[hijack][url=http://www.niele.nl/hijackthis/index.php]
Logfile of HijackThis v1.99.1
scan saved at 17:58:40, on 11-3-2008
platform: windows xp sp2 (winnt 5.01.2600)
msie: internet explorer v7.00 (7.00.6000.16608)
browser: Internet Explorer 7.0
ColorCoder Build: 4136
Running Processes:
c:\windows\system32\smss.exe
c:\windows\system32\csrss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\windows\system32\svchost.exe
c:\program files\lavasoft\ad-aware 2007\aawservice.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\cisvc.exe
c:\program files\common files\microworld\agent\mwaser.exe
c:\program files\common files\microworld\agent\mwagent.exe
c:\windows\system32\nvsvc32.exe
c:\program files\spyware doctor\pctsauxs.exe
c:\program files\browser usb mouse\mouse32a.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\macrogaming\sweetim\sweetim.exe
c:\windows\pixart\pac207\monitor.exe
c:\windows\sysockeu.exe
c:\program files\spyware doctor\pctstray.exe
c:\windows\system32\ctfmon.exe
c:\program files\spyware doctor\pctssvc.exe
c:\windows\system32\svchost.exe
c:\windows\system32\alg.exe
c:\windows\system32\cidaemon.exe
c:\program files\msn messenger\usnsvc.exe
c:\documents and settings\hasan\mijn documenten\hj\hijackthis.exe
R0 - hkcu\software\microsoft\internet explorer\main,start page = http://www.google.nl/
R0 - hklm\software\microsoft\internet explorer\main,start page = http://home.sweetim.com
R0 - hklm\software\microsoft\internet explorer\search,searchassistant =
R0 - hklm\software\microsoft\internet explorer\search,customizesearch =
R0 - hkcu\software\microsoft\internet explorer\main,local page = \blank.htm
R0 - hklm\software\microsoft\internet explorer\main,local page =
R0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
F2 - reg:system.ini: shell=explorer.exe
O2 - bho: acroiehlprobj class - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll
O2 - bho: (no name) - {16975c1e-950b-f58a-b187-08ed8f89a6b0} - (no file)
O2 - bho: ssvhelper class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
O2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
O2 - bho: (no name) - {9b6465bd-fc01-4ad9-894c-05f74f486391} - (no file)
O2 - bho: (no name) - {d3551e8b-a79b-4880-81fd-3e4b84367085} - (no file)
O2 - bho: (no name) - {fbd29c3c-c642-4843-a627-6e54a947b511} - (no file)
O3 - toolbar: (no name) - {0bf43445-2f28-4351-9252-17fe6e806aa0} - (no file)
O4 - HKLM\..\Run: [flmoffice4dmouse] "c:\program files\browser usb mouse\mouse32a.exe"
O4 - HKLM\..\Run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
O4 - HKLM\..\Run: [sweetim] "c:\program files\macrogaming\sweetim\sweetim.exe"
O4 - HKLM\..\Run: [monitor] c:\windows\pixart\pac207\monitor.exe
O4 - HKLM\..\Run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
O4 - HKLM\..\Run: [1029bb4b-16a9-4e77-aa3d-96930bd68eec] "c:\windows\sysockeu.exe"
O4 - HKLM\..\Run: [msdrive] "rundll32.exe" c:\windows\system32\drvfir.dll,startup
O4 - HKLM\..\Run: [istray] "c:\program files\spyware doctor\pctstray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [sweetim] "c:\program files\macrogaming\sweetim\sweetim.exe"
O4 - Global Startup: microsoft office.lnk = c:\program files\microsoft office\office10\osa.exe
O6 - hkcu\software\policies\microsoft\internet explorer\restrictions present
O8 - extra context menu item: e&xporteren naar microsoft excel - res://c:\progra~1\micros~2\office10\excel.exe/3000
O9 - extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - extra 'tools' menuitem: uninstall bitdefender online scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - options group: [international] international*
O16 - dpf: {070ca17a-4bd2-4612-83b4-32b1b9159b47} (ulivectrl control) - http://uc.sina.com.cn/download/live/weblive2.4.0.0.cab
O16 - dpf: {193c772a-87be-4b19-a7bb-445b226fe9a1} (ewidoonlinescan control) - http://downloads.ewido.net/ewidoonlinescan.cab
O16 - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) - http://by102fd.bay102.hotmail.msn.com/resources/msnpupld.cab
O16 - dpf: {556dde35-e955-11d0-a707-000000521957} - http://www.xblock.com/download/[color=#0000ff]xclean_micro.exe[/color]
O16 - dpf: {58ef1388-af07-4d13-a069-d107671b8819} - http://www.gamegarden.net/game/ggsecure.cab
O16 - dpf: {5d86ddb5-bdf9-441b-9e9e-d4730f4ee499} (bdscanonline control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - dpf: {67dabfbf-d0ab-41fa-9c46-cc0f21721616} - http://download.divx.com/player/divxbrowserplugin.cab
O16 - dpf: {91f52a42-c10d-49a7-b941-882c657c604f} (installation helper object) - http://kitcentral.wanadoo.nl/download/install/win32/nl/instwact/[color=#0000ff]instwact.dll[/color]
O16 - dpf: {b49c4597-8721-4789-9250-315dfbd9f525} (iwinampactivex class) - http://www.yayindayiz.biz/yayin/ampx2.6.1.11_en_dl.cab
O16 - dpf: {c3f79a2b-b9b4-4a66-b012-3ee46475b072} (messengerstatsclient class) - http://messenger.zone.msn.com/binary/messengerstatspaclient.cab56907.cab
O16 - dpf: {c4925e65-7a1e-11d2-8bb4-00a0c9cc72c3} - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/install2.5/[color=#0000ff]installer.exe[/color]
O16 - dpf: {d4323bf2-006a-4440-a2f5-27e3e7ab25f8} - http://3dlifeplayer.dl.3dvia.com/player/install/[color=#0000ff]installer.exe[/color]
O16 - dpf: {e8f628b5-259a-4734-97ee-ba914d7be941} (driver agent activex control) - http://driveragent.com/files/driveragent.cab
O16 - dpf: {f5a7706b-b9c0-4c89-a715-7a0c6b05dd48} (minesweeper flags class) - http://messenger.zone.msn.com/binary/minesweeper.cab56986.cab
O18 - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
O18 - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
O20 - winlogon notify: wgalogon - c:\windows\system32\wgalogon.dll
O20 - winlogon notify: xxyayxw - xxyayxw.dll (file missing)
O21 - ssodl: wpdshserviceobj - {aaa288ba-9a4c-45b0-95d7-94d524869db5} - c:\windows\system32\wpdshserviceobj.dll
O21 - ssodl: kernelcomponent - {afe6c5ee-0c8f-4790-8483-8f333497df34} - (no file)
O23 - Service: ad-aware 2007 service (aawservice) - lavasoft - c:\program files\lavasoft\ad-aware 2007\aawservice.exe
O23 - Service: installdriver table manager (idrivert) - macrovision corporation - c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
O23 - Service: mwagent - microworld technologies inc. - c:\program files\common files\microworld\agent\mwaser.exe
O23 - Service: nmindexingservice - unknown owner - c:\program files\common files\ahead\lib\nmindexingservice.exe (file missing)
O23 - Service: nvidia driver helper service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
O23 - Service: pc tools auxiliary service (sdauxservice) - pc tools - c:\program files\spyware doctor\pctsauxs.exe
O23 - Service: pc tools security service (sdcoreservice) - pc tools - c:\program files\spyware doctor\pctssvc.exe
O23 - Service: sysenforce - unknown owner - c:\progra~1\trisna~1\ssi\sysenf~1.exe[/hijack]

Logfile of HijackThis v1.99.1
scan saved at 17:58:40, on 11-3-2008
platform: windows xp sp2 (winnt 5.01.2600)
msie: internet explorer v7.00 (7.00.6000.16608)
browser: Internet Explorer 7.0
ColorCoder Build: 4136
Running Processes:
c:\windows\system32\smss.exe
c:\windows\system32\csrss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\windows\system32\svchost.exe
c:\program files\lavasoft\ad-aware 2007\aawservice.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\cisvc.exe
c:\program files\common files\microworld\agent\mwaser.exe
c:\program files\common files\microworld\agent\mwagent.exe
c:\windows\system32\nvsvc32.exe
c:\program files\spyware doctor\pctsauxs.exe
c:\program files\browser usb mouse\mouse32a.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\macrogaming\sweetim\sweetim.exe
c:\windows\pixart\pac207\monitor.exe
c:\windows\sysockeu.exe
c:\program files\spyware doctor\pctstray.exe
c:\windows\system32\ctfmon.exe
c:\program files\spyware doctor\pctssvc.exe
c:\windows\system32\svchost.exe
c:\windows\system32\alg.exe
c:\windows\system32\cidaemon.exe
c:\program files\msn messenger\usnsvc.exe
c:\documents and settings\hasan\mijn documenten\hj\hijackthis.exe
R0 - hkcu\software\microsoft\internet explorer\main,start page = http://www.google.nl/
R0 - hklm\software\microsoft\internet explorer\main,start page = http://home.sweetim.com
R0 - hklm\software\microsoft\internet explorer\search,searchassistant =
R0 - hklm\software\microsoft\internet explorer\search,customizesearch =
R0 - hkcu\software\microsoft\internet explorer\main,local page = \blank.htm
R0 - hklm\software\microsoft\internet explorer\main,local page =
R0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
F2 - reg:system.ini: shell=explorer.exe
O2 - bho: acroiehlprobj class - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll
O2 - bho: (no name) - {16975c1e-950b-f58a-b187-08ed8f89a6b0} - (no file)
O2 - bho: ssvhelper class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
O2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
O2 - bho: (no name) - {9b6465bd-fc01-4ad9-894c-05f74f486391} - (no file)
O2 - bho: (no name) - {d3551e8b-a79b-4880-81fd-3e4b84367085} - (no file)
O2 - bho: (no name) - {fbd29c3c-c642-4843-a627-6e54a947b511} - (no file)
O3 - toolbar: (no name) - {0bf43445-2f28-4351-9252-17fe6e806aa0} - (no file)
O4 - HKLM\..\Run: [flmoffice4dmouse] "c:\program files\browser usb mouse\mouse32a.exe"
O4 - HKLM\..\Run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
O4 - HKLM\..\Run: [sweetim] "c:\program files\macrogaming\sweetim\sweetim.exe"
O4 - HKLM\..\Run: [monitor] c:\windows\pixart\pac207\monitor.exe
O4 - HKLM\..\Run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
O4 - HKLM\..\Run: [1029bb4b-16a9-4e77-aa3d-96930bd68eec] "c:\windows\sysockeu.exe"
O4 - HKLM\..\Run: [msdrive] "rundll32.exe" c:\windows\system32\drvfir.dll,startup
O4 - HKLM\..\Run: [istray] "c:\program files\spyware doctor\pctstray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [sweetim] "c:\program files\macrogaming\sweetim\sweetim.exe"
O4 - Global Startup: microsoft office.lnk = c:\program files\microsoft office\office10\osa.exe
O6 - hkcu\software\policies\microsoft\internet explorer\restrictions present
O8 - extra context menu item: e&xporteren naar microsoft excel - res://c:\progra~1\micros~2\office10\excel.exe/3000
O9 - extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - extra 'tools' menuitem: uninstall bitdefender online scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - unknown file in winsock lsp: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - options group: [international] international*
O16 - dpf: {070ca17a-4bd2-4612-83b4-32b1b9159b47} (ulivectrl control) - http://uc.sina.com.cn/download/live/weblive2.4.0.0.cab
O16 - dpf: {193c772a-87be-4b19-a7bb-445b226fe9a1} (ewidoonlinescan control) - http://downloads.ewido.net/ewidoonlinescan.cab
O16 - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) - http://by102fd.bay102.hotmail.msn.com/resources/msnpupld.cab
O16 - dpf: {556dde35-e955-11d0-a707-000000521957} - http://www.xblock.com/download/[color=#0000ff]xclean_micro.exe[/color]
O16 - dpf: {58ef1388-af07-4d13-a069-d107671b8819} - http://www.gamegarden.net/game/ggsecure.cab
O16 - dpf: {5d86ddb5-bdf9-441b-9e9e-d4730f4ee499} (bdscanonline control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - dpf: {67dabfbf-d0ab-41fa-9c46-cc0f21721616} - http://download.divx.com/player/divxbrowserplugin.cab
O16 - dpf: {91f52a42-c10d-49a7-b941-882c657c604f} (installation helper object) - http://kitcentral.wanadoo.nl/download/install/win32/nl/instwact/[color=#0000ff]instwact.dll[/color]
O16 - dpf: {b49c4597-8721-4789-9250-315dfbd9f525} (iwinampactivex class) - http://www.yayindayiz.biz/yayin/ampx2.6.1.11_en_dl.cab
O16 - dpf: {c3f79a2b-b9b4-4a66-b012-3ee46475b072} (messengerstatsclient class) - http://messenger.zone.msn.com/binary/messengerstatspaclient.cab56907.cab
O16 - dpf: {c4925e65-7a1e-11d2-8bb4-00a0c9cc72c3} - http://a532.g.akamai.net/7/532/6712/6c5b0a1ae398e3/player.virtools.com/downloads/player/install2.5/[color=#0000ff]installer.exe[/color]
O16 - dpf: {d4323bf2-006a-4440-a2f5-27e3e7ab25f8} - http://3dlifeplayer.dl.3dvia.com/player/install/[color=#0000ff]installer.exe[/color]
O16 - dpf: {e8f628b5-259a-4734-97ee-ba914d7be941} (driver agent activex control) - http://driveragent.com/files/driveragent.cab
O16 - dpf: {f5a7706b-b9c0-4c89-a715-7a0c6b05dd48} (minesweeper flags class) - http://messenger.zone.msn.com/binary/minesweeper.cab56986.cab
O18 - protocol: livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
O18 - protocol: msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\msnmes~1\msgrap~1.dll
O20 - winlogon notify: wgalogon - c:\windows\system32\wgalogon.dll
O20 - winlogon notify: xxyayxw - xxyayxw.dll (file missing)
O21 - ssodl: wpdshserviceobj - {aaa288ba-9a4c-45b0-95d7-94d524869db5} - c:\windows\system32\wpdshserviceobj.dll
O21 - ssodl: kernelcomponent - {afe6c5ee-0c8f-4790-8483-8f333497df34} - (no file)
O23 - Service: ad-aware 2007 service (aawservice) - lavasoft - c:\program files\lavasoft\ad-aware 2007\aawservice.exe
O23 - Service: installdriver table manager (idrivert) - macrovision corporation - c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
O23 - Service: mwagent - microworld technologies inc. - c:\program files\common files\microworld\agent\mwaser.exe
O23 - Service: nmindexingservice - unknown owner - c:\program files\common files\ahead\lib\nmindexingservice.exe (file missing)
O23 - Service: nvidia driver helper service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
O23 - Service: pc tools auxiliary service (sdauxservice) - pc tools - c:\program files\spyware doctor\pctsauxs.exe
O23 - Service: pc tools security service (sdcoreservice) - pc tools - c:\program files\spyware doctor\pctssvc.exe
O23 - Service: sysenforce - unknown owner - c:\progra~1\trisna~1\ssi\sysenf~1.exe[/hijack]
Comment