Logfile of HijackThis v1.99.1
Scan saved at 22:12:02, on 31/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
E:\ScreenShooter\ScreenShooter.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lorena\Bureau\Programmes Arnaud\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.be/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ScreenShooter] "E:\ScreenShooter\ScreenShooter.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [does warn cdrom start] C:\Documents and Settings\All Users\Application Data\file date does warn\stupiddent.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1110035206546
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 1C99-95F8
R‚pertoire de C:\Documents and Settings\All Users\Application Data
31/08/2005 21:40 <REP> Skype
31/08/2005 21:22 <REP> ..
31/08/2005 21:22 <REP> .
27/08/2005 22:48 <REP> Adobe
17/08/2005 15:26 <REP> DVD Shrink
12/08/2005 21:17 <REP> Windows Genuine Advantage
21/05/2005 15:17 <REP> Microsoft
08/04/2005 21:48 <REP> QuickTime
08/04/2005 21:45 <REP> Apple Computer
22/02/2005 00:13 <REP> Spybot - Search & Destroy
29/01/2005 17:22 <REP> Ahead
19/01/2005 22:21 <REP> Ulead Systems
16/01/2005 22:11 <REP> Macrovision
16/01/2005 19:14 <REP> CyberLink
09/01/2005 20:37 <REP> Network Associates
09/01/2005 18:34 62 desktop.ini
1 fichier(s) 62 octets
15 R‚p(s) 2.999.328.768 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 1C99-95F8
R‚pertoire de C:\Documents and Settings\Lorena\Application Data
31/08/2005 21:23 <REP> ..
31/08/2005 21:23 <REP> .
27/08/2005 22:47 <REP> Adobe
08/04/2005 21:19 <REP> Skype
08/04/2005 21:18 <REP> Microsoft
10/02/2005 08:23 <REP> Azureus
29/01/2005 17:23 <REP> Ahead
19/01/2005 22:25 <REP> ArcSoft
19/01/2005 22:22 <REP> Ulead Systems
09/01/2005 20:28 <REP> Apple Computer
09/01/2005 20:28 <REP> Creative
09/01/2005 20:28 <REP> InterTrust
09/01/2005 20:28 <REP> Lavasoft
09/01/2005 20:28 <REP> Identities
09/01/2005 20:28 <REP> CyberLink
09/01/2005 20:28 <REP> Macromedia
09/01/2005 20:28 <REP> Sun
09/01/2005 19:58 <REP> Help
09/12/2004 06:52 62 desktop.ini
1 fichier(s) 62 octets
18 R‚p(s) 2.999.328.768 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 1C99-95F8
R‚pertoire de C:\WINDOWS\Tasks
31/08/2005 21:39 6 SA.DAT
31/08/2005 21:33 <REP> ..
31/08/2005 21:33 <REP> .
07/09/2002 02:00 65 desktop.ini
2 fichier(s) 71 octets
2 R‚p(s) 2.999.328.768 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 1C99-95F8
R‚pertoire de C:\Documents and Settings\All Users\Application Data
31/08/2005 22:10 <REP> Skype
31/08/2005 21:22 <REP> ..
31/08/2005 21:22 <REP> .
27/08/2005 22:48 <REP> Adobe
17/08/2005 15:26 <REP> DVD Shrink
12/08/2005 21:17 <REP> Windows Genuine Advantage
21/05/2005 15:17 <REP> Microsoft
08/04/2005 21:48 <REP> QuickTime
08/04/2005 21:45 <REP> Apple Computer
22/02/2005 00:13 <REP> Spybot - Search & Destroy
29/01/2005 17:22 <REP> Ahead
19/01/2005 22:21 <REP> Ulead Systems
16/01/2005 22:11 <REP> Macrovision
16/01/2005 19:14 <REP> CyberLink
09/01/2005 20:37 <REP> Network Associates
09/01/2005 18:34 62 desktop.ini
1 fichier(s) 62 octets
15 R‚p(s) 3.006.418.944 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 1C99-95F8
R‚pertoire de C:\Documents and Settings\Lorena\Application Data
31/08/2005 21:23 <REP> ..
31/08/2005 21:23 <REP> .
27/08/2005 22:47 <REP> Adobe
08/04/2005 21:19 <REP> Skype
08/04/2005 21:18 <REP> Microsoft
10/02/2005 08:23 <REP> Azureus
29/01/2005 17:23 <REP> Ahead
19/01/2005 22:25 <REP> ArcSoft
19/01/2005 22:22 <REP> Ulead Systems
09/01/2005 20:28 <REP> Apple Computer
09/01/2005 20:28 <REP> Creative
09/01/2005 20:28 <REP> InterTrust
09/01/2005 20:28 <REP> Lavasoft
09/01/2005 20:28 <REP> Identities
09/01/2005 20:28 <REP> CyberLink
09/01/2005 20:28 <REP> Macromedia
09/01/2005 20:28 <REP> Sun
09/01/2005 19:58 <REP> Help
09/12/2004 06:52 62 desktop.ini
1 fichier(s) 62 octets
18 R‚p(s) 3.006.414.848 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le num‚ro de s‚rie du volume est 1C99-95F8
R‚pertoire de C:\WINDOWS\Tasks
31/08/2005 22:09 6 SA.DAT
31/08/2005 21:33 <REP> ..
31/08/2005 21:33 <REP> .
07/09/2002 02:00 65 desktop.ini
2 fichier(s) 71 octets
2 R‚p(s) 3.006.414.848 octets libres