...logs continued...
Here is the combofix log:
Jean-Pierre Hall‚ - 06-11-11 13:59:41,31 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Jean-Pierre Hall‚\Bureau"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\components
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Program Files\ICROSO~1.NET
C:\QooBox\Purity\Program Files\ICROSO~1.NET\d?xplore.exe
((((((((((((((((((((((((((((((( Files Created from 2006-10-11 to 2006-11-11 ))))))))))))))))))))))))))))))))))
2006-11-11 13:41 106,496 --a------ C:\WINDOWS\SYSTEM32\impgsje.dll
2006-11-11 11:56 101,888 --a------ C:\WINDOWS\SYSTEM32\drvmoc.dll
2006-11-11 11:54 40,973 ---hs---- C:\WINDOWS\SYSTEM32\xxyvwww.dll
2006-11-11 11:45 674,187 ---hs---- C:\WINDOWS\SYSTEM32\npqss.bak2
2006-11-05 19:44 602,245 ---hs---- C:\WINDOWS\SYSTEM32\npqss.bak1
2006-11-05 19:43 692,276 ---hs---- C:\WINDOWS\SYSTEM32\ssqpn.dll
2006-11-05 19:42 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2006-11-05 19:36 40,973 ---hs---- C:\WINDOWS\SYSTEM32\mljgheb.dll
2006-11-05 16:24 2 --a------ C:\WINDOWS\SYSTEM32\wapiit.exe
2006-11-05 16:22 40,973 ---hs---- C:\WINDOWS\SYSTEM32\ljjjghg.dll
2006-11-05 16:22 15,872 --------- C:\WINDOWS\SYSTEM32\wintfj32.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-11 13:53 -------- d-------- C:\Program Files\SAM
2006-11-11 13:53 -------- d-------- C:\Documents and Settings\Jean-Pierre Hall‚\Application Data\Skype
2006-11-11 13:05 -------- d-------- C:\Program Files\Fichiers communs
2006-11-06 05:43 -------- d-------- C:\Program Files\Hijackthis
2006-11-05 19:44 -------- d-------- C:\Program Files\VSAdd-in
2006-11-05 19:42 -------- d-------- C:\Program Files\Grisoft
2006-11-05 18:09 -------- d-------- C:\Program Files\NavNT
2006-10-24 11:08 -------- d-------- C:\Program Files\Morpheus
2006-10-14 13:00 -------- d-------- C:\Program Files\Fichiers communs\SWF Studio
2006-10-11 11:24 58880 --a------ C:\WINDOWS\SYSTEM32\pnrpnsp.dll
2006-10-11 11:24 553984 --a------ C:\WINDOWS\SYSTEM32\p2psvc.dll
2006-10-11 11:24 313344 --a------ C:\WINDOWS\SYSTEM32\p2pgraph.dll
2006-10-11 11:24 153088 --a------ C:\WINDOWS\SYSTEM32\p2p.dll
2006-10-11 11:24 116224 --a------ C:\WINDOWS\SYSTEM32\p2pnetsh.dll
2006-10-11 11:24 104960 --a------ C:\WINDOWS\SYSTEM32\p2pgasvc.dll
2006-09-29 20:35 67896 --a------ C:\Documents and Settings\Jean-Pierre Hall‚\Application Data\GDIPFONTCACHEV1.DAT
2006-09-29 20:06 -------- d-------- C:\Program Files\Fichiers communs\HP
2006-09-29 20:04 -------- d-------- C:\Program Files\HP
2006-09-29 20:04 -------- d-------- C:\Program Files\Hewlett-Packard
2006-09-29 20:03 -------- d-------- C:\Program Files\Fichiers communs\Hewlett-Packard
2006-09-29 19:07 -------- d--h----- C:\Documents and Settings\Jean-Pierre Hall‚\Application Data\GTek
2006-09-23 10:54 -------- d-------- C:\Program Files\Adobe
2006-09-13 00:03 1084416 --a------ C:\WINDOWS\SYSTEM32\msxml3.dll
2006-08-25 10:51 617472 --a------ C:\WINDOWS\SYSTEM32\comctl32.dll
2006-08-21 07:26 16896 --a------ C:\WINDOWS\SYSTEM32\fltlib.dll
2006-08-21 04:14 23040 --a------ C:\WINDOWS\SYSTEM32\fltmc.exe
2006-08-16 06:59 100352 --a------ C:\WINDOWS\SYSTEM32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Sonic RecordNow!"=""
"IncrediMail"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe /c"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"BCMSMMSG"="BCMSMMSG.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"StorageGuard"="\"C:\\Program Files\\Fichiers communs\\Sonic\\Update Manager\\sgtray.exe\" /r"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe"
"CTDVDDet"="C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE"
"CTHelper"="CTHELPER.EXE"
"AsioReg"="REGSVR32.EXE /S CTASIO.DLL"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"nwiz"="nwiz.exe /install"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"vptray"="C:\\PROGRA~1\\NavNT\\vptray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"D-Link AirPlus XtremeG"="C:\\Program Files\\D-Link\\AirPlus XtremeG\\AirPlusCFG.exe"
"ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"
"HP Software Update"="\"c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
"{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}"="archenteric"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{CFE9E8A8-38C0-4EF8-AEC2-5035EFE81030}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"archenteric"="{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wintfj32
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyvwww
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061111-135106-248
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
backup-20061111-135106-504
O16 - DPF: {00000000-0000-0000-0000-000020040000} - http://207.234.185.217/ABoxInst_int14.exe
backup-20061111-135105-693
O4 - HKCU\..\Run: [Rwtt] "C:\DOCUME~1\JEAN-P~1\MESDOC~1\CROSOF~1\cmd.exe" -vt ndrv
backup-20061111-135105-415
R3 - URLSearchHook: (no name) - {6A945B63-BCA0-B626-868E-CD6937A68EC1} - C:\WINDOWS\system32\bfdoeg.dll (file missing)
backup-20061111-135105-494
O4 - HKCU\..\Run: [Fqafyaz] C:\Program Files\?icrosoft.NET\d?xplore.exe
backup-20061111-135105-590
O4 - HKLM\..\Run: [beep regs about start] C:\Documents and Settings\All Users\Application Data\Meta data beep regs\chicnoun.exe
backup-20061111-135105-404
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
backup-20061111-135105-227
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvmoc.dll,startup
backup-20061111-135105-195
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
backup-20061111-135105-435
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AC49A83B90A25E4B.job
Completion time: 06-11-11 14:03:38.85
C:\ComboFix.txt ... 06-11-11 14:03
Hope this helps.... Last note... Internet Explorer is REALLY slow today...
thanks for your help!
Here is the combofix log:
Jean-Pierre Hall‚ - 06-11-11 13:59:41,31 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Jean-Pierre Hall‚\Bureau"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\components
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Program Files\ICROSO~1.NET
C:\QooBox\Purity\Program Files\ICROSO~1.NET\d?xplore.exe
((((((((((((((((((((((((((((((( Files Created from 2006-10-11 to 2006-11-11 ))))))))))))))))))))))))))))))))))
2006-11-11 13:41 106,496 --a------ C:\WINDOWS\SYSTEM32\impgsje.dll
2006-11-11 11:56 101,888 --a------ C:\WINDOWS\SYSTEM32\drvmoc.dll
2006-11-11 11:54 40,973 ---hs---- C:\WINDOWS\SYSTEM32\xxyvwww.dll
2006-11-11 11:45 674,187 ---hs---- C:\WINDOWS\SYSTEM32\npqss.bak2
2006-11-05 19:44 602,245 ---hs---- C:\WINDOWS\SYSTEM32\npqss.bak1
2006-11-05 19:43 692,276 ---hs---- C:\WINDOWS\SYSTEM32\ssqpn.dll
2006-11-05 19:42 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2006-11-05 19:36 40,973 ---hs---- C:\WINDOWS\SYSTEM32\mljgheb.dll
2006-11-05 16:24 2 --a------ C:\WINDOWS\SYSTEM32\wapiit.exe
2006-11-05 16:22 40,973 ---hs---- C:\WINDOWS\SYSTEM32\ljjjghg.dll
2006-11-05 16:22 15,872 --------- C:\WINDOWS\SYSTEM32\wintfj32.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-11 13:53 -------- d-------- C:\Program Files\SAM
2006-11-11 13:53 -------- d-------- C:\Documents and Settings\Jean-Pierre Hall‚\Application Data\Skype
2006-11-11 13:05 -------- d-------- C:\Program Files\Fichiers communs
2006-11-06 05:43 -------- d-------- C:\Program Files\Hijackthis
2006-11-05 19:44 -------- d-------- C:\Program Files\VSAdd-in
2006-11-05 19:42 -------- d-------- C:\Program Files\Grisoft
2006-11-05 18:09 -------- d-------- C:\Program Files\NavNT
2006-10-24 11:08 -------- d-------- C:\Program Files\Morpheus
2006-10-14 13:00 -------- d-------- C:\Program Files\Fichiers communs\SWF Studio
2006-10-11 11:24 58880 --a------ C:\WINDOWS\SYSTEM32\pnrpnsp.dll
2006-10-11 11:24 553984 --a------ C:\WINDOWS\SYSTEM32\p2psvc.dll
2006-10-11 11:24 313344 --a------ C:\WINDOWS\SYSTEM32\p2pgraph.dll
2006-10-11 11:24 153088 --a------ C:\WINDOWS\SYSTEM32\p2p.dll
2006-10-11 11:24 116224 --a------ C:\WINDOWS\SYSTEM32\p2pnetsh.dll
2006-10-11 11:24 104960 --a------ C:\WINDOWS\SYSTEM32\p2pgasvc.dll
2006-09-29 20:35 67896 --a------ C:\Documents and Settings\Jean-Pierre Hall‚\Application Data\GDIPFONTCACHEV1.DAT
2006-09-29 20:06 -------- d-------- C:\Program Files\Fichiers communs\HP
2006-09-29 20:04 -------- d-------- C:\Program Files\HP
2006-09-29 20:04 -------- d-------- C:\Program Files\Hewlett-Packard
2006-09-29 20:03 -------- d-------- C:\Program Files\Fichiers communs\Hewlett-Packard
2006-09-29 19:07 -------- d--h----- C:\Documents and Settings\Jean-Pierre Hall‚\Application Data\GTek
2006-09-23 10:54 -------- d-------- C:\Program Files\Adobe
2006-09-13 00:03 1084416 --a------ C:\WINDOWS\SYSTEM32\msxml3.dll
2006-08-25 10:51 617472 --a------ C:\WINDOWS\SYSTEM32\comctl32.dll
2006-08-21 07:26 16896 --a------ C:\WINDOWS\SYSTEM32\fltlib.dll
2006-08-21 04:14 23040 --a------ C:\WINDOWS\SYSTEM32\fltmc.exe
2006-08-16 06:59 100352 --a------ C:\WINDOWS\SYSTEM32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Sonic RecordNow!"=""
"IncrediMail"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe /c"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"BCMSMMSG"="BCMSMMSG.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"StorageGuard"="\"C:\\Program Files\\Fichiers communs\\Sonic\\Update Manager\\sgtray.exe\" /r"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe"
"CTDVDDet"="C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE"
"CTHelper"="CTHELPER.EXE"
"AsioReg"="REGSVR32.EXE /S CTASIO.DLL"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"nwiz"="nwiz.exe /install"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"vptray"="C:\\PROGRA~1\\NavNT\\vptray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"D-Link AirPlus XtremeG"="C:\\Program Files\\D-Link\\AirPlus XtremeG\\AirPlusCFG.exe"
"ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"
"HP Software Update"="\"c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
"{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}"="archenteric"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{CFE9E8A8-38C0-4EF8-AEC2-5035EFE81030}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"archenteric"="{d7bdd42a-7e69-4bb8-aac3-d76ff65a3aa3}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wintfj32
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyvwww
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061111-135106-248
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
backup-20061111-135106-504
O16 - DPF: {00000000-0000-0000-0000-000020040000} - http://207.234.185.217/ABoxInst_int14.exe
backup-20061111-135105-693
O4 - HKCU\..\Run: [Rwtt] "C:\DOCUME~1\JEAN-P~1\MESDOC~1\CROSOF~1\cmd.exe" -vt ndrv
backup-20061111-135105-415
R3 - URLSearchHook: (no name) - {6A945B63-BCA0-B626-868E-CD6937A68EC1} - C:\WINDOWS\system32\bfdoeg.dll (file missing)
backup-20061111-135105-494
O4 - HKCU\..\Run: [Fqafyaz] C:\Program Files\?icrosoft.NET\d?xplore.exe
backup-20061111-135105-590
O4 - HKLM\..\Run: [beep regs about start] C:\Documents and Settings\All Users\Application Data\Meta data beep regs\chicnoun.exe
backup-20061111-135105-404
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
backup-20061111-135105-227
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvmoc.dll,startup
backup-20061111-135105-195
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
backup-20061111-135105-435
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AC49A83B90A25E4B.job
Completion time: 06-11-11 14:03:38.85
C:\ComboFix.txt ... 06-11-11 14:03
Hope this helps.... Last note... Internet Explorer is REALLY slow today...
thanks for your help!