Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:21:06 PM, on 12/21/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\nslsvice.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Altiris\AClient\AClient.exe C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe C:\WINDOWS\System32\Ati2evxx.exe C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\RCSERV.EXE C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\atiptaxx.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Legato\DiskXtender Explorer Add-ons\BIN\DxShell.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Peregrine Call Optimization\bin\mpbtn.exe C:\WINDOWS\system32\rcntrlwa.exe C:\WINDOWS\system32\kqdsrngs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\windows C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portal.edisonintl.com/irj/portal R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://portal.edisonintl.com/irj/portal R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://edna.sce.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Edison International R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://edna.sce.com/ie5/ie6/sp1/ie_proxy.pac R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.edisonintl.com;*.sce.com; *myedison.net; myedison.*; O1 - Hosts: 155.13.134.119 g2vlide04 O1 - Hosts: 155.13.79.47 go2ntldsr02 O1 - Hosts: 153.13.79.187 go2ntldsr03 O1 - Hosts: 155.13.134.100 g2vldsr01 O1 - Hosts: 155.13.134.127 g2vldsr02 O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [DiskXtender Explorer Add-ons] C:\Program Files\Legato\DiskXtender Explorer Add-ons\BIN\DxShell.exe /NOWIZARD O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [SCAT Launcher] C:\CORPAPPS\DESKTOP_MGMT\dalaunch.exe O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe O4 - HKLM\..\Run: [SwdisUsrPCN.D096506] "C:\PROGRA~1\Tivoli\lcf\dat\2\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.envD096506" O4 - HKLM\..\Run: [AeXAgentLogon] "C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe" /logon O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [{E2-2D-D7-78-ZN}] C:\WINDOWS\system32\kqdsrngs.exe CHD001 O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\rcntrlwa.exe CHD001 O4 - HKLM\..\Run: [{E2-2D-D7-78-DW}] C:\WINDOWS\system32\kqwdw64s.exe CHD001 O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [44fe2dd7] rundll32.exe "C:\WINDOWS\system32\tfluaqkb.dll",b O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKLM\..\Policies\Explorer\Run: [wininet.dll] regperf.exe O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\rcntrlwa.exe O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\kqwdw64s.exe O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\kqdsrngs.exe O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\rwinrldq.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Peregrine Call Optimization.lnk = C:\Program Files\Peregrine Call Optimization\bin\mpbtn.exe O4 - Global Startup: SAP_IE.LNK = C:\CorpApps\DESKTOP_MGMT\SAP_IE.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://edna.sce.com/ O15 - Trusted Zone: http://media.corporate-ir.net O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.kumudam.com/wfplayer/tdserver.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/21c838315f355cf30b05/netzip/RdxIE601.cab O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sce.eix.com O17 - HKLM\Software\..\Telephony: DomainName = sce.eix.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sce.eix.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = edisonintl.com,sce.eix.com,sce.com,eix.com O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = edisonintl.com,sce.eix.com,sce.com,eix.com O20 - AppInit_DLLs: AMINIT.dll c:\windows\system32\ldcore.dll O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Altiris\AClient\AClient.exe O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: Bits Tool Service - Southern California Edison - c:\corpapps\desktop_mgmt\btsrvc.exs O23 - Service: DB2 JDBC Applet Server (DB2JDS) - Unknown owner - C:\corpapps\ddcs\sqllib\bin\db2jds.exe O23 - Service: DB2 Security Server (DB2NTSECSERVER) - International Business Machines Corporation - C:\corpapps\ddcs\sqllib\bin\db2sec.exe O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\brrdsrch.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\WINDOWS\System32\nslsvice.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\lotus\notes\ntmulti.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: OracleOraHome90ClientCache - Unknown owner - C:\oracle\ora90\bin\ONRSD.EXE O23 - Service: Tivoli Remote Control Service (TME10RC) - IBM Corporation - C:\WINDOWS\RCSERV.EXE -- End of file - 10188 bytes