Logfile of Trend Micro HijackThis v2.0.2Scan saved at 7:41:52 AM on 10/3/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: Normal Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\schedule Files\Ahead\InCD\InCDsrv exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\spoolsv exeC:\WINDOWS\Explorer. EXEC:\WINDOWS\system32\hkcmd exeC:\WINDOWS\system32\igfxpers exeC:\WINDOWS\RTHDCPL. EXEC:\schedule Files\Java\jre1.6.0_02\bin\jusched exeC:\Program Files\Microsoft IntelliType Pro\itype exeC:\Program Files\Microsoft IntelliPoint\ipoint exeC:\schedule Files\Hewlett-Packard\HP Software modify\HPWuSchd exeC:\PROGRA~1\Grisoft\AVG7\avgcc exeC:\Program Files\Common Files\Real\Update_OB\realsched exeC:\PROGRA~1\Logitech\iTouch\iTouch exeC:\PROGRA~1\Canon\SCANGE~1\SGTBox exeC:\schedule Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy exeC:\WINDOWS\system32\ctfmon exeC:\schedule Files\Spybot - examine & undo\TeaTimer exeC:\schedule Files\InterVideo\Common\Bin\WinCinemaMgr exeC:\Program Files\Norton SystemWorks\Norton GoBack\GBTray exeC:\PROGRA~1\Webshots\Webshots scrC:\schedule Files\Lavasoft\Ad-Aware 2007\aawservice exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc exeC:\PROGRA~1\Grisoft\AVG7\avgemc exeC:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll exeC:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr exeC:\Program Files\Common Files\NMSAccessU exeC:\WINDOWS\system32\svchost exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc exeC:\PROGRA~1\INCRED~1\bin\IMApp exeC:\PROGRA~1\INCRED~1\bin\IncMail exeC:\Program Files\Mozilla Firefox\firefox exeC:\schedule Files\Trend Micro\HijackThis\HijackThis exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_Search_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search summon = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\examine,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt dllR3 - URLSearchHook: overlap_Accelerator_MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1 dllO2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\affiliate\Installs\cpn1\yt dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper dllO2 - BHO: Share_Accelerator_MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1 dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper dllO2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\schedule Files\Yahoo!\Common\yiesrvc dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt dllO3 - Toolbar: overlap_Accelerator_MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1 dllO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers exeO4 - HKLM\..\Run: [SkyTel] SkyTel. EXEO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL. EXEO4 - HKLM\..\Run: [Alcmtr] ALCMTR. EXEO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\schedule Files\Java\jre1.6.0_02\bin\jusched exe"O4 - HKLM\..\Run: [itype] "c:\schedule Files\Microsoft IntelliType Pro\itype exe"O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint exe"O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd exe"O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09 exeO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc exe /STARTUPO4 - HKLM\..\Run: [TkBellExe] "C:\schedule Files\Common Files\Real\modify_OB\realsched exe" -osbootO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\schedule Files\Adobe\Reader 8.0\Reader\Reader_sl exe"O4 - HKLM\..\Run: [zBrowser Launcher] C:\PROGRA~1\Logitech\iTouch\iTouch exeO4 - HKLM\..\Run: [SGTBox] C:\PROGRA~1\Canon\SCANGE~1\SGTBox exeO4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck exeO4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy exe"O4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail exe /cO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - examine & Destroy\TeaTimer exeO4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw exe /RUNONCE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack dll,LaunchINFSection nlite inf,nLiteReg (User 'LOCAL function')O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw exe /RUNONCE (User 'NETWORK function')O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack dll,LaunchINFSection nlite inf,nLiteReg (User 'NETWORK function')O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw exe /RUNONCE (User 'SYSTEM')O4 - HKUS\. DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw exe /RUNONCE (User 'Default user')O4 - Startup: Webshots lnk = C:\Program Files\Webshots\Launcher exeO4 - Global Startup: Adobe Gamma Loader lnk = C:\schedule Files\Common Files\Adobe\Calibration\Adobe Gamma Loader exeO4 - Global Startup: InterVideo WinCinema Manager lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr exeO4 - Global Startup: Microsoft Office lnk = C:\schedule Files\Microsoft Office\Office\OSA9. EXEO4 - Global Startup: Norton GoBack lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray exeO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\schedule Files\IncrediMail\bin\resources\WebMenuImg htmO8 - Extra context menu item: &Search - ?p=ZRfox000O8 - Extra context menu item: &Yahoo! Search - file:///C:\schedule Files\Yahoo!\Common/ycsrch htmO8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict htmO8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap htmO8 - Extra context menu item: Yahoo! &SMS - register:///C:\schedule Files\Yahoo!\Common/ycsms htmO9 - Extra add: (no label) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv dllO9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program.
Forex Groups - Tips on Trading
Related article:
http://www.vista-xp.co.uk/forums/hijackthis-security-problems/13772-tabs-slow-links-e-mail-dont-work-results-hjt.html
comments | Add comment | Report as Spam
|