Start a Conversation

Unsolved

This post is more than 5 years old

279

June 15th, 2008 11:00

hijackthis log, please help... thanks in adv...

​Logfile of Trend Micro HijackThis v2.0.2​
​Scan saved at 5:09:41, on 08/6/15​
​Platform: Windows XP SP2 (WinNT 5.01.2600)​
​MSIE: Internet Explorer v7.00 (7.00.6000.16674)​
​Boot mode: Normal​

​Running processes:​
​C:\WINDOWS\System32\smss.exe​
​C:\WINDOWS\system32\winlogon.exe​
​C:\WINDOWS\system32\services.exe​
​C:\WINDOWS\system32\lsass.exe​
​C:\WINDOWS\system32\svchost.exe​
​C:\WINDOWS\System32\svchost.exe​
​C:\Program Files\Intel\Wireless\Bin\EvtEng.exe​
​C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe​
​C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe​
​C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe​
​C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe​
​C:\WINDOWS\system32\spoolsv.exe​
​C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe​
​C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe​
​C:\Program Files\Symantec AntiVirus\DefWatch.exe​
​C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe​
​C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe​
​C:\WINDOWS\system32\svchost.exe​
​C:\Program Files\Symantec AntiVirus\Rtvscan.exe​
​C:\WINDOWS\Explorer.EXE​
​C:\WINDOWS\system32\gpr33.exe​
​C:\WINDOWS\system32\hkcmd.exe​
​C:\WINDOWS\system32\igfxpers.exe​
​C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe​
​C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe​
​C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe​
​C:\WINDOWS\stsystra.exe​
​C:\Program Files\Dell\QuickSet\quickset.exe​
​C:\Program Files\Synaptics\SynTP\SynTPEnh.exe​
​C:\WINDOWS\system32\igfxsrvc.exe​
​C:\WINDOWS\system32\wscntfy.exe​
​C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe​
​C:\Program Files\Dell\MediaDirect\PCMService.exe​
​C:\Program Files\Common Files\Real\Update_OB\realsched.exe​
​C:\WINDOWS\system32\dla\tfswctrl.exe​
​C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE​
​C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe​
​C:\WINDOWS\FixCamera.exe​
​C:\WINDOWS\tsnp2std.exe​
​C:\WINDOWS\vsnp2std.exe​
​C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe​
​C:\Program Files\iTunes\iTunesHelper.exe​
​C:\Program Files\Common Files\Symantec Shared\ccApp.exe​
​C:\PROGRA~1\SYMANT~1\VPTray.exe​
​C:\WINDOWS\system32\ctfmon.exe​
​C:\Program Files\NetWaiting\netWaiting.exe​
​C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe​
​C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe​
​C:\Program Files\Internet Explorer\iexplore.exe​
​C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe​
​C:\Program Files\Digital Line Detect\DLG.exe​
​C:\Program Files\Logitech\SetPoint\SetPoint.exe​
​C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe​
​C:\Program Files\Common Files\PCSuite\Services\NclBTHandler.exe​
​C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE​
​C:\Program Files\iPod\bin\iPodService.exe​
​C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE​
​C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe​
​C:\WINDOWS\system32\conime.exe​
​C:\Program Files\Windows Live\Messenger\usnsvc.exe​
​C:\Program Files\Trend Micro\HijackThis\HijackThis.exe​
​C:\Documents and Settings\SLeung\桌面\HiJackThis.exe​

​R3 - URLSearchHook: Yahoo! 工具列 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll​
​F2 - REG:system.ini: Shell=Explorer.exe,gpr33.exe,gpr74.exe​
​O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll​
​O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll​
​O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll​
​O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll (file missing)​
​O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll​
​O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll​
​O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)​
​O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll​
​O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll (file missing)​
​O3 - Toolbar: Yahoo! 工具列 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll​
​O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32​
​O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC​
​O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName​
​O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe​
​O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe​
​O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe​
​O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"​
​O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"​
​O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless​
​O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe​
​O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe​
​O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe​
​O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup​
​O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start​
​O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot​
​O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"​
​O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe​
​O4 - HKLM\..\Run: [Flashget] C:\PROGRA~1\FlashGet\Flashget.exe /min​
​O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup​
​O4 - HKLM\..\Run: [Free-1] "C:\Program Files\IPEVO\Free-1 USB Phone\Free-1 USB Phone.exe"​
​O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe​
​O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe​
​O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe​
​O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"​
​O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime​
​O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"​
​O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"​
​O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe​
​O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe​
​O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe​
​O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog​
​O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime​
​O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')​
​O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')​
​O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')​
​O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')​
​O8 - Extra context menu item: &使用 FlashGet 下載 - C:\PROGRA~1\FlashGet\jc_link.htm​
​O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\PROGRA~1\FlashGet\jc_all.htm​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000​
​O8 - Extra context menu item: 傳送到 &Bluetooth 裝置... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll​
​O9 - Extra 'Tools' menuitem: Sun Java 主控台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll​
​O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll​
​O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)​
​O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)​
​O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe​
​O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe​
​O15 - ESC Trusted Zone: ​​http://*.update.microsoft.com​
​O16 - DPF: {003FACAF-40CB-4358-96D2-B0D8CEF4DBF5} (SKeyHelper Class) - ​​https://bet.hongkongjockeyclub.com/ib/skey/ch/cab/EWinSKey.CAB​
​O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - ​​http://upload.facebook.com/controls/FacebookPhotoUploader5.cab​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=39204​
​O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - ​​http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab​
​O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll​
​O16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) - ​​http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab​
​O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - ​​http://picasaweb.google.com/s/v/25.25/uploader2.cab​
​O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - ​​http://upload.facebook.com/controls/FacebookPhotoUploader3.cab​
​O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - ​​http://upload.facebook.com/controls/FacebookPhotoUploader.cab​
​O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - ​​http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1164726369124​
​O16 - DPF: {8A4943CC-1950-44F9-9045-D3D428FD3948} (SecureX Class) - ​​http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab​
​O16 - DPF: {8DE6AB9C-8C62-486B-8C06-5C9AD6FD06F1} (DataStore Class) - ​​http://txn02.hkjc.com/BetSlip/object/eWinCtl.cab​
​O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - ​​http://otter1.vanaqua.org/activex/AxisCamControl.cab​
​O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - ​​http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab​
​O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - ​​http://www.popcap.com/games/popcaploader_v6.cab​
​O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL​
​O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe​
​O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe​
​O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe​
​O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe​
​O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe​
​O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe​
​O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe​
​O23 - Service: iPod 服務 (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe​
​O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe​
​O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe​
​O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe​
​O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe​
​O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe​
​O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe​
​O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe​
​O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe​

​--​
​End of file - 13497 bytes​

No Responses!
No Events found!

Top