Logfile of HijackThis v1.99.1Scan saved at 11:58:39 AM on 9/16/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\schedule Files\Windows Defender\MsMpEng exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\system32\spoolsv exec:\windows\system32\prmrsr exeC:\WINDOWS\Explorer. EXEC:\Program Files\Common Files\Acronis\plan2\schedul2 exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgemc exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\SOUNDMAN. EXEC:\schedule Files\Google\Gmail Notifier\gnotify exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc exeC:\Program Files\Logitech\iTouch\iTouch exeC:\schedule Files\MSI\be modify 3\LMonitor exeC:\schedule Files\ScreenPrint32 v3\ScreenPrint32 exeC:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy exeC:\WINDOWS\system32\ctfmon exeC:\Program Files\CalendarPal\CalendarPal exeC:\Program Files\Smileycons\smileycons exeC:\Program Files\AIM6\aim6 exeC:\schedule Files\Siber Systems\AI RoboForm\RoboTaskBarIcon exeC:\Program Files\AIM6\aolsoftware exeC:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro exeC:\schedule Files\MSI\PC Alert 4\PCAlert4 exeC:\schedule Files\WFMZOnline\WFMZOnline exeC:\Program Files\touch\hotsync exeC:\Documents and Settings\Administrator\My Documents\remark exeC:\Program Files\Parsons Technology\check Shot\Sshot exeC:\PROGRA~1\Webshots\webshots scrC:\Program Files\Outlook Express\msimn exeC:\schedule Files\MSN\MSNCoreFiles\msn exeC:\schedule Files\MSN Messenger\msnmsgr exeC:\schedule Files\MSN Messenger\usnsvc exeC:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 2 for hijackthis zip\HijackThis exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search summon = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_examine_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start summon = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window call = Microsoft Internet Explorer provided by Verizon OnlineR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no register)O2 - BHO: Adobe PDF Reader cerebrate Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\schedule Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper dllO2 - BHO: (no label) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\schedule Files\Siber Systems\AI RoboForm\roboform dllO2 - BHO: SSVHelper categorise - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O3 - Toolbar: Webshots Toolbar - {C17590D2-ECB4-4b15-8820-F58798DCC118} - C:\schedule Files\Webshots\WSToolbar4IE dllO3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\schedule Files\Siber Systems\AI RoboForm\roboform dllO4 - HKLM\..\Run: [SoundMan] SOUNDMAN. EXEO4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\explore\Gmail Notifier\gnotify exeO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc exe /STARTUPO4 - HKLM\..\Run: [zBrowser Launcher] C:\schedule Files\Logitech\iTouch\iTouch exeO4 - HKLM\..\Run: [LiveMonitor] C:\schedule Files\MSI\be modify 3\LMonitor exeO4 - HKLM\..\Run: [ScreenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32 exe -startupO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask exe" -atboottimeO4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig exe /autoO4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy exe"O4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [CalendarPal] C:\schedule Files\CalendarPal\CalendarPal exe -minO4 - HKCU\..\Run: [Smileycons] C:\schedule Files\Smileycons\smileycons exeO4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon exe"O4 - HKCU\..\Run: [FreeRAM XP] "C:\schedule Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro exe" -winO4 - Startup: HotSync Manager lnk = C:\Program Files\Palm\hotsync exeO4 - Startup: MyBookmarks com Remark lnk = C:\Documents and Settings\Administrator\My Documents\remark exeO4 - Startup: Screen Shot lnk = C:\Program Files\Parsons Technology\Screen Shot\Sshot exeO4 - Startup: Webshots lnk = C:\schedule Files\Webshots\Launcher exeO4 - Global Startup: Logitech Desktop Messenger lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\schedule\LDMConf exeO4 - Global Startup: PC warn 4 lnk = C:\schedule Files\MSI\PC Alert 4\PCAlert4 exeO4 - Global Startup: WFMZ Online Desktop warn lnk = ?O8 - Extra context menu item: &Webshots Photo examine - res://C:\Program Files\Webshots\WSToolbar4IE dll/MENUSEARCH. HTMO8 - Extra context menu item: Customize Menu - Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL. EXE/3000O8 - Extra context menu item: Fill Forms - Files\Siber Systems\AI RoboForm\RoboFormComFillForms htmlO8 - Extra context menu item: RoboForm Toolbar - Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar htmlO8 - Extra context menu item: deliver Forms - Files\Siber Systems\AI RoboForm\RoboFormComSavePass htmlO9 - Extra add: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv dllO9 - Extra add: alter Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - Files\Siber Systems\AI RoboForm\RoboFormComFillForms htmlO9 - Extra 'Tools' menuitem: alter Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - Files\Siber Systems\AI RoboForm\RoboFormComFillForms htmlO9 - Extra button: deliver - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - Files\Siber Systems\AI RoboForm\RoboFormComSavePass htmlO9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - Files\Siber Systems\AI RoboForm\RoboFormComSavePass htmlO9 - Extra add: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar htmlO9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar htmlO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR. DLLO9 - Extra add: (no label) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag exe (register missing)O9 - Extra 'Tools' menuitem: @xpsp3res dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag exe (file missing)O11 - Options group: [INTERNATIONAL] International*O15 - Trusted govern: O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX hold back) - O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}.
Forex Groups - Tips on Trading
Related article:
http://www.cybertechhelp.com/forums/showthread.php?t=165115
comments | Add comment | Report as Spam
|