bonjour
j'ai coché tt le reste sauf 3rd party j'espère que j'ai bien fait
voilà le résultat :
GMER 2.1.19357 -
http://www.gmer.net
Rootkit scan 2014-06-22 10:55:48
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 - \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.GJ00 596,17GB
Running: 052488yb.exe; Driver: C:\Users\mathieu\AppData\Local\Temp\pwdiifow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800035c1000 45 bytes [00, 00, 9E, 00, 55, 4E, 62, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800035c102f 29 bytes [00, 00, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
? C:\Windows\system32\tschannel.dll [452] entry point in ".rsrc" section 000007fef87e6894
.text C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe[2184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077031465 2 bytes [03, 77]
.text C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe[2184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770314bb 2 bytes [03, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077031465 2 bytes [03, 77]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770314bb 2 bytes [03, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe[3172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077031465 2 bytes [03, 77]
.text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe[3172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770314bb 2 bytes [03, 77]
.text ... * 2
? C:\Windows\system32\mssprxy.dll [3172] entry point in ".rdata" section 00000000719671e6
.text C:\Users\mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe[3912] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000077031465 2 bytes [03, 77]
.text C:\Users\mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe[3912] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000770314bb 2 bytes [03, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077031465 2 bytes [03, 77]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770314bb 2 bytes [03, 77]
.text ... * 2
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077031465 2 bytes [03, 77]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770314bb 2 bytes [03, 77]
.text ... * 2
? C:\Windows\system32\mssprxy.dll [5344] entry point in ".rdata" section 00000000719671e6
.text C:\Program Files (x86)\BitTorrent\BitTorrent.exe[4928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077031465 2 bytes [03, 77]
.text C:\Program Files (x86)\BitTorrent\BitTorrent.exe[4928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000770314bb 2 bytes [03, 77]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\svchost.exe [1128:800] 000007fef8585170
Thread C:\Windows\system32\WLANExt.exe [1212:1252] 000000018000b674
Thread C:\Windows\system32\WLANExt.exe [1212:1256] 000000018000b690
Thread C:\Windows\system32\WLANExt.exe [1212:1260] 000000018000b658
Thread C:\Windows\system32\WLANExt.exe [1212:1264] 0000000180022170
Thread C:\Windows\system32\WLANExt.exe [1212:1268] 000007fefa7e2f9c
Thread C:\Windows\System32\spoolsv.exe [1540:4868] 000007fef71110c8
Thread C:\Windows\System32\spoolsv.exe [1540:4876] 000007fef70d6144
Thread C:\Windows\System32\spoolsv.exe [1540:4880] 000007fef4065fd0
Thread C:\Windows\System32\spoolsv.exe [1540:4884] 000007fef7013438
Thread C:\Windows\System32\spoolsv.exe [1540:4888] 000007fef40663ec
Thread C:\Windows\System32\spoolsv.exe [1540:4896] 000007fef7785e5c
Thread C:\Windows\System32\spoolsv.exe [1540:4900] 000007fef7155074
Thread C:\Windows\system32\svchost.exe [1680:2076] 000007fef92d35c0
Thread C:\Windows\system32\svchost.exe [2500:2556] 000007fef8c57130
Thread C:\Windows\system32\svchost.exe [2500:2564] 000007fef8c4d5c0
Thread C:\Windows\system32\svchost.exe [2500:3660] 000007fef4065fd0
Thread C:\Windows\system32\svchost.exe [2500:5244] 000007fef7013438
Thread C:\Windows\system32\svchost.exe [2500:6060] 000007fef40663ec
Thread C:\Windows\system32\svchost.exe [3848:3476] 000007fefde8a808
---- Processes - GMER 2.1 ----
Library C:\Users\mathieu\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe [3912](2014-01-03 01:09:26) 0000000004080000
Library c:\users\mathieu\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfofp0h.dll (*** suspicious ***) @ C:\Users\mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe [3912](2014-06-21 04:34:57) 0000000005470000
Library C:\Users\mathieu\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe [3912](2013-08-23 19:01:44) 00000000698f0000
Library C:\Users\mathieu\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\mathieu\AppData\Roaming\Dropbox\bin\Dropbox.exe [3912] (ICU Data DLL/The ICU Project)(2013-08-23 19:01:42) 0000000068f60000
---- EOF - GMER 2.1 ----
merci