Bonsoir synthexe,
voilà, j'ai executé tes consignes. Et voici le rapport Combofix :
ComboFix 07-12-17.1 - macrounet 2007-12-17 21:20:08.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1210 [GMT 1:00]
Running from: C:\Documents and Settings\macrounet\Local Settings\Temporary Internet Files\Content.IE5\1TQFQ7Z7\ComboFix[1].exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-17 to 2007-12-17 ))))))))))))))))))))))))))))))))))))
.
2007-12-15 09:53 . 2007-12-15 09:53 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-15 09:53 . 2007-12-15 09:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-14 09:53 . 2007-12-14 10:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-12 22:03 . 2007-12-15 09:36 <REP> d-------- C:\Program Files\Navilog1
2007-12-12 21:28 . 2007-12-12 21:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-12 21:28 . 2007-12-16 21:56 1,316,896 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-12 21:28 . 2007-12-12 21:28 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-12 21:28 . 2007-06-21 21:54 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-12-12 21:28 . 2007-12-12 21:28 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-12 21:28 . 2007-06-21 21:55 54,672 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-12-12 21:28 . 2007-06-21 21:55 42,384 --a------ C:\WINDOWS\zllsputility_loc040c.dll
2007-12-12 21:28 . 2007-06-21 21:55 21,904 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
2007-12-12 21:28 . 2007-06-21 21:55 17,808 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
2007-12-12 21:28 . 2007-12-16 21:56 16,508 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-12 21:28 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-12-11 22:54 . 2007-12-11 22:54 18,223,652 --a------ C:\upload_moi_SN012345678912.tar.gz
2007-12-11 20:46 . 2007-12-11 20:46 <REP> d-------- C:\Documents and Settings\macrounet\Application Data\Grisoft
2007-12-11 20:46 . 2007-12-11 20:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-11 20:46 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-11 20:44 . 2007-12-11 20:44 <REP> d-------- C:\Program Files\CCleaner
2007-11-18 18:22 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2007-11-18 18:22 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2007-11-18 18:22 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2007-11-18 18:22 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2007-11-18 18:22 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2007-11-18 18:22 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2007-11-18 18:22 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2007-11-18 18:22 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-17 20:15 --------- d-----w C:\Documents and Settings\macrounet\Application Data\Skype
2007-12-17 20:08 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-17 19:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-12-13 05:14 --------- d-----w C:\Program Files\eMule
2007-12-12 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-11 20:45 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-30 19:28 53,248 ----a-w C:\WINDOWS\PalmDevC.dll
2007-03-06 17:25 47,360 ----a-w C:\Documents and Settings\macrounet\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="C:\APPS\SMP\SmpSys.exe" [2005-11-17 08:51]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 06:54]
"Skype"="C:\APPS\skype\phone\Skype.exe" [2007-08-22 23:19]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 13:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 13:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 13:00]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 13:01]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-12 13:36]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 13:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-08-24 17:40 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 13:00 C:\WINDOWS\system32\rundll32.exe]
"ACU"="C:\Program Files\Atheros WLAN Adapter\ACU.exe" [2006-04-14 15:34]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 15:56 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 17:04 C:\WINDOWS\SkyTel.exe]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-04-17 16:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 02:52]
"DetectorApp"="C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe" [2005-10-20 05:15]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 15:50]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 15:50]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-10-13 17:10]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-13 17:22]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 13:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\ATK0100\ASNDIS5.SYS [2004-05-28 09:13]
S2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" []
S3 EAGLE2RC;Analog/DVB-T Hybrid Tv Infrared Receiver;C:\WINDOWS\system32\DRIVERS\Eagle2RC.sys [2006-05-24 15:01]
S3 Eagle2TV;TV tuner device;C:\WINDOWS\system32\Drivers\eagle2tv_B.sys [2006-06-02 10:40]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30cfc2e6-944e-11db-95c3-0015af095c38}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-16 18:30:02 C:\WINDOWS\Tasks\Master CD_DVD Creator.job"
- C:\Apps\SMP\MCDCHECK.EXE
"2007-12-17 19:44:50 C:\WINDOWS\Tasks\User_Feed_Synchronization-{46BB69B5-8E44-47E8-BA7E-E184501755CC}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-17 21:25:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-17 21:30:08 - machine was rebooted
.
2007-12-12 21:37:43 --- E O F ---
J'avoue que je ne compprends pas tous les méandres de ce que tu me fais faire, mais je sens bien que c'est efficace.
Et oui, je n'ai toujours pas été embêté avec ma bestiole...il n'y a plus d'alerte dans tous les sens...mais est-ce bien réparé pour autant ? Là je te fais totalement confiance
Quant à la lecture d'Avast, oui je l'ai faite. ET j'avoue ne plus savoir que penser. C'est la première fois que je lis autant de catastrophe avec Avast. Tout le monde me préconisait Avast comme un excellent antivirus gratuit et internet semblait aller dans ce sens.
Mais visiblement, tu me conseilles carrément de passer à antivir ?
Bonne soirée