Finalement ca a marché voici le scan :
ComboFix 08-09-14.06 - hervé 2008-09-15 18:17:47.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.1.1036.18.2433 [GMT 2:00]
Lancé depuis: C:\Users\hervé\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-15 au 2008-09-15 ))))))))))))))))))))))))))))))))))))
.
2008-09-15 16:58 . 2008-09-15 16:58 <REP> d-------- C:\Users\hervé\AppData\Roaming\Malwarebytes
2008-09-15 16:58 . 2008-09-15 16:58 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-09-15 16:58 . 2008-09-15 16:58 <REP> d-------- C:\ProgramData\Malwarebytes
2008-09-15 16:58 . 2008-09-15 16:58 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-15 16:58 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-09-15 16:58 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
2008-09-15 16:49 . 2008-09-15 16:49 <REP> d-------- C:\Program Files\Trend Micro
2008-09-14 14:51 . 2008-09-13 12:02 90,112 --------- C:\Windows\System32\trzE31F.tmp
2008-09-13 12:03 . 2008-09-13 12:03 <REP> d-------- C:\Program Files\csiuhj
2008-09-13 12:02 . 2008-09-14 14:51 <REP> d-------- C:\Users\All Users\odgvelkf
2008-09-13 12:02 . 2008-09-14 14:51 <REP> d-------- C:\ProgramData\odgvelkf
2008-09-11 21:25 . 2008-09-11 21:26 <REP> d-------- C:\Users\hervé\AppData\Roaming\SPORE
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Videos
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Searches
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Saved Games
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Pictures
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Music
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Links
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Downloads
2008-09-11 21:21 . 2008-09-11 21:21 <REP> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-09-11 21:21 . 2008-09-11 21:21 1,878 --a------ C:\Windows\System32\ealregsnapshot1.reg
2008-09-11 21:02 . 2008-09-11 21:22 <REP> d-------- C:\Program Files\Electronic Arts
2008-09-09 21:49 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-09 21:49 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
2008-09-09 21:48 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-09 21:48 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
2008-09-09 21:48 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
2008-09-09 21:48 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-09 21:48 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-09-09 21:48 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll
2008-09-09 21:48 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll
2008-09-04 09:41 . 2008-07-19 07:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
2008-09-04 09:41 . 2008-07-19 05:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
2008-09-04 09:41 . 2008-07-19 07:09 563,912 --a------ C:\Windows\System32\wuapi.dll
2008-09-04 09:41 . 2008-07-19 05:44 83,456 --a------ C:\Windows\System32\wudriver.dll
2008-09-04 09:41 . 2008-07-19 07:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
2008-09-04 09:41 . 2008-07-19 07:10 45,768 --a------ C:\Windows\System32\wups2.dll
2008-09-04 09:41 . 2008-07-19 07:10 36,552 --a------ C:\Windows\System32\wups.dll
2008-09-04 09:40 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
2008-09-04 09:40 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-08-28 18:35 . 2008-08-28 18:35 <REP> d-------- C:\Program Files\GameSpy
2008-08-28 18:33 . 2008-08-28 18:33 <REP> d-------- C:\Windows\System32\URTTEMP
2008-08-28 18:31 . 2008-07-11 17:09 107,840 --a------ C:\Windows\System32\GameuxInstallHelper.dll
2008-08-28 18:31 . 2007-04-04 18:53 44,904 --a------ C:\Windows\System32\FirewallInstallHelper.dll
2008-08-28 18:18 . 2008-08-28 18:18 <REP> d-------- C:\Program Files\SEGA
2008-08-28 17:25 . 2008-08-28 17:25 1,830,037 --a------ C:\Windows\screensaver1_1024x768.scr
2008-08-28 17:25 . 2008-08-28 17:25 11 --a------ C:\Windows\wanpatan.ini
2008-08-28 17:24 . 2008-08-28 17:24 2,601,011 --a------ C:\Windows\screensaver2_1024x768.scr
2008-08-22 16:22 . 2008-08-22 16:22 <REP> d-------- C:\Users\hervé\AppData\Roaming\Microsoft Games
2008-08-22 16:22 . 2008-08-22 16:22 <REP> d-------- C:\Users\All Users\Microsoft Games
2008-08-22 16:22 . 2008-08-22 16:22 <REP> d-------- C:\ProgramData\Microsoft Games
2008-08-21 15:44 . 2008-08-21 15:44 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-08-20 13:32 . 2008-08-20 13:32 <REP> d-------- C:\Users\hervé\AppData\Roaming\Summer Athletics 2008
2008-08-17 22:51 . 2008-08-17 22:51 <REP> d-------- C:\Program Files\Apple Software Update
2008-08-17 22:50 . 2008-08-17 22:50 <REP> d-------- C:\Program Files\iTunes
2008-08-17 22:50 . 2008-08-17 22:50 <REP> d-------- C:\Program Files\iPod
2008-08-17 22:48 . 2008-08-17 22:48 <REP> d-------- C:\Program Files\Bonjour
2008-08-17 22:47 . 2008-08-17 22:48 <REP> d-------- C:\Program Files\QuickTime
2008-08-15 00:34 . 2008-07-16 03:32 2,048 --a------ C:\Windows\System32\tzres.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 16:18 2,621,440 --sha-w C:\Users\hervé\NTUSER.DAT
2008-09-15 16:18 2,621,440 --sha-w C:\Users\hervé\NTUSER.DAT
2008-09-15 15:43 --------- d-----w C:\Users\hervé\AppData\Roaming\OpenOffice.org2
2008-09-15 14:58 --------- d-----w C:\Users\hervé\AppData\Roaming\Malwarebytes
2008-09-15 14:22 --------- d-s---w C:\Users\hervé\AppData\Roaming\Microsoft
2008-09-14 11:30 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-09-11 19:26 --------- d-----w C:\Users\hervé\AppData\Roaming\SPORE
2008-09-11 19:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-11 19:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-30 10:06 --------- d-----w C:\ProgramData\Soulseek
2008-08-22 14:22 --------- d-----w C:\Users\hervé\AppData\Roaming\Microsoft Games
2008-08-20 23:39 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-20 11:32 --------- d-----w C:\Users\hervé\AppData\Roaming\Summer Athletics 2008
2008-08-17 20:41 --------- d-----w C:\Program Files\Safari
2008-08-14 22:32 --------- d-----w C:\Program Files\Windows Mail
2008-08-10 23:10 --------- d-----w C:\Users\hervé\AppData\Roaming\Apple Computer
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-27 15:12 --------- d-----w C:\Users\hervé\AppData\Roaming\CamfrogWEB
2008-07-27 15:03 --------- d-----w C:\Program Files\CFWebAdvancedU
2008-07-23 20:35 --------- d-----w C:\Users\hervé\AppData\Roaming\Sports Interactive
2008-07-23 20:34 --------- d--h--w C:\Program Files\Zero G Registry
2008-07-22 18:32 32,000 ----a-w C:\Windows\system32\drivers\usbaapl.sys
2008-07-21 19:24 --------- d-----w C:\Users\hervé\AppData\Roaming\temp
2008-07-21 17:30 --------- d-----w C:\ProgramData\NVIDIA
2008-07-21 17:27 174 --sha-w C:\Program Files\desktop.ini
2008-07-21 17:20 --------- d-----w C:\Program Files\Windows Sidebar
2008-07-21 17:20 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-07-21 17:20 --------- d-----w C:\Program Files\Windows Defender
2008-07-21 17:20 --------- d-----w C:\Program Files\Windows Collaboration
2008-07-21 17:20 --------- d-----w C:\Program Files\Windows Calendar
2008-07-21 17:05 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-07-21 17:05 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-07-19 14:36 51,280 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-19 03:31 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"TomTomHOME.exe"="D:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-05-06 202088]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 C:\Windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="C:\Windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"snpstd"="C:\Windows\vsnpstd.exe" [2003-12-31 40960]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 81920]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 C:\Windows\RtHDVCpl.exe]
C:\Users\herv‚\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"cmdcom"= {740DF498-8757-3867-8355-0BCB7D320181} - C:\Program Files\csiuhj\cmdcom.dll [2008-09-13 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VP40"= vp4vfw.dll
"midi2"= ma_cmidn.dll
"midi1"= ma_cmidn.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{21FFDE7E-16A4-4E5F-A112-CB5E6D07F0F5}E:\\soulseek\\slsk.exe"= UDP:E:\soulseek\slsk.exe:SoulSeek
"UDP Query User{576DADFC-90A3-4476-BEFA-87FDEA93CB94}E:\\soulseek\\slsk.exe"= TCP:E:\soulseek\slsk.exe:SoulSeek
"{E76191EF-86E8-4C10-8F69-173EA3923342}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{6BBF690A-C216-46B0-9D02-D3A99A019F4F}X:\\program files\\anno 1701\\anno1701.exe"= UDP:X:\program files\anno 1701\anno1701.exe:anno1701.exe
"UDP Query User{6DD502B9-B5F4-478B-99A6-403E655B3542}X:\\program files\\anno 1701\\anno1701.exe"= TCP:X:\program files\anno 1701\anno1701.exe:anno1701.exe
"TCP Query User{08A26F4E-F210-4F86-92C7-4C8E1AF12581}D:\\program files\\wdgold lite\\wdgold lite.exe"= UDP:D:\program files\wdgold lite\wdgold lite.exe:Gestion des contacts
"UDP Query User{E48810DE-A77E-4FD1-8B53-59A0F1C231CB}D:\\program files\\wdgold lite\\wdgold lite.exe"= TCP:D:\program files\wdgold lite\wdgold lite.exe:Gestion des contacts
"TCP Query User{AE740CE1-E044-4306-A1B8-3D66BAD99D5D}E:\\soulseek\\soulseekns\\slsk.exe"= UDP:E:\soulseek\soulseekns\slsk.exe:SoulSeek
"UDP Query User{3D7CA31B-5B0E-4F12-A104-D0F8D4CB3592}E:\\soulseek\\soulseekns\\slsk.exe"= TCP:E:\soulseek\soulseekns\slsk.exe:SoulSeek
"TCP Query User{0E80828A-0D81-4A74-B08F-0E72CAC9F4C9}C:\\program files\\soulseek\\slsk.exe"= UDP:C:\program files\soulseek\slsk.exe:SoulSeek
"UDP Query User{1E823DAF-AA7A-4BEF-9E84-A657065C7E90}C:\\program files\\soulseek\\slsk.exe"= TCP:C:\program files\soulseek\slsk.exe:SoulSeek
"{12A7332C-14D7-4236-8879-3256E1AF1859}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{59813BD3-4887-416B-B793-CD4205C8E1ED}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{04680EB2-7B16-4615-B88A-6A5292BBDDE9}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{80E312ED-AC77-4911-AD27-5E7EDFAC10E2}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{325867DD-0458-42D9-89BA-185F20F2B265}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{728766F0-1689-4F63-B834-57777EA83FC8}"= UDP:C:\Program Files\SEGA\Beijing 2008\Beijing.exe:Beijing 2008
"{FFD0FAC4-6934-4D3B-9039-5BA8526BA341}"= TCP:C:\Program Files\SEGA\Beijing 2008\Beijing.exe:Beijing 2008
"TCP Query User{095BA105-E853-467B-A314-344484B9F502}C:\\program files\\electronic arts\\eadm\\core.exe"= UDP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{047E0578-4754-4BC3-8719-48DD25F17667}C:\\program files\\electronic arts\\eadm\\core.exe"= TCP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
R2 X4HSX32Ex;X4HSX32Ex;C:\Program Files\Player Metaboli\X4HSX32Ex.Sys [2007-11-14 29856]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\Windows\system32\DRIVERS\atl01v32.sys [2007-03-15 48128]
S3 MA_CMIDI;M-Audio USB Driver;C:\Windows\system32\drivers\ma_cmidi.sys [2006-08-16 21888]
S3 Service CANALPLAY;Service CANALPLAY;C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe [2007-11-29 431776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38f0a066-dbb6-11dc-93b3-806e6f6e6963}]
\shell\AutoRun\command - D:\.\Bin\Assetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c38737ee-dbc9-11dc-adf5-001e8c1c873d}]
\shell\AutoRun\command - F:\autorun.exe readme.hta
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce41392c-4145-11dd-87ee-001e8c1c873d}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-CanalPlayerHelper - C:\Program Files\Lecteur CANALPLAY\CanalPlayerHelper.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Users\hervé\AppData\Roaming\Mozilla\Firefox\Profiles\hhtk83t9.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 18:19:41
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-09-15 18:20:36
ComboFix-quarantined-files.txt 2008-09-15 16:20:17
Avant-CF: 3,601,948,672 octets libres
AprŠs-CF: 3,532,132,352 octets libres
208 --- E O F --- 2008-09-15 14:05:19