Please, Someone can help me to evaluate my ComboFix file.
Thank you very much
- Code: Select all
ComboFix 09-04-03.01 - Administrateur 2009-04-05 7:59:50.1 - NTFSx86 Microsoft Windows XP Professionnel 5.1.2600.3.1256.216.1036.18.502.140 [GMT 2:00] Running from: c:\documents and settings\Administrateur\Bureau\ComboFix.exe AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\x64 . ((((((((((((((((((((((((( Files Created from 2009-03-05 to 2009-04-05 ))))))))))))))))))))))))))))))) . 2009-04-04 17:34 . 2009-04-04 17:34 <REP> d--h-c--- c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81} 2009-04-04 17:26 . 2009-04-04 17:26 <REP> d-------- c:\program files\Trend Micro 2009-04-03 19:59 . 2009-04-03 19:59 <REP> d-------- c:\program files\Synaptics 2009-04-03 19:59 . 2004-10-08 14:33 185,824 --a------ c:\windows\system32\drivers\SynTP.sys 2009-04-03 19:59 . 2004-10-08 14:36 114,688 --a------ c:\windows\system32\SynCtrl.dll 2009-04-03 19:59 . 2004-10-08 14:36 90,202 --a------ c:\windows\system32\SynTPAPI.dll 2009-04-03 19:59 . 2004-10-08 14:46 81,920 --a------ c:\windows\system32\SynTPCo2.dll 2009-04-03 19:59 . 2004-10-08 14:35 77,917 --a------ c:\windows\system32\SynCOM.dll 2009-04-03 19:59 . 2004-10-08 14:44 69,722 --a------ c:\windows\system32\SynTPFcs.dll 2009-04-03 19:58 . 2005-06-30 16:58 7,296 --a------ c:\windows\system32\drivers\osaio.sys 2009-04-03 19:58 . 2005-01-14 15:57 4,010 --a------ c:\windows\system32\drivers\osanbm.sys 2009-04-03 19:57 . 2009-04-03 19:57 <REP> d-------- c:\windows\Downloaded Installations 2009-04-03 19:54 . 2009-04-03 19:54 <REP> d-------- c:\program files\CONEXANT 2009-04-03 19:54 . 2005-06-30 15:16 1,034,752 -ra------ c:\windows\system32\drivers\HSF_DPV.sys 2009-04-03 19:54 . 2005-06-30 15:16 716,416 -ra------ c:\windows\system32\drivers\HSF_CNXT.sys 2009-04-03 19:54 . 2005-06-30 15:16 200,704 -ra------ c:\windows\system32\drivers\HSFHWAZL.sys 2009-04-03 19:54 . 2005-06-30 11:01 133,528 -ra------ c:\windows\system32\drivers\HSFProf.cty 2009-04-03 19:54 . 2005-06-20 09:57 110,592 --a------ c:\windows\system32\UCI100.dll 2009-04-03 19:54 . 2004-03-17 12:00 86,016 -ra------ c:\windows\system32\mdmxsdk.dll 2009-04-03 19:54 . 2004-03-17 12:04 13,059 -ra------ c:\windows\system32\drivers\mdmxsdk.sys 2009-04-03 19:51 . 2005-05-03 18:43 69,632 --a------ c:\windows\ALCMTR.EXE 2009-04-03 19:47 . 2005-06-08 11:03 122,880 -ra------ c:\windows\system32\igfxres.dll 2009-04-03 19:35 . 2005-05-18 13:38 40,960 -r------- c:\windows\system32\ChCfg.exe 2009-04-03 19:34 . 2009-04-03 19:51 <REP> d-------- c:\program files\Realtek 2009-04-03 19:34 . 2005-04-16 22:20 487,424 -r------- c:\windows\RtlExUpd.dll 2009-04-03 19:23 . 2009-04-03 19:29 <REP> d-------- c:\windows\SxsCaPendDel 2009-04-03 18:36 . 2009-04-05 07:29 2,560 --a------ c:\windows\system32\drivers\mchInjDrv.sys 2009-04-03 18:35 . 2009-04-03 18:35 <REP> d-------- c:\program files\Enigma Software Group 2009-04-03 12:29 . 2009-04-03 12:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2009-03-25 08:50 . 2009-04-05 08:19 <REP> d-------- c:\documents and settings\Administrateur\Tracing 2009-03-25 08:47 . 2009-03-25 08:47 <REP> d-------- c:\program files\Microsoft Office Outlook Connector 2009-03-25 08:46 . 2009-02-06 19:08 55,152 --a------ c:\windows\system32\drivers\fssfltr_tdi.sys 2009-03-25 08:43 . 2006-11-29 14:06 3,426,072 --a------ c:\windows\system32\d3dx9_32.dll 2009-03-25 08:37 . 2009-04-03 19:25 <REP> d-------- c:\program files\Microsoft 2009-03-25 07:47 . 2009-03-25 07:47 <REP> d-------- c:\program files\Fichiers communs\Windows Live 2009-03-24 09:48 . 2009-03-24 09:48 <REP> d--h----- c:\windows\PIF 2009-03-24 09:12 . 2009-03-24 09:13 <REP> d-------- c:\program files\WinHTTrack 2009-03-23 13:14 . 2009-03-23 13:14 <REP> d-------- c:\program files\Glary Utilities 2009-03-23 13:14 . 2009-03-23 14:24 <REP> d-------- c:\program files\AskBarDis 2009-03-23 13:10 . 2009-03-23 13:32 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-03-23 13:10 . 2009-01-15 03:16 44,544 --a------ c:\windows\system32\msxml4a.dll 2009-03-23 08:23 . 2009-04-03 06:41 54,156 --ah----- c:\windows\QTFont.qfn 2009-03-23 08:23 . 2009-03-23 08:23 1,409 --a------ c:\windows\QTFont.for . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-04 15:04 --------- d-----w c:\documents and settings\All Users\Application Data\Babylon 2009-04-03 17:58 --------- d--h--w c:\program files\InstallShield Installation Information 2009-04-03 17:34 --------- d-----w c:\program files\Fichiers communs\InstallShield 2009-04-03 17:27 --------- d-----w c:\program files\DivX 2009-04-03 17:23 --------- d-----w c:\program files\Windows Live 2009-04-03 16:21 --------- d-----w c:\documents and settings\Administrateur\Application Data\Skype 2009-04-03 15:27 --------- d-----w c:\program files\Canon 2009-04-03 15:27 --------- d-----w c:\documents and settings\Administrateur\Application Data\Canon 2009-04-03 15:26 --------- d-----w c:\program files\Publication Web 2009-04-03 14:53 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-04-03 06:00 --------- d-----w c:\documents and settings\Administrateur\Application Data\skypePM 2009-03-26 14:49 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-03-26 14:49 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-03-13 08:02 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help 2009-02-15 06:13 --------- d-----w c:\documents and settings\Administrateur\Application Data\CoSoSys 2009-02-06 18:39 308,600 ----a-w c:\windows\WLXPGSS.SCR 2009-01-12 13:56 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-07-17 18:20 279944 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "Google Update"="c:\documents and settings\Administrateur\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-13 133104] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-08 94208] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824] "Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-06 69216] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832] "Print2PDF Print Monitor"="c:\program files\Software602\Print2PDF\Print2PDF.exe" [2008-10-03 77824] "pdfw"="c:\program files\Amic Utilities\PDF Writer Pro\pdfwload.exe" [2004-03-24 32768] "Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2008-09-01 3563232] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-01-08 185872] "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-01-12 29744] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218] "RTHDCPL"="RTHDCPL.EXE" [2005-08-09 c:\windows\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] "nltide_3"="advpack.dll" [2008-12-21 c:\windows\system32\advpack.dll] c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\ OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000] c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\ BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-05-17 661369] DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-09-17 1205840] InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-01-12 278528] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) "NoResolveTrack"= 1 (0x1) [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) "StartMenuLogoff"= 1 (0x1) "NoResolveTrack"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3acm"= l3codecp.acm "msacm.divxa32"= DivXa32.acm [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\Microsoft Visual Studio\\VB98\\VB6.EXE"= "c:\\Documents and Settings\\Administrateur\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\Administrateur\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Rise of Nations\\rise.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"= "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "c:\\Program Files\\WinHTTrack\\WinHTTrack.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 mchInjDrv;madCodeHook DLL injection driver;c:\windows\system32\drivers\mchInjDrv.sys [2009-04-03 2560] R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\[u]0[/u]00.fcl [2008-08-28 22:03:03 13560] R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-25 55152] R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2009-04-03 7296] R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2009-04-03 4010] R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656] S2 Apache2.2;Apache2.2;"d:\xampp\apache\bin\apache.exe" -k runservice --> d:\xampp\apache\bin\apache.exe [?] S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2008-09-17 69656] S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?] S3 e4usbae;USB ADSL2 LAN Adapter;c:\windows\system32\drivers\e4usbae.sys [2008-09-17 89600] S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-01-12 29744] S3 Tomcat5;Apache Tomcat;c:\program files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe [2008-08-29 57344] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7e9ad954-b704-11dd-b10b-001167000000}] \Shell\AutoRun\command - wscript.exe .\.vbs \Shell\open\command - wscript.exe .\.vbs [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e99fe1e-a73d-11dd-b0cc-001167000000}] \Shell\AutoRun\command - F:\xqf.com \Shell\explore\Command - F:\xqf.com \Shell\open\Command - F:\xqf.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e99fe1f-a73d-11dd-b0cc-001167000000}] \Shell\AutoRun\command - F:\xqf.com \Shell\explore\Command - F:\xqf.com \Shell\open\Command - F:\xqf.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e99fe20-a73d-11dd-b0cc-001167000000}] \Shell\AutoRun\command - F:\xih9.cmd \Shell\explore\Command - F:\xih9.cmd \Shell\open\Command - F:\xih9.cmd . Contents of the 'Scheduled Tasks' folder 2009-04-05 c:\windows\Tasks\GlaryInitialize.job - c:\program files\Glary Utilities\initialize.exe [2009-03-23 10:49] 2009-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-1303643608-725345543-500.job - c:\documents and settings\Administrateur\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 00:28] 2009-04-05 c:\windows\Tasks\User_Feed_Synchronization-{20E9DBEB-11DA-4947-9BF2-0E42A6839CE8}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 19:36] . . ------- Supplementary Scan ------- . uStart Page = www.google.com/ uInternet Settings,ProxyServer = 170.170.0.3:8080 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm IE: {{5B7027AD-AA6D-40df-8F56-9560F277D2A5} - {E4ABF418-CB30-470C-BFF7-674AC0FC564F} - c:\program files\Software602\Print2PDF\Print602.dll FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p= FF - component: c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\FFAlert.dll FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - plugin: c:\documents and settings\Administrateur\Application Data\Mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\Administrateur\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll . ************************************************************************** catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-05 08:18:57 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}] "ImagePath"="\??\c:\program files\CyberLink\PowerDVD\[u]0[/u]00.fcl" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1757981266-1303643608-725345543-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) "659BD8E725A05FDCC64118EA787EAA2B534A94FABE"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,de,80,dc,77,cd,7e,44,bb,b5,21,\ "3A77B377802A4B6183DDE08FDE4AD9AF647A702826"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,de,80,dc,77,cd,7e,44,bb,b5,21,\ "B34DEDAE08DEBC3D9AE72E5085B5F343BB2B215141"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,be,de,80,dc,77,cd,7e,44,bb,b5,21,\ . ------------------------ Other Running Processes ------------------------ . c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe c:\acer\eManager\anbmServ.exe c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\wbem\wmiapsrv.exe c:\windows\system32\wscntfy.exe c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\OpenOffice.org 3\program\soffice.bin . ************************************************************************** . Completion time: 2009-04-05 8:23:17 - machine was rebooted ComboFix-quarantined-files.txt 2009-04-05 06:23:10 Pre-Run: 9 323 528 192 octets libres Post-Run: 9,258,741,760 octets libres 264 --- E O F --- 2009-04-03 07:01:03