Voici le rapport combofix :
ComboFix 08-12-01.03 - Nicolas 2008-12-02 22:24:50.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.281 [GMT 1:00]
Lancé depuis: c:\documents and settings\Nicolas\Bureau\téléchargement firefox\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
.
2008-12-02 20:43 . 2008-12-02 20:43 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-02 20:41 . 2008-12-02 20:41 <REP> d-------- c:\windows\ERUNT
2008-12-02 20:33 . 2008-12-02 21:25 <REP> d-------- C:\SDFix
2008-12-01 21:22 . 2008-12-01 21:46 <REP> d-------- C:\ToolBar SD
2008-11-30 21:33 . 2008-11-30 21:33 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-30 21:33 . 2008-11-30 21:33 <REP> d-------- c:\documents and settings\Nicolas\Application Data\Malwarebytes
2008-11-30 21:33 . 2008-11-30 21:33 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-30 21:33 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-30 21:33 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-30 17:10 . 2008-11-30 17:24 <REP> d-------- c:\program files\UsbFix
2008-11-30 11:37 . 2008-11-30 11:37 <REP> d-------- C:\QUARANTINE
2008-11-30 11:19 . 2008-11-30 11:19 <REP> d-------- c:\windows\report
2008-11-30 11:19 . 2008-11-30 11:18 21,137,485 --a------ c:\windows\LPT$VPN.681
2008-11-30 11:18 . 2008-11-30 11:18 <REP> d-------- c:\windows\AU_Backup
2008-11-30 11:18 . 2008-11-30 11:18 21,137,485 --a------ c:\windows\VPTNFILE.681
2008-11-30 11:18 . 2008-11-30 11:18 1,971,953 --a------ c:\windows\tsc.ptn
2008-11-30 11:18 . 2008-11-30 11:18 1,213,784 --a------ c:\windows\vsapi32.dll
2008-11-30 11:18 . 2008-11-30 11:18 345,157 --a------ c:\windows\tsc.exe
2008-11-30 11:18 . 2008-11-30 11:18 91,744 --a------ c:\windows\BPMNT.dll
2008-11-30 11:18 . 2008-11-30 11:18 71,749 --a------ c:\windows\hcextoutput.dll
2008-11-30 11:18 . 2008-11-30 11:21 823 --a------ c:\windows\tsc.ini
2008-11-30 11:16 . 2008-11-30 11:18 <REP> d-------- c:\windows\AU_Temp
2008-11-30 11:16 . 2008-11-30 11:16 <REP> d-------- c:\windows\AU_Log
2008-11-30 11:16 . 2008-11-30 11:16 507,904 --a------ c:\windows\TMUPDATE.DLL
2008-11-30 11:16 . 2008-11-30 11:16 69,689 --a------ c:\windows\UNZIP.DLL
2008-11-30 11:16 . 2008-11-30 11:16 170 --a------ c:\windows\GetServer.ini
2008-11-30 11:15 . 2008-11-30 11:15 286,720 --a------ c:\windows\PATCH.EXE
2008-11-12 11:07 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 11:06 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-11 12:17 . 2008-11-11 13:11 <REP> d-------- c:\documents and settings\Nicolas\.jenny
2008-11-11 11:42 . 2008-11-11 11:42 <REP> d-------- c:\program files\Windows Installer Clean Up
2008-11-11 11:40 . 2008-11-11 11:40 <REP> d-------- c:\program files\MSECACHE
2008-11-09 20:18 . 2008-11-09 20:18 268 --ah----- C:\sqmdata02.sqm
2008-11-09 20:18 . 2008-11-09 20:18 244 --ah----- C:\sqmnoopt02.sqm
2008-11-02 17:16 . 2008-11-02 17:17 <REP> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-02 17:14 . 2008-11-02 17:14 <REP> d-------- c:\program files\Bonjour
2008-11-02 17:07 . 2008-11-02 17:07 <REP> d-------- c:\program files\Apple Software Update
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 20:47 --------- d-----w c:\documents and settings\Nicolas\Application Data\BitTorrent
2008-11-02 16:13 --------- d-----w c:\program files\QuickTime
2008-11-02 16:10 --------- d-----w c:\program files\Fichiers communs\Apple
2008-11-02 12:39 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-18 16:28 --------- d-----w c:\documents and settings\Nicolas\Application Data\OfficeUpdate12
2008-10-18 16:24 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-10-12 16:53 --------- d-----w c:\program files\DNA
2008-10-12 16:53 --------- d-----w c:\documents and settings\Nicolas\Application Data\DNA
2008-10-12 14:06 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-12 13:53 --------- d-----w c:\documents and settings\Nicolas\Application Data\Azureus
2008-10-12 13:31 --------- d-----w c:\documents and settings\All Users\Application Data\Azureus
2008-10-12 13:30 --------- d-----w c:\program files\AskSBar
2008-10-10 13:51 --------- d-----w c:\documents and settings\Nicolas\Application Data\ICAClient
2008-10-10 13:44 --------- d-----w c:\program files\Citrix
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2001-11-23 04:08 712,704 ----a-w c:\windows\inf\OTHER\AUDIO3D.DLL
2006-05-06 16:42 7,260,160 ----a-w c:\program files\mozilla firefox\plugins\libvlc.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 94208]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2006-07-25 131072]
"Network Associates Error Reporting Service"="c:\program files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2003-10-07 147514]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-05-21 221184]
"HTpatch"="c:\windows\htpatch.exe" [2002-10-30 28672]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="d:\programmes\itunes\iTunesHelper.exe" [2008-10-01 289576]
"NielsenOnline"="c:\program files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2007-11-16 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-10 113664]
D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-05-10 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 2200 Series]
--a------ 2004-02-13 14:13 57344 c:\program files\Lexmark 2200 Series\lxbvbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--------- 2004-06-01 11:46 196608 c:\program files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--------- 2004-06-01 10:09 458752 c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--------- 2004-06-01 10:03 217088 c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2006-09-12 17:07 1175552 c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"d:\\programmes\\BitTorrent\\bittorrent.exe"=
"d:\\programmes\\eMule\\emule.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\programmes\\itunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:PORT TCP EMULE
"4672:UDP"= 4672:UDP:PORT UDP EMULE
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2008-05-10 58464]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [2008-06-02 14336]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [2008-06-02 8832]
S4 Briarbpi_s;Briarbpi_s; []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b16ea7cb-3afe-11dd-b101-000b6a41a194}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - I:\Boot.exe e
*Newly Created Service* - ENTDRV51
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-NWEReboot - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\11zvc5bs.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://id.orange.fr/auth_user/bin/auth_user.cgi?service=communiquer&url=http://www.orange.fr/...
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\np_gp.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npvlc.dll
FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
FF -: plugin - d:\programmes\itunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 22:26:25
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HTpatch = c:\windows\htpatch.exe?ows\CurrentVersion\Run???\???]??[???????[???[???????????????? ??[???[?L?????[$??????[????????????{??[???????????[$??~????(????~:~???~?????~:~???~???[@???????d????? [%??[x??[???????[,>?[???[v?:~Z|?[{3?[?2?[????st.I????G? [????d????<?[?I?[
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(568)
c:\windows\system32\EntApi.dll
.
Heure de fin: 2008-12-02 22:27:38
ComboFix-quarantined-files.txt 2008-12-02 21:27:12
Avant-CF: 27 782 283 264 octets libres
Après-CF: 27,803,459,584 octets libres
190 --- E O F --- 2008-11-12 18:27:32