Hello,
Ok action exécutée, voici le rapport de combofix
______________________________________________________
CHRISTINE - 06-12-27 20:15:27,51 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\CHRISTINE\Bureau"
((((((((((((((((((((((((((((((( Files Created from 2006-11-27 to 2006-12-27 ))))))))))))))))))))))))))))))))))
2006-12-27 20:03 <REP> d-------- C:\Program Files\Fnacmusic
2006-12-27 00:34 <REP> d-------- C:\Program Files\ewido anti-spyware 4.0
2006-12-27 00:27 <REP> dr-h----- C:\Documents and Settings\CHRISTINE\Recent
2006-12-27 00:19 <REP> d-------- C:\Program Files\CCleaner
2006-12-26 18:48 <REP> d-------- C:\WINDOWS\pss
2006-12-26 07:06 3,522 --a------ C:\WINDOWS\system32\tmp.reg
2006-12-26 07:05 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2006-12-26 07:05 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-12-26 07:05 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2006-12-26 07:05 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-12-26 07:05 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-12-26 07:05 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-12-26 03:08 94,258 --a------ C:\Program Files\fsld32.dll
2006-12-26 03:08 70,896 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
2006-12-26 03:08 360,448 --a------ C:\Program Files\fsuninst.exe
2006-12-26 03:08 33,584 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
2006-12-26 03:08 229,376 --a------ C:\Program Files\fsisu.dll
2006-12-26 03:08 151,552 --a------ C:\Program Files\fsdeph.dll
2006-12-26 03:08 135,168 --a------ C:\Program Files\fsisuNT.dll
2006-12-26 03:08 <REP> d-------- C:\Program Files\TNB
2006-12-26 03:08 <REP> d-------- C:\Program Files\Spam Control
2006-12-26 03:08 <REP> d-------- C:\Program Files\FWES
2006-12-26 03:08 <REP> d-------- C:\Program Files\FW
2006-12-26 03:08 <REP> d-------- C:\Program Files\FSGUI
2006-12-26 03:08 <REP> d-------- C:\Program Files\DAAS
2006-12-26 03:08 <REP> d-------- C:\Program Files\Anti-Virus
2006-12-26 03:08 <REP> d-------- C:\Program Files\Anti-Spyware
2006-12-26 03:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\F-Secure
2006-12-26 03:03 <REP> d-------- C:\Program Files\Common
2006-12-26 03:02 118,842 -r------- C:\WINDOWS\bwUnin-6.3.2.123-6588780L.exe
2006-12-26 02:37 <REP> d-------- C:\Program Files\Wanadoo
2006-12-26 02:37 <REP> d-------- C:\Program Files\Messager Wanadoo
2006-12-26 00:12 <REP> d-------- C:\Program Files\Securitoo AntiVirus
2006-12-25 16:37 <REP> d-------- C:\Documents and Settings\CHRISTINE\Application Data\Lavasoft
2006-12-25 02:51 20,992 --a------ C:\WINDOWS\system32\cthkpcv.dll
2006-12-09 01:36 <REP> d--h-c--- C:\WINDOWS\ie7
2006-12-09 01:36 <REP> d-------- C:\WINDOWS\WBEM
2006-12-09 01:36 <REP> d-------- C:\WINDOWS\system32\fr-fr
2006-12-09 01:34 121,856 --------- C:\WINDOWS\system32\xmllite.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-26 08:23 -------- d-------- C:\Documents and Settings\CHRISTINE\Application Data\F-Secure
2006-12-26 04:52 -------- d--h----- C:\Program Files\Zero G Registry
2006-12-26 04:51 -------- d-------- C:\Program Files\Fichiers communs\Services
2006-12-26 04:51 -------- d-------- C:\Program Files\Fichiers communs
2006-12-26 04:49 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-12-26 04:43 -------- d-------- C:\Program Files\Canon
2006-12-26 03:08 1445 --a------ C:\Program Files\install.ini
2006-12-26 00:12 24576 --a--c--- C:\WINDOWS\TEMPIadHide3.dll
2006-12-23 03:03 -------- d-------- C:\Program Files\Norton Utilities
2006-12-21 01:03 -------- d-------- C:\Program Files\Outlook Express
2006-12-21 01:03 -------- d-------- C:\Program Files\Fichiers communs\System
2006-12-19 00:34 -------- d-------- C:\Program Files\Internet Explorer
2006-12-07 07:40 2362184 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-10-20 02:38 716800 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-17 12:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-10-17 12:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-17 12:05 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:05 105984 --a------ C:\WINDOWS\system32\url.dll
2006-10-17 12:04 101376 --a------ C:\WINDOWS\system32\occache.dll
2006-10-17 12:03 17408 --a------ C:\WINDOWS\system32\corpol.dll
2006-10-17 11:58 61952 --------- C:\WINDOWS\system32\icardie.dll
2006-10-17 11:58 12288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 11:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-17 11:57 266752 --------- C:\WINDOWS\system32\iertutil.dll
2006-10-17 11:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-10-17 11:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-17 11:27 380928 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-10-13 13:36 145920 --a------ C:\WINDOWS\system32\nwprovau.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"ATIPTA"="C:\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"ACTIVBOARD"="c:\\apps\\ABoard\\ABoard.exe"
"ADUserMon"="C:\\Program Files\\Iomega\\AutoDisk\\ADUserMon.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"WooCnxMon"="C:\\PROGRA~1\\Wanadoo\\CnxMon.exe"
"MessagerStarter Wanadoo"="C:\\PROGRA~1\\MESSAG~1\\StartMessager.exe Messager Wanadoo"
"WOOWATCH"="C:\\PROGRA~1\\Wanadoo\\Watch.exe"
"WOOTASKBARICON"="C:\\Program Files\\Wanadoo\\taskbaricon.exe"
"F-Secure Manager"="\"C:\\Program Files\\Common\\FSM32.EXE\" /splash"
"F-Secure TNB"="\"C:\\Program Files\\TNB\\TNBUtil.exe\" /CHECKALL /WAITFORSW"
"F-Secure Startup Wizard"="\"C:\\Program Files\\FSGUI\\FSSW.EXE\" /reboot"
"News Service"="\"C:\\Program Files\\FSGUI\\ispnews.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
"{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}"="buprestidae"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=hex:95,00,00,00
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDrives"=dword:0000e000
"NoDriveAutoRun"=dword:0000e000
"NoCDBurning"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"isamonitor.exe"="C:\\Program Files\\Video ActiveX Object\\isamonitor.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\HDReg.job
C:\WINDOWS\tasks\Scheduled scanning task.job
Completion time: 06-12-27 20:16:53.79
C:\ComboFix.txt ... 06-12-27 20:16
_____________________________________________________
A+ tard