Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 13:12:40, on 23-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Programas\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programas\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
C:\Programas\AOL\Active Virus Shield\avp.exe
C:\Programas\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Programas\Comodo\Firewall\cmdagent.exe
C:\Programas\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Programas\OO Software\CleverCache\ooccag.exe
C:\Programas\Raxco\PerfectDiskRx\PD9Engine.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Raxco\PerfectDisk\PDAgent.exe
C:\Programas\Spyware Terminator\sp_rsser.exe
C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Raxco\PerfectDisk\PDEngine.exe
C:\Programas\Synaptics\SynTP\SynTPEnh.exe
C:\Programas\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\system32\LGDMEBTN.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Programas\AOL\Active Virus Shield\avp.exe
C:\Programas\Comodo\Firewall\CPF.exe
C:\Programas\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programas\Fingerprint Sensor\ATSwpNav.exe
C:\Programas\LG Software\Battery Miser\batterymiser.exe
C:\Programas\Microsoft IntelliPoint\ipoint.exe
C:\Programas\Raxco\PerfectDiskRx\PerfectDiskRx.exe
C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRSTrayApp.exe
C:\Programas\RocketDock\RocketDock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\TrueCrypt\TrueCrypt.exe
C:\Programas\DNA-drivers\DNA-ATi\Driver\ATI Tray Tools\atitray.exe
C:\Programas\TaskSwitchXP\TaskSwitchXP.exe
C:\Programas\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Programas\CyberLink\PowerDVD\PDVDServ.exe
C:\Programas\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Programas\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Programas\Raxco\PerfectDiskRx\PDCleaner.exe
C:\Programas\Raxco\PerfectDiskRx\PDState.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Programas\Raxco\PerfectDiskRx\PD9Agent.exe
C:\Programas\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Programas\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\OO Software\CleverCache\ooccctrl.exe
C:\Programas\Softex\OmniPass\scureapp.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\AGRSMMSG.exe
D:\Downloads\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.evillabs.sk/evillyrics/faq/faq1.php?faqnr=49
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Programas\FlashGet\jccatch.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Programas\MegauploadToolbar\megauploadtoolbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Explorer Breadcrumbs Helper Class - {DB5FC78C-0D12-448B-A0B0-DB0F0E6B67DB} - C:\Programas\Minimalist\Explorer Breadcrumbs\BCToolbar.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Programas\FlashGet\getflash.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Programas\MegauploadToolbar\megauploadtoolbar.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Explorer Breadcrumbs - {A3EB65EC-D9B4-4DC1-88AF-0C7A21EBE5F9} - C:\Programas\Minimalist\Explorer Breadcrumbs\BCToolbar.dll
O3 - Toolbar: QT TabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll (file missing)
O3 - Toolbar: QT Tab Standard Buttons - {D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [SynTPEnh] C:\Programas\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Programas\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [LG Direct Media Button Service] LGDMEBTN.exe
O4 - HKLM\..\Run: [KeybdUtility] "C:\Program Files\LG Software\On Screen Display\HotKey.exe"
O4 - HKLM\..\Run: [aol] "C:\Programas\AOL\Active Virus Shield\avp.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programas\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programas\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\VIPv3\VIPhd\vsdrv.exe
O4 - HKLM\..\Run: [StartupDelayer] "C:\Programas\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATSwpNav] "C:\Programas\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [batterymiser] "C:\Programas\LG Software\Battery Miser\batterymiser.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programas\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [PerfectDiskRx] C:\Programas\Raxco\PerfectDiskRx\PerfectDiskRx.exe /tray /startrun
O4 - HKCU\..\Run: [SRSTrayApp] C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRSTrayApp.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Programas\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TrueCrypt] "C:\Programas\TrueCrypt\TrueCrypt.exe" /q preferences
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Programas\DNA-drivers\DNA-ATi\Driver\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Programas\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-21-1004336348-630328440-839522115-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Administrador')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Programas\IVT Corporation\BlueSoleil\BlueSoleil.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download All with FlashGet - C:\Programas\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Programas\FlashGet\jc_link.htm
O8 - Extra context menu item: + Offline &Explorer: Download the link -
file://C:\Programas\Portable Offline Browser\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page -
file://C:\Programas\Portable Offline Browser\Add_AllO.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Programas\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Programas\FlashGet\FlashGet.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon da cache de categorias dos componentes - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Programas\Ficheiros comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Active Virus Shield (AVP) - AOL - C:\Programas\AOL\Active Virus Shield\avp.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programas\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programas\Comodo\Firewall\cmdagent.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programas\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Programas\Softex\OmniPass\Omniserv.exe
O23 - Service: O&O CleverCache Agent (OOCleverCacheAgent) - O&O Software GmbH - C:\Programas\OO Software\CleverCache\ooccag.exe
O23 - Service: PD9Engine - Raxco Software, Inc. - C:\Programas\Raxco\PerfectDiskRx\PD9Engine.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Programas\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Programas\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programas\Spyware Terminator\sp_rsser.exe
O23 - Service: SRS PostInstaller Service (SRS_PostInstaller) - SRS Labs, Inc. - C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 11149 bytes