rebonjour,
je sai bien que c suicidaire mais je voyage a travers le japon et ce n'est pas mon pc en fait et en plus c tout en japonais!!!lol
voici les rapports combofix et hijackthis. merci encore et bon courage pour cette lecture qui m'a l'air fastidieuse pour le neophite que je suis....
ComboFix 07-12-21.4 - ゲスト1 2005-12-31 11:22:46.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Home Edition 5.1.2600.2.932.81.1041.18.72 [GMT 9:00]
Running from: C:\Documents and Settings\ゲスト1\デスクトップ\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\microsoft\office\system\finder.dll
C:\Documents and Settings\All Users\Application Data.\microsoft\office\system\sysloader.exe
C:\Documents and Settings\All Users\Application Data.\microsoft\office\userdata\_keepfile
C:\Documents and Settings\All Users\Application Data.\microsoft\office\userdata\tJV9vOJq9d.dll
C:\Documents and Settings\All Users\Application Data.\microsoft\pctools
C:\Documents and Settings\All Users\Application Data.\microsoft\pctools\pctools.dll
C:\Documents and Settings\All Users\Application Data.\t
C:\Documents and Settings\All Users\Application Data\microsoft\pctools\pctools.dll
C:\Documents and Settings\ゲスト1\デスクトップ\仕事部屋\しんや\慎也整理箱\ダウンロード控え\jword_plugin\CnsMin.dll
C:\Documents and Settings\ゲスト1\デスクトップ\仕事部屋\しんや\慎也整理箱\ダウンロード控え\jword_plugin\CnsMinSetup_pino.exe
C:\privilege.dat
C:\Program Files\ad4all
C:\Program Files\ad4all\Install.exe
C:\Program Files\ad4all\install.ini
C:\Program Files\ad4all\link1\eachlink.htm
C:\Program Files\ad4all\link1\eachlink.ico
C:\Program Files\ad4all\link1\ebaylink.ico
C:\Program Files\ad4all\link1\install.ini
C:\Program Files\ad4all\link1\Thumbs.db
C:\Program Files\Common Files\cpush
C:\Program Files\Common Files\cpush\cpush.dll
C:\Program Files\Common Files\cpush\Uninst.exe
C:\WINDOWS\571.bmp
C:\WINDOWS\avpsrv.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\dc.exe
C:\WINDOWS\help\Other.exe
C:\WINDOWS\icon.ico
C:\WINDOWS\inf\Other.exe
C:\WINDOWS\kvsc3.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\msimms32.exe
C:\WINDOWS\start.exe
C:\WINDOWS\sviq.exe
C:\WINDOWS\SYSTEM32\571.dll
C:\WINDOWS\SYSTEM32\66061.exe
C:\WINDOWS\SYSTEM32\7661.dll
C:\WINDOWS\system32\avpsrv.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\config\Win.exe
C:\WINDOWS\system32\csikez.dll
C:\WINDOWS\system32\d3d1caps.srg
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\dodolook591.exe
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\WINDOWS\system32\igrpba.dll
C:\WINDOWS\system32\jukolr.dll
C:\WINDOWS\system32\k119900426211.exe
C:\WINDOWS\system32\k119900427219.exe
C:\WINDOWS\system32\k11990176552.exe
C:\WINDOWS\system32\k11990176563.exe
C:\WINDOWS\system32\k11990176574.exe
C:\WINDOWS\system32\k11990176606.exe
C:\WINDOWS\system32\k11990176628.exe
C:\WINDOWS\system32\k119901766510.exe
C:\WINDOWS\system32\k119901766611.exe
C:\WINDOWS\system32\k119901766712.exe
C:\WINDOWS\system32\k119901766913.exe
C:\WINDOWS\system32\k119901767115.exe
C:\WINDOWS\system32\k119901767216.exe
C:\WINDOWS\system32\k119901767417.exe
C:\WINDOWS\system32\k119901767518.exe
C:\WINDOWS\system32\k119901767619.exe
C:\WINDOWS\system32\k11990178302.exe
C:\WINDOWS\system32\k11990178313.exe
C:\WINDOWS\system32\k11990178324.exe
C:\WINDOWS\system32\k11990178356.exe
C:\WINDOWS\system32\k11990178388.exe
C:\WINDOWS\system32\k11990178399.exe
C:\WINDOWS\system32\k119901784010.exe
C:\WINDOWS\system32\k119901784311.exe
C:\WINDOWS\system32\k119901784714.exe
C:\WINDOWS\system32\k119901843011.exe
C:\WINDOWS\system32\k119901844119.exe
C:\WINDOWS\system32\k11990185204.exe
C:\WINDOWS\system32\k11990185269.exe
C:\WINDOWS\system32\k119901854511.exe
C:\WINDOWS\system32\k119901855619.exe
C:\WINDOWS\system32\k11990540392.exe
C:\WINDOWS\system32\k11990540413.exe
C:\WINDOWS\system32\k119905405111.exe
C:\WINDOWS\system32\k119905405313.exe
C:\WINDOWS\system32\k119905406119.exe
C:\WINDOWS\system32\k119905721011.exe
C:\WINDOWS\system32\k119905722119.exe
C:\WINDOWS\system32\kvsc3.dll
C:\WINDOWS\system32\lxzqlp.dll
C:\WINDOWS\system32\lyloader.exe
C:\WINDOWS\system32\lymangr.dll
C:\WINDOWS\system32\mhsha1.dat
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\mprmsgse.axz
C:\WINDOWS\system32\mpyzxf.dll
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\mscpx32r.det
C:\WINDOWS\system32\msdeg32.dll
C:\WINDOWS\system32\msimms32.dll
C:\WINDOWS\system32\MsPrint32D.dll
C:\WINDOWS\system32\n1199017820k.exe
C:\WINDOWS\system32\nvdispdrv.dll
C:\WINDOWS\system32\qhcnvw.dll
C:\WINDOWS\system32\SHQ.DLL
C:\WINDOWS\system32\SHQMANGR.DLL
C:\WINDOWS\system32\svchost.dat
C:\WINDOWS\system32\svchost.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\windows.scr
C:\WINDOWS\system32\WinSit.exe
C:\WINDOWS\system32\wviugj.dll
C:\WINDOWS\system32\xrmgkm.dll
C:\WINDOWS\system32\xwnvml.dll
C:\WINDOWS\TEMP.\~my1.tmp
C:\WINDOWS\tempaq
C:\WINDOWS\upxdnd.exe
C:\Documents and Settings\All Users\Application Data.\microsoft\office\userdata
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ACPIDISK
-------\LEGACY_MS_2FAX
-------\LEGACY_SVCHOST
-------\acpidisk
-------\ms_2fax
-------\svchost
((((((((((((((((((((((((( Files Created from 2005-11-21 to 2005-12-21 )))))))))))))))))))))))))))))))
.
2005-12-31 11:13 . 2005-12-31 11:09 17,560 --a------ C:\WINDOWS\xfvdpj.exe
2005-12-31 11:13 . 2005-12-31 11:09 16,503 --a------ C:\WINDOWS\jvojzz.exe
2005-12-31 11:11 . 2005-12-31 11:11 127,488 --a------ C:\WINDOWS\SYSTEM32\upkuhi.dll
2005-12-31 11:11 . 2005-12-31 11:11 27,648 --a------ C:\WINDOWS\SYSTEM32\gipmxf.dll
2005-12-31 11:11 . 2005-12-31 11:11 26,624 --a------ C:\WINDOWS\SYSTEM32\zucnwx.dll
2005-12-31 11:11 . 2007-12-31 08:26 16,080 --a------ C:\WINDOWS\umzlda.exe
2005-12-31 11:11 . 2005-12-31 11:09 15,297 --a------ C:\WINDOWS\aqueys.exe
2005-12-31 11:10 . 2005-12-31 11:10 52,529 --a------ C:\WINDOWS\SYSTEM32\k113599499819.exe
2005-12-31 11:09 . 2005-12-31 11:09 29,537 --a------ C:\WINDOWS\SYSTEM32\k113599498811.exe
2005-12-31 11:09 . 2005-12-31 11:14 1 --a------ C:\WINDOWS\SYSTEM32\num.ini
2005-12-31 10:36 . 2005-12-31 10:36 68 --a------ C:\WINDOWS\SYSTEM32\407
2005-12-31 10:06 . 2005-12-31 10:06 68 --a------ C:\WINDOWS\SYSTEM32\3f9
2005-12-31 09:36 . 2005-12-31 09:36 68 --a------ C:\WINDOWS\SYSTEM32\352
2005-12-31 09:13 . 2005-12-31 09:13 0 --a------ C:\WINDOWS\SYSTEM32\21c15500
2005-12-31 09:06 . 2005-12-31 09:06 68 --a------ C:\WINDOWS\SYSTEM32\[u]0[/u]7fc
2005-12-31 09:06 . 2005-12-31 11:09 29 --a------ C:\WINDOWS\SYSTEM32\91-63850
2005-12-31 09:05 . 2005-12-31 09:05 208,896 ---hs---- C:\WINDOWS\SYSTEM32\bho.dll
2005-12-31 09:05 . 2005-12-21 11:42 803 --a------ C:\WINDOWS\SYSTEM32\ini.~tmp
2005-12-31 09:05 . 2005-12-31 09:05 8 --a------ C:\WINDOWS\SYSTEM32\75-63850
2005-12-31 09:04 . 2005-12-31 09:05 <DIR> d-------- C:\WINDOWS\SYSTEM32\13242
2005-12-31 09:04 . 2005-12-21 11:42 49,152 --a------ C:\WINDOWS\SYSTEM32\16CCF8.DLL
2005-12-31 09:04 . 2005-12-31 09:04 14,504 --a------ C:\WINDOWS\SYSTEM32\2E1A7558.EXE
2005-12-31 09:04 . 2005-12-21 11:42 598 --a------ C:\WINDOWS\SYSTEM32\setyahoo.ini
2005-12-31 09:04 . 2005-12-31 09:04 23 --a------ C:\WINDOWS\SYSTEM32\6F906650.dat
2005-12-21 11:44 . 2005-12-21 11:44 127,488 --a------ C:\WINDOWS\SYSTEM32\qsbzwt.dll
2005-12-21 11:44 . 2005-12-21 11:44 26,624 --a------ C:\WINDOWS\SYSTEM32\hatatd.dll
2005-12-21 11:44 . 2005-12-21 11:42 15,297 --a------ C:\WINDOWS\dnujld.exe
2005-12-21 11:43 . 2005-12-21 11:42 17,560 --a------ C:\WINDOWS\NVDispDRV.EXE
2005-12-21 11:43 . 2005-12-21 11:42 16,503 --a------ C:\WINDOWS\RegSrv64D.exE
2005-12-21 11:42 . 2005-12-21 11:42 52,529 --a------ C:\WINDOWS\SYSTEM32\k113513297319.exe
2005-12-21 11:42 . 2005-12-21 11:42 29,537 --a------ C:\WINDOWS\SYSTEM32\k113513296411.exe
2005-12-21 11:42 . 2005-12-21 11:42 16,080 --a------ C:\WINDOWS\MsPrint32D.exe
2005-12-21 11:42 . 2005-12-21 11:42 8,192 --a------ C:\WINDOWS\SYSTEM32\REGKEY.hiv
2005-12-21 11:22 . 2005-12-21 11:24 0 --a------ C:\WINDOWS\SYSTEM32\Penx.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-30 12:39 30,311 --sha-w C:\NeroCheck.exe
2007-12-30 12:30 13,903 ---h--w C:\auto.exe
2007-12-29 00:19 17,280 --sha-w C:\WINDOWS\system32\drivers\opengl.sys
2007-12-28 03:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 03:31 --------- d-----w C:\Program Files\Trojan Remover
2007-12-25 03:51 --------- d-----w C:\Program Files\Sharp
2007-11-27 05:49 --------- d-----w C:\Program Files\iPod
2007-11-21 07:12 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2007-11-21 06:49 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-21 06:49 --------- d-----w C:\Program Files\Windows Live Favorites
2007-11-21 06:28 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-21 06:28 --------- d-----w C:\Program Files\Windows Live
2007-11-21 06:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-16 08:20 17,280 ----a-w C:\WINDOWS\system32\drivers\opengl.sys.vir
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 08:13 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\U3
2007-10-10 02:38 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Leadertech
2007-09-19 01:42 --------- d-----w C:\Documents and Settings\NEC-PCuser\Application Data\Apple
2007-09-17 06:56 62,024 ----a-w C:\Documents and Settings\NEC-PCuser\Application Data\GDIPFONTCACHEV1.DAT
2007-09-14 08:44 --------- d-----w C:\Program Files\iTunes
2007-09-14 07:48 --------- d-----w C:\Program Files\Common Files\Apple
2007-09-14 07:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-04 11:13 --------- d--h--w C:\Documents and Settings\ゲスト1\Application Data\Hangame
2007-08-21 01:57 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Google
2007-08-21 01:48 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Adobe
2007-08-21 01:44 --------- d-----w C:\Program Files\Google
2007-08-01 12:34 --------- d-----w C:\Program Files\Skype
2007-08-01 12:34 --------- d-----w C:\Program Files\Common Files\Skype
2007-08-01 12:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-06-23 10:11 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Skype
2007-05-29 13:57 --------- d-----w C:\Program Files\QuickTime
2007-05-25 01:25 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-04-23 10:32 364,160 ----a-w C:\WINDOWS\system32\drivers\update.sys
2007-04-06 11:47 --------- d-----w C:\Documents and Settings\Guest\Application Data\Skype
2007-02-09 11:10 574,464 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2006-12-23 15:31 --------- d-----w C:\Program Files\Madonote
2006-12-23 02:35 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Apple Computer
2006-12-20 04:34 --------- d-----w C:\Program Files\SHOEISHA
2006-12-18 13:50 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\MSN6
2006-12-12 05:17 --------- d-----w C:\Program Files\Common Files\L&H
2006-12-12 05:14 --------- d-----w C:\Program Files\Microsoft ActiveSync
2006-11-27 05:03 --------- d-----w C:\Program Files\Apple Software Update
2006-10-18 11:00 38,528 ----a-w C:\WINDOWS\system32\drivers\wpdusb.sys
2006-10-14 05:24 --------- d-----w C:\Documents and Settings\NEC-PCuser\Application Data\i4
2006-10-02 09:48 --------- d-----w C:\Documents and Settings\Guest\Application Data\Apple Computer
2006-10-02 07:11 --------- d-----w C:\Documents and Settings\Guest\Application Data\MSN6
2006-09-28 10:00 82,944 ------w C:\WINDOWS\system32\drivers\WudfRd.sys
2006-09-28 09:55 77,568 ------w C:\WINDOWS\system32\drivers\WudfPf.sys
2006-09-25 04:44 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\i4
2006-09-25 04:41 --------- d-----w C:\Program Files\Common Files\Konica Uploader
2006-09-25 04:34 --------- d-----w C:\Program Files\Fudeoh2006Select
2006-09-25 03:17 --------- d-----w C:\Program Files\Rakuten
2006-09-25 02:55 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Macromedia
2006-09-25 02:53 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Help
2006-09-19 06:44 15,664 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2006-09-11 12:57 --------- d-----w C:\Documents and Settings\NEC-PCuser\Application Data\Skype
2006-08-21 09:14 128,896 ------w C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-20 10:23 --------- d-----w C:\Documents and Settings\NEC-PCuser\Application Data\Apple Computer
2006-08-20 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2006-08-16 09:37 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2006-08-14 10:34 332,928 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2006-07-22 15:16 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Identities
2006-07-22 10:06 --------- d-----w C:\Documents and Settings\NEC-PCuser\Application Data\Microsoft Web Folders
2006-07-22 09:12 --------- d-----w C:\Documents and Settings\NEC-PCuser\Application Data\MSN6
2006-07-22 09:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\MSN6
2006-07-22 08:10 --------- d-----w C:\Program Files\microsoft frontpage
2006-07-22 08:02 --------- d-----w C:\Documents and Settings\NEC-PCuser\Application Data\NEC
2006-07-22 07:47 --------- d-----w C:\Documents and Settings\ゲスト1\Application Data\Microsoft
2006-07-22 05:31 --------- d-----w C:\Program Files\Exif Launcher
2006-07-22 05:30 --------- d-----w C:\Program Files\Exif Viewer
2006-07-22 05:30 --------- d-----w C:\Program Files\DP Editor
2006-07-22 05:18 --------- d-----w C:\Program Files\Audio Download
2006-07-18 01:10 --------- d-----w C:\Program Files\Common Files\Adaptec Shared
2006-07-13 08:48 202,240 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
2006-06-14 09:00 82,944 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2006-06-14 08:47 6,400 ----a-w C:\WINDOWS\system32\drivers\splitter.sys
2006-06-14 08:47 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
2006-05-05 09:47 174,592 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2006-05-05 09:41 453,120 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2006-04-20 11:51 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2006-03-17 00:33 262,784 ------w C:\WINDOWS\system32\drivers\http.sys
2006-03-06 07:08 8,946 ----a-w C:\WINDOWS\system32\drivers\tmimo3.bin
2006-03-06 07:07 783,872 ----a-w C:\WINDOWS\system32\drivers\tmimo31p.SYS
2006-02-23 08:11 0 ----a-w C:\WINDOWS\system32\drivers\tmimo3p.CAT
2006-02-15 00:22 142,464 ----a-w C:\WINDOWS\system32\drivers\aec.sys
2006-02-02 23:59 355,616 ----a-w C:\WINDOWS\system32\drivers\PRISMA02.sys
2005-12-31 02:10 17,053 ----a-w C:\WINDOWS\WINSvr32.exE
2005-12-31 02:10 16,569 ----a-w C:\WINDOWS\NAVMon32.exE
2005-12-31 02:09 16,643 ----a-w C:\WINDOWS\PTSShell.exe
2005-12-21 02:43 28,672 ----a-w C:\WINDOWS\SYSTEM32\MsIMMs32.dll
2005-12-21 02:43 28,672 ----a-w C:\WINDOWS\SYSTEM32\cmdbcs.dll
2005-12-21 02:43 28,672 ----a-w C:\WINDOWS\SYSTEM32\AVPSrv.dll
2005-12-21 02:43 28,160 ----a-w C:\WINDOWS\SYSTEM32\WINSvr32.dll
2005-12-21 02:43 28,160 ----a-w C:\WINDOWS\SYSTEM32\NVDispDrv.dll
2005-12-21 02:43 27,136 ----a-w C:\WINDOWS\SYSTEM32\DbgHlp32.dll
2005-12-21 02:43 26,624 ----a-w C:\WINDOWS\SYSTEM32\PTSShell.dll
2005-12-21 02:43 26,624 ----a-w C:\WINDOWS\SYSTEM32\msccrt.dll
2005-12-21 02:43 26,112 ----a-w C:\WINDOWS\SYSTEM32\RegSrv64D.dll
2005-12-21 02:43 26,112 ----a-w C:\WINDOWS\SYSTEM32\NAVMon32.dll
2005-12-21 02:42 50,873 --sha-w C:\WINDOWS\351677MM.DLL
2002-12-16 11:29 8 --sh--w C:\WINDOWS\DRM\pdrm.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F776B2A-72DF-40C1-BD69-EDB642A706D7}]
2005-12-31 09:05 208896 ---hs---- C:\WINDOWS\SYSTEM32\bho.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:55]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG9.0"="C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.exe" [2005-03-17 14:40]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Mini\3.2\Apps\apdproxy.exe" [2007-04-27 15:44]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2003-01-21 16:19]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-27 15:06]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11]
"WSockDrv32"="C:\WINDOWS\dnujld.exe" [2005-12-21 11:42]
"LotusHlp"="C:\WINDOWS\LotusHlp.exe" [2005-12-21 11:42]
"PTSShell"="C:\WINDOWS\PTSShell.exe" [2005-12-21 11:42]
"WinSysW"="C:\WINDOWS\351677L.exe" []
"NAVMon32"="C:\WINDOWS\NAVMon32.exE" [2005-12-21 11:42]
"WINSvr32"="C:\WINDOWS\WINSvr32.exE" [2005-12-21 11:42]
"RegSrv64D"="C:\WINDOWS\jltjhy.exe" [2005-12-21 11:42]
"Kvsc3"="C:\WINDOWS\Kvsc3.exE" []
"AVPSrv"="C:\WINDOWS\AVPSrv.exE" []
"cmdbcs"="C:\WINDOWS\cmdbcs.exe" []
"DbgHlp32"="C:\WINDOWS\okyeig.exe" []
"MsIMMs32"="C:\WINDOWS\MsIMMs32.exE" []
"NVDispDrv"="C:\WINDOWS\ntlcwj.exe" [2005-12-21 11:42]
"msccrt"="C:\WINDOWS\msccrt.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"McAfeeVirusScanService"="" []
"MOSearch"="C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe" [2007-12-12 23:22]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2004-08-04 16:55 C:\WINDOWS\SYSTEM32\ctfmon.exe]
C:\Documents and Settings\All Users\スタート メニュー\プログラム\スタートアップ\
QuickShelf.lnk - C:\Program Files\Microsoft Reference\Microsoft Bookshelf 3.0\qshelf.exe [2000-12-20 19:06:14]
PenPlus手書きメモ.lnk - C:\Program Files\PenPlusパーソナル\PenHusen.exe [2002-05-28 16:24:39]
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2002-08-03 22:15:39]
EPSONプリンタウインドウ!3 環境設定(2).lnk - C:\WINDOWS\SYSTEM32\E_SRCV02.EXE [2002-06-02 12:08:46]
Photo Loader 監視.lnk - C:\Documents and Settings\ゲスト1\My Documents\setupソフト\Plauto.exe [2002-10-23 20:17:05]
Exif Launcher.lnk - C:\Program Files\Exif Launcher\QuickDCF.exe [2006-07-22 14:31:07]
NetShow PowerPoint Helper.lnk - C:\Program Files\NetShow Services\Tools\nsppthlp.exe [1998-10-07 18:30:58]
アクティブメニューNX.lnk - C:\NECAMENU\NActMenu.exe [2000-12-21 16:21:14]
Network tool (UX-MF25_50_60).lnk - C:\Program Files\Sharp\UX-MF25_50_60\SMON.exe [2007-12-25 12:51:43]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= C:\Program Files\DigitalAdventure\imorning\start.htm
FriendlyName= アイモーニング
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
Source= C:\WINDOWS\WEB\Wallpaper\biglobe_adt.htm
FriendlyName= BIGLOBE ACTIVE DESKTOP
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"Hidserv"=Hidserv.exe run
"NMFTASK"=NMFTASK.EXE /RESET
"NECTVRC"=C:\PROGRA~1\nectvrc\tvrc.exe
"Alogserv"=C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
"NECMFK"=C:\PROGRA~1\necmfk\necmfk.exe
"LoadQM"=loadqm.exe
R0 36n9pih2;36n9pih;C:\WINDOWS\system32\DRIVERS\36n9pih2.sys [2004-08-04 16:55]
R2 bwcdrv;BUFFALO Wireless Configuration;C:\WINDOWS\system32\DRIVERS\bwcdrv.sys [2003-12-21 17:21]
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-24 12:40]
R2 rbwzjc14;rbwzjc14;C:\WINDOWS\system32\drivers\rbwzjc14.sys [2004-08-04 16:55]
R2 YahooSvr;Yahoo Service;C:\WINDOWS\system32\13242\svchost.exe [2005-12-31 09:05]
R3 CBBCM43;BUFFALO WLI-CB-XXX Series Wireless LAN Adapter;C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-11-01 17:13]
R3 Ptserli;PCTEL Serial Device Driver for INTEL;C:\WINDOWS\system32\DRIVERS\ptserli.sys [2001-08-17 13:28]
S2 584823C8;584823C8;C:\WINDOWS\system32\279F07D0.EXE -k []
S2 6F906650;6F906650;C:\WINDOWS\system32\2E1A7558.EXE -g []
S2 sysloader;System Event loader;"C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\sysloader.exe" []
S3 BT848;NEC TV Tuner Unit/ Bt878 WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2001-08-23 13:59]
S3 BTTUNER;NEC TV Tuner Unit/ Bt878 WDM Tv Tuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2001-08-23 13:59]
S3 BTXBAR;NEC TV Tuner Unit/ Bt878 WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [2001-08-23 13:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3532da70-b087-11dc-978f-001601234175}]
\Shell\AutoRun\command - F:\autorun.exe
\Shell\Open\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1d4cec0-af7e-11dc-978d-001601234175}]
\Shell\Auto\command - F:\auto.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}]
C:\WINDOWS\system32\NeroCheck.exe s
.
Contents of the 'Scheduled Tasks' folder
"2007-12-05 14:00:02 C:\WINDOWS\Tasks\アプリケーションの起動チューンアップ.job"
"2007-12-30 23:52:02 C:\WINDOWS\Tasks\有効期間の確認通知のアンインストール.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-12-30 23:57:02 C:\WINDOWS\Tasks\データ収集の PCHealth スケジューラ.job"
- C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
"2007-12-29 14:35:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-12-30 23:41:02 C:\WINDOWS\Tasks\Windows Live Toolbar の更新プログラムを確認します.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2005-12-21 11:44:42
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OpenGL]
"ImagePath"="system32\DRIVERS\opengl.sys"
.
Completion time: 2005-12-21 11:47:18 - machine was rebooted
.
2007-12-22 14:26:36 --- E O F ---
-----------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:00:27, on 2005/12/21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\Drivers\bwcsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\13242\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Photoshop Album Mini\3.2\Apps\apdproxy.exe
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\13242\ctfmon.exe
C:\Program Files\Microsoft Reference\Microsoft Bookshelf 3.0\qshelf.exe
C:\Program Files\PenPlusパーソナル\PenHusen.exe
C:\Documents and Settings\ゲスト1\My Documents\setupソフト\Plauto.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\NECAMENU\NActMenu.exe
C:\Program Files\Sharp\UX-MF25_50_60\SMON.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\WINDOWS\system32\13242\ctfmon.exe
C:\DOCUME~1\ゲスト1\LOCALS~1\Temp\HiJackThis.zip の一時ディレクトリ 1\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {8F776B2A-72DF-40C1-BD69-EDB642A706D7} - C:\WINDOWS\SYSTEM32\bho.dll
O2 - BHO: Windows Live サインイン ヘルパー - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Mini\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Tekram USB Web Camera TM-506
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WSockDrv32] C:\WINDOWS\dnujld.exe
O4 - HKLM\..\Run: [LotusHlp] C:\WINDOWS\LotusHlp.exe
O4 - HKLM\..\Run: [PTSShell] C:\WINDOWS\PTSShell.exe
O4 - HKLM\..\Run: [WinSysW] C:\WINDOWS\351677L.exe
O4 - HKLM\..\Run: [NAVMon32] C:\WINDOWS\NAVMon32.exE
O4 - HKLM\..\Run: [WINSvr32] C:\WINDOWS\WINSvr32.exE
O4 - HKLM\..\Run: [RegSrv64D] C:\WINDOWS\jltjhy.exe
O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\COMMON~1\System\MOSearch\Bin\mosearch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [ezie] rundll32 "C:\WINDOWS\Downlo~1\ezie.dll",start
O4 - HKLM\..\Policies\Explorer\Run: [ai38qv] rundll32 "C:\WINDOWS\Downlo~1\ai38qv.dll",Run
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Bookshelfで検索(&L) - res://C:\PROGRAM FILES\MICROSOFT REFERENCE\MICROSOFT BOOKSHELF 3.0\BSDEF.DLL/#1001
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: このコンテンツを引用 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Windows Live Writer でこのコンテンツに関する記事を書く(&B) - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: リサーチ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C945890-327C-11D5-995C-0090272E513E} (UpdateNecXPCtl Class) - file://E:\GuideXP\obj\UpNxp.ocx
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/...
O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) -
http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: 584823C8 - Unknown owner - C:\WINDOWS\system32\279F07D0.EXE
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BUFFALO Wireless Configuration Service (bwcsrv) - Unknown owner - C:\WINDOWS\System32\Drivers\bwcsrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: System Event loader (sysloader) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\sysloader.exe (file missing)
O23 - Service: Yahoo Service (YahooSvr) - Unknown owner - C:\WINDOWS\system32\13242\svchost.exe
O24 - Desktop Component 0: (no name) -
http://www.microsoft.com/japan/plus/images/screenshot_aqua_375x283.jpg
O24 - Desktop Component 2: アイモーニング - C:\Program Files\DigitalAdventure\imorning\start.htm
O24 - Desktop Component 3: BIGLOBE ACTIVE DESKTOP - C:\WINDOWS\WEB\Wallpaper\biglobe_adt.htm