Voici le rapport. Désolé pour la fausse manip.
Dit-moi dédédétraqué; tu n'as pas dormi de la nuit ou vous êtes plusieurs a essayer de sauver la planète contre ces salles bete numérique ?
En tous les cas, merci beaucoup pour le temps que tu m'accorde. Voici donc le rapport :
"Jean Trawalter" - 2009-01-09 13:19:30 Service Pack 3
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Jean Trawalter\"
Command switches used :: ""C:\Documents and Settings\Jean Trawalter\Bureau\CFScript.txt""
((((((((((((((((((((((((((((((( Files Created from 2008-12-09 to 2009-01-09 ))))))))))))))))))))))))))))))))))
2009-01-09 11:32 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-01-09 11:32 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2009-01-09 11:32 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-09 10:12 49,152 --a------ C:\WINDOWS\nircmd.exe
2009-01-09 03:56 <REP> d-------- C:\Program Files\Ad-remover
2009-01-09 03:28 <REP> d-------- C:\WINDOWS\ERUNT
2009-01-09 03:28 <REP> d-------- C:\!FixIEDef
2009-01-09 03:06 <REP> d--h----- C:\autorun.inf
2009-01-09 02:48 <REP> d-------- C:\Program Files\UsbFix
2009-01-09 02:26 <REP> d-------- C:\rsit
2009-01-09 02:26 <REP> d-------- C:\Program Files\trend micro
2009-01-09 01:04 <REP> d-------- C:\Lop SD
2009-01-09 00:42 <REP> d-------- C:\Program Files\Windows Live Safety Center
2009-01-09 00:18 <REP> d-------- C:\WINDOWS\BDOSCAN8
2009-01-08 23:25 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2009-01-08 22:38 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-01-08 22:20 <REP> d-------- C:\JULIA_V_ALLEMANDE
2009-01-08 19:07 <REP> d-------- C:\DOCUME~1\JEANTR~1\APPLIC~1\Malwarebytes
2009-01-08 17:30 1,048,576 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2009-01-08 17:30 <REP> dr------- C:\DOCUME~1\ADMINI~1\Mes documents
2009-01-08 17:30 <REP> dr------- C:\DOCUME~1\ADMINI~1\Menu D‚marrer
2009-01-08 17:30 <REP> dr------- C:\DOCUME~1\ADMINI~1\Favoris
2009-01-08 17:30 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage r‚seau
2009-01-08 17:30 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage d'impression
2009-01-08 17:30 <REP> d--h----- C:\DOCUME~1\ADMINI~1\ModŠles
2009-01-08 17:30 <REP> d-------- C:\DOCUME~1\ADMINI~1\WINDOWS
2009-01-08 17:30 <REP> d-------- C:\DOCUME~1\ADMINI~1\Bureau
2009-01-08 17:30 <REP> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2009-01-08 16:24 <REP> d-------- C:\Program Files\a-squared Free
2009-01-04 20:55 9,341 --a------ C:\WINDOWS\system32\drivers\filedisk.sys
2009-01-04 20:55 74,703 --a------ C:\WINDOWS\system32\mfc45.dll
2009-01-04 20:55 <REP> d-------- C:\Program Files\iolo
2009-01-04 20:55 <REP> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\iolo
2009-01-04 20:53 <REP> d-------- C:\DOCUME~1\JEANTR~1\APPLIC~1\iolo
2009-01-04 20:53 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\iolo
2008-12-31 15:59 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TomTom
2008-12-31 15:58 <REP> d-------- C:\DOCUME~1\JEANTR~1\APPLIC~1\TomTom
2008-12-31 15:57 <REP> d-------- C:\Program Files\TomTom HOME 2
2008-12-29 11:11 <REP> d-------- C:\Program Files\Network Stumbler
2008-12-28 17:50 <REP> d-------- C:\Program Files\TomTom DesktopSuite
2008-12-23 20:44 <REP> d-------- C:\Program Files\Bonjour
2008-12-15 14:16 <REP> d-------- C:\Program Files\EasyPHP
2008-12-15 14:10 <REP> d-------- C:\DOCUME~1\JEANTR~1\APPLIC~1\PSpad
2008-12-15 14:09 <REP> d-------- C:\Program Files\PSPad editor
2008-12-13 18:07 <REP> d-------- C:\Program Files\PostgreSQL
2008-12-13 17:54 <REP> d-------- C:\DOCUME~1\JEANTR~1\APPLIC~1\postgresql
2008-12-13 17:30 <REP> d-------- C:\Documents and Settings\JEANTR~1\uDig
2008-12-13 17:30 <REP> d-------- C:\DOCUME~1\JEANTR~1\uDig
2008-12-13 17:30 <REP> d-------- C:\DOCUME~1\JEANTR~1\APPLIC~1\udig
2008-12-13 17:29 <REP> d-------- C:\Program Files\uDig
2008-12-13 15:47 524,288 --ah----- C:\DOCUME~1\postgres\NTUSER.DAT
2008-12-13 15:47 <REP> dr------- C:\DOCUME~1\postgres\Mes documents
2008-12-13 15:47 <REP> dr------- C:\DOCUME~1\postgres\Menu D‚marrer
2008-12-13 15:47 <REP> dr------- C:\DOCUME~1\postgres\Favoris
2008-12-13 15:47 <REP> d--h----- C:\DOCUME~1\postgres\Voisinage r‚seau
2008-12-13 15:47 <REP> d--h----- C:\DOCUME~1\postgres\Voisinage d'impression
2008-12-13 15:47 <REP> d--h----- C:\DOCUME~1\postgres\ModŠles
2008-12-13 15:47 <REP> d-------- C:\DOCUME~1\postgres\WINDOWS
2008-12-13 15:47 <REP> d-------- C:\DOCUME~1\postgres\Bureau
2008-12-13 15:47 <REP> d-------- C:\DOCUME~1\postgres\APPLIC~1\Symantec
2008-12-12 11:18 87,336 --a------ C:\WINDOWS\system32\dns-sd.exe
2008-12-12 11:11 61,440 --a------ C:\WINDOWS\system32\dnssd.dll
2008-12-09 18:15 <REP> d-------- C:\Program Files\CCleaner
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2009-01-09 09:16:09 -------- d-----w C:\Program Files\Mozilla Thunderbird
2009-01-09 01:47:02 -------- d-----w C:\DOCUME~1\JEANTR~1\APPLIC~1\U3
2009-01-07 10:41:46 -------- d-----w C:\DOCUME~1\JEANTR~1\APPLIC~1\OpenOffice.org2
2009-01-06 12:16:29 410,984 ----a-w C:\WINDOWS\system32\deploytk.dll
2008-12-26 22:57:44 -------- d-----w C:\Program Files\The GodFather
2008-12-09 17:42:20 -------- d-----w C:\DOCUME~1\JEANTR~1\APPLIC~1\Autodesk
2008-12-09 17:34:53 26 ----a-w C:\AUTOEXEC.BAT
2008-12-07 16:24:05 -------- d-----w C:\Program Files\eMule
2008-12-04 20:25:23 -------- d-----w C:\Program Files\Fichiers communs\Autodesk Shared
2008-12-04 20:23:21 -------- d-----w C:\Program Files\AutoCAD 2009
2008-12-04 17:07:20 -------- d-----w C:\DOCUME~1\JEANTR~1\APPLIC~1\AdobeUM
2008-12-03 19:08:24 -------- d-----w C:\Program Files\Autodesk
2008-12-01 22:20:59 -------- d-----w C:\Program Files\TimeCore
2008-11-23 22:58:21 -------- d-----w C:\Program Files\VobSub
2008-11-23 20:17:29 -------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-11-22 21:41:55 -------- d-----w C:\Program Files\DivX
2008-11-22 16:13:29 -------- d-----w C:\DOCUME~1\JEANTR~1\APPLIC~1\Logitech
2008-11-22 16:10:02 -------- d-----w C:\Program Files\Fichiers communs\Logitech
2008-11-22 16:08:51 -------- d-----w C:\Program Files\Logitech
2008-11-22 16:08:50 -------- d--h--w C:\Program Files\InstallShield Installation Information
2008-11-22 15:36:07 -------- d-----w C:\Program Files\Avira
2008-11-22 15:30:16 -------- d-----w C:\Program Files\QuickZip4
2008-11-21 18:03:57 -------- d-----w C:\Program Files\iTunes
2008-11-21 18:03:25 -------- d-----w C:\Program Files\iPod
2008-11-21 18:03:25 -------- d-----w C:\Program Files\Fichiers communs\Apple
2008-11-21 17:59:23 -------- d-----w C:\Program Files\QuickTime
2008-11-21 17:57:15 -------- d-----w C:\Program Files\Apple Software Update
2008-11-21 17:42:47 -------- d-----w C:\Program Files\Free Audio Pack
2008-11-20 20:49:11 -------- d-----w C:\Program Files\SiS VGA Utilities V3.84
2008-11-20 20:49:05 -------- d-----w C:\Program Files\sisagp
2008-11-20 19:11:33 -------- d-----w C:\Program Files\PowerStrip
2008-11-20 19:08:37 -------- d-----w C:\Program Files\SiS VGA Utilities V3.65g
2008-11-20 18:49:31 85,256 ----a-w C:\WINDOWS\system32\perfc00C.dat
2008-11-20 18:49:31 511,392 ----a-w C:\WINDOWS\system32\perfh00C.dat
2008-11-20 18:34:32 -------- d-----w C:\Program Files\Asus
2008-11-20 17:34:50 -------- d-----w C:\Program Files\Messenger
2008-11-20 17:29:29 -------- d-----w C:\Program Files\Movie Maker
2008-11-20 17:22:07 -------- d-----w C:\Program Files\Windows NT
2008-11-20 17:10:25 -------- d-----w C:\Program Files\audible
2008-10-28 22:36:00 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-10-28 22:36:00 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-10-28 22:35:58 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-10-28 22:35:58 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-10-28 22:35:56 684,032 ----a-w C:\WINDOWS\system32\DivX.dll
2008-10-23 12:36:51 286,720 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-10-16 13:13:40 202,776 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-10-16 13:13:40 1,809,944 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-10-16 13:12:22 323,608 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-10-16 13:12:20 561,688 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-10-16 13:09:44 92,696 ----a-w C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09:44 51,224 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-10-16 13:09:44 43,544 ----a-w C:\WINDOWS\system32\wups2.dll
2008-10-16 13:08:58 34,328 ----a-w C:\WINDOWS\system32\wups.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-12-17 23:22]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-06 13:16]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2008-11-20 19:50]
{DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-06 13:16]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}=C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-06 13:16]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" []
"NB Probe"="C:\Program Files\ASUS\NB Probe\NBProbe.exe" [2005-06-09 10:50]
"RemoteControl"="C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 19:24]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2004-09-21 15:55]
"CTCheck"="C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 10:08]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 13:53]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-11-19 22:26]
"SiSPower"="SiSPower.dll" [2008-03-20 18:58 C:\WINDOWS\system32\SiSPower.dll]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 14:16]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-11-04 10:30]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-11-20 13:20]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" []
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" []
"@"="" []
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 02:08]
"EasyPHP"="C:\Program Files\EasyPHP\EasyPHP.exe" [2006-11-19 22:16]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-01-06 13:16]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [2007-01-01 14:31]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 10:03]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 03:33]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 11:12]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-12-17 23:23]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
%SystemRoot%\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=acaptuser32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
C:\Program Files\eMule\emule.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Instafinder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboTask]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
napagent
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe
Contents of the 'Scheduled Tasks' folder
2009-01-06 19:43:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-09 13:21:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs = acaptuser32.dll??
scanning hidden files ...
disk error: C:\WINDOWS\
please note that you need administrator rights to perform deep scan
********************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\JavaQuickStarterService]
"ImagePath"="\"C:\Program Files\Java\jre6\bin\jqs.exe\" -service -config \"C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf\""
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSrfdc.sys"
Completion time: 2009-01-09 13:23:02
C:\ComboFix2.txt ... 2009-01-09 13:18
C:\ComboFix3.txt ... 2009-01-09 13:01
--- E O F ---