Excuse moi du temps de réponse .
Ci joint le rapport combofix .
ComboFix 08-11-20.02 - Tanguy 2008-11-21 17:15:09.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.99 [GMT 1:00]
Lancé depuis: c:\documents and settings\Tanguy\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\10.tmp
c:\windows\12.tmp
c:\windows\4.tmp
c:\windows\5.tmp
c:\windows\6.tmp
c:\windows\7.tmp
c:\windows\8.tmp
c:\windows\9.tmp
c:\windows\A.tmp
c:\windows\B.tmp
c:\windows\C.tmp
c:\windows\D.tmp
c:\windows\E.tmp
c:\windows\F.tmp
c:\windows\system32\_000006_.tmp.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-21 au 2008-11-21 ))))))))))))))))))))))))))))))))))))
.
2008-11-09 16:00 . 2008-11-09 16:00 <REP> d-------- c:\windows\ERUNT
2008-11-09 15:51 . 2008-11-09 17:37 <REP> d-------- C:\SDFix
2008-11-09 13:55 . 2008-11-19 19:32 250 --a------ c:\windows\gmer.ini
2008-10-29 21:26 . 2008-10-03 18:12 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-10-29 21:26 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-10-29 21:26 . 2007-03-08 06:10 1,048,576 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-10-29 21:26 . 2008-08-26 09:11 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-10-29 21:26 . 2008-08-26 09:11 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-10-29 21:26 . 2008-08-26 09:11 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-10-29 21:26 . 2008-08-26 09:11 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-10-29 21:26 . 2008-08-26 09:11 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-10-29 21:26 . 2008-08-25 09:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-10-29 21:25 . 2008-10-29 21:29 <REP> d-------- c:\windows\system32\fr-fr
2008-10-29 21:05 . 2007-08-13 18:54 33,792 --a--c--- c:\windows\system32\dllcache\custsat.dll
2008-10-29 20:30 . 2008-10-29 20:30 <REP> d-------- c:\documents and settings\Zim\Application Data\Auslogics
2008-10-29 20:29 . 2008-10-29 20:29 <REP> d-------- c:\program files\Auslogics
2008-10-29 18:24 . 2008-10-29 20:52 <REP> d-------- c:\windows\system32\CatRoot_bak
2008-10-25 17:48 . 2008-10-25 17:48 <REP> d-------- c:\documents and settings\Zim\Application Data\PCToolsFirewallPlus
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 19:36 --------- d-----w c:\documents and settings\Zim\Application Data\SiteAdvisor
2008-11-19 18:33 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-19 18:33 --------- d-----w c:\program files\SpywareBlaster
2008-11-17 18:48 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-07 19:07 --------- d-----w c:\program files\Fichiers communs\Real
2008-10-28 17:13 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 15:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-08 18:40 --------- d-----w c:\program files\CCleaner
2008-10-01 17:07 --------- d-----w c:\documents and settings\Tanguy\Application Data\Malwarebytes
2007-04-16 15:53 150,528 ------w c:\program files\Fichiers communs\WLJ.exe
2007-04-16 15:53 146,944 ------w c:\program files\Fichiers communs\EyS.exe
2007-04-16 15:53 143,360 ------w c:\program files\Fichiers communs\vCIY.exe
2007-04-16 15:53 129,536 ------w c:\program files\Fichiers communs\nnZb.exe
2001-08-28 12:00 74,240 ------w c:\program files\Fichiers communs\EtK.exe
2001-08-28 12:00 103,936 ------w c:\program files\Fichiers communs\hPkwM.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-20 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-20 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
--a------ 2004-08-20 00:09 160768 c:\windows\PCHEALTH\HELPCTR\Binaries\msconfig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R3 trid3d;trid3d;c:\windows\system32\DRIVERS\trid3dm.sys [2006-09-08 222336]
S3 alcan5ln;SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\DRIVERS\alcan5ln.sys [2006-09-08 36256]
S3 NtApm;Pilote d'interface NT APM/hérité;c:\windows\system32\DRIVERS\NtApm.sys [2006-09-08 9472]
S4 hpt3xx;hpt3xx; []
.
- - - - ORPHELINS SUPPRIMES - - - -
HKU-Default-Run-Windows installer - C:\winstall.exe
MSConfigStartUp-TkBellExe - c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\Tanguy\Application Data\Mozilla\Firefox\Profiles\e6h6p927.default\
FF -: plugin - c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-21 17:23:55
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SecVmd]
"ImagePath"="\"c:\program files\Fichiers communs\Services\enQ.exe\""
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-11-21 17:28:46 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-21 16:28:36
Avant-CF: 25.996.402.688 octets libres
Après-CF: 25,945,948,160 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
144 --- E O F --- 2008-11-12 19:09:38
Même si cela peut te sembler bizarre , l'antislash est supprimé à chaque fois que je copie/colle du texte .