Re
voici le scan ave c combofix (reboot de l'ordi)
"didi" - 2007-07-24 22:37:53 - ComboFix 07-07-23.6 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\didi\APPLIC~1.\.rdr.ini
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\bot.dll
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Think-Adz.lnk
C:\WINDOWS\b122.exe
C:\WINDOWS\kernel32.exe
C:\WINDOWS\retadpu27.exe
C:\WINDOWS\smsys.dat
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
C:\WINDOWS\system32\_000020_.tmp.dll
C:\WINDOWS\system32\1582084341.dll
C:\WINDOWS\system32\20303384341.dll
C:\WINDOWS\system32\b06FdUe
C:\WINDOWS\system32\config\system~1\applic~1\install.dat
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\dllh8jkd1q1.exe
C:\WINDOWS\system32\dllh8jkd1q2.exe
C:\WINDOWS\system32\dllh8jkd1q6.exe
C:\WINDOWS\system32\dllh8jkd1q7.exe
C:\WINDOWS\system32\dllh8jkd1q8.exe
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\poof
C:\WINDOWS\system32\vedxg4am1et2.exe
C:\WINDOWS\system32\vedxg6ame4.exe
C:\WINDOWS\system32\vedxga3me2.exe
C:\WINDOWS\system32\vedxga4m1et4.exe
C:\WINDOWS\system32\vedxga4me1.exe
C:\WINDOWS\system32\vedxga5me3.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_POOF
-------\LEGACY_RUNTIME
-------\asc3550u
((((((((((((((((((((((((( Files Created from 2007-06-24 to 2007-07-24 )))))))))))))))))))))))))))))))
2007-07-24 22:37 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-23 23:30 <REP> dr------- C:\DOCUME~1\NETWOR~1\Favoris
2007-07-23 23:30 <REP> d-------- C:\DOCUME~1\NETWOR~1\Menu D‚marrer
2007-07-23 23:30 <REP> d-------- C:\Brave-Sentry
2007-07-23 23:28 20,992 --a------ C:\oocmhxl.exe
2007-07-23 23:28 <REP> d-------- C:\Program Files\CCleaner
2007-07-23 23:18 97,559 --a------ C:\WINDOWS\spooldr.exe
2007-07-23 23:18 7,968 --a------ C:\WINDOWS\system32\spooldr.sys
2007-07-23 22:04 <REP> d-------- C:\Program Files\MSN Messenger
2007-07-23 18:43 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-22 23:11 2,322,176 --a------ C:\WINDOWS\system32\TUKernel.exe
2007-07-22 21:25 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-07-22 21:25 <REP> d-------- C:\Program Files\TuneUp Utilities 2007
2007-07-22 21:25 <REP> d-------- C:\DOCUME~1\didi\APPLIC~1\TuneUp Software
2007-07-22 21:14 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-07-22 21:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
2007-07-22 20:26 <REP> d-------- C:\DOCUME~1\didi\.housecall6.6
2007-07-22 16:33 <REP> d-------- C:\Program Files\Dictionnaire
2007-07-22 05:05 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-07-22 05:04 <REP> d-------- C:\Program Files\Yahoo!
2007-07-22 05:04 <REP> d-------- C:\Program Files\Common Files
2007-07-22 04:59 <REP> d-------- C:\WINDOWS\cache
2007-07-22 04:58 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-07-22 04:55 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-07-22 04:54 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-07-22 04:52 <REP> d-------- C:\Program Files\Microsoft Works
2007-07-22 04:51 <REP> d-------- C:\WINDOWS\SHELLNEW
2007-07-22 04:51 <REP> d-------- C:\Program Files\Microsoft.NET
2007-07-22 04:49 <REP> dr-h----- C:\MSOCache
2007-07-22 04:31 <REP> d-------- C:\DOCUME~1\didi\APPLIC~1\vlc
2007-07-22 04:01 <REP> d--h----- C:\WINDOWS\msdownld.tmp
2007-07-22 04:01 <REP> d-------- C:\WINDOWS\system32\fr-fr
2007-07-22 03:51 <REP> d-------- C:\WINDOWS\network diagnostic
2007-07-22 03:43 <REP> d-------- C:\Program Files\Windows Media Connect 2
2007-07-22 03:38 <REP> d-------- C:\WINDOWS\system32\LogFiles
2007-07-22 03:38 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-07-22 03:34 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-22 03:24 <REP> d-------- C:\DOCUME~1\didi\Contacts
2007-07-22 03:23 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-07-21 20:55 <REP> d-------- C:\Program Files\Foreignword
2007-07-21 20:54 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-07-21 20:54 5,120 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-07-21 20:54 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-21 20:54 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-07-21 20:54 1,415,680 --a------ C:\WINDOWS\system32\WMV9VCM.dll
2007-07-21 20:54 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-07-21 20:03 <REP> d-------- C:\Program Files\SymNetDrv
2007-07-21 19:37 <REP> d-------- C:\Program Files\VideoLAN
2007-07-21 19:35 <REP> d-------- C:\Program Files\AtomixMP3
2007-07-21 19:34 <REP> d-------- C:\Program Files\RM-X© Search
2007-07-21 19:33 4,608 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-07-21 19:33 <REP> d-------- C:\Program Files\RM-X© Easy Compress
2007-07-21 19:32 91,904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-21 19:32 124,016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-21 19:32 <REP> d-------- C:\Program Files\Norton AntiVirus
2007-07-21 19:24 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-07-21 19:24 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-07-21 19:15 <REP> d--hs---- C:\RECYCLER
2007-07-21 19:04 25,808 --a------ C:\WINDOWS\system\CTL3DV2.DLL
2007-07-21 19:04 <REP> d-------- C:\LAROUSSE
2007-07-21 19:03 <REP> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Symantec
2007-07-21 19:03 <REP> d-------- C:\DOCUME~1\didi\WINDOWS
2007-07-21 19:00 <REP> d-------- C:\WINDOWS\pss
2007-07-21 18:56 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-07-21 18:55 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2007-07-21 18:55 58,496 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-07-21 18:55 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2007-07-21 18:55 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2007-07-21 18:55 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2007-07-21 18:55 <REP> d-------- C:\WINDOWS\Documents and Settings
2007-07-21 18:55 <REP> d-------- C:\WINDOWS\All Users
2007-07-21 18:54 8,832 --a------ C:\WINDOWS\system32\drivers\wmiacpi.sys
2007-07-21 18:54 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2007-07-21 18:53 76,288 --a------ C:\WINDOWS\system32\uniime.dll
2007-07-21 18:53 <REP> d-a------ C:\Program Files
2007-07-21 18:53 <REP> d--hs---- C:\WINDOWS\Installer
2007-07-21 18:53 <REP> d-------- C:\Program Files\Fichiers communs\SpeechEngines
2007-07-21 18:53 <REP> d-------- C:\Program Files\Fichiers communs\ODBC
2007-07-21 18:52 98,304 --a------ C:\WINDOWS\system32\msir3jp.dll
2007-07-21 18:52 838,144 --a------ C:\WINDOWS\system32\chtbrkr.dll
2007-07-21 18:52 811,064 --a------ C:\WINDOWS\system32\imjp81k.dll
2007-07-21 18:52 70,656 --a------ C:\WINDOWS\system32\korwbrkr.dll
2007-07-21 18:52 6,144 -ra------ C:\WINDOWS\system32\kbdth3.dll
2007-07-21 18:52 6,144 -ra------ C:\WINDOWS\system32\kbdth2.dll
2007-07-21 18:52 6,144 -ra------ C:\WINDOWS\system32\kbdinpun.dll
2007-07-21 18:52 6,144 --a------ C:\WINDOWS\system32\kbd101a.dll
2007-07-21 18:52 6,144 --a------ C:\WINDOWS\system32\ftlx041e.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdvntc.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdurdu.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdth1.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdth0.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdsyr2.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdsyr1.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdintel.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdintam.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdinmar.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdinkan.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdinhin.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdinguj.dll
2007-07-21 18:52 5,632 -ra------ C:\WINDOWS\system32\kbdindev.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-24 15:35:05 64,052 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-07-24 15:35:05 445,672 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-07-24 15:30:28 374,912 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2007-07-21 16:34:00 -------- d-----w C:\Program Files\RM-X® Search
2007-07-21 16:33:36 -------- d-----w C:\Program Files\RM-X® Easy Compress
2007-07-21 14:41:33 1,571 --sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_Presario R4100 (EF003EA#ABF)_YN_0Pres_QCND5340MS1_EU_46_I3085_SHP_V42.3A_BF.19_T050809_WXH2_L40C_M895_J60_7AMD_8Sempron_91.79_#070721_N10EC8139_(EF003EA#ABF)_XMOBILE_CN10_Z10024378_2F.19_G10025955.MRK
2007-04-25 14:22:35 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 22:05]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-02-17 15:01]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-21 17:33]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 15:12]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 15:11]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 04:36]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 16:21]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 17:50]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-21 17:29]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-07-21 20:03]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 12:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15:00]
"TuneUp MemOptimizer"="C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" [2007-04-27 01:10]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"ccleaner"="C:\Program Files\CCleaner\ccleaner.exe" [2007-05-10 14:01]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{356B3A99-01D7-512D-113C-EBA850C10473}"= C:\DOCUME~1\didi\LOCALS~1\Temp\sysreg.dll [2007-07-23 23:29 10752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SysRegClass"= {356B3A99-01D7-512D-113C-EBA850C10473} - C:\DOCUME~1\didi\LOCALS~1\Temp\sysreg.dll [2007-07-23 23:29 10752]
"SysRegClass"= {356B3A99-01D7-512D-113C-EBA850C10473} - Apartment [ ]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xanadu]
C:\Program Files\Foreignword\Xanadu\Xanadu.exe
R0 a347bus;a347bus;C:\WINDOWS\system32\DRIVERS\a347bus.sys
R0 a347scsi;a347scsi;C:\WINDOWS\system32\Drivers\a347scsi.sys
R1 AmdK8;Pilote de processeur AMD;C:\WINDOWS\system32\DRIVERS\AmdK8.sys
R1 eabfiltr;EABFiltr;\??\C:\WINDOWS\system32\drivers\EABFiltr.sys
R1 PQNTDrv;PQNTDrv;C:\WINDOWS\system32\drivers\PQNTDrv.sys
R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI;C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
R2 UxTuneUp;TuneUp Extension de thŠme;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 CAMCAUD;Conexant AMC Audio;C:\WINDOWS\system32\drivers\camc6aud.sys
R3 CAMCHALA;CAMCHALA;C:\WINDOWS\system32\drivers\camc6hal.sys
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys
S3 eabusb;eabusb;\??\C:\WINDOWS\system32\drivers\eabusb.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a02c131a-37b4-11dc-9d23-00904bf413df}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a02c131b-37b4-11dc-9d23-00904bf413df}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a02c131c-37b4-11dc-9d23-00904bf413df}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
Contents of the 'Scheduled Tasks' folder
2007-07-22 18:26:04 C:\WINDOWS\tasks\Maintenance en 1 clic.job
2007-07-21 16:57:28 C:\WINDOWS\tasks\Norton AntiVirus - Analyser mon ordinateur - didi.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-24 22:41:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\spooldr.exe [2008] 0x8432EC00
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\\24\xe1\21]
"DisplayName"="\x5448\x398\x5448\x398\1"
"DeviceDesc"="\x5448\x398\x5448\x398\1"
"ProviderName"="\xfed4\21\xee18\x7c91\xff44\21\b"
"MFG"="\x558"
"ReinstallString"="C:\WINDOWS\System32\ReinstallBackups\\xe114\21\x80\xc010\DriverFiles\.INF"
"DeviceInstanceIds"=str(7):"d:\swsetup\video\sbdrv\smbus\smbusati.inf"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120"
scanning hidden files ...
C:\WINDOWS\bak sana Paris Hilton ne hale gelmis hapiste :(4.zip 121036 bytes hidden from API
C:\WINDOWS\bak sana Paris Hilton ne hale gelmis hapiste :(40.zip 121038 bytes hidden from API
scan completed successfully
hidden files: 2
**************************************************************************
Completion time: 2007-07-24 22:43:54 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-24 22:43
--- E O F ---
hijackthis scan
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:52, on 24/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\didi\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.symantec.com/techsupp/subscribe/sub_select_region.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Xanadu - {5CC384BB-1326-11D5-F4AE-00C04923F885} - C:\Program Files\Foreignword\Xanadu\XanaduLaunch.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A03A27E8-FA9D-4624-BB70-A09862D5B4C1}: NameServer = 61.123.225.72
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0331209-6D06-4948-B9C8-F1E0309E9909}: NameServer = 61.123.225.72
O21 - SSODL: SysRegClass - {356B3A99-01D7-512D-113C-EBA850C10473} - C:\DOCUME~1\didi\LOCALS~1\Temp\sysreg.dll
O22 - SharedTaskScheduler: SysRegClass - {356B3A99-01D7-512D-113C-EBA850C10473} - C:\DOCUME~1\didi\LOCALS~1\Temp\sysreg.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
End of file - 8698 bytes
je pense que je vais formater, je viens juste d'ouvrir une fenetre et il y a eu au moins 200 fenetres qui sont apparus... j'ai peur...