Génial ça a marché !
Voici le fichier log :
ComboFix 09-07-13.01 - jms 14/07/2009 19:09.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1279.889 [GMT 2:00]
Running from: c:\documents and settings\jms\Bureau\tdss.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-1390067357-1844237615-725345543-1003
c:\windows\Installer\22f29.msi
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\b4fm.dll
c:\windows\system32\drivers\UACbapbiqqhkwkkyiuwk.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\UACanswqwqxdgitkltyn.dat
c:\windows\system32\UACfuylidmrxfjoexyqq.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkoqmqpgxtmpjxvkvi.dll
c:\windows\system32\UAClaqbdnupxjnwrujwm.dll
c:\windows\system32\UACroqglcaliivbvpyen.dll
c:\windows\system32\UACsdjjavymexrldlvro.dll
c:\windows\system32\uactmp.db
c:\windows\system32\UACvnkvcnotmsbnethxc.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WDJlmnpo.ini
c:\windows\system32\WDJlmnpo.ini2
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-06-14 to 2009-07-14 )))))))))))))))))))))))))))))))
.
2009-07-14 16:02 . 2009-07-14 16:06 -------- d-----w- C:\ToolBar SD
2009-07-14 15:25 . 2009-07-14 15:25 -------- d-----w- C:\GenProc
2009-07-14 15:25 . 2009-07-14 15:25 1948803 ----a-w- c:\program files\GenProc.exe
2009-07-14 15:21 . 2009-07-14 15:21 -------- d-----w- c:\program files\trend micro
2009-07-14 15:21 . 2009-07-14 15:21 -------- d-----w- C:\rsit
2009-07-14 15:21 . 2009-07-14 15:21 781909 ----a-w- c:\program files\RSIT.exe
2009-07-14 15:10 . 2007-01-18 12:00 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2009-07-14 15:09 . 2009-07-14 15:09 423736 ----a-w- c:\program files\avg-anti-rootkit_avg_anti-rootkit_1.1.0.42_anglais_34515.exe
2009-07-14 13:47 . 2009-07-14 13:47 8171320 ----a-w- c:\program files\Firefox Setup 3.5.exe
2009-07-14 13:29 . 2009-07-14 15:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-14 13:29 . 2009-07-14 15:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-07-14 13:23 . 2009-07-14 13:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-14 12:51 . 2009-07-14 12:51 -------- d-----w- c:\program files\Crawler
2009-07-14 12:28 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-14 12:28 . 2009-07-14 12:28 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-07-14 12:28 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-14 10:39 . 2009-07-14 10:39 -------- d-----w- c:\documents and settings\jms\Application Data\Nero
2009-07-14 10:24 . 2009-07-14 10:24 -------- d-----w- c:\program files\Windows Sidebar
2009-07-14 10:12 . 2009-07-14 10:26 -------- d-----w- c:\program files\Nero
2009-07-14 10:12 . 2009-07-14 10:19 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Nero
2009-07-14 10:12 . 2009-07-14 10:16 -------- d-----w- c:\program files\Fichiers communs\Nero
2009-07-14 09:36 . 2009-07-14 10:09 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-07-14 09:04 . 2002-05-06 09:01 45056 ----a-w- c:\windows\system32\WNASPI32.DLL
2009-07-14 09:04 . 2002-05-06 09:01 17005 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
2009-07-14 09:04 . 2001-04-19 15:34 4672 ----a-w- c:\windows\system\WOWPOST.EXE
2009-07-14 09:04 . 2001-04-19 15:34 5600 ----a-w- c:\windows\system\WINASPI.DLL
2009-07-14 09:02 . 2009-07-14 09:02 -------- d-----w- C:\adaptec
2009-07-14 08:57 . 2009-07-14 08:57 -------- d-----w- c:\program files\Burn4Free
2009-06-27 09:25 . 2009-06-14 14:07 1004800 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-26 16:04 . 2009-06-26 16:04 -------- d-----w- c:\documents and settings\jms\Local Settings\Application Data\AVG Security Toolbar
2009-06-26 07:31 . 2009-06-26 07:31 832144 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-26 07:31 . 2009-06-27 09:25 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2009-06-26 07:31 . 2009-06-26 07:31 -------- d-----w- c:\documents and settings\NetworkService.AUTORITE NT.000\Menu Démarrer
2009-06-26 07:31 . 2009-06-26 07:31 -------- d-----w- c:\documents and settings\NetworkService.AUTORITE NT.000\Application Data\AVGTOOLBAR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-14 16:52 . 2008-05-30 17:34 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2009-07-14 13:09 . 2008-04-20 20:07 -------- d-----w- c:\program files\VirtualDubMOD
2009-07-14 11:13 . 2008-04-20 20:31 -------- d-----w- c:\program files\PowerArchiver
2009-07-14 10:49 . 2008-05-26 19:12 -------- d-----w- c:\documents and settings\jms\Application Data\BitTorrent
2009-07-14 07:45 . 2008-04-30 18:19 -------- d-----w- c:\program files\emule
2009-06-28 10:13 . 2008-04-20 18:04 -------- d-----w- c:\program files\SUPER
2009-06-26 17:57 . 2008-06-19 19:59 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-06-26 07:31 . 2008-05-30 17:35 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-26 07:31 . 2008-05-30 17:35 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-26 07:31 . 2008-04-23 21:47 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-06 12:19 . 2001-08-24 12:00 76698 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-06 12:19 . 2001-08-24 12:00 471726 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-01 13:46 . 2009-06-01 13:46 -------- d-----w- c:\program files\Debugmode
2009-05-19 17:33 . 2009-05-19 17:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DVD Shrink
2009-05-09 07:16 . 2008-05-30 17:35 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-08 11:51 . 2009-05-08 11:51 1496576 ---h--w- c:\windows\system32\wodfamop.dll
2008-08-18 10:30 . 2008-08-18 10:32 2889336 ----a-w- c:\program files\tvants_tvants_1.0.0.59_francais_41479.exe
2008-04-21 20:02 . 2008-04-21 20:02 34590128 ----a-w- c:\program files\Nero6.exe
2008-04-21 18:34 . 2008-04-21 18:34 28914866 ----a-w- c:\program files\71.89_win2kxp_international.exe
2008-04-21 18:27 . 2008-04-21 18:27 4103902 ----a-w- c:\program files\3DP-9x-1241.exe
2002-07-26 16:02 . 2008-04-21 18:27 153088 ----a-w- c:\program files\UNWISE.EXE
2009-06-24 15:27 . 2009-07-14 13:47 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2008-07-06 09:31 . 2008-07-06 09:31 608 --sha-w- c:\windows\system32\winzvprt5.sys
.
------- Sigcheck -------
[-] 2006-03-09 08:25 578048 0DF75FB73F705B011630159A43D7C354 c:\windows\system32\user32.dll
[-] 2006-02-14 19:56 359808 667192A11DB19F36624119C0DD4DE4F2 c:\windows\system32\drivers\tcpip.sys
[-] 2006-05-09 08:11 2058880 73FA9C95D235844A36968C7852C7DBDD c:\windows\system32\ntkrnlpa.exe
[-] 2006-03-09 08:25 2181376 63729DD0F2AAE36CC52B89C05505146C c:\windows\system32\ntoskrnl.exe
[-] 2006-03-09 08:25 57856 DA81EC57ACD4CDC3D4C51CF3D409AF9F c:\windows\system32\spoolsv.exe
[-] 2006-03-09 09:40 1548288 E51172E3C82D76FCC02001D0FF41A1A1 c:\windows\system32\sfcfiles.dll
[-] 2006-03-09 08:25 397824 CB7D37602638369A516757E994CBB31D c:\windows\system32\rpcss.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"Clavier+"="c:\program files\Clavier+\Clavier.exe" [2007-10-21 88576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"Config"="c:\windows\system32\run.cmd" [2006-02-14 248]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-19 44544]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-26 07:31 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=SMNT40.dll
"aux1"=SMNT40.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"DisablePagingExecutive"=dword:00000001
"SecondLevelDataCache"=dword:00000200
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"= c:\\Program Files\\BitTorrent\\bittorrent.exe
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [30/05/2008 19:35 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [30/05/2008 19:35 108552]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [16/09/2008 13:03 169312]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [06/07/2008 10:17 906520]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [06/07/2008 10:17 298776]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [21/02/2009 23:18 55152]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
IE: Crawler Search - tbr:iemenu
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\jms\Application Data\Mozilla\Firefox\Profiles\nfh6yjtw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://fr.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_fr&p=
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\VirtualDubMOD\K-Lite Codec Pack2\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VirtualDubMOD\K-Lite Codec Pack2\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-14 19:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3812)
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSFR.DLL
c:\windows\system32\msi.dll
c:\windows\system32\nvwddi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2009-07-14 19:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-14 17:18
Pre-Run: 151 764 111 360 octets libres
Post-Run: 151 908 073 472 octets libres
277