logfile of trend micro hijackthis v2.0.2
scan saved at 1:16:56 am, on 3/31/2009
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp3 (6.00.2900.5512)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\common files\system\ssecbjf.exe
c:\program files\common files\microsoft shared\umrsoux.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\windows\system32\ctfmon.exe
c:\program files\zydas technology corporation\zydas_802.11g_utility\zdwlan.exe
c:\windows\services.exe
c:\windows\services.exe
c:\documents and settings\semadona\application data\thinstall\{54bcf935-ee50-483e-b979-a6556ca36f55}\40000011500002i\pctstray.exe
c:\windows\explorer.exe
c:\windows\system32\svchost.exe
c:\program files\internet explorer\iexplore.exe
c:\zyzoom_hijackthis.exe
f2 - reg:system.ini: Shell=explorer.exe c:\windows\system32\fservice.exe
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o4 - hklm\..\run: [dlkphjj] c:\program files\common files\system\ssecbjf.exe
o4 - hklm\..\run: [durjgxr] c:\program files\common files\microsoft shared\umrsoux.exe
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files\adobe\reader 9.0\reader\reader_sl.exe"
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hklm\..\policies\explorer\run: [directx for microsoft® windows] c:\windows\system32\fservice.exe
o4 - hkus\s-1-5-19\..\runonce: [nltide_3] rundll32 advpack.dll,launchinfsectionex nlite.inf,c,,4,n (user 'local service')
o4 - hkus\s-1-5-20\..\runonce: [nltide_3] rundll32 advpack.dll,launchinfsectionex nlite.inf,c,,4,n (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\s-1-5-18\..\runonce: [nltide_3] rundll32 advpack.dll,launchinfsectionex nlite.inf,c,,4,n (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - hkus\.default\..\runonce: [nltide_3] rundll32 advpack.dll,launchinfsectionex nlite.inf,c,,4,n (user 'default user')
o4 - global startup: Zdwlan utility.lnk = c:\program files\zydas technology corporation\zydas_802.11g_utility\zdwlan.exe
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8} (activescan 2.0 installer class) -
o16 - dpf: {cf40acc5-e1bb-4aff-ac72-04c2f616bca7} (get_atlcom class) -
o23 - service: Getplus(r) helper - nos microsystems ltd. - c:\program files\nos\bin\getplus_helpersvc.exe
--
end of file - 3684 bytes