Logfile of HijackThis v1.99.0
Scan saved at 12:11:06, on 22/12/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSExplorer.EXE
C:PROGRA~1Wanadootaskbaricon.exe
C:PROGRA~1mcafee.comvsomcvsshld.exe
c:program filesmcafee.comagentmcagent.exe
c:progra~1mcafee.comvsomcvsescn.exe
C:WINDOWSsystem32atiptaxx.exe
C:WINDOWSsystem32sstray.exe
C:PROGRA~1McAfee.comPERSON~1MpfTray.exe
C:Program FilesAheadInCDInCD.exe
C:WINDOWSsystem32internat.exe
C:Program FilesCASIOPhoto LoaderPlauto.exe
C:Program FilesMemoKitmemokit2.exe
C:PROGRA~1McAfee.comPERSON~1MpfAgent.exe
C:PROGRA~1WanadooEspaceWanadoo.exe
C:PROGRA~1WanadooComComp.exe
C:PROGRA~1WanadooWatch.exe
C:Program FilesInternet Exploreriexplore.exe
C:PROGRA~1IZArcIZArc.exe
C:DOCUME~1mikeLOCALS~1TempARCCHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = <a href="
http://www.wanadoo.fr/go/page_recherche/" target="_blank">
http://www.wanadoo.fr/go/page_recherche/</a>
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href="
http://www.wanadoo.fr" target="_blank">http://www.wanadoo.fr</a>
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Wanadoo
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:PROGRA~1WanadooSEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:PROGRAM FILESADOBEACROBAT 5.0READERACTIVEXACROIEHELPER.OCX
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:progra~1mcafee.comvsomcvsshl.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSsystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 - HKLM..Run: [WOOWATCH] C:PROGRA~1WanadooWatch.exe
O4 - HKLM..Run: [WOOTASKBARICON] C:PROGRA~1Wanadootaskbaricon.exe
O4 - HKLM..Run: [VSOCheckTask] "c:PROGRA~1mcafee.comvsomcmnhdlr.exe" /checktask
O4 - HKLM..Run: [VirusScan Online] "c:PROGRA~1mcafee.comvsomcvsshld.exe"
O4 - HKLM..Run: [MCAgentExe] c:PROGRA~1mcafee.comagentmcagent.exe
O4 - HKLM..Run: [MCUpdateExe] C:PROGRA~1mcafee.comagentmcupdate.exe
O4 - HKLM..Run: [AtiPTA] atiptaxx.exe
O4 - HKLM..Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSsystem32spooldriversw32x863hpztsb04.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [MPFExe] C:PROGRA~1McAfee.comPERSON~1MpfTray.exe
O4 - HKLM..Run: [InCD] C:Program FilesAheadInCDInCD.exe
O4 - HKCU..Run: [internat.exe] internat.exe
O4 - HKCU..Run: [NBJ] "C:Program FilesAheadNero BackItUpNBJ.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesFichiers communsAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: MemoKit.lnk = C:Program FilesMemoKitmk.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O4 - Global Startup: Supervision de Photo Loader.lnk = C:Program FilesCASIOPhoto LoaderPlauto.exe
<B>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - <a href="
http://www.wanadoo.fr" target="_blank">http://www.wanadoo.fr</a> (file missing) (HKCU)</B>
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - <a href="
http://download.mcafee.com/molbin/shared/mcinsctl/fr/4" target="_blank">
http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - <a href="
http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab" target="_blank">
http://a840.g.akamai.net/7/840/537/2004 ... n53.cab</a>
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - <a href="
http://messenger.msn.com/download/MsnMe ... loader.cab" target="_blank">
http://messenger.msn.com/download/MsnMe ... der.cab</a>
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - <a href="
http://download.mcafee.com/molbin/shared/mcgdmgr/fr/1" target="_blank">
http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - <a href="
http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?323" target="_blank">
http://h30043.www3.hp.com/hpdj/en/check ... cab?323</a>
O17 - HKLMSystemCCSServicesTcpip..{BA6BA776-445A-40AE-9647-B8A932D25139}: NameServer = 80.10.246.1 80.10.246.132
O23 - Service: Adobe LM Service - Unknown - C:Program FilesFichiers communsAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: Gestion d'applications - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Ati HotKey Poller - Unknown - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: Client DHCP - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:WINDOWSSystem32dmadmin.exe
O23 - Service: Gestionnaire de disque logique - Unknown - C:WINDOWSSystem32services.exe
O23 - Service: Client DNS - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Journal des événements - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Service de télécopie - Unknown - C:WINDOWSsystem32faxsvc.exe
O23 - Service: InCD Helper - Ahead Software AG - C:Program FilesAheadInCDInCDsrv.exe
O23 - Service: Service d'application d'assistance TCP/IP NetBIOS - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: McAfee.com McShield - Unknown - c:PROGRA~1mcafee.comvsomcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:PROGRA~1McAfee.comAgentmcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:PROGRA~1mcafee.comvsomcvsrte.exe
O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:WINDOWSsystem32mnmsrvc.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:PROGRA~1McAfee.comPERSON~1MPFSERVICE.exe
O23 - Service: DDE réseau - Unknown - C:WINDOWSsystem32netdde.exe
O23 - Service: DSDM DDE réseau - Unknown - C:WINDOWSsystem32netdde.exe
O23 - Service: NMSAccess - Unknown - C:Program FilesCDBurnerXP Pro 3ToolsNMSAccess.exe
O23 - Service: Plug-and-Play - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Agent de stratégie IPSEC - Unknown - C:WINDOWSsystem32lsass.exe
O23 - Service: Emplacement protégé - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Gestionnaire de comptes de sécurité - Unknown - C:WINDOWSsystem32lsass.exe
O23 - Service: Prise en charge des cartes à puces - Unknown - C:WINDOWSSystem32SCardSvr.exe
O23 - Service: Carte à puce - Unknown - C:WINDOWSSystem32SCardSvr.exe
O23 - Service: Planificateur de tà¢ches - Unknown - C:WINDOWSsystem32MSTask.exe
O23 - Service: Service d'exécution par délégation - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Still Image Service - Unknown - C:WINDOWSsystem32stisvc.exe
O23 - Service: Journaux et alertes de performance - Unknown - C:WINDOWSsystem32smlogsvc.exe
O23 - Service: Telnet - Unknown - C:WINDOWSsystem32tlntsvr.exe
O23 - Service: Client de suivi de lien distribué - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Gestionnaire d'utilitaires - Unknown - C:WINDOWSSystem32UtilMan.exe
O23 - Service: Horloge Windows - Unknown - C:WINDOWSSystem32services.exe
O23 - Service: Infrastructure de gestion Windows - Unknown - C:WINDOWSSystem32WBEMWinMgmt.exe
O23 - Service: Extensions du pilote WMI - Unknown - C:WINDOWSsystem32Services.exe
Merci pour cette manip, j'ai remarqué une nouveauté , c'est que ces tà¢ches planifiées changent souvent ; maintenant l'auteur à changer, le titre aussi, avec des caractéres chinois.
J'espère que ce fichier vous permettra de m'aider. A++