Salut Dédétraqué,
J'ai pu télécharger et executer combofix, voici le rapport :
ComboFix 08-08-08.06 - Daniel 2008-08-09 2:09:44.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1138 [GMT 2:00]
* CrÚation d'un nouveau point de restauration
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\AutoRun.inf
C:\Windows\system32\ban_list.txt
C:\Windows\system32\drivers\downld
C:\Windows\system32\drivers\downld\101915.exe
C:\Windows\system32\drivers\downld\1020090.exe
C:\Windows\system32\drivers\downld\104427.exe
C:\Windows\system32\drivers\downld\1058903.exe
C:\Windows\system32\drivers\downld\118389.exe
C:\Windows\system32\drivers\downld\121930.exe
C:\Windows\system32\drivers\downld\131368.exe
C:\Windows\system32\drivers\downld\131945.exe
C:\Windows\system32\drivers\downld\135486.exe
C:\Windows\system32\drivers\downld\158699.exe
C:\Windows\system32\drivers\downld\16142687.exe
C:\Windows\system32\drivers\downld\16161485.exe
C:\Windows\system32\drivers\downld\16188504.exe
C:\Windows\system32\drivers\downld\16191172.exe
C:\Windows\system32\drivers\downld\16223635.exe
C:\Windows\system32\drivers\downld\16247145.exe
C:\Windows\system32\drivers\downld\16255569.exe
C:\Windows\system32\drivers\downld\162724.exe
C:\Windows\system32\drivers\downld\168871.exe
C:\Windows\system32\drivers\downld\194798.exe
C:\Windows\system32\drivers\downld\203908.exe
C:\Windows\system32\drivers\downld\247230.exe
C:\Windows\system32\drivers\downld\257698.exe
C:\Windows\system32\drivers\downld\62025.exe
C:\Windows\system32\drivers\downld\71776.exe
C:\Windows\system32\drivers\downld\83569.exe
C:\Windows\system32\drivers\downld\909782.exe
C:\Windows\system32\drivers\downld\93257.exe
C:\Windows\system32\drivers\downld\936458.exe
C:\Windows\system32\drivers\downld\963446.exe
C:\Windows\system32\drivers\downld\966535.exe
C:\Windows\system32\drivers\downld\96829.exe
C:\Windows\system32\drivers\downld\998406.exe
C:\Windows\system32\drivers\hldrrr.exe
C:\Windows\system32\drivers\mdelk.exe
C:\Windows\system32\drivers\srosa.sys
C:\Windows\system32\mdelk.exe
C:\Windows\system32\oqWELkkj.ini
C:\Windows\System32\oqWELkkj.ini2
C:\Windows\System32\ryyijmsa.ini
C:\Windows\system32\wintems.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
.
2008-08-09 02:04 . 2008-08-09 02:04 2,708,945 --a------ C:\Users\Daniel\daile.exe
2008-08-09 00:12 . 2008-08-09 00:12 <REP> d-------- C:\Windows\System32\Kaspersky Lab
2008-08-09 00:01 . 2008-08-09 00:01 <REP> dr------- C:\Users\Daniel\Searches
2008-08-08 23:45 . 2008-08-08 23:45 <REP> d-------- C:\Program Files\Alwil Software
2008-08-08 23:45 . 2008-07-19 16:36 51,280 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2008-08-08 16:26 . 2008-08-08 16:26 <REP> dr------- C:\Users\Public\Videos
2008-08-08 16:26 . 2008-08-08 16:26 <REP> dr------- C:\Users\Public\Pictures
2008-08-08 16:26 . 2008-08-08 16:26 <REP> dr------- C:\Users\Public\Music
2008-08-08 16:26 . 2008-08-08 16:26 <REP> dr------- C:\Users\Daniel\Videos
2008-08-08 09:17 . 2008-08-08 09:17 <REP> d-------- C:\Users\All Users\WEBREG
2008-08-08 09:17 . 2008-08-08 09:17 <REP> d-------- C:\ProgramData\WEBREG
2008-08-08 09:16 . 2008-08-08 09:16 <REP> d-------- C:\Users\All Users\Hewlett-Packard
2008-08-08 09:16 . 2008-08-08 09:16 <REP> d-------- C:\ProgramData\Hewlett-Packard
2008-08-07 10:38 . 2008-08-07 10:45 <REP> d-------- C:\Users\All Users\Ciel
2008-08-07 10:38 . 2008-08-07 10:45 <REP> d-------- C:\ProgramData\Ciel
2008-08-07 10:36 . 2008-08-07 10:36 <REP> dr------- C:\Windows\System32\config\systemprofile\Videos
2008-08-07 10:36 . 2008-08-07 10:36 <REP> dr------- C:\Windows\System32\config\systemprofile\Searches
2008-08-07 10:36 . 2008-08-07 10:36 <REP> dr------- C:\Windows\System32\config\systemprofile\Saved Games
2008-08-07 10:36 . 2008-08-07 10:36 <REP> dr------- C:\Windows\System32\config\systemprofile\Pictures
2008-08-07 10:36 . 2008-08-07 10:36 <REP> dr------- C:\Windows\System32\config\systemprofile\Links
2008-08-07 10:36 . 2008-08-07 10:36 <REP> dr------- C:\Windows\System32\config\systemprofile\Downloads
2008-08-07 10:36 . 2008-08-07 10:36 <REP> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-08-07 10:36 . 2008-08-07 10:45 <REP> d-------- C:\Program Files\Ciel
2008-08-07 07:07 . 2008-08-07 12:47 <REP> d-------- C:\Users\All Users\NVIDIA
2008-08-07 07:07 . 2008-08-07 12:47 <REP> d-------- C:\ProgramData\NVIDIA
2008-08-06 23:15 . 2008-08-06 23:15 <REP> d-------- C:\Program Files\Lavasoft
2008-08-06 23:14 . 2008-08-06 23:14 <REP> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-04 13:30 . 2007-11-08 11:04 11,967,524 --a------ C:\Windows\System32\korwbrkr.lex
2008-07-30 23:46 . 2008-07-25 08:23 25,748,413 --a------ C:\Windows\LPT$VPN.433
2008-07-30 23:44 . 2008-07-30 23:44 <REP> d-------- C:\Windows\AU_Temp
2008-07-30 05:28 . 2008-04-26 10:25 3,600,952 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-07-30 05:28 . 2008-04-26 10:25 3,549,240 --a------ C:\Windows\System32\ntoskrnl.exe
2008-07-30 05:28 . 2008-04-26 10:26 891,448 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-07-30 05:28 . 2008-04-12 05:32 784,896 --a------ C:\Windows\System32\rpcrt4.dll
2008-07-30 05:28 . 2008-05-10 05:35 564,736 --a------ C:\Windows\System32\emdmgmt.dll
2008-07-30 05:28 . 2008-04-05 03:21 72,192 --a------ C:\Windows\System32\drivers\pacer.sys
2008-07-30 05:28 . 2008-04-05 05:34 15,360 --a------ C:\Windows\System32\pacerprf.dll
2008-07-30 04:41 . 2008-05-08 23:59 430,080 --a------ C:\Windows\System32\vbscript.dll
2008-07-30 04:41 . 2008-05-08 23:59 180,224 --a------ C:\Windows\System32\scrobj.dll
2008-07-30 04:41 . 2008-05-08 23:59 172,032 --a------ C:\Windows\System32\scrrun.dll
2008-07-30 04:41 . 2008-05-08 23:59 155,648 --a------ C:\Windows\System32\wscript.exe
2008-07-30 04:41 . 2008-05-08 23:58 135,168 --a------ C:\Windows\System32\wshom.ocx
2008-07-30 04:41 . 2008-05-08 23:58 135,168 --a------ C:\Windows\System32\cscript.exe
2008-07-30 04:41 . 2008-05-08 23:59 90,112 --a------ C:\Windows\System32\wshext.dll
2008-07-30 00:11 . 2008-07-30 00:11 <REP> d-------- C:\Users\All Users\Adobe
2008-07-29 19:17 . 2008-07-29 19:17 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-28 13:36 . 2008-08-06 23:15 <REP> d-------- C:\Users\All Users\Lavasoft
2008-07-28 13:36 . 2008-08-06 23:15 <REP> d-------- C:\ProgramData\Lavasoft
2008-07-28 09:06 . 2008-07-28 09:06 <REP> d-------- C:\Users\All Users\HP Product Assistant
2008-07-28 09:06 . 2008-07-28 09:06 <REP> d-------- C:\ProgramData\HP Product Assistant
2008-07-28 08:39 . 2008-08-08 15:29 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-07-28 08:39 . 2008-08-08 15:29 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-07-28 08:19 . 2008-08-08 15:29 <REP> d-------- C:\Users\All Users\HP
2008-07-28 08:19 . 2008-08-08 15:29 <REP> d-------- C:\ProgramData\HP
2008-07-25 08:28 . 2008-07-25 08:27 102,664 --a------ C:\Windows\System32\drivers\tmcomm.sys
2008-07-25 08:27 . 2008-06-19 17:24 28,544 --a------ C:\Windows\System32\drivers\pavboot.sys
2008-07-25 08:23 . 2008-07-25 08:23 25,748,413 --a------ C:\Windows\VPTNFILE.433
2008-07-24 23:43 . 2008-07-24 23:43 <REP> d-------- C:\Windows\McAfee.com
2008-07-24 23:27 . 2008-07-30 23:46 <REP> d-------- C:\Windows\report
2008-07-24 23:25 . 2008-07-25 08:23 <REP> d-------- C:\Windows\AU_Backup
2008-07-24 23:25 . 2008-07-24 23:25 1,962,632 --a------ C:\Windows\tsc.ptn
2008-07-24 23:25 . 2008-07-25 08:23 1,213,784 --a------ C:\Windows\vsapi32.dll
2008-07-24 23:25 . 2008-07-24 23:25 333,576 --a------ C:\Windows\TSC.exe
2008-07-24 23:25 . 2008-07-25 08:23 91,744 --a------ C:\Windows\BPMNT.dll
2008-07-24 23:25 . 2008-07-24 23:25 71,749 --a------ C:\Windows\hcextoutput.dll
2008-07-24 23:25 . 2008-08-04 13:43 823 --a------ C:\Windows\tsc.ini
2008-07-24 23:23 . 2008-07-24 23:23 <REP> d-------- C:\Windows\AU_Log
2008-07-24 23:23 . 2008-07-24 23:23 507,904 --a------ C:\Windows\TMUPDATE.DLL
2008-07-24 23:23 . 2008-07-24 23:23 286,720 --a------ C:\Windows\PATCH.EXE
2008-07-24 23:23 . 2008-07-24 23:23 69,689 --a------ C:\Windows\UNZIP.DLL
2008-07-24 23:23 . 2008-07-30 23:44 170 --a------ C:\Windows\GetServer.ini
2008-07-23 19:18 . 2008-01-19 09:33 8,139,264 --a------ C:\Windows\System32\ssBranded.scr
2008-07-23 19:17 . 2008-01-19 09:33 2,515,968 --a------ C:\Windows\System32\accessibilitycpl.dll
2008-07-23 19:16 . 2008-01-19 09:35 3,072,000 --a------ C:\Windows\System32\networkmap.dll
2008-07-23 19:15 . 2008-01-19 09:32 1,370,624 --a------ C:\Windows\System32\Aurora.scr
2008-07-23 19:14 . 2008-01-19 09:32 5,714,432 --a------ C:\Windows\System32\logon.scr
2008-07-23 19:13 . 2008-01-19 08:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-07-23 19:11 . 2008-01-19 09:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-07-23 19:11 . 2008-01-19 09:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-07-23 19:11 . 2008-01-19 09:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-07-23 19:11 . 2008-01-19 09:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-07-23 19:11 . 2008-01-19 09:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-07-23 19:11 . 2008-01-19 09:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-07-23 19:11 . 2008-01-19 09:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-07-23 19:11 . 2008-01-19 09:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-07-23 19:11 . 2008-01-19 09:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-07-23 15:15 . 2008-07-23 15:15 8,284 --a------ C:\Windows\System32\eps_icon.avi
2008-07-22 10:58 . 2008-07-22 10:58 43,521 ---hs---- C:\Windows\System32\ghhvnsdl.ini
2008-07-22 02:18 . 2008-07-22 07:26 43,581 ---hs---- C:\Windows\System32\obarnogc.ini
2008-07-22 01:17 . 2005-05-26 15:34 2,297,552 --a------ C:\Windows\System32\d3dx9_26.dll
2008-07-20 08:32 . 2008-07-20 08:32 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-07-11 12:54 . 2008-07-11 12:54 988,216 --a------ C:\Windows\System32\winload.exe
2008-07-11 12:54 . 2008-07-11 12:54 927,288 --a------ C:\Windows\System32\winresume.exe
2008-07-11 12:54 . 2008-07-11 12:54 615,992 --a------ C:\Windows\System32\ci.dll
2008-07-11 12:54 . 2008-07-11 12:54 378,368 --a------ C:\Windows\System32\srcore.dll
2008-07-11 12:54 . 2008-07-11 12:54 318,464 --a------ C:\Windows\System32\rstrui.exe
2008-07-11 12:54 . 2008-07-11 12:54 46,592 --a------ C:\Windows\System32\setbcdlocale.dll
2008-07-11 12:54 . 2008-07-11 12:54 40,960 --a------ C:\Windows\System32\srclient.dll
2008-07-11 12:54 . 2008-07-11 12:54 19,000 --a------ C:\Windows\System32\kd1394.dll
2008-07-11 12:54 . 2008-07-11 12:54 14,848 --a------ C:\Windows\System32\srdelayed.exe
2008-07-11 12:54 . 2008-07-11 12:54 6,656 --a------ C:\Windows\System32\kbd106n.dll
2008-07-11 12:53 . 2008-07-11 12:53 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2008-07-11 12:53 . 2008-07-11 12:53 14,848 --a------ C:\Windows\System32\wshrm.dll
2008-07-11 12:52 . 2008-07-11 12:52 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-07-11 12:52 . 2008-07-11 12:52 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-07-11 12:51 . 2008-07-11 12:51 1,314,816 --a------ C:\Windows\System32\quartz.dll
2008-07-11 12:51 . 2008-07-11 12:51 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-07-11 12:51 . 2008-07-11 12:51 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-07-11 12:51 . 2008-07-11 12:51 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-07-11 12:51 . 2008-07-11 12:51 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-07-11 12:51 . 2008-07-11 12:51 69,632 --a------ C:\Windows\System32\Mpeg2Data.ax
2008-07-11 12:51 . 2008-07-11 12:51 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-07-11 12:48 . 2008-07-11 12:48 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-07-11 12:48 . 2008-07-11 12:48 826,880 --a------ C:\Windows\System32\wininet.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 21:54 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-08 21:48 --------- d-----w C:\Program Files\Avast
2008-08-08 20:26 --------- d-----w C:\Program Files\eMule
2008-08-08 13:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-08 13:30 --------- d-----w C:\Program Files\QuickTime
2008-08-08 13:30 --------- d-----w C:\Program Files\HP
2008-08-08 13:30 --------- d-----w C:\Program Files\Heredis 8
2008-08-08 13:30 --------- d-----w C:\Program Files\EBP
2008-08-08 13:30 --------- d-----w C:\Program Files\EasyDivX
2008-08-08 13:30 --------- d-----w C:\Program Files\DivX
2008-08-08 13:29 --------- d-----w C:\Users\Daniel\AppData\Roaming\Todae
2008-08-08 13:29 --------- d-----w C:\Users\Daniel\AppData\Roaming\Roxio
2008-08-08 13:29 --------- d-----w C:\Users\Daniel\AppData\Roaming\IMSI
2008-08-06 22:21 --------- d-----w C:\Program Files\Spybot
2008-08-06 22:19 2,560 ----a-w C:\Windows\_MSRSTRT.EXE
2008-08-03 09:15 --------- d-----w C:\Program Files\avinst
2008-07-29 05:48 174 --sha-w C:\Program Files\desktop.ini
2008-07-29 05:41 --------- d-----w C:\Program Files\Windows Sidebar
2008-07-29 05:41 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-07-29 05:41 --------- d-----w C:\Program Files\Windows Mail
2008-07-29 05:41 --------- d-----w C:\Program Files\Windows Journal
2008-07-29 05:41 --------- d-----w C:\Program Files\Windows Defender
2008-07-29 05:41 --------- d-----w C:\Program Files\Windows Calendar
2008-07-29 05:40 --------- d-----w C:\Program Files\Microsoft Games
2008-07-24 21:55 --------- d-----w C:\Program Files\Java
2008-07-21 12:37 --------- d-----w C:\Program Files\Mail PassView
2008-07-11 10:52 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-07-11 10:52 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-11 10:52 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-07-11 10:52 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-11 10:52 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-08 13:41 --------- d-----w C:\Program Files\Common Files\HP
2008-07-08 13:26 --------- d-----w C:\Program Files\Packard Bell
2008-07-08 13:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-08 06:15 --------- d-----w C:\Users\Daniel\AppData\Roaming\HP
2008-07-07 09:08 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-02-27 13:58 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-02-27 13:58 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-02-27 13:58 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
"Copernic Desktop Search 2"="C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" [2008-03-03 22:45 1583624]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 08:47 1629480]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-06-25 08:47 1057064]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 05:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 05:28 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 05:28 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 16:38 4390912 C:\Windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm
"msacm.divxa32"= divxa32.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1178637878-977580592-3688612770-1002]
"EnableNotificationsRef"=dword:00000006
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C1B5ACE4-1743-43FA-A0D9-91E9F5238771}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A304AA59-9047-4DF0-9100-6A83B31CEDE8}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6D7E9487-0FBE-422D-A957-FF33F42A0764}"= UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{58890A74-79E0-475B-A76E-D68B90DEED0A}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"TCP Query User{CE5983C2-45D5-4A0C-ABD2-3CBB2B8B47AB}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{F6351E53-B430-4D7E-93BA-D5C2F8B0520F}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{8E9A3699-FFAC-4497-A926-614940F6D797}"= UDP:C:\Program Files\Grisoft\AVG Free\avginet.exe:avginet.exe
"{1F7A1861-0C44-41F9-9C21-42CB4D3CA7A8}"= TCP:C:\Program Files\Grisoft\AVG Free\avginet.exe:avginet.exe
"{D540AA14-192A-487E-A06D-0CE0018924F2}"= UDP:C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:avgamsvr.exe
"{53B7AC63-95A9-4774-965D-8298694612E8}"= TCP:C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:avgamsvr.exe
"{62A8325C-7988-457A-9E9C-33A0197C565E}"= UDP:C:\Program Files\Grisoft\AVG Free\avgcc.exe:avgcc.exe
"{319EDE3F-9C54-4448-B89E-F7389C2BC7A5}"= TCP:C:\Program Files\Grisoft\AVG Free\avgcc.exe:avgcc.exe
R0 pavboot;pavboot;C:\Windows\system32\drivers\pavboot.sys [2008-06-19 17:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-08-09 C:\Windows\Tasks\Extension de garantie.job
- C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe [2006-11-21 18:38]
2008-08-09 C:\Windows\Tasks\Recovery DVD Creator.job
- C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe [2006-11-21 18:34]
2008-08-08 C:\Windows\Tasks\User_Feed_Synchronization-{CA5197DF-187B-482A-9EAF-118C02B63186}.job
- C:\Windows\system32\msfeedssync.exe [2008-01-19 09:33]
.
- - - - ORPHANS REMOVED - - - -
BHO-{2101E4F4-AE9D-4D88-BD4E-098BD7BCD250} - (no file)
BHO-{60093FC9-BB69-4540-8AEE-163F580686F6} - (no file)
HKLM-Run-NeroFilterCheck - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\p6ja84u3.default\
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-09 02:15:36
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Cobian Backup 8\cbService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\conime.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2008-08-09 2:18:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-09 00:18:34
Pre-Run: 114,930,253,824 octets libres
Post-Run: 114,713,206,784 octets libres
307 --- E O F --- 2008-08-08 05:53:31