1. Rapport combofix:
ComboFix 09-10-16.09 - Eric 17/10/2009 19:54.1.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1023.567 [GMT 2:00]
Lancé depuis: c:\documents and settings\Eric\Bureau\combo-fix.exe
AV: avast! antivirus 4.8.1351 [VPS 091016-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Eric\Application Data\020000000a175713660C.manifest
c:\documents and settings\Eric\Application Data\020000000a175713660O.manifest
c:\documents and settings\Eric\Application Data\020000000a175713660P.manifest
c:\documents and settings\Eric\Application Data\020000000a175713660S.manifest
c:\documents and settings\Eric\Application Data\Dossier de téléchargement Share-to-Web
c:\recycler\S-1-5-21-2201293084-4022452294-1283766774-1003
c:\windows\system32\2gllXtSjoGmoD.vbs
c:\windows\system32\48XdkQExYiZ3P.vbs
c:\windows\system32\4to9V0Y.vbs
c:\windows\system32\5xynF7g.vbs
c:\windows\system32\79ttYd0Pe3J1jTm.vbs
c:\windows\system32\AQdCd.vbs
c:\windows\system32\AutoRun.inf
c:\windows\system32\autorun.ini
c:\windows\system32\BHoBByV.vbs
c:\windows\system32\CdDEg.vbs
c:\windows\system32\ejvvBE1Seonws1L.vbs
c:\windows\system32\EnuFRoM.vbs
c:\windows\system32\fhzHaIdNOT3oSNF.vbs
c:\windows\system32\Fkcpv.vbs
c:\windows\system32\Flm2SFU.vbs
c:\windows\system32\FyOmastxHKvcTs3.vbs
c:\windows\system32\gHznW.vbs
c:\windows\system32\GrAfp.vbs
c:\windows\system32\iLUWcmJloaxnvvi.vbs
c:\windows\system32\jHBO6oR.vbs
c:\windows\system32\k0nSklQ0GpUh8.vbs
c:\windows\system32\K39oxKl.vbs
c:\windows\system32\mbEoIziceBmWJQc.vbs
c:\windows\system32\Mt78BXm.vbs
c:\windows\system32\muzapp.exe
c:\windows\system32\RDGNA.vbs
c:\windows\system32\SK9QvaQHil5Md.vbs
c:\windows\system32\SToJe3GAaCUUJ.vbs
c:\windows\system32\uwRzeAfMyjXAw74.vbs
c:\windows\system32\YMQBrtMQJknUW.vbs
c:\windows\system32\zQZPn1OWbavdieX.vbs
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-17 au 2009-10-17 ))))))))))))))))))))))))))))))))))))
.
2009-10-16 21:01 . 2009-10-16 21:01 -------- d-----w- c:\documents and settings\Eric\Application Data\Malwarebytes
2009-10-16 21:01 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-16 21:01 . 2009-10-16 21:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-16 21:01 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-16 21:01 . 2009-10-17 06:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-15 20:59 . 2009-10-15 20:59 -------- d-----w- c:\program files\Trend Micro
2009-10-15 17:28 . 2009-10-15 17:30 -------- d-----w- c:\program files\Navilog1
2009-10-15 10:14 . 2009-10-15 10:14 237877 ----a-w- c:\windows\Enjoy 3e professeur Uninstaller.exe
2009-10-15 10:12 . 2009-10-15 10:12 -------- d-----w- c:\program files\Enjoy 3e professeur
2009-10-12 15:39 . 2009-10-12 15:39 358100 ----a-w- c:\windows\Enjoy 3e Uninstaller.exe
2009-10-12 15:37 . 2009-10-12 15:37 -------- d-----w- c:\program files\Enjoy 3e
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-17 15:15 . 2007-04-25 13:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-17 11:00 . 2005-09-03 20:27 60064 ----a-w- c:\documents and settings\Eric\Application Data\wklnhst.dat
2009-10-17 06:19 . 2008-10-23 21:11 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-16 20:40 . 2008-04-04 08:44 -------- d-----w- c:\program files\CCleaner
2009-10-16 17:07 . 1979-12-31 22:00 85636 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-16 17:07 . 1979-12-31 22:00 512292 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-10 08:02 . 2008-06-13 11:20 158958 ----a-w- c:\windows\hpoins15.dat
2009-10-07 19:22 . 2008-09-15 11:05 -------- d-----w- c:\program files\Enjoy 5e
2009-10-07 19:19 . 2008-10-17 14:36 -------- d-----w- c:\program files\Enjoy 4e professeur
2009-10-05 17:30 . 2009-10-05 17:30 7680 --sha-w- c:\program files\Thumbs.db
2009-10-05 17:30 . 2007-12-25 03:03 -------- d-----w- c:\program files\Windows Media Connect 2
2009-10-05 17:30 . 2007-12-25 03:07 -------- d-----w- c:\program files\Lame MP3 Codec
2009-10-05 17:30 . 2007-07-05 09:24 -------- d-----w- c:\program files\AdorageI-SAL
2009-10-04 10:40 . 2006-03-13 12:51 -------- d-----w- c:\program files\Microsoft Games
2009-10-01 18:33 . 2006-09-02 17:27 -------- d-----w- c:\program files\Enjoy 6e professeur
2009-09-25 05:54 . 1979-12-31 22:00 666112 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:54 . 1979-12-31 22:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-20 07:14 . 2005-12-30 18:52 -------- d-----w- c:\documents and settings\Eric\Application Data\Ahead
2009-09-16 19:54 . 2005-09-03 17:55 103992 ----a-w- c:\documents and settings\Eric\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-16 19:52 . 2005-12-30 18:51 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-09-16 19:48 . 2009-09-16 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2009-09-16 19:45 . 2009-09-16 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-09-14 14:47 . 2009-09-14 14:47 -------- d-----w- c:\documents and settings\Eric\Application Data\OpenOffice.org
2009-09-14 14:44 . 2009-09-14 14:44 -------- d-----w- c:\program files\JRE
2009-09-14 14:44 . 2009-09-14 14:44 -------- d-----w- c:\program files\OpenOffice.org 3
2009-09-14 14:42 . 2009-09-14 14:42 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-14 14:42 . 2005-06-23 04:37 -------- d-----w- c:\program files\Java
2009-09-13 18:20 . 2008-09-15 10:48 -------- d-----w- c:\program files\Enjoy 5e professeur
2009-09-11 14:34 . 1979-12-31 22:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 14:00 . 2007-04-25 13:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-07 19:21 . 2009-09-07 19:21 0 ----a-w- c:\windows\system32\CB.tmp
2009-09-07 15:21 . 2009-09-07 15:21 0 ----a-w- c:\windows\system32\B2.tmp
2009-09-05 19:07 . 2009-09-05 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-05 19:06 . 2009-09-05 19:07 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-05 18:58 . 2009-09-05 18:58 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-09-05 18:58 . 2009-09-05 18:58 -------- d-----w- c:\program files\Lavasoft
2009-09-05 18:44 . 2009-09-05 18:36 34543112 ----a-w- c:\program files\Ad-AwareAE.exe
2009-09-05 18:34 . 2005-06-25 05:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-05 18:33 . 2007-04-25 14:03 -------- d-----w- c:\documents and settings\Eric\Application Data\Lavasoft
2009-09-05 16:09 . 2009-09-05 16:06 16409960 ----a-w- c:\program files\spybotsd162.exe
2009-09-05 13:13 . 2009-09-05 13:13 99533 ----a-w- C:\ZugoRemovalTool.exe
2009-09-05 13:08 . 2007-10-24 15:41 -------- d-----w- c:\program files\Codemasters
2009-09-05 10:15 . 2009-09-04 19:43 -------- d-----w- c:\program files\PSP Pandora Deluxe
2009-09-05 09:14 . 2009-09-04 22:52 -------- d-----w- c:\program files\PSP Grader
2009-09-04 20:46 . 1979-12-31 22:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-03 10:07 . 2009-09-03 10:06 8104160 ----a-w- c:\program files\Firefox Setup 3.5.2.exe
2009-09-03 09:18 . 2009-09-03 09:18 -------- d-----w- c:\program files\Lphant
2009-09-03 09:17 . 2009-08-27 21:43 2922143 ----a-w- c:\program files\Lphant-v3.51-Installer.exe
2009-09-03 08:59 . 2009-09-03 08:59 -------- d-----w- c:\documents and settings\All Users\Application Data\3036B
2009-09-02 17:54 . 2009-09-02 17:54 0 ----a-w- c:\windows\system32\55A.tmp
2009-09-01 17:49 . 2009-07-14 23:11 -------- d-----w- c:\program files\SlySoft
2009-08-31 22:29 . 2009-08-27 14:13 -------- d-----w- c:\documents and settings\Eric\Application Data\LimeWire
2009-08-31 22:29 . 2009-08-31 21:50 -------- d-----w- c:\documents and settings\Eric\Application Data\FrostWire
2009-08-31 21:56 . 2009-08-31 21:49 -------- d-----w- c:\program files\FrostWire
2009-08-31 21:31 . 2009-08-31 21:13 -------- d-----w- c:\program files\LimeWire
2009-08-30 09:18 . 2009-08-30 09:18 0 ----a-w- c:\windows\system32\3E2.tmp
2009-08-28 17:05 . 2009-08-28 17:05 -------- d-----w- c:\program files\MSBuild
2009-08-28 17:05 . 2009-08-28 17:05 -------- d-----w- c:\program files\Reference Assemblies
2009-08-28 17:01 . 2009-08-28 17:01 -------- d-----w- c:\program files\MSXML 6.0
2009-08-27 21:49 . 2009-08-27 21:45 23510720 ----a-w- c:\program files\dotnetfx.exe
2009-08-27 15:46 . 2009-08-27 15:46 1443065 ----a-w- c:\program files\winrar_winrar_3.90_final_32_bits_francais_9632.exe
2009-08-26 08:15 . 1979-12-31 22:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 16:10 . 2007-04-25 13:06 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2007-04-25 13:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2007-04-25 13:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-10 05:34 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-10 05:34 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2007-04-25 13:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2007-04-25 13:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2007-04-25 13:06 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2007-04-25 13:06 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-05 09:06 . 1979-12-31 22:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 17:05 . 2004-08-03 22:48 2059776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-08-04 17:05 . 1979-12-31 22:00 2182400 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-05-16 10:44 . 2009-05-16 10:44 4097 ----a-w- c:\program files\galupy15.gif
2009-05-15 20:50 . 2009-05-15 20:50 6818213 ----a-w- c:\program files\free-mp3-wma-converter_free_mp3_wma_converter_1.6.3_francais_34863.exe
2008-01-04 22:24 . 2008-01-04 22:24 594944 ----a-w- c:\program files\mozilla firefox\plugins\MannequinPlayer2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-14 32768]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-14 149280]
"Microsoft Works Update Detection"="c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2001-10-05 28738]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-01-24 81920]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"TotalRecorderScheduler"="c:\program files\HighCriteria\TotalRecorder\TotRecSched.exe" [2006-12-05 114688]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-05 188416]
"SMSTray"="c:\program files\Samsung\EmoDio\SMSTray.exe" [2009-03-21 484888]
"ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2008-02-27 570664]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2008-02-18 1629480]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2008-02-18 1057064]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-06-14 14477312]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-29 88363]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\Eric\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
PHOTOfunSTUDIO -viewer-.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe [2008-10-8 40960]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2007-4-10 589824]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=DrvTrNTm.dll
"wave"=DrvTrNTm.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Lphant\\eLePhantClient.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [05/09/2009 21:07 64160]
R0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [01/01/1980 85888]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [10/04/2008 07:34 114768]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [17/08/2009 12:51 11776]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [10/04/2008 07:34 20560]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 23:34 1028432]
S1 MUsbFltr;WayTechUSBFilterDriver; [x]
S1 UsbFltr;WayTechUSBFilterDriver; [x]
S2 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe --> c:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe [?]
S3 5f8a6493-7f70-4f75-8e6a-e54b410c75a9;5f8a6493-7f70-4f75-8e6a-e54b410c75a9;\??\e:\player\cds300.dll --> e:\player\cds300.dll [?]
S3 lac97inf;lac97inf;\??\c:\docume~1\Eric\LOCALS~1\Temp\lac97inf.sys --> c:\docume~1\Eric\LOCALS~1\Temp\lac97inf.sys [?]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [30/05/2008 16:49 576680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-10-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 19:07]
2009-10-17 c:\windows\Tasks\WebReg Photosmart C4200 series.job
- c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe [2007-03-11 19:27]
.
.
------- Examen supplémentaire -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext =
hxxp://shell.windows.com/fileassoc/fileassoc.asp?LangID=040c&Ext=odt
FF - ProfilePath - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\3b14tyhf.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npredoute.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-WOOKIT - c:\progra~1\Wanadoo\Shell.exe
HKLM-Run-MediaSync - c:\program files\Acer\Acer eConsole\MediaSync.exe
HKLM-Run-AspireService - c:\program files\Acer\Acer eMode Management\AspireService.exe
HKLM-Run-NWEReboot - (no file)
Notify-984d37da660 - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-17 19:59
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(744)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-10-17 20:01
ComboFix-quarantined-files.txt 2009-10-17 18:01
Avant-CF: 46 820 212 736 octets libres
Après-CF: 46 822 092 800 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptOut
256 --- E O F --- 2009-10-16 17:08
2. Rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:02:37, on 17/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://shell.windows.com/fileassoc/fileassoc.asp?LangID=040c&Ext=odt
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\EmoDio\SMSTray.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: PHOTOfunSTUDIO -viewer-.lnk = C:\Program Files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb(...)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb(...)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
--
End of file - 9085 bytes
Cordialement