- Logfile of Trend Micro HijackThis v2.0.4
- Scan saved at 15:41:32, on 18.12.2011
- Platform: Windows XP SP3 (WinNT 5.01.2600)
- MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
- Boot mode: Normal
- Running processes:
- C:\WINDOWS\System32\smss.exe
- C:\WINDOWS\system32\winlogon.exe
- C:\WINDOWS\system32\services.exe
- C:\WINDOWS\system32\lsass.exe
- C:\WINDOWS\system32\svchost.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\Explorer.EXE
- C:\WINDOWS\system32\spoolsv.exe
- C:\WINDOWS\system32\rundll32.exe
- C:\Program Files\Avira\AntiVir Desktop\sched.exe
- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
- C:\WINDOWS\system32\igfxtray.exe
- C:\WINDOWS\system32\hkcmd.exe
- C:\WINDOWS\system32\igfxpers.exe
- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
- C:\WINDOWS\system32\igfxsrvc.exe
- C:\WINDOWS\system32\ctfmon.exe
- C:\Program Files\DAEMON Tools Lite\DTLite.exe
- C:\Documents and Settings\All Users\COHServer.exe
- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
- C:\WINDOWS\system32\msapps\comsrvr.exe
- C:\Program Files\Java\jre6\bin\jqs.exe
- C:\WINDOWS\system32\svchost.exe
- C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
- C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
- C:\WINDOWS\system32\wuauclt.exe
- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
- C:\Program Files\Mozilla Firefox\firefox.exe
- C:\Program Files\Mozilla Firefox\plugin-container.exe
- C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
- C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
- C:\Documents and Settings\Ivana\Desktop\HijackThis.exe
- O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
- O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
- O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
- O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
- O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
- O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
- O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
- O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
- O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
- O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
- O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
- O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
- O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
- O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
- O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
- O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
- O4 - HKCU\..\Run: [44929] C:\Documents and Settings\All Users\COHServer.exe
- O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
- O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
- O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
- O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
- O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
- O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
- O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- O17 - HKLM\System\CCS\Services\Tcpip\..\{1F9CC070-6AF3-4A36-BFAB-08CB8AD670A3}: NameServer = 193.198.184.140 193.198.184.130
- O17 - HKLM\System\CS1\Services\Tcpip\..\{1F9CC070-6AF3-4A36-BFAB-08CB8AD670A3}: NameServer = 193.198.184.140 193.198.184.130
- O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
- O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
- O23 - Service: 10841 - Unknown owner - C:\Documents and Settings\All Users\COHServer.exe
- O23 - Service: 49459 - Unknown owner - C:\Documents and Settings\All Users\COHServer.exe
- O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
- O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
- O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
- O23 - Service: COMServer - Unknown owner - C:\WINDOWS\system32\msapps\comsrvr.exe
- O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
- O23 - Service: Usluga Google ažuriranje (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
- O23 - Service: Usluga Google ažuriranje (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
- O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
- O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
- O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
- --
- End of file - 7046 bytes