Ok merci voila le conetenu du fichier log :
Logfile of random's system information tool 1.06 (written by random/random)
Run by m.alaoui at 2009-10-20 11:13:45
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 93 GB (93%) free of 100 GB
Total RAM: 1014 MB (63% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16 37808]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PtiuPbmd"=ptipbm.dll,SetWriteBack []
"RoxioDragToDisc"=C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe [2006-10-30 1116920]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-07-01 150040]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-07-01 170520]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-07-01 141848]
"OfficeScanNT Monitor"=C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe [2007-05-08 702072]
"OrderReminder"=C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [2006-01-30 98304]
"restorer64_a"=C:\WINDOWS\system32\restorer64_a.exe [2009-10-14 61034]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-03 15360]
"userinit"=C:\Documents and Settings\m.alaoui\Application Data\sdra64.exe [2004-08-03 108032]
"restorer64_a"=C:\Documents and Settings\m.alaoui\restorer64_a.exe [2009-10-14 61034]
"mserv"=C:\Documents and Settings\m.alaoui\Application Data\seres.exe [2009-10-16 44544]
"svchost"=C:\Documents and Settings\m.alaoui\Application Data\svcst.exe [2009-10-16 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe [2007-11-19 2295072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\mscdz.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
C:\WINDOWS\system32\msauwehp.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^m.alaoui^Menu Démarrer^Programmes^Démarrage^ikowin32.exe]
C:\Documents and Settings\m.alaoui\Menu Démarrer\Programmes\Démarrage\ikowin32.exe [2004-08-03 31232]
C:\Documents and Settings\m.alaoui\Menu Démarrer\Programmes\Démarrage
ikowin32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-06-27 212992]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Olerp-rh V5.4\exe\Monitoring.exe"="C:\Olerp-rh V5.4\exe\Monitoring.exe:*:Enabled:Monitoring"
"C:\WINDOWS\EXPLORER.EXE"="C:\WINDOWS\EXPLORER.EXE:*:Disabled:Explorateur Windows"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\m.alaoui\Application Data\U3\00001541CB6139F8\0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe"="C:\Documents and Settings\m.alaoui\Application Data\U3\00001541CB6139F8\0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe:*:Enabled:skype"
"C:\WINDOWS\System32\SPOOL\DRIVERS\W32X86\3\HP1006MC.EXE"="C:\WINDOWS\System32\SPOOL\DRIVERS\W32X86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{557264f0-1792-11de-adf4-001d923f3554}]
shell\AutoRun\command - F:\LaunchU3.exe -a
======List of files/folders created in the last 2 months======
2009-10-20 11:13:45 ----D---- C:\rsit
2009-10-20 10:37:35 ----A---- C:\rapport3.txt
2009-10-20 10:26:44 ----A---- C:\WINDOWS\ntbtlog.txt
2009-10-20 09:54:02 ----A---- C:\WINDOWS\system32\tmp.txt
2009-10-20 09:53:55 ----A---- C:\rapport.txt
2009-10-16 17:44:25 ----D---- C:\WINDOWS\pss
2009-10-16 17:41:42 ----A---- C:\Documents and Settings\m.alaoui\Application Data\lizkavd.exe
2009-10-16 17:23:30 ----SHD---- C:\FOUND.009
2009-10-16 09:15:40 ----A---- C:\WINDOWS\system32\delycila.exe
2009-10-16 09:15:40 ----A---- C:\WINDOWS\maxel.bat
2009-10-16 09:15:40 ----A---- C:\WINDOWS\joroz.bat
2009-10-16 09:15:40 ----A---- C:\WINDOWS\bywu.com
2009-10-16 09:15:40 ----A---- C:\Program Files\Fichiers communs\ihul.exe
2009-10-16 09:15:40 ----A---- C:\Documents and Settings\m.alaoui\Application Data\aqymagawo.bat
2009-10-15 21:42:45 ----A---- C:\WINDOWS\svohost.exe
2009-10-15 21:42:44 ----A---- C:\WINDOWS\system32\pump.exe
2009-10-15 21:42:44 ----A---- C:\WINDOWS\system32\plugie.dll
2009-10-15 21:42:36 ----A---- C:\WINDOWS\odb.exe
2009-10-14 18:07:33 ----A---- C:\WINDOWS\zikafi.com
2009-10-14 18:07:33 ----A---- C:\WINDOWS\ynyzec.vbs
2009-10-14 18:07:33 ----A---- C:\WINDOWS\system32\ynemare.vbs
2009-10-14 18:07:33 ----A---- C:\WINDOWS\itylas.com
2009-10-14 18:07:33 ----A---- C:\Documents and Settings\All Users\Application Data\qabawy.com
2009-10-14 12:29:55 ----A---- C:\WINDOWS\ulega.dll
2009-10-14 12:29:55 ----A---- C:\WINDOWS\oxiz.exe
2009-10-14 12:29:55 ----A---- C:\WINDOWS\iviqopaj.dll
2009-10-14 12:29:55 ----A---- C:\Program Files\Fichiers communs\pojaf.com
2009-10-14 12:29:55 ----A---- C:\Documents and Settings\m.alaoui\Application Data\axudi.bat
2009-10-14 12:29:55 ----A---- C:\Documents and Settings\All Users\Application Data\teqyfadu.dll
2009-10-14 12:29:55 ----A---- C:\Documents and Settings\All Users\Application Data\eqep.bat
2009-10-14 12:28:13 ----A---- C:\Documents and Settings\m.alaoui\Application Data\svcst.exe
2009-10-14 12:28:13 ----A---- C:\Documents and Settings\m.alaoui\Application Data\seres.exe
2009-10-14 12:28:10 ----A---- C:\WINDOWS\system32\restorer64_a.exe
2009-10-07 09:22:02 ----SHD---- C:\FOUND.008
2009-10-01 10:40:05 ----A---- C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameD.txt
2009-09-30 11:16:46 ----A---- C:\WINDOWS\lsass.exe
======List of files/folders modified in the last 2 months======
2009-10-20 10:24:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-10-16 17:47:54 ----N---- C:\WINDOWS\system.ini
2009-10-16 17:47:54 ----ASH---- C:\boot.ini
2009-10-16 17:47:54 ----A---- C:\WINDOWS\win.ini
2009-10-16 11:25:24 ----A---- C:\WINDOWS\svx.exe
2009-10-16 11:25:24 ----A---- C:\WINDOWS\svw.exe
2009-10-16 11:25:24 ----A---- C:\WINDOWS\svc.exe
2009-10-16 10:01:52 ----A---- C:\WINDOWS\cfgall.ini
2009-10-14 10:50:38 ----A---- C:\WINDOWS\wdmon.exe
2009-10-12 15:02:06 ----A---- C:\WINDOWS\IE4 Error Log.txt
2009-09-30 11:17:20 ----A---- C:\WINDOWS\servicelayer.exe
2009-08-24 10:33:52 ----A---- C:\WINDOWS\ODBC.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2007-02-08 12856]
R1 DLARTL_M;DLARTL_M; C:\WINDOWS\System32\Drivers\DLARTL_M.SYS [2007-02-08 28120]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-03 40320]
R1 tmtdi;Trend Micro TDI Driver; C:\WINDOWS\system32\DRIVERS\tmtdi.sys [2006-11-14 73288]
R2 DLABMFSM;DLABMFSM; C:\WINDOWS\System32\DLA\DLABMFSM.SYS [2006-10-26 35096]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2006-10-26 32472]
R2 DLADResM;DLADResM; C:\WINDOWS\System32\DLA\DLADResM.SYS [2006-10-26 9432]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2006-10-26 104536]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2006-10-26 26296]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2006-10-26 14520]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2006-10-26 97848]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2006-10-26 94648]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2007-02-09 51768]
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2004-07-16 76288]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R2 TmFilter;Trend Micro Filter; \??\C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys []
R2 TmPreFilter;Trend Micro PreFilter; \??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys []
R2 VSApiNt;Trend Micro VSAPI NT; \??\C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys []
R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2008-01-14 163328]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-06-27 6023072]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-21 4399104]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
S3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-24 9600]
S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-24 12288]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 Sntnlusb;Rainbow USB SuperPro; C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS [2004-07-16 26120]
S3 SONYPVU1;Pilote de filtrage Sony USB (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2007-11-19 79136]
R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 ntrtscan;OfficeScanNT RealTime Scan; C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe [2007-05-08 771704]
R2 tmlisten;OfficeScan NT Listener; C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe [2007-05-08 796280]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2006-11-06 887544]
S3 stllssvr;stllssvr; C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe [2006-11-01 73728]
S3 TmProxy;OfficeScan NT Proxy Service; C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe [2007-04-27 575064]
-----------------EOF-----------------