Merci beaucoup de ton aide kewin05 ,j'ai fais ce que tu m'as dit et je te poste le rapportComboFix 08-12-17.01 - christine 2008-12-18 19:24:58.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.3070.2295 [GMT 1:00]
Lancé depuis: c:\users\christine\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\autorun.inf
c:\users\christine\AppData\Local\wkmau.dat
c:\users\christine\AppData\Local\wkmau_nav.dat
c:\users\christine\AppData\Local\wkmau_navps.dat
c:\windows\system32\drivers\msqpdxiwifnwtq.sys
c:\windows\system32\msqpdxrlmsxdei.dll
D:\Autorun.inf
D:\resycled
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSQPDXSERV.SYS
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-18 au 2008-12-18 ))))))))))))))))))))))))))))))))))))
.
2008-12-18 18:33 . 2008-06-19 17:24 28,544 --a------ c:\windows\System32\drivers\pavboot.sys
2008-12-18 18:32 . 2008-12-18 18:32 <REP> d-------- c:\program files\Panda Security
2008-12-18 15:26 . 2008-12-18 15:26 <REP> d-------- c:\program files\Trend Micro
2008-12-18 14:22 . 2008-12-18 14:22 <REP> d-------- c:\program files\Lavasoft
2008-12-16 20:59 . 2008-12-18 14:22 <REP> d-------- c:\users\All Users\Lavasoft
2008-12-16 20:59 . 2008-12-18 14:22 <REP> d-------- c:\programdata\Lavasoft
2008-12-16 20:32 . 2008-12-16 20:32 <REP> d-------- c:\program files\uTorrent
2008-12-14 14:06 . 2008-12-14 14:06 <REP> d-------- c:\program files\Ad Muncher
2008-12-13 22:28 . 2008-12-13 22:28 <REP> d-------- c:\users\christine\AppData\Roaming\SoftInform
2008-12-13 22:27 . 2008-12-13 22:36 <REP> d-------- c:\users\christine\AppData\Roaming\AdsCleaner
2008-12-13 22:27 . 2008-12-13 22:27 <REP> d-------- c:\program files\SoftInform
2008-12-11 20:37 . 2008-10-22 00:31 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-11 20:06 . 2008-11-01 00:38 4,247,552 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-11 20:06 . 2008-11-01 04:33 1,687,040 --a------ c:\windows\System32\gameux.dll
2008-12-11 20:06 . 2008-10-21 06:16 297,472 --a------ c:\windows\System32\gdi32.dll
2008-12-11 20:06 . 2008-11-01 04:33 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-02 23:20 . 2008-12-02 23:20 <REP> d-------- c:\users\christine\AppData\Roaming\WildTangent
2008-12-02 23:20 . 2008-12-02 23:20 <REP> d-------- c:\program files\HP Games
2008-11-26 10:01 . 2008-10-22 04:43 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-26 10:01 . 2008-10-22 04:43 160,768 --a------ c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 10:01 . 2008-10-22 04:43 95,232 --a------ c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-26 10:00 . 2008-10-21 06:16 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-26 10:00 . 2008-08-28 04:22 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-26 10:00 . 2008-08-28 04:24 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 10:00 . 2008-08-28 04:22 347,648 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-23 19:47 . 2008-11-23 19:47 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 19:20 . 2008-11-23 19:19 130,208 -r------- c:\windows\bwUnin-8.1.1.87-8876480SL.exe
2008-11-22 19:46 . 2008-11-23 19:15 <REP> d-------- c:\users\christine\AppData\Roaming\Smart PC Solutions
2008-11-22 19:41 . 2008-11-22 19:42 <REP> d-------- c:\program files\Dream Aquarium
2008-11-22 19:31 . 2006-10-09 12:00 94,208 --a------ c:\windows\Dream Aquarium.scr
2008-11-22 15:04 . 2008-11-22 15:04 102,400 --a------ c:\windows\DreamAquarium.scr
2008-11-21 14:53 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-21 14:53 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-21 14:53 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-21 14:53 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-21 14:52 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-21 14:52 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-21 14:52 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-21 14:52 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-21 14:52 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-21 12:17 . 2008-11-21 12:17 <REP> d-------- c:\program files\RayV(64)
2008-11-21 07:56 . 2008-11-21 07:56 2,046 --a------ C:\lma_log.html
2008-11-21 07:56 . 2008-11-21 08:01 243 --a------ C:\log.html
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 13:21 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-18 07:25 --------- d-----w c:\users\christine\AppData\Roaming\uTorrent
2008-12-17 21:57 --------- d-----w c:\programdata\Google Updater
2008-12-17 20:14 --------- d-----w c:\program files\Google
2008-12-17 13:50 --------- d-----w c:\programdata\Spybot - Search & Destroy
2008-12-14 13:06 --------- d-----w c:\programdata\Ad Muncher
2008-12-11 20:45 --------- d-----w c:\programdata\Roxio
2008-12-11 19:51 174 --sha-w c:\program files\desktop.ini
2008-12-11 19:44 --------- d-----w c:\programdata\Microsoft Help
2008-12-11 19:44 --------- d-----w c:\program files\Windows Mail
2008-12-09 22:17 --------- d-----w c:\users\christine\AppData\Roaming\SolSuite
2008-12-02 22:20 --------- d-----w c:\programdata\WildTangent
2008-12-02 22:02 --------- d-----w c:\programdata\WLInstaller
2008-11-23 17:52 --------- d-----w c:\programdata\fssg
2008-11-21 13:44 --------- d-----w c:\program files\RayV
2008-11-15 18:40 --------- d-----w c:\program files\Common Files\ScanSoft Shared
2008-11-15 14:03 --------- d-----w c:\program files\Canon
2008-11-10 12:55 --------- d-----w c:\program files\QuickTime
2008-11-10 12:54 --------- d-----w c:\programdata\Apple Computer
2008-11-10 12:54 --------- d-----w c:\program files\Common Files\Apple
2008-11-10 12:52 --------- d-----w c:\program files\Apple Software Update
2008-11-06 15:55 --------- d-----w c:\program files\Common Files\Adobe
2008-11-01 03:33 537,600 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:33 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:33 449,536 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:33 2,144,256 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:33 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-31 23:23 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-10-29 06:20 2,923,520 ----a-w c:\windows\explorer.exe
2008-10-24 05:06 --------- d-----w c:\programdata\SpinTop Games
2008-10-23 15:08 --------- d-----w c:\program files\StuffPlug3
2008-10-23 10:43 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-22 14:45 21,248 ----a-w c:\windows\Help\OEM\scripts\HPScript.exe
2008-10-20 22:18 --------- d-----w c:\program files\lbreakout2
2008-10-18 13:26 --------- d-----w c:\users\christine\AppData\Roaming\GrassGames
2008-10-18 13:26 --------- d-----w c:\program files\Free Solitaire 3D
2008-10-18 10:41 --------- d-----w c:\program files\Patience
2008-10-13 11:59 319,456 ----a-w c:\windows\DIFxAPI.dll
2008-10-07 20:42 2,560 ----a-w c:\windows\_MSRSTRT.EXE
2008-08-22 21:10 4 ----a-w c:\users\christine\AppData\Roaming\wklnhst.dat
2005-09-09 05:05 271 ----a-w c:\users\christine\install.cmd
2005-06-20 16:52 1,163,776 ----a-w c:\users\All Users\autorun.exe
2005-06-20 16:52 1,163,776 ----a-w c:\programdata\autorun.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC9377A2-2E8D-44A1-99DB-F8A821DF254D}]
2007-05-02 23:02 237568 --a------ c:\windows\System32\SiPlugins.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-22 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-10 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-10 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-10 88608]
"Ad Muncher"="c:\program files\Ad Muncher\AdMunch.exe" [2008-12-14 779776]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 c:\windows\RtHDVCpl.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-11-23 91440]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-06-29 805392]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"Sidebar"=c:\program files\windows sidebar\sidebar.exe /autoRun
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7D4C8E21-8BE5-4D14-B93C-C6FB12CEBA4D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{5F4608E0-7677-4A21-B6FC-788D401FC3BE}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{C2F26A54-4B9D-4174-9A71-169236729BFB}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{4B124A13-373C-4BB3-9CA5-07E2A42DC42E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{BD8586A9-0592-443D-9A5E-EA7D001FCF3C}c:\\windows\\system32\\mcoinstall.exe"= UDP:c:\windows\system32\mcoinstall.exe:mcoinstall
"UDP Query User{2380C97C-2CB8-48D2-9D7C-81CED8CBC8E7}c:\\windows\\system32\\mcoinstall.exe"= TCP:c:\windows\system32\mcoinstall.exe:mcoinstall
"{488848DD-EE37-4802-9C74-0F0614DFF670}"= UDP:c:\program files\Podmailing\podmailing.exe:Podmailing Beta
"{613209B8-EF83-4111-B946-24068A2211EB}"= TCP:c:\program files\Podmailing\podmailing.exe:Podmailing Beta
"TCP Query User{2D93BE5E-DF19-4830-80F7-D05D85F24C72}c:\\program files\\tribalweb\\tribalweb.exe"= UDP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"UDP Query User{E675256D-A9B6-4DBA-BCA5-BB5EFB1F3FBB}c:\\program files\\tribalweb\\tribalweb.exe"= TCP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"TCP Query User{841AD0EA-1F41-4D41-9018-E88CBD1BFA1C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{1EDF6C52-0099-48C8-91F8-F0EDAF9024DC}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{2BBAAF46-0EAC-4DC5-A7E9-5E368FF18234}c:\\users\\christine\\documents\\jeux\\clickomania\\kyodai mahjongg 2006\\kmj.exe"= UDP:c:\users\christine\documents\jeux\clickomania\kyodai mahjongg 2006\kmj.exe:kmj.exe
"UDP Query User{9C4056A2-B642-4413-B297-C4322ECB02C7}c:\\users\\christine\\documents\\jeux\\clickomania\\kyodai mahjongg 2006\\kmj.exe"= TCP:c:\users\christine\documents\jeux\clickomania\kyodai mahjongg 2006\kmj.exe:kmj.exe
"{3F1B3005-9582-41E0-B882-C03C6DD8A54E}"= c:\program files\Windows Live\Messenger\wlcsdk.exe:Windows Live Messenger (Phone)
"{F9E525A1-3A98-4EC0-A66D-A7C9D62CF5F0}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{77B79812-3600-4629-B259-DDE7E8EE801E}c:\\program files\\rayv\\rayv\\rayv.exe"= UDP:c:\program files\rayv\rayv\rayv.exe:RayV
"UDP Query User{9F2CE553-C270-4B34-B68F-166DEB032A0B}c:\\program files\\rayv\\rayv\\rayv.exe"= TCP:c:\program files\rayv\rayv\rayv.exe:RayV
"{17628562-56A5-4330-9D89-67DA6B1DB0DA}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{582285F9-8808-42C3-A011-2AC4A738079C}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{0BBC8B3C-4539-4BD5-9648-576A32896FB3}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{20B42294-537B-497E-B673-A09B93F56E2D}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{6F300AFF-1526-4872-B6F2-2D94DD72BB2B}c:\\program files\\windows live\\mcoview.sfx.exe"= UDP:c:\program files\windows live\mcoview.sfx.exe:mcoview.sfx
"UDP Query User{5298D6CB-F27D-49B3-BFD4-56F9C29B05A5}c:\\program files\\windows live\\mcoview.sfx.exe"= TCP:c:\program files\windows live\mcoview.sfx.exe:mcoview.sfx
"{B19BBC52-6B06-4F74-A2D6-77B6B3D4985D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D7A1EABA-A7D2-4C51-A29C-06C1E9BC347F}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{D88833B2-A76C-44BD-9CA7-BF4F55F77FC2}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{9275AEE7-5A47-45C4-97A8-98853DBCC245}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{C2DE0951-AEA8-4588-B5E2-3EDCFE5A9068}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{BB026E3D-5081-4BE9-B757-0D1C071B6EAE}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{0BA5DB59-0A5D-4A1D-BBB6-0871B559BC16}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{F0CFCE1A-D308-481A-A5DB-51D1C57845E3}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{1366F4B5-E5B4-4643-9E81-AAABADF7FCDD}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-18 28544]
R1 F-Secure HIPS;F-Secure HIPS;\??\c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [2008-09-09 47936]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys [2008-09-09 34752]
R1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-09-09 66816]
R1 fsvista;F-Secure Vista Support Driver;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [2008-09-09 12896]
R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [2007-09-05 198240]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [2008-09-09 62048]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2008-02-26 493568]
R3 P0630VID;Creative WebCam Live!;c:\windows\system32\DRIVERS\P0630Vid.sys [2008-03-22 91830]
S4 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\Win2K\FSfilter.sys [2008-09-09 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\Win2K\FSrec.sys [2008-09-09 25184]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL k:\resycled\boot.com k:
\shell\Open\command - k:\resycled\boot.com k:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cff95dc-2fb0-11dd-911f-001bb98c51b0}]
\shell\AutoRun\command - K:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54272d4a-f830-11dc-b34f-001bb98c51b0}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL k:\resycled\boot.com k:
\shell\Open\command - k:\resycled\boot.com k:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5a12293-0865-11dd-bdee-001bb98c51b0}]
\shell\AutoRun\command - K:\InstallTomTomHOME.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-03 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\users\christine\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-02 22:45]
2008-11-21 c:\windows\Tasks\HPCeeScheduleForchristine.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2007-05-17 15:55]
2008-12-18 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 08:23]
2008-12-18 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2008-04-23 17:11]
.
.
------- Associations de fichier -------
.
regedit=regedit.exe "%1"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-18 19:30:57
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(972)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'lsass.exe'(692)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(596)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(644)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsgk32.exe
c:\program files\Orange\AntivirusFirewall\Common\FSMA32.EXE
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Orange\AntivirusFirewall\Common\FSMB32.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Orange\AntivirusFirewall\Common\FCH32.EXE
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
c:\program files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
c:\program files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
c:\program files\Orange\AntivirusFirewall\FWES\program\fsdfwd.exe
c:\program files\Orange\AntivirusFirewall\FSAUA\program\fsus.exe
c:\windows\System32\conime.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsav32.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Heure de fin: 2008-12-18 19:37:54 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-18 18:37:51
Avant-CF: 225,382,268,928 octets libres
Après-CF: 224,960,315,392 octets libres
272 --- E O F --- 2008-12-11 19:44:29