2010-01-30 14:23:12 UTC
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://mail.yahoo.com/?.redir=ymmapi9&.clntymver=2004.6.13.1&.cldefstat=Def2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe lfrt.njo gxsgk
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\strCodec\isaddon.dll (file missing)
O2 - BHO: TBSB02751 - {25875464-7327-417C-8264-902D99CF6FD1} - C:\Program Files\Search Enhancer Toolbar\tbu07722\enhancer.dll (file missing)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Protection Bar - {479fd0cf-5be9-4c63-8cda-b6d371c67bd5} - C:\Program Files\strCodec\iesplugin.dll (file missing)
O3 - Toolbar: Search Enhancer Toolbar - {BFB5F154-9212-46F3-B547-AC6106030A54} - C:\Program Files\Search Enhancer Toolbar\tbu07722\enhancer.dll (file missing)
O4 - HKLM\..\Run: [bomuwonaw] Rundll32.exe "c:\windows\system32\dagimewo.dll",a
O4 - HKLM\..\Run: [Htotucobu] rundll32.exe "C:\WINDOWS\uyodunuj.dll",Startup
O4 - HKLM\..\Policies\Explorer\Run: [pmsngr.exe] C:\Program Files\strCodec\pmsngr.exe
O4 - HKLM\..\Policies\Explorer\Run: [Network Sub Spooler] C:\WINDOWS\system32\oobe\SERVICES.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\mshta.dll c:\windows\system32\palodide.dll zodabuma.dll C:\WINDOWS\system32\guard32.dll c:\windows\system32\dagimewo.dll c:\windows\system32\zudalure.dll c:\windows\system32\bulisazu.dll
O20 - Winlogon Notify: bidmon - bidmon.dll (file missing)
O21 - SSODL: pofepavoz - {92b3ad14-0c43-4800-921f-ecc7275e5078} - c:\windows\system32\palodide.dll (file missing)
O21 - SSODL: rozofagus - {738d6079-6c7e-46e5-922d-e5b3215ba385} - c:\windows\system32\zudalure.dll
O21 - SSODL: tilubahiz - {05327ae7-2d41-4fe1-8862-33df2de4951f} - c:\windows\system32\bulisazu.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: jugezatag - {92b3ad14-0c43-4800-921f-ecc7275e5078} - c:\windows\system32\palodide.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {738d6079-6c7e-46e5-922d-e5b3215ba385} - c:\windows\system32\zudalure.dll
O22 - SharedTaskScheduler: gahurihor - {05327ae7-2d41-4fe1-8862-33df2de4951f} - c:\windows\system32\bulisazu.dll
O23 - Service: AntipyProex (AntipPro2009_100) - Unknown owner - C:\WINDOWS\svchast.exe (file missing)