Voici ce que combofix a dit :
ComboFix 08-12-17.01 - Nicolas 2008-12-18 22:49:02.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2047.1608 [GMT 1:00]
Lancé depuis: d:documents and settingsNicolasBureauComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
d:windowssystem32appcert
d:windowssystem32dataclenn.dll . . . . impossible à supprimer
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-18 au 2008-12-18 ))))))))))))))))))))))))))))))))))))
.
2008-12-18 21:32 . 2008-12-18 22:48 <REP> d--h----- d:windows$hf_mig$
2008-12-18 21:30 . 2008-10-16 21:18 6,066,176 -----c--- d:windowssystem32dllcacheieframe.dll
2008-12-18 21:30 . 2007-04-17 10:32 2,455,488 -----c--- d:windowssystem32dllcacheieapfltr.dat
2008-12-18 21:30 . 2007-03-08 06:10 1,048,576 -----c--- d:windowssystem32dllcacheieframe.dll.mui
2008-12-18 21:30 . 2008-10-16 21:18 459,264 -----c--- d:windowssystem32dllcachemsfeeds.dll
2008-12-18 21:30 . 2008-10-16 21:18 383,488 -----c--- d:windowssystem32dllcacheieapfltr.dll
2008-12-18 21:30 . 2008-10-16 21:18 267,776 -----c--- d:windowssystem32dllcacheiertutil.dll
2008-12-18 21:30 . 2008-10-16 21:18 63,488 -----c--- d:windowssystem32dllcacheicardie.dll
2008-12-18 21:30 . 2008-10-16 21:18 52,224 -----c--- d:windowssystem32dllcachemsfeedsbs.dll
2008-12-18 21:30 . 2008-10-16 14:11 13,824 -----c--- d:windowssystem32dllcacheieudinit.exe
2008-12-18 20:59 . 2008-04-13 19:33 221,184 --a------ d:windowssystem32wmpns.dll
2008-12-18 20:58 . 2008-12-18 20:58 <REP> d-------- d:documents and settingsLocalServiceMenu Démarrer
2008-12-18 20:50 . 2008-12-18 21:34 <REP> d-------- d:windowssystem32fr-fr
2008-12-18 20:49 . 2008-12-18 20:49 <REP> d-------- d:windowsServicePackFiles
2008-12-18 20:49 . 2007-08-13 18:54 33,792 --a--c--- d:windowssystem32dllcachecustsat.dll
2008-12-18 20:47 . 2006-12-28 12:01 19,569 --a------ d:windows
002680_.tmp
2008-12-18 20:47 . 2008-12-18 21:34 1,393 --a------ d:windowsimsins.BAK
2008-12-18 20:46 . 2008-12-18 20:51 <REP> d-------- d:windowsEHome
2008-12-01 21:23 . 2008-12-01 21:34 754 --a------ d:windowsWORDPAD.INI
2008-11-26 21:40 . 2008-11-26 21:40 <REP> d-------- d:documents and settingsNicolasApplication Datavlc
2008-11-23 11:21 . 2008-11-25 20:23 <REP> d-------- d:documents and settingsNicolasApplication DataLimeWire
2008-11-23 11:20 . 2008-12-02 21:34 <REP> d-------- d:program filesJava
2008-11-23 11:20 . 2008-11-10 05:43 410,984 --a------ d:windowssystem32deploytk.dll
2008-11-23 11:20 . 2008-11-10 03:39 73,728 --a------ d:windowssystem32javacpl.cpl
2008-11-23 01:02 . 2008-11-23 01:02 <REP> d-------- d:program filesvotre_repertoire_cstrike
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 21:52 --------- d-----w d:program filesAvast4
2008-12-18 21:51 105,984 ----a-w d:windowssystem32hpslitppl.dll
2008-12-16 16:41 --------- d-----w d:documents and settingsAll UsersApplication DataSpybot - Search & Destroy
2008-12-09 16:56 --------- d-----w d:program filesmIRC
2008-12-05 17:44 --------- d-----w d:program filesMetin2_France
2008-12-02 21:27 --------- d--h--w d:program filesInstallShield Installation Information
2008-11-23 18:44 --------- d-----w d:program filesVideoLAN
2008-11-23 16:24 --------- d-----w d:program filesValve
2008-10-16 20:18 826,368 ----a-w d:windowssystem32wininet.dll
2008-10-16 13:13 202,776 ----a-w d:windowssystem32wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w d:windowssystem32wuaueng.dll
2008-10-16 13:12 561,688 ----a-w d:windowssystem32wuapi.dll
2008-10-16 13:12 323,608 ----a-w d:windowssystem32wucltui.dll
2008-10-16 13:09 92,696 ----a-w d:windowssystem32cdm.dll
2008-10-16 13:09 51,224 ----a-w d:windowssystem32wuauclt.exe
2008-10-16 13:09 43,544 ----a-w d:windowssystem32wups2.dll
2008-10-16 13:08 34,328 ----a-w d:windowssystem32wups.dll
2002-08-29 09:44 384 --sha-r d:windowsinfsdatabl.sav.bin
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE~Browser Helper Objects{8636E810-11CB-4290-9044-DAE459D672E3}]
2008-12-18 22:51 105984 --a------ d:windowssystem32dataclenn.dll
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"SpybotSD TeaTimer"="d:program filesSpybot - Search & DestroyTeaTimer.exe" [2008-01-28 2097488]
"ctfmon.exe"="d:windowssystem32ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="d:windowsSystem32NvCpl.dll" [2007-10-04 8491008]
"avast!"="d:progra~1Avast4ashDisp.exe" [2008-11-26 81000]
"SunJavaUpdateSched"="d:program filesJavajre6injusched.exe" [2008-11-10 136600]
"nwiz"="nwiz.exe" [2007-10-04 d:windowssystem32
wiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 d:windowsRTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 d:windowsAlcmtr.exe]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="d:windowsSystem32CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon
otifypgzttqcn]
2008-12-18 22:51 105984 d:windowssystem32dataclenn.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
--a------ 2007-10-04 17:14 81920 d:windowssystem32
vmctray.dll
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"%windir%\system32\sessmgr.exe"=
R0 irgwrilj;irgwrilj;d:windowssystem32driversirgwrilj.sys [2001-08-28 23424]
R0 tffsport;M-Systems DiskOnChip 2000;d:windowssystem32DRIVERS ffsport.sys [2008-09-26 149376]
R1 aswSP;avast! Self Protection;d:windowssystem32driversaswSP.sys [2008-08-08 111184]
R2 aswFsBlk;aswFsBlk;d:windowssystem32DRIVERSaswFsBlk.sys [2008-12-18 20560]
S2 halhpjcw;AGP Bus v038c Helper;d:windowsSystem32svchost.exe -k netsvcs [2001-08-28 14336]
S3 ESLvnic1;ESLvnic Virtual Network 32 Bit;d:windowssystem32DRIVERSESLvnic.sys [2008-05-01 20216]
S3 SetupNTGLM7X;SetupNTGLM7X;??E:NTGLM7X.sys []
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs
halhpjcw
.
.
------- Examen supplémentaire -------
.
O16 -: DirectAnimation Java Classes -
file://d:windowsJavaclassesdajava.cab
d:windowsDownloaded Program FilesDirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java -
file://d:windowsJavaclassesxmldso.cab
d:windowsDownloaded Program FilesMicrosoft XML Parser for Java.osd
FF - ProfilePath - d:documents and settingsNicolasApplication DataMozillaFirefoxProfilesqr1cot1u.default
ATTENTION: FIREFOX POLICES IS IN FORCE
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-18 22:51:39
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
d:program filesAvast4aswUpdSv.exe
d:program filesAvast4ashServ.exe
d:program filesJavajre6injqs.exe
d:windowssystem32
vsvc32.exe
d:windowssystem32wdfmgr.exe
d:program filesAvast4ashMaiSv.exe
d:program filesAvast4ashWebSv.exe
d:windowssystem32wbemwmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2008-12-18 22:54:09 - La machine a redémarré [Nicolas]
ComboFix-quarantined-files.txt 2008-12-18 21:54:06
Avant-CF: 52 134 858 752 octets libres
Après-CF: 52,214,292,480 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)WINDOWS
[operating systems]
c:cmdconsBOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
140 --- E O F --- 2008-12-18 21:46:37
merci