logfile of trend micro hijackthis v2.0.2
scan saved at 11:06:33 ص, on 03/03/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\program files\faronics\deep freeze\install c-0\df5serv.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\common files\protexis\license service\psiservice_2.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\program files\faronics\deep freeze\install c-0\_$df\frzstate2k.exe
c:\windows\system32\tskstsh.exe
c:\windows\system32\igfxtray.exe
c:\windows\system32\hkcmd.exe
c:\windows\soundman.exe
c:\program files\elaborate bytes\virtualclonedrive\vcddaemon.exe
c:\program files\java\jre1.5.0_08\bin\jusched.exe
c:\windows\system32\ctfmon.exe
c:\program files\wintools\ram saver pro\ramsaverpro.exe
c:\program files\nokia\nokia pc suite 7\pcsuite.exe
c:\program files\no-ip\duc20.exe
c:\program files\pc connectivity solution\servicelayer.exe
c:\program files\pc connectivity solution\transports\nclusbsrv.exe
c:\program files\pc connectivity solution\transports\nclrssrv.exe
c:\windows\system32\jetaudio.exe
c:\program files\windows live messenger khalid edition v5.1\msnmsgr.exe
c:\program files\windows live messenger khalid edition v5.1\msnmsgr.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\documents and settings\عقبه\desktop\zyzoom_hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,window title = %username%
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
o2 - bho: Ssvhelper class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_08\bin\ssv.dll
o2 - bho: Snapflash class - {a44cbb0b-c77d-4bf5-87cc-b4ee79ad1b7e} - c:\windows\system32\jd2002.dll
o3 - toolbar: (no name) - {0bf43445-2f28-4351-9252-17fe6e806aa0} - (no file)
o4 - hklm\..\run: [smserial] sm56hlpr.exe
o4 - hklm\..\run: [cmaudio] rundll32 cmicnfg.cpl,cmictrlwnd
o4 - hklm\..\run: [igfxtray] c:\windows\system32\igfxtray.exe
o4 - hklm\..\run: [hotkeyscmds] c:\windows\system32\hkcmd.exe
o4 - hklm\..\run: [soundman] soundman.exe
o4 - hklm\..\run: [virtualclonedrive] "c:\program files\elaborate bytes\virtualclonedrive\vcddaemon.exe" /s
o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files\java\jre1.5.0_08\bin\jusched.exe"
o4 - hklm\..\run: [0265791235870101mcinstcleanup] c:\docume~1\عقبه\local settings\temp\0265791235870101mcinst.exe c:\progra~1\common~1\mcafee\installer\cleanup.ini -cleanup -nolog
o4 - hklm\..\run: [adobecs4servicemanager] "c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe" -launchedbylogin
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [ramsaverpro] c:\program files\wintools\ram saver pro\ramsaverpro.exe
o4 - hkcu\..\run: [adobebridge] "c:\program files\adobe\adobe bridge cs4\bridge.exe" -stealth
o4 - hkcu\..\run: [pc suite tray] "c:\program files\nokia\nokia pc suite 7\pcsuite.exe" -onlytray
o4 - hklm\..\policies\explorer\run: [altap] tskstsh
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [set] fuset.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-20\..\runonce: [set] fuset.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\s-1-5-18\..\runonce: [set] fuset.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - hkus\.default\..\runonce: [set] fuset.exe (user 'default user')
o4 - startup: No-ip duc.lnk = c:\program files\no-ip\duc20.exe
o8 - extra context menu item: Save flash with flash catcher - res://c:\windows\system32\iecatcher.dll/flashcatcher.htm
o9 - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_08\bin\ssv.dll
o9 - extra 'tools' menuitem: Sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.5.0_08\bin\ssv.dll
o9 - extra button: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\windows\system32\iecatcher.dll
o9 - extra 'tools' menuitem: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\windows\system32\iecatcher.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msnmsgr.exe
o9 - extra 'tools' menuitem: Msn messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msnmsgr.exe
o17 - hklm\system\ccs\services\tcpip\..\{0105ad32-83ac-467d-93b6-b20cad6ef0e3}: Nameserver = 82.137.216.11 82.137.216.10
o17 - hklm\system\cs1\services\tcpip\..\{0105ad32-83ac-467d-93b6-b20cad6ef0e3}: Nameserver = 82.137.216.11 82.137.216.10
o17 - hklm\system\cs2\services\tcpip\..\{0105ad32-83ac-467d-93b6-b20cad6ef0e3}: Nameserver = 82.137.216.11 82.137.216.10
o20 - winlogon notify: Dflogon - c:\windows\system32\logondll.dll
o23 - service: Adobe lm service - adobe systems - c:\program files\common files\adobe systems shared\service\adobelmsvc.exe
o23 - service: Df5serv - faronics corporation - c:\program files\faronics\deep freeze\install c-0\df5serv.exe
o23 - service: Flexnet licensing service - acresso software inc. - c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe
o23 - service: Macromedia licensing service - unknown owner - c:\program files\common files\macromedia shared\service\macromedia licensing.exe
o23 - service: Protexis licensing v2 (psi_svc_2) - protexis inc. - c:\program files\common files\protexis\license service\psiservice_2.exe
o23 - service: Servicelayer - nokia. - c:\program files\pc connectivity solution\servicelayer.exe
--
end of file - 6188 bytes