Logfile of HijackThis v1.99.1
Scan saved at 2:29:07 PM, on 8/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\program files\Century Development\Century VPN Client\cvpnd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Barbara\Desktop\HijackThis.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~3\Office\1033\phdintl.dll/phdContext.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\i2nmlc511f.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\program files\Century Development\Century VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\oracle\ora81\BIN\ONRSD.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:59:37 PM, 8/22/2005
+ Report-Checksum: FF4AA3CC
+ Scan result:
HKLM\SOFTWARE\tsvcin -> Spyware.Look2Me : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00041A26-7033-432C-94C7-6371DE343822} -> Spyware.SearchEnhancement : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0421701D-CF13-4E70-ADF0-45A953E7CB8B} -> Spyware.SmartPops : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{12EE7A5E-0674-42F9-A76A-000000004D00} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{12EE7A5E-0674-42F9-A76B-000000004D00} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{13197ACE-6851-45C3-A7FF-C281324D5489} -> Spyware.2nsSearch : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1678F7E1-C422-11D0-AD7D-00400515CAAA} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28CAEFF3-0F18-4036-B504-51D73BD81ABC} -> Spyware.SearchMiracle : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36A59337-6EEF-40AE-94B1-ED443A0C4740} -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{825CF5BD-8862-4430-B771-0C15C5CA8DEF} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0CE16CB-741C-4B24-8D04-A817856E07F4} -> Spyware.Roimoi : Cleaned with backup
HKU\S-1-5-21-117609710-842925246-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBBD88E5-C372-469D-B4C5-1FE00352AB9B} -> Spyware.FavoriteMan : Cleaned with backup
[952] C:\WINDOWS\system32\ktp2l77o1.dll -> Spyware.Look2Me : Error during cleaning
[1368] C:\WINDOWS\system32\ncwrscs.dll -> Spyware.Look2Me : Error during cleaning
C:\Documents and Settings\Barbara\Local Settings\Temp\Cookies\barbara@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Program Files\Ftk\ftk.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000003.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000011.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000282.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000286.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000570.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000575.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000579.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000588.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000593.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{427964EB-5B75-4FC6-A643-368EA3831DB1}\RP1\A0000597.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\WINDOWS\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\msdownld.tmp\Temp\!update.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\msdownld.tmp\Temp\bw2.com -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\system32\aavapi32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ayi2dvaa.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\azamla711d.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cqmcat.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\d2j00c1mef.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dfnet.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\e8202ifmg82a2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\eR00bmsg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\exccmn.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\f22mlcf11f2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\fpls0337e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\HTL.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\i060lajm1doa.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\irj2l51o1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\j00slad71d0.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\jtl6073se.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\k0pmla711d.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\k426lefs1h26.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kddru1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kt20l7fm1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\l8p2li7o18.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\litif13n.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\lvju0919e.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\m2polc731f.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mfpatcha.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mygsvc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\Nodscsi.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\o248lchu1f48.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ojbcint.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ombcjt32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\oMkley.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\p6r40g9qe6.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\p8r40i9qe8.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rLstls.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rxmps.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\sflwid.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\svbcsp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\uqnpui.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\uqrdtea.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\vjmdbg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wcnsock.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\barbara@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\WINDOWS\Temp\Cookies\barbara@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
::Report End