logfile of trend micro hijackthis v2.0.2
scan saved at 18
.gif)
13, on 11-12-2010
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
E:\windows\system32\smss.exe
e:\windows\system32\winlogon.exe
e:\windows\system32\services.exe
e:\windows\system32\lsass.exe
e:\program files\faronics\deep freeze\install e-0\dfserv.exe
e:\windows\system32\svchost.exe
e:\windows\system32\spoolsv.exe
e:\program files\avira\antivir desktop\sched.exe
e:\windows\explorer.exe
e:\windows\system32\rundll32.exe
e:\windows\soundman.exe
c:\vmware\vmware-tray.exe
e:\program files\keyscrambler\keyscrambler.exe
e:\program files\malwarebytes' anti-malware\mbamgui.exe
e:\program files\avira\antivir desktop\avgnt.exe
e:\program files\internet download manager\idman.exe
e:\program files\bittorrent\bittorrent.exe
e:\program files\windows live\messenger\msnmsgr.exe
e:\program files\faronics\deep freeze\install e-0\_$df\frzstate2k.exe
e:\program files\avira\antivir desktop\avfwsvc.exe
e:\program files\avira\antivir desktop\avguard.exe
e:\program files\malwarebytes' anti-malware\mbamservice.exe
e:\windows\system32\nvsvc32.exe
e:\windows\system32\svchost.exe
e:\program files\avira\antivir desktop\avshadow.exe
e:\program files\common files\vmware\usb\vmware-usbarbitrator.exe
e:\windows\system32\vmnat.exe
e:\windows\system32\vmnetdhcp.exe
c:\vmware\vmware-authd.exe
e:\program files\avira\antivir desktop\avmailc.exe
e:\program files\avira\antivir desktop\av************grd.exe
e:\program files\internet download manager\iemonitor.exe
e:\documents and settings\v\bureau\procexp.exe
e:\windows\system32\svchost.exe
e:\program files\mozilla firefox\firefox.exe
e:\program files\mozilla firefox\plugin-container.exe
e:\program files\trend micro\hijackthis\hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page =
http://fr.ask.com?o=15183&l=dis
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = liens
r3 - urlsearchhook: (no name) - {00000000-6e41-4fd3-8538-502f5495e5fc} - (no file)
r3 - urlsearchhook: Bittorrentbar toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - e:\program files\bittorrentbar\tbbitt.dll
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - e:\program files\internet download manager\idmiecc.dll
o2 - bho: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - e:\program files\conduitengine\conduitengine.dll
o2 - bho: Bittorrentbar toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - e:\program files\bittorrentbar\tbbitt.dll
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - e:\program files\fichiers communs\microsoft shared\windows live\windowslivelogin.dll
o3 - toolbar: Bittorrentbar toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - e:\program files\bittorrentbar\tbbitt.dll
o3 - toolbar: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - e:\program files\conduitengine\conduitengine.dll
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe e:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run: [nwiz] nwiz.exe /install
o4 - hklm\..\run: [nvmediacenter] rundll32.exe e:\windows\system32\nvmctray.dll,nvtaskbarinit
o4 - hklm\..\run: [soundman] soundman.exe
o4 - hklm\..\run: [conime] conime.exe
o4 - hklm\..\run: [vmware-tray] "c:\vmware\vmware-tray.exe"
o4 - hklm\..\run: [keyscrambler] e:\program files\keyscrambler\keyscrambler.exe /a
o4 - hklm\..\run: [malwarebytes' anti-malware] "e:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
o4 - hklm\..\run: [kernelfaultcheck] %systemroot%\system32\dumprep 0 -k
o4 - hklm\..\run: [avgnt] "e:\program files\avira\antivir desktop\avgnt.exe" /min
o4 - hkcu\..\run: [idman] e:\program files\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [bittorrent] "e:\program files\bittorrent\bittorrent.exe"
o4 - hkcu\..\run: [skype] "e:\program files\skype\phone\skype.exe" /nosplash /minimized
o4 - hkcu\..\run: [msnmsgr] "e:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] e:\windows\system32\ctfmon.exe (user 'service local')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] e:\windows\system32\ctfmon.exe (user 'service reseau')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] e:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] e:\windows\system32\ctfmon.exe (user 'default user')
o4 - global startup: Paltalk.lnk = e:\program files\paltalk messenger\paltalk.exe
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - e:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - e:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى flv بواسطة internet download manager - e:\program files\internet download manager\iegetvl.htm
o9 - extra button: (no name) - {5c106a59-cc3c-4caa-81a4-6d909b5ace23} - e:\program files\keyscrambler\keyscramblerie.dll
o9 - extra 'tools' menuitem: &keyscrambler options - {5c106a59-cc3c-4caa-81a4-6d909b5ace23} - e:\program files\keyscrambler\keyscramblerie.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - e:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - e:\program files\messenger\msmsgs.exe
o10 - unknown file in winsock lsp: C:\vmware\vsocklib.dll
o10 - unknown file in winsock lsp: C:\vmware\vsocklib.dll
o17 - hklm\system\ccs\services\tcpip\..\{8164bf72-103a-4efc-a12d-5218bc7d7d94}: Nameserver = 208.67.222.222 193.55.10.102
o17 - hklm\system\ccs\services\tcpip\..\{cf7083a3-a73e-4c88-8482-c1220183fba5}: Nameserver = 192.168.1.2
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - e:\progra~1\fichie~1\skype\skype4~1.dll
o20 - winlogon notify: Dflogon - e:\windows\system32\logondll.dll
o23 - service: Avira firewall (antivirfirewallservice) - avira gmbh - e:\program files\avira\antivir desktop\avfwsvc.exe
o23 - service: Avira antivir mailguard (antivirmailservice) - avira gmbh - e:\program files\avira\antivir desktop\avmailc.exe
o23 - service: Avira antivir scheduler (antivirschedulerservice) - avira gmbh - e:\program files\avira\antivir desktop\sched.exe
o23 - service: Avira antivir guard (antivirservice) - avira gmbh - e:\program files\avira\antivir desktop\avguard.exe
o23 - service: Avira antivir ************guard (antivir************service) - avira gmbh - e:\program files\avira\antivir desktop\av************grd.exe
o23 - service: Dfserv - faronics corporation - e:\program files\faronics\deep freeze\install e-0\dfserv.exe
o23 - service: Mbamservice - malwarebytes corporation - e:\program files\malwarebytes' anti-malware\mbamservice.exe
o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - e:\windows\system32\nvsvc32.exe
o23 - service: Vmware agent service (ufad-ws60) - vmware, inc. - c:\vmware\vmware-ufad.exe
o23 - service: Vmware authorization service (vmauthdservice) - vmware, inc. - c:\vmware\vmware-authd.exe
o23 - service: Vmware dhcp service (vmnetdhcp) - vmware, inc. - e:\windows\system32\vmnetdhcp.exe
o23 - service: Vmware usb arbitration service (vmusbarbservice) - vmware, inc. - e:\program files\common files\vmware\usb\vmware-usbarbitrator.exe
o23 - service: Vmware nat service - vmware, inc. - e:\windows\system32\vmnat.exe
--
end of file - 7498 bytes