Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:00:03, on 10/03/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\4pp\AppServ\Apache2.2\bin\httpd.exe
D:\4pp\AppServ\Apache2.2\bin\httpd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\ctfmon.exe
D:\intel\ia32\bin\smpd.exe
D:\MAP\Malwarebytes' Anti-Malware\mbamservice.exe
D:\4pp\AppServ\MySQL\bin\mysqld-nt.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\Program Files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe
D:\Program Files\Reg\ScsiAccess.exe
C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
D:\IAM-T\Internet Mobile\Internet Mobile.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\GoogleChromePortable.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtblfs.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Documents and Settings\Administrateur\Bureau\GoogleChromePortable\GoogleChromePortableDev\App\Chrome-bin\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O2 - BHO: LeapFTP Internet Explorer Hook - {A5479DA1-7843-43A7-B5C0-BE342C77B629} - D:\FTP\LEAPFT~1.0\lftpie.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {1F958B09-6612-7a0e-9223-4C7324C57B23} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Internet Cleaner - {45819E58-6E84-4A5D-BD65-A706981E5BE8} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O9 - Extra 'Tools' menuitem: Internet Cleaner - {45819E58-6E84-4A5D-BD65-A706981E5BE8} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{3B397832-D24E-4ECB-A000-46436FAEA0B6}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{93208876-3EF1-45D3-A3CA-837FA40FFF0A}: NameServer = 67.138.54.100,207.225.209.66
O17 - HKLM\System\CCS\Services\Tcpip\..\{CCF75AAD-F324-4AF2-9D83-36058CE33F46}: NameServer = 212.217.0.1 212.217.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{231F1D70-169A-4E32-BA2E-79E9C351FF3E}: NameServer = 87.118.111.215,81.174.67.134
O17 - HKLM\System\CS1\Services\Tcpip\..\{CCF75AAD-F324-4AF2-9D83-36058CE33F46}: NameServer = 87.118.111.215,81.174.67.134
O23 - Service: Apache2.2 - Apache Software Foundation - D:\4pp\AppServ\Apache2.2\bin\httpd.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Intel(R) MPI Library Process Manager, Intel (impi_smpd) - Intel Corporation - D:\intel\ia32\bin\smpd.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MBAMService - Malwarebytes Corporation - D:\MAP\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: mysql - Unknown owner - D:\4pp\AppServ\MySQL\bin\mysqld-nt.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Fichiers communs\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: ScsiAccess - Unknown owner - D:\Program Files\Reg\ScsiAccess.exe
O23 - Service: Sentinel RMS License Manager - SafeNet, Inc. - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Fichiers communs\Adobe\SwitchBoard\SwitchBoard.exe
--
End of file - 8385 bytes