Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:12:47 PM, on 9/23/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\ScanSoft\PaperPort\p
ptd40nt.ex
e
C:\Program Files (x86)\Brother\Brmfcmon\BrM
fcWnd.exe
C:\Program Files (x86)\Brother\ControlCente
r3\brccMCt
l.exe
C:\Program Files (x86)\Java\jre6\bin\jusche
d.exe
C:\Program Files (x86)\Brother\Brmfcmon\BrM
fimon.exe
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EX
E
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macrom
ed\Flash\F
lashUtil10
b.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\iTunes\iTunesHelper.
exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceHelper.
exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\PROGRA~2\Java\jre6\bin\
jp2launche
r.exe
C:\Program Files (x86)\Java\jre6\bin\java.e
xe
C:\Users\Walt\AppData\Loca
l\Yahoo!\B
rowserPlus
\2.4.17\Br
owserPlusC
ore.exe
C:\Users\Walt\AppData\Loca
l\Yahoo!\B
rowserPlus
\2.4.17\Br
owserPlusS
ervice.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.
htm
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F
A578C2EBDC
3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lperShim.d
ll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0
BBC1D38A37
E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShel
lExtension
s.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv
.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMoni
tor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgd
update.exe
" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files (x86)\ScanSoft\PaperPort\p
ptd40nt.ex
e"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files (x86)\ScanSoft\PaperPort\I
ndexSearch
.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files (x86)\ScanSoft\PaperPort\E
reg\Ereg.e
xe" -r "C:\ProgramData\ScanSoft\P
aperPort\1
1\Config\E
reg\Ereg.i
ni"
O4 - HKLM\..\Run: [BrMfcWnd] "C:\Program Files (x86)\Brother\Brmfcmon\BrM
fcWnd.exe"
/AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] "C:\Program Files (x86)\Brother\ControlCente
r3\brctrce
n.exe" /autorun
O4 - HKLM\..\Run: [NeroCheck] C:\Windows\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusche
d.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe
" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.
exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCe
nter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2
\Office12\
EXCEL.EXE/
3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~2\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~2\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\
INetRepl.d
ll,-222 - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Windows\WindowsMobile\I
NetRepl.dl
l
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Windows\WindowsMobile\I
NetRepl.dl
l
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\
INetRepl.d
ll,-223 - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\Windows\WindowsMobile\I
NetRepl.dl
l
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~2\MICROS~2\Offic
e12\REFIEB
AR.DLL
O13 - Gopher Prefix:
O16 - DPF: {01113300-3E00-11D2-8470-0
060089874E
D} (Support.com Configuration Class) -
http://supportcenter.rr.com/sdccommon/download/tgctlcm.cabO16 - DPF: {49232000-16E4-426C-A231-6
2846947304
B} (SysData Class) -
https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
060082AA75
C} (GpcContainer Class) -
https://nicewareintl.webex.com/client/T26L/webex/ieatgpc1.cabO16 - DPF: {F27237D7-93C8-44C2-AC6E-D
6057B9A918
F} (JuniperSetupClient Control) -
https://burl-ssl.gotapco.com/dana-cached/sc/JuniperSetupClient.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3
CB6248B04C
D} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSyst
emServices
.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\Driver
Store\File
Repository
\stwrt64.i
nf_9b67df9
1\AESTSr64
.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg
.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.ex
e (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponde
r.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.e
xe (file missing)
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxs
resm.dll,-
118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc
.exe (file missing)
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shar
ed\hpqwmie
x.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.
exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\net
logon.dll,
-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexing
Service.ex
e
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlS
vc.exe
O23 - Service: @%systemroot%\system32\psb
ase.dll,-3
00 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: @%systemroot%\system32\Loc
ator.exe,-
2 (RpcLocator) - Unknown owner - C:\Windows\system32\locato
r.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sam
srv.dll,-1
(SamSs) - Unknown owner - C:\Windows\system32\lsass.
exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLs
vc.exe,-10
1 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.
exe (file missing)
O23 - Service: @%SystemRoot%\system32\snm
ptrap.exe,
-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptr
ap.exe (file missing)
O23 - Service: @%systemroot%\system32\spo
olsv.exe,-
1 (Spooler) - Unknown owner - C:\Windows\System32\spools
v.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\Driver
Store\File
Repository
\stwrt64.i
nf_9b67df9
1\STacSV64
.exe (file missing)
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc
.exe
O23 - Service: @%SystemRoot%\system32\ui0
detect.exe
,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Det
ect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds
.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.ex
e (file missing)
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - c:\Windows\system32\vfsFPS
ervice.exe
O23 - Service: @%systemroot%\system32\vss
vc.exe,-10
2 (VSS) - Unknown owner - C:\Windows\system32\vssvc.
exe (file missing)
O23 - Service: @%systemroot%\system32\wbe
ngine.exe,
-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengi
ne.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbe
m\wmiapsrv
.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\W
miApSrv.ex
e (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10873 bytes