voila le log combofix
ComboFix 08-12-18.03 - Quentin 2008-12-20 11:13:55.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3070.1941 [GMT 1:00]
Lancé depuis: c:\users\Quentin\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Antivirus 2009
c:\program files\Antivirus 2009\av2009.exe
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\users\Quentin\AppData\Local\eisgaaq.dat
c:\users\Quentin\AppData\Local\eisgaaq.exe
c:\users\Quentin\AppData\Local\eisgaaq_nav.dat
c:\users\Quentin\AppData\Local\eisgaaq_navps.dat
c:\users\Quentin\AppData\Local\Microsoft\Windows\Temporary Internet Files\fbk.sts
c:\users\Quentin\AppData\Local\mwgwg.dat
c:\users\Quentin\AppData\Local\mwgwg.exe
c:\users\Quentin\AppData\Local\mwgwg_nav.dat
c:\users\Quentin\AppData\Local\mwgwg_navps.dat
c:\users\Quentin\AppData\Local\ssoueeo.dat
c:\users\Quentin\AppData\Local\ssoueeo_nav.dat
c:\users\Quentin\AppData\Local\ssoueeo_navps.dat
c:\users\Quentin\ctfmon.exe
c:\users\Quentin\smss.exe
c:\windows\system32\nsinet.exe
c:\windows\system32\nvs2.inf
c:\windows\system32\TDSSmbcb.dll
c:\windows\system32\TDSSrfpp.log
c:\windows\system32\TDSStmei.dll
c:\windows\system32\TDSSwqsc.dat
J:\Autorun.inf
----- BITS: Il y a peut-être des sites infectés -----
hxxp://www.datingnoon.com
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-20 au 2008-12-20 ))))))))))))))))))))))))))))))))))))
.
2008-12-20 10:22 . 2008-12-20 11:10 <REP> d-------- c:\users\All Users\Spybot - Search & Destroy
2008-12-20 10:22 . 2008-12-20 11:10 <REP> d-------- c:\programdata\Spybot - Search & Destroy
2008-12-20 10:22 . 2008-12-20 10:23 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-20 09:31 . 2008-12-20 09:31 537 --a------ c:\users\Quentin\981.bat
2008-12-20 09:31 . 2008-12-20 09:31 537 --a------ c:\users\Quentin\469.bat
2008-12-19 18:52 . 2008-12-19 19:00 <REP> d--hs---- c:\users\Quentin\Searched
2008-12-19 18:52 . 2008-12-19 18:52 537 --a------ c:\users\Quentin\278.bat
2008-12-19 07:48 . 2008-12-19 07:48 537 --a------ c:\users\Quentin\893.bat
2008-12-18 07:52 . 2008-12-18 07:52 537 --a------ c:\users\Quentin\373.bat
2008-12-18 07:17 . 2008-12-18 07:17 537 --a------ c:\users\Quentin\596.bat
2008-12-17 18:42 . 2008-12-17 18:42 537 --a------ c:\users\Quentin\634.bat
2008-12-17 14:28 . 2008-12-17 14:22 35 --a------ c:\windows\lmhos
2008-12-16 20:31 . 2008-12-16 20:24 0 --a------ c:\windows\lmhosts
2008-12-16 19:53 . 2008-12-18 07:52 38,400 --a------ c:\users\Quentin\rundll32.exe
2008-12-15 07:25 . 2008-12-20 09:30 488,448 --a------ c:\users\Quentin\msiexec.exe
2008-12-14 17:14 . 2008-12-14 17:14 705 --a------ C:\xohlv.exe
2008-12-14 17:13 . 2008-12-14 17:13 <REP> d-------- c:\windows\System32\whSLD02
2008-12-14 17:13 . 2008-12-14 17:13 <REP> d-------- c:\temp\REX81
2008-12-14 17:13 . 2008-12-14 17:13 15,000 --------- c:\windows\System32\jkse73hedfdgf.0ll
2008-12-14 17:13 . 2008-12-14 17:13 705 --a------ C:\uuyrv.exe
2008-12-14 17:13 . 2008-12-14 17:13 2 --a------ C:\104543478
2008-12-14 14:21 . 2008-12-14 14:21 <REP> d-------- c:\program files\Valve
2008-12-14 14:06 . 2008-12-14 14:06 <REP> d-------- c:\program files\Ares
2008-12-13 16:32 . 2008-12-13 16:32 <REP> d-------- c:\program files\AdVantage
2008-12-13 14:18 . 2008-12-13 14:18 <REP> d-------- c:\users\Quentin\AppData\Roaming\Webcammax
2008-12-13 14:18 . 2008-12-13 14:18 <REP> d-------- c:\users\All Users\Webcammax
2008-12-13 14:18 . 2008-12-13 14:18 <REP> d-------- c:\programdata\Webcammax
2008-12-13 14:16 . 2008-12-13 14:19 <REP> d-------- c:\program files\WebcamMax
2008-12-13 11:53 . 2008-12-13 12:11 <REP> d-------- c:\program files\SupraASCIIArt
2008-12-12 19:47 . 2008-12-12 19:47 <REP> d-------- c:\program files\VirtualDJ
2008-12-12 19:43 . 2008-12-14 17:27 <REP> d-------- c:\users\Quentin\AppData\Roaming\EoRezo
2008-12-11 07:00 . 2008-10-22 02:22 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-10 08:24 . 2008-10-21 06:25 296,960 --a------ c:\windows\System32\gdi32.dll
2008-12-10 08:23 . 2008-11-01 02:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-10 08:23 . 2008-10-29 07:29 2,927,104 --a------ c:\windows\explorer.exe
2008-12-10 08:23 . 2008-10-16 05:47 827,392 --a------ c:\windows\System32\wininet.dll
2008-12-10 08:23 . 2008-11-01 04:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-10 08:22 . 2008-06-23 02:59 2,868,736 --a------ c:\windows\System32\mf.dll
2008-12-10 08:22 . 2008-06-23 02:59 996,352 --a------ c:\windows\System32\WMNetMgr.dll
2008-12-10 08:22 . 2008-06-23 02:58 94,720 --a------ c:\windows\System32\logagent.exe
2008-12-07 19:49 . 2008-12-07 19:49 <REP> d-------- c:\program files\Common Files\Steam
2008-12-07 19:03 . 2008-12-07 19:03 69,632 ---hs---- c:\users\Quentin\winlogon.exe
2008-12-05 11:17 . 2008-12-20 11:21 0 --------- c:\windows\System32\Ikeext.etl
2008-11-30 15:45 . 2008-11-30 16:31 <REP> d-------- C:\Downloads
2008-11-30 15:42 . 2008-12-18 07:17 <REP> d-------- c:\users\Quentin\AppData\Roaming\Free Download Manager
2008-11-30 15:42 . 2008-11-30 16:32 <REP> d-------- c:\program files\Free Download Manager
2008-11-25 20:05 . 2008-10-22 04:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-25 20:04 . 2008-10-21 06:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-25 20:04 . 2008-08-28 04:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-25 20:04 . 2008-08-28 04:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-25 20:04 . 2008-08-28 04:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-23 07:59 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-23 07:59 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-23 07:59 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-23 07:59 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-23 07:59 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-23 07:59 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-23 07:59 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-23 07:59 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-23 07:59 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 06:32 --------- d-----w c:\users\Quentin\AppData\Roaming\FontCreator
2008-12-18 06:28 --------- d-----w c:\users\Quentin\AppData\Roaming\gtk-2.0
2008-12-18 06:24 --------- d-----w c:\users\Quentin\AppData\Roaming\Sony
2008-12-18 06:23 --------- d-----w c:\users\Quentin\AppData\Roaming\Yahoo!
2008-12-18 06:22 --------- d-----w c:\users\Quentin\AppData\Roaming\Notepad++
2008-12-18 06:21 --------- d-----w c:\users\Quentin\AppData\Roaming\CyberLink
2008-12-18 06:19 --------- d-----w c:\users\Quentin\AppData\Roaming\WinBatch
2008-12-18 06:19 --------- d-----w c:\users\Quentin\AppData\Roaming\vlc
2008-12-18 06:18 --------- d-----w c:\users\Quentin\AppData\Roaming\Template
2008-12-18 06:18 --------- d-----w c:\users\Quentin\AppData\Roaming\PSPDocMaker
2008-12-18 06:17 --------- d-----w c:\users\Quentin\AppData\Roaming\Media Center Programs
2008-12-18 06:16 --------- d-----w c:\users\Quentin\AppData\Roaming\WildTangent
2008-12-18 06:16 --------- d-----w c:\users\Quentin\AppData\Roaming\Symantec
2008-12-18 06:16 --------- d-----w c:\users\Quentin\AppData\Roaming\PlayFirst
2008-12-18 06:16 --------- d-----w c:\users\Quentin\AppData\Roaming\Hewlett-Packard
2008-12-18 06:16 --------- d-----w c:\users\Quentin\AppData\Roaming\F-Secure
2008-12-18 06:16 --------- d-----w c:\users\Quentin\AppData\Roaming\AVS4YOU
2008-12-11 06:11 --------- d-----w c:\program files\Windows Mail
2008-12-11 06:05 --------- d-----w c:\programdata\Microsoft Help
2008-12-07 19:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-19 13:31 --------- d-----w c:\program files\Red Kawa
2008-11-16 11:52 --------- d-----w c:\program files\Free Audio Pack
2008-11-16 11:32 --------- d-----w c:\program files\pspvc
2008-11-16 11:32 --------- d-----w c:\program files\AviSynth 2.5
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-29 13:27 --------- d-----w c:\users\Quentin\AppData\Roaming\Apple Computer
2008-10-29 13:26 --------- d-----w c:\programdata\Apple Computer
2008-10-29 13:26 --------- d-----w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-29 13:26 --------- d-----w c:\program files\iTunes
2008-10-29 13:26 --------- d-----w c:\program files\iPod
2008-10-29 13:26 --------- d-----w c:\program files\Bonjour
2008-10-29 13:25 --------- d-----w c:\program files\Common Files\Apple
2008-10-29 13:14 --------- d-----w c:\program files\QuickTime
2008-10-24 07:27 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-21 18:35 --------- d-----w c:\programdata\NVIDIA
2008-10-21 18:32 174 --sha-w c:\program files\desktop.ini
2008-10-21 18:22 --------- d-----w c:\program files\Windows Sidebar
2008-10-21 18:22 --------- d-----w c:\program files\Windows Photo Gallery
2008-10-21 18:22 --------- d-----w c:\program files\Windows Journal
2008-10-21 18:22 --------- d-----w c:\program files\Windows Defender
2008-10-21 18:22 --------- d-----w c:\program files\Windows Collaboration
2008-10-21 18:22 --------- d-----w c:\program files\Windows Calendar
2008-10-06 05:59 319,456 ----a-w c:\windows\DIFxAPI.dll
2008-10-06 05:59 315,392 ----a-w c:\windows\HideWin.exe
2008-07-18 07:13 0 ----a-w c:\users\Quentin\AppData\Roaming\wklnhst.dat
2008-07-11 17:21 22 --sha-w c:\windows\SMINST\HPCD.sys
2006-05-03 09:06 163,328 --sh--r c:\windows\System32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\System32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-01-18 942080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 495616]
"Windows Logon Applicationedc"="c:\users\Quentin\winlogon.exe" [2008-12-07 69632]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"MSServer"="c:\users\Quentin\AppData\Local\Temp\tuvVNEus.dll" [2008-12-20 51712]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-12 275800]
"VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
"F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2007-06-13 176177]
"F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2007-06-13 733184]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-10 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-10 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-10 88608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"WebcamMaxMoniter"="c:\program files\WebcamMax\wcmmon.exe" [2008-02-09 456024]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SoftwareHelper"="c:\users\Quentin\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe" [2008-12-09 368224]
c:\users\Quentin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 - Capture d'‚cran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"msacm.l3codecp"= l3codecp.acm
"vidc.xvid"= xvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{CAFFF5E4-4152-4EA0-B27B-CEF2CEB483D5}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{66352A5F-94CD-47D0-A21A-78184693C9B8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D4E12859-B8FA-4B87-9C0A-A01928A90E35}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DF156CF0-7387-438A-8903-FAABDEB7E09C}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{0489492B-9FCD-4F9D-8CC5-8ABB6333ACA6}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{4B05EB55-F415-46FB-96F6-C47BF4B51413}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{0B7458AC-7241-47D4-8E01-C3AA2A026945}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{58853E9F-3DC9-43AA-8F9E-80247EAEE66A}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{CEA788A5-F8CF-4D7A-8D57-596551EB9AD6}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5A06D53B-8470-4D3B-ADD4-0F2794AE0B35}"= UDP:80:ares
"{6D9B3251-85B7-4DFD-B440-72C614B8ED90}"= UDP:c:\program files\Ares\Ares.exe:Ares
"{A72F5AE5-7858-44D2-A705-743CEC41BC34}"= TCP:c:\program files\Ares\Ares.exe:Ares
"TCP Query User{3F6F210A-0F34-4123-B4F5-907BE8E66B7C}c:\\users\\quentin\\desktop\\psp2\\emule\\emule.exe"= UDP:c:\users\quentin\desktop\psp2\emule\emule.exe:emule.exe
"UDP Query User{E3F43825-A596-47E6-A25D-735038A2424B}c:\\users\\quentin\\desktop\\psp2\\emule\\emule.exe"= TCP:c:\users\quentin\desktop\psp2\emule\emule.exe:emule.exe
"TCP Query User{FBADBD36-8567-4828-8E8C-6346F4B98EC8}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{AE99AB2B-5F8C-4271-A363-BC85C5201AD1}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"TCP Query User{1CEDC229-331D-4508-8A02-7CA0B3A7BF8F}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{15F3B85A-F974-48D0-94BD-D80D30E260BC}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{40397A96-6E47-45A3-BF06-175AD6EBF0FB}c:\\counter-strike source lan edition\\hl2.exe"= UDP:c:\counter-strike source lan edition\hl2.exe:hl2
"UDP Query User{797F6FA2-9E4B-47C7-BD99-4F3E3CA93D81}c:\\counter-strike source lan edition\\hl2.exe"= TCP:c:\counter-strike source lan edition\hl2.exe:hl2
"{A25A8B8A-A6BE-43CC-B1BD-5FA51FE5D74F}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
"{3631E6FF-8FC5-4AFE-A047-2236E5B7420E}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
"{CC40287A-8DAE-4E05-A362-B8188C9EDDE0}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1DA3A9A4-BE3F-4B48-B041-9426A8C323C3}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4BCC911F-0F6C-4337-AC33-A4CF0723784A}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{C58C0A03-378F-48C0-904E-2799F2274213}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 F-Secure HIPS;F-Secure HIPS;\??\c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [2008-09-23 41184]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys [2008-09-23 28000]
R1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-09-23 60064]
R1 fsvista;F-Secure Vista Support Driver;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [2008-09-23 6144]
R2 CamthWDM;WebcamMax, WDM Video Capture;c:\windows\system32\DRIVERS\CamthWDM.sys [2008-02-09 941784]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [2008-09-23 52736]
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\c:\windows\System32\DRIVERS\ASPI32.sys [2008-07-17 84832]
S4 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\Win2K\FSfilter.sys [2008-09-23 33024]
S4 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\Orange\AntivirusFirewall\Anti-Virus\Win2K\FSrec.sys [2008-09-23 18432]
.
Contenu du dossier 'Tâches planifiées'
2008-12-20 c:\windows\Tasks\User_Feed_Synchronization-{EBF09023-D9B6-4443-9CF5-CDF99F227B13}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-mwgwg - c:\users\quentin\appdata\local\mwgwg.exe
HKCU-Run-Windows Logon - c:\users\Quentin\winlogin.exe
HKCU-Run-NVIDIA nView - c:\users\Quentin\nview.exe
HKCU-Run-eisgaaq - c:\users\quentin\appdata\local\eisgaaq.exe
HKCU-Run-xsjfn83jkemfofght - c:\users\Quentin\AppData\Local\Temp\winlogin.exe
HKCU-Run-cmds - c:\users\Quentin\AppData\Local\Temp\tuvVOFWq.dll
HKCU-Run-gadcom - c:\users\Quentin\AppData\Roaming\gadcom\gadcom.exe
HKCU-Run-Jnskdfmf9eldfd - c:\users\Quentin\AppData\Local\Temp\csrssc.exe
HKCU-Run-49338777649131267862487775833817 - c:\program files\Antivirus 2009\av2009.exe
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
HKLM-Run-EoEngine - (no file)
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-20 11:22:07
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(900)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'lsass.exe'(680)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'Explorer.exe'(1500)
c:\users\Quentin\AppData\Local\Temp\hrleudxl.dll
c:\users\Quentin\AppData\Local\Temp\geBqQICv.dll
- - - - - - - > 'csrss.exe'(572)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(628)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsgk32.exe
c:\program files\Orange\AntivirusFirewall\Common\FSMA32.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Orange\AntivirusFirewall\Common\FSMB32.EXE
c:\windows\System32\WUDFHost.exe
c:\program files\Orange\AntivirusFirewall\Common\FCH32.EXE
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
c:\program files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
c:\program files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
c:\program files\Orange\AntivirusFirewall\FWES\program\fsdfwd.exe
c:\windows\System32\conime.exe
c:\program files\Orange\AntivirusFirewall\FSAUA\program\fsus.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsav32.exe
c:\windows\System32\schtasks.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\jusched.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\hp\KBD\kbd.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\users\Quentin\smss.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Internet Explorer\ieuser.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Heure de fin: 2008-12-20 11:38:25 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-20 10:38:12
Avant-CF: 213 454 245 888 octets libres
Après-CF: 213,554,429,952 octets libres
334 --- E O F --- 2008-12-19 06:32:16