Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 2:47:07 PM, on 6/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\brian\Desktop\HiJackThis_v2.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.co...site.cab?1182223170218
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.co...site.cab?1182223205609
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5965 bytes
==================================================
Item Name : SunJavaUpdateSched
Type : Registry -> Machine Run
Command : "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
Disabled : No
Product Name : Java(TM) Platform SE 6 U1
File Version : 6.0.10.6
Description : Java(TM) Platform SE binary
Company : Sun Microsystems, Inc.
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 6/25/2007 3:10:20 PM
==================================================
==================================================
Item Name : NotebookHardwareControl
Type : Registry -> Machine Run
Command : "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
Disabled : No
Product Name : Notebook Hardware Control
File Version : 1.8.9.6
Description : Notebook Hardware Control
Company :
http://www.pbus-167.com
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 5/3/2007 8:33:22 PM
==================================================
==================================================
Item Name : Adobe PDF Conversion Toolbar Helper
Type : Browser Helper Objects
Command : C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
Disabled : No
Product Name : Adobe PDF Toolbar for IE
File Version : 8.1.0.0
Description : Adobe PDF Toolbar for Internet Explorer
Company : Adobe Systems Incorporated
Location :
File Created Date : 6/20/2007 7:59:57 PM
==================================================
==================================================
Item Name : Adobe PDF Reader Link Helper
Type : Browser Helper Objects
Command : C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
Disabled : No
Product Name : AcroIEHelper Library
File Version : 8.0.0.2006102200
Description : Adobe PDF Helper for Internet Explorer
Company : Adobe Systems Incorporated
Location :
File Created Date : 10/22/2006 11:08:42 PM
==================================================
==================================================
Item Name : SSVHelper Class
Type : Browser Helper Objects
Command : C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
Disabled : No
Product Name : Java(TM) Platform SE 6 U1
File Version : 6.0.10.6
Description : Java(TM) Platform SE binary
Company : Sun Microsystems, Inc.
Location :
File Created Date : 6/25/2007 3:10:20 PM
==================================================
==================================================
Item Name : SynTPEnh
Type : Registry -> Machine Run
Command : C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Disabled : No
Product Name : Synaptics Pointing Device Driver
File Version : 8.3.4 19May06
Description : Synaptics TouchPad Enhancements
Company : Synaptics, Inc.
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 6/18/2007 11:46:19 PM
==================================================
==================================================
Item Name : Hcontrol
Type : Registry -> Machine Run
Command : C:\WINDOWS\ATK0100\HControl.exe
Disabled : No
Product Name : ATK0100
File Version : 1043, 2, 15, 51
Description : HControl
Company :
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 6/19/2007 7:43:22 PM
==================================================
==================================================
Item Name : MSConfig
Type : Registry -> Machine Run
Command : C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
Disabled : No
Product Name : Microsoft® Windows® Operating System
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : System Configuration Utility
Company : Microsoft Corporation
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 6/18/2007 10:37:24 PM
==================================================
==================================================
Item Name : ctfmon.exe
Type : Registry -> User Run
Command : C:\WINDOWS\system32\ctfmon.exe
Disabled : No
Product Name : Microsoft® Windows® Operating System
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : CTF Loader
Company : Microsoft Corporation
Location : HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 8/4/2004 8:00:00 AM
==================================================
==================================================
Item Name : High Definition Audio Property Page Shortcut
Type : Registry -> Machine Run
Command : HDAShCut.exe
Disabled : No
Product Name : Microsoft® Windows® Operating System
File Version : 5.10.01.5013 built by: WinDDK
Description : High Definition Audio Property Page Shortcut v1.0a
Company : Windows (R) Server 2003 DDK provider
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 1/7/2005 5:07:16 PM
==================================================
==================================================
Item Name : nwiz
Type : Registry -> Machine Run
Command : nwiz.exe /install
Disabled : No
Product Name : NVIDIA nView Wizard, Version 110.91
File Version : 6.14.10.11091
Description : NVIDIA nView Wizard, Version 110.91
Company : NVIDIA Corporation
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 6/18/2007 11:30:51 PM
==================================================
==================================================
Item Name : NvCplDaemon
Type : Registry -> Machine Run
Command : RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
Disabled : No
Product Name : Microsoft® Windows® Operating System
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Run a DLL as an App
Company : Microsoft Corporation
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 8/4/2004 8:00:00 AM
==================================================
==================================================
Item Name : WIAWizardMenu
Type : Registry -> Machine RunOnce
Command : RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
Disabled : No
Product Name : Microsoft® Windows® Operating System
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Run a DLL as an App
Company : Microsoft Corporation
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
File Created Date : 8/4/2004 8:00:00 AM
==================================================
==================================================
Item Name : NvMediaCenter
Type : Registry -> Machine Run
Command : RunDLL32.exe NvMCTray.dll,NvTaskbarInit
Disabled : No
Product Name : Microsoft® Windows® Operating System
File Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Run a DLL as an App
Company : Microsoft Corporation
Location : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
File Created Date : 8/4/2004 8:00:00 AM
==================================================
I don't know why it's saying the Acrobat stuff and HDAshcut are loading, because I disabled those and they are not loaded in the services.
Oh and I tried lowering the priority but it wouldn't let me, I'm guessing since its so vital to the system.