logfile of trend micro hijackthis v2.0.4
scan saved at 07:24:16 م, on 05/04/11
platform: Windows 7 (winnt 6.00.3504)
msie: Internet explorer v8.00 (8.00.7600.16722)
boot mode: Normal
running processes:
C:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe
c:\program files (x86)\microsoft office\office12\onenotem.exe
c:\program files (x86)\sony\isb utility\isbmgr.exe
c:\program files (x86)\real\realplayer\update\realsched.exe
c:\program files (x86)\zte connection manager\uiexec.exe
c:\program files (x86)\common files\spigot\search settings\searchsettings.exe
c:\program files (x86)\yahoo!\messenger\ymsgr_tray.exe
c:\program files\widcomm\bluetooth software\bluetoothheadsetproxy.exe
c:\users\nossa\appdata\local\google\chrome\application\chrome.exe
c:\users\nossa\appdata\local\google\chrome\application\chrome.exe
c:\users\nossa\appdata\local\google\chrome\application\chrome.exe
c:\users\nossa\appdata\local\google\chrome\application\chrome.exe
c:\users\nossa\appdata\local\google\chrome\application\chrome.exe
c:\program files (x86)\orbitdownloader\orbitdm.exe
c:\program files (x86)\orbitdownloader\orbitnet.exe
c:\users\nossa\appdata\local\google\chrome\application\chrome.exe
c:\users\nossa\appdata\local\google\chrome\application\chrome.exe
c:\zyzoom_forum_tools\zyzoom.exe
c:\zyzoom_forum_tools\zhijak.com
r1 - hkcu\software\microsoft\internet explorer\main,default_page_url =
r1 - hkcu\software\microsoft\internet explorer\main,search page =
r0 - hkcu\software\microsoft\internet explorer\main,start page =
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r1 - hklm\software\microsoft\internet explorer\main,search page =
r0 - hklm\software\microsoft\internet explorer\main,start page =
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r0 - hklm\software\microsoft\internet explorer\main,local page = c:\windows\syswow64\blank.htm
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
r3 - urlsearchhook: Dealio toolbar - {01398b87-61af-4ffb-9ab5-1a1c5fb39a9c} - c:\program files (x86)\dealio toolbar\ie\4.3\dealiotoolbarie.dll
r3 - urlsearchhook: (no name) - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - (no file)
r3 - urlsearchhook: Messenger plus saudi toolbar - {9e1b5c68-1ab5-49fe-97a9-d3f777c51663} - c:\program files (x86)\messenger_plus_saudi\prxtbmess.dll
r3 - urlsearchhook: Power karaoke toolbar - {3303e956-2a3a-48e0-be39-2e0ef11a2f44} - c:\program files (x86)\power_karaoke\tbpowe.dll
f2 - reg:system.ini: Userinit=userinit.exe
o2 - bho: Btorbit.com - {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files (x86)\orbitdownloader\orbitcth.dll
o2 - bho: Snagit toolbar loader - {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files (x86)\techsmith\snagit 10\snagitbho.dll
o2 - bho: Dealio toolbar - {01398b87-61af-4ffb-9ab5-1a1c5fb39a9c} - c:\program files (x86)\dealio toolbar\ie\4.3\dealiotoolbarie.dll
o2 - bho: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file)
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Pccbho.cpccbho - {22fc6ce8-7d47-479f-b74a-bfbb04adb9af} - c:\program files (x86)\winferno\pc confidential\pccbho.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
o2 - bho: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files (x86)\conduitengine\prxconduitengine.dll
o2 - bho: Power karaoke toolbar - {3303e956-2a3a-48e0-be39-2e0ef11a2f44} - c:\program files (x86)\power_karaoke\tbpowe.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files (x86)\microsoft office\office12\grooveshellextensions.dll
o2 - bho: مساعد تسجيل الدخول إلى معرف windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Messenger plus saudi - {9e1b5c68-1ab5-49fe-97a9-d3f777c51663} - c:\program files (x86)\messenger_plus_saudi\prxtbmess.dll
o2 - bho: Windows live messenger companion helper - {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files (x86)\windows live\companion\companioncore.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\googletoolbar_32.dll
o2 - bho: Google toolbar notifier bho - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
o2 - bho: Bing bar helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files (x86)\microsoft\bingbar\bingext.dll" (file missing)
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll (file missing)
o3 - toolbar: Google toolbar - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\googletoolbar_32.dll
o3 - toolbar: Snagit - {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files (x86)\techsmith\snagit 10\snagitieaddin.dll
o3 - toolbar: Grab pro - {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files (x86)\orbitdownloader\grabpro.dll
o3 - toolbar: Messenger plus saudi toolbar - {9e1b5c68-1ab5-49fe-97a9-d3f777c51663} - c:\program files (x86)\messenger_plus_saudi\prxtbmess.dll
o3 - toolbar: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files (x86)\conduitengine\prxconduitengine.dll
o3 - toolbar: Bing bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files (x86)\microsoft\bingbar\bingext.dll" (file missing)
o3 - toolbar: Dealio toolbar - {01398b87-61af-4ffb-9ab5-1a1c5fb39a9c} - c:\program files (x86)\dealio toolbar\ie\4.3\dealiotoolbarie.dll
o3 - toolbar: Power karaoke toolbar - {3303e956-2a3a-48e0-be39-2e0ef11a2f44} - c:\program files (x86)\power_karaoke\tbpowe.dll
o4 - hklm\..\run: [isbmgr.exe] "c:\program files (x86)\sony\isb utility\isbmgr.exe"
o4 - hklm\..\run: [nortononlinebackupreminder] "c:\program files (x86)\symantec\norton online backup\activation\nobuactivation.exe" unattended
o4 - hklm\..\run: [groovemonitor] "c:\program files (x86)\microsoft office\office12\groovemonitor.exe"
o4 - hklm\..\run: [switchboard] "c:\program files (x86)\common files\adobe\switchboard\switchboard.exe"
o4 - hklm\..\run: [adobecs5servicemanager] "c:\program files (x86)\common files\adobe\cs5servicemanager\cs5servicemanager.exe" -launchedbylogin
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files (x86)\adobe\reader 9.0\reader\reader_sl.exe"
o4 - hklm\..\run: [adobe arm] "c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe"
o4 - hklm\..\run: [tkbellexe] "c:\program files (x86)\real\realplayer\update\realsched.exe" -osboot
o4 - hklm\..\run: [uiexec] "c:\program files (x86)\zte connection manager\uiexec.exe"
o4 - hklm\..\run: [searchsettings] "c:\program files (x86)\common files\spigot\search settings\searchsettings.exe"
o4 - hkcu\..\run: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [swg] "c:\program files (x86)\google\googletoolbarnotifier\googletoolbarnotifier.exe"
o4 - hkcu\..\run: [google update] "c:\users\nossa\appdata\local\google\update\googleupdate.exe" /c
o4 - hkcu\..\run: [messenger (yahoo!)] "c:\progra~2\yahoo!\messenger\yahoomessenger.exe" -quiet
o4 - hkcu\..\run: [beyluxemessenger] "c:\program files (x86)\beyluxe messenger\beyluxe messenger.exe" /hide
o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'network service')
o4 - hkus\s-1-5-20\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'network service')
o4 - startup: Fliptoast.lnk = c:\program files (x86)\fliptoast\fliptoast.exe
o4 - startup: Onenote 2007 screen clipper and launcher.lnk = c:\program files (x86)\microsoft office\office12\onenotem.exe
o4 - global startup: Bluetooth.lnk = ?
O8 - extra context menu item: &download by orbit - res://c:\program files (x86)\orbitdownloader\orbitmxt.dll/201
o8 - extra context menu item: &grab video by orbit - res://c:\program files (x86)\orbitdownloader\orbitmxt.dll/204
o8 - extra context menu item: Do&wnload selected by orbit - res://c:\program files (x86)\orbitdownloader\orbitmxt.dll/203
o8 - extra context menu item: Down&load all by orbit - res://c:\program files (x86)\orbitdownloader\orbitmxt.dll/202
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~2\micros~4\office12\excel.exe/3000
o8 - extra context menu item: Google sidewiki... - res://c:\program files (x86)\google\google toolbar\component\googletoolbardynamic_mui_en_89d8574934b26ac4.dll/cmsidewiki.html
o8 - extra context menu item: جاري إرسال الصفحة إلى &جهاز bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o8 - extra context menu item: جاري إرسال الصورة إلى &جهاز bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o9 - extra button: @c:\program files (x86)\windows live\companion\companionlang.dll,-600 - {0000036b-c524-4050-81a0-243669a86b9f} - c:\program files (x86)\windows live\companion\companioncore.dll
o9 - extra button: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1004 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: @c:\program files (x86)\windows live\writer\windowslivewritershortcuts.dll,-1003 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra button: إرسال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~2\micros~4\office12\onbttnie.dll
o9 - extra 'tools' menuitem: إر&سال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~2\micros~4\office12\onbttnie.dll
o9 - extra button: (no name) - {53f6fccd-9e22-4d71-86ea-6e43136192ab} - c:\program files (x86)\winferno\pc confidential\pcconfidential.exe
o9 - extra 'tools' menuitem: Pc confidential - {53f6fccd-9e22-4d71-86ea-6e43136192ab} - c:\program files (x86)\winferno\pc confidential\pcconfidential.exe
o9 - extra button: Pc confidential - {925dab62-f9ac-4221-806a-057bfb1014aa} - c:\program files (x86)\winferno\pc confidential\pcconfidential.exe
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~2\micros~4\office12\refiebar.dll
o9 - extra button: Send to bluetooth - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra 'tools' menuitem: Send to &bluetooth device... - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o10 - unknown file in winsock lsp: C:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: C:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
o16 - dpf: {e2883e8f-472f-4fb0-9522-ac9bf37916a7} -
o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\program files (x86)\microsoft office\office12\groovesystemservices.dll
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~2\common~1\skype\skype4~1.dll
o18 - protocol: Wlpg - {e43ef6cd-a37a-4a9b-9e6f-83f89b8e6324} - c:\program files (x86)\windows live\photo gallery\albumdownloadprotocolhandler.dll
o23 - service: Arcsoft connect daemon (acdaemon) - arcsoft inc. - c:\program files (x86)\common files\arcsoft\connection service\bin\acservice.exe
o23 - service: Adobe active file monitor v7 (adobeactivefilemonitor7.0) - adobe systems incorporated - c:\program files (x86)\adobe\photoshop elements 7.0\photoshopelementsfileagent.exe
o23 - service: @%systemroot%\system32\alg.exe,-112 (alg) - unknown owner - c:\windows\system32\alg.exe (file missing)
o23 - service: Application updater - spigot, inc. - c:\program files (x86)\application updater\applicationupdater.exe
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\btwdins.exe
o23 - service: @%systemroot%\system32\efssvc.dll,-100 (efs) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\fxsresm.dll,-118 (fax) - unknown owner - c:\windows\system32\fxssvc.exe (file missing)
o23 - service: Flexnet licensing service - acresso software inc. - c:\program files (x86)\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe
o23 - service: خدمة تحديث google (gupdate) (gupdate) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: Google software updater (gusvc) - google - c:\program files (x86)\google\common\google updater\googleupdaterservice.exe
o23 - service: Intel(r) matrix storage event monitor (iaantmon) - intel corporation - c:\program files (x86)\intel\intel matrix storage manager\iaantmon.exe
o23 - service: @keyiso.dll,-100 (keyiso) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @comres.dll,-2797 (msdtc) - unknown owner - c:\windows\system32\msdtc.exe (file missing)
o23 - service: @%systemroot%\system32\netlogon.dll,-102 (netlogon) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Nvidia display driver service (nvsvc) - unknown owner - c:\windows\system32\nvvsvc.exe (file missing)
o23 - service: @%systemroot%\system32\psbase.dll,-300 (protectedstorage) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Roxio upnp renderer 10 - sonic solutions - c:\program files (x86)\roxio\digital home 10\roxioupnprenderer10.exe
o23 - service: Roxio upnp server 10 - sonic solutions - c:\program files (x86)\roxio\digital home 10\roxioupnpservice10.exe
o23 - service: @%systemroot%\system32\locator.exe,-2 (rpclocator) - unknown owner - c:\windows\system32\locator.exe (file missing)
o23 - service: @%systemroot%\system32\samsrv.dll,-1 (samss) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\snmptrap.exe,-3 (snmptrap) - unknown owner - c:\windows\system32\snmptrap.exe (file missing)
o23 - service: Vaio media plus content importer (sohcimp) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohcimp.exe
o23 - service: Vaio media plus database manager (sohdbsvr) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohdbsvr.exe
o23 - service: Vaio media plus digital media server (sohdms) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohdms.exe
o23 - service: Vaio media plus device searcher (sohds) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohds.exe
o23 - service: Vaio media plus playlist manager (sohplmgr) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohplmgr.exe
o23 - service: @%systemroot%\system32\spoolsv.exe,-1 (spooler) - unknown owner - c:\windows\system32\spoolsv.exe (file missing)
o23 - service: @%systemroot%\system32\sppsvc.exe,-101 (sppsvc) - unknown owner - c:\windows\system32\sppsvc.exe (file missing)
o23 - service: Switchboard - adobe systems incorporated - c:\program files (x86)\common files\adobe\switchboard\switchboard.exe
o23 - service: Cammonitor (ucammonitor) - arcsoft, inc. - c:\program files (x86)\arcsoft\magic-i visual effects 2\ucammonitor.exe
o23 - service: Ui assistant service - unknown owner - c:\program files (x86)\zte connection manager\assistantservices.exe
o23 - service: @%systemroot%\system32\ui0detect.exe,-101 (ui0detect) - unknown owner - c:\windows\system32\ui0detect.exe (file missing)
o23 - service: Vaio entertainment tv device arbitration service - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzhardwareresourcemanager\vzhardwareresourcemanager\vzhardwareresourcemanager.exe
o23 - service: Vaio event service - sony corporation - c:\program files (x86)\sony\vaio event service\vesmgr.exe
o23 - service: Vaio power management - sony corporation - c:\program files\sony\vaio power management\spmservice.exe
o23 - service: @%systemroot%\system32\vaultsvc.dll,-1003 (vaultsvc) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Vaio content folder watcher (vcfw) - sony corporation - c:\program files (x86)\common files\sony shared\vaio content folder watcher\vcfw.exe
o23 - service: Vaio content metadata intelligent analyzing manager (vcmialzmgr) - sony corporation - c:\program files\sony\vcm intelligent analyzing manager\vcmialzmgr.exe
o23 - service: Vaio content metadata intelligent network service manager (vcminsmgr) - sony corporation - c:\program files\sony\vcm intelligent network service manager\vcminsmgr.exe
o23 - service: Vaio content metadata xml interface (vcmxmlifhelper) - sony corporation - c:\program files\common files\sony shared\vcmxml\vcmxmlifhelper64.exe
o23 - service: Vaio entertainment upnp client adapter (vcsw) - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vcsw\vcsw.exe
o23 - service: @%systemroot%\system32\vds.exe,-100 (vds) - unknown owner - c:\windows\system32\vds.exe (file missing)
o23 - service: Vsnservice - sony corporation - c:\program files\sony\vaio smart network\vsnservice.exe
o23 - service: @%systemroot%\system32\vssvc.exe,-102 (vss) - unknown owner - c:\windows\system32\vssvc.exe (file missing)
o23 - service: Vaio entertainment database service (vzcdbsvc) - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzcdb\vzcdbsvc.exe
o23 - service: @%systemroot%\system32\wat\watux.exe,-601 (watadminsvc) - unknown owner - c:\windows\system32\wat\watadminsvc.exe (file missing)
o23 - service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - unknown owner - c:\windows\system32\wbengine.exe (file missing)
o23 - service: @%systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiapsrv) - unknown owner - c:\windows\system32\wbem\wmiapsrv.exe (file missing)
o23 - service: @%programfiles%\windows media player\wmpnetwk.exe,-101 (wmpnetworksvc) - unknown owner - c:\program files (x86)\windows media player\wmpnetwk.exe (file missing)
o23 - service: Yahoo! Updater (yahooauservice) - yahoo! Inc. - c:\program files (x86)\yahoo!\softwareupdate\yahooauservice.exe
--
end of file - 19264 bytes