Ok, merci.
Voici le rapport SmitFraudFix :
SmitFraudFix v2.119
Rapport fait à 19:29:45,09, 03/11/2006
Executé à partir de C:\Documents and Settings\perso\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\perso
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\perso\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\perso\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
et le rapport combofix:
perso - 06-11-03 19:35:07,32 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((( Files Created from 2006-10-03 to 2006-11-03 ))))))))))))))))))))))))))))))))))
2006-11-03 19:29 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-11-03 19:29 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-11-03 19:29 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-11-03 19:29 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-11-03 19:29 1,338 --a------ C:\WINDOWS\system32\tmp.reg
2006-11-03 17:42 143,360 --a------ C:\WINDOWS\system32\flash9.dll
2006-11-03 17:16 11,264 --a------ C:\WINDOWS\system32\fixmfs.dll
2006-11-02 00:38 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2006-11-01 23:03 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2006-10-28 00:10 61,440 --a------ C:\WINDOWS\system32\stdstub.dll
2006-10-28 00:10 51,712 --a------ C:\WINDOWS\system32\albus.dll
2006-10-28 00:10 49,152 --a------ C:\WINDOWS\system32\stdvote.dll
2006-10-28 00:10 32,768 --a------ C:\WINDOWS\system32\stdplay.dll
2006-10-28 00:10 28,672 --a------ C:\WINDOWS\system32\drivers\Albus.SYS
2006-10-28 00:10 16,384 --a------ C:\WINDOWS\system32\alsmt.exe
2006-10-28 00:10 106,496 --a------ C:\WINDOWS\system32\stdupnet.dll
2006-10-27 12:49 2,597 --a------ C:\WINDOWS\system32\ipconfig.vbs
2006-10-25 12:42 570,880 --a------ C:\WINDOWS\system32\adsimg01.dll
2006-10-24 22:16 173,184 --a------ C:\WINDOWS\system32\ygpss.scr
2006-10-24 22:14 54,784 --a------ C:\WINDOWS\system32\Inetwh32.dll
2006-10-24 22:14 1,044,480 --a------ C:\WINDOWS\system32\roboex32.dll
2006-10-21 23:04 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-03 19:34 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-03 17:28 -------- d-------- C:\Program Files\Sunbelt Software
2006-11-03 15:28 -------- d-------- C:\Program Files\a-squared Free
2006-11-03 13:03 -------- d-------- C:\Program Files\PeerGuardian2
2006-11-03 01:50 -------- d-------- C:\Program Files\Video Capturix Suite
2006-11-03 01:35 -------- d-------- C:\Program Files\CCleaner
2006-11-03 01:18 -------- d-------- C:\Program Files\eMule
2006-11-03 01:17 -------- d-------- C:\Program Files\CleanUp!
2006-11-02 23:08 -------- d-------- C:\Program Files\Grisoft
2006-11-02 22:50 -------- d-a------ C:\Program Files\MMSAssist
2006-11-02 22:39 -------- d-------- C:\Program Files\WinRAR
2006-11-02 21:59 -------- d-------- C:\Program Files\Internet Explorer
2006-11-02 20:10 -------- d-------- C:\Documents and Settings\perso\Application Data\Lavasoft
2006-11-02 12:23 -------- d-------- C:\Program Files\Fichiers communs\Softwin
2006-11-02 02:45 -------- d-------- C:\Program Files\RegCleaner
2006-11-02 01:39 -------- d-------- C:\Program Files\Windows Defender
2006-11-02 01:39 -------- d-------- C:\Program Files\Microsoft AntiSpyware
2006-11-02 01:39 -------- d-------- C:\Program Files\Fichiers communs\Microsoft Shared
2006-11-02 01:30 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-02 01:03 -------- d-------- C:\Program Files\K-Lite Codec Pack
2006-11-01 22:19 350 --a------ C:\Documents and Settings\perso\Application Data\AutoGK.ini
2006-11-01 22:11 -------- d-------- C:\Program Files\Windows Media Player
2006-11-01 21:51 -------- d-------- C:\Program Files\undelete plus
2006-10-30 19:55 -------- d-------- C:\Documents and Settings\perso\Application Data\DeepBurner
2006-10-30 19:45 -------- d-------- C:\Program Files\Astonsoft
2006-10-30 14:06 -------- d-------- C:\Documents and Settings\perso\Application Data\Image Zone Express
2006-10-29 00:07 -------- d---s---- C:\Documents and Settings\perso\Application Data\Microsoft
2006-10-28 23:12 81920 --a------ C:\WINDOWS\system32\W32N50.dll
2006-10-28 23:12 17134 --a------ C:\WINDOWS\system32\PCANDIS5.sys
2006-10-24 22:30 -------- d-------- C:\Program Files\BitComet
2006-10-24 22:27 -------- d-------- C:\Program Files\Fichiers communs
2006-10-24 22:23 -------- d-------- C:\Program Files\Fichiers communs\AOL
2006-10-24 22:23 -------- d-------- C:\Documents and Settings\perso\Application Data\AOL
2006-10-24 22:16 -------- d-------- C:\Program Files\Viewpoint
2006-10-24 22:16 -------- d-------- C:\Program Files\QuickTime
2006-10-24 22:16 -------- d-------- C:\Program Files\Learn2.com
2006-10-24 22:16 -------- d-------- C:\Program Files\Fichiers communs\aolback
2006-10-24 22:16 -------- d-------- C:\Documents and Settings\perso\Application Data\You've Got Pictures Screensaver
2006-10-24 22:15 -------- d-------- C:\Program Files\Fichiers communs\Nullsoft
2006-10-23 14:09 -------- d-------- C:\Program Files\AOLbox
2006-10-23 13:45 -------- d-------- C:\Documents and Settings\perso\Application Data\Mozilla
2006-10-14 23:48 346849 --a------ C:\Documents and Settings\perso\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
2006-10-14 18:35 4173 --a------ C:\Documents and Settings\perso\Application Data\HPSU_48BitScanUpdate.log
2006-10-14 18:32 524565 --a------ C:\Documents and Settings\perso\Application Data\Update_HP_RedboxHprblog_HPSU.log
2006-10-14 18:30 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll
2006-10-11 14:29 -------- d-------- C:\Program Files\Hewlett-Packard
2006-09-25 16:45 666240 --a------ C:\WINDOWS\system32\aswBoot.exe
2006-09-25 16:40 87424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2006-09-25 16:40 85952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2006-09-25 16:39 36176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2006-09-25 16:39 16352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2006-09-25 16:37 90112 --a------ C:\WINDOWS\system32\AVASTSS.scr
2006-09-25 16:37 24560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2006-09-24 11:21 8983 --a------ C:\WINDOWS\xtrestmd.dll
2006-09-23 12:36 -------- d-------- C:\Program Files\HP
2006-09-23 12:36 -------- d-------- C:\Program Files\Fichiers communs\HP
2006-09-22 14:29 348 --a------ C:\Documents and Settings\perso\Application Data\HelpFilesUpdatePatch_PRINTHELPWRAPPER.log
2006-09-22 14:29 2752 --a------ C:\Documents and Settings\perso\Application Data\PatchUpdate_HP_ISRegionListUpdatelog_HPSU.log
2006-09-22 14:29 0 --a------ C:\Documents and Settings\perso\Application Data\HelpFilesUpdatePatch_HELPFILEREPLACE.log
2006-09-22 14:28 3915 --a------ C:\Documents and Settings\perso\Application Data\PatchUpdate_IZClosingDiscError.log
2006-09-22 14:28 3144 --a------ C:\Documents and Settings\perso\Application Data\PatchUpdate_InstantShareJPG.log
2006-09-22 14:25 7143 --a------ C:\Documents and Settings\perso\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
2006-09-22 14:05 444 --a------ C:\Documents and Settings\perso\Application Data\Hewlett-PackardHP PSC 1400 series1157969865_PROTOCOL.log
2006-09-22 14:05 362 --a------ C:\Documents and Settings\perso\Application Data\Hewlett-PackardHP PSC 1400 series1157969865_UI.log
2006-09-22 14:05 0 --a------ C:\Documents and Settings\perso\Application Data\Hewlett-PackardHP PSC 1400 series1157969865_API.log
2006-09-22 14:05 -------- d-------- C:\Documents and Settings\perso\Application Data\HP
2006-09-22 06:44 358400 -rahs---- C:\WINDOWS\system32\soundmix.dll
2006-09-18 22:35 -------- d-------- C:\Program Files\Messenger
2006-09-18 22:32 -------- d-------- C:\Program Files\Outlook Express
2006-09-18 22:32 -------- d-------- C:\Program Files\Fichiers communs\System
2006-09-18 19:51 -------- d-------- C:\Program Files\Common Files
2006-09-18 19:24 12023296 --a------ C:\Program Files\avastsetupfre.exe
2006-09-18 19:20 5037072 --a------ C:\Program Files\spybotsd14.exe
2006-09-18 19:13 10617256 --a------ C:\Program Files\a2freesetup.exe
2006-09-18 17:01 7 --a------ C:\Documents and Settings\perso\Application Data\dapcon1.2.ini
2006-09-18 16:48 190976 --a------ C:\WINDOWS\system32\flash8.dll
2006-09-18 16:17 -------- d-------- C:\Documents and Settings\perso\Application Data\Macromedia
2006-09-18 13:39 278528 --a------ C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2006-09-13 06:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-11 11:10 -------- d-------- C:\Program Files\Fichiers communs\Hewlett-Packard
2006-08-31 09:56 5800 --a------ C:\WINDOWS\system32\nt.sys
2006-08-30 14:11 82080 --a------ C:\Documents and Settings\perso\Application Data\GDIPFONTCACHEV1.DAT
2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 13:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 12:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-08-10 17:17 194560 --a------ C:\WINDOWS\runsetup.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Smapp"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMTray.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,90,01,00,00,00,00,00,00,90,01,00,00,3a,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:000000ff
"EditLevel"=dword:00000000
"NoRun"=dword:00000000
"NoClose"=dword:00000000
"NoSaveSettings"=dword:00000000
"NoFileMenu"=dword:00000000
"NoCommonGroups"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"DTService"="rundll32.exe C:\\WINDOWS\\system32\\soundmix.dll,Load"
"DEFAULT"="rundll32.exe C:\\WINDOWS\\system32\\SYSPOL~1.DLL,Start"
"CONFIGURATION"="rundll32.exe C:\\WINDOWS\\system32\\tapidef.dll,Start"
"9"="C:\\WINDOWS\\system32\\Ravdm.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"0aMCPClient"="{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}"
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\HP Digital Imaging Monitor.lnk"
"backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe "
"item"="HP Digital Imaging Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Kodak software updater.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Kodak software updater.lnk"
"backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE "
"item"="Kodak software updater"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logiciel Kodak EasyShare.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Logiciel Kodak EasyShare.lnk"
"backup"="C:\\WINDOWS\\pss\\Logiciel Kodak EasyShare.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -hx"
"item"="Logiciel Kodak EasyShare"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Service Manager.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Service Manager.lnk"
"backup"="C:\\WINDOWS\\pss\\Service Manager.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~3\\80\\Tools\\Binn\\sqlmangr.exe /n"
"item"="Service Manager"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\-200431]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="-200431"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\-200431.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON PictureMate 500]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="E_FATI9TE"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9TE.EXE /P21 \"EPSON PictureMate 500\" /O6 \"USB004\" /M \"PictureMate 500\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hkcmd"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\hkcmd.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPWuSchd2"
"hkey"="HKLM"
"command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="igfxtray"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\igfxtray.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InstantTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PCLETray"
"hkey"="HKCU"
"command"="C:\\Program Files\\Pinnacle\\Shared Files\\InstantCDDVD\\PCLETray.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IW_Drop_Icon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iwctrl"
"hkey"="HKCU"
"command"="C:\\Program Files\\Pinnacle\\InstantCDDVD\\InstantWrite\\iwctrl.exe /dropdisc"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
"key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows"
"item"="????????Ÿ
????????"
"hkey"="HKCU"
"command"="????????Ÿ
????????"
"inimapping"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXSUPMON]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LXSUPMON"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\LXSUPMON.EXE RUN"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PSDrvCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\PSDrvCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Profiler]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Profiler"
"hkey"="HKLM"
"command"="C:\\Program Files\\Saitek\\Software\\Profiler.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AdobeR"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\AdobeR.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rlflnmk]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="rlflnmk"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\rlflnmk.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SaiMfd"
"hkey"="HKLM"
"command"="C:\\Program Files\\Saitek\\Software\\SaiMfd.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiSmart]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SaiSmart"
"hkey"="HKLM"
"command"="C:\\Program Files\\Saitek\\Software\\SaiSmart.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Update"
"hkey"="HKLM"
"command"="C:\\Program Files\\Fichiers communs\\UPDATE2\\Update.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSASCui"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Win_Update_Program.job
Completion time: 06-11-03 19:37:04.07
C:\ComboFix.txt ... 06-11-03 19:37
un diagnostic?