Eclypse16, quelle promptitude !!!
Ci-dessus le rapport ComboFix (celui de GenProc ne détecte pas d'infection...)
J'ai également relancé HiJackThis et effectué la manip que tu me recommande. Merci.
ComboFix 07-08-09.3 - "CBREMAUD" 2007-08-11 11:23:01.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.685 [GMT 2:00]
/wow section not completed
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\CBREMAUD\APPLIC~1\..\err.log
C:\WINDOWS\system32\kdupp.exe
C:\WINDOWS\system32\stera.log
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_FOPN
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))
2007-08-11 11:15 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-08 19:37 50,007 --a------ C:\WINDOWS\system32\drivers\adildr.sys
2007-08-08 19:37 46,892 --a------ C:\WINDOWS\system32\adadix16.dll
2007-08-08 19:37 4,981 --a------ C:\WINDOWS\system32\adadix2k.dll
2007-08-08 19:37 24,576 --a------ C:\WINDOWS\enddisk32.exe
2007-08-08 19:37 155,648 --a------ C:\WINDOWS\system32\adadix32.dll
2007-08-08 19:37 127,456 --a------ C:\WINDOWS\system32\ipdetect.exe
2007-08-08 19:37 127,065 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys
2007-08-08 19:37 114,688 --a------ C:\WINDOWS\system32\unaddrv.exe
2007-08-08 19:37 106,496 --a------ C:\WINDOWS\system32\coclassfast.dll
2007-08-08 19:36 <REP> d-------- C:\Program Files\SAGEM
2007-08-08 19:35 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin
2007-08-08 19:35 143,360 --a------ C:\WINDOWS\autoclk.exe
2007-08-08 19:35 143,360 --a------ C:\WINDOWS\adiras.exe
2007-08-08 13:50 <REP> d-------- C:\Program Files\Neuf
2007-08-06 12:32 <REP> d-------- C:\Program Files\9telecom
2007-08-06 12:31 335 --a------ C:\WINDOWS\nsreg.dat
2007-08-06 12:30 28,672 -ra------ C:\WINDOWS\system32\rnaph.dll
2007-08-06 10:02 28,672 -ra------ C:\WINDOWS\system32\adinst32.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-11 11:06 3020 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-08 19:37 23 --a------ C:\WINDOWS\system32\drivers\adidsl.cfg
2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 23:57 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-07-07 16:40 --------- d-------- C:\Program Files\XoftSpySE
2007-05-16 17:13 86528 --a------ C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 17:13 85504 --a------ C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 17:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 17:13 683520 --a------ C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 17:13 510976 --a------ C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 17:13 1314816 --a------ C:\WINDOWS\system32\dllcache\msoe.dll
2006-12-25 09:46 0 --a------ C:\DOCUME~1\CBREMAUD\APPLIC~1\wklnhst.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-07 20:02]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-07 19:59]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-07 20:03]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 C:\WINDOWS\system32\HdAShCut.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 19:51]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 14:44]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 14:43]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 05:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 05:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-09 15:17 C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 18:43 C:\WINDOWS\Alcmtr.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"FLMOFFICE4DMOUSE"="C:\Program Files\Trust\MI-4550XP WIRELESS OPTICAL MINI MOUSE\Mouse32a.exe" [2006-12-28 16:48]
"TQ566808"="E:\Setup.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
"autoclk"="autoclk.exe" [2003-01-30 05:48 C:\WINDOWS\autoclk.exe]
"adiras"="adiras.exe" [2005-05-03 12:57 C:\WINDOWS\adiras.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 05:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-08-08 19:37:00]
R2 EpmPsd;Acer EPM Power Scheme Driver;\??\C:\WINDOWS\system32\drivers\epm-psd.sys
R2 EpmShd;Acer EPM System Hardware Driver;\??\C:\WINDOWS\system32\drivers\epm-shd.sys
R2 int15.sys;int15.sys;\??\C:\Program Files\Acer\eRecovery\int15.sys
R3 NTIDrvr;Upper Class Filter Driver;C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
R3 w29n51;Pilote de carte de connexion réseau Intel(R) PRO/Wireless 2200BG pour Windows XP;C:\WINDOWS\system32\DRIVERS\w29n51.sys
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys
S3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys
S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys
S3 QV2KUX;Appareil photo numérique Casio;C:\WINDOWS\system32\DRIVERS\qv2kux.sys
Contents of the 'Scheduled Tasks' folder
2007-05-15 15:11:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 11:27:15
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-11 11:28:47 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-11 11:28
--- E O F ---
Merci
Nicolas