logfile of trend micro hijackthis v2.0.2
scan saved at 01:00:14 م, on 04/04/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\nero\nero 7\incd\incdsrv.exe
c:\program files\common files\lightscribe\lssrvc.exe
c:\windows\system32\hpzipm12.exe
c:\windows\system32\slserv.exe
c:\windows\explorer.exe
c:\windows\system32\vttimer.exe
c:\windows\system32\vttrayp.exe
c:\windows\soundman.exe
c:\program files\cyberlink\powerdvd\pdvdserv.exe
c:\program files\nero\nero 7\incd\nbhgui.exe
c:\program files\nero\nero 7\incd\incd.exe
c:\program files\google\google desktop search\googledesktop.exe
c:\program files\athan\athan.exe
c:\windows\system32\rundll32.exe
c:\program files\hp\hp software update\hpwuschd2.exe
c:\program files\x'nbeep 1.1\xnbeep.exe
c:\program files\google\google desktop search\googledesktop.exe
c:\program files\common files\lightscribe\lightscribecontrolpanel.exe
c:\program files\internet download manager\idman.exe
c:\windows\system32\ctfmon.exe
c:\program files\picasa2\picasamediadetector.exe
c:\program files\messenger\msmsgs.exe
c:\windows\system32\svchost.exe
c:\program files\hp\digital imaging\bin\hpqtra08.exe
c:\program files\ralink\common\raui.exe
c:\program files\winzip\wzqkpick.exe
c:\program files\internet download manager\iemonitor.exe
c:\program files\hp\digital imaging\bin\hpqste08.exe
c:\windows\system32\wscript.exe
c:\windows\system32\wscript.exe
c:\windows\system32\wscript.exe
c:\windows\system32\wscript.exe
c:\windows\system32\wscript.exe
c:\windows\system32\svchost.exe
c:\program files\opera\opera.exe
c:\documents and settings\free user\desktop\zyzoom_hijackthis.exe
o2 - bho: Idmiehlprobj class - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Snapflash class - {a44cbb0b-c77d-4bf5-87cc-b4ee79ad1b7e} - c:\program files\common files\justdo\jd2002.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
o3 - toolbar: &google - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
o4 - hklm\..\run: [vttimer] vttimer.exe
o4 - hklm\..\run: [vttrayp] vttrayp.exe
o4 - hklm\..\run: [soundman] soundman.exe
o4 - hklm\..\run: [remotecontrol] "c:\program files\cyberlink\powerdvd\pdvdserv.exe"
o4 - hklm\..\run: [nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe
o4 - hklm\..\run: [securdisc] c:\program files\nero\nero 7\incd\nbhgui.exe
o4 - hklm\..\run: [incd] c:\program files\nero\nero 7\incd\incd.exe
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe"
o4 - hklm\..\run: [google desktop search] "c:\program files\google\google desktop search\googledesktop.exe" /startup
o4 - hklm\..\run: [athan] c:\program files\athan\athan.exe
o4 - hklm\..\run: [bluetoothauthenticationagent] rundll32.exe bthprops.cpl,,bluetoothauthenticationagent
o4 - hklm\..\run: [hp software update] c:\program files\hp\hp software update\hpwuschd2.exe
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files\adobe\reader 8.0\reader\reader_sl.exe"
o4 - hklm\..\run: [ctfmon] c:\windows\system32\wscript.exe /e:vbs c:\windows\system32\winjpg.jpg
o4 - hklm\..\run: [regdiit] c:\windows\system32\winxp.exe
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [x'nbeep] c:\program files\x'nbeep 1.1\xnbeep.exe
o4 - hkcu\..\run: [lightscribe control panel] c:\program files\common files\lightscribe\lightscribecontrolpanel.exe -hidden
o4 - hkcu\..\run: [idman] c:\program files\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [picasa media detector] c:\program files\picasa2\picasamediadetector.exe
o4 - hkcu\..\run: [msmsgs] "c:\program files\messenger\msmsgs.exe" /background
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - startup: Adobe gamma.lnk = c:\program files\common files\adobe\calibration\adobe gamma loader.exe
o4 - global startup: Hp digital imaging monitor.lnk = c:\program files\hp\digital imaging\bin\hpqtra08.exe
o4 - global startup: Ralink wireless utility.lnk = c:\program files\ralink\common\raui.exe
o4 - global startup: Winzip quick pick.lnk = c:\program files\winzip\wzqkpick.exe
o8 - extra context menu item: &google search - res://c:\program files\google\googletoolbar1.dll/cmsearch.html
o8 - extra context menu item: &save flash in this page by flash saver - c:\progra~1\flashs~1\save.htm
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: Backward &links - res://c:\program files\google\googletoolbar1.dll/cmbacklinks.html
o8 - extra context menu item: Cac&hed snapshot of page - res://c:\program files\google\googletoolbar1.dll/cmcache.html
o8 - extra context menu item: Save flash with flash catcher - res://c:\program files\common files\justdo\iecatcher.dll/flashcatcher.htm
o8 - extra context menu item: Si&milar pages - res://c:\program files\google\googletoolbar1.dll/cmsimilar.html
o8 - extra context menu item: Translate into english - res://c:\program files\google\googletoolbar1.dll/cmtrans.html
o8 - extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\iegetvl.htm
o9 - extra button: Flash saver - {09ea1f80-f40a-11d1-b792-444553540001} - c:\progra~1\flashs~1\save.htm
o9 - extra 'tools' menuitem: Flash saver - {09ea1f80-f40a-11d1-b792-444553540001} - c:\progra~1\flashs~1\save.htm
o9 - extra button: Web anti-virus statistics - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky internet security 7.0\scieplgn.dll
o9 - extra button: Paltalk - {4eafef58-eefa-4116-983d-03b49bcbfffe} - c:\program files\paltalk messenger\paltalk.exe (file missing)
o9 - extra button: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\program files\common files\justdo\iecatcher.dll
o9 - extra 'tools' menuitem: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\program files\common files\justdo\iecatcher.dll
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {38d6d77c-5ec1-4a4a-afeb-85fe780cd61a} (fontdownloaderie class) -
o16 - dpf: {b0067ca5-2c37-4c6b-aaec-5e2ce8635061} (fontdown class) -
o18 - filter hijack: Text/html - (no clsid) - (no file)
o18 - filter: Text/plain - (no clsid) - (no file)
o20 - appinit_dlls: C:\progra~1\kasper~1\kasper~1.0\adialhk.dll c:\progra~1\google\google~2\goec62~1.dll
o23 - service: Adobe lm service - adobe systems - c:\program files\common files\adobe systems shared\service\adobelmsvc.exe
o23 - service: Kaspersky internet security 7.0 (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
o23 - service: Google desktop manager 5.7.806.10245 (googledesktopmanager-061008-081103) - google - c:\program files\google\google desktop search\googledesktop.exe
o23 - service: Google updater service (gusvc) - google - c:\program files\google\common\google updater\googleupdaterservice.exe
o23 - service: Incd helper (incdsrv) - nero ag - c:\program files\nero\nero 7\incd\incdsrv.exe
o23 - service: Lightscribeservice direct disc labeling service (lightscribeservice) - hewlett-packard company - c:\program files\common files\lightscribe\lssrvc.exe
o23 - service: Macromedia licensing service - unknown owner - c:\program files\common files\macromedia shared\service\macromedia licensing.exe
o23 - service: Nbservice - nero ag - c:\program files\nero\nero 7\nero backitup\nbservice.exe
o23 - service: Nmindexingservice - nero ag - c:\program files\common files\ahead\lib\nmindexingservice.exe
o23 - service: Pml driver hpz12 - hp - c:\windows\system32\hpzipm12.exe
o23 - service: Smartlinkservice (slservice) - smart link - c:\windows\system32\slserv.exe
--
end of file - 9332 bytes