Merci de m'avoir répondu.
Le rapport a été assez long.
Suite à ce rapport j'ai l'impression d'être sous une apparence 98 et non Xp. Le virus est toujours là, car j'ai toujours la fenêtre qui s'affiche.
Le voici:
ComboFix 09-10-08.04 - Marlène Cxxxx 10/10/2009 21:12.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1279.602 [GMT 2:00]
Lancé depuis: c:\documents and settings\Marlène Cxxxx\Bureau\combo-fix.exe
AV: avast! antivirus 4.8.1335 [VPS 091009-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
[i] ADS - WINDOWS: deleted 72 bytes in 1 streams.
/i
[i] ADS - svchost.exe: deleted 31744 bytes in 1 streams.
/i
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\NetworkService\ntuser.dll
c:\recycler\S-1-5-21-0208374356-2181206355-079396765-9477
c:\recycler\S-1-5-21-0243936033-3052116371-381863308-1811
c:\recycler\S-1-5-21-0243936033-3052116371-381863308-1858
c:\recycler\S-1-5-21-0245289987-9686493290-335870376-2847
c:\recycler\S-1-5-21-0628706161-6088795659-537978588-1656
c:\recycler\S-1-5-21-0892343856-2271740846-761648556-1606
c:\recycler\S-1-5-21-0951332512-5343315443-174227498-0259
c:\recycler\S-1-5-21-1484080291-8858831330-464184352-3359
c:\recycler\S-1-5-21-2132614119-5863744320-667308370-5921
c:\recycler\S-1-5-21-2467913445-7132686288-352137432-7831
c:\recycler\S-1-5-21-2478505781-7020578900-670750353-3689
c:\recycler\S-1-5-21-2478505781-7020578900-670750353-3689\Desktop.ini
c:\recycler\S-1-5-21-2478505781-7020578900-670750353-3689\wnzip32.exe
c:\recycler\S-1-5-21-2743983155-6285318407-928190796-9847
c:\recycler\S-1-5-21-2907026870-7554786089-492674946-5545
c:\recycler\S-1-5-21-3539946292-8063953586-335323656-7394
c:\recycler\S-1-5-21-4386793937-4524700639-680774601-9478
c:\recycler\S-1-5-21-4407150767-1561733905-179563447-7031
c:\recycler\S-1-5-21-4469495292-4260688815-324929095-0094
c:\recycler\S-1-5-21-4614510201-8890611533-499363049-7280
c:\recycler\S-1-5-21-5060942413-4791985025-628070533-5700
c:\recycler\S-1-5-21-5287088361-7090177700-141952692-2267
c:\recycler\S-1-5-21-5540211268-4794550213-572687221-3699
c:\recycler\S-1-5-21-5614638252-5671007538-913735555-1698
c:\recycler\S-1-5-21-5661752594-2892416011-397527773-4087
c:\recycler\S-1-5-21-6033903343-5277688092-381710061-3237
c:\recycler\S-1-5-21-6438904790-2652938547-528198323-5059
c:\recycler\S-1-5-21-6450961797-3279482723-089984359-4184
c:\recycler\S-1-5-21-6594004721-4184889828-302637648-0060
c:\recycler\S-1-5-21-6668144127-4209684199-445945401-9863
c:\recycler\S-1-5-21-6669884855-5026225659-871457908-6117
c:\recycler\S-1-5-21-7326129695-0507378237-029498061-1807
c:\recycler\S-1-5-21-7636304563-0031248976-699515553-6252
c:\recycler\S-1-5-21-7726428107-4799412952-488568901-2764
c:\recycler\S-1-5-21-8039072132-7996001462-199017986-1688
c:\recycler\S-1-5-21-8526701702-9534707388-204099756-8653
c:\recycler\S-1-5-21-8584318107-6593789130-459891586-9245
c:\recycler\S-1-5-21-8705049247-0814168968-885919000-2963
c:\recycler\S-1-5-21-8735367446-0220211375-025514443-2870
c:\windows\Fonts\Txtrider.fon
c:\windows\kb913800.exe
c:\windows\system32\_004841_.tmp.dll
c:\windows\system32\_004842_.tmp.dll
c:\windows\system32\_004843_.tmp.dll
c:\windows\system32\_004844_.tmp.dll
c:\windows\system32\_004851_.tmp.dll
c:\windows\system32\_004852_.tmp.dll
c:\windows\system32\_004853_.tmp.dll
c:\windows\system32\_004854_.tmp.dll
c:\windows\system32\_004856_.tmp.dll
c:\windows\system32\_004857_.tmp.dll
c:\windows\system32\_004860_.tmp.dll
c:\windows\system32\_004861_.tmp.dll
c:\windows\system32\_004864_.tmp.dll
c:\windows\system32\_004865_.tmp.dll
c:\windows\system32\_004867_.tmp.dll
c:\windows\system32\_004869_.tmp.dll
c:\windows\system32\_004870_.tmp.dll
c:\windows\system32\_004871_.tmp.dll
c:\windows\system32\_004876_.tmp.dll
c:\windows\system32\_004878_.tmp.dll
c:\windows\system32\_004881_.tmp.dll
c:\windows\system32\_004883_.tmp.dll
c:\windows\system32\_004884_.tmp.dll
c:\windows\system32\_004885_.tmp.dll
c:\windows\system32\_004886_.tmp.dll
c:\windows\system32\_004887_.tmp.dll
c:\windows\system32\_004890_.tmp.dll
c:\windows\system32\_004891_.tmp.dll
c:\windows\system32\_004892_.tmp.dll
c:\windows\system32\_004893_.tmp.dll
c:\windows\system32\_004894_.tmp.dll
c:\windows\system32\_004899_.tmp.dll
c:\windows\system32\_004901_.tmp.dll
c:\windows\system32\calc.dll
c:\windows\system32\drivers\downld
c:\windows\system32\drivers\downld\308984.exe
c:\windows\system32\drivers\downld\319687.exe
c:\windows\system32\drivers\downld\320718.exe
c:\windows\system32\drivers\downld\4487625.exe
c:\windows\system32\drivers\downld\4488765.exe
c:\windows\system32\drivers\downld\4520906.exe
c:\windows\system32\drivers\downld\4523593.exe
c:\windows\system32\drivers\downld\4526312.exe
c:\windows\system32\drivers\downld\4575203.exe
c:\windows\system32\drivers\downld\833187.exe
c:\windows\system32\drivers\hldrrr .exe
c:\windows\system32\drivers\str.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\lsprcxs .exe
c:\windows\system32\lvcomsx .exe
c:\windows\system32\mssrv32.exe
c:\windows\system32\ncmdds .exe
c:\windows\system32\qazbrnn .exe
c:\windows\system32\sdra64.exe
c:\windows\system32\sysmonitor .exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ICF
-------\Service_ICF
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-10 au 2009-10-10 ))))))))))))))))))))))))))))))))))))
.
2009-10-10 18:26 . 2009-10-10 18:27 -------- d-----w- c:\program files\Unlocker
2009-10-10 16:55 . 2009-10-10 16:57 -------- d-----w- c:\windows\LastGood.Tmp
2009-10-10 16:52 . 2009-10-10 16:52 -------- d-----w- c:\windows\system32\fr
2009-10-10 16:52 . 2009-10-10 16:52 -------- d-----w- c:\windows\system32\bits
2009-10-10 16:52 . 2009-10-10 16:52 -------- d-----w- c:\windows\l2schemas
2009-10-10 16:50 . 2009-10-10 16:52 -------- d-----w- c:\windows\ServicePackFiles
2009-10-10 16:40 . 2009-10-10 16:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-08 16:43 . 2009-10-08 16:43 56832 ----a-w- c:\windows\system32\jrnfd32.dll
2009-10-08 15:35 . 2009-10-10 16:32 30720 --sh--r- c:\windows\system32\lsprcxs.exe
2009-10-08 15:35 . 2009-10-10 16:32 30720 --sh--r- c:\windows\system32\ncmdds.exe
2009-10-08 15:35 . 2009-10-10 16:26 30720 --sh--r- c:\windows\system32\qazbrnn.exe
2009-10-08 14:40 . 2009-10-08 14:40 9440 ----a-w- c:\windows\system32\drivers\nmwcdq.sys
2009-10-08 13:52 . 2009-10-08 16:43 82944 --sh--w- C:\klnjswpx.exe
2009-09-24 20:59 . 2009-09-24 20:59 -------- d-----w- c:\program files\ma-config.com
2009-09-24 20:59 . 2009-09-24 20:59 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-10 18:06 . 2007-03-06 09:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-10 16:39 . 2007-03-03 10:03 -------- d-----w- c:\program files\Java
2009-10-10 16:37 . 2006-09-08 11:17 85018 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-10 16:37 . 2006-09-08 11:17 492138 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-10 16:32 . 2004-05-21 18:11 30720 ----a-w- c:\windows\system32\lvcomsx.exe
2009-10-10 16:32 . 2007-03-03 10:04 30720 ----a-w- c:\windows\system32\sysmonitor.exe
2009-10-09 16:10 . 2008-05-05 18:42 -------- d-----w- c:\program files\CEDP Stealer 6.0 for Messenger
2009-09-27 19:48 . 2009-03-20 16:57 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-25 15:16 . 2007-06-18 21:27 -------- d-----w- c:\program files\Windows Live
2009-09-14 10:27 . 2007-03-06 08:43 -------- d-----w- c:\program files\eMule
2009-09-08 16:15 . 2007-04-17 17:28 -------- d-----w- c:\program files\Nvu
2009-09-08 16:13 . 2006-09-08 11:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
.
------- Sigcheck -------
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp3gdr\tcpip.sys
[-] 2008-06-20 . 0B788EE2A876D7B31DF840C13F08CD2B . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\tcpip.sys
[-] 2008-04-13 . 99BD46C2C790E52363DD1021DDCA3E8F . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2006-01-13 . 5562CC0A47B2AEF06D3417B733F3C195 . 360448 . . [5.1.2600.2827] . . c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"wesspell"="c:\windows\system32\qazbrnn.exe" [2009-10-10 30720]
"zmmclr"="c:\windows\system32\ncmdds.exe" [2009-10-10 30720]
"mqlwindl"="c:\windows\system32\lsprcxs.exe" [2009-10-10 30720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2009-10-10 30720]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"Acer Empowering Technology Monitor"="c:\windows\system32\SysMonitor.exe" [2009-10-10 30720]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2009-10-10 30720]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-03-17 345088]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2009-10-10 30720]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2009-10-10 30720]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2009-10-10 30720]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-11-17 185896]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"\\marlene\EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-06-01 16208384]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
c:\documents and settings\MarlŠne CHERPEAU\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-19 630784]
scandisk.dll [2009-10-8 25088]
scandisk.lnk - c:\windows\system32\rundll32.exe [2004-8-10 33792]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-3-3 45056]
Acer WLAN 11g USB Dongle.lnk - c:\program files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 745472]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Marlène CHERPEAU^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\Marlène CHERPEAU\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Marlène CHERPEAU^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Marlène CHERPEAU\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI.SP1a\\RpcSandraSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XI.SP1a\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\explorer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6881:TCP"= 6881:TCP:BitTorrent
"21758:TCP"= 21758:TCP:BitComet 21758 TCP
"21758:UDP"= 21758:UDP:BitComet 21758 UDP
"65534:TCP"= 65534:TCP:BitComet 65534 TCP
"65534:UDP"= 65534:UDP:BitComet 65534 UDP
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [03/04/2008 18:58 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [03/04/2008 18:58 20560]
R2 e4mnt4;e4mnt4;c:\windows\system32\drivers\e4mnt4.sys [07/05/2008 17:18 75360]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [24/01/2008 13:12 24652]
R3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [06/03/2007 21:49 163328]
S2 e4mservice;E4M service;e4mserv.exe --> e4mserv.exe [?]
S2 qrdgjouxevmdq;qrdgjouxevmdq;\??\c:\windows\system32\drivers\kdehlyggwpefu.sys --> c:\windows\system32\drivers\kdehlyggwpefu.sys [?]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 14:50 238960]
S3 pohci13F;pohci13F;\??\c:\docume~1\MARLNE~1\LOCALS~1\Temp\pohci13F.sys --> c:\docume~1\MARLNE~1\LOCALS~1\Temp\pohci13F.sys [?]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [28/03/2007 21:11 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [28/03/2007 21:11 85696]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - EHRECVR
*NewlyCreated* - EHSCHED
.
Contenu du dossier 'Tâches planifiées'
2009-09-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
c:\windows\Tasks\At6.job
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mStart Page = hxxp://fr.fr.acer.yahoo.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Marlène CHERPEAU\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk
TCP: {D32D6B20-C01E-4920-AA7A-8E2B05516D9D} = 192.168.30.1,0.0.0.0
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game12.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\Marlène CHERPEAU\Application Data\Mozilla\Firefox\Profiles\leo1ccsp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-AVG Anti-Spyware Driver
AddRemove-debug meta obj - c:\docume~1\MARLNE~1\APPLIC~1\MEETMI~1\Batvccake.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-10 21:22
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\windows\system32\lsprcxs .exe 30720 bytes executable
c:\windows\system32\lvcomsx .exe 30720 bytes executable
c:\windows\system32\ncmdds .exe 30720 bytes executable
c:\windows\system32\sysmonitor .exe 30720 bytes executable
c:\windows\system32\qazbrnn .exe 30720 bytes executable
Scan terminé avec succès
Fichiers cachés: 5
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1840)
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
c:\windows\system32\MSNCHATHOOK.DLL
c:\windows\system32\sysenv.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\MFC71U.DLL
c:\program files\Unlocker\UnlockerHook.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_fre.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
c:\windows\system32\searchindexer.exe
c:\windows\ehome\mcrdsvc.exe
c:\acer\Empowering Technology\eRecovery\eragent .exe
c:\program files\Logitech\Video\logitray .exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\searchprotocolhost.exe
c:\docume~1\MARLNE~1\LOCALS~1\Temp\ctv333.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Windows Live\Toolbar\wltuser.exe
c:\windows\ehome\ehSched.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Heure de fin: 2009-10-10 21:30 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-10 19:30
Avant-CF: 11 114 086 400 octets libres
Après-CF: 11 098 783 744 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
Current=2 Default=2 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
362 --- E O F --- 2009-10-10 16:55
Que dois-je en conclure? Merci d'avance.