Probleme avec poste de travail
Fermé
ludoking
Messages postés
52
Date d'inscription
dimanche 7 juin 2009
Statut
Membre
Dernière intervention
22 octobre 2009
-
8 juin 2009 à 20:21
ludoking Messages postés 52 Date d'inscription dimanche 7 juin 2009 Statut Membre Dernière intervention 22 octobre 2009 - 8 juin 2009 à 21:31
ludoking Messages postés 52 Date d'inscription dimanche 7 juin 2009 Statut Membre Dernière intervention 22 octobre 2009 - 8 juin 2009 à 21:31
A voir également:
- Probleme avec poste de travail
- Acheter colis perdu poste - Guide
- Avis d'instance la poste ✓ - Forum Réseaux sociaux
- La poste la poste mobile - Guide
- Identité numérique la poste danger - Télécharger - Confidentialité
- Impossible de créer le fichier de travail. vérifiez la variable d'environnement temp ✓ - Forum Word
7 réponses
cs-bilou
Messages postés
769
Date d'inscription
dimanche 2 décembre 2007
Statut
Membre
Dernière intervention
24 février 2011
164
8 juin 2009 à 20:22
8 juin 2009 à 20:22
Lance ComboFix.
Et poste nous le rapport.
Bilou.
Et poste nous le rapport.
Bilou.
Brachior
Messages postés
613
Date d'inscription
dimanche 21 octobre 2007
Statut
Membre
Dernière intervention
22 juin 2009
46
8 juin 2009 à 20:26
8 juin 2009 à 20:26
Ça sent le formatage a plein nez ça ^^
ludoking
Messages postés
52
Date d'inscription
dimanche 7 juin 2009
Statut
Membre
Dernière intervention
22 octobre 2009
8 juin 2009 à 20:28
8 juin 2009 à 20:28
eux quand je clic je sur le lien je me retrouve sur un site espagnol c normal ?? et je connais pas combofix
cs-bilou
Messages postés
769
Date d'inscription
dimanche 2 décembre 2007
Statut
Membre
Dernière intervention
24 février 2011
164
8 juin 2009 à 20:29
8 juin 2009 à 20:29
Tien sinon ici.
Bilou
Bilou
ludoking
Messages postés
52
Date d'inscription
dimanche 7 juin 2009
Statut
Membre
Dernière intervention
22 octobre 2009
8 juin 2009 à 21:31
8 juin 2009 à 21:31
re ayez j'ai le rapport de combofix pourai tu y jeter un coup d'oeil des que tu pourra merci
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
eux je suis allez sur l'autre lien j'ai telecharger combofix j'ai lu les instruction mais quand je lance combofix j'ai juste une fenetre bleu qui s'affiche et rien d'otre
Que dois je faire ?????
Que dois je faire ?????
ludoking
Messages postés
52
Date d'inscription
dimanche 7 juin 2009
Statut
Membre
Dernière intervention
22 octobre 2009
8 juin 2009 à 21:01
8 juin 2009 à 21:01
eux en faites ayez j'ai reussi a lancer combofix donc ya pu qu'a ^^
ludoking
Messages postés
52
Date d'inscription
dimanche 7 juin 2009
Statut
Membre
Dernière intervention
22 octobre 2009
8 juin 2009 à 21:16
8 juin 2009 à 21:16
rapport combofix :
ComboFix 09-06-07.07 - guilleux 08/06/2009 20:58.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.2106 [GMT 2:00]
Lancé depuis: c:\users\guilleux\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Performanceoptimizer (Free)
c:\program files\Performanceoptimizer (Free)\creader.exe
c:\program files\Performanceoptimizer (Free)\language.cfg
c:\program files\Performanceoptimizer (Free)\Language\English.ini
c:\program files\Performanceoptimizer (Free)\Language\English_po.ini
c:\program files\Performanceoptimizer (Free)\Language\English_spo.ini
c:\program files\Performanceoptimizer (Free)\Language\Franch.ini
c:\program files\Performanceoptimizer (Free)\Language\Franch_po.ini
c:\program files\Performanceoptimizer (Free)\Language\Franch_spo.ini
c:\program files\Performanceoptimizer (Free)\Language\German.ini
c:\program files\Performanceoptimizer (Free)\Language\German_po.ini
c:\program files\Performanceoptimizer (Free)\Language\German_spo.ini
c:\program files\Performanceoptimizer (Free)\Language\Spanish.ini
c:\program files\Performanceoptimizer (Free)\Language\Spanish_po.ini
c:\program files\Performanceoptimizer (Free)\Language\Spanish_spo.ini
c:\program files\Performanceoptimizer (Free)\MFC71.dll
c:\program files\Performanceoptimizer (Free)\msvcp71.dll
c:\program files\Performanceoptimizer (Free)\msvcr71.dll
c:\program files\Performanceoptimizer (Free)\pcid.exe
c:\program files\Performanceoptimizer (Free)\PerfOpt.exe.manifest
c:\program files\Performanceoptimizer (Free)\PerfOpt.sdb
c:\program files\Performanceoptimizer (Free)\po_cfg.ini
c:\program files\Performanceoptimizer (Free)\PoChk.exe.manifest
c:\program files\Performanceoptimizer (Free)\Tweaks\data001.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data003.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data006.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data007.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data009.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data011.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data013.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data016.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data017.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data020.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data023.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data027.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data030.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data031.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data033.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data040.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data042.reg
c:\program files\Performanceoptimizer (Free)\ua_manager.exe
c:\program files\Performanceoptimizer (Free)\uninstpo.exe
c:\program files\Performanceoptimizer (Free)\updater.exe.manifest
c:\users\guilleux\AppData\Roaming\.#
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-08 au 2009-06-08 ))))))))))))))))))))))))))))))))))))
.
2009-06-08 18:38 . 2009-06-08 18:38 -------- d-----w- \Qoobox
2009-06-07 18:40 . 2009-06-07 18:40 -------- d-----w- c:\program files\CCleaner
2009-06-07 16:35 . 2009-06-07 16:35 -------- d-----w- c:\progra~2\WindowsSearch
2009-06-07 14:51 . 2009-06-07 15:07 -------- d-----w- c:\program files\McAfee
2009-06-07 12:11 . 2009-06-07 14:18 -------- d-----w- c:\program files\trend micro
2009-06-07 12:11 . 2009-06-07 12:25 -------- d-----w- C:\rsit
2009-06-07 12:11 . 2009-06-07 12:25 -------- d-----w- \rsit
2009-06-07 11:38 . 2009-06-07 13:25 -------- d-----w- c:\program files\Navilog1
2009-06-07 11:11 . 2009-06-07 11:11 -------- d-----w- c:\program files\Zone Labs
2009-06-07 11:11 . 2009-06-07 11:11 -------- d-----w- c:\progra~2\CheckPoint
2009-06-07 11:09 . 2009-06-07 15:50 -------- d-----w- c:\windows\Internet Logs
2009-06-07 10:24 . 2009-06-07 16:38 -------- d-----w- c:\windows\BDOSCAN8
2009-06-07 09:35 . 2009-06-07 09:35 -------- d-----w- c:\users\guilleux\AppData\Roaming\Malwarebytes
2009-06-07 09:35 . 2009-06-07 09:35 -------- d-----w- c:\progra~2\Malwarebytes
2009-06-07 09:35 . 2009-06-07 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-07 09:15 . 2009-06-07 09:21 -------- d-----w- c:\users\guilleux\.housecall6.6
2009-06-07 09:14 . 2009-06-07 09:14 -------- d-----w- c:\program files\Java
2009-05-31 19:23 . 2009-05-31 19:23 -------- d-----w- c:\program files\QuickTime
2009-05-22 09:19 . 2009-05-22 09:19 -------- d-----w- c:\progra~2\ATI
2009-05-22 09:11 . 2009-05-22 09:11 10134 ----a-r- c:\users\guilleux\AppData\Roaming\Microsoft\Installer\{AA3DDA7B-A960-51C2-69C5-86F3AFB3E074}\ARPPRODUCTICON.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 19:06 . 2009-01-20 14:41 3220357120 --sha-w- \hiberfil.sys
2009-06-08 19:06 . 2008-04-29 20:31 3534041088 --sha-w- \pagefile.sys
2009-06-08 19:04 . 2008-12-24 23:47 -------- d-----w- c:\users\guilleux\AppData\Roaming\Free Download Manager
2009-06-08 18:49 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-08 18:49 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-07 18:20 . 2008-03-21 11:35 -------- d-----w- c:\program files\Acer GameZone
2009-06-07 17:32 . 2008-03-21 11:21 -------- d-----w- c:\program files\Common Files\LightScribe
2009-06-07 17:30 . 2008-12-24 23:47 -------- d-----w- c:\program files\Free Download Manager
2009-06-07 14:51 . 2008-03-21 11:50 -------- d-----w- c:\progra~2\McAfee
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-05-30 12:45 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-30 12:44 . 2008-04-29 20:34 -------- d-----w- c:\program files\ATI
2009-05-30 12:44 . 2008-09-24 18:45 -------- d-----w- c:\progra~2\Yahoo! Companion
2009-05-22 09:16 . 2008-04-29 20:34 -------- d-----w- c:\program files\ATI Technologies
2009-05-14 17:38 . 2008-09-24 17:45 -------- d-----w- c:\program files\Dofus
2009-05-14 01:03 . 2008-03-21 11:14 -------- d-----w- c:\progra~2\Microsoft Help
2009-05-08 01:09 . 2008-09-24 15:57 70104 ----a-w- c:\users\guilleux\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-07 20:22 . 2008-03-21 11:16 -------- d-----w- c:\program files\Microsoft Works
2009-05-05 17:20 . 2008-09-25 20:35 1356 ----a-w- c:\users\guilleux\AppData\Local\d3d9caps.dat
2009-05-02 22:38 . 2009-05-02 22:38 -------- d-----w- c:\users\guilleux\AppData\Roaming\vlc
2009-04-29 03:31 . 2009-04-29 03:31 4491776 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2009-04-29 02:08 . 2009-04-29 02:08 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-04-29 02:08 . 2009-04-29 02:08 303104 ----a-w- c:\windows\system32\atieclxx.exe
2009-04-29 02:07 . 2009-04-29 02:07 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2009-04-29 02:06 . 2006-04-09 06:33 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2009-04-29 02:06 . 2006-04-09 06:33 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2009-04-29 02:05 . 2009-04-29 02:05 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2009-04-29 02:05 . 2009-04-29 02:05 11776 ----a-w- c:\windows\system32\atimuixx.dll
2009-04-29 02:05 . 2006-04-09 06:33 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-04-29 02:02 . 2009-04-29 02:02 2428928 ----a-w- c:\windows\system32\atidxx32.dll
2009-04-29 01:52 . 2006-04-09 06:33 3082752 ----a-w- c:\windows\system32\atiumdag.dll
2009-04-29 01:41 . 2009-04-29 01:41 11559424 ----a-w- c:\windows\system32\atioglxx.dll
2009-04-29 01:37 . 2006-04-09 06:33 4963840 ----a-w- c:\windows\system32\atiumdva.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\atimpc32.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\amdpcom32.dll
2009-04-29 01:24 . 2009-04-29 01:24 163840 ----a-w- c:\windows\system32\atiadlxx.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalrt.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalcl.dll
2009-04-29 01:20 . 2009-04-29 01:20 3293184 ----a-w- c:\windows\system32\aticaldd.dll
2009-04-29 01:11 . 2009-04-29 01:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-04-28 18:53 . 2009-03-28 19:15 -------- d-----w- c:\program files\DofusBeta
2009-04-24 05:43 . 2009-04-24 05:43 95544 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
2009-04-14 17:00 . 2008-10-02 16:52 1624 ----a-w- c:\users\guilleux\AppData\Roaming\wklnhst.dat
2009-03-17 03:38 . 2009-04-16 03:09 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 03:09 24064 ----a-w- c:\windows\system32\amxread.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 22:38 121392 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-11-12 2474031]
"Google Update"="c:\users\guilleux\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-04-25 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-21 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-21 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-21 81920]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2008-01-09 326176]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2007-12-07 196128]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-28 61440]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2008-05-02 307200]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-10-11 4702208]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-3-21 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2103130941-1255188074-3532458092-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9A0FC0E6-C41A-491D-85B2-7B42B0C4D7B6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9272E7EA-E5B0-4E65-AA03-61B849992A79}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0590D135-20CF-4616-83A2-B4D64D7A7ADC}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{40F60C6C-DD8E-40B8-AB34-5061C567E010}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
"{EC714915-D3A6-43D3-B785-23155F4ED9A6}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
"{8FB6D042-3CF4-407D-A2E9-A1CE05C41456}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
"{542BA28B-703D-48DB-B83F-94E757E578BF}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
"{B34DAF09-668F-41FD-94EB-A7A892360F5C}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
"{A924C65E-76C0-4E34-9E09-9FC3F7E6691A}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
"{F051E17E-51EF-4830-B367-F6DA497077E5}"= c:\program files\Acer Arcade Live\Acer HomeMedia Trial Creator\Acer HomeMedia Trial Creator.exe:Acer HomeMedia Trial Creator
"{F158742F-48F9-4833-8369-7CBA8CC22457}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
"{D5CDD3AC-3A9B-4EAA-B42D-5B9FE17A148C}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{F859AB84-4B19-4649-BABF-C6A69475B7B4}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{659629A3-7D4E-4EC5-B3D6-9C2D20284F87}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{97AC95B8-F2CE-487E-BBDF-484936085F48}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{7A98BAAC-7796-4F71-8E7C-96AEB504DEC6}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{0E3A9A90-514B-43F0-9E07-44A8A4C93981}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{677E4415-9903-4D2D-9E59-76BEBC33147A}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{07ADF2D6-44B2-41D6-998C-EE7BB2DD1E1E}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{BA2C04C7-ADA2-418C-A251-BC301EA6F216}"= UDP:d:\programe files\DSLtest2007.exe:DSLtest2007
"{08D65637-16DF-4947-B256-7D9E2AED6CE1}"= TCP:d:\programe files\DSLtest2007.exe:DSLtest2007
"{9D963BBF-279A-4453-B031-D5FD45FF3D68}"= UDP:c:\program files\ESTsoft\ALShow\ALShow.exe:ALShow
"{DABA5295-7A1F-4B40-9F40-96FC70119AFD}"= TCP:c:\program files\ESTsoft\ALShow\ALShow.exe:ALShow
"{56A46C1D-C375-4B8B-B639-5449EA0887FE}"= UDP:c:\program files\SuperCopier2\SuperCopier2.exe:SuperCopier2
"{08B8DC5A-8D5C-4847-AD52-0A496BC691D9}"= TCP:c:\program files\SuperCopier2\SuperCopier2.exe:SuperCopier2
"TCP Query User{38782EEC-3CFE-4709-8AC0-2ABFEF27CB4F}c:\\program files\\orange\\browser\\browser.exe"= UDP:c:\program files\orange\browser\browser.exe:Browser
"UDP Query User{7326271B-DBEB-4AD7-A49E-E9B5D619A76F}c:\\program files\\orange\\browser\\browser.exe"= TCP:c:\program files\orange\browser\browser.exe:Browser
"{4ACF2D9E-A674-4CD8-8B66-4526A2594B3E}"= UDP:c:\program files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus
"{DC1A2892-BCB1-4562-B67F-E90772064405}"= TCP:c:\program files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus
"TCP Query User{1B320938-6B46-46C8-9426-017C47F124A5}c:\\users\\guilleux\\appdata\\roaming\\m\\flec006.exe"= UDP:c:\users\guilleux\appdata\roaming\m\flec006.exe:flec006.exe
"UDP Query User{8737D2E6-6CEE-4D81-8E3F-24AB19D14DF3}c:\\users\\guilleux\\appdata\\roaming\\m\\flec006.exe"= TCP:c:\users\guilleux\appdata\roaming\m\flec006.exe:flec006.exe
"TCP Query User{D41F5C61-8A72-4604-8F25-7D948D04B51B}c:\\windows\\system32\\wintems.exe"= UDP:c:\windows\system32\wintems.exe:wintems
"UDP Query User{E8D7DF14-D79E-420C-8B54-997B980F9216}c:\\windows\\system32\\wintems.exe"= TCP:c:\windows\system32\wintems.exe:wintems
"{45FC2FF8-D5C5-4AE4-B499-B8EB53F8CDF7}"= UDP:c:\program files\ESTsoft\ALShow\alupdate.exe:alupdate
"{E1D1A7FA-AE6E-4C71-82A7-9BE5D9E980AA}"= TCP:c:\program files\ESTsoft\ALShow\alupdate.exe:alupdate
"TCP Query User{F907567B-6168-4AEF-BE6A-0B2336FCD0CF}c:\\program files\\free download manager\\fdm.exe"= UDP:c:\program files\free download manager\fdm.exe:Free Download Manager
"UDP Query User{D58D5D66-5258-48CA-80C6-43F555109AA6}c:\\program files\\free download manager\\fdm.exe"= TCP:c:\program files\free download manager\fdm.exe:Free Download Manager
"{45CC4C9F-03B7-4C57-9EA2-BC598FC131BF}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"= c:\program files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [23/11/2008 15:48 114768]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [21/03/2008 13:34 269448]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [29/04/2009 04:07 176128]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [23/11/2008 15:48 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [23/11/2008 15:47 51792]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\System32\drivers\AtiHdmi.sys [24/04/2009 07:43 95544]
R3 NVHDA;Service for NVIDIA HDMI Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [21/03/2008 20:47 30752]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [25/09/2008 23:23 28224]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-eRecoveryService - (no file)
SafeBoot-procexp90.Sys
.
------- Examen supplémentaire -------
.
mStart Page = hxxp://fr.fr.acer.yahoo.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-08 21:10
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(960)
c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\System32\atieclxx.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\conime.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Heure de fin: 2009-06-08 21:13 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-08 19:13
Avant-CF: 60 326 322 176 octets libres
Après-CF: 60 176 441 344 octets libres
280 --- E O F --- 2009-06-08 11:48
ComboFix 09-06-07.07 - guilleux 08/06/2009 20:58.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.2106 [GMT 2:00]
Lancé depuis: c:\users\guilleux\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Performanceoptimizer (Free)
c:\program files\Performanceoptimizer (Free)\creader.exe
c:\program files\Performanceoptimizer (Free)\language.cfg
c:\program files\Performanceoptimizer (Free)\Language\English.ini
c:\program files\Performanceoptimizer (Free)\Language\English_po.ini
c:\program files\Performanceoptimizer (Free)\Language\English_spo.ini
c:\program files\Performanceoptimizer (Free)\Language\Franch.ini
c:\program files\Performanceoptimizer (Free)\Language\Franch_po.ini
c:\program files\Performanceoptimizer (Free)\Language\Franch_spo.ini
c:\program files\Performanceoptimizer (Free)\Language\German.ini
c:\program files\Performanceoptimizer (Free)\Language\German_po.ini
c:\program files\Performanceoptimizer (Free)\Language\German_spo.ini
c:\program files\Performanceoptimizer (Free)\Language\Spanish.ini
c:\program files\Performanceoptimizer (Free)\Language\Spanish_po.ini
c:\program files\Performanceoptimizer (Free)\Language\Spanish_spo.ini
c:\program files\Performanceoptimizer (Free)\MFC71.dll
c:\program files\Performanceoptimizer (Free)\msvcp71.dll
c:\program files\Performanceoptimizer (Free)\msvcr71.dll
c:\program files\Performanceoptimizer (Free)\pcid.exe
c:\program files\Performanceoptimizer (Free)\PerfOpt.exe.manifest
c:\program files\Performanceoptimizer (Free)\PerfOpt.sdb
c:\program files\Performanceoptimizer (Free)\po_cfg.ini
c:\program files\Performanceoptimizer (Free)\PoChk.exe.manifest
c:\program files\Performanceoptimizer (Free)\Tweaks\data001.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data003.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data006.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data007.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data009.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data011.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data013.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data016.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data017.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data020.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data023.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data027.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data030.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data031.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data033.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data040.reg
c:\program files\Performanceoptimizer (Free)\Tweaks\data042.reg
c:\program files\Performanceoptimizer (Free)\ua_manager.exe
c:\program files\Performanceoptimizer (Free)\uninstpo.exe
c:\program files\Performanceoptimizer (Free)\updater.exe.manifest
c:\users\guilleux\AppData\Roaming\.#
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-08 au 2009-06-08 ))))))))))))))))))))))))))))))))))))
.
2009-06-08 18:38 . 2009-06-08 18:38 -------- d-----w- \Qoobox
2009-06-07 18:40 . 2009-06-07 18:40 -------- d-----w- c:\program files\CCleaner
2009-06-07 16:35 . 2009-06-07 16:35 -------- d-----w- c:\progra~2\WindowsSearch
2009-06-07 14:51 . 2009-06-07 15:07 -------- d-----w- c:\program files\McAfee
2009-06-07 12:11 . 2009-06-07 14:18 -------- d-----w- c:\program files\trend micro
2009-06-07 12:11 . 2009-06-07 12:25 -------- d-----w- C:\rsit
2009-06-07 12:11 . 2009-06-07 12:25 -------- d-----w- \rsit
2009-06-07 11:38 . 2009-06-07 13:25 -------- d-----w- c:\program files\Navilog1
2009-06-07 11:11 . 2009-06-07 11:11 -------- d-----w- c:\program files\Zone Labs
2009-06-07 11:11 . 2009-06-07 11:11 -------- d-----w- c:\progra~2\CheckPoint
2009-06-07 11:09 . 2009-06-07 15:50 -------- d-----w- c:\windows\Internet Logs
2009-06-07 10:24 . 2009-06-07 16:38 -------- d-----w- c:\windows\BDOSCAN8
2009-06-07 09:35 . 2009-06-07 09:35 -------- d-----w- c:\users\guilleux\AppData\Roaming\Malwarebytes
2009-06-07 09:35 . 2009-06-07 09:35 -------- d-----w- c:\progra~2\Malwarebytes
2009-06-07 09:35 . 2009-06-07 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-07 09:15 . 2009-06-07 09:21 -------- d-----w- c:\users\guilleux\.housecall6.6
2009-06-07 09:14 . 2009-06-07 09:14 -------- d-----w- c:\program files\Java
2009-05-31 19:23 . 2009-05-31 19:23 -------- d-----w- c:\program files\QuickTime
2009-05-22 09:19 . 2009-05-22 09:19 -------- d-----w- c:\progra~2\ATI
2009-05-22 09:11 . 2009-05-22 09:11 10134 ----a-r- c:\users\guilleux\AppData\Roaming\Microsoft\Installer\{AA3DDA7B-A960-51C2-69C5-86F3AFB3E074}\ARPPRODUCTICON.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 19:06 . 2009-01-20 14:41 3220357120 --sha-w- \hiberfil.sys
2009-06-08 19:06 . 2008-04-29 20:31 3534041088 --sha-w- \pagefile.sys
2009-06-08 19:04 . 2008-12-24 23:47 -------- d-----w- c:\users\guilleux\AppData\Roaming\Free Download Manager
2009-06-08 18:49 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-08 18:49 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-07 18:20 . 2008-03-21 11:35 -------- d-----w- c:\program files\Acer GameZone
2009-06-07 17:32 . 2008-03-21 11:21 -------- d-----w- c:\program files\Common Files\LightScribe
2009-06-07 17:30 . 2008-12-24 23:47 -------- d-----w- c:\program files\Free Download Manager
2009-06-07 14:51 . 2008-03-21 11:50 -------- d-----w- c:\progra~2\McAfee
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-05-30 12:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-05-30 12:45 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-30 12:44 . 2008-04-29 20:34 -------- d-----w- c:\program files\ATI
2009-05-30 12:44 . 2008-09-24 18:45 -------- d-----w- c:\progra~2\Yahoo! Companion
2009-05-22 09:16 . 2008-04-29 20:34 -------- d-----w- c:\program files\ATI Technologies
2009-05-14 17:38 . 2008-09-24 17:45 -------- d-----w- c:\program files\Dofus
2009-05-14 01:03 . 2008-03-21 11:14 -------- d-----w- c:\progra~2\Microsoft Help
2009-05-08 01:09 . 2008-09-24 15:57 70104 ----a-w- c:\users\guilleux\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-07 20:22 . 2008-03-21 11:16 -------- d-----w- c:\program files\Microsoft Works
2009-05-05 17:20 . 2008-09-25 20:35 1356 ----a-w- c:\users\guilleux\AppData\Local\d3d9caps.dat
2009-05-02 22:38 . 2009-05-02 22:38 -------- d-----w- c:\users\guilleux\AppData\Roaming\vlc
2009-04-29 03:31 . 2009-04-29 03:31 4491776 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2009-04-29 02:08 . 2009-04-29 02:08 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-04-29 02:08 . 2009-04-29 02:08 303104 ----a-w- c:\windows\system32\atieclxx.exe
2009-04-29 02:07 . 2009-04-29 02:07 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2009-04-29 02:06 . 2006-04-09 06:33 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2009-04-29 02:06 . 2006-04-09 06:33 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2009-04-29 02:05 . 2009-04-29 02:05 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2009-04-29 02:05 . 2009-04-29 02:05 11776 ----a-w- c:\windows\system32\atimuixx.dll
2009-04-29 02:05 . 2006-04-09 06:33 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-04-29 02:02 . 2009-04-29 02:02 2428928 ----a-w- c:\windows\system32\atidxx32.dll
2009-04-29 01:52 . 2006-04-09 06:33 3082752 ----a-w- c:\windows\system32\atiumdag.dll
2009-04-29 01:41 . 2009-04-29 01:41 11559424 ----a-w- c:\windows\system32\atioglxx.dll
2009-04-29 01:37 . 2006-04-09 06:33 4963840 ----a-w- c:\windows\system32\atiumdva.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\atimpc32.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\amdpcom32.dll
2009-04-29 01:24 . 2009-04-29 01:24 163840 ----a-w- c:\windows\system32\atiadlxx.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalrt.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalcl.dll
2009-04-29 01:20 . 2009-04-29 01:20 3293184 ----a-w- c:\windows\system32\aticaldd.dll
2009-04-29 01:11 . 2009-04-29 01:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-04-28 18:53 . 2009-03-28 19:15 -------- d-----w- c:\program files\DofusBeta
2009-04-24 05:43 . 2009-04-24 05:43 95544 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
2009-04-14 17:00 . 2008-10-02 16:52 1624 ----a-w- c:\users\guilleux\AppData\Roaming\wklnhst.dat
2009-03-17 03:38 . 2009-04-16 03:09 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 03:09 24064 ----a-w- c:\windows\system32\amxread.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 22:38 121392 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-11-12 2474031]
"Google Update"="c:\users\guilleux\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-04-25 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-21 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-21 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-21 81920]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2008-01-09 326176]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2007-12-07 196128]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-28 61440]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2008-05-02 307200]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-10-11 4702208]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-3-21 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2103130941-1255188074-3532458092-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9A0FC0E6-C41A-491D-85B2-7B42B0C4D7B6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9272E7EA-E5B0-4E65-AA03-61B849992A79}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0590D135-20CF-4616-83A2-B4D64D7A7ADC}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{40F60C6C-DD8E-40B8-AB34-5061C567E010}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
"{EC714915-D3A6-43D3-B785-23155F4ED9A6}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
"{8FB6D042-3CF4-407D-A2E9-A1CE05C41456}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
"{542BA28B-703D-48DB-B83F-94E757E578BF}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
"{B34DAF09-668F-41FD-94EB-A7A892360F5C}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
"{A924C65E-76C0-4E34-9E09-9FC3F7E6691A}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
"{F051E17E-51EF-4830-B367-F6DA497077E5}"= c:\program files\Acer Arcade Live\Acer HomeMedia Trial Creator\Acer HomeMedia Trial Creator.exe:Acer HomeMedia Trial Creator
"{F158742F-48F9-4833-8369-7CBA8CC22457}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
"{D5CDD3AC-3A9B-4EAA-B42D-5B9FE17A148C}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{F859AB84-4B19-4649-BABF-C6A69475B7B4}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{659629A3-7D4E-4EC5-B3D6-9C2D20284F87}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{97AC95B8-F2CE-487E-BBDF-484936085F48}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{7A98BAAC-7796-4F71-8E7C-96AEB504DEC6}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{0E3A9A90-514B-43F0-9E07-44A8A4C93981}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{677E4415-9903-4D2D-9E59-76BEBC33147A}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{07ADF2D6-44B2-41D6-998C-EE7BB2DD1E1E}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{BA2C04C7-ADA2-418C-A251-BC301EA6F216}"= UDP:d:\programe files\DSLtest2007.exe:DSLtest2007
"{08D65637-16DF-4947-B256-7D9E2AED6CE1}"= TCP:d:\programe files\DSLtest2007.exe:DSLtest2007
"{9D963BBF-279A-4453-B031-D5FD45FF3D68}"= UDP:c:\program files\ESTsoft\ALShow\ALShow.exe:ALShow
"{DABA5295-7A1F-4B40-9F40-96FC70119AFD}"= TCP:c:\program files\ESTsoft\ALShow\ALShow.exe:ALShow
"{56A46C1D-C375-4B8B-B639-5449EA0887FE}"= UDP:c:\program files\SuperCopier2\SuperCopier2.exe:SuperCopier2
"{08B8DC5A-8D5C-4847-AD52-0A496BC691D9}"= TCP:c:\program files\SuperCopier2\SuperCopier2.exe:SuperCopier2
"TCP Query User{38782EEC-3CFE-4709-8AC0-2ABFEF27CB4F}c:\\program files\\orange\\browser\\browser.exe"= UDP:c:\program files\orange\browser\browser.exe:Browser
"UDP Query User{7326271B-DBEB-4AD7-A49E-E9B5D619A76F}c:\\program files\\orange\\browser\\browser.exe"= TCP:c:\program files\orange\browser\browser.exe:Browser
"{4ACF2D9E-A674-4CD8-8B66-4526A2594B3E}"= UDP:c:\program files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus
"{DC1A2892-BCB1-4562-B67F-E90772064405}"= TCP:c:\program files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus
"TCP Query User{1B320938-6B46-46C8-9426-017C47F124A5}c:\\users\\guilleux\\appdata\\roaming\\m\\flec006.exe"= UDP:c:\users\guilleux\appdata\roaming\m\flec006.exe:flec006.exe
"UDP Query User{8737D2E6-6CEE-4D81-8E3F-24AB19D14DF3}c:\\users\\guilleux\\appdata\\roaming\\m\\flec006.exe"= TCP:c:\users\guilleux\appdata\roaming\m\flec006.exe:flec006.exe
"TCP Query User{D41F5C61-8A72-4604-8F25-7D948D04B51B}c:\\windows\\system32\\wintems.exe"= UDP:c:\windows\system32\wintems.exe:wintems
"UDP Query User{E8D7DF14-D79E-420C-8B54-997B980F9216}c:\\windows\\system32\\wintems.exe"= TCP:c:\windows\system32\wintems.exe:wintems
"{45FC2FF8-D5C5-4AE4-B499-B8EB53F8CDF7}"= UDP:c:\program files\ESTsoft\ALShow\alupdate.exe:alupdate
"{E1D1A7FA-AE6E-4C71-82A7-9BE5D9E980AA}"= TCP:c:\program files\ESTsoft\ALShow\alupdate.exe:alupdate
"TCP Query User{F907567B-6168-4AEF-BE6A-0B2336FCD0CF}c:\\program files\\free download manager\\fdm.exe"= UDP:c:\program files\free download manager\fdm.exe:Free Download Manager
"UDP Query User{D58D5D66-5258-48CA-80C6-43F555109AA6}c:\\program files\\free download manager\\fdm.exe"= TCP:c:\program files\free download manager\fdm.exe:Free Download Manager
"{45CC4C9F-03B7-4C57-9EA2-BC598FC131BF}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"= c:\program files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [23/11/2008 15:48 114768]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [21/03/2008 13:34 269448]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [29/04/2009 04:07 176128]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [23/11/2008 15:48 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [23/11/2008 15:47 51792]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\System32\drivers\AtiHdmi.sys [24/04/2009 07:43 95544]
R3 NVHDA;Service for NVIDIA HDMI Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [21/03/2008 20:47 30752]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [25/09/2008 23:23 28224]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-eRecoveryService - (no file)
SafeBoot-procexp90.Sys
.
------- Examen supplémentaire -------
.
mStart Page = hxxp://fr.fr.acer.yahoo.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-08 21:10
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(960)
c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\System32\atieclxx.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\conime.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Heure de fin: 2009-06-08 21:13 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-08 19:13
Avant-CF: 60 326 322 176 octets libres
Après-CF: 60 176 441 344 octets libres
280 --- E O F --- 2009-06-08 11:48