***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.7.6.2566. For information, email support@simplysup.com
[Unregistered version]
Scan started at: 12:11:54 14 mars 2009
Using Database v7299
Operating System: Windows XP Home Edition (SP3) [Build: 5.1.2600]
File System: NTFS
UserData directory: C:\Documents and Settings\Marina\Application Data\Simply Super Software\Trojan Remover\
Database directory: C:\Program Files\Trojan Remover\
Logfile directory: C:\Documents and Settings\Marina\Mes documents\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Program Files\Trojan Remover\
Running with Administrator privileges
************************************************************
************************************************************
12:11:56: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
************************************************************
12:11:59: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
Key value: [Explorer.exe]
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1037824 bytes
Created: 16/01/2006 17:22
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
Key value: [C:\WINDOWS\system32\userinit.exe,]
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
26624 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
Key value: [logonui.exe]
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
515584 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: SynTPEnh
Value Data: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
761945 bytes
Created: 17/01/2006 13:05
Modified: 17/12/2005 00:32
Company: Synaptics, Inc.
--------------------
Value Name: LtMoh
Value Data: C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\ltmoh\Ltmoh.exe
184320 bytes
Created: 17/01/2006 13:20
Modified: 18/08/2004 11:37
Company: Agere Systems
--------------------
Value Name: AGRSMMSG
Value Data: AGRSMMSG.exe
C:\WINDOWS\AGRSMMSG.exe
88203 bytes
Created: 17/01/2006 13:20
Modified: 15/10/2005 14:29
Company: Agere Systems
--------------------
Value Name: THotkey
Value Data: C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
352256 bytes
Created: 17/01/2006 13:34
Modified: 05/01/2006 14:02
Company: TOSHIBA
--------------------
Value Name: TFncKy
Value Data: TFncKy.exe
TFncKy.exe - [file not found to scan]
--------------------
Value Name: TDispVol
Value Data: TDispVol.exe
C:\WINDOWS\system32\TDispVol.exe
73728 bytes
Created: 17/01/2006 13:58
Modified: 15/09/2005 14:19
Company: TOSHIBA Corporation
--------------------
Value Name: IntelZeroConfig
Value Data: "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
667718 bytes
Created: 05/12/2005 11:37
Modified: 05/12/2005 11:37
Company: Intel Corporation
--------------------
Value Name: IntelWireless
Value Data: "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
602182 bytes
Created: 28/11/2005 10:41
Modified: 28/11/2005 10:41
Company: Intel Corporation
--------------------
Value Name: RemoteControl
Value Data: "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
32768 bytes
Created: 09/10/2006 13:56
Modified: 31/10/2003 18:42
Company: Cyberlink Corp.
--------------------
Value Name: CFSServ.exe
Value Data: CFSServ.exe -NoClient
CFSServ.exe - [file not found to scan]
--------------------
Value Name: RegisterDropHandler
Value Data: C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
22528 bytes
Created: 12/11/2006 15:15
Modified: 07/07/1998 16:20
Company:
--------------------
Value Name: CanonSolutionMenu
Value Data: C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe
644696 bytes
Created: 28/03/2008 22:42
Modified: 14/05/2007 17:01
Company: CANON INC.
--------------------
Value Name: CanonMyPrinter
Value Data: C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
1603152 bytes
Created: 28/03/2008 22:42
Modified: 03/04/2007 17:50
Company: CANON INC.
--------------------
Value Name: SSBkgdUpdate
Value Data: "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
210472 bytes
Created: 25/10/2006 09:03
Modified: 25/10/2006 09:03
Company: Nuance Communications, Inc.
--------------------
Value Name: OpwareSE4
Value Data: "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
79400 bytes
Created: 04/02/2007 12:02
Modified: 04/02/2007 12:02
Company: Nuance Communications, Inc.
--------------------
Value Name: TkBellExe
Value Data: "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
185896 bytes
Created: 27/05/2008 14:31
Modified: 27/05/2008 14:31
Company: RealNetworks, Inc.
--------------------
Value Name: Adobe Reader Speed Launcher
Value Data: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
34672 bytes
Created: 12/06/2008 01:38
Modified: 12/06/2008 01:38
Company: Adobe Systems Incorporated
--------------------
Value Name: AppleSyncNotifier
Value Data: C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
116040 bytes
Created: 10/07/2008 08:47
Modified: 10/07/2008 08:47
Company: Apple Inc.
--------------------
Value Name: Symantec PIF AlertEng
Value Data: "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
583048 bytes
Created: 29/01/2008 16:38
Modified: 29/01/2008 16:38
Company: Symantec Corporation
--------------------
Value Name: OLPSYNCH
Value Data: C:\Program Files\Offline Course Player\OlpSynch.exe
C:\Program Files\Offline Course Player\OlpSynch.exe
42288 bytes
Created: 27/10/2008 19:58
Modified: 05/09/2008 04:00
Company: [no info]
--------------------
Value Name: RTHDCPL
Value Data: RTHDCPL.EXE
C:\WINDOWS\RTHDCPL.EXE
16206848 bytes
Created: 17/01/2006 13:16
Modified: 05/05/2006 06:59
Company: Realtek Semiconductor Corp.
--------------------
Value Name: Alcmtr
Value Data: ALCMTR.EXE
C:\WINDOWS\ALCMTR.EXE
69632 bytes
Created: 31/01/2009 16:04
Modified: 04/05/2005 09:43
Company: Realtek Semiconductor Corp.
--------------------
Value Name: ATICCC
Value Data: "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe
90112 bytes
Created: 10/05/2006 11:12
Modified: 10/05/2006 11:12
Company: [no info]
--------------------
Value Name: SunJavaUpdateSched
Value Data: "C:\Program Files\Java\jre6\bin\jusched.exe"
C:\Program Files\Java\jre6\bin\jusched.exe
148888 bytes
Created: 21/02/2009 18:19
Modified: 21/02/2009 18:19
Company: Sun Microsystems, Inc.
--------------------
Value Name: TrojanScanner
Value Data: C:\Program Files\Trojan Remover\Trjscan.exe /boot
C:\Program Files\Trojan Remover\Trjscan.exe
1303432 bytes
Created: 14/03/2009 12:09
Modified: 07/03/2009 15:27
Company: Simply Super Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Value Name: RegisterDropHandler
Value Data: C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
22528 bytes
Created: 12/11/2006 15:15
Modified: 07/07/1998 16:20
Company:
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Value Name: (Default) - does not hold valid string data
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: ctfmon.exe
Value Data: C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
15360 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:33
Company: Microsoft Corporation
--------------------
Value Name: PhotoJoy
Value Data: C:\Program Files\PhotoJoy\bin\PhotoJoy.exe /c
C:\Program Files\PhotoJoy\bin\PhotoJoy.exe
918840 bytes
Created: 22/09/2008 13:45
Modified: 22/09/2008 13:45
Company: IncrediMail, Ltd.
--------------------
Value Name: msnmsgr
Value Data: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
5724184 bytes
Created: 18/10/2007 11:34
Modified: 18/10/2007 11:34
Company: Microsoft Corporation
--------------------
Value Name: SUPERAntiSpyware
Value Data: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
1830128 bytes
Created: 17/02/2009 11:43
Modified: 17/02/2009 11:43
Company: SUPERAntiSpyware.com
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
This Registry Key appears to be empty
************************************************************
12:12:41: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------
ValueName: {56F9679E-7826-4C84-81F3-532071A8BCC5}
File: C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll
C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll
294400 bytes
Created: 05/02/2007 14:39
Modified: 05/02/2007 14:39
Company: Microsoft Corporation
----------
ValueName: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}
Value: Microsoft AntiMalware ShellExecuteHook
File: C:\PROGRA~1\WIFD1F~1\MpShHook.dll
C:\PROGRA~1\WIFD1F~1\MpShHook.dll
83224 bytes
Created: 03/11/2006 19:20
Modified: 03/11/2006 19:20
Company: Microsoft Corporation
----------
ValueName: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
File: C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
77824 bytes
Created: 13/05/2008 09:13
Modified: 13/05/2008 09:13
Company: SuperAdBlocker.com
----------
************************************************************
12:12:42: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
************************************************************
12:12:44: Scanning -----ACTIVE SCREENSAVER-----
ScreenSaver: C:\WINDOWS\system32\PHOTOJ~1.SCR
C:\WINDOWS\system32\PHOTOJ~1.SCR
1271096 bytes
Created: 22/09/2008 13:45
Modified: 22/09/2008 13:45
Company: IncrediMail, Ltd.
--------------------
************************************************************
12:12:45: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
Key: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}
Path: "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
C:\WINDOWS\system32\rundll32.exe
33792 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
----------
Key: {6BF52A52-394A-11d3-B153-00C04F79FAA6}
Path: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub
C:\WINDOWS\INF\wmp11.inf
2441 bytes
Created: 03/11/2006 10:03
Modified: 03/11/2006 09:03
Company: [no info]
----------
************************************************************
12:12:48: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: AppMgmt
%SystemRoot%\System32\appmgmts.dll - file is globally excluded (file cannot be found)
--------------------
Key: BITS
Path: %systemroot%\system32\qmgr.dll
C:\WINDOWS\system32\qmgr.dll
409088 bytes
Created: 16/01/2006 17:35
Modified: 14/04/2008 03:33
Company: Microsoft Corporation
--------------------
************************************************************
12:12:53: Scanning ----- SERVICES REGISTRY KEYS -----
Key: Apple Mobile Device
ImagePath: "C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
116040 bytes
Created: 10/07/2008 08:47
Modified: 10/07/2008 08:47
Company: Apple Inc.
----------
Key: ATI Smart
ImagePath: C:\WINDOWS\system32\ati2sgag.exe
C:\WINDOWS\system32\ati2sgag.exe
520192 bytes
Created: 01/02/2009 15:54
Modified: 02/08/2006 17:27
Company:
----------
Key: Automatic LiveUpdate Scheduler
ImagePath: "C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe"
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
238968 bytes
Created: 21/02/2008 15:02
Modified: 21/02/2008 15:02
Company: Symantec Corporation
----------
Key: bdfdll
ImagePath: \??\C:\Program Files\Softwin\BitDefender10\bdfdll.sys
C:\Program Files\Softwin\BitDefender10\bdfdll.sys - [file not found to scan]
----------
Key: BDFsDrv
ImagePath: \??\C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys
C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys - [file not found to scan]
----------
Key: BDRsDrv
ImagePath: \??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys
C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys - [file not found to scan]
----------
Key: Belcarra USBLAN
ImagePath: system32\DRIVERS\btblan.sys
C:\WINDOWS\system32\DRIVERS\btblan.sys
37360 bytes
Created: 01/03/2007 11:13
Modified: 01/03/2007 11:13
Company: Belcarra Technologies
----------
Key: BHDrvx86
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\BHDrvx86.sys
C:\WINDOWS\System32\Drivers\NIS\1002000.007\BHDrvx86.sys
255536 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: Bonjour Service
ImagePath: "C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Program Files\Bonjour\mDNSResponder.exe
229376 bytes
Created: 24/07/2007 14:17
Modified: 24/07/2007 14:17
Company: Apple Inc.
----------
Key: btwhid
ImagePath: system32\DRIVERS\btwhid.sys
C:\WINDOWS\system32\DRIVERS\btwhid.sys
47875 bytes
Created: 26/09/2006 17:08
Modified: 26/09/2006 17:08
Company: Broadcom Corporation.
----------
Key: catchme
ImagePath: \??\C:\DOCUME~1\Marina\LOCALS~1\Temp\catchme.sys - this file is globally excluded
----------
Key: ccHP
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\ccHPx86.sys
C:\WINDOWS\System32\Drivers\NIS\1002000.007\ccHPx86.sys
362544 bytes
Created: 16/02/2009 12:55
Modified: 16/02/2009 09:57
Company: Symantec Corporation
----------
Key: CFSvcs
ImagePath: C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
40960 bytes
Created: 17/01/2006 13:53
Modified: 18/01/2005 00:38
Company: TOSHIBA CORPORATION
----------
Key: CoachUsb
ImagePath: system32\DRIVERS\CoachUsb.sys
C:\WINDOWS\system32\DRIVERS\CoachUsb.sys
-R- 46368 bytes
Created: 07/10/2006 22:43
Modified: 29/08/2003 08:37
Company: Accapella Ltd.
----------
Key: CoachVc
ImagePath: system32\DRIVERS\CoachVc.sys
C:\WINDOWS\system32\DRIVERS\CoachVc.sys
-R- 44352 bytes
Created: 07/10/2006 22:43
Modified: 31/07/2003 10:47
Company: Accapella Ltd.
----------
Key: driverhardwarev2
ImagePath: \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
14336 bytes
Created: 24/01/2009 15:18
Modified: 24/01/2009 15:18
Company: CybelSoft
----------
Key: eeCtrl
ImagePath: \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys
C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys
371248 bytes
Created: 16/02/2009 10:10
Modified: 26/02/2009 02:18
Company: Symantec Corporation
----------
Key: EraserUtilRebootDrv
ImagePath: \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
101936 bytes
Created: 26/02/2009 02:18
Modified: 26/02/2009 02:18
Company: Symantec Corporation
----------
Key: EvtEng
ImagePath: C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
114753 bytes
Created: 28/11/2005 10:29
Modified: 28/11/2005 10:29
Company: Intel Corporation
----------
Key: hwdatacard
ImagePath: system32\DRIVERS\ewusbmdm.sys
C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys - [file not found to scan]
----------
Key: ialm
ImagePath: system32\DRIVERS\ialmnt5.sys
C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
1353820 bytes
Created: 17/01/2006 17:25
Modified: 28/11/2005 22:20
Company: Intel Corporation
----------
Key: IDSxpx86
ImagePath: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090310.003\IDSxpx86.sys
C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090310.003\IDSxpx86.sys
276344 bytes
Created: 11/03/2009 21:14
Modified: 29/01/2009 22:50
Company: Symantec Corporation
----------
Key: IJPLMSVC
ImagePath: C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
101528 bytes
Created: 28/03/2008 22:45
Modified: 13/04/2007 07:49
Company:
----------
Key: ImapiService
ImagePath: %systemroot%\system32\imapi.exe
C:\WINDOWS\system32\imapi.exe
150528 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
----------
Key: InCDPass
ImagePath: System32\DRIVERS\InCDPass.sys
C:\WINDOWS\System32\DRIVERS\InCDPass.sys
28672 bytes
Created: 09/10/2006 13:48
Modified: 07/07/2004 12:48
Company: Ahead Software AG
----------
Key: InCDsrv
ImagePath: C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
1163378 bytes
Created: 09/10/2006 13:48
Modified: 07/07/2004 12:42
Company: Ahead Software AG
----------
Key: Iviaspi
ImagePath: system32\drivers\iviaspi.sys
C:\WINDOWS\system32\drivers\iviaspi.sys
21060 bytes
Created: 17/01/2006 14:02
Modified: 10/09/2003 23:36
Company: InterVideo, Inc.
----------
Key: JavaQuickStarterService
ImagePath: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
C:\Program Files\Java\jre6\bin\jqs.exe
152984 bytes
Created: 21/02/2009 18:19
Modified: 21/02/2009 18:19
Company: Sun Microsystems, Inc.
----------
Key: Lbd
ImagePath: system32\DRIVERS\Lbd.sys
C:\WINDOWS\system32\DRIVERS\Lbd.sys
64160 bytes
Created: 20/01/2009 23:11
Modified: 20/01/2009 23:11
Company: Lavasoft AB
----------
Key: LiveUpdate
ImagePath: "C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE"
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
3220856 bytes
Created: 21/02/2008 15:02
Modified: 21/02/2008 15:02
Company: Symantec Corporation
----------
Key: LiveUpdate Notice Service
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll"
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
583048 bytes
Created: 29/01/2008 16:38
Modified: 29/01/2008 16:38
Company: Symantec Corporation
----------
Key: maconfservice
ImagePath: "C:\Program Files\ma-config.com\maconfservice.exe"
C:\Program Files\ma-config.com\maconfservice.exe
216232 bytes
Created: 24/01/2009 14:46
Modified: 24/01/2009 14:46
Company: CybelSoft
----------
Key: NAVENG
ImagePath: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090313.032\NAVENG.SYS
C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090313.032\NAVENG.SYS
89104 bytes
Created: 14/03/2009 10:57
Modified: 10/03/2009 18:14
Company: Symantec Corporation
----------
Key: NAVEX15
ImagePath: \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090313.032\NAVEX15.SYS
C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090313.032\NAVEX15.SYS
876144 bytes
Created: 14/03/2009 10:57
Modified: 10/03/2009 18:14
Company: Symantec Corporation
----------
Key: Netdevio
ImagePath: system32\DRIVERS\netdevio.sys
C:\WINDOWS\system32\DRIVERS\netdevio.sys
12032 bytes
Created: 17/01/2006 13:53
Modified: 29/01/2003 22:35
Company: TOSHIBA Corporation.
----------
Key: Norton Internet Security
ImagePath: "C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files\Norton Internet Security\Engine\16.2.0.7\diMaster.dll" /prefetch:1
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
-R- 115560 bytes
Created: 16/02/2009 12:53
Modified: 12/12/2008 04:28
Company: Symantec Corporation
----------
Key: odserv
ImagePath: "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE"
C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE
443776 bytes
Created: 24/08/2007 03:19
Modified: 24/08/2007 03:19
Company: Microsoft Corporation
----------
Key: ose
ImagePath: "C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE"
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
145184 bytes
Created: 26/10/2006 14:03
Modified: 26/10/2006 14:03
Company: Microsoft Corporation
----------
Key: PCASp50
ImagePath: System32\Drivers\PCASp50.sys
C:\WINDOWS\System32\Drivers\PCASp50.sys
20096 bytes
Created: 19/11/2005 02:13
Modified: 19/11/2005 02:13
Company: Printing Communications Assoc., Inc. (PCAUSA)
----------
Key: Pfc
ImagePath: system32\drivers\pfc.sys
C:\WINDOWS\system32\drivers\pfc.sys
10368 bytes
Created: 17/01/2006 14:02
Modified: 19/09/2003 01:47
Company: Padus, Inc.
----------
Key: Planificateur LiveUpdate automatique
ImagePath: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
238968 bytes
Created: 21/02/2008 15:02
Modified: 21/02/2008 15:02
Company: Symantec Corporation
----------
Key: ProtexisLicensing
ImagePath: C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\PSIService.exe
177704 bytes
Created: 05/06/2007 13:20
Modified: 05/06/2007 13:20
Company:
----------
Key: RegSrvc
ImagePath: C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
217164 bytes
Created: 28/11/2005 10:28
Modified: 28/11/2005 10:28
Company: Intel Corporation
----------
Key: S24EventMonitor
ImagePath: C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
540745 bytes
Created: 28/11/2005 10:31
Modified: 28/11/2005 10:31
Company: Intel Corporation
----------
Key: s24trans
ImagePath: system32\DRIVERS\s24trans.sys
C:\WINDOWS\system32\DRIVERS\s24trans.sys
13568 bytes
Created: 28/11/2005 11:09
Modified: 28/11/2005 11:09
Company: Intel Corporation
----------
Key: SASDIFSV
ImagePath: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
8944 bytes
Created: 17/02/2009 11:43
Modified: 17/02/2009 11:43
Company: SUPERAdBlocker.com and SUPERAntiSpyware.com
----------
Key: SASENUM
ImagePath: \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
-R- 7408 bytes
Created: 17/02/2009 11:43
Modified: 17/02/2009 11:43
Company: SUPERAdBlocker.com and SUPERAntiSpyware.com
----------
Key: SASKUTIL
ImagePath: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
55024 bytes
Created: 17/02/2009 11:43
Modified: 17/02/2009 11:43
Company: SUPERAdBlocker.com and SUPERAntiSpyware.com
----------
Key: sffdisk
ImagePath: system32\DRIVERS\sffdisk.sys
C:\WINDOWS\system32\DRIVERS\sffdisk.sys
11904 bytes
Created: 03/08/2004 23:59
Modified: 13/04/2008 19:40
Company: Microsoft Corporation
----------
Key: sffp_sd
ImagePath: system32\DRIVERS\sffp_sd.sys
C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
11008 bytes
Created: 03/08/2004 23:59
Modified: 13/04/2008 19:40
Company: Microsoft Corporation
----------
Key: SRTSP
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SRTSP.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SRTSP.SYS
306736 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SRTSPX
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SRTSPX.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SRTSPX.SYS
43696 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: ssmdrv
ImagePath: system32\DRIVERS\ssmdrv.sys
C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
21248 bytes
Created: 25/06/2008 14:48
Modified: 08/11/2007 18:03
Company: AVIRA GmbH
----------
Key: SwPrv
ImagePath: C:\WINDOWS\system32\dllhost.exe /Processid:{65BCE06B-43D2-431A-BEDE-87959CB15E18}
C:\WINDOWS\system32\dllhost.exe
5120 bytes
Created: 16/01/2006 17:22
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
----------
Key: SYMDNS
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SYMDNS.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMDNS.SYS
12976 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SymEFA
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SYMEFA.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMEFA.SYS
309296 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SymEvent
ImagePath: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
124464 bytes
Created: 16/02/2009 09:58
Modified: 16/02/2009 09:58
Company: Symantec Corporation
----------
Key: SYMFW
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SYMFW.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMFW.SYS
89904 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SYMIDS
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SYMIDS.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMIDS.SYS
34608 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SymIM
ImagePath: system32\DRIVERS\SymIM.sys
C:\WINDOWS\system32\DRIVERS\SymIM.sys
-R- 36272 bytes
Created: 17/02/2009 15:00
Modified: 12/12/2008 04:28
Company: Symantec Corporation
----------
Key: SymIMMP
ImagePath: system32\DRIVERS\SymIM.sys
C:\WINDOWS\system32\DRIVERS\SymIM.sys
-R- 36272 bytes
Created: 17/02/2009 15:00
Modified: 12/12/2008 04:28
Company: Symantec Corporation
----------
Key: SYMNDIS
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SYMNDIS.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMNDIS.SYS
37424 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SYMREDRV
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SYMREDRV.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMREDRV.SYS
24624 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SYMTDI
ImagePath: \SystemRoot\System32\Drivers\NIS\1002000.007\SYMTDI.SYS
C:\WINDOWS\System32\Drivers\NIS\1002000.007\SYMTDI.SYS
198192 bytes
Created: 16/02/2009 12:55
Modified: 12/12/2008 04:29
Company: Symantec Corporation
----------
Key: SynTP
ImagePath: system32\DRIVERS\SynTP.sys
C:\WINDOWS\system32\DRIVERS\SynTP.sys
191936 bytes
Created: 17/01/2006 13:05
Modified: 17/12/2005 00:15
Company: Synaptics, Inc.
----------
Key: TAPPSRV
ImagePath: "C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe"
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
35328 bytes
Created: 17/01/2006 13:34
Modified: 20/12/2005 11:22
Company: TOSHIBA Corp.
----------
Key: tifm21
ImagePath: system32\drivers\tifm21.sys
C:\WINDOWS\system32\drivers\tifm21.sys
162560 bytes
Created: 30/11/2005 18:12
Modified: 30/11/2005 10:12
Company: Texas Instruments
----------
Key: tosrfec
ImagePath: system32\DRIVERS\tosrfec.sys
C:\WINDOWS\system32\DRIVERS\tosrfec.sys
9344 bytes
Created: 09/09/2005 14:47
Modified: 09/09/2005 14:47
Company: TOSHIBA Corporation
----------
Key: TVALD
ImagePath: system32\DRIVERS\NBSMI.sys
C:\WINDOWS\system32\DRIVERS\NBSMI.sys
6144 bytes
Created: 17/01/2006 13:34
Modified: 20/10/2005 14:03
Company: Toshiba Corporation
----------
Key: Tvs
ImagePath: system32\DRIVERS\Tvs.sys
C:\WINDOWS\system32\DRIVERS\Tvs.sys
43392 bytes
Created: 17/01/2006 13:56
Modified: 30/11/2005 11:01
Company: TOSHIBA Corporation
----------
Key: UMAXPCLS
ImagePath: system32\DRIVERS\umaxpcls.sys
C:\WINDOWS\system32\DRIVERS\umaxpcls.sys
22912 bytes
Created: 22/10/2006 21:16
Modified: 17/08/2001 20:58
Company: Microsoft Corporation
----------
Key: UnlockerDriver5
ImagePath: \??\C:\Program Files\Unlocker\UnlockerDriver5.sys
C:\Program Files\Unlocker\UnlockerDriver5.sys
4096 bytes
Created: 02/05/2008 05:15
Modified: 02/05/2008 05:15
Company: [no info]
----------
Key: usnjsvc
ImagePath: "C:\Program Files\Windows Live\Messenger\usnsvc.exe"
C:\Program Files\Windows Live\Messenger\usnsvc.exe
98328 bytes
Created: 18/10/2007 11:31
Modified: 18/10/2007 11:31
Company: Microsoft Corporation
----------
Key: w39n51
ImagePath: system32\DRIVERS\w39n51.sys
C:\WINDOWS\system32\DRIVERS\w39n51.sys
1428096 bytes
Created: 17/01/2006 17:27
Modified: 05/12/2005 09:55
Company: Intel® Corporation
----------
Key: WinDefend
ImagePath: "C:\Program Files\Windows Defender\MsMpEng.exe"
C:\Program Files\Windows Defender\MsMpEng.exe
13592 bytes
Created: 03/11/2006 19:19
Modified: 03/11/2006 19:19
Company: Microsoft Corporation
----------
Key: WLSetupSvc
ImagePath: "C:\Program Files\Windows Live\installer\WLSetupSvc.exe"
C:\Program Files\Windows Live\installer\WLSetupSvc.exe
266240 bytes
Created: 25/10/2007 15:27
Modified: 25/10/2007 15:27
Company: Microsoft Corporation
----------
Key: WpdUsb
ImagePath: system32\DRIVERS\wpdusb.sys
C:\WINDOWS\system32\DRIVERS\wpdusb.sys
38528 bytes
Created: 10/08/2004 22:05
Modified: 18/10/2006 20:00
Company: Microsoft Corporation
----------
************************************************************
12:13:37: Scanning -----VXD ENTRIES-----
Checking the following VxD entries:
************************************************************
12:13:38: Scanning ----- WINLOGON\NOTIFY DLLS -----
Key : !SASWinLogon
DLLName: C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
356352 bytes
Created: 22/12/2008 11:05
Modified: 22/12/2008 11:05
Company: SUPERAntiSpyware.com
----------
Key : igfxcui
DLLName: igfxdev.dll
C:\WINDOWS\system32\igfxdev.dll
135168 bytes
Created: 17/01/2006 17:25
Modified: 28/11/2005 21:51
Company: Intel Corporation
----------
************************************************************
12:13:39: Scanning ----- CONTEXTMENUHANDLERS -----
Key: ShellExtension
CLSID: [empty]
----------
Key: Symantec.Norton.Antivirus.IEContextMenu
CLSID: {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}
Path: "C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NavShExt.dll"
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\NavShExt.dll
-R- 178032 bytes
Created: 16/02/2009 12:54
Modified: 12/12/2008 04:28
Company: Symantec Corporation
----------
Key: ZFAdd
CLSID: {8FF88D27-7BD0-11D1-BFB7-00AA00262A11}
Path: C:\Program Files\WinAce\arcext.dll
C:\Program Files\WinAce\arcext.dll
166912 bytes
Created: 10/07/2007 14:16
Modified: 26/06/2006 01:06
Company: e-merge GmbH
----------
Key: {B33DE746-DEFE-4D7A-87DB-900864B1D3A8}
Path: C:\Program Files\Ashampoo\Ashampoo WinOptimizer Platinum 3\ContextHandler.dll
C:\Program Files\Ashampoo\Ashampoo WinOptimizer Platinum 3\ContextHandler.dll
418304 bytes
Created: 20/09/2007 13:51
Modified: 10/11/2005 18:08
Company: [no info]
----------
Key: {B83DE149-CEFA-5D3A-82DB-A22864B1E3A9}
CLSID: {B83DE149-CEFA-5D3A-82DB-A22864B1E3A9}
File: [CLSID does not appear to reference a file]
----------
Key: {CA8ACAFA-5FBB-467B-B348-90DD488DE003}
Path: C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
61440 bytes
Created: 27/02/2007 11:39
Modified: 27/02/2007 11:39
Company: SUPERAntiSpyware.com
----------
************************************************************
12:13:40: Scanning ----- FOLDER\COLUMNHANDLERS -----
Key: {F9DB5320-233E-11D1-9F84-707F02C10627}
File: C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
378200 bytes
Created: 11/06/2008 21:49
Modified: 11/06/2008 21:49
Company: Adobe Systems, Inc.
----------
************************************************************
12:13:40: Scanning ----- BROWSER HELPER OBJECTS -----
Key: {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
BHO: C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
75128 bytes
Created: 11/06/2008 21:33
Modified: 11/06/2008 21:33
Company: Adobe Systems Incorporated
----------
Key: {3049C3E9-B461-4BC5-8870-4C09146192CA}
BHO: C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
308856 bytes
Created: 27/05/2008 14:32
Modified: 27/05/2008 14:32
Company: RealPlayer
----------
Key: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
BHO: C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
-R- 344944 bytes
Created: 16/02/2009 12:54
Modified: 12/12/2008 04:28
Company: Symantec Corporation
----------
Key: {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
BHO: C:\Program Files\Norton Internet Security\Engine\16.2.0.7\IPSBHO.DLL
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\IPSBHO.DLL
-R- 107896 bytes
Created: 16/02/2009 12:54
Modified: 16/02/2009 09:57
Company: Symantec Corporation
----------
Key: {9030D464-4C02-4ABF-8ECC-5164760863C6}
BHO: C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
408440 bytes
Created: 17/02/2009 16:11
Modified: 17/02/2009 16:11
Company: Microsoft Corporation
----------
Key: {CFC4F59B-A2DA-4e12-B337-52A4F871E10C}
BHO: C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaIEHelper.dll
C:\Program Files\Shareaza Applications\Shareaza MediaBar\ShareazaIEHelper.dll
398784 bytes
Created: 02/09/2008 15:07
Modified: 02/09/2008 15:07
Company:
----------
Key: {DBC80044-A445-435b-BC74-9C25C1C588A9}
BHO: C:\Program Files\Java\jre6\bin\jp2ssv.dll
C:\Program Files\Java\jre6\bin\jp2ssv.dll
35840 bytes
Created: 21/02/2009 18:19
Modified: 21/02/2009 18:19
Company: Sun Microsystems, Inc.
----------
Key: {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
BHO: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
73728 bytes
Created: 21/02/2009 18:19
Modified: 21/02/2009 18:19
Company: Sun Microsystems, Inc.
----------
************************************************************
12:13:42: Scanning ----- SHELLSERVICEOBJECTS -----
Key: SysTray
CLSID: {35CEC8A3-2BE6-11D2-8773-92E220524153}
Path: %systemroot%\system32\stobject.dll
C:\WINDOWS\system32\stobject.dll
122368 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:33
Company: Microsoft Corporation
----------
************************************************************
12:13:43: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
************************************************************
12:13:43: Scanning ----- IMAGEFILE DEBUGGERS -----
No "Debugger" entries found.
************************************************************
12:13:43: Scanning ----- APPINIT_DLLS -----
The AppInit_DLLs value is blank or does not exist
************************************************************
12:13:44: Scanning ----- SECURITY PROVIDER DLLS -----
************************************************************
12:13:44: Scanning ------ COMMON STARTUP GROUP ------
[C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
-HS- 84 bytes
Created: 16/01/2006 18:29
Modified: 16/01/2006 17:37
Company: [no info]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini - no action taken on this file
--------------------
Microsoft Office.lnk - links to C:\Program Files\Microsoft Office\Office\OSA9.EXE
C:\Program Files\Microsoft Office\Office\OSA9.EXE
65588 bytes
Created: 17/02/1999 21:05
Modified: 17/02/1999 21:05
Company: Microsoft Corporation
--------------------
************************************************************
No User Startup Groups were located to check
************************************************************
12:13:45: Scanning ----- SCHEDULED TASKS -----
Taskname: Ad-Aware Update (Weekly).job
File: C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Parameters: update all silent
Next Run Time: 16/03/2009 23:11:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: SYSTEM
Comments: Cette opération permet d’effectuer une analyse planifiée avec Ad-Aware
C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe - [file not found to scan]
----------
Taskname: MP Scheduled Scan.job
File: C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
293144 bytes
Created: 03/11/2006 19:20
Modified: 03/11/2006 19:20
Company: Microsoft Corporation
Parameters: Scan -RestrictPrivileges
Next Run Time: 15/03/2009 12:00:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: SYSTEM
Comments: Scheduled Scan
----------
Taskname: User_Feed_Synchronization-{2785EB8F-DC22-4694-BC2B-9FB76F000F5D}.job
File: C:\WINDOWS\system32\msfeedssync.exe
C:\WINDOWS\system32\msfeedssync.exe
13312 bytes
Created: 15/01/2009 02:01
Modified: 15/01/2009 02:01
Company: Microsoft Corporation
Parameters: sync
Next Run Time: 14/03/2009 17:10:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: Marina
Comments: Met à jour les flux système obsolètes.
----------
************************************************************
12:13:47: Scanning ----- SHELLICONOVERLAYIDENTIFIERS -----
************************************************************
12:13:47: Scanning ----- DEVICE DRIVER ENTRIES -----
Value: MSACM.CEGSM
File: mobilev.acm
C:\WINDOWS\system32\mobilev.acm
57426 bytes
Created: 22/07/2007 21:25
Modified: 24/02/2004 15:20
Company: [no info]
----------
Value: msacm.siren
File: sirenacm.dll
C:\WINDOWS\system32\sirenacm.dll
49480 bytes
Created: 02/12/2008 22:37
Modified: 02/12/2008 22:37
Company: Microsoft Corporation
----------
Value: vidc.DIVX
File: DivX.dll
C:\WINDOWS\system32\DivX.dll
684032 bytes
Created: 06/11/2008 17:33
Modified: 06/11/2008 17:33
Company: DivX, Inc.
----------
************************************************************
12:14:04: ----- ADDITIONAL CHECKS -----
PE386 rootkit checks completed
----------
Winlogon registry rootkit checks completed
----------
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
----------
Windows Explorer Policies checks completed
----------
Desktop Wallpaper: C:\Documents and Settings\Marina\Local Settings\Application Data\PhotoJoy\Runtime\Collage\PhotoJoy Collage.bmp
C:\Documents and Settings\Marina\Local Settings\Application Data\PhotoJoy\Runtime\Collage\PhotoJoy Collage.bmp
3072054 bytes
Created: 24/09/2008 19:10
Modified: 14/03/2009 10:54
Company: [no info]
----------
Web Desktop Wallpaper: %USERPROFILE%\Local Settings\Application Data\PhotoJoy\Runtime\Collage\PhotoJoy Collage.bmp
C:\Documents and Settings\Marina\Local Settings\Application Data\PhotoJoy\Runtime\Collage\PhotoJoy Collage.bmp
3072054 bytes
Created: 24/09/2008 19:10
Modified: 14/03/2009 10:54
Company: [no info]
----------
Checks for rogue DNS NameServers completed
----------
----------
Additional checks completed
************************************************************
12:14:06: Scanning ----- RUNNING PROCESSES -----
C:\WINDOWS\System32\smss.exe
50688 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\csrss.exe
6144 bytes
Created: 16/01/2006 17:22
Modified: 14/04/2008 03:33
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\winlogon.exe
512000 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\services.exe
109056 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\lsass.exe
13312 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\Ati2evxx.exe
401408 bytes
Created: 17/01/2006 17:25
Modified: 02/08/2006 23:01
Company: ATI Technologies Inc.
--------------------
C:\WINDOWS\system32\svchost.exe
14336 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\Program Files\Windows Defender\MsMpEng.exe - file already scanned
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
--------------------
C:\Program Files\Ahead\InCD\InCDsrv.exe - file already scanned
--------------------
C:\WINDOWS\system32\Ati2evxx.exe - file already scanned
--------------------
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
266295 bytes
Created: 26/09/2006 17:37
Modified: 26/09/2006 17:37
Company: Broadcom Corporation.
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe - file already scanned
--------------------
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe - file already scanned
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\Explorer.EXE - file already scanned
--------------------
C:\WINDOWS\system32\spoolsv.exe
57856 bytes
Created: 16/01/2006 17:23
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
--------------------
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe - file already scanned
--------------------
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe - file already scanned
--------------------
C:\Program Files\Bonjour\mDNSResponder.exe - file already scanned
--------------------
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe - file already scanned
--------------------
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE - file already scanned
--------------------
C:\Program Files\Java\jre6\bin\jqs.exe - file already scanned
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe - file already scanned
--------------------
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe - file already scanned
--------------------
C:\WINDOWS\system32\PSIService.exe - file already scanned
--------------------
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe - file already scanned
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe - file already scanned
--------------------
C:\WINDOWS\system32\SearchIndexer.exe
300032 bytes
Created: 05/02/2007 14:34
Modified: 05/02/2007 14:34
Company: Microsoft Corporation
--------------------
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe - file already scanned
--------------------
C:\Program Files\ltmoh\Ltmoh.exe - file already scanned
--------------------
C:\WINDOWS\AGRSMMSG.exe - file already scanned
--------------------
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe - file already scanned
--------------------
C:\Program Files\Synaptics\SynTP\Toshiba.exe
151552 bytes
Created: 17/01/2006 13:05
Modified: 17/12/2005 00:21
Company: Synaptics, Inc.
--------------------
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
184320 bytes
Created: 17/01/2006 13:58
Modified: 15/09/2005 14:19
Company: TOSHIBA Corporation
--------------------
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe - file already scanned
--------------------
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe - file already scanned
--------------------
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe - file already scanned
--------------------
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
798720 bytes
Created: 17/01/2006 13:54
Modified: 17/11/2005 23:44
Company: TOSHIBA CORPORATION
--------------------
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe - file already scanned
--------------------
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe - file already scanned
--------------------
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe - file already scanned
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe - file already scanned
--------------------
C:\Program Files\Offline Course Player\OlpSynch.exe - file already scanned
--------------------
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
397381 bytes
Created: 28/11/2005 10:37
Modified: 28/11/2005 10:37
Company: Intel Corporation
--------------------
C:\WINDOWS\RTHDCPL.EXE - file already scanned
--------------------
C:\Program Files\Java\jre6\bin\jusched.exe - file already scanned
--------------------
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
45056 bytes
Created: 02/01/2006 17:41
Modified: 02/01/2006 17:41
Company: ATI Technologies Inc.
--------------------
C:\WINDOWS\system32\ctfmon.exe - file already scanned
--------------------
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe - file already scanned
--------------------
C:\WINDOWS\system32\wbem\wmiapsrv.exe
126464 bytes
Created: 16/01/2006 17:33
Modified: 14/04/2008 03:34
Company: Microsoft Corporation
--------------------
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe - file already scanned
--------------------
C:\WINDOWS\System32\alg.exe
44544 bytes
Created: 16/01/2006 17:22
Modified: 14/04/2008 03:33
Company: Microsoft Corporation
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
--------------------
C:\Program Files\PhotoJoy\bin\PjApp.exe
378168 bytes
Created: 22/09/2008 13:45
Modified: 22/09/2008 13:45
Company: IncrediMail, Ltd.
--------------------
C:\Program Files\Windows Live\Messenger\usnsvc.exe - file already scanned
--------------------
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe - file already scanned
--------------------
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe - file already scanned
--------------------
C:\Program Files\Internet Explorer\iexplore.exe
636264 bytes
Created: 16/01/2006 17:35
Modified: 15/01/2009 02:17
Company: Microsoft Corporation
--------------------
C:\Program Files\Internet Explorer\iexplore.exe - file already scanned
--------------------
C:\WINDOWS\system32\igfxsrvc.exe
159744 bytes
Created: 17/01/2006 17:25
Modified: 28/11/2005 21:51
Company: Intel Corporation
--------------------
C:\Program Files\Internet Explorer\iexplore.exe - file already scanned
--------------------
C:\Program Files\Internet Explorer\iexplore.exe - file already scanned
--------------------
C:\Program Files\Internet Explorer\iexplore.exe - file already scanned
--------------------
C:\Program Files\Internet Explorer\iexplore.exe - file already scanned
--------------------
C:\Documents and Settings\Marina\Bureau\trjsetup676.exe
8562240 bytes
Created: 14/03/2009 11:52
Modified: 14/03/2009 11:52
Company: Simply Super Software
--------------------
C:\DOCUME~1\Marina\LOCALS~1\Temp\is-9TR22.tmp\trjsetup676.tmp
993280 bytes
Created: 14/03/2009 11:53
Modified: 14/03/2009 11:53
Company:
--------------------
C:\Program Files\Trojan Remover\trupd.exe
905608 bytes
Created: 14/03/2009 11:55
Modified: 21/02/2009 14:21
Company: Simply Super Software
--------------------
C:\Program Files\Windows Defender\MpCmdRun.exe - file already scanned
--------------------
C:\Documents and Settings\Marina\Application Data\Simply Super Software\Trojan Remover\nyq93.exe
FileSize: 3048312
[This is a Trojan Remover component]
--------------------
************************************************************
12:14:47: Checking HOSTS file
No malicious entries were found in the HOSTS file
************************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
HKLM\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\WINDOWS\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://go.microsoft.com/fwlink/?LinkId=54896
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://mystart.incredimail.com/french/
HKCU\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\WINDOWS\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://recherche.neuf.fr/
************************************************************
=== NO CHANGES HAVE BEEN MADE TO YOUR SYSTEM FILES ===
Scan completed at: 12:14:47 14 mars 2009
Total Scan time: 00:02:52
************************************************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31:44, on 14/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichie