22 <REP> d-------- c:\windows\AU_Temp
2008-11-11 14:22 . 2008-11-11 14:15 20,884,485 --a------ c:\windows\LPT$VPN.647
2008-11-11 14:15 . 2008-11-11 14:15 20,884,485 --a------ c:\windows\VPTNFILE.647
2008-11-06 22:20 . 2008-11-06 22:20 <REP> d-------- c:\documents and settings\dias\Application Data\Apple Computer
2008-11-06 22:19 . 2008-11-06 22:19 <REP> d-------- c:\program files\iTunes
2008-11-06 22:19 . 2008-11-06 22:19 <REP> d-------- c:\program files\iPod
2008-11-06 22:19 . 2008-11-06 22:19 <REP> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-06 22:19 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-11-06 22:19 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-11-06 22:16 . 2008-11-16 12:53 <REP> d-------- c:\program files\QuickTime
2008-11-06 22:16 . 2008-11-06 22:16 <REP> d-------- c:\program files\Apple Software Update
2008-11-06 22:16 . 2008-11-06 22:19 <REP> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-06 22:16 . 2008-10-01 13:01 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys
2008-11-06 22:15 . 2008-11-06 22:16 <REP> d-------- c:\program files\Fichiers communs\Apple
2008-11-06 22:15 . 2008-11-06 22:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-10-24 16:18 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-22 11:49 . 2008-10-22 11:49 <REP> d-------- c:\documents and settings\dias\Application Data\Acreon
2008-10-22 08:00 . 2008-10-22 08:00 <REP> d-------- c:\windows\system32\fr-fr
2008-10-22 08:00 . 2008-10-22 08:00 <REP> d-------- c:\windows\system32\fr
2008-10-22 08:00 . 2008-10-22 08:00 <REP> d-------- c:\windows\system32\bits
2008-10-22 08:00 . 2008-10-22 08:00 <REP> d-------- c:\windows\l2schemas
2008-10-22 07:56 . 2008-10-22 08:00 <REP> d-------- c:\windows\ServicePackFiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 20:56 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-19 19:22 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-13 15:26 --------- d-----w c:\program files\World of Warcraft
2008-11-12 20:43 --------- d-----w c:\program files\BitComet
2008-11-12 20:42 --------- d-----w c:\documents and settings\dias\Application Data\Vso
2008-11-12 18:46 --------- d-----w c:\documents and settings\dias\Application Data\U3
2008-11-11 17:59 --------- d-----w c:\program files\Google
2008-11-11 13:22 91,744 ----a-w c:\windows\BPMNT.dll
2008-11-11 13:22 1,213,784 ----a-w c:\windows\vsapi32.dll
2008-11-10 21:28 71,749 ----a-w c:\windows\hcextoutput.dll
2008-11-10 21:28 348,229 ----a-w c:\windows\TSC.exe
2008-11-05 15:44 --------- d-----w c:\documents and settings\dias\Application Data\Desktopicon
2008-10-29 13:42 --------- d-----w c:\documents and settings\dias\Application Data\Mes fichiers de LSDA, L'Avènement du Roi-sorcier™
2008-10-22 07:16 96,384 ----a-w c:\windows\system32\drivers\sptd5405.sys
2008-10-19 17:59 106,496 ----a-w c:\windows\DUMP5227.tmp
2008-10-18 17:02 --------- d-----w c:\program files\WowCartographe
2008-10-15 11:25 --------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
2008-10-02 18:14 --------- d-----w c:\program files\Picasa2
2008-09-24 14:10 --------- d-----w c:\program files\e-Carte Bleue Caisse d'Epargne
2008-09-24 13:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-09-24 07:14 --------- d-----w c:\program files\ProntoEdit4
2008-09-19 17:27 69,689 ----a-w c:\windows\UNZIP.DLL
2008-09-19 17:27 507,904 ----a-w c:\windows\TMUPDATE.DLL
2008-09-19 17:27 286,720 ----a-w c:\windows\PATCH.EXE
2007-01-09 19:38 87,608 ----a-r c:\documents and settings\dias\Application Data\ezpinst.exe
2007-01-09 19:38 47,360 ----a-r c:\documents and settings\dias\Application Data\pcouffin.sys
2006-10-07 11:50 88 --sha-w c:\windows\system32\[u]0[/u]64E2D8BAA.sys
2006-10-07 11:50 4,700 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NOMAD Detector"="c:\program files\Creative\NOMAD Jukebox Zen (USB2.0)\PlayCenter2\CTNMRUN.EXE" [2002-03-05 18432]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 405583]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-06-13 2752512]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Disc Detector"="c:\program files\Creative\ShareDLL\CtNotify.exe" [2001-12-26 191488]
"CTStartup"="c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" [2002-09-13 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-04-15 45056]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-19 7311360]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Muscbrigade"="c:\musicbrigade\Musicbrigade.exe" [2005-12-22 40960]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 86016]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2005-12-12 8744960]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"fssui"="c:\program files\Windows Live\Contrôle parental\fssui.exe" [2007-12-17 243240]
"EPSON Stylus DX4800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE" [2005-02-02 98304]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2002-07-16 32768]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"nwiz"="nwiz.exe" [2006-01-19 c:\windows\system32\nwiz.exe]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 c:\windows\arpwrmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\dias\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
[HKLM\~\startupfolder\C:^Documents and Settings^dias^Menu Démarrer^Programmes^Démarrage^ubisoft register.lnk]
path=c:\documents and settings\dias\Menu Démarrer\Programmes\Démarrage\ubisoft register.lnk
backup=c:\windows\pss\ubisoft register.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\PSP\\daxizo\\USBHOST_PCSERVER\\usbhostfs_pc.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.9\\cnc3game.dat"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
"c:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat"=
"c:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\game.dat"=
"c:\\Program Files\\Electronic Arts\\L'Avènement du Roi-sorcier\\game.dat"=
"c:\\Program Files\\Electronic Arts\\L'Avènement du Roi-sorcier\\patchget.dat"=
"c:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\patchget.dat"=
"c:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\patchget.dat"=
"c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\nethostfs.exe"=
"c:\\PSP\\nethostfs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57120:TCP"= 57120:TCP:Pando P2P TCP Listening Port
"57120:UDP"= 57120:UDP:Pando P2P UDP Listening Port
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"22174:TCP"= 22174:TCP:BitComet 22174 TCP
"22174:UDP"= 22174:UDP:BitComet 22174 UDP
"11270:TCP"= 11270:TCP:BitComet 11270 TCP
"11270:UDP"= 11270:UDP:BitComet 11270 UDP
"45600:TCP"= 45600:TCP:BitComet 45600 TCP
"45600:UDP"= 45600:UDP:BitComet 45600 UDP
R2 fssfltr;FssFltr;c:\windows\system32\DRIVERS\fssfltr.sys [2008-09-06 43816]
R2 fsssvc;Windows Live OneCare Contrôle parental;"c:\program files\Windows Live\Contrôle parental\fsssvc.exe" [2007-12-17 523816]
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2006-05-04 835200]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\DRIVERS\libusb0.sys [2006-06-15 29184]
S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2006-05-04 215040]
S3 TV_551805_Sp50;TV_551805_Sp50 NDIS Protocol Driver;c:\windows\system32\Drivers\TV_551805_Sp50.sys [2007-10-21 27072]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79c1049a-bba1-11dc-b563-003005b2d055}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{daab5837-b0b2-11dd-9abd-001320f35634}]
\Shell\AutoRun\command - M:\LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2008-11-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-11-19 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{0A452A47-C5A8-4854-A237-4B9B06B376F0} - (no file)
HKCU-Run-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-!xSpeed - c:\!xspeedpro\!xSpeedPro.exe
HKLM-Run-SigmatelSysTrayApp - sttray.exe
ShellExecuteHooks-{3CCDF8CE-C339-4DD6-AD4F-CA7230C7E2F2} - (no file)
Notify-klogon - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\dias\Application Data\Mozilla\Firefox\Profiles\j1fu0mik.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/intl/fr/
FF -: plugin - c:\documents and settings\dias\Application Data\Mozilla\plugins\npPxPlay.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Picasa2\npPicasa2.dll
FF -: plugin - c:\program files\QuickTime\Plugins\npqtplugin8.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-19 23:03:39
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = c:\program files\Creative\ShareDLL\CtNotify.exe?X???????????????????E?@?D?tecteur de disque? ?A???????B?e!@???@???@?? C?????E?@?????????@?B???A????? ?A???????B???@?????P?????@?????????~?:~??????????@???????????????????B?????????????????????????????????r?B
CTStartup = "c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" /run?Z?9~d???*?9~????????? ??????h?@?x?????:~D??????sx??s?F??????y??w????@@@?v??|D@@?????>??w????h;??H??????|???|????v??|L(?sh;???????/?s????????D???????????????????,????????????+?s@@@?D???`|?w??????@
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\arservice.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\progra~1\Iomega\System32\AppServices.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Photodex\ProShowProducer\scsiaccess.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Iomega\AutoDisk\ADService.exe
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\Creative\ShareDLL\Mediadet.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\notepad.exe
.
**************************************************************************
.
Heure de fin: 2008-11-19 23:23:55 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-19 22:23:50
Avant-CF: 48 930 615 296 octets libres
Après-CF: 49,079,459,840 octets libres
282 --- E O F --- 2008-11-19 21:11:36