Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:34:41, on 08/09/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
F:\Windows\system32\Dwm.exe
F:\Windows\system32\taskeng.exe
F:\Windows\Explorer.EXE
F:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
F:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
F:\Windows\System32\nvraidservice.exe
F:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
F:\Program Files\Windows Sidebar\sidebar.exe
F:\Program Files\Windows Live\Messenger\msnmsgr.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Windows\SYSTEM32\CTXFISPI.EXE
F:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
F:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
F:\Windows\system32\wbem\unsecapp.exe
F:\Program Files\Windows Live\Contacts\wlcomm.exe
F:\Program Files\Windows Mail\WinMail.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://fr.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - F:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - F:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O4 - HKLM\..\Run: [AudioDrvEmulator] "F:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "F:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CanonMyPrinter] F:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [NVRaidService] F:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [VolPanel] "F:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Sidebar] F:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE RÉSEAU')
O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office\OSA9.EXE
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\nvlsp.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://ushousecall02.trendmicro.com/...vex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -
http://www.nvidia.com/content/Driver...aSmartScan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://ccfiles.creative.com/Web/soft...5108/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF7A7F90-6F1A-4BE8-A8BF-5226DDD0B591}: NameServer = 192.168.1.1
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - F:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - F:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - F:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - F:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - F:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - F:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - F:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - F:\Windows\system32\PnkBstrA.exe
O23 - Service: Steam Client Service - Valve Corporation - F:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - F:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
--
End of file - 7319 bytes