This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HJT log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

seems something wrong on my PC, any advice welcome, thanks in advance

Logfile of HijackThis v1.99.1
Scan saved at 14:35:03, on 07/02/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\WINDOWS\System32\FortiSslvpnDaemon.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Propriétaire\Mes documents\eric\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=8116
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BMbb3aa087] Rundll32.exe "C:\WINDOWS\System32\jwdlwusi.dll",s
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://fr.encyclopedia.yahoo.com/rsc/tdserver.cab
O16 - DPF: {5CE7A7AF-8C5E-48CF-AE30-8FC6F01C27E3} - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_3fr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1196868666953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: FortiSslvpnDaemon - Fortinet Inc. - C:\WINDOWS\System32\FortiSslvpnDaemon.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

_______________________________________________________
1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt



____________________________________
Did you have Nortons internet security installed at one time and have you uninstalled it completly?




_________________________
In your next reply I would like to see:
  • A new HJT log
  • Let me know about Nortons internet security.
  • The report from ComboFix
Hi,
first thanks for your answer. concerning Norton, I think something from norton was on the PC when we bought it, i desintalled it long time ago.

here is the 2 logs you asked :

Logfile of HijackThis v1.99.1
Scan saved at 15:29, on 2008-02-10
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\FortiSslvpnDaemon.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Propriétaire\Mes documents\eric\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=8116
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://fr.encyclopedia.yahoo.com/rsc/tdserver.cab
O16 - DPF: {5CE7A7AF-8C5E-48CF-AE30-8FC6F01C27E3} - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_3fr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1196868666953
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe (file missing)
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: FortiSslvpnDaemon - Fortinet Inc. - C:\WINDOWS\System32\FortiSslvpnDaemon.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe


ComboFix 08-02.05.3 - Propriétaire 2008-02-10 15:11:12.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.1.1252.1.1036.18.910 [GMT 1:00]
Endroit: C:\Documents and Settings\Propriétaire\bureau\combofix.exe
Command switches used :: /killall
* Création d'un nouveau point de restauration
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\System32\awvvs.dll
C:\WINDOWS\system32\iifdcbx.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Propriétaire\Local Settings\Application Data\lbfkxckinc.dat
C:\Documents and Settings\Propriétaire\Local Settings\Application Data\lbfkxckinc.exe
C:\Documents and Settings\Propriétaire\Local Settings\Application Data\lbfkxckinc_nav.dat
C:\Documents and Settings\Propriétaire\Local Settings\Application Data\lbfkxckinc_navps.dat
C:\Temp\1cb
C:\Temp\bkR11
C:\WINDOWS\cookies.ini
C:\WINDOWS\hosts
C:\WINDOWS\system32\acsqemic.dll
C:\WINDOWS\system32\afyivwng.ini
C:\WINDOWS\system32\agcgftoq.dll
C:\WINDOWS\system32\albtoijx.dll
C:\WINDOWS\system32\asxprqvk.dll
C:\WINDOWS\system32\awvvs.dll
C:\WINDOWS\system32\axnyhbsl.dll
C:\WINDOWS\system32\bbnrvrxd.ini
C:\WINDOWS\system32\beuobvtw.dll
C:\WINDOWS\system32\bleonhmp.dll
C:\WINDOWS\system32\bndujqgx.dll
C:\WINDOWS\system32\bnfjtvhv.dll
C:\WINDOWS\system32\bqctesgf.ini
C:\WINDOWS\system32\bugjefup.dll
C:\WINDOWS\system32\cdqfbaqq.dll
C:\WINDOWS\system32\cofntnya.dll
C:\WINDOWS\system32\cqlodbvd.ini
C:\WINDOWS\system32\cthikvfi.dll
C:\WINDOWS\system32\ctnhnysh.ini
C:\WINDOWS\system32\dfkfkwmm.dll
C:\WINDOWS\system32\dhvdvrfd.ini
C:\WINDOWS\system32\dihyjwyo.ini
C:\WINDOWS\system32\dpkrtdej.dll
C:\WINDOWS\system32\dubcjvfu.ini
C:\WINDOWS\system32\dvwepmhb.dll
C:\WINDOWS\system32\effiadgn.ini
C:\WINDOWS\system32\epsgkakx.ini
C:\WINDOWS\system32\eqjihymx.dll
C:\WINDOWS\system32\f3
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\fdxvwdji.ini
C:\WINDOWS\system32\fptfskqf.dll
C:\WINDOWS\system32\frpileiq.dll
C:\WINDOWS\system32\ftnpbafm.ini
C:\WINDOWS\system32\fyykihmh.dll
C:\WINDOWS\system32\gcwmxutg.ini
C:\WINDOWS\system32\gcyqmxsm.ini
C:\WINDOWS\system32\ghirhark.dll
C:\WINDOWS\system32\gimvxfck.ini
C:\WINDOWS\system32\glfoydml.dll
C:\WINDOWS\system32\glofjomp.dll
C:\WINDOWS\system32\grgqchoc.ini
C:\WINDOWS\system32\gscuresw.dll
C:\WINDOWS\system32\gvjowpjr.dll
C:\WINDOWS\system32\gvpibdkv.ini
C:\WINDOWS\system32\gwqugxem.dll
C:\WINDOWS\system32\gxmipamx.ini
C:\WINDOWS\system32\hbvcfecn.ini
C:\WINDOWS\system32\hfrbxmvk.dll
C:\WINDOWS\system32\hjicpaye.dll
C:\WINDOWS\system32\hjljifhi.dll
C:\WINDOWS\system32\hjsjlnbq.dll
C:\WINDOWS\system32\hygelque.dll
C:\WINDOWS\system32\idbxndst.ini
C:\WINDOWS\system32\iifdcbx.dll
C:\WINDOWS\system32\ijdwvxdf.dll
C:\WINDOWS\system32\ikdvqlxd.ini
C:\WINDOWS\system32\itbajmfc.dll
C:\WINDOWS\system32\itodshhu.dll
C:\WINDOWS\system32\jabfhhmo.dll
C:\WINDOWS\system32\jedtrkpd.ini
C:\WINDOWS\system32\jegefurt.ini
C:\WINDOWS\system32\jpefgfkk.dll
C:\WINDOWS\system32\jqfxtgdh.dll
C:\WINDOWS\system32\jttowtoe.dll
C:\WINDOWS\system32\jwdlwusi.dll
C:\WINDOWS\system32\jyupihdc.dll
C:\WINDOWS\system32\kdrikfuq.ini
C:\WINDOWS\system32\klghniqq.ini
C:\WINDOWS\system32\kniucpxx.dll
C:\WINDOWS\system32\krahrihg.ini
C:\WINDOWS\system32\ktlajgxg.dll
C:\WINDOWS\system32\kyrphcve.dll
C:\WINDOWS\system32\l4
C:\WINDOWS\system32\lascnrgf.dll
C:\WINDOWS\system32\ldkjxlue.ini
C:\WINDOWS\system32\lforlfvn.ini
C:\WINDOWS\system32\lfrbvwbh.dll
C:\WINDOWS\system32\lkaysikc.ini
C:\WINDOWS\system32\lmdyoflg.ini
C:\WINDOWS\system32\lmpwqijn.dll
C:\WINDOWS\system32\lneauuwv.dll
C:\WINDOWS\system32\lnrxskam.ini
C:\WINDOWS\system32\lqqbsleu.dll
C:\WINDOWS\system32\maksxrnl.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mexguqwg.ini
C:\WINDOWS\system32\mfabpntf.dll
C:\WINDOWS\system32\mqhstsle.dll
C:\WINDOWS\system32\mswyilfm.dll
C:\WINDOWS\system32\msxmqycg.dll
C:\WINDOWS\system32\navlwpxn.dll
C:\WINDOWS\system32\nbfukdba.dll
C:\WINDOWS\system32\ngdaiffe.dll
C:\WINDOWS\system32\ngqqpmua.dll
C:\WINDOWS\system32\nhqcrilh.dll
C:\WINDOWS\system32\ntpopgrr.dll
C:\WINDOWS\system32\nvflrofl.dll
C:\WINDOWS\system32\oausqnqr.dll
C:\WINDOWS\system32\ocvmbrnk.ini
C:\WINDOWS\system32\odvgstcb.dll
C:\WINDOWS\system32\oggyktjl.dll
C:\WINDOWS\system32\oimivqsu.dll
C:\WINDOWS\system32\okgfrbka.dll
C:\WINDOWS\system32\ombyhomc.dll
C:\WINDOWS\system32\omcvjtqn.dll
C:\WINDOWS\system32\oywjyhid.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pbelkkqt.dll
C:\WINDOWS\system32\pmhnoelb.ini
C:\WINDOWS\system32\pmrhexsg.ini
C:\WINDOWS\system32\ptchwrap.dll
C:\WINDOWS\system32\punqiaej.ini
C:\WINDOWS\system32\puphohgh.dll
C:\WINDOWS\system32\pynviyft.dll
C:\WINDOWS\system32\qgupdjui.ini
C:\WINDOWS\system32\qieliprf.ini
C:\WINDOWS\system32\qpokmdnd.dll
C:\WINDOWS\system32\qqabfqdc.ini
C:\WINDOWS\system32\qrdlpiey.ini
C:\WINDOWS\system32\qrivgbkd.dll
C:\WINDOWS\system32\qufkirdk.dll
C:\WINDOWS\system32\rcsjfbdx.dll
C:\WINDOWS\system32\rjbvgfor.ini
C:\WINDOWS\system32\rjpwojvg.ini
C:\WINDOWS\system32\rogxjmgt.dll
C:\WINDOWS\system32\rpuahjyw.ini
C:\WINDOWS\system32\rtgpeqry.dll
C:\WINDOWS\system32\rvcuspyk.dll
C:\WINDOWS\system32\sbieejsy.dll
C:\WINDOWS\system32\sbpfhkuj.dll
C:\WINDOWS\system32\spnitlaj.dll
C:\WINDOWS\system32\ssvibrkg.dll
C:\WINDOWS\system32\svvwa.ini
C:\WINDOWS\system32\svvwa.ini2
C:\WINDOWS\system32\tfenusqy.dll
C:\WINDOWS\system32\tjswvllm.dll
C:\WINDOWS\system32\tkudvghb.dll
C:\WINDOWS\system32\toskwlsd.dll
C:\WINDOWS\system32\tscwxmly.ini
C:\WINDOWS\system32\twnnisyx.dll
C:\WINDOWS\system32\txxkynqd.dll
C:\WINDOWS\system32\tyjesuhw.dll
C:\WINDOWS\system32\uapvuvex.dll
C:\WINDOWS\system32\ufvjcbud.dll
C:\WINDOWS\system32\uhhsdoti.ini
C:\WINDOWS\system32\uninstall.exe
C:\WINDOWS\system32\uxjwteoo.dll
C:\WINDOWS\system32\vehgoodh.dll
C:\WINDOWS\system32\vhvtjfnb.ini
C:\WINDOWS\system32\vhxgexcc.dll
C:\WINDOWS\system32\vkewbtwc.ini
C:\WINDOWS\system32\vpqapwtw.dll
C:\WINDOWS\system32\waatnbeb.dll
C:\WINDOWS\system32\wcyotwmi.dll
C:\WINDOWS\system32\wnuvavie.dll
C:\WINDOWS\system32\wserucsg.ini
C:\WINDOWS\system32\wsotgnrh.dll
C:\WINDOWS\system32\wtwpaqpv.ini
C:\WINDOWS\system32\wyjhaupr.dll
C:\WINDOWS\system32\xcoacfyk.dll
C:\WINDOWS\system32\xgnmxjwu.dll
C:\WINDOWS\system32\xiunterg.dll
C:\WINDOWS\system32\xkakgspe.dll
C:\WINDOWS\system32\xoeqfyux.ini
C:\WINDOWS\system32\xuyfqeox.dll
C:\WINDOWS\system32\xvlhnhhx.dll
C:\WINDOWS\system32\xwxaimas.ini
C:\WINDOWS\system32\yeipldrq.dll
C:\WINDOWS\system32\yfymuial.dll
C:\WINDOWS\system32\yirawnnq.dll
C:\WINDOWS\system32\ykrxjbiu.dll
C:\WINDOWS\system32\yrqepgtr.ini
D:\Autorun.inf

—– BITS: Possible sites infect‚s —–

hxxp://www.download.windowsupdate.com
hxxp://patch.everquest.com:7001
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-10 to 2008-02-10 ))))))))))))))))))))))))))))))))))))
.

2008-02-09 08:51 . 2008-02-09 08:51 d——– C:\Program Files\Uniblue
2008-02-06 16:40 . 2008-02-06 16:38 691,545 –a—— C:\WINDOWS\unins000.exe
2008-02-06 16:40 . 2008-02-06 16:40 3,455 –a—— C:\WINDOWS\unins000.dat
2008-02-05 18:56 . 2008-02-05 18:56 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-05 18:56 . 2008-02-05 18:56 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-29 10:01 . 2008-01-29 10:01 d——– C:\Program Files\RegistrySmart
2008-01-29 09:39 . 2008-01-30 18:21 d——– C:\Program Files\Panda Security
2008-01-27 11:58 . 2008-01-27 11:59 d——– C:\Program Files\SOE
2008-01-26 18:56 . 2008-01-26 19:08 d——– C:\Program Files\WinEQ2
2008-01-26 11:03 . 2008-01-26 11:03 d——– C:\Program Files\Lavalys
2008-01-11 11:16 . 2008-02-09 18:07 143 –a—— C:\WINDOWS\BMbb3aa087.xml
2008-01-11 11:15 . 2008-02-10 09:30 22 –a—— C:\WINDOWS\pskt.ini
2008-01-10 17:35 . 2008-01-10 17:35 d——– C:\Program Files\RadioXpi

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 14:17 ——— d—–w C:\Program Files\Wanadoo
2008-02-08 15:55 28,256 —-a-w C:\WINDOWS\system32\drivers\MxlW2k.sys
2008-02-07 11:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 15:43 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-01-30 17:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-30 17:19 ——— d—–w C:\Program Files\3DO
2008-01-25 08:23 ——— d—a-w C:\Program Files\Easy Internet signup
2008-01-06 09:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-23 19:51 ——— d—–w C:\Program Files\UnZixWin
2007-12-23 19:50 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-12-23 19:50 249,856 ——w C:\WINDOWS\Setup1.exe
2007-12-23 19:43 ——— d—–w C:\Program Files\Azureus
2007-12-18 18:09 ——— d—–w C:\Program Files\Fichiers communs\xing shared
2007-12-18 18:09 ——— d—–w C:\Program Files\Fichiers communs\Real
2007-12-18 18:08 ——— d—–w C:\Program Files\Real
2007-12-17 09:00 ——— d—–w C:\Program Files\Google
2003-10-07 16:39 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0394042B-9CA1-41DF-94DE-C3391CAE322C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{394E7D5D-FD9F-4D2A-B97A-4D68A9E1DA3A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83BD6D74-0007-4E00-A62C-1D71D6CAFD56}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8D51DCAC-A102-4334-96F7-C7D41EBF7176}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c017ead4-1fdc-4a99-8fc7-d91d8c48309d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 13:50 122880]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-21 05:08 1511453]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StorageGuard"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-02-13 15:01 155648]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 04:42 221184]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 20:05 344064]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 50176 C:\WINDOWS\ALCXMNTR.EXE]
"Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 10:38 57344]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 163840]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-12 00:11 122880]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 17:20 79224]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-29 13:40 282624]
"JeticoPFStartup"="C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe" [2005-07-19 07:22 118784]
"SystrayORAHSS"="C:\Program Files\OrangeHSS\Systray\SystrayApp.exe" [2006-12-12 18:16 90112]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 13:49 28672]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 15:55 32768]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 23:22 35328]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-10-01 09:45 53248]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-10-22 07:18 77824]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-12-18 19:08 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdcbx]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^D-Link AirPlus DWL-120+ Wireless USB Adapter.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\D-Link AirPlus DWL-120+ Wireless USB Adapter.lnk
backup=C:\WINDOWS\pss\D-Link AirPlus DWL-120+ Wireless USB Adapter.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Image Transfer.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Image Transfer.lnk
backup=C:\WINDOWS\pss\Image Transfer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Propriétaire^Menu Démarrer^Programmes^Démarrage^HotSync Manager.lnk]
path=C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Propriétaire^Menu Démarrer^Programmes^Démarrage^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b809931b]
C:\WINDOWS\System32\maksxrnl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMbb3aa087]
C:\WINDOWS\System32\qpokmdnd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
C:\Program Files\dvd43\dvd43_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]
C:\windows\system32\elitevbs32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Heth]
C:\Documents and Settings\Propriétaire\Application Data\teee.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lbfkxckinc]
c:\documents and settings\propriétaire\local settings\application data\lbfkxckinc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2003-10-01 09:45 53248 c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2002-08-21 05:08 1511453 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2003-03-04 01:44 323584 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
–a—— 2002-08-01 03:28 81920 C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-05-29 13:40 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
–a—— 2004-06-30 18:04 95344 C:\PROGRA~1\SYMNET~1\SNDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRebates0]
C:\Program Files\Web_Rebates\WebRebates0.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"NVSvc"=2 (0x2)

R2 FortiSslvpnDaemon;FortiSslvpnDaemon;C:\WINDOWS\System32\FortiSslvpnDaemon.exe [2006-11-03 16:32]
R3 DFE528TX;D-Link DFE-528TX PCI Adapter;C:\WINDOWS\System32\DRIVERS\DLKRTL.SYS [2002-06-24 05:30]
R3 pppop;PPPoP WAN Adapter;C:\WINDOWS\System32\DRIVERS\pppop.sys [2006-11-03 16:31]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\System32\DRIVERS\usbscan.sys [2002-08-29 00:48]
S3 TIAcxubt;D-Link WLAN USB Boot Device;C:\WINDOWS\System32\Drivers\tiacxubt.sys []
S3 TIACXUSB;D-Link AirPlus DWL-120+ Wireless USB Adapter;C:\WINDOWS\System32\Drivers\tiacxusb.sys []
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 00:32]

.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-02-09 23:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 08:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-10 09:00:01 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-10 10:00:02 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-10 11:00:01 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-10 12:00:01 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-10 13:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-10 14:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 15:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 16:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 17:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-10 00:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 18:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 19:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 20:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 21:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 22:00:02 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 01:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 02:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 03:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 04:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 05:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 06:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-07 07:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\System32\8rLxno5Y.exe
"2008-02-09 02:30:09 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-10 15:17:34
Windows 5.1.2600 Service Pack 1 NTFS

Balayage processus cach‚s …

Balayage cach‚ autostart entries …

Balayage des fichiers cach‚s …

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-10 15:20:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-10 14:20:03
________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\pskt.ini
C:\windows\system32\elitevbs32.exe
C:\Documents and Settings\Propriétaire\Application Data\teee.exe
c:\documents and settings\propriétaire\local settings\application data\lbfkxckinc.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
C:\WINDOWS\System32\8rLxno5Y.exe



Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0394042B-9CA1-41DF-94DE-C3391CAE322C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2ABAAC42-84DF-4C00-89DA-BC7EB2B0E70B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{394E7D5D-FD9F-4D2A-B97A-4D68A9E1DA3A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83BD6D74-0007-4E00-A62C-1D71D6CAFD56}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8D51DCAC-A102-4334-96F7-C7D41EBF7176}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c017ead4-1fdc-4a99-8fc7-d91d8c48309d}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdcbx]
[=HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMbb3aa087]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b809931b]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lbfkxckinc]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.



______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


AVG Anti-Spyware:
________________________________________
Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open. Do not run a scan yet.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).



    Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
  • Open up AVG anti Malware
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
  • Make sure that Set all elements to: shows Quarantine
  • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
  • When the program has finished, it will display the message All actions have been applied.
  • Then click the Save Scan Report button.
  • Click the Save Report as button.
  • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
  • Reboot in normal mode.


_____________________
If you have no other Nortons/Symantecs products installed :
go to here
Download and run the appropiate tool for you norton product as described by year..

There are some left overs from Nortons still running on your machine. Nortons is known for not uninstalling that well. :angry:


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
  • The report from AVG anti spyware
  • How are things running now?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI