Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Logfile of Trend Micro HijackThis v2.0.3 (BETA)
- Scan saved at 1:00:39 AM, on 2/12/2010
- Platform: Unknown Windows (WinNT 6.01.3504)
- MSIE: Internet Explorer v8.00 (8.00.7600.16385)
- Boot mode: Normal
- Running processes:
- C:\Windows\system32\taskhost.exe
- C:\Windows\system32\rdpclip.exe
- C:\Windows\system32\Dwm.exe
- C:\Windows\Explorer.EXE
- C:\Program Files\DynDNS Updater\DynTray.exe
- C:\Windows\system32\taskhost.exe
- C:\Program Files\uTorrent\uTorrent.exe
- C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
- C:\Users\ServU\Desktop\procexp.exe
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
- R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
- R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
- R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:80
- R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
- O4 - HKCU\..\Run: [Google Update] "C:\Users\ServU\AppData\Local\Google\Update\GoogleUpdate.exe" /c
- O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
- O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
- O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
- O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
- O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
- O4 - Global Startup: DynDNS Updater Tray Icon.lnk = C:\Program Files\DynDNS Updater\DynTray.exe
- O13 - Gopher Prefix:
- O17 - HKLM\System\CCS\Services\Tcpip\..\{E60C4D6C-69CF-41E6-98C6-939C662FAFC6}: NameServer = 4.2.2.3,4.2.2.4
- O23 - Service: DynDNS Updater - Dynamic Network Services, Inc. - C:\Program Files\DynDNS Updater\DynUpSvc.exe
- --
- End of file - 2531 bytes
- ========================================================================================================================================================================================================================================
- Process PID CPU Description Company Name
- System Idle Process 0 86.36
- Interrupts n/a Hardware Interrupts
- DPCs n/a Deferred Procedure Calls
- System 4
- smss.exe 264 Windows Session Manager Microsoft Corporation
- csrss.exe 368 Client Server Runtime Process Microsoft Corporation
- wininit.exe 420 Windows Start-Up Application Microsoft Corporation
- services.exe 496 Services and Controller app Microsoft Corporation
- svchost.exe 636 Host Process for Windows Services Microsoft Corporation
- WmiPrvSE.exe 332 WMI Provider Host Microsoft Corporation
- dllhost.exe 3424 COM Surrogate Microsoft Corporation
- svchost.exe 704 Host Process for Windows Services Microsoft Corporation
- svchost.exe 804 Host Process for Windows Services Microsoft Corporation
- svchost.exe 856 1.52 Host Process for Windows Services Microsoft Corporation
- dwm.exe 2404 Desktop Window Manager Microsoft Corporation
- svchost.exe 884 Host Process for Windows Services Microsoft Corporation
- svchost.exe 988 Host Process for Windows Services Microsoft Corporation
- svchost.exe 1120 Host Process for Windows Services Microsoft Corporation
- rdpclip.exe 2328 RDP Clip Monitor Microsoft Corporation
- spoolsv.exe 1276 Spooler SubSystem App Microsoft Corporation
- svchost.exe 1304 Host Process for Windows Services Microsoft Corporation
- svchost.exe 1552 0.76 Host Process for Windows Services Microsoft Corporation
- vmnat.exe 1628 VMware NAT Service VMware, Inc.
- vmnetdhcp.exe 1672 VMware VMnet DHCP service VMware, Inc.
- DynUpSvc.exe 1708 DynDNS� Updater Service Dynamic Network Services, Inc.
- vmware-authd.exe 1844 VMware Authorization Service VMware, Inc.
- svchost.exe 724 Host Process for Windows Services Microsoft Corporation
- taskhost.exe 2204 Host Process for Windows Tasks Microsoft Corporation
- UI0Detect.exe 2116 Interactive services detection Microsoft Corporation
- taskhost.exe 3168 Host Process for Windows Tasks Microsoft Corporation
- lsass.exe 532 Local Security Authority Process Microsoft Corporation
- lsm.exe 540 Local Session Manager Service Microsoft Corporation
- csrss.exe 432 Client Server Runtime Process Microsoft Corporation
- winlogon.exe 504 Windows Logon Application Microsoft Corporation
- LogonUI.exe 828 Windows Logon User Interface Host Microsoft Corporation
- csrss.exe 1872 Client Server Runtime Process Microsoft Corporation
- winlogon.exe 2024 Windows Logon Application Microsoft Corporation
- explorer.exe 2428 Windows Explorer Microsoft Corporation
- DynTray.exe 2696 DynDNS� Notification Icon Dynamic Network Services, Inc.
- uTorrent.exe 4284 10.61 �Torrent BitTorrent, Inc.
- HiJackThis.exe 5632 HijackThis Trend Micro Inc.
- notepad.exe 1864 Notepad Microsoft Corporation
- procexp.exe 2340 0.76 Sysinternals Process Explorer Sysinternals
- Process: uTorrent.exe Pid: 4284
- Name Description Company Name Version
- ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.01.7600.16385
- ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000
- CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.8530.16385
- COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7600.16385
- comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.01.7600.16385
- credssp.dll Credential Delegation Security Package Microsoft Corporation 6.01.7600.16385
- CRYPT32.dll Crypto API32 Microsoft Corporation 6.01.7600.16385
- CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.01.7600.16385
- CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.01.7600.16385
- dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.01.7600.16385
- dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.01.7600.16385
- DnsApi.dll DNS Client API DLL Microsoft Corporation 6.01.7600.16385
- FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.01.7600.16385
- fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.01.7600.16385
- GDI32.dll GDI Client DLL Microsoft Corporation 6.01.7600.16385
- GPAPI.dll Group Policy Client API Microsoft Corporation 6.01.7600.16385
- hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 6.01.7600.16385
- hnetcfg.dll.mui Home Networking Configuration Manager Microsoft Corporation 6.01.7600.16385
- iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 8.00.7600.16385
- IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.01.7600.16385
- Iphlpapi.dll IP Helper API Microsoft Corporation 6.01.7600.16385
- kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.01.7600.16385
- KERNELBASE.dll Windows NT BASE API Client DLL Microsoft Corporation 6.01.7600.16385
- KernelBase.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.01.7600.16385
- locale.nls
- LPK.dll Language Pack Microsoft Corporation 6.01.7600.16385
- MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.01.7600.16415
- MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.01.7600.16385
- msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.7600.16385
- mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.01.7600.16385
- msxml3.dll MSXML 3.0 SP11 Microsoft Corporation 8.110.7600.16385
- msxml3r.dll XML Resources Microsoft Corporation 8.110.7600.16385
- msxml3r.dll.mui XML Resources Microsoft Corporation 8.110.7600.16385
- netshell.dll Network Connections Shell Microsoft Corporation 6.01.7600.16385
- netutils.dll Net Win32 API Helpers DLL Microsoft Corporation 6.01.7600.16385
- nlaapi.dll Network Location Awareness 2 Microsoft Corporation 6.01.7600.16385
- npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.01.7600.16385
- NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.01.7600.16385
- ntdll.dll NT Layer DLL Microsoft Corporation 6.01.7600.16385
- ntmarta.dll Windows NT MARTA provider Microsoft Corporation 6.01.7600.16385
- ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.01.7600.16385
- oleaut32.dll Microsoft Corporation 6.01.7600.16385
- profapi.dll User Profile Basic API Microsoft Corporation 6.01.7600.16385
- rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.01.7600.16385
- RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.01.7600.16385
- RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.01.7600.16385
- rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.01.7600.16385
- sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.01.7600.16385
- SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.01.7600.16385
- shfolder.dll Shell Folder Service Microsoft Corporation 6.01.7600.16385
- SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.01.7600.16385
- slc.dll Software Licensing Client Dll Microsoft Corporation 6.01.7600.16385
- SortDefault.nls
- SSDPAPI.dll SSDP Client API DLL Microsoft Corporation 6.01.7600.16385
- SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.01.7600.16385
- StaticCache.dat
- SXS.DLL Fusion 2.5 Microsoft Corporation 6.01.7600.16385
- upnp.dll UPnP Control Point API Microsoft Corporation 6.01.7600.16385
- urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 8.00.7600.16490
- USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.01.7600.16385
- USERENV.dll Userenv Microsoft Corporation 6.01.7600.16385
- USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7600.16385
- uTorrent.exe �Torrent BitTorrent, Inc. 2.00.0000.17920
- UxTheme.dll Microsoft UxTheme Library Microsoft Corporation 6.01.7600.16385
- VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.01.7600.16385
- webio.dll Web Transfer Protocols API Microsoft Corporation 6.01.7600.16385
- WINHTTP.dll Windows HTTP Services Microsoft Corporation 6.01.7600.16385
- WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.01.7600.16385
- wkscli.dll Workstation Service Client DLL Microsoft Corporation 6.01.7600.16385
- WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.01.7600.16385
- WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.01.7600.16385
- wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.01.7600.16385
- wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.01.7600.16385
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement