

xelos
Membres-
Compteur de contenus
33 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par xelos
-
[Résolu] Analyse rapport HijackThis
xelos a répondu à un(e) sujet de xelos dans Analyses et éradication malwares
voici le lien du 2eme rapport http://cjoint.com/?3AgnXZOKIKu merci -
[Résolu] Analyse rapport HijackThis
xelos a répondu à un(e) sujet de xelos dans Analyses et éradication malwares
rapport adw # AdwCleaner v3.016 - Rapport créé le 06/01/2014 à 13:08:34 # Mis à jour le 23/12/2013 par Xplode # Système d'exploitation : Windows 7 Ultimate Service Pack 1 (32 bits) # Nom d'utilisateur : xelos - EMACHINE # Exécuté depuis : C:\Users\xelos\Downloads\adwcleaner.exe # Option : Nettoyer ***** [ Services ] ***** ***** [ Fichiers / Dossiers ] ***** Dossier Supprimé : C:\ProgramData\NCH Software Dossier Supprimé : C:\ProgramData\AlawarWrapper Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Dossier Supprimé : C:\Program Files\NCH Software Dossier Supprimé : C:\Users\xelos\AppData\Local\AlawarWrapper Dossier Supprimé : C:\Users\xelos\AppData\Roaming\NCH Software Dossier Supprimé : C:\Users\xelos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohikckhbcljgombipcdoinkaedlfa Fichier Supprimé : C:\Windows\System32\Tasks\NCH Software Fichier Supprimé : C:\Windows\System32\Tasks\ProtectedSearch ***** [ Raccourcis ] ***** ***** [ Registre ] ***** [#] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5424F33D-43C8-4F72-AA8F-82F0E51D94BC} Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{93DB-0E9758B0D131_PCS_Alcatel_Union}_is1 Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Clé Supprimée : HKCU\Software\Myfree Codec Clé Supprimée : HKCU\Software\NCH Software Clé Supprimée : HKLM\Software\HDvid Codec V1 Clé Supprimée : HKLM\Software\Myfree Codec Clé Supprimée : HKLM\Software\NCH Software Clé Supprimée : HKLM\Software\Uniblue Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094 Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536 Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC ***** [ Navigateurs ] ***** -\\ Internet Explorer v10.0.9200.16750 -\\ Mozilla Firefox v26.0 (fr) [ Fichier : C:\Users\xelos\AppData\Roaming\Mozilla\Firefox\Profiles\1r5rnw6r.default-1371823652693\prefs.js ] -\\ Google Chrome v31.0.1650.63 [ Fichier : C:\Users\xelos\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [20481 octets] - [27/09/2013 15:30:57] AdwCleaner[R1].txt - [3491 octets] - [06/01/2014 13:07:39] AdwCleaner[s0].txt - [19742 octets] - [27/09/2013 15:32:48] AdwCleaner[s1].txt - [3327 octets] - [06/01/2014 13:08:34] ########## EOF - C:\AdwCleaner\AdwCleaner[s1].txt - [3387 octets] ########## -
[Résolu] Analyse rapport HijackThis
xelos a répondu à un(e) sujet de xelos dans Analyses et éradication malwares
j'ai fixé au lieu d'editer le rapport, j'ai rescanné tout de même voici le rapport: # AdwCleaner v3.016 - Rapport créé le 06/01/2014 à 13:20:20 # Mis à jour le 23/12/2013 par Xplode # Système d'exploitation : Windows 7 Ultimate Service Pack 1 (32 bits) # Nom d'utilisateur : xelos - EMACHINE # Exécuté depuis : C:\Users\xelos\Downloads\adwcleaner.exe # Option : Scanner ***** [ Services ] ***** ***** [ Fichiers / Dossiers ] ***** Fichier Présent : C:\Windows\System32\Tasks\NCH Software Fichier Présent : C:\Windows\System32\Tasks\ProtectedSearch ***** [ Raccourcis ] ***** ***** [ Registre ] ***** ***** [ Navigateurs ] ***** -\\ Internet Explorer v10.0.9200.16750 -\\ Mozilla Firefox v26.0 (fr) [ Fichier : C:\Users\xelos\AppData\Roaming\Mozilla\Firefox\Profiles\1r5rnw6r.default-1371823652693\prefs.js ] -\\ Google Chrome v31.0.1650.63 [ Fichier : C:\Users\xelos\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [20481 octets] - [27/09/2013 15:30:57] AdwCleaner[R1].txt - [3491 octets] - [06/01/2014 13:07:39] AdwCleaner[R2].txt - [1047 octets] - [06/01/2014 13:20:20] AdwCleaner[s0].txt - [19742 octets] - [27/09/2013 15:32:48] AdwCleaner[s1].txt - [3467 octets] - [06/01/2014 13:08:34] ########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1228 octets] ########## -
[Résolu] Analyse rapport HijackThis
xelos a répondu à un(e) sujet de xelos dans Analyses et éradication malwares
je poste le rapport adwcleaner ? -
[Résolu] Analyse rapport HijackThis
xelos a répondu à un(e) sujet de xelos dans Analyses et éradication malwares
j'espère qu'il n'est pas trop gros pour le post... ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.9 (01.01.2014:1) OS: Windows 7 Ultimate x86 Ran by xelos on 06/01/2014 at 12:47:10,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\hdvid codec v1 ~~~ Files Successfully deleted: [File] "C:\end" ~~~ Folders Successfully deleted: [Folder] "C:\Users\xelos\AppData\Roaming\pdfforge" Successfully deleted: [Folder] "C:\Program Files\hdvid codec v1" Successfully deleted: [Folder] "C:\Program Files\myfree codec" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue" Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{04A46DA8-1D24-497F-A1C1-6265927B6934} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{082A6E99-6202-43F0-AE6C-9A1D9E818694} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{11B8EDB1-917F-41B7-8E94-41E623243C0C} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{1400D0EE-11C0-43AE-95A4-4846A6E8F2A1} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{14610E37-3543-43F5-BBA0-7E31AEB3AFBE} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{173C9D6E-875C-4999-B839-50F780477D68} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{1C7AD0BC-E3C7-41BA-9D69-7A5FDB06B439} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{1CBBBB7F-E8DF-4774-9D8C-62C46FD665DA} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{1D97CBEC-0479-4835-9D95-46D988D70951} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{226E2D1F-9556-4AEF-9B87-C700D76149DE} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{23D4996C-7CE3-4384-8994-0E46198F14FA} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{2A339AFA-8653-415A-A301-8235C9158C50} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{34A33183-42BE-408A-A7B2-AD3C8A848F3A} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{35D1448C-8D76-4FAF-B8A3-57B2C4B8E9EA} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{3B404EBC-0697-4185-8431-5ACA785D97FD} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{417521D0-9C91-44C8-953D-0A10209083D3} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{423A134B-73BA-437F-A2EC-D4F80C5FD670} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{46D283BA-BDFC-4118-BC49-BE48713945BB} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{48C5638C-A1AE-480D-A083-49863F52B039} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{49E0ADDD-5D17-4C28-A859-640434C0ABC4} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{577F47B7-6004-4033-B6AE-2C514175B58E} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{5BF3B9A0-5E5D-457D-A545-546BD95A2C68} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{5F773928-0467-4DC8-A729-A19F81D6CAE6} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{606D0A3A-3123-4E6E-BA5D-83563AAA9ECB} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{62214856-A7BC-459F-A56D-A548AB8930B3} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{64177129-DC4C-43AE-9A62-48C3F5C959C3} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{688873BD-14B0-41AA-86CF-377E52CAF4C3} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{6974714D-D78E-45F8-8C7E-DF7F46940B16} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{6F99068C-A6B0-4E9E-82DE-E65F424A57C5} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{6FA5EB5D-CB4F-4656-9402-F910DFAE4C8D} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{7031F477-73C5-4948-946F-7BE40B6C1947} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{714477D6-3076-4C1B-AE7B-E5D85C0C18D6} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{72E8B926-C746-4BC5-9795-7913C4C02E6D} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{7906C1B4-B09F-4B67-B194-8FA806453235} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{7A59291E-7FA0-4CF7-9608-31AE57398DCA} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{7E234378-80AB-44A6-8D3A-3376E53A1083} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{7FE6DC77-657A-4FE8-8B58-1DFC4188F984} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{8706D8C1-59D2-4082-8CE4-58113B8BD064} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{88A231F7-BCD9-4DA9-A72D-18D79BF4816B} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{8BC19B82-75EE-480B-A1F3-25DBA1A518F8} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{8E894438-5404-4C65-B0E6-085AD0B9EDD7} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{93B1D728-C99C-4C7A-BD63-61C312F0EC04} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{9BD1F723-DABE-454A-AAB8-EC9B78A0A120} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{A27197CE-B504-461B-8630-2A7BD3514757} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{A6AF499A-449D-4080-A92E-7BD0FD7B7B5D} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{A6CF8F50-AEC3-4A9E-9733-0CFB3F0535BA} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{AC1BA01E-D92C-494F-9DF6-2F3D35F26EA0} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{AD053366-08A9-4DEF-8B7F-23EC2DCEE71F} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{AF9B29B1-8D77-4485-B2C2-6B8BF88D8DE7} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{B04F9AF6-53B5-4077-BA6B-CEA5C0F8582F} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{B20BE67D-DB34-4074-B52D-0757E0385DA8} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{B3238E70-CD5A-41A0-86A8-433DD7901CD8} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{BBCF7CE3-8929-453D-B193-9171745CA1B1} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{BBF8D25C-F954-43D2-A27D-E2BFAB5ED5C8} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{BDB9AA59-266D-4B02-B083-342A44F60F20} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{BDC99421-6D3E-4ECB-A526-EF2F422D5638} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{BEB4BE54-E435-4EB7-8847-7C20C1E4BA31} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{C238B0AD-25CD-4D73-8727-E5127E4322F3} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{C5733BCF-839E-438A-B987-E37FA5C7F6AC} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{C910A8FD-6F8F-4D1D-AEFF-79AC84760686} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{D4C685CB-DFBF-477B-9346-1D3926FC3199} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{DF6BC8E9-334C-4628-9B4F-84AF3082145E} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{DF79531C-9A3F-4792-A6EC-31E1ABB617A1} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{E03B6922-6612-4C78-B54B-E4424D25AD0F} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{EF80F6B7-B487-44E7-9614-50B54DB032BD} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{F3E4EDA6-CEE5-437A-8819-BAAE31D4D4B9} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{F4CDFC72-90DF-4259-A049-EF17A87BC8A2} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{F6096A4D-BCBE-4801-B50D-D98DB4617477} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{F72C4CCD-259E-4557-AFBB-3115D5754412} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{F9E7BE37-41FF-475E-85C8-F76B917F0893} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{FB0F9F3C-ACA3-45B1-8930-8DD3B31EDCFB} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{FE2DEC27-0A41-4A5D-A749-6221D119ABEC} Successfully deleted: [Empty Folder] C:\Users\xelos\appdata\local\{FEF569A9-D3DD-4E10-8C24-CB78F2C66826} ~~~ FireFox Successfully deleted: [File] C:\Users\xelos\AppData\Roaming\mozilla\firefox\profiles\1r5rnw6r.default-1371823652693\extensions\hdvc3@hdvidcodec.com.xpi Emptied folder: C:\Users\xelos\AppData\Roaming\mozilla\firefox\profiles\1r5rnw6r.default-1371823652693\minidumps [95 files] ~~~ Chrome Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\dnllcmllkjofnojidnaknldfehfhehoo ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 06/01/2014 at 12:50:45,14 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -
[Résolu] Analyse rapport HijackThis
xelos a répondu à un(e) sujet de xelos dans Analyses et éradication malwares
Merci pour la rapidité de la réponse, j'ai donc installé et effectué le scan, il est resté bloqué a 15% tout en me faisant un rapport complet disponible sur ce lien: http://cjoint.com/?3AgmJiCWq3s Vivement la suite... merci -
Bonjour, je ne suis pas sur de poster au bon endroit alors pardonnez moi, mais je cherche à analyser ce rapport hijackthis, si quelqu'un peut m'aider, merci beaucoup. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 11:13:29, on 06/01/2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16750) FIREFOX: 26.0 (fr) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe D:\programmes\avast\AvastUI.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe D:\programmes\daemontool\DAEMON Tools Lite\DTLite.exe C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe D:\programmes\magellan\VPLite\VantagePoint Lite.exe C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe C:\Users\xelos\Downloads\HijackThis.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\DllHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://globulos.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\programmes\avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\programmes\avast\aswWebRepIE.dll O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [avast] "D:\programmes\avast\avastUI.exe" /nogui O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [sDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" O4 - HKCU\..\Run: [mRouterConfig] "C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\programmes\daemontool\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [spybot-S&D Cleaning] "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean O4 - HKCU\..\Run: [VantagePointLite.exe] "D:\programmes\magellan\VPLite\VantagePoint Lite.exe" O4 - HKCU\..\Run: [Facebook Update] "C:\Users\xelos\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: (no name) - {5500ac19-e026-444c-8097-6208760b1eca} - (no file) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: skyline - {3A4F9195-65A8-11D5-85C1-0001023952C1} - C:\Users\xelos\AppData\Local\Skyline\TerraExplorer\TerraExplorerX.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @appmgmts.dll,-3250 (AppMgmt) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: avast! Antivirus - AVAST Software - D:\programmes\avast\AvastSvc.exe O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\cscsvc.dll,-200 (CscService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\Program Files\ma-config.com\maconfservice.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\peerdistsvc.dll,-9000 (PeerDistSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (StiSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe -- End of file - 22391 bytes
-
Bonjour à tous je poste un rapport Hijack afin d'analyse, por ceux qui voudront bien m'aider, mais j'ai plutôt l'impression d'avoir un soucis avec ma carte graphique (PC plante ecran bleu, ou violet ou gris ca dépend) Voici ma config: Windows XP Professionnel (build 2600) Service Pack 2 Carte mère SMBios version 2.4 ASUSTeK Computer INC. M2N-E SLI 1.XX Bios: Phoenix Technologies, LTD ASUS M2N-E SLI ACPI BIOS Revision 1102 09/11/2007 taille: 512Kb Chipset Northbridge: NVIDIA nForce4 Southbridge: NVIDIA nForce4 MCP Processeur AMD Athlon 64 X2 4200+ Windsor Socket AM2 (940) (@90 nm) 2200 Mhz ( L1I: 2 x 64 Ko, L1D: 2 x 64 Ko, L2: 2 x 512 Ko ) Mémoire Mémoire physique totale: 2048 Mo, Type: DDR2, @315.9MHz, 5.0-5-5-15-2T DDR2 Kingmax Semiconductor KLCD48F-A8KB5 1024 Mo PC2-5300 (333 Mhz) DDR2 Kingmax Semiconductor KLCD48F-A8KB5 1024 Mo PC2-5300 (333 Mhz) Carte Graphique nVidia Corporation G86 [GeForce 8500 GT] (512 Mo) DD: Hitachi HDP725025GLA380 (232.88Go)et Hitachi HDS721616PLA380 (153.38Go) Mon rapport HT: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:21:29, on 21/11/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe D:\avast\aswUpdSv.exe D:\avast\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\RunDll32.exe D:\programes\webcam\LogiTray.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe D:\avast\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\WINDOWS\System32\FTRTSVC.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\LVComS.exe D:\programes\cd burner\CDBurnerXP\NMSAccessU.exe C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\ctfmon.exe D:\programes\Alcohol 120\StarWind\StarWindServiceAE.exe C:\Program Files\Messenger\Msmsgs.exe C:\WINDOWS\system32\svchost.exe D:\programes\daemon tools\DAEMON Tools Lite\DTLite.exe D:\securite\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\wuauclt.exe D:\avast\ashMaiSv.exe D:\avast\ashWebSv.exe D:\programes\hijachthis\HijackThis.exe D:\programes\firefox\firefox.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/search?q=%s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL (file missing) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\securite\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd O4 - HKLM\..\Run: [LogitechVideoRepair] D:\programes\webcam\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] D:\programes\webcam\LogiTray.exe O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "D:\quicktime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [avast!] D:\avast\ashDisp.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\securite\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Big Boss\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background O4 - HKCU\..\Run: [AlcoholAutomount] "D:\programes\Alcohol 120\axcmd.exe" /automount O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\programes\daemon tools\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [spybotSD TeaTimer] D:\securite\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\msagent" (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_07] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'SERVICE RÉSEAU') O4 - Startup: GigaTribe.lnk = D:\GigaTribe\gigatribe.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = D:\programes\office2003\Office\OSA9.EXE O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\securite\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\securite\SPYBOT~1\SDHelper.dll O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/...can8/oscan8.cab O18 - Protocol: skyline - {3A4F9195-65A8-11D5-85C1-0001023952C1} - C:\Program Files\Skyline\TerraExplorer\TerraExplorerX.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\avast\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - D:\avast\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - D:\avast\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - D:\avast\ashWebSv.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe O23 - Service: Service Google Update (gupdate1c9e67dfe6ac862) (gupdate1c9e67dfe6ac862) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe (file missing) O23 - Service: NMSAccessU - Unknown owner - D:\programes\cd burner\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA-OMEGA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\programes\Alcohol 120\StarWind\StarWindServiceAE.exe -- End of file - 10066 bytes Merci à tous