Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:52 AM, on 7/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Documents and Settings\Dan\My Documents\HijackThis.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.ebay.c...assZoldstufftwo
F3 - REG:win.ini: load=C:\WINDOWS\system32\ljjgh.exe
O2 - BHO: (no name) - {3E62B6AA-A7BB-4817-9B5F-3D9EE195CC6F} - C:\WINDOWS\system32\wvUkHYrO.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: {4c417e86-592d-2f59-3c74-aac5b168ca5e} - {e5ac861b-5caa-47c3-95f2-d29568e714c4} - C:\WINDOWS\system32\fevvag.dll
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [24db4c3a] rundll32.exe "C:\WINDOWS\system32\dudgtcdc.dll",b
O4 - HKLM\..\Run: [BM27e87fa6] Rundll32.exe "C:\WINDOWS\system32\snxfmvog.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingC4019] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data007.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6001] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data009.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7503] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data009.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8919] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data011.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6226] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data011.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9103] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data013.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3396] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data013.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4173] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data016.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5787] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data016.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6702] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data017.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8100] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data017.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8775] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data020.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1187] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data020.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA996] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data023.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6463] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data023.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7699] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data027.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8359] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data027.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7513] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data030.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6566] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data030.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7108] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data031.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4385] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data031.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5466] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data033.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4363] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data033.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5959] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data040.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9959] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data040.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2071] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data042.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3071] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data042.reg"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2466] command /c del "C:\WINDOWS\system32\wvUkHYrO.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC717] cmd /c del "C:\WINDOWS\system32\wvUkHYrO.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6532] command /c del "C:\WINDOWS\system32\snxfmvog.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4852] cmd /c del "C:\WINDOWS\system32\snxfmvog.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB460] command /c del "C:\Program Files\Performanceoptimizer (Free)\ua_manager.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3854] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\ua_manager.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9659] command /c del "C:\Program Files\Performanceoptimizer (Free)\uninstpo.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8089] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\uninstpo.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2992] command /c del "C:\Documents and Settings\Dan\Start Menu\Programs\Performance Optimizer\Performance Optimizer Home Page.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7792] cmd /c del "C:\Documents and Settings\Dan\Start Menu\Programs\Performance Optimizer\Performance Optimizer Home Page.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6454] command /c del "C:\Documents and Settings\Dan\Start Menu\Programs\Performance Optimizer\Performance Optimizer.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2831] cmd /c del "C:\Documents and Settings\Dan\Start Menu\Programs\Performance Optimizer\Performance Optimizer.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8668] command /c del "C:\Documents and Settings\Dan\Start Menu\Programs\Performance Optimizer\Sellmosoft Home Page.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3198] cmd /c del "C:\Documents and Settings\Dan\Start Menu\Programs\Performance Optimizer\Sellmosoft Home Page.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5132] command /c del "C:\Program Files\Performanceoptimizer (Free)\install_stat2.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD685] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\install_stat2.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7120] command /c del "C:\Program Files\Performanceoptimizer (Free)\PerfOpt.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7925] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\PerfOpt.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6814] command /c del "C:\Program Files\Performanceoptimizer (Free)\Performance Optimizer Home Page.url"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3507] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Performance Optimizer Home Page.url"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6830] command /c del "C:\Program Files\Performanceoptimizer (Free)\Sellmosoft Home Page.url"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1809] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Sellmosoft Home Page.url"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5309] command /c del "C:\Program Files\Performanceoptimizer (Free)\sload.sbd"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6788] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\sload.sbd"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2830] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data001.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5462] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data001.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6912] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data003.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9731] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data003.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5437] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data006.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3902] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data006.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2423] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data007.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3576] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data007.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7315] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data009.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD451] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data009.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1907] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data011.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9167] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data011.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5339] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data013.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9814] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data013.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8433] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data016.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2409] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data016.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2896] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data017.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD974] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data017.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB517] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data020.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7287] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data020.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7335] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data023.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD261] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data023.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1507] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data027.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3659] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data027.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1844] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data030.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5716] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data030.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3259] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data031.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1216] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data031.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4132] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data033.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2729] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data033.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6579] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data040.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9753] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data040.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9876] command /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data042.reg"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3160] cmd /c del "C:\Program Files\Performanceoptimizer (Free)\Tweaks\data042.reg"
O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Dan\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewi...oOnlineScan.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg...v43/yacscom.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - http://a.download.to...5.14/ttinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.on...e/en/crlocx.ocx
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} - http://tools.ebayimg...ol_v1-0-3-0.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: urqnomj - urqnomj.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 17587 bytes