Merci, voici le rapport :
ComboFix 08-10-19.03 - Administrateur 2008-10-20 1:04:19.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.0.1252.1.1036.18.294 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
* Resident AV is active
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\plugin1.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-19 au 2008-10-19 ))))))))))))))))))))))))))))))))))))
.
2008-10-18 00:15 . 2008-10-18 00:15 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-18 00:15 . 2008-10-18 00:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-18 00:15 . 2008-10-18 00:15 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-18 00:15 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-18 00:15 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-17 13:05 . 2008-10-17 13:05 <REP> d-------- C:\WINDOWS\LastGood.Tmp
2008-10-17 13:04 . 2008-10-17 13:04 <REP> d-------- C:\ATI
2008-10-15 03:14 . 2008-10-15 03:14 <REP> d-------- C:\de6019e84613bdac55275b474c2f67
2008-10-15 03:04 . 2002-11-14 21:43 221,184 --a------ C:\WINDOWS\system32\srrstr.dll
2008-10-15 03:04 . 2002-11-14 21:43 221,184 --a--c--- C:\WINDOWS\system32\dllcache\srrstr.dll
2008-10-15 03:01 . 2008-10-15 03:12 <REP> d--h-c--- C:\WINDOWS\$xpsp1hfm$
2008-10-15 03:01 . 2003-08-02 06:14 25,600 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2008-10-15 03:00 . 2008-10-15 08:35 1,393 --a------ C:\WINDOWS\imsins.BAK
2008-10-14 18:54 . 2008-10-17 22:15 <REP> d-------- C:\Program Files\Dofus
2008-10-14 17:48 . 2008-10-14 17:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-10-14 17:48 . 2008-10-14 17:48 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\MSN6
2008-10-14 14:08 . 2008-10-14 14:08 <REP> d-------- C:\WINDOWS\system32\bits
2008-10-14 14:07 . 2004-07-02 00:08 360,960 --a--c--- C:\WINDOWS\system32\dllcache\qmgr.dll
2008-10-14 14:07 . 2004-07-02 00:08 331,776 --a------ C:\WINDOWS\system32\winhttp.dll
2008-10-14 14:07 . 2004-07-02 00:08 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-10-14 14:07 . 2004-07-02 00:08 17,408 --a--c--- C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-10-14 14:07 . 2004-07-02 00:08 7,680 -----c--- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-10-14 14:07 . 2004-07-02 00:08 7,680 --------- C:\WINDOWS\system32\bitsprx2.dll
2008-10-14 14:07 . 2004-07-02 00:08 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-10-14 14:07 . 2004-07-02 00:08 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2008-10-14 13:49 . 2003-12-31 10:24 50,523 --------- C:\WINDOWS\UNNMP.cfg
2008-10-14 13:48 . 2003-12-11 14:34 1,318,912 --------- C:\WINDOWS\UNNMP.exe
2008-10-14 13:45 . 2001-07-09 13:50 155,648 -ra------ C:\WINDOWS\system32\NeroCheck.exe
2008-10-14 13:28 . 2008-10-14 13:28 <REP> d-------- C:\Program Files\Lavalys
2008-10-14 12:57 . 2002-12-11 17:34 1,111,040 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2008-10-14 12:56 . 2003-12-11 14:34 1,318,912 --------- C:\WINDOWS\UNNeroVision.exe
2008-10-14 12:56 . 2003-12-31 10:24 105,105 --------- C:\WINDOWS\UNNeroVision.cfg
2008-10-14 12:56 . 2001-03-08 19:30 24,064 -ra------ C:\WINDOWS\system32\msxml3a.dll
2008-10-13 21:13 . 2008-10-13 21:13 4,096 --a------ C:\WINDOWS\system32\crash
2008-10-13 19:04 . 2008-10-14 13:21 <REP> d-------- C:\Program Files\CCleaner
2008-10-13 17:47 . 2008-10-13 17:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2008-10-13 17:44 . 2008-10-13 17:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-13 17:21 . 2008-10-13 17:21 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-10-13 17:21 . 2008-10-13 17:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-10-13 17:20 . 2008-10-13 17:20 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage réseau
2008-10-13 17:20 . 2008-10-13 17:20 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage d'impression
2008-10-13 17:20 . 2008-10-13 16:29 <REP> d--h----- C:\Documents and Settings\Default User\Modèles
2008-10-13 17:20 . 2008-10-13 17:20 <REP> d-------- C:\Documents and Settings\Default User\Mes documents
2008-10-13 17:20 . 2008-10-13 17:20 <REP> dr------- C:\Documents and Settings\Default User\Menu Démarrer
2008-10-13 17:20 . 2008-10-13 17:20 <REP> d-------- C:\Documents and Settings\Default User\Favoris
2008-10-13 17:20 . 2008-10-13 17:20 <REP> d-------- C:\Documents and Settings\Default User\Bureau
2008-10-13 17:20 . 2008-10-13 17:20 <REP> d--h----- C:\Documents and Settings\All Users\Modèles
2008-10-13 17:20 . 2008-10-13 17:19 <REP> dr------- C:\Documents and Settings\All Users\Menu Démarrer
2008-10-13 17:20 . 2008-10-13 17:20 <REP> d-------- C:\Documents and Settings\All Users\Favoris
2008-10-13 17:20 . 2008-10-13 16:30 <REP> dr------- C:\Documents and Settings\All Users\Documents
2008-10-13 17:20 . 2008-10-18 00:15 <REP> d-------- C:\Documents and Settings\All Users\Bureau
2008-10-13 17:19 . 2008-10-13 16:33 <REP> d--h----- C:\Documents and Settings\Default User
2008-10-13 17:19 . 2008-10-13 16:32 <REP> d-------- C:\Documents and Settings\All Users
2008-10-13 17:00 . 2008-10-13 17:03 <REP> d-------- C:\Program Files\Fichiers communs\InstallShield
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 22:41 --------- d-----w C:\Program Files\ESET
2008-10-17 11:10 --------- d-----w C:\Program Files\ATI Technologies
2008-10-14 11:48 --------- d-----w C:\Program Files\Ahead
2008-10-13 16:07 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Talkback
2008-10-13 15:55 502,208 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-10-13 15:55 270,336 ----a-w C:\WINDOWS\system32\imon.dll
2008-10-13 15:10 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\ATI
2008-10-13 15:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-13 15:01 --------- d-----w C:\Program Files\VIA
2008-10-13 14:57 --------- d-----w C:\Program Files\C-Media 3D Audio
2008-10-13 14:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-13 14:31 --------- d-----w C:\Program Files\Services en ligne
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-08-28 13312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-01 339968]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-10-13 917504]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-28 13312]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2001-08-02 07:14 1077277 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
-ra------ 2001-07-09 13:50 155648 C:\WINDOWS\system32\NeroCheck.exe
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\DRIVERS\avgntmgr.sys [2008-01-21 22336]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-05-09 45376]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\o76q7eo0.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.google.fr/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-20 01:05:24
Windows 5.1.2600 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
Heure de fin: 2008-10-20 1:06:26
ComboFix-quarantined-files.txt 2008-10-19 23:06:23
Avant-CF: 114,760,667,136 octets libres
Après-CF: 114,752,827,392 octets libres
139 --- E O F --- 2008-10-16 12:22:10