Main.txt
Deckard's System Scanner v20071014.68
Run by Compaq_Propriétaire on 2008-03-02 12:20:58
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
13: 2008-03-02 11:21:02 UTC - RP13 - Deckard's System Scanner Restore Point
12: 2008-03-02 11:17:21 UTC - RP12 - Installé Ad-Aware 2007
11: 2008-03-02 11:14:58 UTC - RP11 - Installé Ad-Aware 2007
10: 2008-03-02 11:08:32 UTC - RP10 - Installé Ad-Aware 2007
9: 2008-03-02 02:55:40 UTC - RP9 - Installé Adobe Reader 8.1.2 - Français
-- First Restore Point --
1: 2008-03-02 01:32:26 UTC - RP1 - Installé Java(TM) 6 Update 3
Backed up registry hives.
Performed disk cleanup.
[color=red]Total Physical Memory: 447 MiB (512 MiB recommended).[/color]
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-03-02 12:22:00
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system\hpsysdrv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\hp\KBD\kbd.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Compaq_Propriétaire\Bureau\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\msitss.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 6318 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 BDSelfPr - c:\program files\bitdefender\bitdefender 2008\bdselfpr.sys <Not Verified; BitDefender S.R.L.; BitDefender>
S1 intelppm (Pilote de processeur Intel) - c:\windows\system32\drivers\intelppm.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-03-02 02:30:13 486 --a------ C:\WINDOWS\Tasks\Connexion facile à Internet.job
2008-03-02 01:43:40 334 --a------ C:\WINDOWS\Tasks\HPCeeSchedule.job
-- Files created between 2008-02-02 and 2008-03-02 -----------------------------
2008-03-02 12:11:33 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys <Not Verified; Lavasoft AB; Ad-Watch Connections>
2008-03-02 12:11:33 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys <Not Verified; Lavasoft AB; Ad-Watch Registry Protection>
2008-03-02 12:11:33 6272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys <Not Verified; Lavasoft AB; Ad-Watch Beta>
2008-03-02 11:55:53 0 dr-h----- C:\Documents and Settings\Compaq_Propriétaire\Recent
2008-03-02 03:56:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-03-02 03:55:53 0 d-------- C:\Program Files\Fichiers communs\Adobe
2008-03-02 03:00:01 1158 --a------ C:\WINDOWS\mozver.dat
2008-03-02 02:59:25 0 d-------- C:\WINDOWS\system32\fr-fr
2008-03-02 02:38:03 0 dr-hs---- C:\cmdcons
2008-03-02 02:37:45 0 d-------- C:\WINDOWS\setupupd
2008-03-02 02:34:27 0 d-------- C:\WINDOWS\system32\PreInstall
2008-03-02 02:29:22 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Identities
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\WINDOWS
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Voisinage réseau
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Voisinage d'impression
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\SendTo
2008-03-02 02:29:21 2359296 --a------ C:\Documents and Settings\Compaq_Propriétaire\NTUSER.DAT
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Modèles
2008-03-02 02:29:21 0 dr------- C:\Documents and Settings\Compaq_Propriétaire\Mes documents
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Menu Démarrer
2008-03-02 02:29:21 0 d--h----- C:\Documents and Settings\Compaq_Propriétaire\Local Settings
2008-03-02 02:29:21 0 dr------- C:\Documents and Settings\Compaq_Propriétaire\Favoris
2008-03-02 02:29:21 0 d--hs---- C:\Documents and Settings\Compaq_Propriétaire\Cookies
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Bureau
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Application Data
2008-03-02 02:29:21 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Real
2008-03-02 02:26:58 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-03-02 01:22:39 0 d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2008-03-02 01:18:34 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Bitdefender
2008-03-02 01:18:02 0 d-------- C:\Program Files\BitDefender
2008-03-02 01:18:02 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-03-02 01:17:04 0 d-------- C:\Program Files\Fichiers communs\BitDefender
2008-03-01 23:57:25 0 d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-03-01 23:15:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-01 22:35:53 691545 --a------ C:\WINDOWS\unins000.exe
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\SendTo
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Recent
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Modèles
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-03-01 21:50:06 0 d--h----- C:\Documents and Settings\Administrateur\Local Settings
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Favoris
2008-03-01 21:50:06 0 d---s---- C:\Documents and Settings\Administrateur\Cookies
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Bureau
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Application Data
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Real
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-03-01 21:50:06 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Identities
2008-03-01 21:50:05 1835008 --ah----- C:\Documents and Settings\Administrateur\NTUSER.DAT
2008-03-01 21:01:40 0 d-------- C:\Program Files\MSXML 4.0
2008-03-01 20:42:04 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-01 20:42:03 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Mozilla
2008-03-01 20:41:55 0 d-------- C:\Program Files\Mozilla Firefox(2)
2008-03-01 18:38:30 0 d-------- C:\WINDOWS\network diagnostic
2008-03-01 18:37:09 4690 --a------ C:\WINDOWS\unins000.dat
2008-03-01 17:32:21 0 d-------- C:\Program Files\Lavasoft
2008-03-01 17:32:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-01 16:51:02 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Grisoft
2008-03-01 16:47:01 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-01 16:42:38 0 d-------- C:\Program Files\CCleaner
-- Find3M Report ---------------------------------------------------------------
2008-03-02 10:20:51 0 d-------- C:\Program Files\Windows NT
2008-03-02 03:55:53 0 d-------- C:\Program Files\Fichiers communs
2008-03-02 03:04:17 446984 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-03-02 03:04:17 64724 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-03-02 03:00:10 0 d-------- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Adobe
2008-03-02 02:33:46 0 d-------- C:\Program Files\Java
2007-12-19 17:06:19 44282 --a------ C:\Documents and Settings\Compaq_Propriétaire\Application Data\wklnhst.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 01:11]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [07/05/1998 17:04]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [14/08/2005 04:05]
"AlcxMonitor"="ALCXMNTR.EXE" [07/09/2004 21:47 C:\WINDOWS\ALCXMNTR.EXE]
"KBD"="C:\HP\KBD\KBD.EXE" [03/02/2005 00:44]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [22/07/2005 22:14]
"PCDrProfiler"="" []
"PS2"="C:\WINDOWS\system32\ps2.exe" [25/10/2004 23:17]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [17/02/2005 06:11]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [09/10/2007 15:46]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [02/03/2008 01:21]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 10:25]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 22:16]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [05/08/2004 19:00]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx scan
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
8002 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-03-02 12:22:58 ------------