merci a toi jlpjlp
voila le rappport combofix
ComboFix 08-03-30.3 - MIKI 2008-03-31 14:55:35.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.666 [GMT 2:00]
Endroit: C:\Documents and Settings\MIKI\Bureau\Combo__Fix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
TimedOut: progfile.dat
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\seekmo
C:\Program Files\seekmo\seekmohook.dll
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\default.htm
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\lsprst7.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\ssprs.dll
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\TEMP\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-28 to 2008-03-31 ))))))))))))))))))))))))))))))))))))
.
2008-03-31 04:53 . 2008-03-31 04:53 <REP> d-------- C:\Program Files\zango
2008-03-31 04:53 . 2008-03-31 04:53 <REP> d-------- C:\Program Files\Sysmnt
2008-03-31 04:53 . 2008-03-31 04:53 <REP> d-------- C:\Program Files\stc
2008-03-31 04:53 . 2008-03-31 04:53 <REP> d-------- C:\Program Files\180solutions
2008-03-31 04:53 . 2008-03-31 04:53 <REP> d-------- C:\Program Files\180searchassistant
2008-03-31 04:53 . 2008-03-31 04:53 <REP> d-------- C:\Program Files\180search assistant
2008-03-31 04:26 . 2008-03-31 04:26 <REP> d-------- C:\Program Files\Lavasoft
2008-03-31 04:26 . 2008-03-31 04:26 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Lavasoft
2008-03-31 03:44 . 2008-03-31 03:44 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Talkback
2008-03-31 03:38 . 2008-03-31 03:38 15,872 --a------ C:\WINDOWS\123messenger.per
2008-03-31 01:34 . 2008-03-31 01:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-03-31 01:01 . 2008-03-31 01:01 <REP> d--h----- C:\WINDOWS\PIF
2008-03-31 00:13 . 2008-03-31 02:14 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-31 00:13 . 2008-03-31 00:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-03-31 00:13 . 2008-03-31 00:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-03-31 00:13 . 2008-03-31 00:13 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-03-31 00:13 . 2008-03-31 05:05 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-03-31 00:13 . 2008-03-31 00:13 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\InstallShield
2008-03-31 00:13 . 2008-03-31 00:13 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\ATI
2008-03-30 22:12 . 2008-03-31 00:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-03-30 22:12 . 2008-03-31 03:44 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-03-30 22:12 . 2008-03-31 00:13 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-03-30 22:12 . 2007-07-25 04:18 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Roxio
2008-03-30 22:12 . 2008-03-30 22:12 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-03-30 22:12 . 2007-07-25 04:14 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\GTek
2008-03-30 20:59 . 2008-03-30 20:59 <REP> d-------- C:\Documents and Settings\MIKI\Application Data\Malwarebytes
2008-03-30 19:26 . 2008-03-30 19:42 <REP> d-------- C:\Documents and Settings\MIKI\Application Data\AVGTOOLBAR
2008-03-30 19:22 . 2008-03-30 19:22 90,537 --a------ C:\WINDOWS\system32\sbwltbxa.exe
2008-03-15 19:32 . 2008-03-15 19:32 <REP> d-------- C:\Documents and Settings\MIKI\Images
2008-03-15 19:32 . 2008-03-15 19:32 <REP> d-------- C:\Documents and Settings\MIKI\Audio
2008-03-12 20:15 . 2004-08-04 01:54 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-03-12 20:15 . 2004-08-03 23:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-12 20:15 . 2004-08-03 23:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2008-03-12 20:15 . 2001-08-23 18:47 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 02:26 --------- d-----w C:\Documents and Settings\MIKI\Application Data\Lavasoft
2008-03-31 02:14 --------- d-----w C:\Documents and Settings\MIKI\Application Data\Azureus
2008-03-03 20:13 --------- d-----w C:\Program Files\GameSpy Arcade
2008-03-03 20:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-03 20:10 --------- d-----w C:\Program Files\Universalis 8
2008-03-03 20:10 --------- d-----w C:\Program Files\Spamihilator
2008-02-25 14:33 --------- d-----w C:\Program Files\M-Audio
2008-01-11 05:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-19 22:53 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-09 21:01 3,342 ----a-w C:\Documents and Settings\MIKI\Application Data\wklnhst.dat
2007-12-08 05:08 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:03 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:02 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:41 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-03-14 19:36 2,228,534 ----a-w C:\Documents and Settings\instal\audacity-win-1.2.6.exe
2006-03-02 02:12 2,917,130 ----a-w C:\Documents and Settings\instal\EasyCleaner2_0.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 13:09 460784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 20:02 68856]
"Spamihilator"="C:\Program Files\Spamihilator\spamihilator.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 11:20 282624 C:\WINDOWS\stsystra.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 14:00 174872]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 18:41 45056]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]
"RoxWatchTray"="C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 10:00 1116920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"DeltTray"="DeltTray.exe" [2004-08-26 22:43 56320 C:\WINDOWS\system32\delttray.exe]
"DigidesignMMERefresh"="C:\Program Files\Digidesign\Drivers\MMERefresh.exe" [2006-11-14 00:05 61440]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 16:55 267064]
"svchost.exe"="C:\WINDOWS\svchost.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-28 10:05:47 110592]
Assistant d'Acrobat.lnk - C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
LoopBe1 Monitor.lnk - C:\Program Files\nerds.de\LoopBe1\loopBeMon.exe [2005-04-20 19:10:22 225280]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\[u]0
/u]
Source= C:\Documents and Settings\MIKI\Bureau\mouvement T@nk\léa\origine.jpg
FriendlyName=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XIIc\\Win32\\RpcDataSrv.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XIIc\\RpcSandraSrv.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 21:38]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 11:35]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 C-Dilla;C-Dilla;C:\WINDOWS\system32\drivers\CDANT.SYS [2001-09-10 19:09]
S3 MA_CMIDI;M-Audio USB Driver;C:\WINDOWS\system32\drivers\ma_cmidi.sys []
S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys []
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2006-06-05 04:39]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-22 12:53:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-31 14:57:54
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-31 14:58:08
ComboFix-quarantined-files.txt 2008-03-31 12:58:06
Pre-Run: 239,182,405,632 octets libres
Post-Run: 239,170,994,176 octets libres
.
2008-02-13 12:48:11 --- E O F ---
et voila le rapport hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:59:07, on 31/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\sbwltbxa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\WINDOWS\system32\DeltTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Crystal Clear\RocketDock\RocketDock.exe
C:\Program Files\Crystal Clear\UberIcon\UberIcon Manager.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\nanana\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4070725
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4070725
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4070725
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sbwltbxa.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [svchost.exe] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Spamihilator] "C:\Program Files\Spamihilator\spamihilator.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: RocketDock.lnk = C:\Program Files\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: UberIcon.lnk = C:\Program Files\Crystal Clear\UberIcon\UberIcon Manager.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: LoopBe1 Monitor.lnk = C:\Program Files\nerds.de\LoopBe1\loopBeMon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
O24 - Desktop Component 0: (no name) - C:\Documents and Settings\MIKI\Bureau\mouvement T@nk\léa\origine.jpg
***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.6.8.2524. For information, email support@simplysup.com
[Unregistered version]
Scan started at: 6/04/2008 17:28:50
Using Database v6965
Operating System: Windows Vista [Windows Vista (Build 6000)]
Edition: Windows Vista (TM) Home Basic
File System: NTFS
User Account Control is Enabled.
Data directory: C:\Users\albuk\AppData\Roaming\Simply Super Software\Trojan Remover\
Logfile directory: C:\Users\albuk\Documents\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Program Files\Trojan Remover\
Running with Administrator privileges
**************************************************
The following Anti-Malware program(s) are loaded:
Microsoft Windows Defender
Avast! Antivirus
Nortons Anti-Virus
**************************************************
**************************************************
17:28:51: Scanning ----------WIN.INI-----------
WIN.INI found in C:\Windows
**************************************************
17:28:51: Scanning --------SYSTEM.INI---------
SYSTEM.INI found in C:\Windows
**************************************************
17:28:51: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
**************************************************
17:28:52: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
File: Explorer.exe
C:\Windows\Explorer.exe
2923520 bytes
Created: 11/03/2008
Modified: 11/03/2008
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
File: C:\Windows\system32\userinit.exe
C:\Windows\system32\userinit.exe
24576 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: Windows Defender
Value Data: %ProgramFiles%\Windows Defender\MSASCui.exe -hide
C:\Program Files\Windows Defender\MSASCui.exe
1006264 bytes
Created: 2/12/2007
Modified: 2/12/2007
Company: Microsoft Corporation
--------------------
Value Name: NvSvc
Value Data: RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
C:\Windows\system32\nvsvc.dll
86016 bytes
Created: 10/09/2007
Modified: 16/08/2007
Company: NVIDIA Corporation
--------------------
Value Name: NvCplDaemon
Value Data: RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
C:\Windows\system32\NvCpl.dll
8478720 bytes
Created: 10/09/2007
Modified: 16/08/2007
Company: NVIDIA Corporation
--------------------
Value Name: NvMediaCenter
Value Data: RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
C:\Windows\system32\NvMcTray.dll
81920 bytes
Created: 10/09/2007
Modified: 16/08/2007
Company: NVIDIA Corporation
--------------------
Value Name: CardReaderMonitor
Value Data: C:\Program Files\Realtek Semiconductor Corp.\Realtek Card Reader Monitor\CardReaderMonitor.exe
C:\Program Files\Realtek Semiconductor Corp.\Realtek Card Reader Monitor\CardReaderMonitor.exe
643072 bytes
Created: 1/12/2007
Modified: 25/07/2007
Company: Realtek Semiconductor Corp.
--------------------
Value Name: RoxWatchTray
Value Data: "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
232184 bytes
Created: 11/01/2007
Modified: 11/01/2007
Company: Sonic Solutions
--------------------
Value Name: Google Desktop Search
Value Data: "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
243200 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Google
--------------------
Value Name: ccApp
Value Data: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
115816 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
--------------------
Value Name: PCMService
Value Data: "c:\Program Files\Powercinema\PCMService.exe"
c:\Program Files\Powercinema\PCMService.exe
159744 bytes
Created: 1/12/2007
Modified: 14/02/2007
Company: CyberLink Corp.
--------------------
Value Name: Picasa Media Detector
Value Data: C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
366400 bytes
Created: 21/02/2007
Modified: 21/02/2007
Company: Google Inc.
--------------------
Value Name: toolbar_eula_launcher
Value Data: C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
28672 bytes
Created: 1/12/2007
Modified: 20/02/2007
Company:
--------------------
Value Name: SunJavaUpdateSched
Value Data: "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
144784 bytes
Created: 13/03/2008
Modified: 14/12/2007
Company: Sun Microsystems, Inc.
--------------------
Value Name: Symantec PIF AlertEng
Value Data: "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
583048 bytes
Created: 29/01/2008
Modified: 29/01/2008
Company: Symantec Corporation
--------------------
Value Name: fssui
Value Data: "C:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
C:\Program Files\Windows Live\Contrôle parental\fssui.exe
243240 bytes
Created: 17/12/2007
Modified: 17/12/2007
Company: Microsoft Corporation
--------------------
Value Name: TkBellExe
Value Data: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
185896 bytes
Created: 25/03/2008
Modified: 25/03/2008
Company: RealNetworks, Inc.
--------------------
Value Name: PC-Antispyware
Value Data: "C:\Program Files\PC-Antispyware\PC-Antispyware.exe" hide
C:\Program Files\PC-Antispyware\PC-Antispyware.exe [file not found to scan]
--------------------
Value Name: TrojanScanner
Value Data: C:\Program Files\Trojan Remover\Trjscan.exe
C:\Program Files\Trojan Remover\Trjscan.exe
873552 bytes
Created: 6/04/2008
Modified: 3/04/2008
Company: Simply Super Software
--------------------
Value Name: avast!
Value Data: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
79224 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: Sidebar
Value Data: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
C:\Program Files\Windows Sidebar\sidebar.exe
1232896 bytes
Created: 11/03/2008
Modified: 11/03/2008
Company: Microsoft Corporation
--------------------
Value Name: SmpcSys
Value Data: C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe [file not found to scan]
--------------------
Value Name: ISUSPM
Value Data: "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
222128 bytes
Created: 29/03/2007
Modified: 29/03/2007
Company: Macrovision Corporation
--------------------
Value Name: eqervsma
Value Data: C:\ProgramData\eqervsma\byzihcry.exe
C:\ProgramData\eqervsma\byzihcry.exe
94208 bytes
Created: 1/04/2008
Modified: 1/04/2008
Company:
--------------------
Value Name: hED30XIgp2
Value Data: C:\ProgramData\dgxihohm\bkjytonw.exe
C:\ProgramData\dgxihohm\bkjytonw.exe
32256 bytes
Created: 1/04/2008
Modified: 1/04/2008
Company:
--------------------
Value Name: msnmsgr
Value Data: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
5724184 bytes
Created: 18/10/2007
Modified: 18/10/2007
Company: Microsoft Corporation
--------------------
Value Name: lxiiomeh
Value Data: C:\ProgramData\lxiiomeh\qnmvynwf.exe
C:\ProgramData\lxiiomeh\qnmvynwf.exe
98304 bytes
Created: 6/04/2008
Modified: 6/04/2008
Company:
--------------------
Value Name: WMPNSCFG
Value Data: C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
201728 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
This Registry Key appears to be empty
**************************************************
17:28:56: Scanning -----SHELLEXECUTEHOOKS-----
ShellExecuteHooks key is empty
**************************************************
17:28:56: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
**************************************************
17:28:56: Scanning -----ACTIVE SCREENSAVER-----
No active ScreenSaver found to scan.
**************************************************
17:28:56: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
**************************************************
17:28:56: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: AppMgmt
%SystemRoot%\System32\appmgmts.dll - file is globally excluded (file cannot be found)
--------------------
**************************************************
17:29:00: Scanning ----- SERVICES REGISTRY KEYS -----
Key: adpu160m
ImagePath: \SystemRoot\system32\drivers\adpu160m.sys
C:\Windows\system32\drivers\adpu160m.sys
98408 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Adaptec, Inc.
----------
Key: agp440
ImagePath: \SystemRoot\system32\drivers\agp440.sys
C:\Windows\system32\drivers\agp440.sys
53864 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: AmdK8
ImagePath: system32\DRIVERS\amdk8.sys
C:\Windows\system32\DRIVERS\amdk8.sys
40960 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: aswFsBlk
ImagePath: system32\DRIVERS\aswFsBlk.sys
C:\Windows\system32\DRIVERS\aswFsBlk.sys
20560 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
----------
Key: aswMonFlt
ImagePath: system32\DRIVERS\aswMonFlt.sys
C:\Windows\system32\DRIVERS\aswMonFlt.sys
50768 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
----------
Key: aswUpdSv
ImagePath: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
17272 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
----------
Key: avast! Antivirus
ImagePath: "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
C:\Program Files\Alwil Software\Avast4\ashServ.exe
144760 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
----------
Key: avast! Mail Scanner
ImagePath: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
247160 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
----------
Key: avast! Web Scanner
ImagePath: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
345464 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
----------
Key: blbdrive
ImagePath: \SystemRoot\system32\drivers\blbdrive.sys - file is missing - alert is globally excluded
----------
Key: ccEvtMgr
ImagePath: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
108648 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: ccSetMgr
ImagePath: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
108648 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: CLCapSvc
ImagePath: "c:\Program Files\Powercinema\Kernel\TV\CLCapSvc.exe"
c:\Program Files\Powercinema\Kernel\TV\CLCapSvc.exe
278608 bytes
Created: 1/12/2007
Modified: 14/02/2007
Company:
----------
Key: CLSched
ImagePath: "c:\Program Files\Powercinema\Kernel\TV\CLSched.exe"
c:\Program Files\Powercinema\Kernel\TV\CLSched.exe
110677 bytes
Created: 1/12/2007
Modified: 14/02/2007
Company:
----------
Key: CLTNetCnService
ImagePath: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
108648 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: comHost
ImagePath: "C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe"
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
49248 bytes
Created: 12/01/2007
Modified: 12/01/2007
Company: Symantec Corporation
----------
Key: eeCtrl
ImagePath: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
385072 bytes
Created: 12/03/2008
Modified: 13/02/2008
Company: Symantec Corporation
----------
Key: fssfltr
ImagePath: system32\DRIVERS\fssfltr.sys
C:\Windows\system32\DRIVERS\fssfltr.sys
43816 bytes
Created: 22/03/2008
Modified: 17/10/2007
Company: Microsoft Corporation
----------
Key: fsssvc
ImagePath: "C:\Program Files\Windows Live\Contrôle parental\fsssvc.exe"
C:\Program Files\Windows Live\Contrôle parental\fsssvc.exe
523816 bytes
Created: 17/12/2007
Modified: 17/12/2007
Company: Microsoft Corporation
----------
Key: GEARAspiWDM
ImagePath: System32\Drivers\GEARAspiWDM.sys
C:\Windows\System32\Drivers\GEARAspiWDM.sys
15664 bytes
Created: 19/09/2006
Modified: 19/09/2006
Company: GEAR Software Inc.
----------
Key: GoogleDesktopManager
ImagePath: "C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe"
C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
81408 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Google
----------
Key: gusvc
ImagePath: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
138168 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Google
----------
Key: HdAudAddService
ImagePath: system32\drivers\CHDART.sys
C:\Windows\system32\drivers\CHDART.sys
160768 bytes
Created: 16/07/2007
Modified: 12/04/2007
Company: Conexant Systems Inc.
----------
Key: HidUsb
ImagePath: \SystemRoot\system32\drivers\hidusb.sys
C:\Windows\system32\drivers\hidusb.sys
12288 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: hwdatacard
ImagePath: system32\DRIVERS\ewusbmdm.sys
C:\Windows\system32\DRIVERS\ewusbmdm.sys
101376 bytes
Created: 13/03/2008
Modified: 15/10/2007
Company: Huawei Technologies Co., Ltd.
----------
Key: IDriverT
ImagePath: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
69632 bytes
Created: 4/04/2005
Modified: 4/04/2005
Company: Macrovision Corporation
----------
Key: IDSvix86
ImagePath: \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080404.001\IDSvix86.sys
C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080404.001\IDSvix86.sys
261680 bytes
Created: 5/04/2008
Modified: 11/03/2008
Company: Symantec Corporation
----------
Key: IpInIp
ImagePath: system32\DRIVERS\ipinip.sys - file is missing - alert is globally excluded
----------
Key: kbdhid
ImagePath: \SystemRoot\system32\drivers\kbdhid.sys
C:\Windows\system32\drivers\kbdhid.sys
15872 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: LiveUpdate
ImagePath: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
2999664 bytes
Created: 1/12/2007
Modified: 26/09/2007
Company: Symantec Corporation
----------
Key: LiveUpdate Notice Ex
ImagePath: "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
108648 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: LiveUpdate Notice Service
ImagePath: "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll"
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
583048 bytes
Created: 29/01/2008
Modified: 29/01/2008
Company: Symantec Corporation
----------
Key: mouhid
ImagePath: \SystemRoot\system32\drivers\mouhid.sys
C:\Windows\system32\drivers\mouhid.sys
15872 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: NAVENG
ImagePath: \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080405.003\NAVENG.SYS
C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080405.003\NAVENG.SYS
82256 bytes
Created: 5/04/2008
Modified: 15/03/2008
Company: Symantec Corporation
----------
Key: NAVEX15
ImagePath: \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080405.003\NAVEX15.SYS
C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080405.003\NAVEX15.SYS
895408 bytes
Created: 5/04/2008
Modified: 15/03/2008
Company: Symantec Corporation
----------
Key: ntrigdigi
ImagePath: \SystemRoot\system32\drivers\ntrigdigi.sys
C:\Windows\system32\drivers\ntrigdigi.sys
20608 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: N-trig Innovative Technologies
----------
Key: NVENETFD
ImagePath: system32\DRIVERS\nvmfdx32.sys
C:\Windows\system32\DRIVERS\nvmfdx32.sys
1059112 bytes
Created: 16/07/2007
Modified: 6/03/2007
Company: NVIDIA Corporation
----------
Key: nvsmu
ImagePath: system32\DRIVERS\nvsmu.sys
C:\Windows\system32\DRIVERS\nvsmu.sys
12032 bytes
Created: 16/07/2007
Modified: 16/02/2007
Company: NVIDIA Corporation
----------
Key: NwlnkFlt
ImagePath: system32\DRIVERS\nwlnkflt.sys - file is missing - alert is globally excluded
----------
Key: NwlnkFwd
ImagePath: system32\DRIVERS\nwlnkfwd.sys - file is missing - alert is globally excluded
----------
Key: ohci1394
ImagePath: \SystemRoot\system32\drivers\ohci1394.sys
C:\Windows\system32\drivers\ohci1394.sys
62080 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: Parport
ImagePath: \SystemRoot\system32\drivers\parport.sys
C:\Windows\system32\drivers\parport.sys
79360 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: Parvdm
ImagePath: \SystemRoot\system32\drivers\parvdm.sys
C:\Windows\system32\drivers\parvdm.sys
8704 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: PxHelp20
ImagePath: System32\Drivers\PxHelp20.sys
C:\Windows\System32\Drivers\PxHelp20.sys
36560 bytes
Created: 27/09/2006
Modified: 27/09/2006
Company: Sonic Solutions
----------
Key: ql2300
ImagePath: \SystemRoot\system32\drivers\ql2300.sys
C:\Windows\system32\drivers\ql2300.sys
900712 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: QLogic Corporation
----------
Key: ql40xx
ImagePath: \SystemRoot\system32\drivers\ql40xx.sys
C:\Windows\system32\drivers\ql40xx.sys
106088 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: QLogic Corporation
----------
Key: RoxMediaDB9
ImagePath: "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe"
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
887544 bytes
Created: 11/01/2007
Modified: 11/01/2007
Company: Sonic Solutions
----------
Key: RoxWatch9
ImagePath: "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe"
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
166648 bytes
Created: 11/01/2007
Modified: 11/01/2007
Company: Sonic Solutions
----------
Key: RTL8187B
ImagePath: system32\DRIVERS\RTL8187B.sys
C:\Windows\system32\DRIVERS\RTL8187B.sys
287744 bytes
Created: 2/12/2007
Modified: 27/09/2007
Company: Realtek Semiconductor Corporation
----------
Key: RTSTOR
ImagePath: system32\drivers\RTSTOR.SYS
C:\Windows\system32\drivers\RTSTOR.SYS
47616 bytes
Created: 1/12/2007
Modified: 15/06/2007
Company: Realtek Semiconductor Corp.
----------
Key: Serenum
ImagePath: \SystemRoot\system32\drivers\serenum.sys
C:\Windows\system32\drivers\serenum.sys
17920 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: Serial
ImagePath: \SystemRoot\system32\drivers\serial.sys
C:\Windows\system32\drivers\serial.sys
83456 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: sisagp
ImagePath: \SystemRoot\system32\drivers\sisagp.sys
C:\Windows\system32\drivers\sisagp.sys
53352 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: SPBBCDrv
ImagePath: \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
418104 bytes
Created: 1/02/2007
Modified: 14/04/2007
Company: Symantec Corporation
----------
Key: SRTSP
ImagePath: System32\Drivers\SRTSP.SYS
C:\Windows\System32\Drivers\SRTSP.SYS
279088 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Symantec Corporation
----------
Key: SRTSPL
ImagePath: System32\Drivers\SRTSPL.SYS
C:\Windows\System32\Drivers\SRTSPL.SYS
317616 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Symantec Corporation
----------
Key: SRTSPX
ImagePath: System32\Drivers\SRTSPX.SYS
C:\Windows\System32\Drivers\SRTSPX.SYS
43696 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Symantec Corporation
----------
Key: ssm_bus
ImagePath: system32\DRIVERS\ssm_bus.sys
C:\Windows\system32\DRIVERS\ssm_bus.sys
58320 bytes
Created: 9/03/2008
Modified: 30/08/2005
Company: MCCI
----------
Key: ssm_mdfl
ImagePath: system32\DRIVERS\ssm_mdfl.sys
C:\Windows\system32\DRIVERS\ssm_mdfl.sys
8336 bytes
Created: 9/03/2008
Modified: 30/08/2005
Company: MCCI
----------
Key: ssm_mdm
ImagePath: system32\DRIVERS\ssm_mdm.sys
C:\Windows\system32\DRIVERS\ssm_mdm.sys
94000 bytes
Created: 9/03/2008
Modified: 30/08/2005
Company: MCCI
----------
Key: stllssvr
ImagePath: "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe"
C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
73728 bytes
Created: 14/09/2006
Modified: 14/09/2006
Company: MicroVision Development, Inc.
----------
Key: Symantec Core LC
ImagePath: "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
1251720 bytes
Created: 26/03/2008
Modified: 26/03/2008
Company:
----------
Key: SYMDNS
ImagePath: \SystemRoot\System32\Drivers\SYMDNS.SYS
C:\Windows\System32\Drivers\SYMDNS.SYS
12984 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: SymEvent
ImagePath: \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
C:\Windows\system32\Drivers\SYMEVENT.SYS
123952 bytes
Created: 1/12/2007
Modified: 16/03/2008
Company: Symantec Corporation
----------
Key: SYMFW
ImagePath: \SystemRoot\System32\Drivers\SYMFW.SYS
C:\Windows\System32\Drivers\SYMFW.SYS
145976 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: SYMIDS
ImagePath: \SystemRoot\System32\Drivers\SYMIDS.SYS
C:\Windows\System32\Drivers\SYMIDS.SYS
40120 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: SYMNDISV
ImagePath: \SystemRoot\System32\Drivers\SYMNDISV.SYS
C:\Windows\System32\Drivers\SYMNDISV.SYS
38200 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: SYMREDRV
ImagePath: \SystemRoot\System32\Drivers\SYMREDRV.SYS
C:\Windows\System32\Drivers\SYMREDRV.SYS
27576 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: SYMTDI
ImagePath: \SystemRoot\System32\Drivers\SYMTDI.SYS
C:\Windows\System32\Drivers\SYMTDI.SYS
191544 bytes
Created: 9/01/2007
Modified: 9/01/2007
Company: Symantec Corporation
----------
Key: uagp35
ImagePath: \SystemRoot\system32\drivers\uagp35.sys
C:\Windows\system32\drivers\uagp35.sys
56936 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: usnjsvc
ImagePath: "C:\Program Files\Windows Live\Messenger\usnsvc.exe"
C:\Program Files\Windows Live\Messenger\usnsvc.exe
98328 bytes
Created: 18/10/2007
Modified: 18/10/2007
Company: Microsoft Corporation
----------
Key: viaide
ImagePath: \SystemRoot\system32\drivers\viaide.sys
C:\Windows\system32\drivers\viaide.sys
17512 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: VIA Technologies, Inc.
----------
Key: wampapache
ImagePath: "c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
24635 bytes
Created: 27/03/2008
Modified: 5/09/2007
Company: Apache Software Foundation
----------
Key: wampmysqld
ImagePath: c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe wampmysqld
c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
5730304 bytes
Created: 27/03/2008
Modified: 6/07/2007
Company:
----------
Key: Wd
ImagePath: system32\drivers\wd.sys
C:\Windows\system32\drivers\wd.sys
19560 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: WLSetupSvc
ImagePath: "C:\Program Files\Windows Live\installer\WLSetupSvc.exe"
C:\Program Files\Windows Live\installer\WLSetupSvc.exe
266240 bytes
Created: 25/10/2007
Modified: 25/10/2007
Company: Microsoft Corporation
----------
**************************************************
17:29:20: Scanning -----VXD ENTRIES-----
Checking the following VxD entries:
**************************************************
17:29:20: Scanning ----- WINLOGON\NOTIFY DLLS -----
No WINLOGON\NOTIFY DLLs found to scan
**************************************************
17:29:20: Scanning ----- CONTEXTMENUHANDLERS -----
Key: avast
CLSID: {472083B0-C522-11CF-8763-00608CC02F24}
Path: C:\Program Files\Alwil Software\Avast4\ashShell.dll
C:\Program Files\Alwil Software\Avast4\ashShell.dll
75128 bytes
Created: 6/04/2008
Modified: 29/03/2008
Company: ALWIL Software
----------
Key: BriefcaseMenu
CLSID: {85BBD920-42A0-1069-A2E4-08002B30309D}
Path: syncui.dll
C:\Windows\system32\syncui.dll
175616 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: Notepad++
CLSID: {120B94B5-2E6A-4F13-94D0-414BCB64FA0F}
Path: C:\Program Files\Notepad++\nppcm.dll
C:\Program Files\Notepad++\nppcm.dll
24576 bytes
Created: 24/11/2006
Modified: 24/11/2006
Company: Burgaud.com
----------
Key: Open With
CLSID: {09799AFB-AD67-11d1-ABCD-00C04FC30936}
Path: %SystemRoot%\system32\shell32.dll
C:\Windows\system32\shell32.dll
11315200 bytes
Created: 2/12/2007
Modified: 2/12/2007
Company: Microsoft Corporation
----------
Key: Open With EncryptionMenu
CLSID: {A470F8CF-A1E8-4f65-8335-227475AA5C46}
Path: %SystemRoot%\system32\shell32.dll
C:\Windows\system32\shell32.dll
11315200 bytes
Created: 2/12/2007
Modified: 2/12/2007
Company: Microsoft Corporation
----------
Key: Sharing
CLSID: {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
Path: ntshrui.dll
C:\Windows\system32\ntshrui.dll
296448 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
Key: ShellExtension
CLSID: [empty]
----------
Key: Trojan Remover
CLSID: {52B87208-9CCF-42C9-B88E-069281105805}
Path: C:\PROGRA~1\TROJAN~1\Trshlex.dll
C:\PROGRA~1\TROJAN~1\Trshlex.dll
467552 bytes
Created: 6/04/2008
Modified: 5/02/2007
Company: Simply Super Software
----------
Key: {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Path: %SystemRoot%\system32\shell32.dll
C:\Windows\system32\shell32.dll
11315200 bytes
Created: 2/12/2007
Modified: 2/12/2007
Company: Microsoft Corporation
----------
**************************************************
17:29:21: Scanning ----- FOLDER\COLUMNHANDLERS -----
Key: {F9DB5320-233E-11D1-9F84-707F02C10627}
File: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
372736 bytes
Created: 23/10/2006
Modified: 23/10/2006
Company: Adobe Systems, Inc.
----------
**************************************************
17:29:21: Scanning ----- BROWSER HELPER OBJECTS -----
Key: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
BHO: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
62080 bytes
Created: 23/10/2006
Modified: 23/10/2006
Company: Adobe Systems Incorporated
----------
Key: {1E8A6170-7264-4D0F-BEAE-D42A53123C75}
BHO: C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
-R- 97960 bytes
Created: 19/02/2007
Modified: 19/02/2007
Company: Symantec Corporation
----------
Key: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}
BHO: C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
56360 bytes
Created: 17/12/2007
Modified: 17/12/2007
Company: Microsoft Corporation
----------
Key: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
BHO: C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
509328 bytes
Created: 13/03/2008
Modified: 14/12/2007
Company: Sun Microsystems, Inc.
----------
Key: {9030D464-4C02-4ABF-8ECC-5164760863C6}
BHO: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
328752 bytes
Created: 20/09/2007
Modified: 20/09/2007
Company: Microsoft Corporation
----------
Key: {AA58ED58-01DD-4d91-8333-CF10577473F7}
BHO: c:\program files\google\googletoolbar1.dll
c:\program files\google\googletoolbar1.dll
-R- 2436160 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Google Inc.
----------
Key: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
BHO: C:\Program Files\Windows Live Toolbar\msntb.dll
C:\Program Files\Windows Live Toolbar\msntb.dll
546320 bytes
Created: 19/10/2007
Modified: 19/10/2007
Company: Microsoft Corporation
----------
Key: {CA6319C0-31B7-401E-A518-A07C3DB8F777}
BHO: C:\Program Files\Google\Google_BAE\BAE.dll
C:\Program Files\Google\Google_BAE\BAE.dll
98304 bytes
Created: 1/12/2007
Modified: 9/11/2006
Company: Packard Bell
----------
**************************************************
17:29:22: Scanning ----- SHELLSERVICEOBJECTS -----
Key: WebCheck
CLSID: {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Path: C:\Windows\system32\webcheck.dll
C:\Windows\system32\webcheck.dll
232960 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
**************************************************
17:29:22: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
Value: {8C7461EF-2B13-11d2-BE35-3078302C2030}
Comment: Component Categories cache daemon
File: %SystemRoot%\system32\browseui.dll
C:\Windows\system32\browseui.dll
1321472 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
**************************************************
17:29:22: Scanning ----- IMAGEFILE DEBUGGERS -----
No "Debugger" entries found.
**************************************************
17:29:22: Scanning ----- APPINIT_DLLS -----
AppInitDLLs entry = [C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL]
File: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
163328 bytes
Created: 1/12/2007
Modified: 1/12/2007
Company: Google
----------
**************************************************
17:29:23: Scanning ----- SECURITY PROVIDER DLLS -----
DLL: credssp.dll
C:\Windows\system32\credssp.dll
15360 bytes
Created: 2/11/2006
Modified: 2/11/2006
Company: Microsoft Corporation
----------
**************************************************
17:29:23: Scanning ------ COMMON STARTUP GROUP ------
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-HS- 174 bytes
Created: 2/11/2006
Modified: 1/12/2007
Company:
--------------------
**************************************************
17:29:23: Scanning ----- USER STARTUP GROUPS -----
Checking Startup Group for: albuk
[C:\Users\albuk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
C:\Users\albuk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
-HS- 174 bytes
Created: 8/03/2008
Modified: 8/03/2008
Company:
----------
--------------------
**************************************************
17:29:24: Scanning ----- SCHEDULED TASKS -----
Taskname: Antispyware Scheduled Scan.job
File: C:\Program Files\AntiSpywareApp\AntiSpyware.exe
Parameters: scheduled
Next Run Time: 7/04/2008 3:00:00
Status: Une ou plusieurs des propriétés nécessaires pour exécuter cette tâche suivant un calendrier n'ont pas été définies
Creator: albuk
Comments: Runs Antispyware to scan your computer for malicious and potenially unwanted programs.
C:\Program Files\AntiSpywareApp\AntiSpyware.exe [file not found to scan]
----------
Taskname: Extension de garantie.job
File: C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe
Parameters: [blank]
Next Run Time: 6/04/2008 17:30:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: albuk
Comments: [blank]
C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe [file not found to scan]
----------
Taskname: Recovery DVD Creator.job
File: C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe
Parameters: [blank]
Next Run Time: 6/04/2008 17:30:00
Status: La tâche est prête à s'exécuter à l'heure prévue
Creator: albuk
Comments: [blank]
C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe [file not found to scan]
----------
Taskname: Uniblue SpeedUpMyPC Nag.job
File: C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
Parameters: -s
Next Run Time: 9/04/2008 17:15:00
Status: Une ou plusieurs des propriétés nécessaires pour exécuter cette tâche suivant un calendrier n'ont pas été définies
Creator: albuk
Comments: [blank]
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [file not found to scan]
----------
Taskname: Uniblue SpeedUpMyPC.job
File: C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
Parameters: -s
Next Run Time: Never
Status: Une ou plusieurs des propriétés nécessaires pour exécuter cette tâche suivant un calendrier n'ont pas été définies
Creator: albuk
Comments: Uniblue SpeedUpMyPC Scheduler
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [file not found to scan]
----------
Taskname: Vérifier les mises à jour de Windows Live Toolbar.job
File: C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
99856 bytes
Created: 19/10/2007
Modified: 19/10/2007
Company: Microsoft Corporation
Parameters: [blank]
Next Run Time: 6/04/2008 17:35:00
Status: La tâche n'a pas encore été exécutée
Creator: albuk
Comments: [blank]
----------
**************************************************
17:29:24: ----- ADDITIONAL CHECKS -----
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
---------
Windows Explorer Policies checks completed
----------
Desktop Wallpaper: C:\Users\albuk\Pictures\ELIE17.jpg
C:\Users\albuk\Pictures\ELIE17.jpg
31077 bytes
Created: 2/04/2008
Modified: 2/04/2008
Company:
----------
Web Desktop Wallpaper: %USERPROFILE%\Pictures\ELIE17.jpg
C:\Users\albuk\Pictures\ELIE17.jpg
31077 bytes
Created: 2/04/2008
Modified: 2/04/2008
Company:
----------
Additional file checks completed
---------
**************************************************
17:29:24: Scanning ----- RUNNING PROCESSES -----
[Only loaded modules not scanned already
during this scan will be scanned here]
C:\Windows\System32\smss.exe
[1 loaded module]
--------------------
C:\Windows\system32\csrss.exe
[13 loaded modules in total]
--------------------
C:\Windows\system32\wininit.exe
[25 loaded modules in total]
--------------------
C:\Windows\system32\csrss.exe
[13 loaded modules in total]
--------------------
C:\Windows\system32\winlogon.exe
[29 loaded modules in total]
--------------------
C:\Windows\system32\services.exe
[34 loaded modules in total]
--------------------
C:\Windows\system32\lsass.exe
[59 loaded modules in total]
--------------------
C:\Windows\system32\lsm.exe
[21 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[44 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[38 loaded modules in total]
--------------------
C:\Windows\System32\svchost.exe
[50 loaded modules in total]
--------------------
C:\Windows\System32\svchost.exe
[61 loaded modules in total]
--------------------
C:\Windows\System32\svchost.exe
[111 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[152 loaded modules in total]
--------------------
C:\Windows\system32\SLsvc.exe
[22 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[78 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[86 loaded modules in total]
--------------------
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
[145 loaded modules in total]
--------------------
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
[19 loaded modules in total]
--------------------
C:\Program Files\Alwil Software\Avast4\ashServ.exe
[66 loaded modules in total]
--------------------
C:\Windows\System32\spoolsv.exe
[77 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[54 loaded modules in total]
--------------------
C:\Windows\system32\taskeng.exe
[79 loaded modules in total]
--------------------
C:\Windows\system32\Dwm.exe
[36 loaded modules in total]
--------------------
C:\Windows\Explorer.EXE
[136 loaded modules in total]
--------------------
C:\Program Files\Windows Defender\MSASCui.exe
[38 loaded modules in total]
--------------------
C:\Windows\System32\rundll32.exe
[35 loaded modules in total]
--------------------
C:\Program Files\Realtek Semiconductor Corp\Realtek Card Reader Monitor\CardReaderMonitor.exe
[26 loaded modules in total]
--------------------
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[62 loaded modules in total]
--------------------
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[37 loaded modules in total]
--------------------
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[86 loaded modules in total]
--------------------
C:\Program Files\Powercinema\PCMService.exe
[99 loaded modules in total]
--------------------
C:\Program Files\Picasa2\PicasaMediaDetector.exe
[27 loaded modules in total]
--------------------
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
[20 loaded modules in total]
--------------------
C:\Program Files\Windows Live\Contrôle parental\fssui.exe
[41 loaded modules in total]
--------------------
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[31 loaded modules in total]
--------------------
C:\Windows\System32\rundll32.exe
[45 loaded modules in total]
--------------------
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
[47 loaded modules in total]
--------------------
C:\Program Files\Windows Sidebar\sidebar.exe
[57 loaded modules in total]
--------------------
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
[25 loaded modules in total]
--------------------
C:\ProgramData\eqervsma\byzihcry.exe
[15 loaded modules in total]
--------------------
C:\ProgramData\dgxihohm\bkjytonw.exe
[66 loaded modules in total]
--------------------
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[148 loaded modules in total]
--------------------
C:\Program Files\Windows Media Player\wmpnscfg.exe
[28 loaded modules in total]
--------------------
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
[49 loaded modules in total]
--------------------
c:\Program Files\Powercinema\Kernel\TV\CLCapSvc.exe
[72 loaded modules in total]
--------------------
C:\Program Files\Windows Live\Contrôle parental\fsssvc.exe
[72 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[38 loaded modules in total]
--------------------
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
[50 loaded modules in total]
--------------------
C:\Windows\system32\svchost.exe
[60 loaded modules in total]
--------------------
C:\Windows\System32\svchost.exe
[6 loaded modules in total]
--------------------
C:\Windows\system32\SearchIndexer.exe
[61 loaded modules in total]
--------------------
C:\Program Files\Windows Sidebar\sidebar.exe
[64 loaded modules in total]
--------------------
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
[40 loaded modules in total]
--------------------
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
[51 loaded modules in total]
--------------------
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
[35 loaded modules in total]
--------------------
C:\Windows\system32\wbem\wmiprvse.exe
[30 loaded modules in total]
--------------------
C:\Program Files\Windows Media Player\wmpnetwk.exe
[72 loaded modules in total]
--------------------
C:\Windows\system32\taskeng.exe
[47 loaded modules in total]
--------------------
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
[39 loaded modules in total]
--------------------
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
[20 loaded modules in total]
--------------------
C:\Windows\system32\wbem\unsecapp.exe
[27 loaded modules in total]
--------------------
E:\PhoneConnectorVMC.exe
[58 loaded modules in total]
--------------------
C:\Program Files\vodafone\vmclite\vmc.exe
[57 loaded modules in total]
--------------------
C:\Program Files\Windows Live\Messenger\usnsvc.exe
[16 loaded modules in total]
--------------------
C:\Program Files\Internet Explorer\IEUser.exe
[64 loaded modules in total]
--------------------
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
[47 loaded modules in total]
--------------------
C:\Program Files\Internet Explorer\iexplore.exe
[179 loaded modules in total]
--------------------
C:\Windows\system32\taskeng.exe
[63 loaded modules in total]
--------------------
C:\Program Files\Trojan Remover\Rmvtrjan.exe
FileSize: 2478656
[This is a Trojan Remover component]
[35 loaded modules in total]
--------------------
C:\Windows\system32\conime.exe
[15 loaded modules in total]
--------------------
**************************************************
17:30:54: Checking HOSTS file
No malicious entries were found in the HOSTS file
**************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Local Page":
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\"CustomizeSearch":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\"SearchAssistant":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\Windows\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
**************************************************
=== NO CHANGES HAVE BEEN MADE TO YOUR SYSTEM FILES ===
Scan completed at: 6/04/2008 17:30:54
************************************************************
***** INDIVIDUAL FILE SCAN *****
Trojan Remover Ver 6.6.8.2524. For information, email support@simplysup.com
[Unregistered version]
Scan started at: 6/04/2008 16:57:45
Using Database v6965
Operating System: Windows Vista [Windows Vista (Build 6000)]
Edition: Windows Vista (TM) Home Basic
File System: NTFS
User Account Control is Enabled.
Data directory: C:\Users\albuk\AppData\Roaming\Simply Super Software\Trojan Remover\
Logfile directory: C:\Users\albuk\Documents\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Program Files\Trojan Remover\
Running with Administrator privileges
**************************************************
The following Anti-Malware program(s) are loaded:
Microsoft Windows Defender
Avast! Antivirus
Nortons Anti-Virus
**************************************************
Carrying out individual file scan on C:\Users\albuk\Desktop\HJTInstall.exe
This file appears to be OK
************************************************************
cré toi un post et donne moi le lien et je viendrai