Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:40:52, on 2009-12-18 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18349) Boot mode: Normal Running processes: C:\\Windows\\system32\\Dwm.exe C:\\Windows\\Explorer.EXE C:\\Windows\\system32\\taskeng.exe C:\\WINDOWS\\System32\\rundll32.exe C:\\Program Files\\Apoint2K\\Apoint.exe C:\\Program Files\\HP\\QuickPlay\\QPService.exe C:\\Program Files\\Hewlett-Packard\\HP Quick Launch Buttons\\QLBCTRL.exe C:\\Program Files\\Hewlett-Packard\\HP QuickTouch\\HPKBDAPP.exe C:\\Program Files\\HP\\HP Software Update\\hpwuSchd2.exe C:\\Program Files\\Hewlett-Packard\\HP Wireless Assistant\\HPWAMain.exe C:\\Program Files\\Hewlett-Packard\\HP Wireless Assistant\\WiFiMsg.exe C:\\Program Files\\Java\\jre6\\bin\\jusched.exe C:\\Program Files\\Samsung\\Samsung Media Studio 5\\SMSTray.exe C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe C:\\Program Files\\Internet Today\\1.1.0.1260\\InternetToday.exe C:\\Program Files\\Windows Sidebar\\sidebar.exe C:\\WINDOWS\\System32\\rundll32.exe C:\\Program Files\\Common Files\\LightScribe\\LightScribeControlPanel.exe C:\\Program Files\\Internet Today\\1.1.0.1260\\InternetToday.exe C:\\Program Files\\RocketDock\\RocketDock.exe C:\\Program Files\\Hewlett-Packard\\Shared\\HpqToaster.exe C:\\Program Files\\Windows Media Player\\wmpnscfg.exe C:\\Program Files\\Common Files\\Adobe\\Updater5\\AdobeUpdater.exe C:\\Program Files\\WIDCOMM\\Bluetooth Software\\BTTray.exe C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe C:\\Program Files\\Apoint2K\\ApMsgFwd.exe C:\\Program Files\\Apoint2K\\Apntex.exe C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqSTE08.exe C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqbam08.exe C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe C:\\Windows\\system32\\wuauclt.exe C:\\Windows\\system32\\SearchFilterHost.exe C:\\Program Files\\Mozilla Firefox\\firefox.exe C:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_pl&c=81&bd=Pavilion&pf=laptop R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_pl&c=81&bd=Pavilion&pf=laptop R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_pl&c=81&bd=Pavilion&pf=laptop R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_pl&c=81&bd=Pavilion&pf=laptop R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant = R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch = R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\Program Files\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelper.dll O2 - BHO: Automated Content Enhancer - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\\Program Files\\Automated Content Enhancer\\4.1.0.5290\\ACEIEAddOn.dll O2 - BHO: Customized Platform Advancer - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\\Program Files\\Customized Platform Advancer\\4.1.0.1960\\CPAIEAddOn.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\\PROGRA~1\\MICROS~3\\Office12\\GRA8E1~1.DLL O2 - BHO: Content Management Wizard - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\\Program Files\\Content Management Wizard\\1.1.0.1990\\CMWIE.dll O2 - BHO: Textual Content Provider - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\\Program Files\\Textual Content Provider\\1.1.0.1810\\TCPIE.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files\\Java\\jre6\\bin\\jp2ssv.dll O2 - BHO: Web Search Operator - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\\Program Files\\Web Search Operator\\4.1.0.2080\\wso.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\hpswp_BHO.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\\Program Files\\DAEMON Tools Toolbar\\DTToolbar.dll O4 - HKLM\\..\\Run: [NvSvc] RUNDLL32.EXE C:\\Windows\\system32\\nvsvc.dll,nvsvcStart O4 - HKLM\\..\\Run: [NvCplDaemon] RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup O4 - HKLM\\..\\Run: [NvMediaCenter] RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit O4 - HKLM\\..\\Run: [Apoint] C:\\Program Files\\Apoint2K\\Apoint.exe O4 - HKLM\\..\\Run: [IAAnotif] C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe O4 - HKLM\\..\\Run: [QPService] \"C:\\Program Files\\HP\\QuickPlay\\QPService.exe\" O4 - HKLM\\..\\Run: [QlbCtrl] %ProgramFiles%\\Hewlett-Packard\\HP Quick Launch Buttons\\QlbCtrl.exe /Start O4 - HKLM\\..\\Run: [OnScreenDisplay] C:\\Program Files\\Hewlett-Packard\\HP QuickTouch\\HPKBDAPP.exe O4 - HKLM\\..\\Run: [UCam_Menu] \"C:\\Program Files\\CyberLink\\YouCam\\MUITransfer\\MUIStartMenu.exe\" \"C:\\Program Files\\CyberLink\\YouCam\" update \"Software\\CyberLink\\YouCam\\1.0\" O4 - HKLM\\..\\Run: [Windows Defender] %ProgramFiles%\\Windows Defender\\MSASCui.exe -hide O4 - HKLM\\..\\Run: [hpqSRMon] C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqSRMon.exe O4 - HKLM\\..\\Run: [Adobe Reader Speed Launcher] \"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\" O4 - HKLM\\..\\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\\HP Health Check\\HPHC_Scheduler.exe O4 - HKLM\\..\\Run: [HP Software Update] C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe O4 - HKLM\\..\\Run: [hpWirelessAssistant] C:\\Program Files\\Hewlett-Packard\\HP Wireless Assistant\\HPWAMain.exe O4 - HKLM\\..\\Run: [WAWifiMessage] C:\\Program Files\\Hewlett-Packard\\HP Wireless Assistant\\WiFiMsg.exe O4 - HKLM\\..\\Run: [SunJavaUpdateSched] \"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\" O4 - HKLM\\..\\Run: [WinampAgent] \"C:\\Program Files\\Winamp\\winampa.exe\" O4 - HKLM\\..\\Run: [SMSTray] C:\\Program Files\\Samsung\\Samsung Media Studio 5\\SMSTray.exe O4 - HKLM\\..\\Run: [MAAgent] C:\\Program Files\\MarkAny\\ContentSafer\\MAAgent.exe O4 - HKLM\\..\\Run: [QuickTime Task] \"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime O4 - HKLM\\..\\Run: [GrooveMonitor] \"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\" O4 - HKLM\\..\\Run: [avast!] C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe O4 - HKLM\\..\\Run: [Internet Today Task] \"C:\\Program Files\\Internet Today\\1.1.0.1260\\InternetToday.exe\" O4 - HKCU\\..\\Run: [Sidebar] C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun O4 - HKCU\\..\\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\\..\\Run: [LightScribe Control Panel] C:\\Program Files\\Common Files\\LightScribe\\LightScribeControlPanel.exe -hidden O4 - HKCU\\..\\Run: [RocketDock] \"C:\\Program Files\\RocketDock\\RocketDock.exe\" O4 - HKCU\\..\\Run: [ALLUpdate] \"C:\\Program Files\\ALLPlayer2\\ALLUpdate.exe\" \"sleep\" O4 - HKCU\\..\\Run: [WMPNSCFG] C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe O4 - HKCU\\..\\Run: [AdobeUpdater] C:\\Program Files\\Common Files\\Adobe\\Updater5\\AdobeUpdater.exe O4 - HKUS\\S-1-5-19\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \'LOCAL SERVICE\') O4 - HKUS\\S-1-5-19\\..\\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User \'LOCAL SERVICE\') O4 - HKUS\\S-1-5-19\\..\\RunOnce: [] (User \'LOCAL SERVICE\') O4 - HKUS\\S-1-5-20\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \'NETWORK SERVICE\') O4 - HKUS\\S-1-5-20\\..\\RunOnce: [] (User \'NETWORK SERVICE\') O4 - HKUS\\S-1-5-18\\..\\RunOnce: [] (User \'SYSTEM\') O4 - HKUS\\.DEFAULT\\..\\RunOnce: [] (User \'Default user\') O4 - Startup: Adobe Gamma.lnk = C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\\PROGRA~1\\MICROS~3\\Office12\\EXCEL.EXE/3000 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~3\\Office12\\ONBttnIE.dll O9 - Extra \'Tools\' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~3\\Office12\\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~3\\Office12\\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm O9 - Extra \'Tools\' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm O9 - Extra button: Zaznaczanie HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\hpswp_BHO.dll O13 - Gopher Prefix: O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\\PROGRA~1\\MICROS~3\\Office12\\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~1\\COMMON~1\\Skype\\SKYPE4~1.DLL O23 - Service: Adobe LM Service - Adobe Systems - C:\\Program Files\\Common Files\\Adobe Systems Shared\\Service\\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\aswUpdSv.exe O23 - Service: Harmonogram automatycznej usługi LiveUpdate (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\\Program Files\\Symantec\\LiveUpdate\\AluSchedulerSvc.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\\Program Files\\Alwil Software\\Avast4\\ashWebSv.exe O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\\Program Files\\Hewlett-Packard\\HP Quick Launch Buttons\\Com4Qlb.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\\Program Files\\HP Games\\My HP Game Console\\GameConsoleService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\\Program Files\\Hewlett-Packard\\HP Health Check\\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\\Program Files\\Hewlett-Packard\\Shared\\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\\Program Files\\Common Files\\InstallShield\\Driver\\1150\\Intel 32\\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\\Program Files\\Common Files\\LightScribe\\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\\Program Files\\Symantec\\LiveUpdate\\LuComServer_3_4.EXE O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\\Program Files\\HP\\QuickPlay\\Kernel\\TV\\QPCapSvc.exe O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\\Program Files\\HP\\QuickPlay\\Kernel\\TV\\QPSched.exe O23 - Service: QuestService Service - Unknown owner - C:\\ProgramData\\QuestService\\questservice110.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\\Program Files\\CyberLink\\Shared Files\\RichVideo.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\\Windows\\system32\\DRIVERS\\xaudio.exe -- End of file - 12243 bytes