Salut !
Merci beaucoup de ta réponse !
VOila le rapport de Combo Fix
ComboFix 09-05-28.07 - pc 29/05/2009 7:43.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2038.1413 [GMT 2:00]
Lancé depuis: c:\users\pc\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\CISVC.exe
c:\windows\system32\nfr.assembly
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-28 au 2009-05-29 ))))))))))))))))))))))))))))))))))))
.
2009-05-29 05:48 . 2009-05-13 16:52 61440 ----a-w c:\windows\system\rsvp.exe
2009-05-29 05:47 . 2009-05-13 16:52 61440 ----a-w c:\users\pc\AppData\Local\ieudinit.exe
2009-05-29 05:47 . 2009-05-29 05:48 -------- d-----w c:\users\pc\AppData\Local\temp
2009-05-29 05:39 . 2009-05-13 16:52 61440 ----a-w c:\windows\system32\drivers\cisvc.exe
2009-05-27 19:17 . 2009-03-30 08:32 96104 ----a-w c:\windows\system32\drivers\avipbb.sys
2009-05-27 19:17 . 2009-03-24 14:07 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-27 19:17 . 2009-05-27 19:17 -------- d-----w c:\programdata\Avira
2009-05-27 19:17 . 2009-05-27 19:17 -------- d-----w c:\program files\Avira
2009-05-26 08:01 . 2009-05-26 08:01 -------- d-----w c:\windows\system32\Adobe
2009-05-24 18:40 . 2009-05-24 18:40 -------- d-----w c:\users\pc\AppData\Roaming\vlc
2009-05-13 16:52 . 2009-05-13 16:52 61440 ----a-w c:\users\pc\AppData\Roaming\cmstp.exe
2009-05-13 07:27 . 2006-01-04 08:12 77824 ----a-w c:\windows\system32\HPZIDS01.dll
2009-05-13 07:27 . 2006-04-10 12:03 38400 ----a-w c:\windows\system32\hpz3l054.dll
2009-05-13 07:26 . 2006-04-13 01:04 282624 ----a-w c:\windows\system32\HPZc3212.dll
2009-05-13 07:26 . 2006-04-13 01:04 21568 ----a-w c:\windows\system32\drivers\HPZius12.sys
2009-05-13 07:26 . 2006-04-13 01:04 16496 ----a-w c:\windows\system32\drivers\HPZipr12.sys
2009-05-13 07:26 . 2006-04-13 01:04 49664 ----a-w c:\windows\system32\drivers\HPZid412.sys
2009-05-13 07:26 . 2006-04-13 01:02 659456 ----a-w c:\windows\system32\hpowiax2.dll
2009-05-13 07:26 . 2006-04-13 01:02 254026 ----a-w c:\windows\system32\hpovst09.dll
2009-05-13 07:26 . 2006-04-13 01:02 827392 ----a-w c:\windows\system32\hpotiop2.dll
2009-05-04 23:01 . 2009-05-04 23:01 -------- d-----w c:\program files\VideoLAN
2009-04-30 12:17 . 2009-04-30 12:18 -------- d-----w c:\program files\MinitelADSL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-28 12:19 . 2006-03-11 06:42 678956 ----a-w c:\windows\system32\perfh00C.dat
2009-05-28 12:19 . 2006-03-11 06:42 128004 ----a-w c:\windows\system32\perfc00C.dat
2009-05-27 21:04 . 2009-03-16 14:59 -------- d-----w c:\users\pc\AppData\Roaming\FileZilla
2009-05-27 12:26 . 2008-12-03 13:27 -------- d-----w c:\users\pc\AppData\Roaming\OpenOffice.org2
2009-05-27 12:26 . 2008-12-03 13:27 1 ----a-w c:\users\pc\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-05-24 18:41 . 2008-11-04 10:16 -------- d-----w c:\users\pc\AppData\Roaming\dvdcss
2009-05-19 09:23 . 2008-10-31 16:52 -------- d-----w c:\users\pc\AppData\Roaming\LimeWire
2009-05-18 10:58 . 2009-02-17 18:40 -------- d-----w c:\program files\PKR
2009-05-13 16:52 . 2009-05-29 05:48 61440 ----a-w c:\windows\cisvc.exe
2009-05-10 15:07 . 2009-03-16 14:59 -------- d-----w c:\program files\FileZilla FTP Client
2009-05-05 18:15 . 2007-04-29 23:09 -------- d-----w c:\program files\VLC
2009-04-29 18:36 . 2009-04-28 20:17 -------- d-----w c:\program files\eMule
2009-04-28 20:28 . 2009-04-28 20:28 -------- d-----w c:\programdata\eMule
2009-04-18 07:57 . 2009-04-18 07:57 -------- d-----w c:\program files\Microsoft GIF Animator
2009-04-15 20:10 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-15 20:07 . 2006-03-10 23:05 -------- d-----w c:\programdata\Microsoft Help
2009-04-06 07:11 . 2008-11-03 11:38 27050 ----a-w c:\users\pc\AppData\Roaming\nvModes.dat
2009-03-17 03:38 . 2009-04-15 19:58 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 19:58 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-16 18:38 . 2007-04-26 00:53 121496 ----a-w c:\users\pc\AppData\Local\GDIPFONTCACHEV1.DAT
2009-03-13 14:12 . 2009-01-28 16:47 355584 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-03-09 04:19 . 2007-04-29 23:31 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-05 06:55 . 2009-04-13 14:06 4604240 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{364E000A-E670-49A6-8810-08ED0933D0CB}\mpengine.dll
2009-03-03 04:46 . 2009-04-15 19:58 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 19:58 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-15 19:57 827392 ----a-w c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-15 19:58 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 19:58 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 19:58 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 19:57 78336 ----a-w c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-15 19:58 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 19:58 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 19:58 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 19:58 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 19:58 17408 ----a-w c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-15 19:57 26624 ----a-w c:\windows\system32\ieUnatt.exe
2006-03-11 06:49 . 2006-03-11 06:48 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-16 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-23 857648]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-08-16 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-16 8478720]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-08-16 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"CmSTP"="c:\users\pc\AppData\Local\Temp\cmstp.exe" [2009-05-13 61440]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Cisvc"="c:\windows\System32\drivers\cisvc.exe" [2009-05-13 61440]
[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Cisvc"="c:\windows\cisvc.exe" [2009-05-13 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=c:\windows\System\rsvp.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^pc^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EBFC12A6-0DE1-4924-BB4C-6EB414BE97FC}"= UDP:c:\users\pc\AppData\Local\Temp\7zS38BC.tmp\SymNRT.exe:Norton Removal Tool
"{A7A66D1A-5A39-4745-8812-76D1EC4C3E5B}"= TCP:c:\users\pc\AppData\Local\Temp\7zS38BC.tmp\SymNRT.exe:Norton Removal Tool
"{F22066D7-C19B-4CD5-86D0-BC3503BE693A}"= UDP:c:\users\pc\AppData\Local\Temp\7zS9109.tmp\SymNRT.exe:Norton Removal Tool
"{E630157B-F038-42EB-9043-74B7A8E0D0EE}"= TCP:c:\users\pc\AppData\Local\Temp\7zS9109.tmp\SymNRT.exe:Norton Removal Tool
"{691F5CCB-1477-4B72-976A-106074A3362C}"= UDP:c:\users\pc\AppData\Local\Temp\7zS17E4.tmp\SymNRT.exe:Norton Removal Tool
"{DDB0D0A6-D15C-4516-A53A-177351AD4336}"= TCP:c:\users\pc\AppData\Local\Temp\7zS17E4.tmp\SymNRT.exe:Norton Removal Tool
"{A8FBA8F0-2C28-46CD-84FC-3E20E813D26B}"= UDP:c:\users\pc\AppData\Local\Temp\7zS82F5.tmp\SymNRT.exe:Norton Removal Tool
"{B84E556C-2030-4A05-B675-021C5090543A}"= TCP:c:\users\pc\AppData\Local\Temp\7zS82F5.tmp\SymNRT.exe:Norton Removal Tool
"TCP Query User{D1CEBFE4-F4F3-4311-9629-6FBC0FCFC8AB}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{B247D922-7E33-4422-966B-ABBF41FA1C75}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{90C334D3-9410-466F-9995-D3C2CC627A9B}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{4083221F-596A-4841-8B49-01D4759767F7}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{79220BF6-4577-4E93-B99E-E889FFE1D3A4}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"TCP Query User{FD93EDCE-1BD4-49B8-B680-872EA97CBEC9}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{9B255906-8B87-4176-8271-1E56F8D7EC6A}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{0C283B2D-CA96-406F-8324-BA5DD61CFBDC}"= UDP:4662:tcp
"{858024B4-AF82-41DA-BBF5-BA757CB4D83C}"= TCP:4672:udp
"{174E751D-0D2B-4CA3-AA18-3369F9297AC0}"= UDP:4672:tcp
"{865E68E6-8D3A-4519-90FE-2948F1E099BF}"= TCP:4668:udp
"{B3323639-A168-445F-8F5E-1B93E2A7390A}"= UDP:c:\program files\Windows Defender\MSASCui.exe:Windows Defender
"{A907FEB0-D784-46D9-A087-5158B67AEF15}"= TCP:c:\program files\Windows Defender\MSASCui.exe:Windows Defender
"{EE1DC004-4AD1-49FA-9847-B6152DB49E60}"= UDP:c:\windows\System32\wuapp.exe:wuapp.exe
"{F1410145-DE0D-469B-96FA-4F4AA457F4ED}"= TCP:c:\windows\System32\wuapp.exe:wuapp.exe
"TCP Query User{43161F61-52F2-42BF-B772-186AC078DBB3}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{BBFA8057-CDD7-4A3A-9864-AB7F0FCF40A1}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{1E74DD9C-66E7-427A-8564-B2E6F80235E5}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{5F1C176D-2341-43FB-B534-E20040C8AEC0}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [27/05/2009 21:17 108289]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [11/03/2006 00:31 46592]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2009-05-29 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-03-03 08:23]
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-procexp90.Sys
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} - hxxp://minitelweb.minitel.com/imin_data/ocx/MDM.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\9yrrswch.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdrmv2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-29 07:49
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Heure de fin: 2009-05-29 7:52 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-05-29 05:52
ComboFix2.txt 2009-03-17 11:32
Avant-CF: 71 313 559 552 octets libres
Après-CF: 71 324 069 888 octets libres
214 --- E O F --- 2009-04-15 20:09
Merci !