Bien, tout d'abord merci pour les réponses rapides, voilà où j'en suis :
J'ai essayé de suivre les instructions dans l'ordre, mais j'ai lancé deux fois Malwarebytes.
- Rhosts effectué (ça ne prend même pas une seconde, normal ?)
- Vundofix ne trouve rien du tout... (essayé 3 fois)
- J'ai ensuite lancé malwarebytes une première fois. Il trouve une vingtaine d'objet, j'ai tout mis en quarantaine, sauf ce qui concernait mon trojan, pour laisser le soin à Virtumundobegone de s'en charger (désolé, oublié de sauvegarder ce rapport...)
- Virtumundobegone le trouve et redémarre mon ordi (rapport en dessous). Je le relance plusieurs fois, il ne trouve plus rien.
- Je relance malwarebytes, qui bizarrement le retrouve. Cette fois, je le supprime.
Voici les rapports :
-----------
VBG
[05/27/2008, 15:57:28] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Nicolas Prenant\Bureau\VirtumundoBeGone.exe" )
[05/27/2008, 15:57:37] - Detected System Information:
[05/27/2008, 15:57:37] - Windows Version: 5.1.2600, Service Pack 2
[05/27/2008, 15:57:37] - Current Username: Nicolas Prenant (Admin)
[05/27/2008, 15:57:37] - Windows is in NORMAL mode.
[05/27/2008, 15:57:37] - Searching for Browser Helper Objects:
[05/27/2008, 15:57:37] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/27/2008, 15:57:37] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/27/2008, 15:57:37] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/27/2008, 15:57:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/27/2008, 15:57:37] - No filename found. Continuing.
[05/27/2008, 15:57:37] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[05/27/2008, 15:57:37] - BHO 5: {F4D76F01-7896-458a-890F-E1F05C46069F} (Ask Toolbar BHO)
[05/27/2008, 15:57:37] - BHO 6: {F9DF827A-8FA7-48A3-B268-CA4DB563EA40} ()
[05/27/2008, 15:57:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/27/2008, 15:57:37] - Checking for HKLM\...\Winlogon\Notify\xxYrRKCu
[05/27/2008, 15:57:37] - Found: HKLM\...\Winlogon\Notify\xxYrRKCu - This is probably Virtumundo.
[05/27/2008, 15:57:37] - Assigning {F9DF827A-8FA7-48A3-B268-CA4DB563EA40} MSEvents Object
[05/27/2008, 15:57:37] - BHO list has been changed! Starting over...
[05/27/2008, 15:57:37] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/27/2008, 15:57:37] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/27/2008, 15:57:37] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/27/2008, 15:57:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/27/2008, 15:57:37] - No filename found. Continuing.
[05/27/2008, 15:57:37] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[05/27/2008, 15:57:37] - BHO 5: {F4D76F01-7896-458a-890F-E1F05C46069F} (Ask Toolbar BHO)
[05/27/2008, 15:57:37] - BHO 6: {F9DF827A-8FA7-48A3-B268-CA4DB563EA40} (MSEvents Object)
[05/27/2008, 15:57:38] - ALERT: Found MSEvents Object!
[05/27/2008, 15:57:38] - Finished Searching Browser Helper Objects
[05/27/2008, 15:57:38] - *** Detected MSEvents Object
[05/27/2008, 15:57:38] - Trying to remove MSEvents Object...
[05/27/2008, 15:57:39] - Terminating Process: IEXPLORE.EXE
[05/27/2008, 15:57:39] - Terminating Process: RUNDLL32.EXE
[05/27/2008, 15:57:39] - Disabling Automatic Shell Restart
[05/27/2008, 15:57:39] - Terminating Process: EXPLORER.EXE
[05/27/2008, 15:57:39] - Suspending the NT Session Manager System Service
[05/27/2008, 15:57:40] - Terminating Windows NT Logon/Logoff Manager
[05/27/2008, 15:57:40] - Re-enabling Automatic Shell Restart
[05/27/2008, 15:57:40] - File to disable: C:\WINDOWS\system32\xxYrRKCu.dll
[05/27/2008, 15:57:40] - Renaming C:\WINDOWS\system32\xxYrRKCu.dll -> C:\WINDOWS\system32\xxYrRKCu.dll.vir
[05/27/2008, 15:57:40] - File successfully renamed!
[05/27/2008, 15:57:40] - Removing HKLM\...\Browser Helper Objects\{F9DF827A-8FA7-48A3-B268-CA4DB563EA40}
[05/27/2008, 15:57:40] - Removing HKCR\CLSID\{F9DF827A-8FA7-48A3-B268-CA4DB563EA40}
[05/27/2008, 15:57:40] - Adding Kill Bit for ActiveX for GUID: {F9DF827A-8FA7-48A3-B268-CA4DB563EA40}
[05/27/2008, 15:57:40] - Deleting ATLEvents/MSEvents Registry entries
[05/27/2008, 15:57:40] - Removing HKLM\...\Winlogon\Notify\xxYrRKCu
[05/27/2008, 15:57:40] - Searching for Browser Helper Objects:
[05/27/2008, 15:57:40] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/27/2008, 15:57:40] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/27/2008, 15:57:40] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/27/2008, 15:57:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/27/2008, 15:57:40] - No filename found. Continuing.
[05/27/2008, 15:57:40] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[05/27/2008, 15:57:40] - BHO 5: {F4D76F01-7896-458a-890F-E1F05C46069F} (Ask Toolbar BHO)
[05/27/2008, 15:57:40] - Finished Searching Browser Helper Objects
[05/27/2008, 15:57:40] - Finishing up...
[05/27/2008, 15:57:40] - A restart is needed.
[05/27/2008, 15:57:53] - Attempting to Restart via STOP error (Blue Screen!)
[05/27/2008, 16:06:45] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Nicolas Prenant\Bureau\VirtumundoBeGone.exe" )
[05/27/2008, 16:06:47] - Detected System Information:
[05/27/2008, 16:06:47] - Windows Version: 5.1.2600, Service Pack 2
[05/27/2008, 16:06:47] - Current Username: Nicolas Prenant (Admin)
[05/27/2008, 16:06:47] - Windows is in NORMAL mode.
[05/27/2008, 16:06:47] - Searching for Browser Helper Objects:
[05/27/2008, 16:06:47] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/27/2008, 16:06:47] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/27/2008, 16:06:47] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/27/2008, 16:06:47] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/27/2008, 16:06:47] - No filename found. Continuing.
[05/27/2008, 16:06:47] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[05/27/2008, 16:06:47] - BHO 5: {F4D76F01-7896-458a-890F-E1F05C46069F} (Ask Toolbar BHO)
[05/27/2008, 16:06:47] - Finished Searching Browser Helper Objects
[05/27/2008, 16:06:47] - Finishing up...
[05/27/2008, 16:06:47] - Nothing found! Exiting...
[05/27/2008, 16:07:01] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Nicolas Prenant\Bureau\VirtumundoBeGone.exe" )
[05/27/2008, 16:07:02] - Detected System Information:
[05/27/2008, 16:07:02] - Windows Version: 5.1.2600, Service Pack 2
[05/27/2008, 16:07:02] - Current Username: Nicolas Prenant (Admin)
[05/27/2008, 16:07:02] - Windows is in NORMAL mode.
[05/27/2008, 16:07:02] - Searching for Browser Helper Objects:
[05/27/2008, 16:07:02] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/27/2008, 16:07:02] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/27/2008, 16:07:02] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/27/2008, 16:07:02] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/27/2008, 16:07:02] - No filename found. Continuing.
[05/27/2008, 16:07:02] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[05/27/2008, 16:07:02] - BHO 5: {F4D76F01-7896-458a-890F-E1F05C46069F} (Ask Toolbar BHO)
[05/27/2008, 16:07:02] - Finished Searching Browser Helper Objects
[05/27/2008, 16:07:02] - Finishing up...
[05/27/2008, 16:07:02] - Nothing found! Exiting...
[05/27/2008, 16:07:10] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Nicolas Prenant\Bureau\VirtumundoBeGone.exe" )
[05/27/2008, 16:07:15] - Detected System Information:
[05/27/2008, 16:07:15] - Windows Version: 5.1.2600, Service Pack 2
[05/27/2008, 16:07:15] - Current Username: Nicolas Prenant (Admin)
[05/27/2008, 16:07:15] - Windows is in NORMAL mode.
[05/27/2008, 16:07:15] - Searching for Browser Helper Objects:
[05/27/2008, 16:07:15] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/27/2008, 16:07:15] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/27/2008, 16:07:15] - BHO 3: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/27/2008, 16:07:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/27/2008, 16:07:15] - No filename found. Continuing.
[05/27/2008, 16:07:15] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
[05/27/2008, 16:07:15] - BHO 5: {F4D76F01-7896-458a-890F-E1F05C46069F} (Ask Toolbar BHO)
[05/27/2008, 16:07:15] - Finished Searching Browser Helper Objects
[05/27/2008, 16:07:15] - Finishing up...
[05/27/2008, 16:07:15] - Nothing found! Exiting...
----------------
(Rapport avant suppression)
Malwarebytes' Anti-Malware 1.12
Version de la base de données: 789
Type de recherche: Examen complet (C:\|)
Eléments examinés: 146391
Temps écoulé: 36 minute(s), 45 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 5
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{f9df827a-8fa7-48a3-b268-ca4db563ea40} (Trojan.Vundo) -> No action taken.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Documents and Settings\Nicolas Prenant\Local Settings\Temporary Internet Files\Content.IE5\8FB7E0D9\rasesnet[1].exe (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Nicolas Prenant\Local Settings\Temporary Internet Files\Content.IE5\UL6D416B\wavvsnet[1].exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP154\A0022437.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\xxYrRKCu.dll.vir (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ssqPfEvv.dll (Trojan.Vundo) -> No action taken.
---------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:51:09, on 27/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\lotus\register\remind32.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://format.packardbell.com/...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.tele2.fr/internet/portail/go/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://service1.symantec.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Enregistrement de Lotus SmartSuite version 9.lnk = C:\lotus\register\remind32.exe
O4 - Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.storageguardsoft.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusschlacht.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe