2006-08-14 17:24 208,896 --a------ C:\WINDOWS\system32\progman.exe
2006-08-14 17:24 203,776 --a------ C:\WINDOWS\system32\uxtheme.dll
2006-08-14 17:24 200,192 --a------ C:\WINDOWS\system32\termsrv.dll
2006-08-14 17:24 20,992 --a------ C:\WINDOWS\system32\stimon.exe
2006-08-14 17:24 20,992 --a------ C:\WINDOWS\system32\setup.exe
2006-08-14 17:24 20,992 --a------ C:\WINDOWS\system32\seclogon.dll
2006-08-14 17:24 20,480 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-08-14 17:24 2,019,328 --a------ C:\WINDOWS\system32\wmploc.dll
2006-08-14 17:24 198,656 --a------ C:\WINDOWS\system32\t2embed.dll
2006-08-14 17:24 193,536 --a------ C:\WINDOWS\system32\rasppp.dll
2006-08-14 17:24 19,968 --a------ C:\WINDOWS\system32\sclgntfy.dll
2006-08-14 17:24 19,968 --a------ C:\WINDOWS\system32\savedump.exe
2006-08-14 17:24 19,456 --a------ C:\WINDOWS\system32\ssmarque.scr
2006-08-14 17:24 19,456 --a------ C:\WINDOWS\system32\qprocess.exe
2006-08-14 17:24 188,928 --a------ C:\WINDOWS\system32\syncui.dll
2006-08-14 17:24 184,320 --a------ C:\WINDOWS\system32\wzcsvc.dll
2006-08-14 17:24 184,320 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-08-14 17:24 180,800 --a------ C:\WINDOWS\system32\sqlunirl.dll
2006-08-14 17:24 180,224 --a------ C:\WINDOWS\system32\scecli.dll
2006-08-14 17:24 18,944 --a------ C:\WINDOWS\system32\wzcsapi.dll
2006-08-14 17:24 18,944 --a------ C:\WINDOWS\system32\ws2help.dll
2006-08-14 17:24 18,944 --a------ C:\WINDOWS\system32\ssbezier.scr
2006-08-14 17:24 18,944 --a------ C:\WINDOWS\system32\shutdown.exe
2006-08-14 17:24 18,432 --a------ C:\WINDOWS\system32\rsmps.dll
2006-08-14 17:24 175,104 --a------ C:\WINDOWS\system32\winmm.dll
2006-08-14 17:24 174,080 --a------ C:\WINDOWS\system32\snmpsnap.dll
2006-08-14 17:24 173,056 --a------ C:\WINDOWS\system32\qasf.dll
2006-08-14 17:24 171,520 --a------ C:\WINDOWS\system32\sccsccp.dll
2006-08-14 17:24 17,408 --a------ C:\WINDOWS\system32\wshtcpip.dll
2006-08-14 17:24 17,408 --a------ C:\WINDOWS\system32\ssmyst.scr
2006-08-14 17:24 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-08-14 17:24 17,408 --a------ C:\WINDOWS\system32\psapi.dll
2006-08-14 17:24 169,984 --a------ C:\WINDOWS\system32\sccbase.dll
2006-08-14 17:24 169,328 --a------ C:\WINDOWS\system32\xenroll.dll
2006-08-14 17:24 168,448 --a------ C:\WINDOWS\system32\wldap32.dll
2006-08-14 17:24 166,912 --a------ C:\WINDOWS\system32\wintrust.dll
2006-08-14 17:24 166,912 --a------ C:\WINDOWS\system32\photowiz.dll
2006-08-14 17:24 163,328 --a------ C:\WINDOWS\system32\upnphost.dll
2006-08-14 17:24 163,328 --a------ C:\WINDOWS\system32\tapi32.dll
2006-08-14 17:24 162,304 --a------ C:\WINDOWS\system32\w32time.dll
2006-08-14 17:24 160,768 --a------ C:\WINDOWS\system32\schedsvc.dll
2006-08-14 17:24 16,896 --a------ C:\WINDOWS\system32\wtsapi32.dll
2006-08-14 17:24 16,896 --a------ C:\WINDOWS\system32\snmpapi.dll
2006-08-14 17:24 16,384 --a------ C:\WINDOWS\system32\version.dll
2006-08-14 17:24 16,384 --a------ C:\WINDOWS\system32\ups.exe
2006-08-14 17:24 16,384 --a------ C:\WINDOWS\system32\ping.exe
2006-08-14 17:24 155,675 --a------ C:\WINDOWS\system32\scrobj.dll
2006-08-14 17:24 155,648 --a------ C:\WINDOWS\system32\srsvc.dll
2006-08-14 17:24 153,600 --a------ C:\WINDOWS\system32\wuv3is.dll
2006-08-14 17:24 147,483 --a------ C:\WINDOWS\system32\scrrun.dll
2006-08-14 17:24 14,848 --a------ C:\WINDOWS\system32\winrnr.dll
2006-08-14 17:24 14,848 --a------ C:\WINDOWS\system32\usbmon.dll
2006-08-14 17:24 14,848 --a------ C:\WINDOWS\system32\upnpcont.exe
2006-08-14 17:24 14,848 --a------ C:\WINDOWS\system32\rdpsnd.dll
2006-08-14 17:24 14,848 --a------ C:\WINDOWS\system32\powrprof.dll
2006-08-14 17:24 14,592 --a------ C:\WINDOWS\system32\watchdog.sys
2006-08-14 17:24 14,366 --a------ C:\WINDOWS\system32\asfsipc.dll
2006-08-14 17:24 14,336 --a------ C:\WINDOWS\system32\rsh.exe
2006-08-14 17:24 14,336 --a------ C:\WINDOWS\system32\perfmon.exe
2006-08-14 17:24 137,216 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-08-14 17:24 136,704 --a------ C:\WINDOWS\system32\schannel.dll
2006-08-14 17:24 136,192 --a------ C:\WINDOWS\system32\taskmgr.exe
2006-08-14 17:24 134,656 --a------ C:\WINDOWS\system32\sfc_os.dll
2006-08-14 17:24 134,656 --a------ C:\WINDOWS\system32\rdchost.dll
2006-08-14 17:24 133,632 --a------ C:\WINDOWS\system32\sti_ci.dll
2006-08-14 17:24 131,584 --a------ C:\WINDOWS\system32\sessmgr.exe
2006-08-14 17:24 131,584 --a------ C:\WINDOWS\system32\rsaenh.dll
2006-08-14 17:24 13,824 --a------ C:\WINDOWS\system32\wship6.dll
2006-08-14 17:24 13,824 --a------ C:\WINDOWS\system32\uniplat.dll
2006-08-14 17:24 13,824 --a------ C:\WINDOWS\system32\rassapi.dll
2006-08-14 17:24 13,312 --a------ C:\WINDOWS\system32\wupdinfo.dll
2006-08-14 17:24 13,312 --a------ C:\WINDOWS\system32\tcpmib.dll
2006-08-14 17:24 13,312 --a------ C:\WINDOWS\system32\ssstars.scr
2006-08-14 17:24 127,488 --a------ C:\WINDOWS\system32\shmedia.dll
2006-08-14 17:24 126,976 --a------ C:\WINDOWS\system32\imagehlp.dll
2006-08-14 17:24 125,952 --a------ C:\WINDOWS\system32\sndrec32.exe
2006-08-14 17:24 125,440 --a------ C:\WINDOWS\system32\webvw.dll
2006-08-14 17:24 120,832 --a------ C:\WINDOWS\system32\wkssvc.dll
2006-08-14 17:24 12,800 --a------ C:\WINDOWS\system32\svchost.exe
2006-08-14 17:24 12,800 --a------ C:\WINDOWS\system32\rexec.exe
2006-08-14 17:24 12,800 --a------ C:\WINDOWS\system32\pjlmon.dll
2006-08-14 17:24 12,800 --a------ C:\WINDOWS\system32\mgmtapi.dll
2006-08-14 17:24 12,288 --a------ C:\WINDOWS\system32\sigtab.dll
2006-08-14 17:24 12,288 --a------ C:\WINDOWS\system32\runonce.exe
2006-08-14 17:24 12,288 --a------ C:\WINDOWS\system32\rdsaddin.exe
2006-08-14 17:24 12,288 --a------ C:\WINDOWS\system32\lmhsvc.dll
2006-08-14 17:24 119,808 --a------ C:\WINDOWS\system32\upnp.dll
2006-08-14 17:24 118,834 --a------ C:\WINDOWS\system32\wscript.exe
2006-08-14 17:24 118,784 --a------ C:\WINDOWS\system32\wmsdmoe.dll
2006-08-14 17:24 118,784 --a------ C:\WINDOWS\system32\wiadss.dll
2006-08-14 17:24 118,272 --a------ C:\WINDOWS\system32\stobject.dll
2006-08-14 17:24 115,200 --a------ C:\WINDOWS\system32\shsvcs.dll
2006-08-14 17:24 111,104 --a------ C:\WINDOWS\system32\url.dll
2006-08-14 17:24 110,592 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-08-14 17:24 108,032 --a------ C:\WINDOWS\system32\msv1_0.dll
2006-08-14 17:24 107,008 --a------ C:\WINDOWS\system32\umpnpmgr.dll
2006-08-14 17:24 104,960 --a------ C:\WINDOWS\system32\sysocmgr.exe
2006-08-14 17:24 104,448 --a------ C:\WINDOWS\system32\wiavideo.dll
2006-08-14 17:24 101,888 --a------ C:\WINDOWS\system32\services.exe
2006-08-14 17:24 100,720 --a------ C:\WINDOWS\system32\iuctl.dll
2006-08-14 17:24 10,752 --a------ C:\WINDOWS\system32\tracert.exe
2006-08-14 17:24 10,240 --a------ C:\WINDOWS\system32\WshRm.dll
2006-08-14 17:24 10,240 --a------ C:\WINDOWS\system32\regsvr32.exe
2006-08-14 17:24 1,962,496 --a------ C:\WINDOWS\system32\quartz.dll
2006-08-14 17:24 1,901,440 --a------ C:\WINDOWS\system32\ntkrnlpa.exe
2006-08-14 17:24 1,879,168 --a------ C:\WINDOWS\system32\ntoskrnl.exe
2006-08-14 17:24 1,799,808 --a------ C:\WINDOWS\system32\win32k.sys
2006-08-14 17:24 1,798,144 --a------ C:\WINDOWS\system32\qedit.dll
2006-08-14 17:24 1,547,264 --a------ C:\WINDOWS\system32\sfcfiles.dll
2006-08-14 17:24 1,392,640 --a------ C:\WINDOWS\system32\wmpui.dll
2006-08-14 17:24 1,342,976 --a------ C:\WINDOWS\system32\query.dll
2006-08-14 17:24 1,302,528 --a------ C:\WINDOWS\system32\wmpcore.dll
2006-08-14 17:24 1,216,512 --a------ C:\WINDOWS\system32\wmvcore.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-08 08:23 777472 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-08-08 08:23 27904 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-07-31 18:28 -------- d-------- C:\Documents and Settings\Jean-Francois\Application Data\AVG7
2006-07-31 18:27 4992 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-07-31 18:27 4288 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-07-31 18:27 23424 --a------ C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-07-31 07:56 -------- d-------- C:\Program Files\Trisnap Technologies
2006-07-30 16:02 61440 --a------ C:\WINDOWS\system32\mwm52b8c.dll
2006-07-30 16:02 2 --a------ C:\WINDOWS\system32\wnsapisu.exe
2006-07-30 16:02 1064 --a------ C:\WINDOWS\system32\mwm52b8c.sys
2006-07-30 16:01 32768 --a------ C:\WINDOWS\unstall.exe
2006-07-30 16:01 232749 --a------ C:\WINDOWS\pf78.exe
2006-06-07 13:55 3626 --a------ C:\Program Files\Fichiers communs\mejeh.html
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE NvQTwk,NvCplDaemon initialize"
"nwiz"="nwiz.exe /installquiet"
"SxgTkBar"="SxgTkBar.exe"
"00THotkey"="C:\\WINDOWS\\System32\\00THotkey.exe"
"000StTHK"="000StTHK.exe"
"Apoint"="C:\\Program Files\\Apoint2K\\Apoint.exe"
"TouchED"="C:\\Program Files\\TOSHIBA\\TouchED\\TouchED.Exe"
"Tpwrtray"="TPWRTRAY.EXE"
"TFncKy"="TFncKy.exe /Type 20"
"NDSTray.exe"="NDSTray.exe"
"ezShieldProtector for Px"="C:\\WINDOWS\\System32\\ezSP_Px.exe"
"Drag'n Drop CD"="C:\\Program Files\\Drag'n Drop CD\\BinFiles\\DragDrop.exe /StartUp"
"LtMoh"="C:\\Program Files\\ltmoh\\Ltmoh.exe"
"TFNF5"="TFNF5.exe"
"TosHKCW.exe"="C:\\Program Files\\TOSHIBA\\Wireless Hotkey\\TosHKCW.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Zone Labs Client"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe\" -osboot"
"FRISK FP-Scheduler"="C:\\Program Files\\FSI\\F-Prot\\F-Sched.exe STARTUP"
"F-StopW"="C:\\Program Files\\FSI\\F-Prot\\F-StopW.EXE"
"xxcukntA"="C:\\WINDOWS\\xxcukntA.exe"
"mwm52b8c"="RUNDLL32.EXE w79b77c1.dll,n 00252b8a0000000a79b77c1"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Microsoft Windows System"="syshost.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Yahoo! Pager"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.4156\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"Microsoft Windows System"="syshost.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\Program Files\\MSN Gaming Zone\\polokikoj.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="C:\\Program Files\\Fichiers communs\\mejeh.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,c0,02,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 2006-09-01 7:20:04.42
ComboFix.txt