Deckard's System Scanner v20071014.68
Run by Benzekri on 2008-05-04 22:10:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
6: 2008-05-04 22:10:43 UTC - RP105 - Deckard's System Scanner Restore Point
5: 2008-05-04 12:49:09 UTC - RP104 - Point de vérification système
4: 2008-05-02 08:33:41 UTC - RP103 - Point de vérification système
3: 2008-05-01 08:25:18 UTC - RP102 - Point de vérification système
2: 2008-04-29 23:43:11 UTC - RP101 - Point de vérification système
-- First Restore Point --
1: 2008-04-28 21:14:48 UTC - RP100 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
[color=red]System Drive C: has 1.19 GiB (less than 15%) free./color
-- HijackThis (run as Benzekri.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:12:29, on 04/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
C:\Program Files\VisualTaskTips\VisualTaskTips.exe
C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Menara\dslmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Benzekri\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Benzekri.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ma/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: SSV - {69F6C0AE-0C78-4999-B6D1-62932A265C5D} - C:\WINDOWS\onenasus.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Waiting1690] C:\Windows\stid1690.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [xkbfiltr] "E:\driver\ps2\xkb.exe"
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SkwatAutoconnect] C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [cityblah] C:\DOCUME~1\Benzekri\APPLIC~1\AMOKLO~1\bolt stop.exe
O4 - HKCU\..\Run: [VisualTaskTips] C:\Program Files\VisualTaskTips\VisualTaskTips.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: CamTrack.lnk = C:\Program Files\DigitalPeers\CamTrack\camtrack.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\Menara\dslmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{54DFF3BD-8531-423B-A36F-838FAAC3A468}: NameServer = 85.255.113.117,85.255.112.191
O17 - HKLM\System\CCS\Services\Tcpip\..\{F7ABEC66-BD55-40AC-8160-51D4444388DB}: NameServer = 85.255.113.117 85.255.112.191
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.117 85.255.112.191
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.117 85.255.112.191
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.117 85.255.112.191
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: ADSLAutoconnect - Unknown owner - C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
End of file - 8179 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 StarOpen - c:\windows\system32\drivers\staropen.sys
R3 e4usbaw (USB ADSL2 WAN Adapter) - c:\windows\system32\drivers\e4usbaw.sys <Not Verified; Analog Devices Inc.; ADSL USB WAN Driver>
R3 Xkbfiltr - c:\windows\system32\drivers\xkbfiltr.sys <Not Verified; Esac; Xkbfiltr>
S1 InCDPass - c:\windows\system32\drivers\incdpass.sys (file missing)
S1 InCDRm (InCD Reader) - c:\windows\system32\drivers\incdrm.sys (file missing)
S3 CAM1690 (USB PC Camera) - c:\windows\system32\drivers\cam1690.sys <Not Verified; ; USB Camera Driver>
S3 MA-660 (Mobile Action MA-660 USB Infrared Adapter) - c:\windows\system32\drivers\ma-660.sys <Not Verified; Mobile Action Tech. Inc.; MA-620 Infrared Driver.>
S3 SNP325 (USB PC Camera (SNPSTD325)) - c:\windows\system32\drivers\snp325.sys (file missing)
S3 SNPSTD3 (USB PC Camera (SNPSTD3)) - c:\windows\system32\drivers\snpstd3.sys <Not Verified; Sonix Co. Ltd.; USB PC Camera>
S4 InCDFs (InCD File System) - c:\windows\system32\drivers\incdfs.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 ADSLAutoconnect - "c:\program files\adsl autoconnect\adsl autoconnect.exe" -z <Not Verified; ; ADSLAutoconnect>
S4 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S4 FLEXnet Licensing Service - "c:\program files\fichiers communs\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Clavier standard 101/102 touches ou clavier Microsoft Natural Keyboard PS/2
Device ID: ACPI\PNP0303\4&37F38CC7&0
Manufacturer: (Claviers standard)
Name: Clavier standard 101/102 touches ou clavier Microsoft Natural Keyboard PS/2
PNP Device ID: ACPI\PNP0303\4&37F38CC7&0
Service: i8042prt
Class GUID:
Description:
Device ID: ACPI\WEC0515\4&37F38CC7&0
Manufacturer:
Name:
PNP Device ID: ACPI\WEC0515\4&37F38CC7&0
Service:
Class GUID:
Description:
Device ID: ACPI\WEC0518\4&37F38CC7&0
Manufacturer:
Name:
PNP Device ID: ACPI\WEC0518\4&37F38CC7&0
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-04-30 19:26:35 276 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job
2008-04-20 19:25:36 398 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
-- Files created between 2008-04-04 and 2008-05-04 -----------------------------
2008-05-04 10:17:16 0 d-------- C:\Program Files\Trend Micro
2008-05-02 00:19:10 217600 --a------ C:\WINDOWS\onenasus.dll
2008-05-02 00:19:09 51 --a------ C:\smp.bat
2008-04-28 21:51:50 737280 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2008-04-28 21:51:45 0 d-------- C:\WINDOWS\system32\athan
2008-04-28 21:51:38 0 d-------- C:\Program Files\Athan
2008-04-28 19:01:23 0 d-------- C:\Program Files\amoklogroam
2008-04-26 14:55:05 0 d-------- C:\Program Files\Investintech.com Inc
2008-04-20 19:39:14 0 d-------- C:\Program Files\Fake Webcam
2008-04-20 19:29:51 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Uniblue
2008-04-20 19:24:15 0 d-------- C:\Program Files\Uniblue
2008-04-20 10:38:30 2560 --a------ C:\WINDOWS\system32\bitcometres.dll <Not Verified; BitComet; BitComet BCTP Helper>
2008-04-20 10:38:29 0 d-------- C:\Downloads
2008-04-20 10:37:44 0 d-------- C:\Program Files\BitComet
2008-04-19 00:36:43 0 d-------- C:\Program Files\ASIO4ALL v2
2008-04-19 00:36:33 225280 --a------ C:\WINDOWS\system32\rewire.dll <Not Verified; Propellerhead Software AB; ReWire>
2008-04-19 00:35:11 0 d-------- C:\Program Files\VstPlugins
2008-04-19 00:33:49 0 d-------- C:\Program Files\Outsim
2008-04-19 00:21:34 0 d-------- C:\Program Files\Image-Line
2008-04-17 23:47:55 0 d-------- C:\Documents and Settings\Benzekri\Application Data\IDM
2008-04-17 23:47:49 0 d-------- C:\Documents and Settings\Benzekri\Application Data\DMCache
2008-04-17 23:47:16 0 d-------- C:\Program Files\Internet Download Manager
2008-04-17 18:46:43 0 d-------- C:\Documents and Settings\Benzekri\Application Data\ooVoo Details
2008-04-17 18:45:48 0 d-------- C:\Program Files\ooVoo
2008-04-15 00:51:44 0 d-------- C:\Documents and Settings\Benzekri\Application Data\BitTorrent
2008-04-15 00:50:26 0 d-------- C:\Program Files\BitTorrent
2008-04-15 00:36:24 45056 --a------ C:\WINDOWS\system32\wnaspi32.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-04-15 00:36:24 25244 --a------ C:\WINDOWS\system32\drivers\aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-04-15 00:36:24 4672 --a------ C:\WINDOWS\system\wowpost.exe <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-04-15 00:36:24 5600 --a------ C:\WINDOWS\system\winaspi.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2008-04-15 00:29:28 203776 --a------ C:\WINDOWS\system32\clrviddc.dll <Not Verified; Iterated Systems, Inc.; ClearVideo Decoder DLL>
2008-04-12 08:38:00 4445 --a------ C:\WINDOWS\system32\drivers\XKBFILTR.SYS <Not Verified; Esac; Xkbfiltr>
2008-04-11 23:55:46 0 d-------- C:\Documents and Settings\Benzekri\Application Data\WinRAR
2008-04-11 15:04:33 0 d-------- C:\Program Files\Menara
2008-04-10 23:52:49 0 dr-h----- C:\Documents and Settings\Benzekri\Recent
2008-04-10 22:40:36 27136 -ra------ C:\WINDOWS\system32\drivers\MA-660.sys <Not Verified; Mobile Action Tech. Inc.; MA-620 Infrared Driver.>
2008-04-10 22:36:25 344064 --a------ C:\WINDOWS\system32\msexch35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:24 123664 --a------ C:\WINDOWS\system32\msjint35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:22 294912 --a------ C:\WINDOWS\system32\msxbse35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:21 166672 --a------ C:\WINDOWS\system32\mstext35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:19 262144 --a------ C:\WINDOWS\system32\msrd2x35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:19 250128 --a------ C:\WINDOWS\system32\mspdox35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:18 168720 --a------ C:\WINDOWS\system32\msltus35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:17 1238288 --a------ C:\WINDOWS\system32\msjt4jlt.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:16 1050896 --a------ C:\WINDOWS\system32\msjet35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:15 252688 --a------ C:\WINDOWS\system32\msexcl35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:13 368912 --a------ C:\WINDOWS\system32\VBAR332.DLL <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
2008-04-10 22:36:12 44304 --a------ C:\WINDOWS\system32\msrpfs35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:11 415504 --a------ C:\WINDOWS\system32\msrepl35.dll <Not Verified; Microsoft Corporation; Microsoft® Access>
2008-04-10 22:36:10 24848 --a------ C:\WINDOWS\system32\msjter35.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-04-10 22:36:10 39424 --a------ C:\WINDOWS\system32\JETCOMP.exe <Not Verified; Microsoft Corporation; Microsoft® Database Compact Utility>
2008-04-04 23:09:40 0 d-------- C:\Program Files\VisualTaskTips
2008-04-04 08:40:46 0 d-------- C:\Program Files\Total Video Converter
2008-04-04 08:32:15 0 d-------- C:\Program Files\QuickTime
2008-04-04 08:12:09 114616 -ra------ C:\WINDOWS\system32\drivers\e4usbaw.sys <Not Verified; Analog Devices Inc.; ADSL USB WAN Driver>
2008-04-04 03:19:07 0 d-------- C:\Program Files\CommentCaMarche
2008-04-04 02:19:53 0 d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-04 01:54:04 0 d-------- C:\Program Files\Bonjour
2008-04-04 01:08:11 0 d-------- C:\Program Files\Fichiers communs\Macrovision Shared
-- Find3M Report ---------------------------------------------------------------
2008-05-04 08:07:08 0 d-------- C:\Program Files\Fichiers communs\InstallShield
2008-05-04 08:06:43 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-04 08:06:39 0 d-------- C:\Program Files\Fichiers communs\Adobe
2008-05-03 19:07:04 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Adobe
2008-05-01 15:11:39 1956 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-04-28 19:02:57 0 d-------- C:\Documents and Settings\Benzekri\Application Data\amoklogroam
2008-04-27 23:03:28 2068 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-26 13:12:10 0 d-------- C:\Program Files\AV Vcs 6.0 DIAMOND
2008-04-18 12:58:43 0 d-------- C:\Program Files\Acoustica Audio Converter Pro
2008-04-14 21:21:35 0 d-------- C:\Program Files\Fichiers communs
2008-04-11 17:54:20 0 d-------- C:\Program Files\Google
2008-04-11 15:27:36 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Google
2008-04-11 15:21:12 0 d-------- C:\Documents and Settings\Benzekri\Application Data\AVGTOOLBAR
2008-04-11 12:28:08 460986 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-04-11 12:28:08 72126 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-04-10 22:32:49 0 d-------- C:\Program Files\Samsung
2008-04-04 13:23:28 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Ahead
2008-04-01 22:03:19 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Ashampoo
2008-04-01 21:59:37 0 d-------- C:\Program Files\Ashampoo
2008-04-01 07:48:21 0 d-------- C:\Program Files\WebEye
2008-04-01 07:43:50 0 d-------- C:\Program Files\Citron
2008-04-01 07:36:42 0 d-------- C:\Program Files\Fichiers communs\snpstd3
2008-04-01 07:36:02 0 d-------- C:\Documents and Settings\Benzekri\Application Data\InstallShield
2008-04-01 01:06:49 0 d-------- C:\Program Files\Microsoft Works
2008-04-01 01:06:15 0 d-------- C:\Program Files\MSBuild
2008-03-31 23:36:40 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Real
2008-03-31 23:27:28 0 d-------- C:\Program Files\Fichiers communs\xing shared
2008-03-31 23:26:47 0 d-------- C:\Program Files\Fichiers communs\Real
2008-03-28 22:38:25 0 d-------- C:\Program Files\Acoustica MP3 Audio Mixer
2008-03-28 22:28:39 0 d-------- C:\Program Files\Skype
2008-03-28 22:28:34 0 d-------- C:\Program Files\Fichiers communs\Skype
2008-03-28 14:07:56 0 d-------- C:\Documents and Settings\Benzekri\Application Data\CamTrack
2008-03-28 14:05:19 0 d-------- C:\Program Files\DigitalPeers
2008-03-28 14:05:03 0 d-------- C:\Program Files\UCOM
2008-03-28 11:03:59 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Samsung
2008-03-28 10:21:30 0 d-------- C:\Program Files\AVG
2008-03-28 00:22:52 0 d-------- C:\Program Files\MSN Messenger
2008-03-27 19:01:40 0 d-------- C:\Program Files\Fichiers communs\Ahead
2008-03-27 19:01:39 0 d-------- C:\Program Files\Nero
2008-03-26 23:09:41 0 d-------- C:\Program Files\Circle Developement
2008-03-26 23:09:39 0 d-------- C:\Program Files\Messenger Plus! Live
2008-03-26 23:09:36 0 d-------- C:\Program Files\Windows Live
2008-03-24 02:46:13 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Help
2008-03-24 02:45:30 0 d-------- C:\Program Files\Rico Software
2008-03-24 02:25:17 0 d-------- C:\Program Files\SuperCopier2
2008-03-24 02:19:15 0 d-------- C:\Program Files\PhotoBrush
2008-03-23 18:13:20 0 d-------- C:\Program Files\Paltalk Messenger
2008-03-23 18:12:45 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Paltalk
2008-03-22 22:09:20 0 d-------- C:\Program Files\PCI Audio Applications
2008-03-22 22:08:51 0 d-------- C:\Program Files\AIDA32 - Enterprise System Information
2008-03-16 23:01:44 0 d-------- C:\Program Files\PC Drivers HeadQuarters
2008-03-15 14:24:17 0 d-------- C:\Program Files\Real
2008-03-15 12:14:54 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Macromedia
2008-03-15 08:35:09 0 d-------- C:\Program Files\ADSL Autoconnect
2008-03-15 08:12:36 0 d-------- C:\Program Files\Alwil Software
2008-03-15 08:04:14 0 d-------- C:\Documents and Settings\Benzekri\Application Data\Identities
2008-03-15 07:56:52 0 d-------- C:\Program Files\microsoft frontpage
2008-03-15 07:56:07 0 -rahs---- C:\MSDOS.SYS
2008-03-15 07:56:07 0 -rahs---- C:\IO.SYS
2008-03-15 07:56:07 0 --a------ C:\CONFIG.SYS
2008-03-15 07:56:07 0 --a------ C:\AUTOEXEC.BAT
2008-03-15 07:53:50 0 d--h----- C:\Program Files\WindowsUpdate
2008-03-15 07:53:44 0 d-------- C:\Program Files\Services en ligne
2008-03-15 07:52:38 0 d-------- C:\Program Files\Fichiers communs\MSSoap
2008-03-15 07:52:26 0 d-------- C:\Program Files\Movie Maker
2008-03-15 07:51:04 21892 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-15 07:50:31 0 d-------- C:\Program Files\Online Services
2008-03-15 07:50:24 0 d-------- C:\Program Files\Messenger
2008-03-15 07:50:17 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-15 07:50:04 0 d-------- C:\Program Files\Windows NT
2008-03-15 07:38:23 0 d-------- C:\Program Files\Fichiers communs\ODBC
2008-03-15 07:38:18 0 d-------- C:\Program Files\Fichiers communs\SpeechEngines
2008-03-15 07:37:44 62 --ahs---- C:\Documents and Settings\Benzekri\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69F6C0AE-0C78-4999-B6D1-62932A265C5D}]
02/05/2008 00:19 217600 --a------ C:\WINDOWS\onenasus.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [03/08/2004 22:32]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [03/08/2004 22:32]
"Waiting1690"="C:\Windows\stid1690.exe" []
"tsnpstd3"="C:\WINDOWS\tsnpstd3.exe" [21/04/2007 09:37]
"snpstd3"="C:\WINDOWS\vsnpstd3.exe" [10/05/2007 13:18]
"xkbfiltr"="E:\driver\ps2\xkb.exe" []
"Athan"="C:\Program Files\Athan\Athan.exe" [06/09/2007 18:25]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [29/03/2008 18:37]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [31/03/2008 23:23]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [19/08/2004 16:09]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34]
"SkwatAutoconnect"="C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" [15/03/2008 08:35]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [07/07/2006 16:45]
"cityblah"="C:\DOCUME~1\Benzekri\APPLIC~1\AMOKLO~1\bolt stop.exe" [28/04/2008 19:00]
"VisualTaskTips"="C:\Program Files\VisualTaskTips\VisualTaskTips.exe" [31/07/2006 11:33]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [11/04/2008 15:17]
"Uniblue SpeedUpMyPC"="C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [22/10/2007 10:13]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [07/12/2007 15:03]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - C:\Program Files\Menara\dslmon.exe [11/04/2008 15:10:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NofolderOptions"=0 (0x0)
"NoFind"=0 (0x0)
"NoRun"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="lsass.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^PalTalk.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Benzekri^Menu Démarrer^Programmes^Démarrage^CamTrack.lnk]
path=C:\Documents and Settings\Benzekri\Menu Démarrer\Programmes\Démarrage\CamTrack.lnk
backup=C:\WINDOWS\pss\CamTrack.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
"C:\Program Files\BitComet\BitComet.exe" /tray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]
Mixer.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ooVoo.exe]
C:\Program Files\ooVoo\ooVoo.exe /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"gusvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"AresChatServer"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{594db84f-ffbe-11dc-aadb-aecb940683a1}]
AutoRun\command- G:\pagefile.pif
explore\Command- G:\pagefile.pif
open\Command- G:\pagefile.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad2efb76-0acd-11dd-aaf3-4d6564696130}]
AutoRun\command- G:\1ce.cmd
explore\Command- G:\1ce.cmd
open\Command- G:\1ce.cmd
-- Hosts -----------------------------------------------------------------------
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
60 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-05-04 22:13:55 ------------