logfile of trend micro hijackthis v2.0.2
scan saved at 05:05:57 م, on 21/04/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\acs.exe
c:\appserv\apache2.2\bin\httpd.exe
c:\windows\system32\crypserv.exe
c:\program files\hotspot shield\bin\openvpnas.exe
c:\program files\google\update\googleupdate.exe
c:\program files\java\jre6\bin\jqs.exe
c:\windows\explorer.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\appserv\mysql\bin\mysqld-nt.exe
c:\windows\system32\wbsecsvc.exe
c:\appserv\apache2.2\bin\httpd.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxtray.exe
c:\windows\system32\hkcmd.exe
c:\program files\atheros\acu.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\java\jre6\bin\jusched.exe
c:\windows\system32\ctfmon.exe
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\program files\microsoft activesync\wcescomm.exe
c:\progra~1\micros~3\rapimgr.exe
c:\program files\realtek rtl8187 wireless lan driver and utility\rtwlan.exe
c:\program files\winbond\w89c35\wwu.exe
c:\windows\system32\svchost.exe
c:\program files\msn messenger\usnsvc.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\msn messenger\msnmsgr.exe
c:\documents and settings\خالد khalid\سطح المكتب\zyzoom_hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,default_page_url = about:
R0 - hkcu\software\microsoft\internet explorer\main,start page = about:blank
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = local
f2 - reg:system.ini: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\drivers\services.exe
o2 - bho: Btorbit.com - {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
o2 - bho: (no name) - {27b4851a-3207-45a2-b947-be8afe6163ab} - (no file)
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\googletoolbar.dll
o2 - bho: Google toolbar notifier bho - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
o2 - bho: Google dictionary compression sdch - {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219b3e1547538286.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o2 - bho: Jqsiestartdetectorimpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
o3 - toolbar: Grab pro - {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\grabpro.dll
o3 - toolbar: &google toolbar - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\googletoolbar.dll
o4 - hklm\..\run: [igfxtray] c:\windows\system32\igfxtray.exe
o4 - hklm\..\run: [hotkeyscmds] c:\windows\system32\hkcmd.exe
o4 - hklm\..\run: [acu] "c:\program files\atheros\acu.exe" -nogui
o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files\java\jre6\bin\jusched.exe"
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
o4 - hklm\..\run: [msconfig] c:\windows\pchealth\helpctr\binaries\msconfig.exe /auto
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [[system]] c:\windows\system32\drivers\services.exe
o4 - hkcu\..\run: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - global startup: Realtek rtl8187 wireless lan utility.lnk = c:\program files\realtek rtl8187 wireless lan driver and utility\rtwlan.exe
o8 - extra context menu item: &download by orbit - res://c:\program files\orbitdownloader\orbitmxt.dll/201
o8 - extra context menu item: &grab video by orbit - res://c:\program files\orbitdownloader\orbitmxt.dll/204
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: Do&wnload selected by orbit - res://c:\program files\orbitdownloader\orbitmxt.dll/203
o8 - extra context menu item: Down&load all by orbit - res://c:\program files\orbitdownloader\orbitmxt.dll/202
o9 - extra button: إحصائيات حماية حركة زيارة الويب - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky internet security 2009\scieplgn.dll
o9 - extra button: Create mobile favorite - {2eaf5bb1-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\micros~3\inetrepl.dll
o9 - extra button: (no name) - {2eaf5bb2-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\micros~3\inetrepl.dll
o9 - extra 'tools' menuitem: Create mobile favorite... - {2eaf5bb2-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\micros~3\inetrepl.dll
o9 - extra button: Paltalk - {4eafef58-eefa-4116-983d-03b49bcbfffe} - c:\program files\paltalk messenger\paltalk.exe
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) -
o23 - service: 0315291236965362mcinstcleanup - - (no file)
o23 - service: Atheros configuration service (acs) - unknown owner - c:\windows\system32\acs.exe
o23 - service: Apache - unknown owner - c:\appserv\apache\apache.exe (file missing)
o23 - service: Apache2.2 - apache software foundation - c:\appserv\apache2.2\bin\httpd.exe
o23 - service: Kaspersky internet security (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
o23 - service: Crypkey license - kenonic controls ltd. - c:\windows\system32\crypserv.exe
o23 - service: خدمة تحديث google (gupdate1c9ac6c1739d950) (gupdate1c9ac6c1739d950) - google inc. - c:\program files\google\update\googleupdate.exe
o23 - service: Google updater service (gusvc) - google - c:\program files\google\common\google updater\googleupdaterservice.exe
o23 - service: Hotspot shield service (hotspotshieldservice) - unknown owner - c:\program files\hotspot shield\bin\openvpnas.exe
o23 - service: Java quick starter (javaquickstarterservice) - sun microsystems, inc. - c:\program files\java\jre6\bin\jqs.exe
o23 - service: Mysql - unknown owner - c:\appserv\mysql\bin\mysqld-nt.exe
o23 - service: Wbsecsvc - winbond - c:\windows\system32\wbsecsvc.exe
--
end of file - 7722 bytes