***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.6.9.2533. For information, email support@simplysup1.com
[Unregistered version]
Scan started at: 17:13:34 25 mai 2008
Using Database v7005
Operating System: Windows XP SP2 [Windows XP Home Edition Service Pack 2 (Build 2600)]
File System: NTFS
Data directory: D:\Documents and Settings\huby\Application Data\Simply Super Software\Trojan Remover\
Logfile directory: D:\Documents and Settings\huby\Mes documents\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Program Files\Trojan Remover\
Running with Administrator privileges
**************************************************
The following Anti-Malware program(s) are loaded:
Nortons Anti-Virus
**************************************************
**************************************************
17:13:35: Scanning ----------WIN.INI-----------
WIN.INI found in C:\WINDOWS
**************************************************
17:13:36: Scanning --------SYSTEM.INI---------
SYSTEM.INI found in C:\WINDOWS
**************************************************
17:13:36: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
**************************************************
17:13:47: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1037312 bytes
Created: 16/08/2004
Modified: 13/06/2007
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
25088 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
515584 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Value Name: load
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: IMJPMIG8.1
Value Data: "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
208952 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
--------------------
Value Name: PHIME2002ASync
Value Data: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
455168 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
--------------------
Value Name: PHIME2002A
Value Data: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
455168 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
--------------------
Value Name: VTTimer
Value Data: VTTimer.exe
C:\WINDOWS\system32\VTTimer.exe
53248 bytes
Created: 26/05/2006
Modified: 08/03/2005
Company: S3 Graphics, Inc.
--------------------
Value Name: VTTrayp
Value Data: VTtrayp.exe
C:\WINDOWS\system32\VTtrayp.exe
163840 bytes
Created: 26/05/2006
Modified: 01/11/2005
Company: S3 Graphics Co., Ltd.
--------------------
Value Name: SoundMan
Value Data: SOUNDMAN.EXE
C:\WINDOWS\SOUNDMAN.EXE
77824 bytes
Created: 26/05/2006
Modified: 20/01/2005
Company: Realtek Semiconductor Corp.
--------------------
Value Name: SunJavaUpdateSched
Value Data: C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
36975 bytes
Created: 26/05/2006
Modified: 03/06/2005
Company: Sun Microsystems, Inc.
--------------------
Value Name: Vade Retro Outlook Express
Value Data: "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
310272 bytes
Created: 26/05/2006
Modified: 04/10/2004
Company:
--------------------
Value Name: ccApp
Value Data: "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
53096 bytes
Created: 17/09/2005
Modified: 07/03/2008
Company: Symantec Corporation
--------------------
Value Name: PCMService
Value Data: "c:\APPS\Powercinema\PCMService.exe"
c:\APPS\Powercinema\PCMService.exe
147456 bytes
Created: 26/05/2006
Modified: 23/02/2006
Company: CyberLink Corp.
--------------------
Value Name: NvCplDaemon
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
C:\WINDOWS\system32\NvCpl.dll
7700480 bytes
Created: 22/10/2006
Modified: 22/10/2006
Company: NVIDIA Corporation
--------------------
Value Name: nwiz
Value Data: nwiz.exe /install
C:\WINDOWS\system32\nwiz.exe
1622016 bytes
Created: 22/10/2006
Modified: 22/10/2006
Company:
--------------------
Value Name: NvMediaCenter
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
C:\WINDOWS\system32\NvMcTray.dll
86016 bytes
Created: 22/10/2006
Modified: 22/10/2006
Company: NVIDIA Corporation
--------------------
Value Name: SystrayORAHSS
Value Data: "C:\Program Files\Orange\Systray\SystrayApp.exe"
C:\Program Files\Orange\Systray\SystrayApp.exe
94208 bytes
Created: 06/05/2008
Modified: 25/09/2007
Company: France Telecom SA
--------------------
Value Name: ORAHSSSessionManager
Value Data: C:\Program Files\Orange\SessionManager\SessionManager.exe
C:\Program Files\Orange\SessionManager\SessionManager.exe
102400 bytes
Created: 06/05/2008
Modified: 25/09/2007
Company: France Telecom SA
--------------------
Value Name: au
Value Data: C:\Program Files\Dealio\DealioAU.exe
C:\Program Files\Dealio\DealioAU.exe
591200 bytes
Created: 16/04/2008
Modified: 16/04/2008
Company: Vendio Services, Inc.
--------------------
Value Name: SearchSettings
Value Data: C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Search Settings\SearchSettings.exe
985440 bytes
Created: 16/04/2008
Modified: 16/04/2008
Company: Vendio Services, Inc.
--------------------
Value Name: BitDefender Antiphishing Helper
Value Data: "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe
61440 bytes
Created: 09/10/2007
Modified: 09/10/2007
Company: BitDefender
--------------------
Value Name: BDAgent
Value Data: "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
360448 bytes
Created: 16/02/2008
Modified: 16/02/2008
Company: BitDefender S.R.L.
--------------------
Value Name: BM87df9fc1
Value Data: Rundll32.exe "C:\WINDOWS\system32\yheuayxx.dll",s
C:\WINDOWS\system32\yheuayxx.dll [file not found to scan]
--------------------
Value Name: QuickTime Task
Value Data: "C:\Program Files\QuickTime\qttask.exe" -atboottime
C:\Program Files\QuickTime\qttask.exe
98304 bytes
Created: 26/05/2006
Modified: 26/05/2006
Company: Apple Computer, Inc.
--------------------
Value Name: TrojanScanner
Value Data: C:\Program Files\Trojan Remover\Trjscan.exe
C:\Program Files\Trojan Remover\Trjscan.exe
877136 bytes
Created: 25/05/2008
Modified: 21/05/2008
Company: Simply Super Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: SmpcSys
Value Data: C:\APPS\SMP\SmpSys.exe
C:\APPS\SMP\SmpSys.exe
975360 bytes
Created: 17/11/2005
Modified: 17/11/2005
Company: Packard Bell BV
--------------------
Value Name: ctfmon.exe
Value Data: C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
15360 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
--------------------
Value Name: updateMgr
Value Data: C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
313472 bytes
Created: 30/03/2006
Modified: 30/03/2006
Company: Adobe Systems Incorporated
--------------------
Value Name: MsnMsgr
Value Data: "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
5724184 bytes
Created: 18/10/2007
Modified: 18/10/2007
Company: Microsoft Corporation
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
**************************************************
17:13:49: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------
**************************************************
17:13:49: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
**************************************************
17:14:10: Scanning -----ACTIVE SCREENSAVER-----
ScreenSaver: C:\WINDOWS\system32\logon.scr
C:\WINDOWS\system32\logon.scr
221696 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
--------------------
**************************************************
17:14:10: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
**************************************************
17:14:15: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: AppMgmt
%SystemRoot%\System32\appmgmts.dll - file is globally excluded (file cannot be found)
--------------------
Key: scan
Path: C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\scan.dll
C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\scan.dll
135168 bytes
Created: 14/02/2008
Modified: 14/02/2008
Company: S.C. BitDefender S.R.L
--------------------
**************************************************
17:14:16: Scanning ----- SERVICES REGISTRY KEYS -----
Key: abp480n5
ImagePath: system32\DRIVERS\ABP480N5.SYS
C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
23552 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: adpu160m
ImagePath: system32\DRIVERS\adpu160m.sys
C:\WINDOWS\system32\DRIVERS\adpu160m.sys
101888 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: agpCPQ
ImagePath: system32\DRIVERS\agpCPQ.sys
C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
44928 bytes
Created: 16/08/2004
Modified: 03/08/2004
Company: Microsoft Corporation
----------
Key: Aha154x
ImagePath: system32\DRIVERS\aha154x.sys
C:\WINDOWS\system32\DRIVERS\aha154x.sys
12800 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: aic78u2
ImagePath: system32\DRIVERS\aic78u2.sys
C:\WINDOWS\system32\DRIVERS\aic78u2.sys
55168 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: aic78xx
ImagePath: system32\DRIVERS\aic78xx.sys
C:\WINDOWS\system32\DRIVERS\aic78xx.sys
56960 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: alim1541
ImagePath: system32\DRIVERS\alim1541.sys
C:\WINDOWS\system32\DRIVERS\alim1541.sys
42752 bytes
Created: 16/08/2004
Modified: 03/08/2004
Company: Microsoft Corporation
----------
Key: amdagp
ImagePath: system32\DRIVERS\amdagp.sys
C:\WINDOWS\system32\DRIVERS\amdagp.sys
43008 bytes
Created: 16/08/2004
Modified: 03/08/2004
Company: Advanced Micro Devices, Inc.
----------
Key: amsint
ImagePath: system32\DRIVERS\amsint.sys
C:\WINDOWS\system32\DRIVERS\amsint.sys
12032 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: AOL ACS
ImagePath: C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
1135728 bytes
Created: 26/05/2006
Modified: 08/04/2004
Company: America Online, Inc.
----------
Key: asc
ImagePath: system32\DRIVERS\asc.sys
C:\WINDOWS\system32\DRIVERS\asc.sys
26496 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Advanced System Products, Inc.
----------
Key: asc3350p
ImagePath: system32\DRIVERS\asc3350p.sys
C:\WINDOWS\system32\DRIVERS\asc3350p.sys
22400 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: asc3550
ImagePath: system32\DRIVERS\asc3550.sys
C:\WINDOWS\system32\DRIVERS\asc3550.sys
14848 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Advanced System Products, Inc.
----------
Key: aspnet_state
ImagePath: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
32768 bytes
Created: 15/07/2004
Modified: 15/07/2004
Company: Microsoft Corporation
----------
Key: Bdfndisf
ImagePath: system32\DRIVERS\bdfndisf.sys
C:\WINDOWS\system32\DRIVERS\bdfndisf.sys
85520 bytes
Created: 25/01/2008
Modified: 25/01/2008
Company: BitDefender SRL
----------
Key: bdfsfltr
ImagePath: s y s t e m 3 2 \ D R I V E R S \ b d f s f l t r . s y s
C:\WINDOWS\system32\DRIVERS\bdfndisf.sys
85520 bytes
Created: 25/01/2008
Modified: 25/01/2008
Company: BitDefender SRL
----------
Key: bdftdif
ImagePath: \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys
C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys
156688 bytes
Created: 25/01/2008
Modified: 25/01/2008
Company: BitDefender SRL
----------
Key: BDSelfPr
ImagePath: \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys
C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys
8320 bytes
Created: 16/01/2008
Modified: 16/01/2008
Company: BitDefender S.R.L.
----------
Key: cbidf
ImagePath: system32\DRIVERS\cbidf2k.sys
C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
13952 bytes
Created: 17/08/2001
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: ccEvtMgr
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe"
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
191848 bytes
Created: 17/09/2005
Modified: 07/03/2008
Company: Symantec Corporation
----------
Key: ccISPwdSvc
ImagePath: "C:\Program Files\Norton Internet Security\ccPwdSvc.exe"
C:\Program Files\Norton Internet Security\ccPwdSvc.exe
72328 bytes
Created: 14/10/2005
Modified: 20/02/2007
Company: Symantec Corporation
----------
Key: ccProxy
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe"
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
202088 bytes
Created: 17/09/2005
Modified: 13/09/2007
Company: Symantec Corporation
----------
Key: ccSetMgr
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe"
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
169320 bytes
Created: 17/09/2005
Modified: 07/03/2008
Company: Symantec Corporation
----------
Key: cd20xrnt
ImagePath: system32\DRIVERS\cd20xrnt.sys
C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
7680 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: CLCapSvc
ImagePath: "c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe"
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
266338 bytes
Created: 26/05/2006
Modified: 23/02/2006
Company:
----------
Key: CLSched
ImagePath: "c:\APPS\Powercinema\Kernel\TV\CLSched.exe"
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
114784 bytes
Created: 26/05/2006
Modified: 23/02/2006
Company:
----------
Key: CmdIde
ImagePath: system32\DRIVERS\cmdide.sys
C:\WINDOWS\system32\DRIVERS\cmdide.sys
6656 bytes
Created: 16/08/2004
Modified: 23/08/2001
Company: CMD Technology, Inc.
----------
Key: comHost
ImagePath: "C:\Program Files\Norton Internet Security\comHost.exe"
C:\Program Files\Norton Internet Security\comHost.exe
45696 bytes
Created: 22/10/2005
Modified: 01/02/2007
Company: Symantec Corporation
----------
Key: Cpqarray
ImagePath: system32\DRIVERS\cpqarray.sys
C:\WINDOWS\system32\DRIVERS\cpqarray.sys
14976 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: CyberLink Media Library Service
ImagePath: "c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe"
c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
1073152 bytes
Created: 26/05/2006
Modified: 23/02/2006
Company: Cyberlink
----------
Key: dac2w2k
ImagePath: system32\DRIVERS\dac2w2k.sys
C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
179584 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Mylex Corporation
----------
Key: dac960nt
ImagePath: system32\DRIVERS\dac960nt.sys
C:\WINDOWS\system32\DRIVERS\dac960nt.sys
14720 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: dpti2o
ImagePath: system32\DRIVERS\dpti2o.sys
C:\WINDOWS\system32\DRIVERS\dpti2o.sys
20192 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: eeCtrl
ImagePath: \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys
C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys
385072 bytes
Created: 06/05/2008
Modified: 17/04/2008
Company: Symantec Corporation
----------
Key: EraserUtilRebootDrv
ImagePath: \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
109616 bytes
Created: 06/05/2008
Modified: 17/04/2008
Company: Symantec Corporation
----------
Key: FTRTSVC
ImagePath: "C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe"
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
65536 bytes
Created: 06/05/2008
Modified: 25/09/2007
Company: France Telecom SA
----------
Key: gagp30kx
ImagePath: system32\DRIVERS\gagp30kx.sys
C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
46464 bytes
Created: 26/05/2006
Modified: 03/08/2004
Company: Microsoft Corporation
----------
Key: GenericHidService
ImagePath: c:\APPS\HIDSERVICE\HIDSERVICE.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
49152 bytes
Created: 26/05/2006
Modified: 07/01/2005
Company:
----------
Key: hpn
ImagePath: system32\DRIVERS\hpn.sys
C:\WINDOWS\system32\DRIVERS\hpn.sys
25952 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: i2omp
ImagePath: system32\DRIVERS\i2omp.sys
C:\WINDOWS\system32\DRIVERS\i2omp.sys
18560 bytes
Created: 16/08/2004
Modified: 03/08/2004
Company: Microsoft Corporation
----------
Key: ini910u
ImagePath: system32\DRIVERS\ini910u.sys
C:\WINDOWS\system32\DRIVERS\ini910u.sys
16000 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: LIVESRV
ImagePath: "C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe" /service
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
1130496 bytes
Created: 08/02/2008
Modified: 08/02/2008
Company: BitDefender SRL
----------
Key: LiveUpdate
ImagePath: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
2119360 bytes
Created: 06/05/2008
Modified: 03/08/2006
Company: Symantec Corporation
----------
Key: mraid35x
ImagePath: system32\DRIVERS\mraid35x.sys
C:\WINDOWS\system32\DRIVERS\mraid35x.sys
17280 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: American Megatrends Inc.
----------
Key: navapsvc
ImagePath: "C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
139888 bytes
Created: 07/10/2005
Modified: 28/05/2007
Company: Symantec Corporation
----------
Key: NAVENG
ImagePath: \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20080522.003\NAVENG.Sys
C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20080522.003\NAVENG.Sys
82256 bytes
Created: 22/05/2008
Modified: 17/04/2008
Company: Symantec Corporation
----------
Key: NAVEX15
ImagePath: \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20080522.003\NavEx15.Sys
C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20080522.003\NavEx15.Sys
895408 bytes
Created: 22/05/2008
Modified: 17/04/2008
Company: Symantec Corporation
----------
Key: NSCService
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE"
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
750720 bytes
Created: 24/09/2005
Modified: 15/12/2006
Company: Symantec Corporation
----------
Key: ose
ImagePath: "C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE"
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
89136 bytes
Created: 28/07/2003
Modified: 28/07/2003
Company: Microsoft Corporation
----------
Key: PCAMPR5
ImagePath: \??\C:\WINDOWS\system32\PCAMPR5.SYS
C:\WINDOWS\system32\PCAMPR5.SYS
34688 bytes
Created: 06/05/2008
Modified: 23/09/2003
Company: Printing Communications Assoc., Inc. (PCAUSA)
----------
Key: PCANDIS5
ImagePath: \??\C:\WINDOWS\system32\PCANDIS5.SYS
C:\WINDOWS\system32\PCANDIS5.SYS
32128 bytes
Created: 06/05/2008
Modified: 01/03/2006
Company: Printing Communications Assoc., Inc. (PCAUSA)
----------
Key: perc2
ImagePath: system32\DRIVERS\perc2.sys
C:\WINDOWS\system32\DRIVERS\perc2.sys
27296 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: perc2hib
ImagePath: system32\DRIVERS\perc2hib.sys
C:\WINDOWS\system32\DRIVERS\perc2hib.sys
5504 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: Planificateur LiveUpdate automatique
ImagePath: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
100032 bytes
Created: 06/05/2008
Modified: 03/08/2006
Company: Symantec Corporation
----------
Key: Profos
ImagePath: \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys
C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys
12800 bytes
Created: 12/07/2007
Modified: 12/07/2007
Company:
----------
Key: ql1080
ImagePath: system32\DRIVERS\ql1080.sys
C:\WINDOWS\system32\DRIVERS\ql1080.sys
40320 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: QLogic Corporation
----------
Key: Ql10wnt
ImagePath: system32\DRIVERS\ql10wnt.sys
C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
33152 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: ql12160
ImagePath: system32\DRIVERS\ql12160.sys
C:\WINDOWS\system32\DRIVERS\ql12160.sys
45312 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: QLogic Corporation
----------
Key: ql1240
ImagePath: system32\DRIVERS\ql1240.sys
C:\WINDOWS\system32\DRIVERS\ql1240.sys
40448 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: ql1280
ImagePath: system32\DRIVERS\ql1280.sys
C:\WINDOWS\system32\DRIVERS\ql1280.sys
49024 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: QLogic Corporation
----------
Key: RTL8023xp
ImagePath: system32\DRIVERS\Rtlnicxp.sys
C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
70912 bytes
Created: 02/12/2004
Modified: 02/12/2004
Company: Realtek Semiconductor Corporation
----------
Key: SAVRT
ImagePath: \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS
334984 bytes
Created: 26/08/2005
Modified: 26/08/2005
Company: Symantec Corporation
----------
Key: SAVRTPEL
ImagePath: \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS
53896 bytes
Created: 26/08/2005
Modified: 26/08/2005
Company: Symantec Corporation
----------
Key: SAVScan
ImagePath: "C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe"
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
198368 bytes
Created: 26/08/2005
Modified: 26/08/2005
Company: Symantec Corporation
----------
Key: SNDSrvc
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe"
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
214408 bytes
Created: 01/10/2007
Modified: 01/10/2007
Company: Symantec Corporation
----------
Key: Sparrow
ImagePath: system32\DRIVERS\sparrow.sys
C:\WINDOWS\system32\DRIVERS\sparrow.sys
19072 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Adaptec, Inc.
----------
Key: SPBBCDrv
ImagePath: \??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys
389728 bytes
Created: 15/09/2005
Modified: 15/09/2005
Company: Symantec Corporation
----------
Key: SPBBCSvc
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe"
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
1160800 bytes
Created: 15/09/2005
Modified: 15/09/2005
Company: Symantec Corporation
----------
Key: SwPrv
ImagePath: C:\WINDOWS\system32\dllhost.exe /Processid:{4F20079B-9003-46EB-AFC3-0037ECFBBC7A}
C:\WINDOWS\system32\dllhost.exe
5120 bytes
Created: 16/08/2004
Modified: 05/08/2004
Company: Microsoft Corporation
----------
Key: Symantec Core LC
ImagePath: "C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe"
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
1251720 bytes
Created: 26/05/2006
Modified: 06/05/2008
Company:
----------
Key: symc810
ImagePath: system32\DRIVERS\symc810.sys
C:\WINDOWS\system32\DRIVERS\symc810.sys
16256 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Symbios Logic Inc.
----------
Key: symc8xx
ImagePath: system32\DRIVERS\symc8xx.sys
C:\WINDOWS\system32\DRIVERS\symc8xx.sys
32640 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: LSI Logic
----------
Key: SYMDNS
ImagePath: \SystemRoot\System32\Drivers\SYMDNS.SYS
C:\WINDOWS\System32\Drivers\SYMDNS.SYS
12680 bytes
Created: 01/10/2007
Modified: 01/10/2007
Company: Symantec Corporation
----------
Key: SymEvent
ImagePath: \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
123952 bytes
Created: 26/05/2006
Modified: 06/05/2008
Company: Symantec Corporation
----------
Key: SYMFW
ImagePath: \SystemRoot\System32\Drivers\SYMFW.SYS
C:\WINDOWS\System32\Drivers\SYMFW.SYS
98184 bytes
Created: 01/10/2007
Modified: 01/10/2007
Company: Symantec Corporation
----------
Key: SYMIDS
ImagePath: \SystemRoot\System32\Drivers\SYMIDS.SYS
C:\WINDOWS\System32\Drivers\SYMIDS.SYS
31624 bytes
Created: 01/10/2007
Modified: 01/10/2007
Company: Symantec Corporation
----------
Key: SYMIDSCO
ImagePath: \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20080521.001\symidsco.sys
C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20080521.001\symidsco.sys
240496 bytes
Created: 22/05/2008
Modified: 04/04/2008
Company: Symantec Corporation
----------
Key: symlcbrd
ImagePath: \??\C:\WINDOWS\system32\drivers\symlcbrd.sys
C:\WINDOWS\system32\drivers\symlcbrd.sys
10344 bytes
Created: 26/05/2006
Modified: 26/05/2006
Company: Symantec Corporation
----------
Key: SYMNDIS
ImagePath: \SystemRoot\System32\Drivers\SYMNDIS.SYS
C:\WINDOWS\System32\Drivers\SYMNDIS.SYS
28040 bytes
Created: 01/10/2007
Modified: 01/10/2007
Company: Symantec Corporation
----------
Key: SYMREDRV
ImagePath: \SystemRoot\System32\Drivers\SYMREDRV.SYS
C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
23944 bytes
Created: 01/10/2007
Modified: 01/10/2007
Company: Symantec Corporation
----------
Key: SYMTDI
ImagePath: \SystemRoot\System32\Drivers\SYMTDI.SYS
C:\WINDOWS\System32\Drivers\SYMTDI.SYS
189320 bytes
Created: 01/10/2007
Modified: 01/10/2007
Company: Symantec Corporation
----------
Key: sym_hi
ImagePath: system32\DRIVERS\sym_hi.sys
C:\WINDOWS\system32\DRIVERS\sym_hi.sys
28384 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: LSI Logic
----------
Key: sym_u3
ImagePath: system32\DRIVERS\sym_u3.sys
C:\WINDOWS\system32\DRIVERS\sym_u3.sys
30688 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: LSI Logic
----------
Key: TosIde
ImagePath: system32\DRIVERS\toside.sys
C:\WINDOWS\system32\DRIVERS\toside.sys
4992 bytes
Created: 16/08/2004
Modified: 23/08/2001
Company: Microsoft Corporation
----------
Key: Trufos
ImagePath: \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys
C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys
36736 bytes
Created: 10/07/2007
Modified: 10/07/2007
Company:
----------
Key: ultra
ImagePath: system32\DRIVERS\ultra.sys
C:\WINDOWS\system32\DRIVERS\ultra.sys
36736 bytes
Created: 16/08/2004
Modified: 17/08/2001
Company: Promise Technology, Inc.
----------
Key: usnjsvc
ImagePath: "C:\Program Files\Windows Live\Messenger\usnsvc.exe"
C:\Program Files\Windows Live\Messenger\usnsvc.exe
98328 bytes
Created: 18/10/2007
Modified: 18/10/2007
Company: Microsoft Corporation
----------
Key: Via4in1
ImagePath: \??\C:\Via4in1.sys
C:\Via4in1.sys [file not found to scan]
----------
Key: viaagp
ImagePath: system32\DRIVERS\viaagp.sys
C:\WINDOWS\system32\DRIVERS\viaagp.sys
42240 bytes
Created: 16/08/2004
Modified: 03/08/2004
Company: Microsoft Corporation
----------
Key: viaagp1
ImagePath: system32\DRIVERS\viaagp1.sys
C:\WINDOWS\system32\DRIVERS\viaagp1.sys
27904 bytes
Created: 26/05/2006
Modified: 02/07/2003
Company: VIA Technologies, Inc.
----------
Key: VSSERV
ImagePath: "C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
1216512 bytes
Created: 25/02/2008
Modified: 25/02/2008
Company: BitDefender S.R.L.
----------
Key: WLSetupSvc
ImagePath: "C:\Program Files\Windows Live\installer\WLSetupSvc.exe"
C:\Program Files\Windows Live\installer\WLSetupSvc.exe
266240 bytes
Created: 25/10/2007
Modified: 25/10/2007
Company: Microsoft Corporation
----------
Key: XCOMM
ImagePath: "C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe" /service
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
86016 bytes
Created: 27/11/2007
Modified: 27/11/2007
Company: BitDefender
----------
**************************************************
17:14:37: Scanning -----VXD ENTRIES-----
**************************************************
17:14:37: Scanning ----- WINLOGON\NOTIFY DLLS -----
**************************************************
17:14:37: Scanning ----- CONTEXTMENUHANDLERS -----
Key: Symantec.Norton.Antivirus.IEContextMenu
CLSID: {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}
Path: C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
140912 bytes
Created: 11/10/2005
Modified: 07/06/2007
Company: Symantec Corporation
----------
Key: {D653647D-D607-4df6-A5B8-48D2BA195F7B}
Path: C:\Program Files\BitDefender\BitDefender 2008\bdshelxt.dll
C:\Program Files\BitDefender\BitDefender 2008\bdshelxt.dll
155648 bytes
Created: 14/12/2007
Modified: 14/12/2007
Company: BitDefender S.R.L
----------
**************************************************
17:14:37: Scanning ----- FOLDER\COLUMNHANDLERS -----
**************************************************
17:14:37: Scanning ----- BROWSER HELPER OBJECTS -----
Key: {1FFF1119-E11A-42D4-8669-E6D9CD383AC7}
BHO: C:\WINDOWS\system32\pmnkHApM.dll
C:\WINDOWS\system32\pmnkHApM.dll [file not found to scan]
----------
Key: {6A87B991-A31F-4130-AE72-6D0C294BF082}
BHO: C:\Program Files\Dealio\kb127\Dealio.dll
C:\Program Files\Dealio\kb127\Dealio.dll
3167584 bytes
Created: 16/04/2008
Modified: 16/04/2008
Company: Vendio Services, Inc.
----------
Key: {9030D464-4C02-4ABF-8ECC-5164760863C6}
BHO: C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
328752 bytes
Created: 20/09/2007
Modified: 20/09/2007
Company: Microsoft Corporation
----------
Key: {9ECB9560-04F9-4bbc-943D-298DDF1699E1}
BHO: C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
94336 bytes
Created: 22/10/2005
Modified: 22/10/2005
Company: Symantec Corporation
----------
Key: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD}
BHO: C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
140912 bytes
Created: 11/10/2005
Modified: 07/06/2007
Company: Symantec Corporation
----------
**************************************************
17:14:53: Scanning ----- SHELLSERVICEOBJECTS -----
Key: WPDShServiceObj
CLSID: {AAA288BA-9A4C-45B0-95D7-94D524869DB5}
Path: C:\WINDOWS\system32\WPDShServiceObj.dll
C:\WINDOWS\system32\WPDShServiceObj.dll
133632 bytes
Created: 18/10/2006
Modified: 18/10/2006
Company: Microsoft Corporation
----------
**************************************************
17:15:01: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
**************************************************
17:15:02: Scanning ----- IMAGEFILE DEBUGGERS -----
No "Debugger" entries found.
**************************************************
17:15:02: Scanning ----- APPINIT_DLLS -----
The AppInit_DLLs value is blank
**************************************************
17:15:05: Scanning ----- SECURITY PROVIDER DLLS -----
**************************************************
17:15:12: Scanning ------ COMMON STARTUP GROUP ------
[D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]
The Common Startup Group attempts to load the following file(s) at boot time:
D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
-HS- 84 bytes
Created: 11/07/2006
Modified: 17/08/2004
Company:
--------------------
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
29696 bytes
Created: 23/04/2008
Modified: 23/04/2008
Company: Adobe Systems Incorporated
Lancement rapide d'Adobe Reader.lnk - links to C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
--------------------
**************************************************
No User Startup Groups were located to check
**************************************************
17:15:12: Scanning ----- SCHEDULED TASKS -----
Taskname: Configurer mon PC.job
File: C:\Apps\SMP\PCSETUP.EXE
C:\Apps\SMP\PCSETUP.EXE
1422848 bytes
Created: 17/11/2005
Modified: 17/11/2005
Company: Packard Bell BV
Parameters: /REM
Next Run Time: 25/05/2008 17:30:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: math
Comments: [blank]
----------
Taskname: Extension de garantie.job
File: C:\APPS\SMP\PBCARNOT.EXE
C:\APPS\SMP\PBCARNOT.EXE
421888 bytes
Created: 09/11/2005
Modified: 09/11/2005
Company: Packard Bell BV
Parameters: [blank]
Next Run Time: 25/05/2008 17:30:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: huby
Comments: [blank]
----------
Taskname: Master CD_DVD Creator.job
File: C:\Apps\SMP\MCDCHECK.EXE
C:\Apps\SMP\MCDCHECK.EXE
422912 bytes
Created: 08/11/2005
Modified: 08/11/2005
Company: Packard Bell BV
Parameters: [blank]
Next Run Time: 25/05/2008 17:30:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: huby
Comments: [blank]
----------
Taskname: Norton AntiVirus - Effectuer une analyse complète du système - huby.job
File: C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
173680 bytes
Created: 07/10/2005
Modified: 28/05/2007
Company: Symantec Corporation
Parameters: /TASK:"D:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"
Next Run Time: 30/05/2008 20:00:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: huby
Comments: Il s'agit d'une tâche de programmation d'analyse de Norton AntiVirus.
----------
**************************************************
17:15:13: ----- ADDITIONAL CHECKS -----
PE386 rootkit checks completed
----------
Winlogon registry rootkit checks completed
----------
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
----------
==============================
Restrictive Windows Explorer Policies found in force on this computer:
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Value: SHOWALL\"CheckedValue"
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Value: ForceActiveDesktopOn
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
Value: NoEditingComponents
All Policy Values listed have been removed
==============================
Windows Explorer Policies checks completed
----------
Desktop Wallpaper: D:\Documents and Settings\huby\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
D:\Documents and Settings\huby\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
14745654 bytes
Created: 06/05/2008
Modified: 10/05/2008
Company:
----------
Web Desktop Wallpaper: %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
D:\Documents and Settings\huby\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
14745654 bytes
Created: 06/05/2008
Modified: 10/05/2008
Company:
----------
Checking autorun.inf in D:\
D:\autorun.inf open entry: [pa39xth.cmd]
----------
--------------------
Additional file checks completed
**************************************************
17:16:11: Scanning ----- RUNNING PROCESSES -----
C:\WINDOWS\System32\smss.exe
--------------------
C:\WINDOWS\system32\csrss.exe
--------------------
C:\WINDOWS\system32\winlogon.exe
--------------------
C:\WINDOWS\system32\services.exe
--------------------
C:\WINDOWS\system32\lsass.exe
--------------------
C:\WINDOWS\system32\svchost.exe
--------------------
C:\WINDOWS\system32\svchost.exe
--------------------
C:\WINDOWS\System32\svchost.exe
--------------------
C:\WINDOWS\system32\svchost.exe
--------------------
C:\WINDOWS\system32\svchost.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
--------------------
C:\WINDOWS\system32\spoolsv.exe
--------------------
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
--------------------
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
--------------------
c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
--------------------
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
--------------------
c:\APPS\HIDSERVICE\HIDSERVICE.exe
--------------------
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
--------------------
C:\WINDOWS\system32\nvsvc32.exe
--------------------
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
--------------------
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
--------------------
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
--------------------
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
--------------------
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
--------------------
C:\WINDOWS\System32\svchost.exe
--------------------
C:\WINDOWS\System32\alg.exe
--------------------
C:\WINDOWS\Explorer.EXE
--------------------
C:\WINDOWS\system32\ctfmon.exe
--------------------
C:\WINDOWS\system32\VTTimer.exe
--------------------
C:\WINDOWS\SOUNDMAN.EXE
--------------------
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
--------------------
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
--------------------
C:\APPS\Powercinema\PCMService.exe
--------------------
C:\WINDOWS\system32\RUNDLL32.EXE
--------------------
C:\Program Files\Orange\Systray\SystrayApp.exe
--------------------
C:\Program Files\Search Settings\SearchSettings.exe
--------------------
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
--------------------
C:\Program Files\QuickTime\qttask.exe
--------------------
C:\Program Files\Orange\Launcher\Launcher.exe
--------------------
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
--------------------
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
--------------------
C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
--------------------
C:\Program Files\Orange\connectivity\connectivitymanager.exe
--------------------
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
--------------------
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
--------------------
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
--------------------
C:\WINDOWS\system32\wbem\wmiprvse.exe
--------------------
D:\Documents and Settings\huby\Local Settings\Temporary Internet Files\Content.IE5\7YMRR6V3\VundoFix[1].exe
--------------------
D:\Documents and Settings\huby\Application Data\Simply Super Software\Trojan Remover\jpb3A0D.exe
FileSize: 2482752
[This is a Trojan Remover component]
--------------------
--------------------
**************************************************
17:16:31: Checking AUTOEXEC.NT file
AUTOEXEC.NT found in C:\WINDOWS\system32
No malicious entries were found in the AUTOEXEC.NT file
**************************************************
17:16:41: Checking HOSTS file
No malicious entries were found in the HOSTS file
**************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Local Page":
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\"CustomizeSearch":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\"SearchAssistant":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://www.google.fr/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
**************************************************
=== CHANGES WERE MADE TO THE WINDOWS REGISTRY ===
Scan completed at: 17:16:41 25 mai 2008
************************************************************