Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:16:04 PM, on 5/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft....k/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.aka...vex-2.0.6.4.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecu...asyInstallX.CAB
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe (file missing)
--
End of file - 7107 bytes
------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.12
Database version: 744
Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 157137
Time elapsed: 2 hour(s), 25 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
--------------------------------------------------------------
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 05/13/2008 at 05:23 PM
Application Version : 4.0.1154
Core Rules Database Version : 3459
Trace Rules Database Version: 1450
Scan type : Quick Scan
Total Scan Time : 00:13:00
Memory items scanned : 427
Memory threats detected : 0
Registry items scanned : 399
Registry threats detected : 0
File items scanned : 5730
File threats detected : 123
Adware.Tracking Cookie
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][3].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][3].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][3].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][4].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected]twork[1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][1].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
C:\Documents and Settings\dre&bev\Cookies\dre&[email protected][2].txt
Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\NNNMP.INI
thanks!
Edited by heyitssupergirl, 14 May 2008 - 05:46 PM.