logfile of trend micro hijackthis v2.0.2
scan saved at 04:21:51 م, on 11/12/2010
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v8.00 (8.00.6001.18702)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\program files\common files\bitdefender\bitdefender update service\livesrv.exe
c:\program files\bitdefender\bitdefender 2009\vsserv.exe
c:\windows\system32\svchost.exe
c:\program files\alwil software\avast5\avastsvc.exe
c:\windows\system32\spoolsv.exe
c:\windows\explorer.exe
c:\windows\rthdcpl.exe
c:\progra~1\alwils~1\avast5\avastui.exe
c:\program files\usb disk security\usbguard.exe
c:\program files\bitdefender\bitdefender 2009\bdagent.exe
c:\program files\antilogger\antilogger.exe
c:\windows\system32\ctfmon.exe
c:\program files\sandboxie\sbiectrl.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\pctspk.exe
c:\program files\cyberlink\shared files\richvideo.exe
c:\program files\sandboxie\sbiesvc.exe
c:\program files\microsoft\search enhancement pack\seaport\seaport.exe
c:\program files\common files\microsoft shared\windows live\wlidsvc.exe
c:\program files\bitdefender\bitdefender 2009\seccenter.exe
c:\program files\common files\microsoft shared\windows live\wlidsvcm.exe
c:\program files\internet download manager\iemonitor.exe
c:\windows\system32\svchost.exe
c:\program files\internet download manager\idman.exe
c:\program files\trend micro\hijackthis\hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,search page =
http://go.microsoft.com/fwlink/?linkid=54896
r0 - hkcu\software\microsoft\internet explorer\main,start page = about:blank
r1 - hklm\software\microsoft\internet explorer\main,search page =
http://go.microsoft.com/fwlink/?linkid=54896
r0 - hklm\software\microsoft\internet explorer\main,start page = about:blank
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
o2 - bho: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file)
o2 - bho: Search helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office12\gra8e1~1.dll
o2 - bho: Ssvhelper class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
o2 - bho: Windows live id sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Bing bar bho - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll
o3 - toolbar: @c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll
o4 - hklm\..\run: [rthdcpl] rthdcpl.exe
o4 - hklm\..\run: [nwiz] nwiz.exe /install
o4 - hklm\..\run: [microsoft default manager] "c:\program files\microsoft\search enhancement pack\default manager\defmgr.exe" -resume
o4 - hklm\..\run: [avast5] c:\progra~1\alwils~1\avast5\avastui.exe /nogui
o4 - hklm\..\run: [usb antivirus] c:\program files\usb disk security\usbguard.exe
o4 - hklm\..\run: [fortknoxpersonalfirewall] "c:\program files\netgate\fortknox personal firewall\fortknoxgui.exe"
o4 - hklm\..\run: [bdagent] "c:\program files\bitdefender\bitdefender 2009\bdagent.exe"
o4 - hklm\..\run: [antilogger] "c:\program files\antilogger\antilogger.exe" /minimized
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [sandboxiecontrol] "c:\program files\sandboxie\sbiectrl.exe"
o4 - hkcu\..\run: [idman] c:\program files\internet download manager\idman.exe /onboot
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~4\office12\excel.exe/3000
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
o9 - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
o9 - extra 'tools' menuitem: Sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
o9 - extra button: Send to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~4\office12\onbttnie.dll
o9 - extra 'tools' menuitem: S&end to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~4\office12\onbttnie.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~4\office12\refiebar.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
o17 - hklm\system\ccs\services\tcpip\..\{a1facd34-b744-4a9c-a0bb-b5162f2f6b9b}: Nameserver = 192.168.1.1,192.168.1.2
o17 - hklm\system\cs1\services\tcpip\..\{a1facd34-b744-4a9c-a0bb-b5162f2f6b9b}: Nameserver = 192.168.1.1,192.168.1.2
o17 - hklm\system\cs2\services\tcpip\..\{a1facd34-b744-4a9c-a0bb-b5162f2f6b9b}: Nameserver = 192.168.1.1,192.168.1.2
o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\progra~1\micros~4\office12\gr99d3~1.dll
o23 - service: Avast! Antivirus - avast software - c:\program files\alwil software\avast5\avastsvc.exe
o23 - service: Avast! Mail scanner - avast software - c:\program files\alwil software\avast5\avastsvc.exe
o23 - service: Avast! ************ scanner - avast software - c:\program files\alwil software\avast5\avastsvc.exe
o23 - service: Fortknox personal firewall (fortknox) - netgate technologies s.r.o. - c:\program files\netgate\fortknox personal firewall\fortknox.exe
o23 - service: Bitdefender desktop update service (livesrv) - bitdefender srl - c:\program files\common files\bitdefender\bitdefender update service\livesrv.exe
o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
o23 - service: Pctel speaker phone (pctspk) - pctel, inc. - c:\windows\system32\pctspk.exe
o23 - service: Cyberlink richvideo service(crvs) (richvideo) - unknown owner - c:\program files\cyberlink\shared files\richvideo.exe
o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - cace technologies, inc. - c:\program files\winpcap\rpcapd.exe
o23 - service: Sandboxie service (sbiesvc) - tzuk - c:\program files\sandboxie\sbiesvc.exe
o23 - service: Bitdefender virus shield (vsserv) - bitdefender s. R. L. - c:\program files\bitdefender\bitdefender 2009\vsserv.exe
--
end of file - 8456 bytes