Thread: Analyze please!
View Single Post
Old 10-20-2007, 04:35 PM   #7 (permalink)
Rawmaterial
Rawmaterial's Avatar
 
True Techie

Join Date: May 2005

Posts: 247

Rawmaterial is on a distinguished road

Default Re: Analyze please!

new logg.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:28:50 PM, on 10/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
Crogram FilesIntelWirelessBinEvtEng.exe
Crogram FilesIntelWirelessBinS24EvMon.exe
Crogram FilesIntelWirelessBinWLKeeper.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSehomeehtray.exe
C:WINDOWSsystem32hkcmd.exe
Crogram FilesBonjourmDNSResponder.exe
C:WINDOWSsystem32igfxpers.exe
Crogram FilesSynapticsSynTPSynTPEnh.exe
Crogram FilesIntelWirelessbinZCfgSvc.exe
Crogram FilesIntelWirelessBinifrmewrk.exe
C:WINDOWSstsystra.exe
Crogram FilesDellMedia ExperienceDMXLauncher.exe
Crogram FilesDellQuickSetquickset.exe
Crogram FilesCreativeMixerCTSVolFE.exe
C:WINDOWSsystem32igfxsrvc.exe
C:WINDOWSsystem32cisvc.exe
Crogram FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:WINDOWSSystem32DLADLACTRLW.EXE
Crogram FilesHewlett-PackardHP Software UpdateHPWuSchd.exe
C:WINDOWSeHomeehRecvr.exe
Crogram FilesHPhpcoretechhpcmpmgr.exe
C:WINDOWSsystem32spooldriversw32x863hpztsb09.exe
Crogram FilesQuickTimeqttask.exe
Crogram FilesiTunesiTunesHelper.exe
C:WINDOWSeHomeehSched.exe
Crogram FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
Crogram FilesDellQuickSetNICCONFIGSVC.exe
Crogram FilesJavajre1.6.0_03binjusched.exe
Crogram FilesNetWaitingnetWaiting.exe
Crogram FilesIntelWirelessBinRegSrvc.exe
C:WINDOWSsystem32ctfmon.exe
Crogram FilesDellSupportDSAgnt.exe
Crogram FilesSophosSophos Anti-VirusSAVAdminService.exe
Crogram FilesCommon FilesAheadLibNMBgMonitor.exe
Crogram FilesSophosAutoUpdateALsvc.exe
Crogram FilesSophosAutoUpdateALMon.exe
Crogram FilesCommon FilesAheadLibNMIndexStoreSvr.exe
Crogram FilesViewpointCommonViewpointService.exe
Crogram FilesDigital Line DetectDLG.exe
Crogram FilesWinZipWZQKPICK.EXE
Crogram FilesiPodbiniPodService.exe
C:WINDOWSsystem32dllhost.exe
C:WINDOWSeHomeehmsas.exe
C:WINDOWSsystem32wuauclt.exe
Cocuments and SettingsYuree NamDesktoppeter.exe.exe
CROGRA~1IntelWirelessBinDot1XCfg.exe
Crogram FilesCommon FilesAheadLibNMIndexingService.exe
Crogram FilesViewpointViewpoint ManagerViewMgr.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = Dell Start Page
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = Learn about Dell's notebooks, desktops, monitors, printers plus computer electronics & accessories.
R1 - HKLMSoftwareMicrosoftInternet ExplorerSearch,Default_Page_URL = Dell Start Page
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - Crogram FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - CROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:WINDOWSSystem32DLADLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - Crogram FilesJavajre1.6.0_03binssv.dll
O2 - BHO: (no name) - {8143D2CF-A1A6-45CE-AE85-71A0D9B60A4B} - C:WINDOWSsystem32gebyw.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:WINDOWSsystem32ugywqumf.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:WINDOWSsystem32ugywqumf.dll
O4 - HKLM..Run: [ehTray] C:WINDOWSehomeehtray.exe
O4 - HKLM..Run: [igfxtray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [igfxhkcmd] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [igfxpers] C:WINDOWSsystem32igfxpers.exe
O4 - HKLM..Run: [SynTPEnh] Crogram FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [IntelZeroConfig] "Crogram FilesIntelWirelessbinZCfgSvc.exe"
O4 - HKLM..Run: [IntelWireless] "Crogram FilesIntelWirelessBinifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM..Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM..Run: [DMXLauncher] Crogram FilesDellMedia ExperienceDMXLauncher.exe
O4 - HKLM..Run: [Dell QuickSet] Crogram FilesDellQuickSetquickset.exe
O4 - HKLM..Run: [CTSVolFE.exe] "Crogram FilesCreativeMixerCTSVolFE.exe" /r
O4 - HKLM..Run: [ISUSPM Startup] "Crogram FilesCommon FilesInstallShieldUpdateServiceisuspm.exe" -startup
O4 - HKLM..Run: [ISUSScheduler] "Crogram FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [DLA] C:WINDOWSSystem32DLADLACTRLW.EXE
O4 - HKLM..Run: [HP Software Update] "Crogram FilesHewlett-PackardHP Software UpdateHPWuSchd.exe"
O4 - HKLM..Run: [HP Component Manager] "Crogram FilesHPhpcoretechhpcmpmgr.exe"
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSsystem32spooldriversw32x863hpztsb09.exe
O4 - HKLM..Run: [imekrmig] C:IMEIMKRimekrmig.exe
O4 - HKLM..Run: [MSKDetectorExe] Crogram FilesMcAfeeSpamKillerMSKDetct.exe /uninstall
O4 - HKLM..Run: [QuickTime Task] "Crogram FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "Crogram FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [IMJPMIG8.1] "C:WINDOWSIMEimjp8_1IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM..Run: [IMEKRMIG6.1] C:WINDOWSimeimkr6_1IMEKRMIG.EXE
O4 - HKLM..Run: [MSPY2002] C:WINDOWSsystem32IMEPINTLGNTImScInst.exe /SYNC
__________________
Rawmaterial is offline