| Logfile of HijackThis v1.99.1 |
|
|
|
|
|
|
|
| Scan saved at 7:34:24 PM, on 3/7/2005 |
|
|
|
|
|
|
| Platform: Windows XP (WinNT 5.01.2600) |
|
|
|
|
|
|
| MSIE: Internet Explorer v6.00 (6.00.2600.0000) |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Running processes: |
|
|
|
|
|
|
|
|
| C:\WINDOWS\System32\smss.exe |
|
|
|
|
|
|
| C:\WINDOWS\system32\winlogon.exe |
|
|
|
|
|
|
| C:\WINDOWS\system32\services.exe |
|
|
|
|
|
|
| C:\WINDOWS\system32\lsass.exe |
|
|
|
|
|
|
| C:\WINDOWS\system32\svchost.exe |
|
|
|
|
|
|
| C:\WINDOWS\System32\svchost.exe |
|
|
|
|
|
|
| C:\WINDOWS\Explorer.EXE |
|
|
|
|
|
|
|
| C:\WINDOWS\system32\spoolsv.exe |
|
|
|
|
|
|
| C:\Program Files\Evidence Exterminator\erasrv.exe |
|
|
|
|
|
| C:\Program Files\Network Associates\Common Framework\FrameworkService.exe |
|
|
| C:\Program Files\Network Associates\VirusScan\Mcshield.exe |
|
|
|
|
| C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe |
|
|
|
|
| C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe |
|
|
|
| C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe |
|
|
| C:\Program Files\Microsoft Hardware\Keyboard\type32.exe |
|
|
|
|
| C:\WINDOWS\System32\InetCntrl\InetCntrl.exe |
|
|
|
|
|
| C:\Program Files\Creative\ShareDLL\CtNotify.exe |
|
|
|
|
|
| C:\Program Files\Common Files\Real\Update_OB\realsched.exe |
|
|
|
|
| C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe |
|
|
|
| C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE |
|
|
| C:\Program Files\SPYBOT - SEARCH & DESTROY\TeaTimer.exe |
|
|
|
| C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE |
|
|
|
|
| C:\WINDOWS\System32\devldr32.exe |
|
|
|
|
|
|
| C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe |
|
|
| C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AvltMain.exe |
|
|
| C:\PROGRA~1\WINZIP\winzip32.exe |
|
|
|
|
|
|
| C:\hhhhhhh\hijackthis[1]\HijackThis.exe |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hispeed.rogers.com |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet |
| R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) |
|
| F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\SYSTEM\Userinit.exe |
| O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX |
| O2 - BHO: IYBookmarkHO Class - {8B11A219-80C8-4B42-B558-B8C14D1AA8C4} - C:\PROGRAM FILES\YAHOO!\BROWSER\YBMHO.DLL |
| O2 - BHO: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\System32\InetCntrl\PopupKil\BsafeBHO.dll |
| O3 - Toolbar: (no name) - {4B7B69EB-A00F-4FCD-B601-ACCBB86ED528} - (no file) |
|
|
| O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSCSHELLEXTENSION.DLL |
| O3 - Toolbar: (no name) - {43F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) |
|
|
| O3 - Toolbar: (no name) - {EB381422-F797-4A98-A266-9DC490821907} - (no file) |
|
|
| O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx |
| O4 - HKLM\..\Run: [SystemTray] SysTray.Exe |
|
|
|
|
|
| O4 - HKLM\..\Run: [IntelliType] c:\Program Files\Microsoft Hardware\Keyboard\type32.exe |
|
| O4 - HKLM\..\Run: [ShStatEXE] C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE /STANDALONE |
| O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime |
|
| O4 - HKLM\..\Run: [InetCntrl] C:\WINDOWS\System32\InetCntrl\InetCntrl.exe |
|
|
| O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme |
|
| O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe |
|
|
| O4 - HKLM\..\Run: [LoadQM] loadqm.exe |
|
|
|
|
|
|
| O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot |
| O4 - HKLM\..\Run: [McAfeeUpdaterUI] C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe /StartedFromRunKey |
| O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k |
|
|
| O4 - HKLM\..\Run: [xgzwbab] C:\WINDOWS\xgzwbab.exe |
|
|
|
|
| O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s |
| O4 - HKLM\..\Run: [00ERSRRRNKY] C:\Program Files\Evidence Exterminator\eraser.exe |
|
| O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM32\STIMON.EXE |
|
| O4 - HKLM\..\RunOnce: [00ERSRRRNKY] "C:\Program Files\Evidence Exterminator\erasrv.exe" remove |
| O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\SPYBOT - SEARCH & DESTROY\TeaTimer.exe |
| O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe |
|
|
| O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present |
|
|
| O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present |
|
|
| O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxmk145YYUS |
| O9 - Extra button: Advanced Searchbar - {43F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) |
|
| O9 - Extra 'Tools' menuitem: Advanced Searchbar - {43F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) |
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE |
| O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE |
| O9 - Extra button: Dot 911 - {D11BC200-4763-11D6-A2A7-921526F09972} - http://dot.dotsafe.net/ (file missing) (HKCU) |
| O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing |
|
|
|
| O14 - IERESET.INF: START_PAGE_URL=http://hispeed.rogers.com |
|
|
|
| O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab |
|
| O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - |
|
|
|
|
| O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by12fd.bay12.hotmail.msn.com/resources/MsnPUpld.cab |
| O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102717728395 |
| O16 - DPF: {65FDEDF3-8ED9-4F5B-825E-18C2D44191A7} (OneCCCtl Class) - http://d.66.155.171.76.downloads.estara.com./as/OneCCDM.php?template=28047&sessionid=366863418_24.231.17.249_3346&=&req=1105851623281OneCC.cab |
| O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab |
| O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab |
| O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab |
| O23 - Service: Eraser Service (EraserThread) - Unknown owner - C:\Program Files\Evidence Exterminator\erasrv.exe |
| O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe |
| O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe |
| O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe |
| O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe |
| O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavsrv51.exe |
| O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe |
| O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe (file missing) |
|
|