logfile of trend micro hijackthis v2.0.2
scan saved at 05:39:07 م, on 03/02/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v7.00 (7.00.6000.16762)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program files\widcomm\bluetooth software\bin\btwdins.exe
c:\windows\system32\spoolsv.exe
c:\program files\avira\avira premium security suite\sched.exe
c:\windows\explorer.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\windows\system32\ctfmon.exe
c:\program files\nokia\nokia pc suite 7\pcsuite.exe
c:\program files\internet download manager\idman.exe
c:\program files\widcomm\bluetooth software\bttray.exe
c:\progra~1\widcomm\blueto~1\btstac~1.exe
c:\program files\avira\avira premium security suite\avguard.exe
c:\program files\avira\avira premium security suite\avesvc.exe
c:\windows\system32\crypserv.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\program files\avira\avira premium security suite\avwebgrd.exe
c:\program files\hewlett-packard\shared\hpqwmiex.exe
c:\program files\pc connectivity solution\servicelayer.exe
c:\program files\pc connectivity solution\transports\nclusbsrv.exe
c:\program files\pc connectivity solution\transports\nclrssrv.exe
c:\program files\pc connectivity solution\transports\nclbcbtsrv.exe
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\wuauclt.exe
c:\program files\msn messenger\msnmsgr.exe
c:\program files\msn messenger\usnsvc.exe
c:\program files\trend micro\hijackthis\hijackthis.exe
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r1 - hklm\software\microsoft\internet explorer\main,search page =
r0 - hklm\software\microsoft\internet explorer\main,start page =
f2 - reg:system.ini: Userinit=c:\windows\system32\userinit.exe,c:\docume~1\user\locals~1\temp\init.exe
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [avgnt] "c:\program files\avira\avira premium security suite\avgnt.exe" /min
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [pc suite tray] "c:\program files\nokia\nokia pc suite 7\pcsuite.exe" -onlytray
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - global startup: Bluetooth.lnk = ?
O8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: Send to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل باستخدام داون لود إكسبريس - c:\program files\download express\add_url.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
o9 - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\j2re1.4.1\bin\npjpi141.dll
o9 - extra 'tools' menuitem: Sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\j2re1.4.1\bin\npjpi141.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: @btrez.dll,-4015 - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra 'tools' menuitem: @btrez.dll,-12650 - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o16 - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) -
o16 - dpf: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (muwebcontrol class) -
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~1\common~1\skype\skype4~1.dll
o23 - service: Avira premium security suite firewall (antivirfirewallservice) - avira gmbh - c:\program files\avira\avira premium security suite\avfwsvc.exe
o23 - service: Avira premium security suite mailguard (antivirmailservice) - avira gmbh - c:\program files\avira\avira premium security suite\avmailc.exe
o23 - service: Avira premium security suite scheduler (antivirscheduler) - avira gmbh - c:\program files\avira\avira premium security suite\sched.exe
o23 - service: Avira premium security suite guard (antivirservice) - avira gmbh - c:\program files\avira\avira premium security suite\avguard.exe
o23 - service: Avira premium security suite webguard (antivirwebservice) - avira gmbh - c:\program files\avira\avira premium security suite\avwebgrd.exe
o23 - service: Avira premium security suite mailguard helper service (aveservice) - avira gmbh - c:\program files\avira\avira premium security suite\avesvc.exe
o23 - service: Bandluxe service (bandluxe_service) - unknown owner - c:\program files\bandrich\bandluxe hsdpa utility r11\brservice.exe (file missing)
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\bin\btwdins.exe
o23 - service: Crypkey license - kenonic controls ltd. - c:\windows\system32\crypserv.exe
o23 - service: Hpqwmiex - hewlett-packard development company, l.p. - c:\program files\hewlett-packard\shared\hpqwmiex.exe
o23 - service: Servicelayer - nokia. - c:\program files\pc connectivity solution\servicelayer.exe
--
end of file - 7342 bytes