logfile of trend micro hijackthis v2.0.2
scan saved at 12:34:06, on 21/03/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program files\alwil software\avast4\aswupdsv.exe
c:\program files\alwil software\avast4\ashserv.exe
c:\windows\system32\spoolsv.exe
c:\progra~1\alwils~1\avast4\ashdisp.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\internet download manager\idman.exe
c:\windows\system32\ctfmon.exe
c:\program files\fichiers communs\apple\mobile device support\bin\applemobiledeviceservice.exe
c:\program files\widcomm\bluetooth software\bin\btwdins.exe
c:\windows\system32\cisvc.exe
c:\program files\fichiers communs\kutinsoft\coordinationservice\kutinsoftcoordinationservice.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\snmp.exe
c:\windows\system32\svchost.exe
c:\program files\windows live\messenger\usnsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\alwil software\avast4\ashmaisv.exe
c:\program files\alwil software\avast4\ashwebsv.exe
c:\program files\internet download manager\iemonitor.exe
c:\windows\system32\wpabaln.exe
c:\documents and settings\mohammed\bureau\iexplore.exe
c:\program files\speederxp\speederxp.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\vghd\virtuagirl_downloader.exe
c:\windows\explorer.exe
d:\intter\programs\hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page = http://auto.search.msn.com/response.asp?mt=<meta+name%3d"googlebot"+content%3d"noarchive&srch=5&prov=gogl&utf8
r1 - hklm\software\microsoft\internet explorer\search,default_search_url =
r1 - hkcu\software\microsoft\internet explorer\searchurl,(default) =
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = liens
f2 - reg:system.ini: Shell=explorer.exe
o2 - bho: Metaproducts inquiry helper - {001165c1-a640-11d7-9fd9-0080481ada61} - c:\program files\metaproducts inquiry\inquiry.dll
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Askbar bho - {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askbar.dll (file missing)
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Spybot-s&d ie protection - {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\sdhelper.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
o3 - toolbar: Ie reader - {3c24a589-43d7-4ca2-aace-30424985b955} - c:\program files\latestsoft\internet explorer reader\voicebar.dll
o3 - toolbar: &google - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
o3 - toolbar: Metaproducts inquiry bar - {b8238b20-ff2c-11d7-9fd9-0080481ada61} - c:\program files\metaproducts inquiry\inquiry.dll
o4 - hklm\..\run: [imjpmig8.1] "c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
o4 - hklm\..\run: [phime2002async] c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
o4 - hklm\..\run: [phime2002a] c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
o4 - hklm\..\run: [avast!] c:\progra~1\alwils~1\avast4\ashdisp.exe
o4 - hklm\..\run: [kernelfaultcheck] %systemroot%\system32\dumprep 0 -k
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [idman] c:\program files\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'service local')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'service reseau')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - global startup: Bluetooth.lnk = ?
O8 - extra context menu item: &search - ?p=zcfox000
o8 - extra context menu item: Send to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o8 - extra context menu item: Star downloader التنزيل بـ - c:\program files\star downloader\sdie.htm
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
o8 - extra context menu item: حفظ &التحديد بواسطة إنكوايري - res://c:\program files\metaproducts inquiry\inquiry.dll/savesel.htm
o8 - extra context menu item: حفظ ا&لصورة بواسطة إنكوايري - res://c:\program files\metaproducts inquiry\inquiry.dll/saveimg.htm
o8 - extra context menu item: حفظ ال&إطار بواسطة إنكوايري - res://c:\program files\metaproducts inquiry\inquiry.dll/saveframe.htm
o8 - extra context menu item: حفظ ال&صفحة بواسطة إنكوايري - res://c:\program files\metaproducts inquiry\inquiry.dll/savepage.htm
o9 - extra button: Mp inquiry - {49b46060-8ac4-11d7-9fd9-0080481ada61} - c:\program files\metaproducts inquiry\inquiry.dll
o9 - extra button: Save flash files - {55ad98ff-3cb9-4718-b28b-e18f932d7fab} - c:\program files\metaproducts inquiry\inquiry.dll
o9 - extra button: Save page to disk - {7fdb9aee-d04a-440c-8d1d-52b807115c59} - c:\program files\metaproducts inquiry\inquiry.dll
o9 - extra button: Save images - {8f36e80b-ad7c-434e-ab92-da3938ea01e5} - c:\program files\metaproducts inquiry\inquiry.dll
o9 - extra button: Save with mp inquiry - {b98eeb00-a0f2-11d7-9fd9-0080481ada61} - c:\program files\metaproducts inquiry\inquiry.dll
o9 - extra 'tools' menuitem: &save with metaproducts inquiry - {b98eeb00-a0f2-11d7-9fd9-0080481ada61} - c:\program files\metaproducts inquiry\inquiry.dll
o9 - extra button: @btrez.dll,-4015 - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra 'tools' menuitem: @btrez.dll,-12650 - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - c:\progra~1\spybot~1\sdhelper.dll
o9 - extra 'tools' menuitem: Spybot - search & destroy configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - c:\progra~1\spybot~1\sdhelper.dll
o16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) -
o17 - hklm\system\ccs\services\tcpip\..\{81a98f0e-52b6-490f-96c4-29858a12f827}: Nameserver = 41.221.20.4 193.251.169.165
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~1\fichie~1\skype\skype4~1.dll
o23 - service: Apple mobile device - apple inc. - c:\program files\fichiers communs\apple\mobile device support\bin\applemobiledeviceservice.exe
o23 - service: Askupgrade - unknown owner - c:\program files\askbardis\bar\bin\askupgrade.exe (file missing)
o23 - service: Avast! Iavs4 control service (aswupdsv) - alwil software - c:\program files\alwil software\avast4\aswupdsv.exe
o23 - service: Avast! Antivirus - alwil software - c:\program files\alwil software\avast4\ashserv.exe
o23 - service: Avast! Mail scanner - alwil software - c:\program files\alwil software\avast4\ashmaisv.exe
o23 - service: Avast! Web scanner - alwil software - c:\program files\alwil software\avast4\ashwebsv.exe
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\bin\btwdins.exe
o23 - service: Kutinsoft common users folder (commonusersfolderservice) - kutinsoft - c:\program files\fichiers communs\kutinsoft\coordinationservice\kutinsoftcoordinationservice.exe
o23 - service: Dun manager service - magenta systems ltd - c:\program files\dunman\dmservc.exe
o23 - service: Google updater service (gusvc) - google - c:\program files\google\common\google updater\googleupdaterservice.exe
o23 - service: Service de l’ipod (ipod service) - apple inc. - c:\program files\ipod\bin\ipodservice.exe
o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - cace technologies - c:\program files\winpcap\rpcapd.exe
o23 - service: Vlc media player - unknown owner - c:\program files\videolan\vlc\vlc.exe
o23 - service: Vrs recording system (vrsservice) - nch software - c:\program files\nch swift sound\vrs\vrs.exe
--
end of file - 9191 bytes