Voila le rapport
ComboFix 08-02.02.5 - Colin 2008-02-02 13:51:33.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.820 [GMT 1:00]
Endroit: C:\Documents and Settings\Colin\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-02 to 2008-02-02 ))))))))))))))))))))))))))))))))))))
.
2008-02-02 13:48 . 2007-02-27 19:30 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-02-02 13:48 . 2007-02-27 19:30 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-02-02 13:48 . 2007-02-27 18:36 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-02-02 13:48 . 2007-02-27 19:30 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-02-02 13:48 . 2007-02-27 19:30 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-02-02 13:48 . 2007-02-27 19:30 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-02-02 13:48 . 2007-02-27 18:47 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-01-22 13:40 . 2008-01-22 13:41 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
2008-01-21 15:06 . 2008-01-21 15:06 10,593 --a------ C:\WINDOWS\CSTBox.INI
2008-01-21 12:32 . 2008-02-02 09:56 <REP> d-------- C:\HijackThis
2008-01-21 12:08 . 2008-01-21 12:08 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-21 12:05 . 2008-01-21 12:05 <REP> d-------- C:\Program Files\Skype
2008-01-21 12:05 . 2008-01-21 12:05 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-01-21 12:05 . 2008-01-21 12:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-01-10 22:20 . 2008-01-10 22:21 <REP> d-------- C:\Documents and Settings\Colin\Application Data\gtk-2.0
2008-01-10 22:19 . 2008-01-10 22:19 <REP> d-------- C:\Documents and Settings\Colin\.thumbnails
2008-01-10 22:14 . 2008-01-10 22:15 <REP> d-------- C:\Program Files\Gimp Pack Mode
2008-01-10 22:14 . 2008-01-10 22:27 <REP> d-------- C:\Documents and Settings\Colin\.gimp-2.4
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 08:50 --------- d-----w C:\Program Files\AdVantage
2008-02-01 13:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-30 14:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-01-21 14:06 --------- d-----w C:\Program Files\eMule
2008-01-21 14:06 --------- d-----w C:\Program Files\Canon
2008-01-21 14:05 --------- d-----w C:\Documents and Settings\Colin\Application Data\Canon
2007-12-31 10:38 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-27 17:07 --------- d-----w C:\Documents and Settings\Colin\Application Data\NewSoft
2007-12-27 16:52 --------- d-----w C:\Documents and Settings\Colin\Application Data\ArcSoft
2007-12-27 16:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-27 16:45 --------- d-----w C:\Program Files\Fichiers communs\PDFView
2007-12-27 16:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-12-27 16:43 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-12-27 16:41 --------- d-----w C:\Program Files\ArcSoft
2007-12-27 16:39 --------- d-----w C:\Program Files\Fichiers communs\CANON
2007-12-17 17:18 --------- d-----w C:\Program Files\MyPlayCity.com
2007-12-17 11:25 --------- d-----w C:\Program Files\Lame MP3 Codec
2007-12-17 11:24 65,024 ----a-w C:\WINDOWS\IFinst26.exe
2007-12-17 11:06 --------- d-----w C:\Documents and Settings\Colin\Application Data\DataCast
2007-12-17 11:02 --------- d-----w C:\Program Files\TELL ME MORE NV
2007-12-15 18:02 --------- d-----w C:\Program Files\XviD
2007-12-15 18:00 --------- d-----w C:\Program Files\Samsung
2007-12-14 19:00 --------- d-----w C:\Program Files\Java
2007-12-14 18:56 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-14 18:52 --------- d-----w C:\Program Files\Fichiers communs\Real
2007-12-14 17:56 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-12-14 17:56 --------- d-----w C:\Program Files\Windows Live
2007-12-14 16:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-26 15:51 22,845,992 ----a-w C:\Program Files\AdbeRdr80_fr_FR.exe
2007-04-26 15:43 7,218,088 ----a-w C:\Program Files\psa30se_fr_fr.exe
2007-02-28 17:03 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 20:00 15360]
"AdVantage"="C:\Program Files\AdVantage\AdVantage.exe" [2007-06-28 15:19 880080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:34 64512]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 16:58 16264192 C:\WINDOWS\RTHDCPL.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-20 20:58 7581696]
"nwiz"="nwiz.exe" [2006-07-20 20:58 1519616 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-12-06 00:38 707360]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-01-04 23:13]
R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\plcndis5.sys [2004-05-17 11:21]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 20:00]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-02 13:56:52
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-02 13:59:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 12:58:57
.
2008-01-09 11:36:38 --- E O F ---
Merci pour ton aide