.
--------------------------\\\ Start Report Of HijackThis ---------------
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:39, on 11/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Download Manager\bin\IDMan.exe
C:\Program Files\Internet Download Manager\bin\IEMonitor.exe
C:\DOCUME~1\MOHANN~1\LOCALS~1\Temp\bntoz\runn.exe
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\MOHANN~1\LOCALS~1\Temp\bntoz\HijackThis.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\bin\IDMIECC.dll
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\bin\IEGetAll.htm
O8 - Extra context menu item: Download FLV video with IDM - C:\Program Files\Internet Download Manager\bin\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\bin\IEExt.htm
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
--
End of file - 1658 bytes
.
.
--------------------------\\\ End Report Of Of HijackThis ---------------
.
.
.
.
--------------------------\\\ Start Report Of Running Processes ---------------
.
==================================================
Process Name : smss.exe
ProcessID : 500
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Windows NT Session Manager
Company : Microsoft Corporation
Window Title :
File Size : 50,688
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:36 ص
Filename : C:\WINDOWS\System32\smss.exe
Base Address : 0x48580000
Created On : 29/11/2008 02:20:38 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 372 K
Mem Usage Peak : 692 K
Page Faults : 293
Pagefile Usage : 164 K
Pagefile Peak Usage : 1704 K
File Attributes : A
==================================================
==================================================
Process Name : csrss.exe
ProcessID : 560
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Client Server Runtime Process
Company : Microsoft Corporation
Window Title :
File Size : 6,144
File Created Date : 03/08/2004 11:56:50 م
File Modified Date : 14/04/2008 12:12:15 ص
Filename : C:\WINDOWS\system32\csrss.exe
Base Address : 0x4A680000
Created On : 29/11/2008 02:20:41 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3624 K
Mem Usage Peak : 4468 K
Page Faults : 17618
Pagefile Usage : 1724 K
Pagefile Peak Usage : 2628 K
File Attributes : A
==================================================
==================================================
Process Name : winlogon.exe
ProcessID : 584
Priority : High
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2113)
Description : Windows NT Logon Application
Company : Microsoft Corporation
Window Title :
File Size : 507,904
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:39 ص
Filename : C:\WINDOWS\system32\winlogon.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:43 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3876 K
Mem Usage Peak : 12020 K
Page Faults : 7103
Pagefile Usage : 7120 K
Pagefile Peak Usage : 8392 K
File Attributes : A
==================================================
==================================================
Process Name : services.exe
ProcessID : 628
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Services and Controller app
Company : Microsoft Corporation
Window Title :
File Size : 108,544
File Created Date : 03/08/2004 11:56:56 م
File Modified Date : 14/04/2008 12:12:34 ص
Filename : C:\WINDOWS\system32\services.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:46 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3428 K
Mem Usage Peak : 3612 K
Page Faults : 1329
Pagefile Usage : 1748 K
Pagefile Peak Usage : 2264 K
File Attributes : A
==================================================
==================================================
Process Name : lsass.exe
ProcessID : 640
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2113)
Description : LSA Shell (Export Version)
Company : Microsoft Corporation
Window Title :
File Size : 13,312
File Created Date : 03/08/2004 11:56:52 م
File Modified Date : 14/04/2008 12:12:24 ص
Filename : C:\WINDOWS\system32\lsass.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:46 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1700 K
Mem Usage Peak : 6344 K
Page Faults : 3073
Pagefile Usage : 4056 K
Pagefile Peak Usage : 4292 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 792
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:36 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:49 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 4784 K
Mem Usage Peak : 4836 K
Page Faults : 1371
Pagefile Usage : 3036 K
Pagefile Peak Usage : 23336 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 852
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:36 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:49 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 4640 K
Mem Usage Peak : 4640 K
Page Faults : 1325
Pagefile Usage : 2160 K
Pagefile Peak Usage : 2176 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 924
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:36 ص
Filename : C:\WINDOWS\System32\svchost.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:50 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 22356 K
Mem Usage Peak : 28092 K
Page Faults : 16406
Pagefile Usage : 14216 K
Pagefile Peak Usage : 19884 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1020
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:36 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:50 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3864 K
Mem Usage Peak : 3928 K
Page Faults : 1602
Pagefile Usage : 1680 K
Pagefile Peak Usage : 1776 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1092
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:36 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:50 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 4780 K
Mem Usage Peak : 4784 K
Page Faults : 1268
Pagefile Usage : 2012 K
Pagefile Peak Usage : 2036 K
File Attributes : A
==================================================
==================================================
Process Name : spoolsv.exe
ProcessID : 1372
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-0852)
Description : Spooler SubSystem App
Company : Microsoft Corporation
Window Title :
File Size : 57,856
File Created Date : 09/09/2006 12:50:54 ص
File Modified Date : 14/04/2008 12:12:36 ص
Filename : C:\WINDOWS\system32\spoolsv.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:20:55 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 4444 K
Mem Usage Peak : 4472 K
Page Faults : 1266
Pagefile Usage : 3044 K
Pagefile Peak Usage : 3244 K
File Attributes : A
==================================================
==================================================
Process Name : Explorer.EXE
ProcessID : 1616
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.5512 (xpsp.080413-2105)
Description : Windows Explorer
Company : Microsoft Corporation
Window Title : My Documents
File Size : 1,033,728
File Created Date : 09/09/2006 12:48:44 ص
File Modified Date : 14/04/2008 12:12:19 ص
Filename : C:\WINDOWS\Explorer.EXE
Base Address : 0x01000000
Created On : 29/11/2008 02:20:56 م
Visible Windows : 3
Hidden Windows : 29
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 19512 K
Mem Usage Peak : 20112 K
Page Faults : 25600
Pagefile Usage : 11616 K
Pagefile Peak Usage : 14252 K
File Attributes : A
==================================================
==================================================
Process Name : STacSV.exe
ProcessID : 364
Priority : Normal
Product Name : C-Major Audio
Version : 1.0.5511.0 nd595 cp1
Description : STacSV Module
Company : SigmaTel, Inc.
Window Title :
File Size : 94,208
File Created Date : 14/11/2008 02:32:10 م
File Modified Date : 06/05/2007 09:11:36 ص
Filename : C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
Base Address : 0x00400000
Created On : 29/11/2008 02:21:03 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3816 K
Mem Usage Peak : 3828 K
Page Faults : 1003
Pagefile Usage : 2548 K
Pagefile Peak Usage : 2608 K
File Attributes :
==================================================
==================================================
Process Name : alg.exe
ProcessID : 984
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-0852)
Description : Application Layer Gateway Service
Company : Microsoft Corporation
Window Title :
File Size : 44,544
File Created Date : 03/08/2004 11:56:48 م
File Modified Date : 14/04/2008 12:12:12 ص
Filename : C:\WINDOWS\System32\alg.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:21:21 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3892 K
Mem Usage Peak : 3892 K
Page Faults : 1013
Pagefile Usage : 1488 K
Pagefile Peak Usage : 1500 K
File Attributes : A
==================================================
==================================================
Process Name : wscntfy.exe
ProcessID : 692
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2108)
Description : Windows Security Center Notification App
Company : Microsoft Corporation
Window Title :
File Size : 13,824
File Created Date : 03/08/2004 11:56:58 م
File Modified Date : 14/04/2008 12:12:41 ص
Filename : C:\WINDOWS\system32\wscntfy.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:36:05 م
Visible Windows : 0
Hidden Windows : 1
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 1984 K
Mem Usage Peak : 1984 K
Page Faults : 505
Pagefile Usage : 552 K
Pagefile Peak Usage : 552 K
File Attributes : A
==================================================
==================================================
Process Name : firefox.exe
ProcessID : 2432
Priority : Normal
Product Name : Firefox
Version : 1.9.0.3
Description : Firefox
Company : Mozilla Corporation
Window Title : ما معنى هذه الرسالة؟ - زيزوووم للأمن والحمايه - Mozilla Firefox
File Size : 307,712
File Created Date : 27/11/2008 05:46:00 ص
File Modified Date : 25/09/2008 01:51:54 م
Filename : C:\Program Files\Mozilla Firefox\firefox.exe
Base Address : 0x00400000
Created On : 29/11/2008 02:37:22 م
Visible Windows : 1
Hidden Windows : 10
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 53744 K
Mem Usage Peak : 54184 K
Page Faults : 42288
Pagefile Usage : 42324 K
Pagefile Peak Usage : 42772 K
File Attributes : A
==================================================
==================================================
Process Name : IDMan.exe
ProcessID : 2472
Priority : Normal
Product Name : Internet Download Manager (IDM)
Version : 5.14.4.0
Description : Internet Download Manager (IDM)
Company : Tonec Inc.
Window Title :
File Size : 2,606,512
File Created Date : 01/09/2008 12:56:46 م
File Modified Date : 22/11/2008 12:10:16 م
Filename : C:\Program Files\Internet Download Manager\bin\IDMan.exe
Base Address : 0x00400000
Created On : 29/11/2008 02:38:34 م
Visible Windows : 0
Hidden Windows : 5
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 9972 K
Mem Usage Peak : 10408 K
Page Faults : 4032
Pagefile Usage : 3896 K
Pagefile Peak Usage : 4420 K
File Attributes : A
==================================================
==================================================
Process Name : IEMonitor.exe
ProcessID : 2040
Priority : Normal
Product Name : IEMonitor Application
Version : 5, 12, 8, 0
Description : Internet Download Manager agent for click monitoring in IE-based browsers
Company : Tonec Inc.
Window Title :
File Size : 251,312
File Created Date : 01/09/2008 12:56:41 م
File Modified Date : 18/02/2008 01:01:01 م
Filename : C:\Program Files\Internet Download Manager\bin\IEMonitor.exe
Base Address : 0x00400000
Created On : 29/11/2008 02:38:35 م
Visible Windows : 0
Hidden Windows : 1
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 4332 K
Mem Usage Peak : 4340 K
Page Faults : 1120
Pagefile Usage : 2396 K
Pagefile Peak Usage : 2396 K
File Attributes : A
==================================================
==================================================
Process Name : runn.exe
ProcessID : 2460
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 71,680
File Created Date : 29/11/2008 12:39:06 م
File Modified Date : 31/01/2008 11:24:25 م
Filename : C:\DOCUME~1\MOHANN~1\LOCALS~1\Temp\bntoz\runn.exe
Base Address : 0x00400000
Created On : 29/11/2008 02:39:06 م
Visible Windows : 0
Hidden Windows : 0
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 2060 K
Mem Usage Peak : 2068 K
Page Faults : 588
Pagefile Usage : 592 K
Pagefile Peak Usage : 664 K
File Attributes : A
==================================================
==================================================
Process Name : cmd.exe
ProcessID : 3220
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Windows Command Processor
Company : Microsoft Corporation
Window Title :
File Size : 389,120
File Created Date : 09/09/2006 06:31:35 ص
File Modified Date : 14/04/2008 12:12:14 ص
Filename : C:\WINDOWS\system32\cmd.exe
Base Address : 0x4AD00000
Created On : 29/11/2008 02:39:06 م
Visible Windows : 0
Hidden Windows : 1
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 2836 K
Mem Usage Peak : 2900 K
Page Faults : 805
Pagefile Usage : 2020 K
Pagefile Peak Usage : 2096 K
File Attributes : A
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 2748
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2108)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 14/11/2008 11:51:59 ص
File Modified Date : 14/04/2008 12:12:40 ص
Filename : C:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 29/11/2008 02:39:07 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 5592 K
Mem Usage Peak : 5592 K
Page Faults : 1431
Pagefile Usage : 2872 K
Pagefile Peak Usage : 2872 K
File Attributes : A
==================================================
==================================================
Process Name : CProcess.exe
ProcessID : 2784
Priority : Normal
Product Name : CurrProcess
Version : 1.11
Description : CurrProcess
Company : NirSoft
Window Title :
File Size : 35,840
File Created Date : 29/11/2008 12:39:06 م
File Modified Date : 14/07/2005 05:46:34 ص
Filename : C:\DOCUME~1\MOHANN~1\LOCALS~1\Temp\bntoz\CProcess.exe
Base Address : 0x00400000
Created On : 29/11/2008 02:39:07 م
Visible Windows : 0
Hidden Windows : 0
User Name : SICOWIN\MoHaNNaD MaKlAD
Mem Usage : 2120 K
Mem Usage Peak : 2128 K
Page Faults : 689
Pagefile Usage : 856 K
Pagefile Peak Usage : 856 K
File Attributes : A
==================================================
.
.
--------------------------\\\ End Report Of Running Processes ---------------
.
.
.
.
--------------------------\\\ Windows XP Startup List ---------------
.
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
autocheck autochk *
Auto Check Utility
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\autochk.exe
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
rdpclip
rdpclip
RDP Clip Monitor
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
Userinit Logon Application
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Explorer.exe
Explorer.exe
Windows Explorer
Microsoft Corporation
6.00.2900.5512
c:\windows\explorer.exe
.
.
----------- End Report ---------------