logfile of trend micro hijackthis v2.0.2
scan saved at 3:21:40 pm, on 5/21/2009
platform: Windows vista sp2 (winnt 6.00.1906)
msie: Internet explorer v7.00 (7.00.6002.18005)
boot mode: Normal
running processes:
C:\windows\system32\dwm.exe
c:\windows\explorer.exe
c:\windows\system32\taskeng.exe
c:\program files\windows defender\msascui.exe
c:\windows\rthdvcpl.exe
c:\program files\motorola\smserial\sm56hlpr.exe
c:\windows\system32\igfxtray.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
c:\windows\windowsmobile\wmdsync.exe
c:\program files\topos\cfosspeed\cfosspeed.exe
c:\program files\vmware\vmware workstation\vmware-tray.exe
c:\program files\itunes\ituneshelper.exe
c:\program files\windows sidebar\sidebar.exe
c:\program files\nokia\nokia pc suite 7\pcsuite.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\siber systems\ai roboform\robotaskbaricon.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\messengerdiscovery\messengerdiscovery live.exe
c:\program files\pc connectivity solution\transports\nclmsbtsrv.exe
c:\program files\mozilla firefox\firefox.exe
c:\program files\internet download manager\idman.exe
c:\program files\internet download manager\iemonitor.exe
c:\users\3bo0od\desktop\hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,search page =
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r1 - hklm\software\microsoft\internet explorer\main,search page =
r0 - hklm\software\microsoft\internet explorer\main,start page =
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = 62.149.114.14:8080
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = 62.149.114.14:8080;local;<local>
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
f2 - reg:system.ini: Shell=explorer.exe
f2 - reg:system.ini: Userinit=userinit.exe
o1 - hosts: ::1 localhost
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
o2 - bho: Roboform - {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Now!imaging - {9aa2f14f-e956-44b8-8694-a5b615cdf341} - (no file)
o3 - toolbar: &roboform - {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
o4 - hklm\..\run: [windows defender] %programfiles%\windows defender\msascui.exe -hide
o4 - hklm\..\run: [rthdvcpl] rthdvcpl.exe
o4 - hklm\..\run: [skytel] skytel.exe
o4 - hklm\..\run: [smserial] c:\program files\motorola\smserial\sm56hlpr.exe
o4 - hklm\..\run: [syntpenh] c:\program files\synaptics\syntp\syntpenh.exe
o4 - hklm\..\run: [igfxtray] c:\windows\system32\igfxtray.exe
o4 - hklm\..\run: [hotkeyscmds] c:\windows\system32\hkcmd.exe
o4 - hklm\..\run: [persistence] c:\windows\system32\igfxpers.exe
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
o4 - hklm\..\run: [windows mobile-based device management] %windir%\windowsmobile\wmdsync.exe
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files\adobe\reader 9.0\reader\reader_sl.exe"
o4 - hklm\..\run: [cfosspeed] c:\program files\topos\cfosspeed\cfosspeed.exe
o4 - hklm\..\run: [vmware-tray] "c:\program files\vmware\vmware workstation\vmware-tray.exe"
o4 - hklm\..\run: [ituneshelper] "c:\program files\itunes\ituneshelper.exe"
o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
o4 - hkcu\..\run: [pc suite tray] "c:\program files\nokia\nokia pc suite 7\pcsuite.exe" -onlytray
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [roboform] "c:\program files\siber systems\ai roboform\robotaskbaricon.exe"
o6 - hkcu\software\policies\microsoft\internet explorer\control panel present
o6 - hklm\software\policies\microsoft\internet explorer\control panel present
o8 - extra context menu item: Add to banner ad blocker - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
o8 - extra context menu item: تخصيص القائمه - file://c:\program files\siber systems\ai roboform\roboformcomcustomizeiemenu.html
o8 - extra context menu item: حفظ النماذج - file://c:\program files\siber systems\ai roboform\roboformcomsavepass.html
o8 - extra context menu item: شريط ادوات روبوفورم - file://c:\program files\siber systems\ai roboform\roboformcomshowtoolbar.html
o8 - extra context menu item: ملئ النماذج - file://c:\program files\siber systems\ai roboform\roboformcomfillforms.html
o9 - extra button: Web traffic protection statistics - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky internet security 2009\scieplgn.dll
o9 - extra button: C??? C???c?? - {320af880-6646-11d3-abee-c5dbf3571f46} - file://c:\program files\siber systems\ai roboform\roboformcomfillforms.html
o9 - extra 'tools' menuitem: ??? C???c?? - {320af880-6646-11d3-abee-c5dbf3571f46} - file://c:\program files\siber systems\ai roboform\roboformcomfillforms.html
o9 - extra button: ??u - {320af880-6646-11d3-abee-c5dbf3571f49} - file://c:\program files\siber systems\ai roboform\roboformcomsavepass.html
o9 - extra 'tools' menuitem: ??u c???c?? - {320af880-6646-11d3-abee-c5dbf3571f49} - file://c:\program files\siber systems\ai roboform\roboformcomsavepass.html
o9 - extra button: ??e????? - {724d43aa-0d85-11d4-9908-00400523e39a} - file://c:\program files\siber systems\ai roboform\roboformcomshowtoolbar.html
o9 - extra 'tools' menuitem: O??? Ci?ce ??e????? - {724d43aa-0d85-11d4-9908-00400523e39a} - file://c:\program files\siber systems\ai roboform\roboformcomshowtoolbar.html
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o10 - unknown file in winsock lsp: C:\program files\vmware\vmware workstation\vsocklib.dll
o10 - unknown file in winsock lsp: C:\program files\vmware\vmware workstation\vsocklib.dll
o13 - gopher prefix:
O16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash object) -
o20 - appinit_dlls: C:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\adialhk.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
o22 - sharedtaskscheduler: Windows dreamscene - {e31004d1-a431-41b8-826f-e902f9d95c81} - c:\windows\system32\dreamscene.dll
o23 - service: Apple mobile device - apple inc. - c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
o23 - service: Asldr service (asldrservice) - unknown owner - c:\program files\atk hotkey\asldrsrv.exe
o23 - service: Kaspersky internet security (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
o23 - service: Bonjour service - apple inc. - c:\program files\bonjour\mdnsresponder.exe
o23 - service: Cfosspeed system service (cfosspeeds) - cfos software gmbh - c:\program files\topos\cfosspeed\spd.exe
o23 - service: Fspro filter service (fsproflt) - fspro labs - c:\windows\system32\fsproflt.exe
o23 - service: Getplus(r) helper - nos microsystems ltd. - c:\program files\nos\bin\getplus_helpersvc.exe
o23 - service: Hotspot shield service (hotspotshieldservice) - unknown owner - c:\program files\hotspot shield\bin\openvpnas.exe
o23 - service: Ipod service - apple inc. - c:\program files\ipod\bin\ipodservice.exe
o23 - service: Servicelayer - nokia. - c:\program files\pc connectivity solution\servicelayer.exe
o23 - service: Teamviewer 4 (teamviewer4) - teamviewer gmbh - c:\program files\teamviewer\version4\teamviewer_service.exe
o23 - service: @%systemroot%\system32\tuneupdefragservice.exe,-1 (tuneup.defrag) - tuneup software - c:\windows\system32\tuneupdefragservice.exe
o23 - service: @%systemroot%\system32\tuprogst.exe,-1 (tuneup.programstatisticssvc) - tuneup software - c:\windows\system32\tuprogst.exe
o23 - service: Vmware agent service (ufad-ws60) - vmware, inc. - c:\program files\vmware\vmware workstation\vmware-ufad.exe
o23 - service: Uniblue diskrescue - uniblue - c:\program files\uniblue\diskrescue\ubdiskrescuesrv.exe
o23 - service: Vmware authorization service (vmauthdservice) - vmware, inc. - c:\program files\vmware\vmware workstation\vmware-authd.exe
o23 - service: Vmware dhcp service (vmnetdhcp) - vmware, inc. - c:\windows\system32\vmnetdhcp.exe
o23 - service: Vmware nat service - vmware, inc. - c:\windows\system32\vmnat.exe
--
end of file - 10122 bytes