logfile of trend micro hijackthis v2.0.2
scan saved at 02:44:00, on 31/12/2008
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v7.00 (7.00.6000.16762)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\program files\microsoft windows onecare live\antivirus\msmpeng.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\windows\explorer.exe
c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
c:\program files\bandrich\bandluxe hsdpa utility r11\brservice.exe
c:\program files\widcomm\bluetooth software\bin\btwdins.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\program files\microsoft windows onecare live\ochealthmon.exe
c:\program files\yahoo!\softwareupdate\yahooauservice.exe
c:\program files\microsoft windows onecare live\firewall\msfwsvc.exe
c:\windows\system32\winmine.exe
c:\program files\grisoft\avg anti-spyware 7.5\zyzoom.exe
c:\windows\system32\ctfmon.exe
c:\program files\widcomm\bluetooth software\bttray.exe
c:\windows\system32\svchost.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\autorunremover\autorunremover.exe
c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe
c:\documents and settings\user\local settings\temporary internet files\*******.ie5\5dj7rgjp\zyzoom_hijackthis[1].exe
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = 127.0.0.1:8580
r3 - urlsearchhook: Sweetim toolbarurlsearchhook class - {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mghelper.dll
r3 - urlsearchhook: Yahoo! Toolbar - {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Snagit toolbar loader - {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 8\snagitbho.dll
o2 - bho: &yahoo! Toolbar helper - {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
o2 - bho: Askbar bho - {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askbar.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: (no name) - {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - (no file)
o2 - bho: Ssvhelper class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll (file missing)
o2 - bho: (no name) - {b56a7d7d-6927-48c8-a975-17df180c71ac} - (no file)
o2 - bho: Sweetim toolbar helper - {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o2 - bho: Singleinstance class - {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\ytsingleinstance.dll
o3 - toolbar: Snagit - {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 8\snagitieaddin.dll
o3 - toolbar: &google - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll (file missing)
o3 - toolbar: Sweetim toolbar for internet explorer - {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o3 - toolbar: Yahoo! Toolbar - {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
o3 - toolbar: (no name) - {0bf43445-2f28-4351-9252-17fe6e806aa0} - (no file)
o3 - toolbar: Mcafee virusscan - {ba52b914-b692-46c4-b683-905236f6f655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
o3 - toolbar: Ask toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askbar.dll
o4 - hklm\..\run: [!avg anti-spyware] "c:\program files\grisoft\avg anti-spyware 7.5\zyzoom.exe" /minimized
o4 - hkcu\..\run: [uniblue registrybooster 2] c:\program files\registrybooster 2\registrybooster.exe/s /s
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - global startup: Bluetooth.lnk = ?
O7 - hkcu\software\microsoft\windows\currentversion\policies\system, disableregedit=1
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: Save flash - res://c:\program files\unh solutions\flash saving plugin\flashsbutton.dll/210
o8 - extra context menu item: Send to &bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
o9 - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
o9 - extra 'tools' menuitem: Sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
o9 - extra button: Spyware doctor - {2d663d1a-8670-49d9-a1a5-4c56b4e14e84} - c:\windows\system32\shdocvw.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra button: Flash - {43cf38f3-5aec-45a3-ad31-04eb06e9c6ca} - c:\program files\unh solutions\flash saving plugin\flashsbutton.dll (hkcu)
o16 - dpf: {6924091f-cd97-41e1-b1d4-d9079409d413} (imcv1 control) -
o16 - dpf: {b7fdb0c3-4724-46d2-b8db-6fa1dc63f7ca} -
o16 - dpf: {c171ff59-8c55-4796-a398-4f5d02b4c763} -
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash ******) -
o23 - service: Ad-aware 2007 service (aawservice) - unknown owner - c:\program files\lavasoft\ad-aware 2007\aawservice.exe (file missing)
o23 - service: Ares chatroom server (areschatserver) - unknown owner - c:\program files\ares\chatserver.exe (file missing)
o23 - service: Avg anti-spyware guard - grisoft s.r.o. - c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
o23 - service: Bandluxe service (bandluxe_service) - bandrich inc. - c:\program files\bandrich\bandluxe hsdpa utility r11\brservice.exe
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\bin\btwdins.exe
o23 - service: Google updater service (gusvc) - unknown owner - c:\program files\google\common\google updater\googleupdaterservice.exe
o23 - service: Mcafee wsc integration (mcdetect.exe) - mcafee, inc - c:\program files\mcafee.com\agent\mcdetect.exe
o23 - service: Mcafee task scheduler (mctskshd.exe) - mcafee, inc - c:\progra~1\mcafee.com\agent\mctskshd.exe
o23 - service: Mcafee securitycenter update manager (mcupdmgr.exe) - unknown owner - c:\progra~1\mcafee.com\agent\mcupdmgr.exe
o23 - service: Office source engine (ose) - unknown owner - c:\program files\common files\microsoft shared\source engine\ose.exe
o23 - service: Servicelayer - unknown owner - c:\program files\pc connectivity solution\servicelayer.exe
o23 - service: خدمة قارئ مجلة usn بمجلدات مشاركة messenger (usnjsvc) - unknown owner - c:\program files\windows live\messenger\usnsvc.exe
o23 - service: Windows live setup service (wlsetupsvc) - unknown owner - c:\program files\windows live\installer\wlsetupsvc.exe
o23 - service: Yahoo! Updater (yahooauservice) - yahoo! Inc. - c:\program files\yahoo!\softwareupdate\yahooauservice.exe
--
end of file - 9041 bytes