Aqui les van los nuevos reports y logs:
ComboFix 08-07-08.9 - HP_Propriétaire 2008-07-10 14:35:55.2 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.338 [GMT 2:00]
Endroit: C:\ComboFix\Cbofix.exe
Command switches used :: C:\ComboFix\CFScript.txt
FILE ::
C:\TEMP\stmpv4
C:\WINDOWS\BMab979fee.xml
C:\WINDOWS\system32\5PteOI43.exe
C:\WINDOWS\system32\beep.sys
C:\WINDOWS\system32\dapi
C:\WINDOWS\system32\oi3X8efj.exe
C:\WINDOWS\system32\oi3X8efj.exe.a_a
C:\WINDOWS\system32\ole
C:\WINDOWS\system32\olixds01
C:\WINDOWS\system32\olixds01\olixds011065.exe
C:\WINDOWS\system32\ver
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMab979fee.xml
C:\WINDOWS\system32\5PteOI43.exe
C:\WINDOWS\system32\beep.sys
C:\WINDOWS\system32\oi3X8efj.exe
C:\WINDOWS\system32\oi3X8efj.exe.a_a
C:\WINDOWS\system32\olixds01\olixds011065.exe
.
---- Previous Run -------
.
C:\Documents and Settings\HP_Propriétaire\Application Data\ICROSO~1
C:\Documents and Settings\HP_Propriétaire\Application Data\ICROSO~1\?icrosoft\
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\fnts~1
C:\Program Files\winupdates
C:\Program Files\winupdates\a.zip
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\444.470
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\g32.txt
C:\WINDOWS\IA
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\muotr.so
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\clbdll.old
C:\WINDOWS\system32\clbinit.dll
C:\WINDOWS\system32\cookie.dat
C:\WINDOWS\system32\drivers\clbdriver.sys
C:\WINDOWS\system32\help.txt
C:\WINDOWS\system32\kctkvlko.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\oeminfo.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ps.dat
C:\WINDOWS\system32\sCfOnnmp.ini
C:\WINDOWS\system32\sCfOnnmp.ini2
C:\WINDOWS\system32\ssutBcfe.ini
C:\WINDOWS\system32\ssutBcfe.ini2
C:\WINDOWS\update.exe
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CLBDRIVER
-------\Legacy_DRIVER
-------\Legacy_K53LOCK
-------\Legacy_MSSECURITY1.209.4
-------\Service_Driver
-------\Service_k53lock
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-10 to 2008-07-10 ))))))))))))))))))))))))))))))))))))
.
2008-07-09 12:23 . 2008-07-09 12:45 <REP> d-------- C:\fixwareout
2008-07-09 11:50 . 2008-07-09 12:16 49,074,432 --a------ C:\avg_free_stf_en_8_101a1327.exe
2008-07-08 22:07 . 2008-07-09 09:24 <REP> d-------- C:\WINDOWS\system32\ver
2008-07-08 22:07 . 2008-07-10 14:36 <REP> d-------- C:\WINDOWS\system32\olixds01
2008-07-08 22:07 . 2008-07-08 22:07 <REP> d-------- C:\WINDOWS\system32\ole
2008-07-08 22:07 . 2008-07-09 09:24 <REP> d-------- C:\WINDOWS\system32\IP3
2008-07-08 22:07 . 2008-07-09 09:24 <REP> d-------- C:\WINDOWS\system32\dapi
2008-07-08 22:07 . 2008-07-08 22:07 <REP> d-------- C:\TEMP\stmpv4
2008-07-03 08:09 . 2008-07-03 08:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-03 08:09 . 2008-07-03 08:09 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-25 11:05 . 2008-06-25 11:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\QubeSoft
2008-06-25 11:02 . 2008-06-25 11:02 <REP> d-------- C:\Program Files\LEGO Software
2008-06-14 18:46 . 2008-06-14 18:46 <REP> d-------- C:\Program Files\BayGenie
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 08:32 --------- d-----w C:\Program Files\Fichiers communs\SureThing Shared
2008-06-25 09:05 --------- d-----w C:\Program Files\LEGO Company
2008-06-24 06:16 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-06-11 00:35 --------- d-----w C:\Program Files\eMule
2008-06-09 10:54 --------- d-----w C:\Program Files\Picasa2
2008-06-09 10:51 --------- d-----w C:\Program Files\Google
2008-05-31 14:29 --------- d-----w C:\Program Files\Oxin's Style!
2008-05-10 19:51 --------- d-----w C:\Program Files\Spyware Terminator
2008-05-10 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-10 19:16 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-05-10 19:16 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-05-10 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2005-08-31 08:09 24 ----a-w C:\Program Files\lista.txt
2007-06-21 17:38 30,280 ----a-w C:\Program Files\mozilla firefox\plugins\cgpcfg.dll
2007-06-21 17:38 79,432 ----a-w C:\Program Files\mozilla firefox\plugins\CgpCore.dll
2007-06-21 17:38 71,240 ----a-w C:\Program Files\mozilla firefox\plugins\confmgr.dll
2007-06-21 17:38 140,872 ----a-w C:\Program Files\mozilla firefox\plugins\ctxmui.dll
2007-06-21 17:39 38,472 ----a-w C:\Program Files\mozilla firefox\plugins\icafile.dll
2007-06-21 17:39 46,664 ----a-w C:\Program Files\mozilla firefox\plugins\icalogon.dll
2007-06-21 17:39 34,376 ----a-w C:\Program Files\mozilla firefox\plugins\logging.dll
2007-06-21 17:39 685,640 ----a-w C:\Program Files\mozilla firefox\plugins\sslsdk_b.dll
2007-06-21 17:40 30,280 ----a-w C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
.
((((((((((((((((((((((((((((( snapshot[arroba]2008-07-09_21.04.33.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-09 18:52:47 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-10 12:42:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 12:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 14:47 7311360]
"SNPSTD2"="C:\WINDOWS\vsnpstd2.exe" [2004-06-10 12:54 286720]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
"{C738F3D2-1891-449D-AE67-D1969094F1DF}"= "C:\WINDOWS\system32\yayyVonK.dll" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.sl_anet"= C:\PROGRA~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.3ivx"= C:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv0"= C:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv1"= C:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv2"= C:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3ivd"= C:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"msacm.msaudio1"= C:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm
"vidc.mjpg"= C:\PROGRA~1\ACEMEG~1\SystemS\MORGAN~1\m3jpeg32.dll
"vidc.dmb1"= C:\PROGRA~1\ACEMEG~1\SystemS\MORGAN~1\m3jpeg32.dll
"vidc.mj2c"= C:\PROGRA~1\ACEMEG~1\SystemS\MORGAN~1\M3JP2K32.dll
"vidc.tvmj"= C:\PROGRA~1\ACEMEG~1\SystemS\MORGAN~1\MMTVMJ.dll
"vidc.fljp"= C:\PROGRA~1\ACEMEG~1\SystemS\MORGAN~1\MMTVMJ.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^EPSON Background Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\EPSON Background Monitor.lnk
backup=C:\WINDOWS\pss\EPSON Background Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Acrobat.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Acrobat.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Acrobat.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Ralink Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Ralink Wireless Utility.lnk
backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Service Manager.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Service Manager.lnk
backup=C:\WINDOWS\pss\Service Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
path=C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^DW_Start.lnk]
path=C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\DW_Start.lnk
backup=C:\WINDOWS\pss\DW_Start.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^[AIO] TEXAS HOLDEM POKER PACK (FULL).lnk]
path=C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\[AIO] TEXAS HOLDEM POKER PACK (FULL).lnk
backup=C:\WINDOWS\pss\[AIO] TEXAS HOLDEM POKER PACK (FULL).lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zxqnt]
C:\Program Files\F?nts\m?hta.exe [?]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-07-25 00:00 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a8a4ac72]
C:\WINDOWS\system32\uggnaqir.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2006-10-22 23:24 620152 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
--a------ 2004-12-16 17:49 49152 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoTBar]
c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMab979fee]
C:\WINDOWS\system32\jvqtvsed.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-05 12:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Roxio\Media Experience\DMXLauncher.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Firewall auto setup]
C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\winlogon.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intel system tool]
C:\WINDOWS\system32\svehost.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-11-15 14:11 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-08-04 09:07 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-11-11 14:47 7311360 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-11-15 00:43 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
C:\Program Files\Real\RealOne Player\realplay.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2004-04-14 21:43 233472 C:\WINDOWS\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIS2PostReboot]
--a------ 2001-04-27 15:19 212992 C:\Program Files\LEGO MINDSTORMS\RIS 2.0\LaunchRis2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
--a------ 2004-05-20 10:47 249856 C:\WINDOWS\system32\Keyhook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
--a------ 2004-08-04 09:07 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebDriveTray]
C:\Program Files\NetDrive\netdrive.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINREMOTE]
--a------ 2004-06-25 12:47 192512 C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdates]
C:\Program Files\winupdates\winupdates.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{4A-AC-CD-DD-DW}]
c:\windows\system32\rwwnw64d.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{992496cc-5e32-cd16-0fc5-303c8776d4f7}]
C:\WINDOWS\system32\{914725cf-dca6-3d59-946e-8e3ab8769099}.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{dab77a30-a996-a04d-0fb6-74ba798da9cb}]
C:\WINDOWS\system32\snupiclehwqdfbnz.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2004-06-29 18:06 88363 C:\WINDOWS\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXDllRegExe]
dxdllreg.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-11-11 14:47 1519616 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\backburner\\server.exe"=
"C:\\MBS\\gwrd.exe"=
"C:\\MBS\\disp+work.exe"=
"C:\\MBS\\msg_server.exe"=
"C:\\Program Files\\SAPpc\\sapgui\\sapgui.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\Roxio\\Creator Classic 9\\Creator9.exe"=
"C:\\Program Files\\freeBrowser\\freeBrowser\\freeBrowser.exe"=
"C:\\Program Files\\freeBrowser\\vlc\\vlc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Valve\\hl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 c2scsi;c2scsi;C:\WINDOWS\system32\drivers\c2scsi.sys [2006-03-04 14:00]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-01 21:06]
R3 Cap7134;ASUS TV7134 WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-06-23 21:34]
R3 PhTVTune;ASUS WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-05-27 19:49]
R3 snpstd2;VideoCAM Look;C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-07-28 12:49]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S2 WebDriveFSD;WebDrive File System Driver;C:\Program Files\NetDrive\rffsd.sys []
S3 LTower;LEGO USB Tower Driver;C:\WINDOWS\system32\Drivers\LTower.sys [2001-04-25 17:44]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-07 07:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-06-15 08:00:01 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-06-15 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-06-15 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 22:21:02 C:\WINDOWS\Tasks\At145.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 23:00:01 C:\WINDOWS\Tasks\At146.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-07 00:00:01 C:\WINDOWS\Tasks\At147.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-07 01:00:01 C:\WINDOWS\Tasks\At148.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-07 02:00:03 C:\WINDOWS\Tasks\At149.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 03:00:01 C:\WINDOWS\Tasks\At150.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-07 04:00:01 C:\WINDOWS\Tasks\At151.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-07 05:00:01 C:\WINDOWS\Tasks\At152.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-07 06:00:01 C:\WINDOWS\Tasks\At153.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-07 07:00:01 C:\WINDOWS\Tasks\At154.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-06-15 08:00:06 C:\WINDOWS\Tasks\At155.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-06-15 09:00:01 C:\WINDOWS\Tasks\At156.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-06-15 10:00:02 C:\WINDOWS\Tasks\At157.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 11:00:01 C:\WINDOWS\Tasks\At158.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 12:00:02 C:\WINDOWS\Tasks\At159.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 13:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 13:00:03 C:\WINDOWS\Tasks\At160.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 14:00:01 C:\WINDOWS\Tasks\At161.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 15:00:01 C:\WINDOWS\Tasks\At162.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 16:00:06 C:\WINDOWS\Tasks\At163.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 17:00:01 C:\WINDOWS\Tasks\At164.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 18:00:01 C:\WINDOWS\Tasks\At165.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 19:00:01 C:\WINDOWS\Tasks\At166.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 20:00:03 C:\WINDOWS\Tasks\At167.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 21:00:04 C:\WINDOWS\Tasks\At168.job"
- C:\WINDOWS\system32\5PteOI43.exe
"2008-07-06 22:32:01 C:\WINDOWS\Tasks\At169.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 23:00:01 C:\WINDOWS\Tasks\At170.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 00:00:01 C:\WINDOWS\Tasks\At171.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 01:00:01 C:\WINDOWS\Tasks\At172.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 02:00:03 C:\WINDOWS\Tasks\At173.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 03:00:01 C:\WINDOWS\Tasks\At174.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 04:00:01 C:\WINDOWS\Tasks\At175.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 05:00:01 C:\WINDOWS\Tasks\At176.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 06:00:01 C:\WINDOWS\Tasks\At177.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-07 07:00:01 C:\WINDOWS\Tasks\At178.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 10:25:11 C:\WINDOWS\Tasks\At179.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 15:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 10:25:11 C:\WINDOWS\Tasks\At180.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 10:25:11 C:\WINDOWS\Tasks\At181.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 11:00:01 C:\WINDOWS\Tasks\At182.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 12:00:02 C:\WINDOWS\Tasks\At183.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 13:00:03 C:\WINDOWS\Tasks\At184.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 14:00:02 C:\WINDOWS\Tasks\At185.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 15:00:01 C:\WINDOWS\Tasks\At186.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 16:00:06 C:\WINDOWS\Tasks\At187.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 17:00:01 C:\WINDOWS\Tasks\At188.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 18:00:01 C:\WINDOWS\Tasks\At189.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 16:00:02 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 19:00:01 C:\WINDOWS\Tasks\At190.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 20:00:03 C:\WINDOWS\Tasks\At191.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 21:00:02 C:\WINDOWS\Tasks\At192.job"
- C:\WINDOWS\system32\oi3X8efj.exe
"2008-07-06 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 18:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 20:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-06 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 01:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 02:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 03:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 04:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2008-07-07 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\a58plwpD.exe
"2007-05-15 09:59:58 C:\WINDOWS\Tasks\bghyrd.job"
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 15:03, on 2008-07-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vsnpstd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\HP_Propriétaire\Bureau\hithis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...lion&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
htt