Advertisement
Guest User

Untitled

a guest
Mar 27th, 2013
439
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.13 KB | None | 0 0
  1. Logfile of Trend Micro HijackThis v2.0.4
  2. Scan saved at 19:56:48, on 27/03/2013
  3. Platform: Unknown Windows (WinNT 6.02.1008)
  4. MSIE: Internet Explorer v10.0 (10.00.9200.16519)
  5. Boot mode: Normal
  6.  
  7. Running processes:
  8. C:\Windows\Explorer.EXE
  9. C:\Windows\system32\taskhostex.exe
  10. c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
  11. c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
  12. C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
  13. C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x86__8wekyb3d8bbwe\LiveComm.exe
  14. C:\Windows\System32\RuntimeBroker.exe
  15. C:\Program Files\WhatPulse2\whatpulse.exe
  16. C:\Program Files\AVAST Software\Avast\AvastUI.exe
  17. C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
  18. C:\Program Files\Rainmeter\Rainmeter.exe
  19. C:\Windows\system32\ctfmon.exe
  20. C:\Windows\system32\taskhost.exe
  21. C:\Program Files\Skype\Phone\Skype.exe
  22. C:\Windows\system32\NOTEPAD.EXE
  23. C:\Program Files\Google\Chrome\Application\chrome.exe
  24. C:\Program Files\Google\Chrome\Application\chrome.exe
  25. C:\Program Files\Google\Chrome\Application\chrome.exe
  26. C:\Program Files\Google\Chrome\Application\chrome.exe
  27. C:\Program Files\Google\Chrome\Application\chrome.exe
  28. C:\Program Files\Google\Chrome\Application\chrome.exe
  29. C:\Program Files\Google\Chrome\Application\chrome.exe
  30. C:\Program Files\Google\Chrome\Application\chrome.exe
  31. C:\Program Files\Google\Chrome\Application\chrome.exe
  32. C:\Program Files\Google\Chrome\Application\chrome.exe
  33. C:\Windows\System32\mshta.exe
  34. C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.EXE
  35. C:\Program Files\Google\Chrome\Application\chrome.exe
  36. C:\Program Files\Google\Chrome\Application\chrome.exe
  37. C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
  38.  
  39. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mixidj.claro-search.com/?affID=120165&babsrc=HP_ss&mntrId=40d73050000000000000002454a3729b
  40. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
  41. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  42. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  43. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
  44. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
  45. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
  46. R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
  47. O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
  48. O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
  49. O2 - BHO: mixidj Helper Object - {4D6A9BBF-402C-4301-B1EF-28D04F71D761} - C:\Program Files\mixidj\mixidj\1.8.4.1\bh\mixidj.dll
  50. O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL
  51. O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
  52. O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
  53. O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll
  54. O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL
  55. O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL
  56. O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
  57. O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
  58. O3 - Toolbar: MixiDJ Toolbar - {CA9B9C89-4662-4ADC-9C23-A452BECD5D19} - C:\Program Files\mixidj\mixidj\1.8.4.1\mixidjTlbr.dll
  59. O4 - HKLM\..\Run: [EaseUS EPM tray] C:\Program Files\EaseUS\EaseUS Partition Master 9.2.1 Home Edition\bin\EpmNews.exe
  60. O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
  61. O4 - HKLM\..\RunOnce: [{fc46d1b2-9557-4c1f-baac-04af4d2db7e4}] "C:\ProgramData\Package Cache\{fc46d1b2-9557-4c1f-baac-04af4d2db7e4}\adksetup.exe" /burn.log.append "C:\Users\Adam\AppData\Local\Temp\adk\Assessment and Deployment Kit_20130327162749.log" /uninstall /burn.runonce
  62. O4 - HKLM\..\RunOnce: [{e0efdce9-a486-4676-8aa5-65bb08cbf34c}] "C:\ProgramData\Package Cache\{e0efdce9-a486-4676-8aa5-65bb08cbf34c}\wdexpress_full.exe" /burn.log.append "C:\Users\Adam\AppData\Local\Temp\dd_wdexpress_full_20130327163158.log" /uninstall ignored /burn.runonce
  63. O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
  64. O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
  65. O4 - HKCU\..\Run: [BitTorrent] "C:\Users\Adam\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
  66. O4 - HKCU\..\Run: [whatpulse] "C:\Program Files\WhatPulse2\whatpulse.exe"
  67. O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
  68. O4 - HKCU\..\Run: [avast! Antivirus] C:\Program Files\AVAST Software\Avast\AvastUI.exe
  69. O4 - HKCU\..\Run: [EADM] "C:\Program Files\Origin\Origin.exe" -AutoStart
  70. O4 - Startup: EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
  71. O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
  72. O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
  73. O8 - Extra context menu item: Clip selection - C:\Program Files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3
  74. O8 - Extra context menu item: Clip this page - C:\Program Files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1
  75. O8 - Extra context menu item: Clip URL - C:\Program Files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0
  76. O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
  77. O8 - Extra context menu item: New Note - C:\Program Files\Evernote\Evernote\\EvernoteIERes\NewNote.html
  78. O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
  79. O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
  80. O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll
  81. O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
  82. O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
  83. O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
  84. O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
  85. O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
  86. O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
  87. O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
  88. O9 - Extra button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\\EvernoteIERes\AddNote.html
  89. O9 - Extra 'Tools' menuitem: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\\EvernoteIERes\AddNote.html
  90. O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
  91. O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
  92. O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
  93. O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
  94. O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
  95. O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
  96. O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
  97. O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
  98. O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
  99. O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
  100. O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
  101. O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
  102. O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
  103. O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
  104. O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
  105. O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
  106. O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
  107. O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
  108. O23 - Service: VMware Workstation Server (VMwareHostd) - Unknown owner - C:\Program Files\VMware\VMware Workstation\vmware-hostd.exe
  109.  
  110. --
  111. End of file - 10370 bytes
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement