Bon j'ai fait ce que tu m'as demandé
la seule chose c'est que je n'ai pas eue besoin de faire le 1 et de le valider ca ne m'a rien demander du tout.
voici le rapport combofix:
ComboFix 09-02-14.01 - dj 2009-02-15 14:08:53.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3061.1950 [GMT -5:00]
Lancé depuis: c:\users\dj\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\dj\Desktop\CFScript.txt..txt
* Un nouveau point de restauration a été créé
FILE ::
c:\programdata\ezsidmv.dat
c:\users\All Users\ezsidmv.dat
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\ezsidmv.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-15 au 2009-02-15 ))))))))))))))))))))))))))))))))))))
.
2009-02-15 12:52 . 2009-02-15 12:53 <REP> d-------- c:\program files\Common Files\Adobe
2009-02-15 12:49 . 2009-02-15 12:49 <REP> d-------- c:\users\All Users\NOS
2009-02-15 12:49 . 2009-02-15 12:49 <REP> d-------- c:\programdata\NOS
2009-02-15 12:49 . 2009-02-15 12:49 <REP> d-------- c:\program files\NOS
2009-02-14 17:07 . 2008-06-19 20:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-02-14 17:07 . 2008-06-19 20:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-02-14 17:07 . 2008-06-19 20:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-02-14 17:07 . 2008-06-19 20:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-14 17:07 . 2008-06-19 20:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-02-14 17:07 . 2008-06-19 20:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-02-14 17:07 . 2008-06-19 20:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-02-14 17:07 . 2008-06-19 20:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-02-14 17:00 . 2008-07-27 13:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-02-14 17:00 . 2008-07-27 13:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-02-14 17:00 . 2008-07-27 13:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-02-14 17:00 . 2008-07-27 13:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-02-14 17:00 . 2008-07-27 13:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-02-14 16:58 . 2008-12-04 23:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-14 16:58 . 2008-12-04 23:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-14 16:58 . 2008-12-04 23:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-14 16:58 . 2008-12-04 23:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-14 16:58 . 2008-12-04 23:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-13 11:40 . 2009-02-14 12:07 <REP> d-------- c:\users\dj\AppData\Roaming\Nero
2009-02-13 11:12 . 2009-02-13 11:12 4,767 --a------ c:\windows\Irremote.ini
2009-02-13 10:45 . 2009-02-14 12:08 <REP> d-------- c:\users\All Users\Nero
2009-02-13 10:45 . 2009-02-14 12:08 <REP> d-------- c:\programdata\Nero
2009-02-13 10:45 . 2009-02-13 11:37 <REP> d-------- c:\program files\Common Files\Nero
2009-02-13 10:44 . 2009-02-13 10:45 <REP> d-------- c:\program files\Common Files\LightScribe
2009-02-13 10:07 . 2009-02-15 12:23 266,286,692 --a------ c:\windows\MEMORY.DMP
2009-02-11 10:12 . 2009-02-11 11:15 <REP> d-------- c:\program files\MSNFix
2009-02-11 06:35 . 2009-01-14 22:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 06:35 . 2009-01-15 01:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-10 08:00 . 2009-02-10 08:03 <REP> d-------- c:\users\dj\AppData\Roaming\Vso
2009-02-10 08:00 . 2009-02-10 08:00 47,360 --a------ c:\windows\System32\drivers\pcouffin.sys
2009-02-10 08:00 . 2009-02-10 08:03 47,360 --a------ c:\users\dj\AppData\Roaming\pcouffin.sys
2009-02-06 17:56 . 2009-02-06 17:56 <REP> d-------- c:\users\dj\AppData\Roaming\Shape games
2009-02-03 08:56 . 2009-02-15 12:47 <REP> d-------- c:\program files\DVD43
2009-02-03 08:36 . 2009-02-03 08:36 <REP> d-------- c:\program files\SlySoft
2009-01-24 13:08 . 2009-01-24 13:08 <REP> d-------- c:\users\dj\AppData\Roaming\Flood Light Games
2009-01-24 13:08 . 2009-01-24 13:08 <REP> d-------- c:\users\All Users\Flood Light Games
2009-01-24 13:08 . 2009-01-24 13:08 <REP> d-------- c:\programdata\Flood Light Games
2009-01-21 07:39 . 2009-01-21 07:39 <REP> d-------- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-15 17:47 --------- d-----w c:\program files\NCH Swift Sound
2009-02-14 22:27 --------- d-----w c:\program files\Apoint2K
2009-02-14 22:21 --------- d-----w c:\program files\CONEXANT
2009-02-13 16:10 --------- d-----w c:\program files\Nero
2009-02-13 15:19 --------- d-----w c:\program files\Common Files\Ahead
2009-02-13 15:03 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-13 14:57 --------- d-----w c:\programdata\Spybot - Search & Destroy
2009-02-11 13:18 --------- d-----w c:\program files\Windows Mail
2009-02-10 23:36 --------- d-----w c:\program files\a-squared Free
2009-02-10 22:22 --------- d-----w c:\users\dj\AppData\Roaming\LimeWire
2009-02-10 22:11 --------- d-----w c:\users\dj\AppData\Roaming\uTorrent
2009-02-09 15:41 --------- d-----w c:\program files\PokerStars
2009-02-03 14:01 --------- d-----w c:\programdata\DVD Shrink
2009-02-03 13:37 53,248 ----a-w c:\users\dj\AppData\Roaming\AnyDVDPatcher.exe
2009-01-24 17:15 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-24 17:14 --------- d-----w c:\program files\CyberLink
2009-01-16 12:28 --------- d-----w c:\program files\Google
2009-01-12 14:12 --------- d-----w c:\programdata\Hewlett-Packard
2009-01-04 15:15 --------- d-----w c:\users\dj\AppData\Roaming\Friday's games
2008-12-28 23:08 --------- d-----w c:\users\dj\AppData\Roaming\Big Fish Games
2008-12-23 13:52 --------- d-----w c:\programdata\Skype
2008-12-22 13:44 --------- d-----w c:\program files\Common Files\PX Storage Engine
2008-12-22 13:42 --------- d-----w c:\users\dj\AppData\Roaming\DivX
2008-12-22 12:43 --------- d-----w c:\users\dj\AppData\Roaming\vlc
2008-12-21 05:27 --------- d-----w c:\program files\VideoLAN
2008-12-18 20:51 --------- d-----w c:\users\dj\AppData\Roaming\Skip-Bo
2008-12-18 17:28 --------- d-----w c:\programdata\MumboJumbo
2008-12-18 16:44 --------- d-----w c:\programdata\Alex Gordon
2008-12-17 15:58 --------- d-----w c:\programdata\InterAction studios
2008-12-16 14:05 --------- d-----w c:\users\dj\AppData\Roaming\skypePM
2008-12-16 02:42 288,768 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-03 14:30 284 ----a-w c:\users\dj\AppData\Roaming\wklnhst.dat
2008-11-21 21:44 161,096 ----a-w c:\windows\System32\DivXCodecVersionChecker.exe
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((( SnapShot_2009-02-15_12.20.43,44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-12 20:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1036-7B44-A90000000001}\SC_Reader.exe
- 2009-02-15 17:12:47 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-15 17:55:55 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-02-15 17:12:47 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-15 17:55:55 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-02-15 17:15:12 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-15 17:57:10 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-15 17:57:10 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-02-15 17:15:17 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-15 17:57:15 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-15 17:57:15 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-02-15 01:29:07 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-15 17:49:15 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-15 01:29:07 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-15 17:49:15 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-15 01:29:07 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-15 17:49:15 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-15 14:04:05 101,250 ----a-w c:\windows\System32\perfc009.dat
+ 2009-02-15 18:01:50 101,250 ----a-w c:\windows\System32\perfc009.dat
- 2009-02-15 14:04:05 123,556 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-02-15 18:01:50 123,556 ----a-w c:\windows\System32\perfc00C.dat
- 2009-02-15 14:04:05 587,178 ----a-w c:\windows\System32\perfh009.dat
+ 2009-02-15 18:01:50 587,178 ----a-w c:\windows\System32\perfh009.dat
- 2009-02-15 14:04:05 669,566 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-02-15 18:01:50 669,566 ----a-w c:\windows\System32\perfh00C.dat
- 2009-02-15 17:14:50 9,844 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4169959600-2362842377-2617876035-1000_UserData.bin
+ 2009-02-15 17:58:05 9,868 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4169959600-2362842377-2617876035-1000_UserData.bin
- 2009-02-15 17:14:50 74,070 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-15 17:58:05 74,070 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-02-15 00:44:06 3,130 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-02-15 17:55:11 3,130 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-02-15 17:14:47 52,344 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-15 17:58:03 52,376 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-16 39408]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-20 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DBB1980F-B43B-4F6F-A8BC-8368F659B6B3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{AD7F8D76-596A-46B6-A1BE-7978B37EBC19}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{BDD0DB37-CD1A-4630-BF83-284027470A64}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{29BC3C4B-70C5-46D5-A25E-98AA46DCDEE0}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{D5BCFBF9-A899-45D1-8DBF-FCB6CDBF739C}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2AD33227-D967-4FB9-90DC-3432A75F49DA}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2BD3E47F-667B-4919-BFAC-8AC002BD64B2}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C5679A7A-6A74-4760-ADE6-535CB713C192}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{48D80633-EC03-4810-8C4E-5EEBF3C623D9}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{B57C131F-4B99-4B42-87B0-3C9B41681FB7}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{987366F7-FDD5-4E86-80B0-357E5411CD58}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{6206A49D-A085-4517-A8C6-066660AE5DB3}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"TCP Query User{97B2967A-3E5D-4832-8980-DA4D387147D5}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{8B7B6907-1F9C-47AD-837A-5ED1872EC582}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"{2E60E7CE-F873-470D-BBAB-B3ADF14AD79E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-02-15 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2009-02-15 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_ca&c=81&bd=Presario&pf=laptop
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game12.zylom.com/activex/zylomgamesplayer.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-15 14:11:49
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-02-15 14:14:34
ComboFix-quarantined-files.txt 2009-02-15 19:14:31
ComboFix2.txt 2009-02-15 17:22:08
ComboFix3.txt 2009-02-15 01:23:36
Avant-CF: 165 974 695 936 octets libres
Après-CF: 165,946,998,784 octets libres
205 --- E O F --- 2009-02-14 22:23:46
quand j'ai exécuter hijackthis
un message me disait de l'exécuter en tant qu'administrateur alors j,ai fait ce que ce message disait
voici le rapport hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:26:26, on 2009-02-15
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - http://game12.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
End of file - 6612 bytes