Re,
Ca y est, c'est fait alors dans l'ordre le rapport ComboFix suivi de celui d'HJT :
Rapport ComboFix
ComboFix 08-06-01.6 - milo 2008-06-05 9:08:21.5 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1033.18.432 [GMT 2:00]
Running from: C:\Documents and Settings\milo\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\milo\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!/b/color
FILE ::
C:\Documents and Settings\All Users\Application Data\TEMP\
C:\TEMP\
C:\WINDOWS\system32\utkudhnd.ini
C:\WINDOWS\system32\ymhbgwdv.ini
C:\WINDOWS\system32\ymhbgwdv.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\utkudhnd.ini
C:\WINDOWS\system32\ymhbgwdv.ini
C:\WINDOWS\system32\ymhbgwdv.tmp
----- BITS: Possible infected sites -----
hxxp://DFRLYONSM01.ddom.ad.corp
.
((((((((((((((((((((((((( Files Created from 2008-05-05 to 2008-06-05 )))))))))))))))))))))))))))))))
.
2008-05-31 22:48 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-05-31 22:48 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-05-31 22:48 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-05-31 22:48 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-05-31 22:03 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-31 21:26 . 2008-05-31 21:26 <DIR> d-------- C:\Program Files\NKProds
2008-05-31 21:26 . 2008-05-31 21:26 <DIR> d-------- C:\Documents and Settings\milo\Application Data\nCleaner
2008-05-31 19:58 . 2008-05-31 19:58 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-31 18:55 . 2008-05-31 18:55 <DIR> d-------- C:\Documents and Settings\milo\Application Data\Malwarebytes
2008-05-31 18:55 . 2008-05-31 18:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-28 16:33 . 2008-05-28 16:33 <DIR> d-------- C:\Program Files\IGC
2008-05-23 09:13 . 2008-05-23 09:13 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-23 08:43 . 2008-05-26 22:54 2,076 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-19 14:05 . 2008-05-19 14:59 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-05-15 11:43 . 2008-05-15 11:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-15 10:47 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-05-15 10:47 . 2004-08-03 22:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-05-14 18:14 . 1998-07-30 12:51 305,152 --a------ C:\WINDOWS\IsUninst.exe
2008-05-14 18:10 . 2008-05-14 18:17 <DIR> d-------- C:\TEMP
2008-05-14 17:49 . 2008-05-14 17:49 <DIR> d-------- C:\Documents and Settings\milo\Application Data\TuneUp Software
2008-05-14 17:49 . 2008-05-14 17:49 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-14 17:49 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-14 17:48 . 2008-05-14 17:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-05-14 14:18 . 2008-05-14 14:19 <DIR> d-------- C:\Documents and Settings\milo\IGC
2008-05-14 07:32 . 2008-05-14 07:32 <DIR> d-------- C:\Program Files\PDFCreator Toolbar
2008-05-14 07:32 . 2008-05-14 07:33 <DIR> d-------- C:\Program Files\PDFCreator
2008-05-14 07:32 . 2008-05-14 07:32 264,097 --a------ C:\WINDOWS\PDFCreator_Toolbar_Uninstaller_9084.exe
2008-05-14 07:32 . 1998-07-13 02:08 141,312 --a------ C:\WINDOWS\system32\MSCMCFR.DLL
2008-05-14 07:32 . 1998-06-24 01:00 137,000 --a------ C:\WINDOWS\system32\MSMAPI32.OCX
2008-05-14 07:32 . 2001-10-28 17:42 116,224 --a------ C:\WINDOWS\system32\pdfcmnnt.dll
2008-05-14 07:32 . 1998-07-13 02:08 59,904 --a------ C:\WINDOWS\system32\MSCC2FR.DLL
2008-05-14 07:32 . 1998-07-06 01:00 23,552 --a------ C:\WINDOWS\system32\MSMPIDE.DLL
2008-05-13 09:07 . 2008-05-31 21:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-13 09:06 . 2008-05-31 21:08 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-13 08:44 . 2008-05-23 16:18 828 --a------ C:\WINDOWS\wininit.ini
2008-05-13 07:46 . 2008-05-13 07:46 <DIR> d-------- C:\Documents and Settings\milo\Application Data\TmpRecentIcons
2008-05-12 22:21 . 2008-05-20 14:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-12 22:16 . 2008-05-12 22:16 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-05-12 22:16 . 2004-10-07 13:39 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2008-05-12 22:16 . 2001-03-08 18:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-05-12 22:09 . 2008-06-03 21:16 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-12 22:09 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-05-12 22:03 . 2008-05-12 22:03 1 --a------ C:\WINDOWS\system32\kr_done1de
2008-05-07 22:22 . 2008-05-31 21:08 <DIR> d-------- C:\PM
2008-05-06 11:18 . 2008-05-06 11:18 <DIR> dr-h----- C:\MSOCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 12:09 --------- d-----w C:\Program Files\F-Secure
2008-05-31 20:45 505,856 ----a-w C:\WINDOWS\system32\WINLOGON.EXE
2008-05-31 20:03 --------- d-----w C:\Program Files\Java
2008-05-31 19:56 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-22 13:08 58,368 ------w C:\WINDOWS\system32\spoolsv.exe
2008-05-22 13:08 16,896 ------w C:\WINDOWS\system32\svchost.exe
2008-05-22 13:08 14,336 ------w C:\WINDOWS\system32\lsass.exe
2008-05-22 13:08 110,080 ------w C:\WINDOWS\system32\services.exe
2008-05-12 20:05 1,034,240 ----a-w C:\WINDOWS\explorer.exe
2008-05-05 12:47 --------- d-----w C:\Documents and Settings\milo\Application Data\AdobeUM
2008-05-05 07:53 155,995 ----a-w C:\WINDOWS\java\Packages\ECZBJ13L.ZIP
2008-04-23 05:47 --------- d-----w C:\Documents and Settings\milo\Application Data\InterVideo
2008-03-26 08:09 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 08:20 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Documents and Settings\All Users\Application Data\SalesMon ----
---- Directory of C:\WINDOWS\system32\kr_done1de ----
C:\WINDOWS\system32\kr_done1de\
------- Sigcheck -------
2008-05-22 15:08 16896 9491c2135c30b82bb1a6acf928063a59 C:\WINDOWS\system32\svchost.exe
2008-05-31 22:45 505856 6bdf6b80f3c6c37bef59637fa8a652f2 C:\WINDOWS\system32\WINLOGON.EXE
2008-05-12 22:05 1034240 6b06b770badd3ba36da67304ff587ce2 C:\WINDOWS\explorer.exe
2008-05-22 15:08 110080 5cee7e9d377fa228c9e3a95e7d60e08e C:\WINDOWS\system32\services.exe
2008-05-22 15:08 14336 110fb3121c028e5aaedf3307223787cd C:\WINDOWS\system32\lsass.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-03_20.45.58.58 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-03 18:28:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-05 06:58:47 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-05 07:09:38 16,384 ----atw C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Perflib_Perfdata_1e4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\PM\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SecurityBoxKernel"="C:\Program Files\MSI\Security Box\Kernel\SbKrnl.exe" [2005-11-21 23:17 364621]
"F-Secure Manager"="C:\Program Files\F-Secure\Common\FSM32.exe" [2004-09-09 11:03 118832]
"F-Secure TNB"="C:\Program Files\F-Secure\TNB\TNBUtil.exe" [2004-05-27 10:57 684032]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 15:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 12:11 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 12:13 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 12:10 94208]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
coedm-sessionwatcher.lnk - C:\Program Files\COEDM SessionWatcher\coedm-sessionwatcher.exe [2007-07-24 07:34:51 231887]
Symantec NetBackup Desktop Agent.lnk - C:\Program Files\Symantec\NetBackup DLO\DLO\DLOClientu.exe [2007-06-26 13:26:10 7091576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SBSCHED]
C:\Program Files\MSI\Security Box\Kernel\sbxwl.dll 2004-01-30 05:08 24647 C:\Program Files\MSI\Security Box\Kernel\sbxwl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0/u\[u]0/u]
"Script"=\\ddom.ad.corp\SYSVOL\ddom.ad.corp\scripts\GPOSecurityWorkstations\AddAdmins-ddom.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\[u]0/u]
"Script"=\\ddom.ad.corp\SysVol\ddom.ad.corp\scripts\SMSInstall.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1201654002-2523771428-1557942192-119212\Scripts\Logon\[u]0/u\[u]0/u]
"Script"=\\bdom.ad.corp\netlogon\buc\logonpierrelatte.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1201654002-2523771428-1557942192-119212\Scripts\Logon\[u]0/u\1]
"Script"=\\bdom.ad.corp\netlogon\buc\wuauserv.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-371391377-3177841243-1650113322-31118\Scripts\Logoff\[u]0/u\[u]0/u]
"Script"=CleanDocumentum.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-371391377-3177841243-1650113322-31118\Scripts\Logon\[u]0/u\[u]0/u]
"Script"=\\ddom.ad.corp\SYSVOL\ddom.ad.corp\scripts\loginscript.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-371391377-3177841243-1650113322-5347\Scripts\Logoff\[u]0/u\[u]0/u]
"Script"=CleanDocumentum.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-371391377-3177841243-1650113322-5347\Scripts\Logon\[u]0/u\[u]0/u]
"Script"=\\ddom.ad.corp\SYSVOL\ddom.ad.corp\scripts\loginscript.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
"WatchDog"=C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2004-11-10 14:58]
R0 VSP;VERITAS Snapshot Provider;C:\WINDOWS\system32\drivers\vsp.sys [2002-11-04 11:02]
R2 AM.EventService;Access Manager Event Service;"C:\Program Files\Remote Services\AM.utEventServer.exe" [2006-06-29 13:10]
R2 AM.ScriptService;Access Manager Script Service;"C:\Program Files\Remote Services\AM.blScriptEngine.exe" [2006-06-29 13:10]
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2006-02-09 02:50]
R2 DLOChangeJournalSvc;Backup Exec DLO Agent Change Journal Reader;"C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe" [2007-06-26 11:44]
R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 18:14]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSgk.sys [2004-09-10 18:14]
R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys [2003-02-06 14:32]
R2 MCIMonitor;MCI Monitor Service;"C:\Program Files\Remote Services\WENGINE\wmonitor.exe" [2006-01-24 10:07]
R2 SBoxDisk;Security BOX® Disk Driver;C:\WINDOWS\system32\drivers\SBoxDisk.sys [2003-07-01 18:20]
R2 SBoxDiskSrv;Security BOX® Disk;"C:\Program Files\MSI\Security Box\Disk\Sbdsrv.exe" [2003-07-01 18:20]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2008-05-22 15:08]
R3 BW2NDIS5;BW2NDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys [2004-11-02 17:33]
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2004-09-30 22:42]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 12:46]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-06-10 15:26]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-09-30 22:43]
S3 AM.InstallService;Access Manager Install Service;"C:\Program Files\Remote Services\AM.InstallService.exe" [2006-06-29 13:10]
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-09-30 22:43]
S3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2006-02-09 02:50]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-14 17:49]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C869BA1-A1E2-4818-8B12-F22A96DC7EAA}]
msiexec /fu {7C869BA1-A1E2-4818-8B12-F22A96DC7EAA} /qn
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
rundll32.exe advpack.dll,LaunchINFSectionEx C:\WINDOWS\INF\wmactedp.inf,PerUserStub,,4
.
Contents of the 'Scheduled Tasks' folder
"2008-06-05 07:00:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\PM\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-05 09:13:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-05 9:14:33
ComboFix-quarantined-files.txt 2008-06-05 07:14:28
ComboFix2.txt 2008-06-03 18:46:11
Pre-Run: 5,524,320,256 bytes free
Post-Run: 5,531,230,208 bytes free
216
Rapport HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:22, on 2008-06-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Remote Services\AM.utEventServer.exe
C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe
C:\Program Files\Documentum\Shared\DcComponentInstaller.exe
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\Remote Services\WENGINE\wmonitor.exe
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MSI\Security Box\Disk\Sbdsrv.exe
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\Remote Services\AM.blScriptEngine.exe
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure\Common\FIH32.EXE
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\MSI\Security Box\Kernel\SbKrnl.exe
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\F-Secure\FSGUI\fsguiexe.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\PM\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\COEDM SessionWatcher\coedm-sessionwatcher.exe
C:\Program Files\Symantec\NetBackup DLO\DLO\DLOClientu.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet.areva.corp/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://intranet.areva.corp/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy-np.areva.corp/proxy-arevanet-eu.pac
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PM\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O4 - HKLM\..\Run: [SecurityBoxKernel] "C:\Program Files\MSI\Security Box\Kernel\SbKrnl.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\PM\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: coedm-sessionwatcher.lnk = C:\Program Files\COEDM SessionWatcher\coedm-sessionwatcher.exe
O4 - Global Startup: Symantec NetBackup Desktop Agent.lnk = C:\Program Files\Symantec\NetBackup DLO\DLO\DLOClientu.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PM\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PM\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {40895335-0695-4FD9-84B8-7A5B76E7D905} (UDFCHECKINLib.DcCheckInComp) - file://C:\Documentum\Downloads\080071ee8018cc0d\080071ee8018cc0d.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ddom.ad.corp
O17 - HKLM\Software\..\Telephony: DomainName = ddom.ad.corp
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ddom.ad.corp
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = ddom.ad.corp
O20 - Winlogon Notify: SBSCHED - C:\Program Files\MSI\Security Box\Kernel\sbxwl.dll
O23 - Service: Access Manager Event Service (AM.EventService) - MCI, Inc. - C:\Program Files\Remote Services\AM.utEventServer.exe
O23 - Service: Access Manager Install Service (AM.InstallService) - MCI, Inc. - C:\Program Files\Remote Services\AM.InstallService.exe
O23 - Service: Access Manager Script Service (AM.ScriptService) - MCI, Inc. - C:\Program Files\Remote Services\AM.blScriptEngine.exe
O23 - Service: Backup Exec DLO Agent Change Journal Reader (DLOChangeJournalSvc) - Symantec Corporation - C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe
O23 - Service: Documentum Desktop Component Installer - Documentum, a division of EMC. - C:\Program Files\Documentum\Shared\DcComponentInstaller.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MCI Monitor Service (MCIMonitor) - Boingo Wireless, Inc. - C:\Program Files\Remote Services\WENGINE\wmonitor.exe
O23 - Service: Security BOX® Disk (SBoxDiskSrv) - Methode et Solution Informatique S.A.
http://www.msi-sa.com
contact@msi-sa.com - C:\Program Files\MSI\Security Box\Disk\Sbdsrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
End of file - 8080 bytes
Voilà ce que ça m'a donné.
@+