Pancake,
I could not run SDFix. Tried opening as usual, as administrator no luck. I noticed in properties tab win XP compatible. I have Vista.
Combofix and
HJT logs below alongwith a screen shot of Spybot warning ( sorry in attachment - could not figure out how to paste) after combofix report but before
HJT report. I after allowed change since otherwise it comes up with same reminder every 2 minutes exactly.
Thanks for your help so far.
ComboFix 08-02-14.2 - Jeremy 2008-02-14 10:43:26.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.44.1036.18.1254 [GMT 1:00]
Endroit: C:\Users\Jeremy\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Jeremy\AppData\Local\oiyjupm.dat
C:\Users\Jeremy\AppData\Local\oiyjupm.exe
C:\Users\Jeremy\AppData\Local\oiyjupm_nav.dat
C:\Users\Jeremy\AppData\Local\oiyjupm_navps.dat
C:\Windows\prefs_zb.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-14 to 2008-02-14 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-14 08:36 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 08:36 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-14 08:35 943,800 ----a-w C:\Windows\System32\winload.exe
2008-02-14 08:35 905,400 ----a-w C:\Windows\System32\winresume.exe
2008-02-14 08:35 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-14 08:35 613,888 ----a-w C:\Windows\System32\wpd_ci.dll
2008-02-14 08:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-14 08:35 6,656 ----a-w C:\Windows\System32\kbd106.dll
2008-02-14 08:35 595,456 ----a-w C:\Windows\System32\schedsvc.dll
2008-02-14 08:35 558,080 ----a-w C:\Windows\System32\oleaut32.dll
2008-02-14 08:35 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 08:35 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 08:35 39,424 ----a-w C:\Windows\System32\lodctr.exe
2008-02-14 08:35 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 08:35 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 08:35 35,328 ----a-w C:\Windows\System32\dispci.dll
2008-02-14 08:35 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 08:35 32,256 ----a-w C:\Windows\System32\unlodctr.exe
2008-02-14 08:35 260,096 ----a-w C:\Windows\System32\dpx.dll
2008-02-14 08:35 23,552 ----a-w C:\Windows\System32\nshhttp.dll
2008-02-14 08:35 224,824 ----a-w C:\Windows\System32\clfs.sys
2008-02-14 08:35 221,696 ----a-w C:\Windows\System32\umpnpmgr.dll
2008-02-14 08:35 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 08:35 19,456 ----a-w C:\Windows\System32\cfgmgr32.dll
2008-02-14 08:35 17,408 ----a-w C:\Windows\System32\prflbmsg.dll
2008-02-14 08:35 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-14 08:35 15,872 ----a-w C:\Windows\system32\drivers\kbdhid.sys
2008-02-14 08:35 12,800 ----a-w C:\Windows\System32\batt.dll
2008-02-14 08:35 115,200 ----a-w C:\Windows\System32\loadperf.dll
2008-02-14 08:35 101,888 ----a-w C:\Windows\System32\drvinst.exe
2008-02-14 08:35 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
2008-02-14 08:32 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-14 08:32 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-14 08:32 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 08:32 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 08:32 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 08:32 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 08:32 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-14 08:32 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-14 08:32 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-02-14 08:32 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 08:32 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-14 08:32 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-14 08:31 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 08:31 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 08:31 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 08:31 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 08:31 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 08:31 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-14 08:27 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 08:26 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 08:26 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 08:26 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-14 08:19 --------- d-----w C:\Users\Jeremy\AppData\Roaming\AVG7
2008-02-13 15:29 --------- d-----w C:\Program Files\CCleaner
2008-02-13 14:25 --------- d-----w C:\Users\Jeremy\AppData\Roaming\SUPERAntiSpyware.c om
2008-02-13 14:25 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
2008-02-13 14:25 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-02-13 14:24 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-13 13:23 --------- d-----w C:\ProgramData\Grisoft
2008-02-12 13:59 --------- d-----w C:\Program Files\Winamp
2008-02-11 12:42 --------- d-----w C:\Program Files\Winamp Remote
2008-02-11 12:29 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-02-11 12:19 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-11 11:47 --------- d-----w C:\Program Files\Trend Micro
2008-02-11 10:25 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-02-10 22:06 --------- d-----w C:\Users\Jeremy\AppData\Roaming\SecondLife
2008-02-07 16:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-07 16:52 --------- d-----w C:\Program Files\Google
2008-02-07 16:01 --------- d-----w C:\ProgramData\Lavasoft
2008-02-07 16:01 --------- d-----w C:\Program Files\Lavasoft
2008-02-05 15:39 --------- d-----w C:\Users\Jeremy\AppData\Roaming\Winamp
2008-02-04 20:06 --------- d-----w C:\ProgramData\OrbNetworks
2008-02-04 20:02 --------- d-----w C:\ProgramData\Winamp Toolbar
2008-02-04 20:02 --------- d-----w C:\Program Files\Winamp Toolbar
2008-01-30 12:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-23 12:05 --------- d-----w C:\ProgramData\Logishrd
2008-01-23 12:05 --------- d-----w C:\Program Files\Common Files\LogiShrd
2008-01-23 11:54 --------- d-----w C:\ProgramData\Logitech
2008-01-22 12:29 --------- d-----w C:\Program Files\SecondLife
2008-01-17 02:07 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-17 02:07 --------- d-----w C:\Program Files\Windows Mail
2008-01-16 18:20 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-16 18:20 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-16 18:20 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2007-12-14 10:42 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-14 10:41 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-14 10:41 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-14 10:40 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-14 10:40 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-14 10:40 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-14 10:40 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-14 10:32 12,632 ----a-w C:\Windows\System32\lsdelete.exe
2007-11-20 02:01 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-14 02:02 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 02:02 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 02:02 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 02:02 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 02:02 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 02:02 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-04-02 12:35 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 17:49 1185120 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 17:49 1185120]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-16 19:20 1232896]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55 5674352]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"Simple Star PhotoShow Media Manager"="C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras \mssysmgr.exe" [2006-01-13 22:22 233472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe" [2007-03-26 19:00 171448]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-01-16 09:43 1458176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-12 02:01 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 14:42 65536]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 11:57 3784704 C:\Windows\RtHDVCpl.exe]
"CCUTRAYICON"="FactoryMode" []
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"BigDog305"="C:\Windows\VM305_STI.exe" [2005-08-05 14:15 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-04-19 17:11 151552]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-03-12 19:37 90191]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-03-12 19:37 7770112]
"NvMediaCenter"="C:\Windows\system32\NvMcTray. dll" [2007-03-12 19:37 81920]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-16 12:08 579072]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-05 13:36 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16 286720]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 08:49 219136]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-10-02 12:13 9216 C:\Windows\System32\avgwlntf.dll
R2 DQLWinService

QLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.e xe" [2006-09-03 10:32]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot []
R3 3xHybrid;ASUSTek SAA713x PCI Card;C:\Windows\system32\DRIVERS\3xHybrid.sys [2006-09-19 17:57]
R3 ZSMC0305;VIMICRO USB PC Camera V;C:\Windows\system32\Drivers\usbVM305.sys [2006-05-08 09:24]
S2 IntelDHSvcConf;Intel DH Service;"C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe" [2006-05-10 09:13]
S2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-05-11 16:03]
S3 mamotou;mamotou;C:\Windows\system32\DRIVERS\mamoto u.sys [2005-11-07 10:50]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-14 08:22:29 C:\Windows\Tasks\User_Feed_Synchronization-{95E350D7-D7DA-4F44-9ED8-066698C51855}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-02-13 16:01:00 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:13, on 2008-02-14
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\hp\KBD\kbd.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Simple Star\PhotoShow 4\data\Xtras\mssysmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Explorer.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Google News
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
monAOL | HP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
monAOL | HP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [BigDog305] C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Simple Star PhotoShow Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr. exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -
file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.google.com/s/v/25.23/uploader2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by139fd.bay139.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {87AF076E-D86D-4E87-ADDD-F05804E1F150} (VirginMega.DMFacade.Interface) -
https://www.virginmega.fr/DownloadMa...od/DownMan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.com/files/driveragent.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.e xe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 11853 bytes