admin - 06-11-01 20:03:16,34 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\admin\Bureau"
((((((((((((((((((((((((((((((( Files Created from 2006-10-01 to 2006-11-01 ))))))))))))))))))))))))))))))))))
2006-10-31 22:42 66,048 --a------ C:\BFU.exe
2006-10-30 20:53 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2006-10-30 20:53 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2006-10-30 20:53 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2006-10-27 18:44 97,455 --a------ C:\WINDOWS\5-a0c18a429b8010fee34ee31d9073371d.exe
2006-10-27 18:44 622,613 --a------ C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
2006-10-27 18:44 33,085 --a------ C:\WINDOWS\system32\brrot-uninst.exe
2006-10-27 18:43 365,132 --a------ C:\WINDOWS\7-7c15eb3352bcc3049d7e9e974ad283bf.exe
2006-10-25 19:08 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2006-10-25 19:08 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
2006-10-25 19:08 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2006-10-25 19:08 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2006-10-25 19:08 73,832 --------- C:\WINDOWS\system32\slcoinst.dll
2006-10-25 19:08 73,796 --------- C:\WINDOWS\system32\slserv.exe
2006-10-25 19:08 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2006-10-25 19:08 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2006-10-25 19:08 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2006-10-25 19:08 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2006-10-25 19:08 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2006-10-25 19:08 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys
2006-10-25 19:08 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2006-10-25 19:08 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2006-10-25 19:08 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2006-10-25 19:08 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2006-10-25 19:08 516,768 --------- C:\WINDOWS\system32\ativvaxx.dll
2006-10-25 19:08 452,736 --------- C:\WINDOWS\system32\drivers\mtxparhm.sys
2006-10-25 19:08 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2006-10-25 19:08 44,672 --------- C:\WINDOWS\system32\drivers\uagp35.sys
2006-10-25 19:08 43,008 --------- C:\WINDOWS\system32\drivers\amdagp.sys
2006-10-25 19:08 42,752 --------- C:\WINDOWS\system32\drivers\alim1541.sys
2006-10-25 19:08 42,368 --------- C:\WINDOWS\system32\drivers\agp440.sys
2006-10-25 19:08 42,240 --------- C:\WINDOWS\system32\drivers\viaagp.sys
2006-10-25 19:08 41,088 --------- C:\WINDOWS\system32\drivers\sisagp.sys
2006-10-25 19:08 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2006-10-25 19:08 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2006-10-25 19:08 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2006-10-25 19:08 397,056 --------- C:\WINDOWS\system32\s3gnb.dll
2006-10-25 19:08 38,016 --------- C:\WINDOWS\system32\drivers\bthmodem.sys
2006-10-25 19:08 377,984 --------- C:\WINDOWS\system32\ati2dvaa.dll
2006-10-25 19:08 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2006-10-25 19:08 35,456 --------- C:\WINDOWS\system32\drivers\bthprint.sys
2006-10-25 19:08 34,735 --------- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2006-10-25 19:08 327,168 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2006-10-25 19:08 32,866 --------- C:\WINDOWS\system32\slrundll.exe
2006-10-25 19:08 32,866 --------- C:\WINDOWS\slrundll.exe
2006-10-25 19:08 32,768 --------- C:\WINDOWS\system32\ativtmxx.dll
2006-10-25 19:08 32,285 --------- C:\WINDOWS\system32\hsfcisp2.dll
2006-10-25 19:08 31,744 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
2006-10-25 19:08 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys
2006-10-25 19:08 30,080 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2006-10-25 19:08 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2006-10-25 19:08 3,901 --------- C:\WINDOWS\system32\drivers\siint5.dll
2006-10-25 19:08 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2006-10-25 19:08 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2006-10-25 19:08 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2006-10-25 19:08 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2006-10-25 19:08 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
2006-10-25 19:08 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2006-10-25 19:08 286,792 --------- C:\WINDOWS\system32\slextspk.dll
2006-10-25 19:08 28,672 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
2006-10-25 19:08 274,944 --------- C:\WINDOWS\system32\drivers\bthport.sys
2006-10-25 19:08 26,367 --------- C:\WINDOWS\system32\drivers\ati1snxx.sys
2006-10-25 19:08 25,856 --------- C:\WINDOWS\system32\drivers\hidbth.sys
2006-10-25 19:08 25,471 --------- C:\WINDOWS\system32\drivers\watv10nt.sys
2006-10-25 19:08 25,471 --------- C:\WINDOWS\system32\drivers\atv04nt5.dll
2006-10-25 19:08 229,376 --------- C:\WINDOWS\system32\ati2cqag.dll
2006-10-25 19:08 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2006-10-25 19:08 22,271 --------- C:\WINDOWS\system32\drivers\watv06nt.sys
2006-10-25 19:08 21,343 --------- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2006-10-25 19:08 21,183 --------- C:\WINDOWS\system32\drivers\atv01nt5.dll
2006-10-25 19:08 201,728 --------- C:\WINDOWS\system32\ati2dvag.dll
2006-10-25 19:08 188,508 --------- C:\WINDOWS\system32\slgen.dll
2006-10-25 19:08 180,360 --------- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2006-10-25 19:08 18,944 --------- C:\WINDOWS\system32\drivers\bthusb.sys
2006-10-25 19:08 17,279 --------- C:\WINDOWS\system32\drivers\atv10nt5.dll
2006-10-25 19:08 17,024 --------- C:\WINDOWS\system32\drivers\bthenum.sys
2006-10-25 19:08 166,912 --------- C:\WINDOWS\system32\drivers\s3gnbm.sys
2006-10-25 19:08 15,423 --------- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2006-10-25 19:08 15,104 --------- C:\WINDOWS\system32\drivers\hidir.sys
2006-10-25 19:08 14,336 --------- C:\WINDOWS\system32\drivers\atinpdxx.sys
2006-10-25 19:08 14,143 --------- C:\WINDOWS\system32\drivers\atv06nt5.dll
2006-10-25 19:08 13,824 --------- C:\WINDOWS\system32\drivers\atinttxx.sys
2006-10-25 19:08 13,824 --------- C:\WINDOWS\system32\drivers\atinmdxx.sys
2006-10-25 19:08 13,776 --------- C:\WINDOWS\system32\drivers\recagent.sys
2006-10-25 19:08 13,568 --------- C:\WINDOWS\system32\drivers\wacompen.sys
2006-10-25 19:08 13,240 --------- C:\WINDOWS\system32\drivers\slwdmsup.sys
2006-10-25 19:08 129,535 --------- C:\WINDOWS\system32\drivers\slnt7554.sys
2006-10-25 19:08 126,686 --------- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2006-10-25 19:08 12,672 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2006-10-25 19:08 12,672 --------- C:\WINDOWS\system32\drivers\mutohpen.sys
2006-10-25 19:08 12,047 --------- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2006-10-25 19:08 11,935 --------- C:\WINDOWS\system32\drivers\wadv11nt.sys
2006-10-25 19:08 11,871 --------- C:\WINDOWS\system32\drivers\wadv09nt.sys
2006-10-25 19:08 11,868 --------- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2006-10-25 19:08 11,807 --------- C:\WINDOWS\system32\drivers\wadv07nt.sys
2006-10-25 19:08 11,615 --------- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2006-10-25 19:08 11,359 --------- C:\WINDOWS\system32\drivers\atv02nt5.dll
2006-10-25 19:08 11,325 --------- C:\WINDOWS\system32\drivers\vchnt5.dll
2006-10-25 19:08 11,295 --------- C:\WINDOWS\system32\drivers\wadv08nt.sys
2006-10-25 19:08 104,960 --------- C:\WINDOWS\system32\drivers\atinrvxx.sys
2006-10-25 19:08 100,992 --------- C:\WINDOWS\system32\drivers\bthpan.sys
2006-10-25 19:08 1,897,408 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-25 19:08 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2006-10-25 19:08 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2006-10-25 19:08 1,309,184 --------- C:\WINDOWS\system32\drivers\mtlstrm.sys
2006-10-25 19:08 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2006-10-09 21:12 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2006-10-09 21:12 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2006-10-09 21:12 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2006-10-02 20:04 806,912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-10-02 20:04 806,912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-10-02 20:04 790,528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-10-02 20:04 635,486 --a------ C:\WINDOWS\system32\DivX.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-01 20:02 49 --a------ C:\Documents and Settings\admin\Application Data\internaldb41.dat
2006-11-01 20:02 382 --a------ C:\Documents and Settings\admin\Application Data\internaldb1942.dat
2006-11-01 19:58 20480 --a------ C:\Documents and Settings\admin\Application Data\internaldb4827.dat
2006-11-01 19:58 151 --a------ C:\Documents and Settings\admin\Application Data\internaldb2391.dat
2006-10-31 21:50 53624 --a------ C:\Documents and Settings\admin\Application Data\GDIPFONTCACHEV1.DAT
2006-10-31 18:32 -------- d-------- C:\Program Files\Defenza
2006-10-30 21:09 -------- d-------- C:\Program Files\CCleaner
2006-10-30 20:53 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-30 19:37 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-29 22:55 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-29 16:50 -------- d-------- C:\Program Files\MessengerPlus! 3
2006-10-29 16:50 -------- d-------- C:\Program Files\Adverts
2006-10-29 16:50 -------- d-------- C:\Program Files\4 flag
2006-10-28 13:44 -------- d-------- C:\Program Files\VirtualDJ
2006-10-27 18:44 9216 --a------ C:\Documents and Settings\admin\Application Data\internaldb8467.dat
2006-10-27 18:44 0 --a------ C:\Documents and Settings\admin\Application Data\internaldb6334.dat
2006-10-27 18:43 23 --a------ C:\Documents and Settings\admin\Application Data\inifile41.ini
2006-10-27 18:43 0 --a------ C:\Documents and Settings\admin\Application Data\internaldb5436.dat
2006-10-25 19:19 -------- d-------- C:\Program Files\Internet Explorer
2006-10-25 19:08 -------- d-------- C:\Program Files\Windows Media Player
2006-10-25 19:08 -------- d-------- C:\Program Files\Movie Maker
2006-10-25 19:08 -------- d-------- C:\Program Files\Messenger
2006-10-25 19:05 -------- d-------- C:\Program Files\Windows NT
2006-10-25 19:05 -------- d-------- C:\Program Files\Outlook Express
2006-10-25 19:05 -------- d-------- C:\Program Files\NetMeeting
2006-10-23 18:45 -------- d-------- C:\Program Files\AtomixMP3
2006-10-18 17:52 -------- d-------- C:\Program Files\Pinnacle
2006-10-13 10:41 -------- d-------- C:\Program Files\DivX
2006-10-12 19:17 -------- d-------- C:\Documents and Settings\admin\Application Data\LimeWire
2006-10-09 21:04 -------- d-------- C:\Program Files\ArcSoft
2006-10-09 21:04 -------- d-------- C:\Documents and Settings\admin\Application Data\ArcSoft
2006-09-25 16:45 666240 --a------ C:\WINDOWS\system32\aswBoot.exe
2006-09-25 16:40 87424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2006-09-25 16:40 85952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2006-09-25 16:39 36176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2006-09-25 16:39 16352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2006-09-25 16:37 90112 --a------ C:\WINDOWS\system32\AVASTSS.scr
2006-09-25 16:37 24560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2006-09-13 06:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-26 13:36 139 --a------ C:\AUTOEXEC.BAT
2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 13:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 12:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-08-11 00:03 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-08-11 00:03 196608 --a------ C:\WINDOWS\system32\dtu100.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MoneyAgent"="\"\"C:\\Program Files\\Microsoft Money\\System\\Money Express.exe\"\""
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"LaunchApp"="Alaunch"
"SoundMan"="SOUNDMAN.EXE"
"ntiMUI"="c:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\ntiMUI.exe"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"VTTimer"="VTTimer.exe"
"VTTrayp"="VTtrayp.exe"
"AspireService"="C:\\Program Files\\Acer\\Acer eMode Management\\AspireService.exe"
"MediaSync"="C:\\Program Files\\Acer\\Acer eConsole\\MediaSync.exe"
"eRecoveryService"="C:\\Acer\\Empowering Technology\\eRecovery\\Monitor.exe"
"MoneyStartUp10.0"="\"C:\\Program Files\\Microsoft Money\\System\\Activation.exe\""
"Register MediaRing Talk"="C:\\Program Files\\MediaRing Talk\\register.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"USB2Check"="RUNDLL32.EXE \"C:\\WINDOWS\\system32\\PCLECoInst.dll\",CheckUSBController"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PinnacleDriverCheck"="C:\\WINDOWS\\system32\\\\PSDrvCheck.exe"
"PCLEPCI"="C:\\PROGRA~1\\Pinnacle\\PPE\\PPE.EXE"
"adstart"="\"iexplore.exe\" \"
http://iesettingsupdate\""
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="
http://www.wowpapers.com/wowpapers/Images/en-US.Wallpaper/pre_over.gif"
"SubscribedURL"="
http://www.wowpapers.com/wowpapers/Images/en-US.Wallpaper/pre_over.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,18,01,00,00,d2,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,bf,01,00,00,14,01,00,00,18,01,00,00,d2,00,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="
https://europe.f-secure.com/images/newlook/menutop.gif"
"SubscribedURL"="
https://europe.f-secure.com/images/newlook/menutop.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,39,00,00,00,95,00,00,00,97,03,00,00,41,00,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,23,00,00,00,97,03,00,00,41,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,b3,06,41,c0,ab,74,50,fa,2b,06,68,de,b3,06,20,6d,\
b3,06,e3,9f,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="
http://www.bitdefender.fr/scan8/images/scan-online-b_05.jpg"
"SubscribedURL"="
http://www.bitdefender.fr/scan8/images/scan-online-b_05.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,12,02,00,00,19,01,00,00,d9,01,00,00,b0,00,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,19,01,00,00,d9,01,00,00,b0,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,0f,0a,41,c0,ab,74,d0,25,f1,06,68,de,0f,0a,20,6d,\
0f,0a,59,d7,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,00,00,ee,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\A238D92590DB53DD.job
Completion time: 06-11-01 20:04:58.04
C:\ComboFix.txt ... 06-11-01 20:04
C:\ComboFix2.txt ... 06-11-01 19:09
admin - 06-11-01 20:03:16,34 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\admin\Bureau"
((((((((((((((((((((((((((((((( Files Created from 2006-10-01 to 2006-11-01 ))))))))))))))))))))))))))))))))))
2006-10-31 22:42 66,048 --a------ C:\BFU.exe
2006-10-30 20:53 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2006-10-30 20:53 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2006-10-30 20:53 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2006-10-27 18:44 97,455 --a------ C:\WINDOWS\5-a0c18a429b8010fee34ee31d9073371d.exe
2006-10-27 18:44 622,613 --a------ C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
2006-10-27 18:44 33,085 --a------ C:\WINDOWS\system32\brrot-uninst.exe
2006-10-27 18:43 365,132 --a------ C:\WINDOWS\7-7c15eb3352bcc3049d7e9e974ad283bf.exe
2006-10-25 19:08 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2006-10-25 19:08 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
2006-10-25 19:08 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2006-10-25 19:08 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2006-10-25 19:08 73,832 --------- C:\WINDOWS\system32\slcoinst.dll
2006-10-25 19:08 73,796 --------- C:\WINDOWS\system32\slserv.exe
2006-10-25 19:08 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2006-10-25 19:08 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2006-10-25 19:08 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2006-10-25 19:08 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2006-10-25 19:08 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2006-10-25 19:08 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys
2006-10-25 19:08 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2006-10-25 19:08 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2006-10-25 19:08 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2006-10-25 19:08 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2006-10-25 19:08 516,768 --------- C:\WINDOWS\system32\ativvaxx.dll
2006-10-25 19:08 452,736 --------- C:\WINDOWS\system32\drivers\mtxparhm.sys
2006-10-25 19:08 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2006-10-25 19:08 44,672 --------- C:\WINDOWS\system32\drivers\uagp35.sys
2006-10-25 19:08 43,008 --------- C:\WINDOWS\system32\drivers\amdagp.sys
2006-10-25 19:08 42,752 --------- C:\WINDOWS\system32\drivers\alim1541.sys
2006-10-25 19:08 42,368 --------- C:\WINDOWS\system32\drivers\agp440.sys
2006-10-25 19:08 42,240 --------- C:\WINDOWS\system32\drivers\viaagp.sys
2006-10-25 19:08 41,088 --------- C:\WINDOWS\system32\drivers\sisagp.sys
2006-10-25 19:08 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2006-10-25 19:08 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2006-10-25 19:08 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2006-10-25 19:08 397,056 --------- C:\WINDOWS\system32\s3gnb.dll
2006-10-25 19:08 38,016 --------- C:\WINDOWS\system32\drivers\bthmodem.sys
2006-10-25 19:08 377,984 --------- C:\WINDOWS\system32\ati2dvaa.dll
2006-10-25 19:08 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2006-10-25 19:08 35,456 --------- C:\WINDOWS\system32\drivers\bthprint.sys
2006-10-25 19:08 34,735 --------- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2006-10-25 19:08 327,168 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2006-10-25 19:08 32,866 --------- C:\WINDOWS\system32\slrundll.exe
2006-10-25 19:08 32,866 --------- C:\WINDOWS\slrundll.exe
2006-10-25 19:08 32,768 --------- C:\WINDOWS\system32\ativtmxx.dll
2006-10-25 19:08 32,285 --------- C:\WINDOWS\system32\hsfcisp2.dll
2006-10-25 19:08 31,744 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
2006-10-25 19:08 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys
2006-10-25 19:08 30,080 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2006-10-25 19:08 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2006-10-25 19:08 3,901 --------- C:\WINDOWS\system32\drivers\siint5.dll
2006-10-25 19:08 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2006-10-25 19:08 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2006-10-25 19:08 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2006-10-25 19:08 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2006-10-25 19:08 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
2006-10-25 19:08 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2006-10-25 19:08 286,792 --------- C:\WINDOWS\system32\slextspk.dll
2006-10-25 19:08 28,672 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
2006-10-25 19:08 274,944 --------- C:\WINDOWS\system32\drivers\bthport.sys
2006-10-25 19:08 26,367 --------- C:\WINDOWS\system32\drivers\ati1snxx.sys
2006-10-25 19:08 25,856 --------- C:\WINDOWS\system32\drivers\hidbth.sys
2006-10-25 19:08 25,471 --------- C:\WINDOWS\system32\drivers\watv10nt.sys
2006-10-25 19:08 25,471 --------- C:\WINDOWS\system32\drivers\atv04nt5.dll
2006-10-25 19:08 229,376 --------- C:\WINDOWS\system32\ati2cqag.dll
2006-10-25 19:08 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2006-10-25 19:08 22,271 --------- C:\WINDOWS\system32\drivers\watv06nt.sys
2006-10-25 19:08 21,343 --------- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2006-10-25 19:08 21,183 --------- C:\WINDOWS\system32\drivers\atv01nt5.dll
2006-10-25 19:08 201,728 --------- C:\WINDOWS\system32\ati2dvag.dll
2006-10-25 19:08 188,508 --------- C:\WINDOWS\system32\slgen.dll
2006-10-25 19:08 180,360 --------- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2006-10-25 19:08 18,944 --------- C:\WINDOWS\system32\drivers\bthusb.sys
2006-10-25 19:08 17,279 --------- C:\WINDOWS\system32\drivers\atv10nt5.dll
2006-10-25 19:08 17,024 --------- C:\WINDOWS\system32\drivers\bthenum.sys
2006-10-25 19:08 166,912 --------- C:\WINDOWS\system32\drivers\s3gnbm.sys
2006-10-25 19:08 15,423 --------- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2006-10-25 19:08 15,104 --------- C:\WINDOWS\system32\drivers\hidir.sys
2006-10-25 19:08 14,336 --------- C:\WINDOWS\system32\drivers\atinpdxx.sys
2006-10-25 19:08 14,143 --------- C:\WINDOWS\system32\drivers\atv06nt5.dll
2006-10-25 19:08 13,824 --------- C:\WINDOWS\system32\drivers\atinttxx.sys
2006-10-25 19:08 13,824 --------- C:\WINDOWS\system32\drivers\atinmdxx.sys
2006-10-25 19:08 13,776 --------- C:\WINDOWS\system32\drivers\recagent.sys
2006-10-25 19:08 13,568 --------- C:\WINDOWS\system32\drivers\wacompen.sys
2006-10-25 19:08 13,240 --------- C:\WINDOWS\system32\drivers\slwdmsup.sys
2006-10-25 19:08 129,535 --------- C:\WINDOWS\system32\drivers\slnt7554.sys
2006-10-25 19:08 126,686 --------- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2006-10-25 19:08 12,672 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2006-10-25 19:08 12,672 --------- C:\WINDOWS\system32\drivers\mutohpen.sys
2006-10-25 19:08 12,047 --------- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2006-10-25 19:08 11,935 --------- C:\WINDOWS\system32\drivers\wadv11nt.sys
2006-10-25 19:08 11,871 --------- C:\WINDOWS\system32\drivers\wadv09nt.sys
2006-10-25 19:08 11,868 --------- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2006-10-25 19:08 11,807 --------- C:\WINDOWS\system32\drivers\wadv07nt.sys
2006-10-25 19:08 11,615 --------- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2006-10-25 19:08 11,359 --------- C:\WINDOWS\system32\drivers\atv02nt5.dll
2006-10-25 19:08 11,325 --------- C:\WINDOWS\system32\drivers\vchnt5.dll
2006-10-25 19:08 11,295 --------- C:\WINDOWS\system32\drivers\wadv08nt.sys
2006-10-25 19:08 104,960 --------- C:\WINDOWS\system32\drivers\atinrvxx.sys
2006-10-25 19:08 100,992 --------- C:\WINDOWS\system32\drivers\bthpan.sys
2006-10-25 19:08 1,897,408 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-25 19:08 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2006-10-25 19:08 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2006-10-25 19:08 1,309,184 --------- C:\WINDOWS\system32\drivers\mtlstrm.sys
2006-10-25 19:08 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2006-10-09 21:12 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2006-10-09 21:12 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2006-10-09 21:12 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2006-10-02 20:04 806,912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-10-02 20:04 806,912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-10-02 20:04 790,528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-10-02 20:04 635,486 --a------ C:\WINDOWS\system32\DivX.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-01 20:02 49 --a------ C:\Documents and Settings\admin\Application Data\internaldb41.dat
2006-11-01 20:02 382 --a------ C:\Documents and Settings\admin\Application Data\internaldb1942.dat
2006-11-01 19:58 20480 --a------ C:\Documents and Settings\admin\Application Data\internaldb4827.dat
2006-11-01 19:58 151 --a------ C:\Documents and Settings\admin\Application Data\internaldb2391.dat
2006-10-31 21:50 53624 --a------ C:\Documents and Settings\admin\Application Data\GDIPFONTCACHEV1.DAT
2006-10-31 18:32 -------- d-------- C:\Program Files\Defenza
2006-10-30 21:09 -------- d-------- C:\Program Files\CCleaner
2006-10-30 20:53 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-30 19:37 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-10-29 22:55 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-29 16:50 -------- d-------- C:\Program Files\MessengerPlus! 3
2006-10-29 16:50 -------- d-------- C:\Program Files\Adverts
2006-10-29 16:50 -------- d-------- C:\Program Files\4 flag
2006-10-28 13:44 -------- d-------- C:\Program Files\VirtualDJ
2006-10-27 18:44 9216 --a------ C:\Documents and Settings\admin\Application Data\internaldb8467.dat
2006-10-27 18:44 0 --a------ C:\Documents and Settings\admin\Application Data\internaldb6334.dat
2006-10-27 18:43 23 --a------ C:\Documents and Settings\admin\Application Data\inifile41.ini
2006-10-27 18:43 0 --a------ C:\Documents and Settings\admin\Application Data\internaldb5436.dat
2006-10-25 19:19 -------- d-------- C:\Program Files\Internet Explorer
2006-10-25 19:08 -------- d-------- C:\Program Files\Windows Media Player
2006-10-25 19:08 -------- d-------- C:\Program Files\Movie Maker
2006-10-25 19:08 -------- d-------- C:\Program Files\Messenger
2006-10-25 19:05 -------- d-------- C:\Program Files\Windows NT
2006-10-25 19:05 -------- d-------- C:\Program Files\Outlook Express
2006-10-25 19:05 -------- d-------- C:\Program Files\NetMeeting
2006-10-23 18:45 -------- d-------- C:\Program Files\AtomixMP3
2006-10-18 17:52 -------- d-------- C:\Program Files\Pinnacle
2006-10-13 10:41 -------- d-------- C:\Program Files\DivX
2006-10-12 19:17 -------- d-------- C:\Documents and Settings\admin\Application Data\LimeWire
2006-10-09 21:04 -------- d-------- C:\Program Files\ArcSoft
2006-10-09 21:04 -------- d-------- C:\Documents and Settings\admin\Application Data\ArcSoft
2006-09-25 16:45 666240 --a------ C:\WINDOWS\system32\aswBoot.exe
2006-09-25 16:40 87424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2006-09-25 16:40 85952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2006-09-25 16:39 36176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2006-09-25 16:39 16352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2006-09-25 16:37 90112 --a------ C:\WINDOWS\system32\AVASTSS.scr
2006-09-25 16:37 24560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2006-09-13 06:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-26 13:36 139 --a------ C:\AUTOEXEC.BAT
2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 13:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 12:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-08-11 00:03 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-08-11 00:03 196608 --a------ C:\WINDOWS\system32\dtu100.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MoneyAgent"="\"\"C:\\Program Files\\Microsoft Money\\System\\Money Express.exe\"\""
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"LaunchApp"="Alaunch"
"SoundMan"="SOUNDMAN.EXE"
"ntiMUI"="c:\\Program Files\\NewTech Infosystems\\NTI CD & DVD-Maker 7\\ntiMUI.exe"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"VTTimer"="VTTimer.exe"
"VTTrayp"="VTtrayp.exe"
"AspireService"="C:\\Program Files\\Acer\\Acer eMode Management\\AspireService.exe"
"MediaSync"="C:\\Program Files\\Acer\\Acer eConsole\\MediaSync.exe"
"eRecoveryService"="C:\\Acer\\Empowering Technology\\eRecovery\\Monitor.exe"
"MoneyStartUp10.0"="\"C:\\Program Files\\Microsoft Money\\System\\Activation.exe\""
"Register MediaRing Talk"="C:\\Program Files\\MediaRing Talk\\register.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"USB2Check"="RUNDLL32.EXE \"C:\\WINDOWS\\system32\\PCLECoInst.dll\",CheckUSBController"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PinnacleDriverCheck"="C:\\WINDOWS\\system32\\\\PSDrvCheck.exe"
"PCLEPCI"="C:\\PROGRA~1\\Pinnacle\\PPE\\PPE.EXE"
"adstart"="\"iexplore.exe\" \"
http://iesettingsupdate\""
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="
http://www.wowpapers.com/wowpapers/Images/en-US.Wallpaper/pre_over.gif"
"SubscribedURL"="
http://www.wowpapers.com/wowpapers/Images/en-US.Wallpaper/pre_over.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,18,01,00,00,d2,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,bf,01,00,00,14,01,00,00,18,01,00,00,d2,00,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="
https://europe.f-secure.com/images/newlook/menutop.gif"
"SubscribedURL"="
https://europe.f-secure.com/images/newlook/menutop.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,39,00,00,00,95,00,00,00,97,03,00,00,41,00,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,23,00,00,00,97,03,00,00,41,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,b3,06,41,c0,ab,74,50,fa,2b,06,68,de,b3,06,20,6d,\
b3,06,e3,9f,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="
http://www.bitdefender.fr/scan8/images/scan-online-b_05.jpg"
"SubscribedURL"="
http://www.bitdefender.fr/scan8/images/scan-online-b_05.jpg"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,12,02,00,00,19,01,00,00,d9,01,00,00,b0,00,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,19,01,00,00,d9,01,00,00,b0,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,0f,0a,41,c0,ab,74,d0,25,f1,06,68,de,0f,0a,20,6d,\
0f,0a,59,d7,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,00,00,ee,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\A238D92590DB53DD.job
Completion time: 06-11-01 20:04:58.04
C:\ComboFix.txt ... 06-11-01 20:04
C:\ComboFix2.txt ... 06-11-01 19:09