geerr Posted March 14, 2010 Report Share Posted March 14, 2010 Here are the details from hijack this and process explorer ....running Windows7 32bit verLogfile of Trend Micro HijackThis v2.0.2Scan saved at 9:15:41 AM, on 3/14/2010Platform: Unknown Windows (WinNT 6.01.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:C:\Windows\system32\taskhost.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\Google\Google Desktop Search\GoogleDesktop.exeC:\Windows\System32\rundll32.exeC:\tools\tools\Anti-Malware\mbamgui.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exeC:\Program Files\HP\Digital Imaging\bin\hpqbam08.exeC:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exeC:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\wuauclt.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\tools\Mozilla Firefox\firefox.exeC:\Program Files\uTorrent\uTorrent.exeC:\tools\sysinternals\procexp.exeC:\temp\HijackThis.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dllO2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dllO2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dllO2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dllO4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startupO4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkeyO4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntryO4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\tools\tools\Anti-Malware\mbam.exe" /runcleanupscriptO4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] C:\tools\tools\Anti-Malware\mbamgui.exe /starttrayO4 - HKCU\..\Run: [Google Update] "C:\Users\gmekala\AppData\Local\Google\Update\GoogleUpdate.exe" /cO4 - HKCU\..\Run: [setDefaultMIDI] MIDIDef.exeO4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"O4 - Startup: AutorunsDisabledO4 - Global Startup: AutorunsDisabledO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dllO9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dllO9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLLO9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dllO13 - Gopher Prefix: O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dllO20 - AppInit_DLLs: ???? C:\PROGRA~1\Google\GOOGLE~2\GO36F4~1.DLLO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exeO23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exeO23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exeO23 - Service: Google Update Service (gupdate1c980eece5887d0) (gupdate1c980eece5887d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: LiveUpdate - Unknown owner - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (file missing)O23 - Service: MBAMService - Malwarebytes Corporation - C:\tools\tools\Anti-Malware\mbamservice.exe--End of file - 7291 bytesProcess PID CPU Description Company NameSystem Idle Process 0 5.06 Interrupts n/a 0.72 Hardware Interrupts DPCs n/a 1.45 Deferred Procedure Calls System 4 38.35 smss.exe 268 psxss.exe 436 csrss.exe 380 csrss.exe 444 0.36 wininit.exe 472 services.exe 516 0.36 svchost.exe 700 hpqbam08.exe 2228 HP CUE Alert Popup Window Objects Hewlett-Packard Co. hpqgpc01.exe 2556 GPCore COM object Hewlett-Packard hpswp_clipbook.exe 1420 HP Smart Web Printing add-on for Internet Explorer Hewlett-Packard Co. svchost.exe 776 0.36 svchost.exe 996 0.36 audiodg.exe 1224 0.36 svchost.exe 1048 dwm.exe 1604 Desktop Window Manager Microsoft Corporation svchost.exe 1080 1.81 taskeng.exe 3240 wuauclt.exe 772 Windows Update Microsoft Corporation CTAudSvc.exe 1328 svchost.exe 1388 svchost.exe 1484 spoolsv.exe 1596 svchost.exe 1636 3.26 svchost.exe 1760 1.81 svchost.exe 1880 svchost.exe 1904 svchost.exe 2032 0.36 svchost.exe 504 WLIDSVC.EXE 956 WLIDSVCM.EXE 2900 taskhost.exe 1448 Host Process for Windows Tasks Microsoft Corporation svchost.exe 2280 mbamservice.exe 1996 3.62 taskhost.exe 1900 MsMpEng.exe 2672 0.36 SearchIndexer.exe 5452 SearchProtocolHost.exe 4412 SearchFilterHost.exe 5080 lsass.exe 524 2.53 lsm.exe 532 winlogon.exe 564 explorer.exe 580 0.72 Windows Explorer Microsoft Corporation GoogleDesktop.exe 3088 Google Desktop Google rundll32.exe 3128 Windows host process (Rundll32) Microsoft Corporation mbamgui.exe 3184 Malwarebytes' Anti-Malware Malwarebytes Corporation hpqtra08.exe 3552 HP Digital Imaging Monitor Hewlett-Packard Co. hpqste08.exe 1732 HP CUE Status Root Hewlett-Packard Co. iexplore.exe 3040 Internet Explorer Microsoft Corporation iexplore.exe 5964 Internet Explorer Microsoft Corporation iexplore.exe 4984 Internet Explorer Microsoft Corporation iexplore.exe 4908 Internet Explorer Microsoft Corporation procexp.exe 2104 27.49 Sysinternals Process Explorer Sysinternals - www.sysinternals.comtaskmgr.exe 4528 0.36 firefox.exe 3680 1.45 Firefox Mozilla CorporationuTorrent.exe 5024 8.68 µTorrent BitTorrent, Inc.Process: uTorrent.exe Pid: 5024Name Description Company Name Version{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000004.db {AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000d.db {DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db AcGenral.DLL Windows Compatibility DLL Microsoft Corporation 6.01.7600.16385AcLayers.DLL Windows Compatibility DLL Microsoft Corporation 6.01.7600.16385actxprxy.dll ActiveX Interface Marshaling Library Microsoft Corporation 6.01.7600.16385AcXtrnal.DLL Windows Compatibility DLL Microsoft Corporation 6.01.7600.16385ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.01.7600.16385apphelp.dll Application Compatibility Client Library Microsoft Corporation 6.01.7600.16481ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000ATL80.DLL ATL Module for Windows (Unicode) Microsoft Corporation 8.00.50727.4053AUTHZ.dll Authorization Framework Microsoft Corporation 6.01.7600.16385CFGMGR32.dll Configuration Manager DLL Microsoft Corporation 6.01.7600.16385CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.8530.16385COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7600.16385comctl32.dll.mui User Experience Controls Library Microsoft Corporation 6.10.7600.16385comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.01.7600.16385credssp.dll Credential Delegation Security Package Microsoft Corporation 6.01.7600.16385CRYPT32.dll Crypto API32 Microsoft Corporation 6.01.7600.16385CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.01.7600.16385CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.01.7600.16385CSCAPI.dll Offline Files Win32 API Microsoft Corporation 6.01.7600.16385CSCDLL.dll Offline Files Temporary Shim Microsoft Corporation 6.01.7600.16385cscui.dll Client Side Caching UI Microsoft Corporation 6.01.7600.16385cversions.2.db cversions.2.db cversions.2.db DEVOBJ.dll Device Information Set DLL Microsoft Corporation 6.01.7600.16385dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.01.7600.16385dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.01.7600.16385DnsApi.dll DNS Client API DLL Microsoft Corporation 6.01.7600.16385DUser.dll Windows DirectUser Engine Microsoft Corporation 6.01.7600.16385duser.dll.mui Windows DirectUser Engine Microsoft Corporation 6.01.7600.16385dwmapi.dll Microsoft Desktop Window Manager API Microsoft Corporation 6.01.7600.16385EhStorShell.dll Windows Enhanced Storage Shell Extension DLL Microsoft Corporation 6.01.7600.16385FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.01.7600.16385fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.01.7600.16385GDI32.dll GDI Client DLL Microsoft Corporation 6.01.7600.16385GPAPI.dll Group Policy Client API Microsoft Corporation 6.01.7600.16385GrooveNew.DLL GrooveNew Module Microsoft Corporation 12.00.6413.1000GrooveShellExtensions.dll GrooveShellExtensions Module Microsoft Corporation 12.00.6421.1000GrooveUtil.DLL GrooveUtil Module Microsoft Corporation 12.00.6423.1000hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 6.01.7600.16385hnetcfg.dll.mui Home Networking Configuration Manager Microsoft Corporation 6.01.7600.16385ICMP.DLL ICMP DLL Microsoft Corporation 6.01.7600.16385iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 8.00.7600.16385IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.01.7600.16385index.dat index.dat index.dat index.dat Iphlpapi.dll IP Helper API Microsoft Corporation 6.01.7600.16385kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.01.7600.16481KERNELBASE.dll Windows NT BASE API Client DLL Microsoft Corporation 6.01.7600.16385KernelBase.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.01.7600.16385locale.nls LPK.dll Language Pack Microsoft Corporation 6.01.7600.16385mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.00.0005.0011MPR.dll Multiple Provider Router DLL Microsoft Corporation 6.01.7600.16385MSACM32.dll Microsoft ACM Audio Filter Microsoft Corporation 6.01.7600.16385MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.01.7600.16415MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.01.7600.16385msctf.dll.mui MSCTF Server DLL Microsoft Corporation 6.01.7600.16385MSImg32.dll GDIEXT Client DLL Microsoft Corporation 6.01.7600.16385mssprxy.dll Microsoft Search Proxy Microsoft Corporation 7.00.7600.16385MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.00.50727.4927msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.7600.16385mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.01.7600.16385msxml3.dll MSXML 3.0 SP11 Microsoft Corporation 8.110.7600.16385msxml3r.dll XML Resources Microsoft Corporation 8.110.7600.16385napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.01.7600.16385netshell.dll Network Connections Shell Microsoft Corporation 6.01.7600.16385netutils.dll Net Win32 API Helpers DLL Microsoft Corporation 6.01.7600.16385nlaapi.dll Network Location Awareness 2 Microsoft Corporation 6.01.7600.16385Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.01.7600.16385NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.01.7600.16385ntdll.dll NT Layer DLL Microsoft Corporation 6.01.7600.16385ntmarta.dll Windows NT MARTA provider Microsoft Corporation 6.01.7600.16385ntshrui.dll Shell extensions for sharing Microsoft Corporation 6.01.7600.16385ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.01.7600.16385OLEAUT32.dll Microsoft Corporation 6.01.7600.16385peerdist.dll BranchCache Client Library Microsoft Corporation 6.01.7600.16385pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.01.7600.16385profapi.dll User Profile Basic API Microsoft Corporation 6.01.7600.16385PROPSYS.dll Microsoft Property System Microsoft Corporation 7.00.7600.16385PSAPI.DLL Process Status Helper Microsoft Corporation 6.01.7600.16385R00000000000d.clb rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.01.7600.16385RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.01.7600.16385RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.01.7600.16385rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.01.7600.16385samcli.dll Security Accounts Manager Client DLL Microsoft Corporation 6.01.7600.16385sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.01.7600.16385SETUPAPI.dll Windows Setup API Microsoft Corporation 6.01.7600.16385setupapi.dll.mui Windows Setup API Microsoft Corporation 6.01.7600.16385sfc.dll Windows File Protection Microsoft Corporation 6.01.7600.16385sfc_os.DLL Windows File Protection Microsoft Corporation 6.01.7600.16385SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.01.7600.16385shell32.dll.mui Windows Shell Common Dll Microsoft Corporation 6.01.7600.16385shfolder.dll Shell Folder Service Microsoft Corporation 6.01.7600.16385SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.01.7600.16385SHUNIMPL.DLL Windows Shell Obsolete APIs Microsoft Corporation 6.01.7600.16385slc.dll Software Licensing Client Dll Microsoft Corporation 6.01.7600.16385SortDefault.nls SortVistaCompat.nls SortWindows6Compat.dll Sort Version Windows 6.0 Microsoft Corporation 6.01.7600.16385srvcli.dll Server Service Client DLL Microsoft Corporation 6.01.7600.16385SSDPAPI.dll SSDP Client API DLL Microsoft Corporation 6.01.7600.16385SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.01.7600.16385StaticCache.dat SXS.DLL Fusion 2.5 Microsoft Corporation 6.01.7600.16385tiptsf.dll Tablet PC Input Panel Text Services Framework Microsoft Corporation 6.01.7600.16385upnp.dll UPnP Control Point API Microsoft Corporation 6.01.7600.16385urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 8.00.7600.16490urlmon.dll.mui OLE32 Extensions for Win32 Microsoft Corporation 8.00.7600.16385USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.01.7600.16385user32.dll.mui Multi-User Windows USER API Client DLL Microsoft Corporation 6.01.7600.16385USERENV.dll Userenv Microsoft Corporation 6.01.7600.16385USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7600.16385uTorrent.exe µTorrent BitTorrent, Inc. 2.00.0000.18488UxTheme.dll Microsoft UxTheme Library Microsoft Corporation 6.01.7600.16385VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.01.7600.16385webio.dll Web Transfer Protocols API Microsoft Corporation 6.01.7600.16385WindowsCodecs.dll Microsoft Windows Codecs Library Microsoft Corporation 6.01.7600.16385WINHTTP.dll Windows HTTP Services Microsoft Corporation 6.01.7600.16385WININET.dll Internet Extensions for Win32 Microsoft Corporation 8.00.7600.16490WINMM.dll MCI API DLL Microsoft Corporation 6.01.7600.16385WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.01.7600.16385winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.01.7600.16385WINSPOOL.DRV Windows Spooler Driver Microsoft Corporation 6.01.7600.16385wkscli.dll Workstation Service Client DLL Microsoft Corporation 6.01.7600.16385WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.01.7600.16385WLIDNSP.DLL Microsoft® Windows Live ID Namespace Provider Microsoft Corporation 6.500.3146.0000WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.01.7600.16385wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.01.7600.16385wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.01.7600.16385 Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.