Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:22:32, on 18/12/2011
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:Program Files (x86)Common FilesAVerMediaAVerQuickAVerHIDReceiver.exe
C:Program Files (x86)MotorolaMotoHelperMotoHelperAgent.exe
C:Program Files (x86)RocketDockRocketDock.exe
C:Program Files (x86)Software Informersoftinfo.exe
C:Program Files (x86)SuperCopier2SuperCopier2.exe
C:Program Files (x86)iTunesiTunes.exe
C:Program Files (x86)DeviceVMBrowser Configuration UtilityBCU.exe
C:Program Files (x86)NEC ElectronicsUSB 3.0 Host Controller DriverApplicationnusb3mon.exe
C:PROGRA~2Raptrraptr.exe
C:Program Files (x86)iTunesiTunesHelper.exe
C:PROGRA~2Raptrraptr_im.exe
C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceHelper.exe
C:Program Files (x86)Common FilesAppleApple Application Supportdistnoted.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)DivXDivX UpdateDivXUpdate.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program FilesLogitechSetPointx86SetPoint32.exe
C:Program Files (x86)OriginOrigin.exe
C:Program Files (x86)Free Download Managerfdm.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:Program Files (x86)Combined Community Codec PackMPCmpc-hc.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:WindowsSysWOW64rundll32.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:UsersWarnawakAppDataLocalGoogleChromeApplicationchrome.exe
C:Program Files (x86)Trend MicroHijackThisHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://downloads.phpnuke.org/fr/index.php?rvs=google
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://downloads.phpnuke.org/fr/index.php?rvs=google
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://downloads.phpnuke.org/fr/index.php?rvs=google
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local;192.168.*.*
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:Program Files (x86)DeviceVMBrowser Configuration UtilityAddressBarSearch.dll
R3 - URLSearchHook: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - (no file)
R3 - URLSearchHook: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:Program Files (x86)uTorrentBar_FRprxtbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: uTorrentBar_FR - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:Program Files (x86)uTorrentBar_FRprxtbuTor.dll
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:Program Files (x86)PriceGong2.1.0PriceGongIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:Program Files (x86)ConduitEngineprxConduitEngine.dll
O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~2SPYBOT~1SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program Files (x86)GoogleGoogleToolbarNotifier5.2.4204.1700swg.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:Program Files (x86)Free Download Manageriefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre6binjp2ssv.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:Program Files (x86)ConduitEngineprxConduitEngine.dll
O3 - Toolbar: uTorrentBar_FR Toolbar - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:Program Files (x86)uTorrentBar_FRprxtbuTor.dll
O4 - HKLM..Run: [BCU] "C:Program Files (x86)DeviceVMBrowser Configuration UtilityBCU.exe"
O4 - HKLM..Run: [NUSB3MON] "C:Program Files (x86)NEC ElectronicsUSB 3.0 Host Controller DriverApplicationnusb3mon.exe"
O4 - HKLM..Run: [ATICustomerCare] "C:Program Files (x86)ATIATICustomerCareATICustomerCare.exe"
O4 - HKLM..Run: [APSDaemon] "C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe"
O4 - HKLM..Run: [StartCCC] "C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe" MSRun
O4 - HKLM..Run: [iTunesHelper] "C:Program Files (x86)iTunesiTunesHelper.exe"
O4 - HKLM..RunOnce: [DES2] C:Program Files (x86)gigabyteEnergySaver2des2.exe state
O4 - HKCU..Run: [RocketDock] "C:Program Files (x86)RocketDockRocketDock.exe"
O4 - HKCU..Run: [Software Informer] "C:Program Files (x86)Software Informersoftinfo.exe" -autorun
O4 - HKCU..Run: [Google Update] "C:UsersWarnawakAppDataLocalGoogleUpdateGoogleUpdate.exe" /c
O4 - HKCU..Run: [SuperCopier2.exe] C:Program Files (x86)SuperCopier2SuperCopier2.exe
O4 - HKCU..Run: [Raptr] C:PROGRA~2Raptrraptrstub.exe --startup
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [ccleaner] "C:Program Files (x86)CCleanerCCleaner64.exe" /AUTO
O4 - HKCU..Run: [EADM] "C:Program Files (x86)OriginOrigin.exe" -AutoStart
O4 - HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-19..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUSS-1-5-20..RunOnce: [mctadmin] C:WindowsSystem32mctadmin.exe (User 'SERVICE RÉSEAU')
O4 - Global Startup: iTunes.lnk = C:Program Files (x86)iTunesiTunes.exe
O4 - Global Startup: RocketDock.lnk = C:Program Files (x86)RocketDockRocketDock.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:PROGRA~2MIF5BA~1Office12EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec Free Download Manager -
file://C:Program Files (x86)Free Download Managerdlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager -
file://C:Program Files (x86)Free Download Managerdllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager -
file://C:Program Files (x86)Free Download Managerdlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager -
file://C:Program Files (x86)Free Download Managerdlfvideo.htm
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~2MIF5BA~1Office12REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~2SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~2SPYBOT~1SDHelper.dll
O10 - Unknown file in Winsock LSP: c:program files (x86)common filesmicrosoft sharedwindows livewlidnsp.dll
O10 - Unknown file in Winsock LSP: c:program files (x86)common filesmicrosoft sharedwindows livewlidnsp.dll
O13 - Gopher Prefix:
O15 - Trusted Zone:
www.companyofheroes.com
O15 - Trusted IP range:
http://127.0.0.1
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} ("Ma-Config.com control) -
http://fichiers.touslesdrivers.com/maconfig/MaConfig_4_0_2_0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLMSystemCCSServicesTcpip..{28705E5D-7818-4E33-BCDD-E51EB34F0CEC}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:Program Files (x86)SkypeToolbarsInternet Explorerskypeieplugin.dll
O23 - Service: @%SystemRoot%system32Alg.exe,-112 (ALG) - Unknown owner - C:WindowsSystem32alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:Windowssystem32atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe
O23 - Service: AVerRemote - AVerMedia - C:Program Files (x86)Common FilesAVerMediaServiceAVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:Program Files (x86)Common FilesAVerMediaServiceAVerScheduleService.exe
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:Program Files (x86)DeviceVMBrowser Configuration UtilityBCUService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: DES2 Service for Energy Saving. (DES2 Service) - Unknown owner - C:Program Files (x86)gigabyteEnergySaver2des2svr.exe
O23 - Service: @%SystemRoot%system32efssvc.dll,-100 (EFS) - Unknown owner - C:WindowsSystem32lsass.exe (file missing)
O23 - Service: @%systemroot%system32fxsresm.dll,-118 (Fax) - Unknown owner - C:Windowssystem32fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:Program Files (x86)Common FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program Files (x86)GoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:Program FilesiPodbiniPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:Program FilesCommon FilesLogishrdBluetoothLBTServ.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:Program Filesma-config.comx64maconfservice.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:Program Files (x86)MotorolaMotoHelperMotoHelperService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:WindowsSystem32msdtc.exe (file missing)
O23 - Service: @%SystemRoot%System32netlogon.dll,-102 (Netlogon) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: O&O Defrag - Unknown owner - C:Windowssystem32oodag.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:Windowssystem32PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:Windowssystem32PnkBstrB.exe
O23 - Service: @%systemroot%system32psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: @%systemroot%system32Locator.exe,-2 (RpcLocator) - Unknown owner - C:Windowssystem32locator.exe (file missing)
O23 - Service: @%SystemRoot%system32samsrv.dll,-1 (SamSs) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:Program Files (x86)Spybot - Search & DestroySDWinSec.exe
O23 - Service: @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:WindowsSystem32snmptrap.exe (file missing)
O23 - Service: @%systemroot%system32spoolsv.exe,-1 (Spooler) - Unknown owner - C:WindowsSystem32spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%system32sppsvc.exe,-101 (sppsvc) - Unknown owner - C:Windowssystem32sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:Program Files (x86)Common FilesSteamSteamService.exe
O23 - Service: @%SystemRoot%system32ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:Windowssystem32UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%system32vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: @%SystemRoot%system32vds.exe,-100 (vds) - Unknown owner - C:WindowsSystem32vds.exe (file missing)
O23 - Service: @%systemroot%system32vssvc.exe,-102 (VSS) - Unknown owner - C:Windowssystem32vssvc.exe (file missing)
O23 - Service: @%SystemRoot%system32WatWatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:Windowssystem32WatWatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%system32wbengine.exe,-104 (wbengine) - Unknown owner - C:Windowssystem32wbengine.exe (file missing)
O23 - Service: @%Systemroot%system32wbemwmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:Windowssystem32wbemWmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%Windows Media Playerwmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:Program Files (x86)Windows Media Playerwmpnetwk.exe (file missing)
--
End of file - 16402 bytes