Salut,
le rapport de combofix:
ComboFix 07-12-19.2 - Guillaume 2007-12-19 22:53:38.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.139 [GMT 1:00]
Running from: C:\Documents and Settings\Guillaume\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Helper
C:\Program Files\Helper\superfinderusa.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\rundll32.exe
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\drivers\XAY33.sys
C:\WINDOWS\system32\lfzqva.dat
c:\WINDOWS\system32\lfzqva_nav.dat
c:\WINDOWS\system32\lfzqva_navps.dat
C:\WINDOWS\system32\llkkj.bak1
C:\WINDOWS\system32\llkkj.bak2
C:\WINDOWS\system32\llkkj.ini
C:\WINDOWS\system32\llkkj.ini2
C:\WINDOWS\system32\llkkj.tmp
C:\WINDOWS\system32\mllmm.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_XAY33
((((((((((((((((((((((((( Files Created from 2007-11-19 to 2007-12-19 )))))))))))))))))))))))))))))))
.
2007-12-19 22:09 . 2007-12-19 22:09 2,554 --a------ C:\WINDOWS\system32\tmp.reg
2007-12-19 22:08 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-12-19 22:08 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-12-19 22:08 . 2007-12-13 19:40 77,824 --a------ C:\WINDOWS\system32\IEDFix.exe
2007-12-19 22:08 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-12-19 22:08 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-12-19 22:08 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-12-19 21:33 . 2007-12-19 21:33 56,320 ---hs---- C:\lo.exe
2007-12-19 20:30 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-12-19 20:05 . 2007-12-19 20:20 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-19 00:16 . 2007-12-19 00:16 303,104 --a------ C:\WINDOWS\system32\lfzqva.exe.ren
2007-12-19 00:15 . 2007-12-19 00:15 0 --a------ C:\WINDOWS\system32\MSNGR32.com
2007-12-18 23:20 . 2007-12-18 23:20 <DIR> d-------- C:\Program Files\Avira
2007-12-18 23:20 . 2007-12-18 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-17 00:43 . 2007-12-17 00:48 81,984 --a------ C:\apekl.exe
2007-12-11 07:11 . 2007-12-17 00:49 2 --a------ C:\1683552049
2007-12-10 23:39 . 2007-12-11 00:08 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-12-10 23:25 . 2007-12-10 23:25 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-10 22:21 . 2007-12-19 19:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-10 21:02 . 2007-12-10 21:02 <DIR> d-------- C:\Documents and Settings\Guillaume\Application Data\Grisoft
2007-12-10 21:02 . 2007-12-10 21:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-10 21:02 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-04 23:22 . 2007-12-04 23:22 <DIR> d-------- C:\Documents and Settings\Guillaume\Application Data\vlc
2007-12-04 23:08 . 2007-12-04 23:08 <DIR> d-------- C:\Program Files\VideoLAN
2007-12-04 21:42 . 2007-12-04 21:42 29 --a------ C:\WINDOWS\system32\gofuteid.tmp
2007-12-04 21:40 . 2007-12-04 21:38 162,304 ---hsc--- C:\WINDOWS\system32\dllcache\msfav32.exe
2007-12-04 21:31 . 2007-12-04 21:31 29 --a------ C:\WINDOWS\system32\wtpwsgrs.tmp
2007-12-02 23:59 . 2007-12-02 23:59 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-02 23:59 . 2003-03-18 22:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-02 22:55 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-12-02 22:55 --------- d-----w C:\Program Files\Symantec
2007-12-02 22:55 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-02 22:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-22 18:47 25,212 ----a-w C:\WINDOWS\system32\hderjsw.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2003-07-07 13:00]
"InstantTray"="C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe" [2003-10-22 15:03]
"IW_Drop_Icon"="C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe" [2004-02-26 15:00]
"Windows Secure Update"="load.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 10:24]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 10:11]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42]
"PinnacleDriverCheck"="C:\WINDOWS\System32\PSDrvCheck.exe" [2003-11-10 16:06]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-08-31 12:25]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2003-07-07 13:00]
"Microsoft Windows Driver"="C:\WINDOWS\rundll32.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Assistant d'Acrobat.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 06:01:04]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-19 22:57:58
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-19 23:00:45 - machine was rebooted