Ok here is some logs I made, but there is nothing to see:
Logfile of HijackThis v1.99.1
Scan saved at 18:48:04, on 13/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Documents and Settings\Admin\Menu Démarrer\Programmes\Utilitaires\Sécurité\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Applications\Spybot\SDHelper.dll
O4 - Startup: Foobar.lnk.disabled
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133439302781
O17 - HKLM\System\CCS\Services\Tcpip\..\{16172282-7A3C-4C05-B23B-0A1A866DB884}: NameServer = 194.49.160.1,193.55.10.101
CompatAlyser shows 9 known functions, no one suspicious.
RessHacker shows two tress, Registry & TypeLib with only one ressource in each collapsed tree. Here's registry related:
HKCR
{
CmdLineExt.CmdLineContextMenu.1 = s 'CmdLineContextMenu Class'
{
CLSID = s '{9869EFB4-18E9-11D3-A837-00104B9E30B5}'
}
CmdLineExt.CmdLineContextMenu = s 'CmdLineContextMenu Class'
{
CLSID = s '{9869EFB4-18E9-11D3-A837-00104B9E30B5}'
CurVer = s 'CmdLineExt.CmdLineContextMenu.1'
}
NoRemove CLSID
{
ForceRemove {9869EFB4-18E9-11D3-A837-00104B9E30B5} = s 'CmdLineContextMenu Class'
{
ProgID = s 'CmdLineExt.CmdLineContextMenu.1'
VersionIndependentProgID = s 'CmdLineExt.CmdLineContextMenu'
InprocServer32 = s '%MODULE%'
{
val ThreadingModel = s 'Apartment'
}
'TypeLib' = s '{9869EFA6-18E9-11D3-A837-00104B9E30B5}'
}
}
}
Looks like really usual to me.
Spybot S&D scan shows no spyware found (for years on this machine).
ClamWin scan shows no virus found. Both have been updated to the last software & signatures version.
Now here's:
Removed, please do not link to infected files.
It has no compagny name nor description.
If you need more informations, just ask ...
Thanks a lot. Regards,
Kr.