rugdude234 Posted November 18, 2009 Report Share Posted November 18, 2009 please help here is my hijack this and system explorer resultsLogfile of Trend Micro HijackThis v2.0.2Scan saved at 7:25:00 PM, on 11/17/2009Platform: Unknown Windows (WinNT 6.01.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:E:\Windows\system32\taskhost.exeE:\Windows\system32\Dwm.exeE:\Windows\Explorer.EXEE:\Windows\RtHDVCpl.exeE:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exeE:\Program Files\Microsoft Office\Office12\GrooveMonitor.exeE:\Program Files\Pure Networks\Network Magic\nmapp.exeE:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exeE:\Program Files\PowerISO\PWRISOVM.EXEE:\Program Files\Zune\ZuneLauncher.exeE:\Program Files\AVG\AVG9\avgtray.exeE:\Program Files\Windows Sidebar\sidebar.exeE:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exeE:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exeE:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exeE:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeE:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exeE:\Windows\system32\conhost.exeE:\Program Files\Webroot\Washer\wwDisp.exeE:\Program Files\Common Files\Nero\Lib\NeroGadgetCMServer.exeE:\Program Files\uTorrent\uTorrent.exeE:\Program Files\Mozilla Firefox\firefox.exeE:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15179&l=disR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dllO1 - Hosts: ::1 localhostO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program Files\AVG\AVG9\avgssie.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dllO2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dllO2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - E:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dllO2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files\Ask.com\GenericAskToolbar.dllO3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dllO3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - E:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dllO3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - E:\Program Files\Ask.com\GenericAskToolbar.dllO4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exeO4 - HKLM\..\Run: [Acrobat Assistant 8.0] "E:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"O4 - HKLM\..\Run: [AppleSyncNotifier] E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exeO4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKLM\..\Run: [NBKeyScan] "E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"O4 - HKLM\..\Run: [nmapp] "E:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplashO4 - HKLM\..\Run: [nmctxth] "E:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"O4 - HKLM\..\Run: [PWRISOVM.EXE] "E:\Program Files\PowerISO\PWRISOVM.EXE"O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [Zune Launcher] "E:\Program Files\Zune\ZuneLauncher.exe"O4 - HKLM\..\Run: [AVG9_TRAY] E:\PROGRA~1\AVG\AVG9\avgtray.exeO4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"O4 - HKCU\..\Run: [sidebar] E:\Program Files\Windows Sidebar\sidebar.exe /autoRunO4 - HKCU\..\Run: [DW6] "E:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"O4 - HKCU\..\Run: [ehTray.exe] E:\Windows\ehome\ehTray.exeO4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "E:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020O4 - HKCU\..\Run: [LightScribe Control Panel] "E:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" -hiddenO4 - HKCU\..\Run: [swg] "E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"O4 - HKCU\..\Run: [Window Washer] "E:\Program Files\Webroot\Washer\wwDisp.exe"O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] E:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = E:\Program Files\Microsoft Office\Office12\ONENOTEM.EXEO8 - Extra context menu item: Append to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLLO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\Windows\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\Windows\Network Diagnostic\xpnetdiag.exeO13 - Gopher Prefix: O15 - Trusted IP range: http://192.168.1.1O15 - ESC Trusted IP range: http://192.168.1.1O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/Verizon%20High%20Speed%20Internet%20Installer.cabO16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///E:/Program%20Files/Elf%20Bowling%20Holiday%20Pack/Images/stg_drm.ocxO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/VistaMSNPUplden-us.cabO16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cabO16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///E:/Program%20Files/Elf%20Bowling%20Holiday%20Pack/Images/armhelper.ocxO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dllO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program Files\AVG\AVG9\avgpp.dllO20 - AppInit_DLLs: avgrsstx.dllO23 - Service: Norton 2009 Reset (.norton2009Reset) - Unknown owner - E:\ProgramData\Norton\Norton2009Reset.exeO23 - Service: Apple Mobile Device - Apple Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - E:\Program Files\AVG\AVG9\avgwdsvc.exeO23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - E:\Program Files\AVG\AVG9\avgfws9.exeO23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - E:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exeO23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - E:\Program Files\Canon\CAL\CALMAIN.exeO23 - Service: Diskeeper - Diskeeper Corporation - E:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Software Updater (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - E:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: LiveUpdate - Symantec Corporation - E:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXEO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeO23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - E:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exeO23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - E:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exeO23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - E:\Windows\system32\IoctlSvc.exeO23 - Service: WMP54GSSVC - GEMTEKS - E:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exeO23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - E:\Program Files\Webroot\Washer\WasherSvc.exe--End of file - 12164 bytesProcess PID CPU Description Company NameSystem Idle Process 0 90.15 Interrupts n/a Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 smss.exe 284 csrss.exe 428 wininit.exe 496 avgchsvx.exe 516 avgrsx.exe 532 avgcsrvx.exe 652 services.exe 616 svchost.exe 1100 NeroGadgetCMServer.exe 4220 1.52 Nero Copy Medium Gadget Server Nero AG svchost.exe 1164 svchost.exe 1236 audiodg.exe 4988 svchost.exe 1308 dwm.exe 316 1.52 Desktop Window Manager Microsoft Corporation WUDFHost.exe 5184 svchost.exe 1356 svchost.exe 1528 svchost.exe 1800 spoolsv.exe 1928 AVGIDSAgent.exe 1964 svchost.exe 628 taskhost.exe 392 Host Process for Windows Tasks Microsoft Corporation AppleMobileDeviceService.exe 1704 avgwdsvc.exe 1792 avgam.exe 2836 avgnsx.exe 2856 avgcsrvx.exe 3396 avgfws9.exe 228 mDNSResponder.exe 2072 DkService.exe 2108 svchost.exe 2384 LSSrvc.exe 2456 NBService.exe 2512 IoctlSvc.exe 2644 svchost.exe 2952 WasherSvc.exe 3540 CALMAIN.exe 3700 nmsrvc.exe 3776 FNPLicensingService.exe 4552 SearchIndexer.exe 4588 SearchProtocolHost.exe 5632 SearchFilterHost.exe 4728 NMIndexingService.exe 4780 svchost.exe 5028 wmpnetwk.exe 5552 lsass.exe 624 lsm.exe 636 csrss.exe 508 conhost.exe 4064 Console Window Host Microsoft Corporationwinlogon.exe 576 explorer.exe 756 Windows Explorer Microsoft Corporation RtHDVCpl.exe 2716 HD Audio Control Panel Realtek Semiconductor Acrotray.exe 2748 AcroTray Adobe Systems Inc. GrooveMonitor.exe 2976 GrooveMonitor Utility Microsoft Corporation nmapp.exe 3068 Network Magic Application Pure Networks, Inc. nmctxth.exe 3168 Pure Networks Platform Assistant Pure Networks, Inc. PWRISOVM.EXE 3188 PowerISO Virtual Drive Manager PowerISO Computing, Inc. ZuneLauncher.exe 3252 Zune Auto-Launcher Microsoft Corporation avgtray.exe 3336 AVG Tray Monitor AVG Technologies CZ, s.r.o. AVGIDSMonitor.exe 4028 AVG IDS application AVG Technologies CZ, s.r.o. sidebar.exe 3516 3.79 Windows Desktop Gadgets Microsoft Corporation DesktopWeather.exe 3560 The Weather Channel Interactive, Inc. NMIndexStoreSvr.exe 3800 Nero Home Nero AG LightScribeControlPanel.exe 3820 Hewlett-Packard Company GoogleToolbarNotifier.exe 4000 GoogleToolbarNotifier Google Inc. wwDisp.exe 2532 Window Washer Client Executable Webroot Software, Inc. uTorrent.exe 4040 µTorrent BitTorrent, Inc. firefox.exe 4664 1.52 Firefox Mozilla Corporation WinRAR.exe 4716 WinRAR archiver Alexander Roshal procexp.exe 5916 1.52 Sysinternals Process Explorer Sysinternals - www.sysinternals.comProcess: uTorrent.exe Pid: 4040Name Description Company Name VersionADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.1.7600.16385avgrsstx.dll AVG Resident Shield Starter AVG Technologies CZ, s.r.o. 9.0.0.663COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7600.16385comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.1.7600.16385CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.1.7600.16385CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.1.7600.16385dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.1.7600.16385dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.1.7600.16385DnsApi.dll DNS Client API DLL Microsoft Corporation 6.1.7600.16385dwmapi.dll Microsoft Desktop Window Manager API Microsoft Corporation 6.1.7600.16385fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.1.7600.16385GDI32.dll GDI Client DLL Microsoft Corporation 6.1.7600.16385IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.1.7600.16385Iphlpapi.dll IP Helper API Microsoft Corporation 6.1.7600.16385kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385KERNELBASE.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385KernelBase.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385locale.nls LPK.dll Language Pack Microsoft Corporation 6.1.7600.16385mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.0.6.2MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.1.7600.16385msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.7600.16385mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.1.7600.16385NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.1.7600.16385ntdll.dll NT Layer DLL Microsoft Corporation 6.1.7600.16385ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.1.7600.16385oleaut32.dll Microsoft Corporation 6.1.7600.16385profapi.dll User Profile Basic API Microsoft Corporation 6.1.7600.16385rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.1.7600.16385RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.1.7600.16385rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.1.7600.16385sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.1.7600.16385SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.1.7600.16385shfolder.dll Shell Folder Service Microsoft Corporation 6.1.7600.16385SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.1.7600.16385SortDefault.nls SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.1.7600.16385StaticCache.dat USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.1.7600.16385USERENV.dll Userenv Microsoft Corporation 6.1.7600.16385USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7600.16385uTorrent.exe µTorrent BitTorrent, Inc. 1.8.4.16688uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.1.7600.16385WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.1.7600.16385WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.1.7600.16385wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.1.7600.16385wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.1.7600.16385 Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.