Rapport Combo
ComboFix 08-09-05.03 - Johan 2008-09-07 15:58:00.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1358 [GMT 2:00]
Endroit: C:\Users\Johan\Desktop\ComboFix.exe
Command switches used
C:\Users\Johan\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\System32\korwbrkr.lex
C:\Windows\System32\ntkrnlpa.exe . . . . Echec de suppression
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-08-07 to 2008-09-07 ))))))))))))))))))))))))))))))))))))
.
2008-09-07 15:35 . 2008-09-07 15:35 <REP> d-------- C:\Program Files\ERUNT
2008-09-06 16:05 . 2008-09-07 16:04 3,600,952 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-09-06 15:34 . 2008-09-06 15:34 <REP> d-------- C:\PerfLogs
2008-08-21 21:31 . 2008-07-19 07:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
2008-08-21 21:31 . 2008-07-19 05:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
2008-08-21 21:31 . 2008-07-19 07:09 563,912 --a------ C:\Windows\System32\wuapi.dll
2008-08-21 21:31 . 2008-07-19 05:44 83,456 --a------ C:\Windows\System32\wudriver.dll
2008-08-21 21:31 . 2008-07-19 07:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
2008-08-21 21:31 . 2008-07-19 07:10 45,768 --a------ C:\Windows\System32\wups2.dll
2008-08-21 21:31 . 2008-07-19 07:10 36,552 --a------ C:\Windows\System32\wups.dll
2008-08-21 21:30 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
2008-08-21 21:30 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-08-13 16:10 . 2008-07-16 03:32 2,048 --a------ C:\Windows\System32\tzres.dll
2008-08-13 13:04 . 2008-06-19 05:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
2008-08-13 13:04 . 2008-01-19 09:36 272,896 --a------ C:\Windows\System32\polstore.dll
2008-08-13 13:04 . 2008-04-18 07:48 269,312 --a------ C:\Windows\System32\es.dll
2008-08-13 13:04 . 2008-01-19 09:36 61,440 --a------ C:\Windows\System32\winipsec.dll
2008-08-13 13:04 . 2008-01-19 09:34 28,672 --a------ C:\Windows\System32\FwRemoteSvr.dll
2008-08-13 13:03 . 2008-06-27 03:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-08-13 13:03 . 2008-06-27 06:15 827,392 --a------ C:\Windows\System32\wininet.dll
2008-08-13 13:02 . 2008-04-10 07:12 738,304 --a------ C:\Windows\System32\inetcomm.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 15:19 --------- d-----w C:\ProgramData\Lavasoft
2008-09-06 13:48 174 --sha-w C:\Program Files\desktop.ini
2008-09-06 13:36 --------- d-----w C:\Program Files\Windows Sidebar
2008-09-06 13:36 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-09-06 13:36 --------- d-----w C:\Program Files\Windows Mail
2008-09-06 13:36 --------- d-----w C:\Program Files\Windows Journal
2008-09-06 13:36 --------- d-----w C:\Program Files\Windows Collaboration
2008-09-06 13:36 --------- d-----w C:\Program Files\Windows Calendar
2008-09-06 13:35 --------- d-----w C:\Program Files\Windows Defender
2008-09-02 08:32 --------- d-----w C:\Program Files\Launch Manager
2008-08-13 14:11 --------- d-----w C:\ProgramData\Microsoft Help
2008-07-19 14:36 51,280 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-07-18 18:39 587,264 ----a-w C:\Windows\WLXPGSS.SCR
2008-07-15 22:50 --------- d-----w C:\Users\Johan\AppData\Roaming\Talkback
2008-06-12 05:28 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-04 16:49 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-03-04 16:49 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-03-04 16:49 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-03-12 16:23 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-03-12 16:23 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-03-12 16:23 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2007-06-18 22:03 8 --sha-r C:\Windows\System32\E4BA9F2F62.sys
2007-06-18 22:12 2,828 --sha-w C:\Windows\System32\KGyGaAvL.sys
.
------- Sigcheck -------
2008-09-07 16:04 3600952 bccc38c6a4ea08e0b3e2acf44200ad91 C:\Windows\System32\ntkrnlpa.exe
2006-11-02 11:51 3502184 cadaa2fcb7f3d18be056a34d84ee2ca1 C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16386_none_69f99fa4b7380194\ntkrnlpa.exe
2007-08-31 23:02 3504824 b0315aab99ca2cf6576e68465b3ac554 C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16514_none_6a435250b701059d\ntkrnlpa.exe
2007-11-18 12:26 3504824 a676d072ff3967821ec292f5c885a32d C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16551_none_6a1511c2b724295c\ntkrnlpa.exe
2007-12-12 16:49 3504824 7b3de8f172bd5ba3842237088595e0dd C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16575_none_6a037312b730c69a\ntkrnlpa.exe
2008-02-14 12:13 3504696 0be027340c32d14abecda068e45e532a C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16584_none_69f7a2dcb739c934\ntkrnlpa.exe
2007-08-31 23:02 3504824 a59c7ea8f866ba9ebe06cb57f01fa5e1 C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20629_none_6ac720a1d022400b\ntkrnlpa.exe
2007-11-18 12:26 3504824 99ac9f5573f9376970a82d77731be62a C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20670_none_6a880e6bd052e7b1\ntkrnlpa.exe
2007-12-12 16:49 3505848 0bdca5c80ed74ad207eec0535d2af508 C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20697_none_6a797099d05cd0f4\ntkrnlpa.exe
2008-02-14 12:13 3505720 4821ab9f49b32cc17887ae861895826e C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20707_none_6adac1cbd013d2a2\ntkrnlpa.exe
2008-01-19 09:43 3600440 fe51e8dbbef2d01ef886499fecbf2d78 C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18000_none_6c3061a0b4231268\ntkrnlpa.exe
2008-09-07 16:04 3600952 bccc38c6a4ea08e0b3e2acf44200ad91 C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_6bf282f6b4510613\ntkrnlpa.exe
2008-04-26 10:11 3601464 68eef02a8846442fe98ad0e0517ee6bc C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_6c8020e9cd6b0b39\ntkrnlpa.exe
.
((((((((((((((((((((((((((((( snapshot@2008-09-07_12.12.01.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-07 10:06:27 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-09-07 14:05:18 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-09-07 14:05:18 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-09-07 10:05:07 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-09-07 14:05:13 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
- 2008-09-07 10:04:57 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-07 14:04:47 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-07 10:04:57 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-07 14:04:47 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-07 10:04:57 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-07 14:04:47 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-07 09:59:17 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-07 13:57:50 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-07 13:57:50 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2008-09-07 09:34:51 101,250 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-09-07 13:49:08 101,250 ----a-w C:\Windows\System32\perfc009.dat
- 2008-09-07 09:34:51 123,556 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-09-07 13:49:08 123,556 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-09-07 09:34:51 587,178 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-09-07 13:49:08 587,178 ----a-w C:\Windows\System32\perfh009.dat
- 2008-09-07 09:34:51 669,566 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-09-07 13:49:08 669,566 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-09-06 14:17:56 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
+ 2008-09-08 00:03:34 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
- 2008-09-07 10:07:19 14,150 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3170326469-2404168806-2133045765-1000_UserData.bin
+ 2008-09-07 14:07:20 14,292 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3170326469-2404168806-2133045765-1000_UserData.bin
- 2008-09-07 10:07:18 67,490 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-07 14:07:20 67,554 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-07 09:30:51 64,178 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-07 14:07:12 64,448 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-08 00:03:31 3,600,952 ----a-w C:\Windows\winsxs\Temp\PendingRenames\1882e0534611c9010200000074039803.ntkrnlpa.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"Speech Recognition"="C:\Windows\Speech\Common\sapisvr.exe" [2008-01-19 49664]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-11-15 614400]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-07 464168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 267064]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-20 C:\Windows\RtHDVCpl.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-21 110592]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-05 528384]
ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2007-11-28 303104]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8EBFFF4D-3E7E-4664-B625-AF732DCAFA64}"= UDP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{8A8B13C7-3F61-4116-A5E1-BF55907A7D2D}"= TCP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"TCP Query User{D6A99EF2-7361-4CF7-9DE3-DB7D38505AE1}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{A51E8CBB-ED45-4A7C-8CC6-EC4C824A2000}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{076043C8-DC57-4C3D-97C7-E7B7AFB71CEB}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4CA0709E-9A66-498B-974A-E68F2CD115BA}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6BBCDE4D-C6A1-439C-A6EF-7144168BF6B1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{21541E16-DFDF-4DEE-8092-D6BACBB6D704}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{33DB94A6-14E2-4168-BF79-E125E524B8E6}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{240D2859-0CAA-4FE2-9CFA-25B2DD6812D0}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{D4FA28E8-27D7-48BC-B7A4-1EF6735048A8}C:\\program files\\warcraft iii\\war3.exe"= UDP:C:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{322B6D3F-B788-4B2B-A74F-FE0C87E31515}C:\\program files\\warcraft iii\\war3.exe"= TCP:C:\program files\warcraft iii\war3.exe:Warcraft III
"TCP Query User{E28BD043-ABDC-4200-83F3-E2F265574D95}D:\\johan\\divers\\favoris\\emule\\emule.exe"= UDP:D:\johan\divers\favoris\emule\emule.exe:eMule
"UDP Query User{25DE419E-FFC2-453B-A3CD-4E804373A228}D:\\johan\\divers\\favoris\\emule\\emule.exe"= TCP:D:\johan\divers\favoris\emule\emule.exe:eMule
"{05D3FD57-C456-4619-8E1A-ABDB15D984CC}"= UDP:D:\Johan\PES2008.exe:Pro Evolution Soccer 2008
"{0FADEDE5-81B9-49E1-9D70-AA530A445BB7}"= TCP:D:\Johan\PES2008.exe:Pro Evolution Soccer 2008
"{AE98EA27-2B28-4ADC-B0B9-3AC18D1A275D}"= UDP:C:\Users\Johan\Desktop\PES2008.exe:Pro Evolution Soccer 2008
"{6DB9B7DD-99B3-4584-97CA-DA79FF602DEE}"= TCP:C:\Users\Johan\Desktop\PES2008.exe:Pro Evolution Soccer 2008
"{3F8556B3-342C-4A01-9743-99607272F586}"= UDP:C:\Users\Johan\Desktop\PES2008.exe:Pro Evolution Soccer 2008
"{A4B1E949-C528-42B1-B4D0-8DCF9F32B7C3}"= TCP:C:\Users\Johan\Desktop\PES2008.exe:Pro Evolution Soccer 2008
"{F03F6FC6-15E3-4F98-9ADC-D9AE99CDCC04}"= UDP:F:\PES2008.exe:Pro Evolution Soccer 2008
"{8348ADBA-B064-49D4-B027-71C0E01C458E}"= TCP:F:\PES2008.exe:Pro Evolution Soccer 2008
"TCP Query User{EE4F25F3-9EBB-4C5C-8F0D-0C3785F19C4D}D:\\johan\\divers\\veohclient.exe"= UDP:D:\johan\divers\veohclient.exe:Veoh Client
"UDP Query User{50AEBFDB-77B4-464A-814D-55DFFF537757}D:\\johan\\divers\\veohclient.exe"= TCP:D:\johan\divers\veohclient.exe:Veoh Client
"TCP Query User{2E742108-5227-489A-B7EE-0B41DD8AE0D1}D:\\johan\\divers\\veohclient.exe"= UDP:D:\johan\divers\veohclient.exe:Veoh Client
"UDP Query User{7549F54C-C9F5-4C0F-BA63-FFBD81D35D31}D:\\johan\\divers\\veohclient.exe"= TCP:D:\johan\divers\veohclient.exe:Veoh Client
"{9EC43070-3A31-4FBC-BC5C-44107B6E5E57}"= UDP:D:\Johan\PES2008.exe:Pro Evolution Soccer 2008
"{9AE88ABE-6629-402E-8154-D9E661896965}"= TCP:D:\Johan\PES2008.exe:Pro Evolution Soccer 2008
"{E7D5043D-D24B-41FE-80E1-BE603019D9EF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{F1DC6AAE-7081-459D-A30B-86703703C29A}"= UDP:D:\Johan\PES2008 (2).exe:Pro Evolution Soccer 2008
"{4AD6F603-BA17-42F2-98EC-D2CA5ABE0190}"= TCP:D:\Johan\PES2008 (2).exe:Pro Evolution Soccer 2008
"{F6C1D55A-3ED6-4E93-B67F-775A5348128C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E4EA9E55-2912-4F98-9495-E2D532182F26}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{C14CC5DD-A479-4DD5-B1E2-51A5C46CA0E9}D:\\johan\\divers\\emule\\emule.exe"= Disabled:UDP:D:\johan\divers\emule\emule.exe:eMule
"UDP Query User{04CE883C-44A7-4EE9-9FBC-5878E58FCCDE}D:\\johan\\divers\\emule\\emule.exe"= Disabled:TCP:D:\johan\divers\emule\emule.exe:eMule
"TCP Query User{1D9C062E-7CB4-4149-A8D6-4818C70868E9}D:\\johan\\divers\\favoris\\emule\\emule.exe"= Disabled:UDP:D:\johan\divers\favoris\emule\emule.exe:eMule
"UDP Query User{110061CE-D04C-417D-8BC3-DD14D8BE630E}D:\\johan\\divers\\favoris\\emule\\emule.exe"= Disabled:TCP:D:\johan\divers\favoris\emule\emule.exe:eMule
"TCP Query User{FA4756B2-66FA-472B-8823-EBB24062A7C6}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{5A6E19E2-D9A7-4A0F-BCFC-B511C79AAF11}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8973477-8fb7-11dc-9913-0016d4b34b62}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\shell\Open(&0)\command - Recycled\ctfmon.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-07 16:05:33
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\Windows\Explorer.exe
-> ?:\Windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Windows\System32\conime.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Acer\Empowering Technology\eNet\eNMTray.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-07 16:11:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-07 14:11:45
ComboFix2.txt 2008-09-07 10:13:24
Pre-Run: 25,298,087,936 octets libres
Post-Run: 25,049,247,744 octets libres
265 --- E O F --- 2008-09-06 14:07:07