Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:57:22 PM, on 1/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:..WINDOWS..System32..smss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..system32..svchost.exe
C:..Program Files..Lavasoft..Ad-Aware..aawservice.exe
C:..WINDOWS..Explorer.EXE
C:..WINDOWS..system32..spoolsv.exe
C:..WINDOWS..system32..hkcmd.exe
C:..WINDOWS..MMKeybd.exe
C:..PROGRA~1..Logitech..SYSTEM..EM_EXEC.EXE
C:..PROGRA~1..Grisoft..AVGFRE~1..avgcc.exe
C:..Program Files..Java..jre1.5.0_08..bin..jusched.exe
C:..Program Files..Netropa..OSD.exe
C:..Program Files..AT&T..Internet Security Wizard..ISW.exe
C:..Program Files..Bellsouth..HelpCenter40b..bin..sprtcmd.exe
C:..Program Files..iTunes..iTunesHelper.exe
C:..WINDOWS..Nhksrv.exe
C:..Program Files..MySpace..IM..MySpaceIM.exe
C:..WINDOWS..system32..ctfmon.exe
C:..Program Files..Common Files..Apple..Mobile Device Support..bin..AppleMobileDeviceService.exe
C:..PROGRA~1..Grisoft..AVGFRE~1..avgamsvr.exe
C:..PROGRA~1..Grisoft..AVGFRE~1..avgupsvc.exe
C:..PROGRA~1..Grisoft..AVGFRE~1..avgemc.exe
C:..Program Files..Bonjour..mDNSResponder.exe
C:..Program Files..Common Files..Motive..McciCMService.exe
C:..WINDOWS..System32..svchost.exe
C:..Program Files..Viewpoint..Common..ViewpointService.exe
C:..Program Files..iPod..bin..iPodService.exe
C:..Program Files..Viewpoint..Viewpoint Manager..ViewMgr.exe
C:..WINDOWS..system32..wuauclt.exe
C:..Program Files..MySpace..IM..MySpaceIM.exe
C:..Program Files..Java..jre1.5.0_08..bin..jucheck.exe
C:..PROGRA~1..Grisoft..AVGFRE~1..avgwb.dat
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Search Page = http://g. msn. com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = http://my. att. net
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://go. microsoft. com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL = http://go. microsoft. com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Page = http://go. microsoft. com/fwlink/?LinkId=54896
R0 - HKLM..Software..Microsoft..Internet Explorer..Main,Start Page = http://go. microsoft. com/fwlink/?LinkId=69157
R0 - HKLM..Software..Microsoft..Internet Explorer..Search,SearchAssistant = http://resultsmaster. com/SmartOffers/Services/resultsmaster/ResultsMasterHomeLeft
Pane. htm
R1 - HKCU..Software..Microsoft..Internet Explorer..SearchURL,(Default) = http://g. msn. com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU..Software..Microsoft..Windows..CurrentVersion..Internet
Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:..Program Files..Common Files..Adobe..Acrobat..ActiveX..AcroIEHelper.dll
O2 - BHO: &Research - {0B014B81-4E12-46F9-806F-55867AF8FD3C} - C:..WINDOWS..system32..winsystems.dll
O2 - BHO: testCPV6 - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:..Program Files..Webtools..webtools.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:..Program Files..Java..jre1.5.0_08..bin..ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:..Program Files..Google..Google Toolbar..GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:..Program Files..Google..GoogleToolbarNotifier..5.0.926.3450..swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:..Program Files..Google..Google Toolbar..Component..fastsearch_219B3E1547538286.dll
O3 - Toolbar: (no name) - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:..Program Files..Google..Google Toolbar..GoogleToolbar.dll
O4 - HKLM......Run: [IgfxTray] C:..WINDOWS..system32..igfxtray.exe
O4 - HKLM......Run: [HotKeysCmds] C:..WINDOWS..system32..hkcmd.exe
O4 - HKLM......Run: [DellTouch] C:..WINDOWS..MMKeybd.exe
O4 - HKLM......Run: [EM_EXEC] C:..PROGRA~1..Logitech..SYSTEM..EM_EXEC.EXE
O4 - HKLM......Run: [AVG7_CC] C:..PROGRA~1..Grisoft..AVGFRE~1..avgcc.exe /STARTUP
O4 - HKLM......Run: [IPHSend] C:..Program Files..Common Files..AOL..IPHSend..IPHSend.exe
O4 - HKLM......Run: [SunJavaUpdateSched] "C:..Program Files..Java..jre1.5.0_08..bin..jusched.exe"
O4 - HKLM......Run: [ProfileWatcher] C:..Program Files..ProfileWatcher..profilewatcher.exe
O4 - HKLM......Run: [SDR6_Check] "C:..Program Files..Common Files..DriveCleaner Free..udcsdr.exe"
O4 - HKLM......Run: [PAS_Check] "C:..Program Files..Common Files..DriveCleaner Free..udcpas.exe"
O4 - HKLM......Run: [KernelFaultCheck] %systemroot%..system32..dumprep 0 -k
O4 - HKLM......Run: [Adobe Reader Speed Launcher] "C:..Program Files..Adobe..Reader 8.0..Reader..Reader_sl.exe"
O4 - HKLM......Run: [ISW.exe] "C:..Program Files..AT&T..Internet Security Wizard..ISW.exe" /AUTORUN
O4 - HKLM......Run: [HelpCenter4.1] C:..Program Files..Bellsouth..HelpCenter40b..bin..sprtcmd.exe /P HelpCenter4.1
O4 - HKLM......Run: [QuickTime Task] "C:..Program Files..QuickTime..QTTask.exe" -atboottime
O4 - HKLM......Run: [iTunesHelper] "C:..Program Files..iTunes..iTunesHelper.exe"
O4 - HKCU......Run: [MySpaceIM] C:..Program Files..MySpace..IM..MySpaceIM.exe
O4 - HKCU......Run: [ctfmon.exe] C:..WINDOWS..system32..ctfmon.exe
O4 - HKCU......Run: [MsnMsgr] "C:..Program Files..MSN Messenger..MsnMsgr.Exe" /background
O4 - HKCU......Run: [GetModule29] C:..Program Files..GetModule..GetModule29.exe
O4 - HKCU......Run: [78642331366494082346418562388856] C:..Program Files..Antivirus 2009..av360.exe
O4 - HKUS..S-1-5-19......Run: [AVG7_Run] C:..PROGRA~1..Grisoft..AVGFRE~1..avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS..S-1-5-20......Run: [AVG7_Run] C:..PROGRA~1..Grisoft..AVGFRE~1..avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS..S-1-5-18......Run: [AVG7_Run] C:..PROGRA~1..Grisoft..AVGFRE~1..avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS...DEFAULT......Run: [AVG7_Run] C:..PROGRA~1..Grisoft..AVGFRE~1..avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:..program files..aol..aim toolbar 5.0..resources..en-US..local..search.html
O8 - Extra context menu item: &Search - http://edits. mywebsearch. com/toolbaredits/menusearch. jhtml?p=ZKxdm011YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..WINDOWS..System32..msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:..WINDOWS..System32..msjava.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network Diagnostic..xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:..WINDOWS..Network Diagnostic..xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:..Program Files..Messenger..msmsgs.exe
O16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} (Support. com SmartIssue) - http://support. fastaccess. com/sdccommon/download/tgctlsi. cab
O16 - DPF: {01112B00-3E00-11D2-8470-0060089874ED} (Support. com RemoteControl Class) - http://support. fastaccess. com/sdccommon/download/tgrc. cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support. com Configuration Class) - http://help. bellsouth. net/sdccommon/download/tgctlcm. cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup. msn. com/pages/MsnInstC. cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak. exe. imgfarm. com/images/nocache/funwebproducts/ei/WebfettiInitialSetup1. 0. 0. 15-3. cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www. drivecleaner. com/. freeware/installdrivecleanerstart. cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2. macromedia. com/get/shockwave/cabs/flash/swflash. cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:..Program Files..Lavasoft..Ad-Aware..aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:..Program Files..Common Files..Apple..Mobile Device Support..bin..AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:..PROGRA~1..Grisoft..AVGFRE~1..avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:..PROGRA~1..Grisoft..AVGFRE~1..avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:..PROGRA~1..Grisoft..AVGFRE~1..avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:..Program Files..Bonjour..mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:..Program Files..Google..Common..Google Updater..GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:..Program Files..iPod..bin..iPodService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:..Program Files..Common Files..Motive..McciCMService.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:..WINDOWS..Nhksrv.exe
O23 - Service: Shell Software Detection (ShellSWDetection) - Unknown owner - C:..WINDOWS..system32..shellsw.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:..Program Files..Viewpoint..Common..ViewpointService.exe
--
End of file - 9460 bytes