Bonsoir
Merci beaucoup de m'avoir répondu. J'ai fait ce que tu m'as dit. Voici le rapport :
ComboFix 08-10-07.01 - Malou 2008-10-07 19:59:40.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.159 [GMT 2:00]
Lancé depuis: D:\Documents and Settings\Malou\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\WINDOWS\system32\atyuxgbj.ini
D:\WINDOWS\system32\cjhxdrwx.ini
D:\WINDOWS\system32\nvugeytw.ini
D:\WINDOWS\system32\qYaHPXyb.ini
D:\WINDOWS\system32\qYaHPXyb.ini2
D:\WINDOWS\system32\rqluagdt.ini
D:\WINDOWS\system32\xwrdxhjc.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-07 au 2008-10-07 ))))))))))))))))))))))))))))))))))))
.
2008-10-07 17:38 . 2008-10-07 17:38 <REP> d-------- D:\Program Files\Trend Micro
2008-10-07 17:02 . 2008-10-07 17:02 <REP> d-------- D:\Documents and Settings\Malou\Contacts
2008-10-06 23:27 . 2008-10-06 23:27 11,264 --ahs---- D:\WINDOWS\system32\Thumbs.db
2008-09-28 23:24 . 2008-10-07 17:33 <REP> d--h----- D:\$AVG8.VAULT$
2008-09-25 00:29 . 2008-09-25 00:29 <REP> d-------- D:\WINDOWS\system32\Adobe
2008-09-25 00:29 . 2008-09-25 00:29 <REP> d-------- D:\Program Files\Fichiers communs\Vbox
2008-09-25 00:29 . 2001-10-26 23:16 16,384 --a------ D:\WINDOWS\system32\FileOps.exe
2008-09-25 00:23 . 2008-09-25 00:23 <REP> d-------- D:\WINDOWS\Adobe Illustrator CS
2008-09-25 00:00 . 2008-09-27 20:42 <REP> d-------- D:\Documents and Settings\Malou\Application Data\gtk-2.0
2008-09-18 19:26 . 2008-09-18 19:26 <REP> d-------- D:\Program Files\Fichiers communs\Apple
2008-09-18 19:25 . 2008-09-18 19:26 <REP> d-------- D:\Program Files\QuickTime
2008-09-18 19:25 . 2008-09-18 19:25 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-18 19:24 . 2008-09-18 19:24 <REP> d-------- D:\Program Files\Apple Software Update
2008-09-18 19:24 . 2008-09-18 19:24 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Apple
2008-09-14 22:41 . 2008-04-13 19:33 221,184 --a------ D:\WINDOWS\system32\wmpns.dll
2008-09-13 19:36 . 2008-09-13 19:36 45 ---h----- D:\WINDOWS\dbac9524.dat
2008-09-13 19:07 . 2008-10-06 00:02 69 --a------ D:\WINDOWS\NeroDigital.ini
2008-09-13 19:05 . 2008-09-13 19:06 <REP> d-------- D:\Program Files\PhotoFiltre Studio
2008-09-13 18:53 . 2008-04-13 19:33 159,232 --a------ D:\WINDOWS\system32\ptpusd.dll
2008-09-13 18:53 . 2008-04-13 11:45 15,104 --a------ D:\WINDOWS\system32\drivers\usbscan.sys
2008-09-13 18:53 . 2008-04-13 11:45 15,104 --a--c--- D:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-13 18:53 . 2001-08-23 17:47 5,632 --a------ D:\WINDOWS\system32\ptpusb.dll
2008-09-11 00:48 . 2008-09-11 00:48 <REP> d-------- D:\WINDOWS\Sun
2008-09-08 19:33 . 2008-09-08 19:33 <REP> d-------- D:\Documents and Settings\Malou\Application Data\Nero
2008-09-08 19:31 . 2008-09-08 19:32 <REP> d-------- D:\Program Files\Nero
2008-09-08 19:31 . 2008-09-08 19:31 <REP> d-------- D:\Program Files\Fichiers communs\Nero
2008-09-08 19:31 . 2008-09-08 19:31 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Nero
2008-09-08 19:31 . 2006-03-17 11:45 1,757,184 --a------ D:\WINDOWS\system32\imagX7.dll
2008-09-08 19:31 . 2006-03-17 11:45 802,816 --a------ D:\WINDOWS\system32\imagXRA7.dll
2008-09-08 19:31 . 2006-03-17 11:45 497,296 --a------ D:\WINDOWS\system32\imagXpr7.dll
2008-09-08 19:31 . 2006-03-17 14:49 368,640 --a------ D:\WINDOWS\system32\TwnLib4.dll
2008-09-08 19:31 . 2006-03-17 11:45 258,048 --a------ D:\WINDOWS\system32\imagXR7.dll
2008-09-08 01:14 . 2008-09-08 19:29 27,033,807 --a------ D:\Nero.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 20:59 --------- d-----w D:\Program Files\BitComet
2008-10-06 20:58 --------- d-----w D:\Program Files\FoxTarot4
2008-10-06 20:29 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-24 22:29 --------- d-----w D:\Program Files\Fichiers communs\Adobe
2008-09-24 22:26 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-09-20 12:08 --------- d-----w D:\Program Files\OpenOffice.org 2.4
2008-09-20 12:05 --------- d-----w D:\Program Files\Google
2008-09-11 19:06 --------- d-----w D:\Program Files\Neuf
2008-09-04 20:16 --------- d-----w D:\Program Files\Spybot - Search & Destroy
2008-09-03 21:37 --------- d-----w D:\Documents and Settings\Malou\Application Data\Inkscape
2008-09-03 21:35 --------- d-----w D:\Program Files\Inkscape
2008-09-02 22:55 --------- d-----w D:\Documents and Settings\Malou\Application Data\Winamp
2008-08-30 10:12 97,928 ----a-w D:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-26 12:56 --------- d-----w D:\Program Files\SweetIM
2008-08-26 12:56 --------- d-----w D:\Documents and Settings\All Users\Application Data\SweetIM
2008-08-26 01:04 --------- d-----w D:\Program Files\MSXML 4.0
2008-08-25 11:32 --------- d-----w D:\Program Files\Microsoft.NET
2008-08-25 01:19 --------- d-----w D:\Program Files\MSBuild
2008-08-25 01:19 --------- d-----w D:\Program Files\Microsoft Works
2008-08-25 01:02 720,896 ----a-w D:\WINDOWS\iun6002.exe
2008-08-25 01:02 --------- d-----w D:\Program Files\CDImage GUI
2008-08-24 23:45 --------- d-----w D:\Documents and Settings\Malou\Application Data\OpenOffice.org2
2008-08-22 19:12 --------- d-----w D:\Program Files\Picasa2
2008-08-22 15:51 --------- d-----w D:\Program Files\Java
2008-08-22 15:46 --------- d-----w D:\Program Files\Winamp
2008-08-22 15:41 --------- d-----w D:\Program Files\VideoLAN
2008-08-22 15:38 --------- d-----w D:\Documents and Settings\Malou\Application Data\vlc
2008-08-22 14:51 76,040 ----a-w D:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-20 08:24 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-20 08:12 20,747 ----a-w D:\WINDOWS\system32\drivers\AegisP.sys
2008-08-20 08:12 --------- d-----w D:\Program Files\OLITEC
2008-08-20 08:11 --------- d-----w D:\Program Files\Fichiers communs\InstallShield
2008-08-20 08:06 --------- d-----w D:\Program Files\ma-config.com
2008-08-20 08:06 --------- d-----w D:\Documents and Settings\All Users\Application Data\ma-config.com
2008-08-20 07:42 --------- d-----w D:\Program Files\Fichiers communs\Java
2008-08-20 07:36 --------- d-----w D:\Program Files\MSN Messenger
2008-08-20 07:35 10,520 ----a-w D:\WINDOWS\system32\avgrsstx.dll
2008-08-20 07:35 --------- d-----w D:\Program Files\AVG
2008-08-20 07:35 --------- d-----w D:\Documents and Settings\All Users\Application Data\avg8
2008-08-20 07:16 --------- d-----w D:\Program Files\VIA
2008-08-19 20:24 --------- d-----w D:\Program Files\microsoft frontpage
2008-08-19 20:22 --------- d-----w D:\Program Files\Services en ligne
2008-07-18 20:10 94,920 ----a-w D:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w D:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w D:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w D:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w D:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w D:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w D:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w D:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w D:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w D:\WINDOWS\system32\muweb.dll
2008-07-07 20:28 253,952 ----a-w D:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Picasa Media Detector"="D:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="D:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Autoconfigurateur WiFi Neuf"="D:\Program Files\Neuf\Kit\WiFi\9wifi.exe" [2006-12-15 139264]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SweetIM"="D:\Program Files\SweetIM\Messenger\SweetIM.exe" [2008-07-06 111928]
"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [2008-08-04 36352]
"QuickTime Task"="D:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 D:\WINDOWS\SOUNDMAN.EXE]
"VTTrayp"="VTtrayp.exe" [2004-06-22 D:\WINDOWS\system32\VTTrayp.exe]
"VTTimer"="VTTimer.exe" [2004-09-01 D:\WINDOWS\system32\VTTimer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]
D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - D:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2008-09-25 110592]
Lancement rapide de Microsoft Office OneNote 2003.lnk - D:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
Moniteur reseau 802.11g OLITEC.lnk - D:\Program Files\OLITEC\Common\RaUI.exe [2008-08-20 618496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"=
"D:\Program Files\Neuf\Media Center\httpd\httpd.exe"= D:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11304:TCP"= 11304:TCP:BitComet 11304 TCP
"11304:UDP"= 11304:UDP:BitComet 11304 UDP
R1 AvgLdx86;AVG AVI Loader Driver x86;D:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG8 E-mail Scanner;D:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG8 WatchDog;D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG8 Network Redirector;D:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-22 76040]
R3 PCASp50;PCASp50 NDIS Protocol Driver;D:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 20096]
S3 maconfservice;Ma-Config Service;D:\Program Files\ma-config.com\maconfservice.exe [2008-07-25 191656]
.
Contenu du dossier 'Tâches planifiées'
2008-09-18 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- D:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
BHO-{EEE6C35C-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
BHO-{F72C3477-DA0C-447E-BF01-D8324982868E} - D:\WINDOWS\system32\byXPHaYq.dll
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
Notify-opnnopOG - opnnopOG.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - D:\Documents and Settings\Malou\Application Data\Mozilla\Firefox\Profiles\w9kdwfqy.default\
FF -: plugin - D:\Program Files\ma-config.com\nphardwaredetection.dll
FF -: plugin - D:\Program Files\Picasa2\npPicasa2.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-07 20:07:18
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
D:\WINDOWS\system32\slserv.exe
D:\Program Files\AVG\AVG8\avgrsx.exe
D:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-10-07 20:14:28 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-07 18:14:17
Avant-CF: 31 646 253 056 octets libres
Après-CF: 31,631,360,000 octets libres
195 --- E O F --- 2008-09-10 17:45:30