logfile of trend micro hijackthis v2.0.2
scan saved at 02:03:38 م, on 14/01/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\hkcmd.exe
c:\windows\soundman.exe
c:\program files\cyberlink\powerdvd\pdvdserv.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\windows\system32\regsvr32.exe
c:\program files\hiyo\bin\hiyo.exe
c:\program files\grisoft\avg anti-spyware 7.5\zyzoom.exe
c:\windows\system32\ctfmon.exe
c:\documents and settings\administrator\local settings\application data\google\update\googleupdate.exe
c:\docume~1\admini~1\locals~1\temp\a.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
c:\program files\winzip\wzqkpick.exe
c:\program files\msn messenger\msnmsgr.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
c:\documents and settings\administrator\local settings\application data\google\chrome\application\chrome.exe
c:\documents and settings\administrator\local settings\application data\google\chrome\application\chrome.exe
c:\documents and settings\administrator\local settings\application data\google\chrome\application\chrome.exe
c:\documents and settings\administrator\local settings\application data\google\chrome\application\chrome.exe
c:\documents and settings\administrator\local settings\application data\google\chrome\application\chrome.exe
c:\docume~1\admini~1\locals~1\temp\winproawo.exe
c:\docume~1\admini~1\locals~1\temp\winqihac.exe
c:\docume~1\admini~1\locals~1\temp\winokbm.exe
c:\windows\system32\4ug83bpx.exe
c:\documents and settings\administrator\my documents\downloads\zyzoom_hijackthis.exe
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = 127.0.0.1:4001
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Offersfortoday browser enhancer - {34287454-138e-5a70-84a0-6bac0b414a2c} - c:\windows\system32\sgosamllyrrrel.dll
o2 - bho: Xml module - {500bca15-57a7-4eaf-8143-8c619470b13d} - c:\windows\system32\msxml71.dll
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
o2 - bho: Java(tm) plug-in ssv helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o4 - hklm\..\run: [igfxtray] c:\windows\system32\igfxtray.exe
o4 - hklm\..\run: [hotkeyscmds] c:\windows\system32\hkcmd.exe
o4 - hklm\..\run: [soundman] soundman.exe
o4 - hklm\..\run: [remotecontrol] "c:\program files\cyberlink\powerdvd\pdvdserv.exe"
o4 - hklm\..\run: [languageshortcut] "c:\program files\cyberlink\powerdvd\language\language.exe"
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files\adobe\reader 8.0\reader\reader_sl.exe"
o4 - hklm\..\run: [aodzxehcwjrjggu] c:\windows\system32\regsvr32.exe /s "c:\windows\system32\sgosamllyrrrel.dll"
o4 - hklm\..\run: [hiyo] c:\program files\hiyo\bin\hiyo.exe /runfromstartup
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
o4 - hklm\..\run: [!avg anti-spyware] "c:\program files\grisoft\avg anti-spyware 7.5\zyzoom.exe" /minimized
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [google update] "c:\documents and settings\administrator\local settings\application data\google\update\googleupdate.exe" /c
o4 - hkcu\..\run: [hichatter] c:\program files\hichatter messenger\hichater.exe
o4 - hkcu\..\run: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [msfox] c:\docume~1\admini~1\locals~1\temp\yyy12807.exe
o4 - hkcu\..\run:
copy /y "c:\windows\system32\msxml71.dll.upd" "c:\windows\system32\msxml71.dll"
o4 - hkcu\..\run: [windows service help] c:\recycler\s-1-5-21-1507482886-0776918185-670508857-2585\winservices.exe
o4 - hkcu\..\run: [cognac] c:\docume~1\admini~1\locals~1\temp\a.exe
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\s-1-5-18\..\runonce: *******playerupdate] c:\windows\system32\macromed\flash\flashutil9f.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - hkus\.default\..\runonce: *******playerupdate] c:\windows\system32\macromed\flash\flashutil9f.exe (user 'default user')
o4 - global startup: Winzip quick pick.lnk = c:\program files\winzip\wzqkpick.exe
o7 - hkcu\software\microsoft\windows\currentversion\policies\system, disableregedit=1
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: ت&صدير إلى microsoft excel - res://c:\progra~1\micros~2\office12\excel.exe/3000
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) -
o16 - dpf: {6924091f-cd97-41e1-b1d4-d9079409d413} (imcv1 control) -
o16 - dpf: {b7fdb0c3-4724-46d2-b8db-6fa1dc63f7ca} (readuid.usercontrolmacentry) -
o16 - dpf: {c3f79a2b-b9b4-4a66-b012-3ee46475b072} (messengerstatsclient class) -
o20 - appinit_dlls: C:\progra~1\kasper~1\kasper~1\mzvkbd.dll
o23 - service: Avg anti-spyware guard - grisoft s.r.o. - c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
--
end of file - 7135 bytes
[/size][/font]