
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:33:53 PM, on 8/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\DSentry.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\Lloyd Lopez\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [USRobotics Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\system32\DSentry.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXBOX_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\AXSKY_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\AXBANN~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\ADS_1_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\FASTLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\BUDSBO~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\BUDSLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\FASTSK~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXLEAD~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\STATS_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\INDEX
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcp...a/PCPitStop.CAB
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase5036.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1219737890859
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: AplDsc - {26299438-EA22-2AA5-8B34-0923437708C1} - C:\Program Files\zipnrrd\AplDsc.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 6113 bytes
StartupList report, 8/26/2008, 12:35:42 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Lloyd Lopez\Desktop\HiJackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16705)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\DSentry.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\Lloyd Lopez\Desktop\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
mcagent_exe = C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
USRobotics Wireless Manager UI = C:\WINDOWS\system32\WLTRAY.exe
DVDSentry = C:\WINDOWS\system32\DSentry.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
DelayShred = "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXBOX_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\AXSKY_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\AXBANN~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\ADS_1_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\FASTLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\BUDSBO~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\CLICK_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\BUDSLE~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\FOSQVT6W\FASTSK~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\AXLEAD~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\STATS_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\INDEX_~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\TCYH4ECN\FASTBO~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\9JSCHH5X\160X60~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\TEMPOR~1\Content.IE5\VI3W8Z5W\BUDSSK~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\CABGEN~1\DirOne\default.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\CABGEN~1\DirOne.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\CABGEN~1.SH! C:\DOCUME~1\LLOYDL~1\LOCALS~1\Temp\HSPERF~1.SH!
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
=
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
McDefragTask.job
McQcTask.job
--------------------------------------------------
Enumerating Download Program Files:
[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://utilities.pcp...a/PCPitStop.CAB
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Adobe\Director\swdir.dll
CODEBASE = http://download.macr...director/sw.cab
[Windows Live Safety Center Base Module]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\wlscBase.dll
CODEBASE = http://cdn.scan.onec...lscbase5036.cab
[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.micros...b?1219737890859
[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.ma...t/ultrashim.cab
--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
AplDsc: C:\Program Files\zipnrrd\AplDsc.dll
--------------------------------------------------
End of report, 6,583 bytes
Report generated in 0.370 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only