Non c bon j'ai reussi parcontre je n'ai pas désactivé mon antivirus c'est grave? je te donne mon rapport :
ComboFix 08-05-21.2 - hp 2008-05-22 19:40:04.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.138 [GMT 2:00]
Endroit: C:\Users\hp\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-22 to 2008-05-22 ))))))))))))))))))))))))))))))))))))
.
2008-05-22 18:57 . 2008-05-22 19:38 <REP> d-------- C:\327882R2FWJFW
2008-05-22 13:05 . 2008-05-22 13:05 <REP> d-------- C:\Users\hp\AppData\Roaming\Malwarebytes
2008-05-22 13:05 . 2008-05-22 13:05 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-05-22 13:05 . 2008-05-22 13:05 <REP> d-------- C:\ProgramData\Malwarebytes
2008-05-22 13:05 . 2008-05-22 13:05 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-22 13:05 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-22 13:05 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-21 22:20 . 2008-05-22 18:35 <REP> d-------- C:\Program Files\Navilog1
2008-05-21 22:00 . 2008-05-21 22:00 <REP> d-------- C:\Program Files\Trend Micro
2008-05-21 19:41 . 2008-05-21 19:50 <REP> d-------- C:\Users\All Users\Lavasoft
2008-05-21 19:41 . 2008-05-21 19:50 <REP> d-------- C:\ProgramData\Lavasoft
2008-05-21 19:41 . 2008-05-21 19:41 <REP> d-------- C:\Program Files\Lavasoft
2008-05-21 12:56 . 2008-05-21 12:56 <REP> d-------- C:\Users\All Users\WindowsSearch
2008-05-21 12:56 . 2008-05-21 12:56 <REP> d-------- C:\ProgramData\WindowsSearch
2008-05-20 19:09 . 2008-05-21 21:16 <REP> d-------- C:\Program Files\Norton Security Scan
2008-05-20 18:55 . 2008-05-20 19:03 <REP> d-------- C:\Windows\System32\Adobe
2008-05-16 19:08 . 2008-05-16 19:08 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-15 08:56 . 2008-05-15 08:56 <REP> d-------- C:\PerfLogs
2008-05-15 08:02 . 2008-01-19 09:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-05-15 08:01 . 2008-01-19 09:32 5,714,432 --a------ C:\Windows\System32\logon.scr
2008-05-15 08:00 . 2008-01-19 08:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-05-15 07:59 . 2008-01-19 09:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-05-15 07:59 . 2008-01-19 09:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-05-15 07:59 . 2008-01-19 09:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-05-15 07:59 . 2008-01-19 09:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-05-15 07:59 . 2008-01-19 09:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-05-15 07:59 . 2008-01-19 09:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-05-15 07:59 . 2008-01-19 09:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-05-15 07:59 . 2008-01-19 09:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-05-15 07:59 . 2008-01-19 09:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-05-15 07:59 . 2006-11-02 11:39 6,656 --a------ C:\Windows\System32\kbd106.dll
2008-05-12 21:34 . 2008-05-12 21:34 <REP> d-------- C:\Users\hp\AppData\Roaming\eMule
2008-05-12 21:34 . 2008-05-12 21:34 <REP> d-------- C:\Program Files\eMule2
2008-05-10 22:24 . 2008-05-10 22:24 <REP> d-------- C:\Users\hp\AppData\Roaming\dvdcss
2008-05-07 21:02 . 2008-05-07 21:41 <REP> d-------- C:\Users\hp\AppData\Roaming\U3
2008-05-04 12:43 . 2008-05-04 13:27 148,067 --a------ C:\Windows\hpoins12.dat
2008-05-04 12:43 . 2007-01-22 18:05 1,470 --------- C:\Windows\hpomdl12.dat
2008-05-01 22:23 . 2008-05-01 22:23 <REP> d-------- C:\GenProc
2008-05-01 21:54 . 2008-05-01 21:54 <REP> d-------- C:\Program Files\MSNFix
2008-05-01 21:45 . 1996-08-20 20:37 15,840 --a------ C:\Windows\System32\Machnm1.exe
2008-05-01 21:45 . 2005-09-25 16:37 5,632 --a------ C:\Windows\System32\Machnm64.sys
2008-05-01 21:45 . 2008-05-01 21:45 3,120 --a------ C:\Windows\System32\118290.54
2008-05-01 21:45 . 2008-05-01 21:45 3,120 --a------ C:\Windows\118294.78
2008-05-01 21:45 . 2003-08-13 00:27 2,304 --a------ C:\Windows\System32\Machnm32.sys
2008-05-01 21:31 . 2008-05-01 21:31 <REP> d-------- C:\MSNFix
2008-04-22 22:09 . 2008-04-22 23:18 <REP> d-------- C:\Program Files\YesMessenger
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 17:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-22 17:13 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-05-20 10:20 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-19 07:57 --------- d-----w C:\Program Files\AskTBar
2008-05-18 14:38 --------- d-----w C:\Program Files\Macrogaming
2008-05-15 07:10 174 --sha-w C:\Program Files\desktop.ini
2008-05-15 06:59 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-15 06:59 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-05-15 06:59 --------- d-----w C:\Program Files\Windows Mail
2008-05-15 06:59 --------- d-----w C:\Program Files\Windows Journal
2008-05-15 06:59 --------- d-----w C:\Program Files\Windows Defender
2008-05-15 06:59 --------- d-----w C:\Program Files\Windows Collaboration
2008-05-15 06:59 --------- d-----w C:\Program Files\Windows Calendar
2008-05-14 22:22 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-10 20:15 --------- d-----w C:\ProgramData\Roxio
2008-05-04 17:21 --------- d-----w C:\Users\hp\AppData\Roaming\Image Zone Express
2008-05-04 11:12 --------- d-----w C:\ProgramData\HP
2008-05-02 10:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 21:13 --------- d-----w C:\Program Files\Windows Live
2008-05-01 20:59 --------- d-----w C:\ProgramData\WLInstaller
2008-05-01 20:43 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-18 20:01 158 ----a-w C:\Users\hp\AppData\Roaming\wklnhst.dat
2008-04-18 19:06 --------- d-----w C:\Users\hp\AppData\Roaming\Template
2008-04-18 12:05 --------- d-----w C:\Program Files\HP
2008-04-18 11:54 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-04-07 13:41 --------- d-----w C:\Users\hp\AppData\Roaming\MSN Pictures Displayer
2008-04-07 12:26 --------- d-----w C:\Program Files\MioNet
2008-03-29 11:38 --------- d-----w C:\Program Files\Realtek
2008-03-28 19:29 --------- d-----w C:\Program Files\Yahoo!
2008-03-28 19:27 --------- d-----w C:\Program Files\Gamenext
2008-03-28 19:26 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-03-28 19:26 --------- d-----w C:\Program Files\AVS4YOU
2008-03-27 21:57 --------- d-----w C:\Program Files\Common Files\Nero
2008-03-27 21:56 --------- d-----w C:\ProgramData\Nero
2008-03-25 07:06 --------- d-----w C:\ProgramData\Symantec
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-10-14 19:09 103712]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [ ]
"eMuleAutoStart"="C:\Program Files\eMule2\emule.exe" [2008-05-11 13:19 5423104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 09:38 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 15:42 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 18:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 12:59 118784]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 22:52 49152]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 15:59 115816]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-10-14 19:09 103712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SPC500NC_Monitor"="C:\Windows\Philips\SPC500NC\Monitor.exe" [2006-11-03 12:01 319488]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 21:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 21:15 8466432]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 21:15 81920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MSN Pictures Displayer.lnk - C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe [2008-01-06 15:41:11 4571136]
OneNote 2007 - Capture d'‚cran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 05:45:42 101784]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
VPro500.lnk - C:\Windows\VPro500.exe [2007-11-23 20:23:41 470016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2649675A-7430-407B-B844-0C265CC2C0F3}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{22506DA6-A719-4A9D-B25B-5328BB97F7B2}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{68ACED22-B62C-410C-A477-B4160360842D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D52A4132-4A82-4CF5-A9BE-AD01BD83459F}"= UDP:4661:emule
"{A59B0A52-C3EF-41F9-9021-A71C0AA6FC90}"= TCP:4671:emule
"{590D6EA1-D37F-4F0D-897A-D467C7FC0AB2}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{EDA2302A-91FB-426F-9B60-B3D60607B245}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{0B431E76-3B97-4A39-A7FD-81EFDD5A28AA}"= UDP:4661:emule TCP
"{0219F4F8-7B35-462E-9BCB-E892514777EF}"= TCP:4671:emule UDP
"TCP Query User{AF0C1D35-8EA3-4985-B714-AB3DA2F5749C}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{FD2A4235-4B7A-4EDC-8FE7-4EAB981A53EF}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{3319604A-70CF-48D2-A1BA-8153DB0FB12E}C:\\program files\\emule2\\emule.exe"= UDP:C:\program files\emule2\emule.exe:eMule
"UDP Query User{19BE8452-8CB9-49BB-815F-384BB7BA7EA3}C:\\program files\\emule2\\emule.exe"= TCP:C:\program files\emule2\emule.exe:eMule
"{66A2F6DC-D1E8-4D4A-862C-FC4FD54C4CE7}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{54B0C7C5-C3C1-41A2-8E83-24133653DB0F}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{30196C97-B7FA-4EB2-8D84-01052A14D7F9}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080116.003\IDSvix86.sys [2007-11-06 18:28]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2007-08-31 14:54]
R3 SPC500NC;SPC 500NC Laptop Camera;C:\Windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 18:14]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 14:39]
S3 SPC610NC;Philips SPC500NC Webcam;C:\Windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 18:14]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{104fced8-c739-11dc-8d08-001bfcb58507}]
\shell\AutoRun\command - K:\LaunchU3.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-19 19:29:34 C:\Windows\Tasks\Norton Internet Security - Analyse système complète - hp.job"
- c:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-05-21 16:40:40 C:\Windows\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2008-05-22 16:50:24 C:\Windows\Tasks\User_Feed_Synchronization-{4E927033-2FBE-4A7F-A1AF-5D52D20C0008}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-22 19:45:32
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-22 19:49:28
ComboFix-quarantined-files.txt 2008-05-22 17:49:19
Pre-Run: 256,780,316,672 octets libres
Post-Run: 257,018,589,184 octets libres
198 --- E O F --- 2008-05-21 06:07:23