Bonjour,
Comme dans un autre post (mais marqué [résolu], c'est pour cette raison que j'en ouvre un autre...), je me trouve face à ce trojan.
Pour un raison que j'ignore, Anti-Malware (mbam) et Hijackthis ne fonctionnent (ils plantent dès le lancement...). Sur les conseils de Guillaume5188, j'ai pu lancé RSIT dont voici le log.
En esperant que quelqu'un pourra me donner une piste,
Cordialement,
++++++++++++++++++++++++++
Logfile of random's system information tool 1.06 (written by random/random)
Run by Pat at 2009-06-15 23:24:24
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 208 GB (44%) free of 477 GB
Total RAM: 3325 MB (65% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\Ad-Aware Update (Weekly).job
C:\Windows\tasks\GoogleUpdateTaskMachine.job
C:\Windows\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-05-20 1107224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"toolbar_eula_launcher"=C:\Program Files\GoogleEULA\EULALauncher.exe []
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-10-11 4702208]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-05-20 1947928]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"Zboard"=C:\Program Files\Ideazon\ZEngine\Zboard.exe [2008-06-27 53248]
"Ulead AutoDetector v2"=C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [2004-11-26 90112]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-05-16 13535776]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-05-16 92704]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2008-05-28 570664]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-01-05 413696]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-04-01 486856]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-04-24 251240]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
NewShortcut2.lnk - C:\Windows\Installer\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe"="C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe"="C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{33877db6-09a0-11de-bd92-001d9248beb2}]
shell\AutoRun\command - M:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6b31c01-2d92-11dd-a103-001d9248beb2}]
shell\AutoRun\command - RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\scsaver.exe
shell\open\command - RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\scsaver.exe
======List of files/folders created in the last 2 months======
2009-06-15 23:24:24 ----D---- C:\rsit
2009-06-15 23:24:24 ----D---- C:\Program Files\trend micro
2009-06-15 23:00:46 ----D---- C:\Users\Pat\AppData\Roaming\Hyperionics
2009-06-15 19:59:50 ----D---- C:\ProgramData\Malwarebytes
2009-06-15 19:59:50 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-14 17:23:25 ----A---- C:\Users\Pat\AppData\Roaming\SetValue.bat
2009-06-14 17:23:25 ----A---- C:\Users\Pat\AppData\Roaming\GetValue.vbs
2009-06-14 17:23:24 ----A---- C:\Windows\system32\tmp.txt
2009-06-14 17:23:14 ----A---- C:\rapport.txt
2009-06-14 17:22:34 ----D---- C:\Windows\system32\SmitfraudFix
2009-06-14 13:28:46 ----D---- C:\PC_Hijacking
2009-06-14 13:12:10 ----SHD---- C:\Config.Msi
2009-06-14 11:38:48 ----DC---- C:\Windows\system32\DRVSTORE
2009-06-14 11:37:37 ----D---- C:\ProgramData\Lavasoft
2009-06-14 11:01:44 ----A---- C:\Windows\ntbtlog.txt
2009-06-13 17:33:13 ----A---- C:\Windows\system32\psisdecd.dll
2009-06-13 17:33:13 ----A---- C:\Windows\system32\EncDec.dll
2009-06-11 20:56:00 ----A---- C:\Windows\system32\localspl.dll
2009-06-11 20:55:57 ----A---- C:\Windows\system32\rpcrt4.dll
2009-06-11 20:55:54 ----A---- C:\Windows\system32\mshtml.dll
2009-06-11 20:55:52 ----A---- C:\Windows\system32\ieframe.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\wininet.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\urlmon.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\occache.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\msfeeds.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\ieUnatt.exe
2009-06-11 20:55:51 ----A---- C:\Windows\system32\iertutil.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\ieencode.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\iedkcs32.dll
2009-06-11 20:55:51 ----A---- C:\Windows\system32\ieaksie.dll
2009-06-11 20:55:50 ----A---- C:\Windows\system32\mstime.dll
2009-06-11 20:55:50 ----A---- C:\Windows\system32\jsproxy.dll
2009-06-09 23:45:11 ----D---- C:\Users\Pat\AppData\Roaming\Media Player Classic
2009-06-09 23:42:26 ----A---- C:\Windows\system32\unrar.dll
2009-06-09 23:42:25 ----A---- C:\Windows\avisplitter.ini
2009-06-09 23:42:24 ----A---- C:\Windows\system32\yv12vfw.dll
2009-06-09 23:42:24 ----A---- C:\Windows\system32\xvidvfw.dll
2009-06-09 23:42:24 ----A---- C:\Windows\system32\xvidcore.dll
2009-06-09 23:42:23 ----D---- C:\Program Files\K-Lite Codec Pack
2009-06-09 23:37:48 ----D---- C:\Program Files\FLVCodec
2009-06-09 23:37:35 ----D---- C:\Program Files\WinPcap
2009-06-09 17:31:20 ----AD---- C:\ProgramData\TEMP
2009-06-09 17:31:18 ----D---- C:\Fraps
2009-05-31 23:25:19 ----A---- C:\Windows\system32\spr32d35.dll
2009-05-31 23:21:08 ----D---- C:\Program Files\Architecte_3D_Silver_Advanced
2009-05-30 19:51:16 ----D---- C:\Program Files\Tomtomax Maxi-Box
2009-05-24 00:13:40 ----D---- C:\ProgramData\TomTom
2009-05-24 00:13:26 ----D---- C:\Users\Pat\AppData\Roaming\TomTom
2009-05-24 00:13:12 ----D---- C:\Program Files\TomTom International B.V
2009-05-24 00:12:58 ----D---- C:\Program Files\TomTom HOME 2
2009-05-24 00:10:55 ----D---- C:\Program Files\TomTom DesktopSuite
2009-05-01 23:02:26 ----A---- C:\Windows\system32\divx_xx16.dll
2009-05-01 23:02:26 ----A---- C:\Windows\system32\divx_xx11.dll
2009-05-01 23:02:26 ----A---- C:\Windows\system32\divx_xx0c.dll
2009-05-01 23:02:26 ----A---- C:\Windows\system32\divx_xx0a.dll
2009-05-01 23:02:26 ----A---- C:\Windows\system32\divx_xx07.dll
2009-05-01 23:02:26 ----A---- C:\Windows\system32\DivX.dll
2009-04-29 21:51:36 ----D---- C:\Program Files\Common Files\INCA Shared
2009-04-29 21:30:57 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-04-29 21:30:57 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-04-29 21:30:56 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-04-29 21:30:56 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-04-29 21:30:56 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-04-29 21:30:56 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-04-29 21:30:55 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-04-29 21:30:55 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-04-29 21:30:55 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-04-29 21:30:55 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-04-29 21:30:55 ----A---- C:\Windows\system32\d3dx10_39.dll
2009-04-29 21:30:55 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2009-04-29 21:30:54 ----A---- C:\Windows\system32\XAudio2_1.dll
2009-04-29 21:30:54 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2009-04-29 21:30:54 ----A---- C:\Windows\system32\xactengine3_1.dll
2009-04-29 21:30:54 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2009-04-29 21:30:54 ----A---- C:\Windows\system32\D3DX9_39.dll
2009-04-29 21:30:53 ----A---- C:\Windows\system32\D3DX9_38.dll
2009-04-29 21:30:53 ----A---- C:\Windows\system32\d3dx10_38.dll
2009-04-29 21:30:53 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2009-04-29 00:20:04 ----D---- C:\Program Files\Ê¢´óÍøÂç
2009-04-24 22:52:29 ----D---- C:\Program Files\Common Files\DivX Shared
2009-04-17 19:22:10 ----D---- C:\ProgramData\Apple
2009-04-17 19:22:10 ----D---- C:\Program Files\Apple Software Update
2009-04-17 10:59:26 ----A---- C:\Windows\system32\winhttp.dll
2009-04-17 10:59:21 ----A---- C:\Windows\system32\xolehlp.dll
2009-04-17 10:59:21 ----A---- C:\Windows\system32\msdtcprx.dll
2009-04-17 10:59:03 ----A---- C:\Windows\system32\rpcss.dll
2009-04-17 10:59:03 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-04-17 10:59:03 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-04-17 10:59:02 ----A---- C:\Windows\system32\sdohlp.dll
2009-04-17 10:59:02 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-04-17 10:59:02 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-04-17 10:59:02 ----A---- C:\Windows\system32\iasrecst.dll
2009-04-17 10:59:02 ----A---- C:\Windows\system32\iashost.exe
2009-04-17 10:59:02 ----A---- C:\Windows\system32\iasdatastore.dll
2009-04-17 10:59:02 ----A---- C:\Windows\system32\iasads.dll
2009-04-17 10:58:55 ----A---- C:\Windows\system32\lsasrv.dll
2009-04-17 10:58:55 ----A---- C:\Windows\system32\kernel32.dll
2009-04-17 10:58:54 ----A---- C:\Windows\system32\secur32.dll
2009-04-17 10:58:54 ----A---- C:\Windows\system32\apilogen.dll
2009-04-17 10:58:54 ----A---- C:\Windows\system32\amxread.dll
======List of files/folders modified in the last 2 months======
2009-06-15 23:24:24 ----RD---- C:\Program Files
2009-06-15 23:24:15 ----D---- C:\Windows\Temp
2009-06-15 23:23:45 ----HD---- C:\$AVG8.VAULT$
2009-06-15 23:00:00 ----D---- C:\Windows\Tasks
2009-06-15 22:25:40 ----D---- C:\Windows\System32
2009-06-15 22:25:40 ----D---- C:\Windows\inf
2009-06-15 22:25:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-06-15 22:23:16 ----D---- C:\Windows\system32\WDI
2009-06-15 22:23:04 ----D---- C:\ProgramData\avg8
2009-06-15 22:06:39 ----D---- C:\Windows\system32\Tasks
2009-06-15 19:59:51 ----D---- C:\Windows\system32\drivers
2009-06-15 19:59:50 ----HD---- C:\ProgramData
2009-06-14 15:10:35 ----D---- C:\Windows\Minidump
2009-06-14 15:10:27 ----D---- C:\Windows
2009-06-14 13:12:11 ----SHD---- C:\Windows\Installer
2009-06-14 13:10:39 ----SD---- C:\Windows\Downloaded Program Files
2009-06-14 11:41:38 ----D---- C:\Windows\system32\catroot2
2009-06-14 11:38:48 ----D---- C:\Windows\system32\catroot
2009-06-14 11:37:34 ----D---- C:\Windows\winsxs
2009-06-14 11:21:04 ----SHD---- C:\System Volume Information
2009-06-13 18:34:19 ----D---- C:\Windows\ehome
2009-06-13 08:27:27 ----D---- C:\Warhammer Online - Age of Reckoning
2009-06-12 17:10:04 ----D---- C:\Program Files\Internet Explorer
2009-06-07 17:49:06 ----D---- C:\Users\Pat\AppData\Roaming\Vso
2009-06-04 21:13:35 ----D---- C:\Program Files\DivX
2009-06-01 18:51:12 ----A---- C:\Windows\system32\mrt.exe
2009-05-24 00:13:28 ----D---- C:\Users\Pat\AppData\Roaming\Mozilla
2009-05-20 10:01:08 ----A---- C:\Windows\system32\avgrsstx.dll
2009-05-12 23:19:12 ----D---- C:\Program Files\Windows Mail
2009-05-06 14:40:13 ----SD---- C:\Users\Pat\AppData\Roaming\Microsoft
2009-05-06 12:51:37 ----D---- C:\Users\Pat\AppData\Roaming\dvdcss
2009-04-29 21:51:36 ----D---- C:\Program Files\Common Files
2009-04-29 21:30:38 ----RSD---- C:\Windows\assembly
2009-04-29 21:29:10 ----D---- C:\Windows\Logs
2009-04-24 22:54:03 ----D---- C:\Program Files\Google
2009-04-18 08:51:25 ----D---- C:\Windows\system32\wbem
2009-04-18 08:51:24 ----D---- C:\Windows\system32\manifeststore
2009-04-18 08:51:24 ----D---- C:\Windows\AppPatch
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-05-20 325896]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-05-20 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-05-20 108552]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\Windows\system32\DRIVERS\nwlnkipx.sys [2007-02-17 88448]
R3 Alpham1;Ideazon ZBoard USB Human Interface Device; C:\Windows\system32\DRIVERS\Alpham1.sys [2007-07-23 42624]
R3 Alpham2;Ideazon ZBoard MM USB Human Interface Device; C:\Windows\system32\DRIVERS\Alpham2.sys [2007-03-20 18432]
R3 bcgame;Nostromo HID Device Minidriver; C:\Windows\system32\drivers\bcgame.sys [2007-08-14 23040]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2007-04-13 228224]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-10-16 1971928]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-05-16 7465312]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-06-01 47360]
R3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 3xHybrid;Philips SAA713x PCI Card; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-01-08 1136600]
S3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-01-26 705536]
S3 athrusb;Atheros Wireless LAN USB device driver; C:\Windows\system32\DRIVERS\athrusb.sys [2006-12-22 449536]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 aujlopip;aujlopip; C:\Windows\system32\drivers\aujlopip.sys []
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
S3 XUIF;X10 USB Wireless Transceiver; C:\Windows\System32\Drivers\x10ufx2.sys [2006-11-30 27416]
S4 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-07-12 305176]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-05-20 908568]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-05-20 298776]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-05-16 118784]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-04-24 92008]
S2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-08-13 610304]
S2 gupdate1c9c51e9c104af0;Service Google Update (gupdate1c9c51e9c104af0); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-24 133104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2009-04-15 2722845]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
-----------------EOF-----------------Configuration: Windows Vista Internet Explorer 7.0
AVG 8.5
Defender
