J'ai fais ce que tu ma dis (j'ignore si tout mes antivirus ou la garde antispyware etais tous belle et bien fermer) j'ai fermer Avg et pui je suis aller dans / Démarrer /Panneau de Config /Pare-feu Window (et mis a Désactiver) C'est ce que j'ai cru etre complet... enfin apres avoir passer ComboFix je n'arrive plu a me connecter sur internet sur ma session Admin :/
Pour le raport Combo : (Je sais pas si c'est bien cela mais c'est tout ce que j'ai)
ComboFix 08-05-11.1 - lXKl 2008-05-12 9:31:46.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1486 [GMT -4:00]
Endroit: C:\Documents and Settings\lXKl\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-12 to 2008-05-12 ))))))))))))))))))))))))))))))))))))
.
2008-05-11 20:04 . 2008-05-11 20:04 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-11 20:04 . 2008-05-11 20:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-11 19:59 . 2008-05-12 09:31 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG
2008-05-09 05:23 . 2008-05-09 05:23 <REP> d-------- C:\Program Files\CCleaner
2008-05-09 04:03 . 2008-03-05 14:33 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-05-09 04:03 . 2008-03-05 14:33 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-05-09 04:03 . 2008-03-05 20:42 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-05-09 04:03 . 2008-05-09 05:45 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-05-09 04:03 . 2008-03-05 14:33 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-05-09 04:03 . 2008-03-05 14:33 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-05-09 04:03 . 2008-03-05 14:33 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-05-09 04:03 . 2008-05-09 05:46 <REP> d-------- C:\Documents and Settings\Administrateur
2008-05-09 04:03 . 2008-05-11 22:34 1,024 --ah----- C:\Documents and Settings\Administrateur\NtUser.dat.LOG
2008-05-08 13:19 . 2008-05-08 13:19 <REP> d-------- C:\Program Files\Trend Micro
2008-05-07 23:20 . 2008-05-11 22:18 <REP> d--h----- C:\$AVG8.VAULT$
2008-05-07 23:17 . 2008-05-12 08:07 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-07 23:17 . 2008-05-07 23:17 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-07 23:17 . 2008-05-07 23:17 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-07 23:17 . 2008-05-07 23:17 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-07 23:16 . 2008-05-07 23:16 <REP> d-------- C:\Program Files\AVG
2008-05-07 23:16 . 2008-05-07 23:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-06 22:52 . 2008-05-06 22:52 268 --ah----- C:\sqmdata00.sqm
2008-05-06 22:52 . 2008-05-06 22:52 244 --ah----- C:\sqmnoopt00.sqm
2008-05-05 04:56 . 2008-05-05 04:56 <REP> d-------- C:\Program Files\Common Files
2008-05-05 04:56 . 2008-05-05 05:01 <REP> d-------- C:\Program Files\CamStudio
2008-05-01 10:43 . 2008-05-01 10:46 <REP> d-------- C:\Program Files\EMUSB2.0
2008-05-01 10:43 . 2008-05-01 10:43 <REP> d-------- C:\Program Files\eMPIA
2008-05-01 10:43 . 2005-04-11 10:50 168,576 --a------ C:\WINDOWS\system32\drivers\emDevice.sys
2008-05-01 10:43 . 2005-04-11 10:49 57,344 --a------ C:\WINDOWS\system32\emVFW.dll
2008-05-01 10:43 . 2005-04-11 10:49 32,768 --a------ C:\WINDOWS\system32\emProp.ax
2008-05-01 10:43 . 2004-09-14 19:25 17,808 --a------ C:\WINDOWS\system32\emYUV.dll
2008-05-01 10:43 . 2005-04-11 10:50 8,192 --a------ C:\WINDOWS\system32\emUSD.dll
2008-05-01 10:43 . 2005-04-11 10:50 5,248 --a------ C:\WINDOWS\system32\drivers\emFilter.sys
2008-05-01 10:43 . 2005-04-11 10:50 5,120 --a------ C:\WINDOWS\system32\drivers\emScan.sys
2008-04-28 12:04 . 2006-01-11 00:50 24,576 --a------ C:\WINDOWS\system32\AsIO.dll
2008-04-28 12:04 . 2007-12-18 01:14 12,400 --a------ C:\WINDOWS\system32\drivers\AsIO.sys
2008-04-28 12:04 . 2008-01-04 13:34 11,832 --a------ C:\WINDOWS\system32\drivers\AsInsHelp64.sys
2008-04-28 12:04 . 2008-01-04 13:34 10,216 --a------ C:\WINDOWS\system32\drivers\AsInsHelp32.sys
2008-04-28 12:03 . 2008-04-28 12:03 <REP> d-------- C:\Program Files\Attansic
2008-04-28 11:23 . 2008-04-28 12:07 <REP> d-------- C:\Carte mere
2008-04-28 11:14 . 2008-04-28 11:14 0 --a------ C:\WINDOWS\p5.idx
2008-04-25 23:27 . 2008-04-25 23:27 <REP> d-------- C:\Program Files\THQ
2008-04-16 02:47 . 2008-04-16 02:47 <REP> d-------- C:\Documents and Settings\lXKl_2\Application Data\fltk.org
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-08 03:34 --------- d-----w C:\Program Files\GameSpy Arcade
2008-05-07 22:20 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
2008-05-05 08:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-05 08:54 --------- d-----w C:\Documents and Settings\lXKl_2\Application Data\InstallShield
2008-04-28 16:04 --------- d-----w C:\Program Files\ASUS
2008-04-28 15:58 --------- d-----w C:\Program Files\Realtek
2008-04-14 21:42 --------- d-----w C:\Documents and Settings\lXKl_2\Application Data\LimeWire
2008-04-07 05:33 --------- d-----w C:\Documents and Settings\lXKl\Application Data\uTorrent
2008-04-07 05:32 --------- d-----w C:\Documents and Settings\lXKl_2\Application Data\uTorrent
2008-03-23 18:06 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-03-23 17:41 --------- d-----w C:\Documents and Settings\lXKl\Application Data\InterVideo
2008-03-23 16:57 --------- d-----w C:\Documents and Settings\lXKl_2\Application Data\Media Player Classic
2008-03-21 21:20 --------- d-----w C:\Documents and Settings\lXKl\Application Data\Media Player Classic
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 18:39 --------- d-----w C:\Documents and Settings\lXKl_2\Application Data\Ventrilo
2008-03-17 23:56 --------- d-----w C:\Program Files\uTorrent
2008-03-17 08:20 --------- d-----w C:\Program Files\GRETECH
2008-03-17 08:09 --------- d-----w C:\Program Files\Java
2008-03-17 05:48 --------- d-----w C:\Documents and Settings\lXKl_2\Application Data\Leadertech
2008-03-12 22:06 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-03-12 19:56 --------- d-----w C:\Program Files\EA GAMES
2008-03-07 01:26 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-03-07 01:26 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-06 01:58 579,225 ----a-w C:\WINDOWS\P5KSE0604.zip
2008-03-06 01:00 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-03-01 12:58 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2006-06-23 18:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
2005-04-01 02:17 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2002-08-27 16:40 55,313 ----a-w C:\Program Files\viewsonicinstruct_xp.pdf
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS SmartDoctor"="C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe" [2007-11-09 18:29 1126400]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 19:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-06 05:30 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-06 05:30 81920]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-10-23 18:48 380928]
"emMON"="emMON.exe" [2006-05-30 22:24 61440 C:\WINDOWS\emMON.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 14:49 16126464 C:\WINDOWS\RTHDCPL.exe]
"Ai Nap"="C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 12:55 1413120]
"CPU Power Monitor"="C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 10:17 627200]
"Cpu Level Up help"="C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 20:03 881152]
"ASUS Energy Saving"="C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe" [2008-01-28 10:42 1352704]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-07 23:17 1177368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 19:09 15360]
C:\Documents and Settings\lXKl\Menu D‚marrer\Programmes\D‚marrage\
PowerReg Scheduler.exe [2008-03-06 04:31:17 225280]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
InterVideo WinCinema Manager.lnk - E:\XK\Programe\Common\Bin\WinCinemaMgr.exe [2008-03-23 13:46:00 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
"VIDC.NSVI"= nsvideo.dll
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"E:\\XK\\Programe\\Limewire\\LimeWire.exe"=
"E:\\XK\\Uo_ml3\\No_Crypt_Client_3d.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"C:\\Program Files\\ASUS\\ASUSUpdate\\Update.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R0 Achernar;Achernar - SCSI Command Filters;C:\WINDOWS\system32\Drivers\Achernar.sys [2005-09-23 14:50]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-07 23:17]
R1 EIO_XP;EIO_XP;C:\WINDOWS\system32\drivers\EIO_XP.sys [2006-06-14 14:44]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-07 23:17]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-07 23:16]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-07 23:17]
R3 Aldebaran;Aldebaran - SCSI Command Filters;C:\WINDOWS\system32\Drivers\Aldebaran.sys [2005-09-23 14:50]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-10-23 18:48]
R3 ASUSVRC;ASUSTeK Virtual Capture Device;C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 18:12]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 14:12]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-10-23 18:48]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Autorun.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - HTTPFILTER
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 09:32:26
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-12 9:32:45
ComboFix-quarantined-files.txt 2008-05-12 13:32:43
Pre-Run: 10,257,825,792 octets libres
Post-Run: 10,268,639,232 octets libres
168 --- E O F --- 2008-04-14 09:43:56