logfile of trend micro hijackthis v2.0.2
scan saved at 12:47:16 ص, on 03/08/2009
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v7.00 (7.00.6000.16640)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\program files\usb safely remove\usbsrservice.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\windows\explorer.exe
c:\windows\rthdcpl.exe
c:\program files\unlocker\unlockerassistant.exe
c:\windows\vsnpstd3.exe
c:\program files\java\jre6\bin\jusched.exe
c:\vistadriveicon\drvicon.exe
c:\windows\system32\ctfmon.exe
c:\program files\usb safely remove\usbsafelyremove.exe
c:\program files\rocketdock\rocketdock.exe
c:\program files\hotspot shield\anchorfree\ctrl\afcontroller.exe
c:\program files\siber systems\ai roboform\robotaskbaricon.exe
c:\windows\system32\astsrv.exe
c:\program files\bonjour\mdnsresponder.exe
c:\windows\system32\crypserv.exe
c:\progra~1\gfi\gfibac~1\gfihinst.exe
c:\progra~1\gfi\gfibac~1\gfihsc~1.exe
c:\program files\hotspot shield\bin\openvpnas.exe
c:\program files\java\jre6\bin\jqs.exe
c:\program files\common files\lightscribe\lssrvc.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\program files\common files\nero\nero backitup 4\nbservice.exe
c:\windows\system32\svchost.exe
c:\program files\common files\ulead systems\dvd\ulcdrsvr.exe
c:\program files\internet download manager\iemonitor.exe
c:\windows\system32\svchost.exe
c:\program files\mozilla firefox\firefox.exe
c:\program files\internet download manager\idman.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\windows live\contacts\wlcomm.exe
c:\documents and settings\administrator\سطح المكتب\fscapture.exe
c:\docume~1\admini~1\locals~1\temp\rarsfx0\fscapture.exe
c:\program files\java\jre6\launch4j-tmp\frd.exe
h:\برامج الكمبيوتر\برامج تعمل بدون تثبيت\بورتابل برنامج ava find خطيـــــر للبحث السريع جداً جداً نسخة مكركرة وكاملة\ava find.exe
c:\documents and settings\administrator\my documents\downloads\programs\hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,first home page =
r1 - hkcu\software\microsoft\internet explorer\main,window title = *@lf@is@l* internet explorer
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = *.local;<local>
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
o2 - bho: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
o2 - bho: (no name) - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - (no file)
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o2 - bho: Jqsiestartdetectorimpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
o3 - toolbar: Radio - {8e718888-423f-11d2-876e-00a0c9082467} - c:\windows\system32\msdxm.ocx
o3 - toolbar: (no name) - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - (no file)
o3 - toolbar: &roboform - {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
o4 - hklm\..\run: [rthdcpl] rthdcpl.exe
o4 - hklm\..\run: [skytel] skytel.exe
o4 - hklm\..\run: [alcmtr] alcmtr.exe
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
o4 - hklm\..\run: [unlockerassistant] "c:\program files\unlocker\unlockerassistant.exe"
o4 - hklm\..\run: [clocx] c:\program files\clocx\clocx.exe
o4 - hklm\..\run: [snpstd3] c:\windows\vsnpstd3.exe
o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files\java\jre6\bin\jusched.exe"
o4 - hklm\..\run: [nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe
o4 - hklm\..\run: [drvicon] c:\vistadriveicon\drvicon.exe
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [avafind] "c:\program files\avafind\avafind.exe" /minimized
o4 - hkcu\..\run: [idman] c:\program files\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [usb safely remove] c:\program files\usb safely remove\usbsafelyremove.exe /startup
o4 - hkcu\..\run: [rocketdock] "c:\program files\rocketdock\rocketdock.exe"
o4 - hkcu\..\run: [afprog] c:\program files\hotspot shield\anchorfree\ctrl\afcontroller.exe
o4 - hkcu\..\run: [roboform] "c:\program files\siber systems\ai roboform\robotaskbaricon.exe"
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [nltide_2] regsvr32 /s /n /i:u shell32 (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [itd7] "c:\program files\steganos internet trace destructor 7\itd7.exe" -firstboot (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-20\..\runonce: [nltide_2] regsvr32 /s /n /i:u shell32 (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\s-1-5-18\..\runonce: [nltide_2] regsvr32 /s /n /i:u shell32 (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - hkus\.default\..\runonce: [nltide_2] regsvr32 /s /n /i:u shell32 (user 'default user')
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~1\office11\excel.exe/3000
o8 - extra context menu item: إضافة إلى حاجب إعلان الشعار - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm
o8 - extra context menu item: ت&صدير إلى microsoft excel - res://c:\progra~1\micros~1\office12\excel.exe/3000
o8 - extra context menu item: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
o8 - extra context menu item: تخصيص القائمه - file://c:\program files\siber systems\ai roboform\roboformcomcustomizeiemenu.html
o8 - extra context menu item: حفظ النماذج - file://c:\program files\siber systems\ai roboform\roboformcomsavepass.html
o8 - extra context menu item: شريط ادوات روبوفورم - file://c:\program files\siber systems\ai roboform\roboformcomshowtoolbar.html
o8 - extra context menu item: ملئ النماذج - file://c:\program files\siber systems\ai roboform\roboformcomfillforms.html
o8 - extra context menu item: وباستخدام التحميل &bitspirit - c:\program files\bitspirit\bsurl.htm
o9 - extra button: إحصائيات حماية حركة زيارة الويب - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky internet security 2009\scieplgn.dll
o9 - extra button: (no name) - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\windows\system32\shdocvw.dll
o9 - extra button: املأ النماذج - {320af880-6646-11d3-abee-c5dbf3571f46} - file://c:\program files\siber systems\ai roboform\roboformcomfillforms.html
o9 - extra 'tools' menuitem: ملئ النماذج - {320af880-6646-11d3-abee-c5dbf3571f46} - file://c:\program files\siber systems\ai roboform\roboformcomfillforms.html
o9 - extra button: حفظ - {320af880-6646-11d3-abee-c5dbf3571f49} - file://c:\program files\siber systems\ai roboform\roboformcomsavepass.html
o9 - extra 'tools' menuitem: حفظ النماذج - {320af880-6646-11d3-abee-c5dbf3571f49} - file://c:\program files\siber systems\ai roboform\roboformcomsavepass.html
o9 - extra button: روبوفورم - {724d43aa-0d85-11d4-9908-00400523e39a} - file://c:\program files\siber systems\ai roboform\roboformcomshowtoolbar.html
o9 - extra 'tools' menuitem: شريط ادوات روبوفورم - {724d43aa-0d85-11d4-9908-00400523e39a} - file://c:\program files\siber systems\ai roboform\roboformcomshowtoolbar.html
o9 - extra button: Bonjour - {7f9db11c-e358-4ca6-a83d-acc663939424} - c:\program files\bonjour\explorerplugin.dll
o9 - extra button: Add to videoget - {88cfa58b-a63f-4a94-9c54-0c7a58e3333e} - c:\progra~1\nuclea~1\videoget\plugins\videog~1.dll
o9 - extra 'tools' menuitem: Add to &videoget - {88cfa58b-a63f-4a94-9c54-0c7a58e3333e} - c:\progra~1\nuclea~1\videoget\plugins\videog~1.dll
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~1\office11\refiebar.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o10 - unknown file in winsock lsp: Nclspnt.dll
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash object) -
o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - (no file)
o20 - appinit_dlls: C:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\adialhk.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
o20 - winlogon notify: Antiwpa - c:\windows\system32\antiwpa.dll
o20 - winlogon notify: Hggawvoo - hggawvoo.dll (file missing)
o23 - service: Ast service (astcc) - nalpeiron ltd. - c:\windows\system32\astsrv.exe
o23 - service: Kaspersky internet security (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
o23 - service: Bonjour service - apple inc. - c:\program files\bonjour\mdnsresponder.exe
o23 - service: Crypkey license - kenonic controls ltd. - c:\windows\system32\crypserv.exe
o23 - service: Flexnet licensing service - macrovision europe ltd. - c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe
o23 - service: Gfi backup 2009 - home edition attendant service (gfibckhatt) - gfi software ltd. - c:\progra~1\gfi\gfibac~1\gfihinst.exe
o23 - service: Gfi backup 2009 - home edition scheduler service (gfibckhsched) - gfi software ltd. - c:\progra~1\gfi\gfibac~1\gfihsc~1.exe
o23 - service: Hotspot shield service (hotspotshieldservice) - unknown owner - c:\program files\hotspot shield\bin\openvpnas.exe
o23 - service: Java quick starter (javaquickstarterservice) - sun microsystems, inc. - c:\program files\java\jre6\bin\jqs.exe
o23 - service: Lightscribeservice direct disc labeling service (lightscribeservice) - hewlett-packard company - c:\program files\common files\lightscribe\lssrvc.exe
o23 - service: Microsoft office groove audit service - unknown owner - c:\program files\microsoft office\office12\grooveauditservice.exe (file missing)
o23 - service: Nbservice - nero ag - c:\program files\nero\nero 7\nero backitup\nbservice.exe
o23 - service: Net control 2 remote desktop server service (nc2remotedesktop) - net software 2 - c:\program files\net control 2\ncvserver.exe
o23 - service: Nero backitup scheduler 4.0 - nero ag - c:\program files\common files\nero\nero backitup 4\nbservice.exe
o23 - service: Net control 2 server (netcontrol2server) - net software 2 - c:\program files\net control 2\ncserver.exe
o23 - service: Nmindexingservice - nero ag - c:\program files\common files\ahead\lib\nmindexingservice.exe
o23 - service: Pml driver hpz12 - hp - c:\windows\system32\hpzipm12.exe
o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - cace technologies - c:\program files\winpcap\rpcapd.exe
o23 - service: Ulead burning helper (uleadburninghelper) - ulead systems, inc. - c:\program files\common files\ulead systems\dvd\ulcdrsvr.exe
o23 - service: Usb safely remove assistant (usbsafelyremoveservice) - unknown owner - c:\program files\usb safely remove\usbsrservice.exe
--
end of file - 13280 bytes