Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 21:47:03, on 22-3-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\csrss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\guard.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\Program Files\\Sitecom\\Bluetooth Software\\bin\\btwdins.exe
C:\\WINDOWS\\system32\\cisvc.exe
C:\\WINDOWS\\System32\\nvsvc32.exe
C:\\Program Files\\Spyware Doctor\\svcntaux.exe
C:\\Program Files\\Spyware Doctor\\swdsvc.exe
C:\\Program Files\\Alcohol Soft\\Alcohol 120\\StarWind\\StarWindService.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\Program Files\\Webroot\\Spy Sweeper\\WRSSSDK.exe
C:\\WINDOWS\\system32\\rundll32.exe
C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe
C:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe
C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe
C:\\WINDOWS\\system32\\ctfmon.exe
C:\\Program Files\\PeerGuardian2\\pg2.exe
C:\\Program Files\\CleanMyPC\\Registry Cleaner\\RCHelper.exe
C:\\Program Files\\Sitecom\\Bluetooth Software\\BTTray.exe
C:\\Program Files\\Nokia\\PC Suite for Nokia 6600\\connmngmntbox.exe
C:\\Program Files\\Nokia\\PC Suite for Nokia 6600\\ectaskscheduler.exe
C:\\Program Files\\Intuwave\\Shared\\mRouterRunTime\\mRouterRuntime.exe
C:\\PROGRA~1\\Nokia\\PCSUIT~1\\Elogerr.exe
C:\\PROGRA~1\\Nokia\\PCSUIT~1\\BROADC~1.EXE
C:\\PROGRA~1\\Nokia\\PCSUIT~1\\SCRFS.exe
C:\\Program Files\\PC Connectivity Solution\\ServiceLayer.exe
C:\\Program Files\\MSN Messenger\\usnsvc.exe
C:\\WINDOWS\\System32\\alg.exe
C:\\Program Files\\PC Connectivity Solution\\NclBTHandler.exe
C:\\Program Files\\Spyware Doctor\\update.exe
C:\\WINDOWS\\explorer.exe
C:\\Program Files\\Azureus\\Azureus.exe
C:\\Program Files\\Mozilla Firefox\\firefox.exe
C:\\Temp\\HiJackThis_v2.exe
C:\\WINDOWS\\System32\\wbem\\wmiprvse.exe
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL =
http://www.euro.dell.com/R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page =
http://google.icq.comR0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =
http://owa.nl.logicacmg.com/exchange/logon.aspR1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL =
http://www.euro.dell.com/R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =
http://www.euro.dell.comR0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\Program Files\\Adobe\\Acrobat 7.0\\ActiveX\\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\\WINDOWS\\system32\\dla\\tfswshx.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\\Program Files\\Ipswitch\\WS_FTP Pro\\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files\\Java\\jre1.5.0_06\\bin\\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\\..\\Run: [NvCplDaemon] RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup
O4 - HKLM\\..\\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\\..\\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\\Program Files\\Google\\Gmail Notifier\\G001-1.0.25.0\\gnotify.exe
O4 - HKLM\\..\\Run: [DAEMON Tools] \"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033
O4 - HKLM\\..\\Run: [AVG7_CC] C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP
O4 - HKLM\\..\\Run: [TkBellExe] \"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot
O4 - HKLM\\..\\Run: [PCSuiteTrayApplication] C:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -startup
O4 - HKLM\\..\\Run: [TomTomHOME.exe] \"C:\\Program Files\\TomTom HOME\\TomTomHOME.exe\" -s
O4 - HKLM\\..\\Run: [hldrrr] C:\\WINDOWS\\system32\\hldrrr.exe
O4 - HKLM\\..\\Run: [!AVG Anti-Spyware] \"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized
O4 - HKCU\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\system32\\ctfmon.exe
O4 - HKCU\\..\\Run: [PeerGuardian] C:\\Program Files\\PeerGuardian2\\pg2.exe
O4 - HKCU\\..\\Run: [msnmsgr] \"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background
O4 - HKCU\\..\\Run: [Registry Cleaner Scheduler] \"C:\\Program Files\\CleanMyPC\\Registry Cleaner\\RCHelper.exe\" /startup
O4 - HKCU\\..\\Run: [german.exe] C:\\WINDOWS\\system32\\wintems.exe
O4 - HKCU\\..\\Run: [drvsyskit] C:\\Documents and Settings\\-\\Application Data\\hidires\\hidr.exe
O4 - HKCU\\..\\Run: [hldrrr] C:\\WINDOWS\\system32\\hldrrr.exe
O4 - HKUS\\S-1-5-19\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'Lokale service\')
O4 - HKUS\\S-1-5-19\\..\\Run: [AVG7_Run] C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE (User \'Lokale service\')
O4 - HKUS\\S-1-5-20\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'Netwerkservice\')
O4 - HKUS\\S-1-5-18\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'SYSTEM\')
O4 - HKUS\\.DEFAULT\\..\\Run: [CTFMON.EXE] C:\\WINDOWS\\System32\\CTFMON.EXE (User \'Default user\')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: PCSuiteForNokia6600 Detect.lnk = ?
O4 - Global Startup: PCSuiteForNokia6600 TS.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.5.0_06\\bin\\ssv.dll
O9 - Extra \'Tools\' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.5.0_06\\bin\\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\\PROGRA~1\\SPYWAR~1\\tools\\iesdpb.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\\PROGRA~1\\ICQ\\ICQ.exe (file missing)
O9 - Extra \'Tools\' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\\PROGRA~1\\ICQ\\ICQ.exe (file missing)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\Sitecom\\Bluetooth Software\\btsendto_ie.htm
O9 - Extra \'Tools\' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\Sitecom\\Bluetooth Software\\btsendto_ie.htm
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\\Program Files\\PartyGaming.Net\\PartyPokerNet\\RunPF.exe
O9 - Extra \'Tools\' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\\Program Files\\PartyGaming.Net\\PartyPokerNet\\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\\windows\\system32\\nwprovau.dll
O10 - Unknown file in Winsock LSP: c:\\program files\\spyware doctor\\filterlsp.dll
O10 - Unknown file in Winsock LSP: c:\\program files\\spyware doctor\\filterlsp.dll
O10 - Unknown file in Winsock LSP: c:\\program files\\spyware doctor\\filterlsp.dll
O10 - Unknown file in Winsock LSP: c:\\program files\\spyware doctor\\filterlsp.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.euro.dell.com/systemprofiler/SysPro.CABO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://spaces.msn.com//PhotoUpload/MsnPUpld.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn(...)sClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://game19.zylomgames.com/activex/zylomgamesplayer.cabO22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\\WINDOWS\\System32\\browseui.dll
O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieėn - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\\WINDOWS\\System32\\browseui.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\guard.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\\Program Files\\Sitecom\\Bluetooth Software\\bin\\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\\Program Files\\Common Files\\InstallShield\\Driver\\11\\Intel 32\\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\\Program Files\\Intel\\NCS\\Sync\\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\\WINDOWS\\System32\\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\\Program Files\\Spyware Doctor\\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\\Program Files\\Spyware Doctor\\swdsvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\\Program Files\\Spyware Doctor\\sdhelp.exe
O23 - Service: ServiceLayer - Nokia. - C:\\Program Files\\PC Connectivity Solution\\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\\Program Files\\Alcohol Soft\\Alcohol 120\\StarWind\\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\\Program Files\\Webroot\\Spy Sweeper\\WRSSSDK.exe
--
End of file - 10130 bytes