logfile of trend micro hijackthis v2.0.2
scan saved at 09:06:49 ص, on 23/02/2009
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v7.00 (7.00.6000.16791)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program files\intel\wireless\bin\evteng.exe
c:\program files\intel\wireless\bin\s24evmon.exe
c:\program files\intel\wireless\bin\wlkeeper.exe
c:\windows\system32\spoolsv.exe
c:\program files\intel\wireless\bin\zcfgsvc.exe
c:\windows\explorer.exe
c:\windows\system32\rundll32.exe
c:\windows\stsystra.exe
c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\intel\wireless\bin\ifrmewrk.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\progra~1\intel\wireless\bin\1xconfig.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\synaptics\syntp\syntpenh.exe
c:\program files\dell\quickset\quickset.exe
c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
c:\windows\system32\ctfmon.exe
c:\program files\messenger\msmsgs.exe
c:\program files\superantispyware\superantispyware.exe
c:\program files\dell\quickset\nicconfigsvc.exe
c:\program files\intel\wireless\bin\regsrvc.exe
c:\program files\microsoft\search enhancement pack\seaport\seaport.exe
c:\windows\system32\svchost.exe
c:\windows\system32\wscntfy.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\windows live\toolbar\wltuser.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\windows live\contacts\wlcomm.exe
c:\program files\internet explorer\iexplore.exe
c:\documents and settings\flower\my documents\hijackthis.exe
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r1 - hklm\software\microsoft\internet explorer\main,search page =
r0 - hklm\software\microsoft\internet explorer\main,start page =
r1 - hkcu\software\microsoft\internet connection wizard,shellnext =
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
o2 - bho: Search helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\searchhelper.dll
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Windows live toolbar helper - {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
o3 - toolbar: &windows live toolbar - {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
o4 - hklm\..\run: [bluetoothauthenticationagent] rundll32.exe bthprops.cpl,,bluetoothauthenticationagent
o4 - hklm\..\run: [sigmatelsystrayapp] stsystra.exe
o4 - hklm\..\run: [igfxtray] c:\windows\system32\igfxtray.exe
o4 - hklm\..\run: [igfxhkcmd] c:\windows\system32\hkcmd.exe
o4 - hklm\..\run: [igfxpers] c:\windows\system32\igfxpers.exe
o4 - hklm\..\run: [intelzeroconfig] c:\program files\intel\wireless\bin\zcfgsvc.exe
o4 - hklm\..\run: [intelwireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf intel proset/wireless
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [syntpenh] c:\program files\synaptics\syntp\syntpenh.exe
o4 - hklm\..\run: [dell quickset] c:\program files\dell\quickset\quickset.exe
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
o4 - hklm\..\run: [adobe photo downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [msmsgs] "c:\program files\messenger\msmsgs.exe" /background
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [superantispyware] c:\program files\superantispyware\superantispyware.exe
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [tsclientmsiuninstaller] cmd.exe /c "cscript %systemroot%\installer\tsclientmsitrans\tscuinst.vbs" (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [nltide_3] rundll32 advpack.dll,launchinfsectionex nlite.inf,c,,4,n (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-20\..\runonce: [tsclientmsiuninstaller] cmd.exe /c "cscript %systemroot%\installer\tsclientmsitrans\tscuinst.vbs" (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\s-1-5-18\..\runonce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - hkus\.default\..\runonce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (user 'default user')
o4 - global startup: Adobe gamma loader.lnk = c:\program files\common files\adobe\calibration\adobe gamma loader.exe
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: Add to anti-banner - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm
o9 - extra button: Web traffic protection statistics - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky internet security 2009\scieplgn.dll
o9 - extra button: تدوين هذا في المدونة - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: &تدوين هذا في windows live writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o10 - unknown file in winsock lsp: C:\windows\system32\nwprovau.dll
o20 - appinit_dlls: ,c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\adialhk.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
o20 - winlogon notify: !saswinlogon - c:\program files\superantispyware\saswinlo.dll
o23 - service: Kaspersky internet security (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
o23 - service: Evteng - intel corporation - c:\program files\intel\wireless\bin\evteng.exe
o23 - service: Nicconfigsvc - dell inc. - c:\program files\dell\quickset\nicconfigsvc.exe
o23 - service: Regsrvc - intel corporation - c:\program files\intel\wireless\bin\regsrvc.exe
o23 - service: Spectrum24 event monitor (s24eventmonitor) - intel corporation - c:\program files\intel\wireless\bin\s24evmon.exe
o23 - service: Wlankeeper - intel® corporation - c:\program files\intel\wireless\bin\wlkeeper.exe
--
end of file - 7858 bytes