Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:46:27, on 25/12/2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\windows\system32\taskhost.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Windows\StartupMonitor.exe C:\Program Files\Avast\AvastUI.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe G:\Steam\Steam.exe C:\Program Files\Tools\DiskLED\DiskLED.exe C:\Program Files\Everything\Everything.exe C:\Program Files\Launchy\Launchy.exe C:\Program Files\Carthago Software\Meminfo\meminfo.exe C:\Program Files\Ditto\Ditto.exe C:\Program Files\Wizmouse\WizMouse.exe C:\Program Files\Truecrypt\TrueCrypt.exe C:\Program Files\COMODO\COMODO Internet Security\cis.exe C:\Program Files\Minibin\MiniBin.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Nurgo\Aquasnap\AquaSnap.Daemon.exe C:\Program Files\Gadwin Systems\Printscreen\PrintScreen.exe C:\Windows\System32\taskmgr.exe C:\Users\Marnick\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files\Pale Moon\palemoon.exe C:\Program Files\Ventis\Mediamonkey\MediaMonkey.exe J:\9ypke8r8.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}\components\afom.exe C:\Program Files\Q-Dir\Q-Dir.exe C:\Program Files\Notepad++\notepad++.exe C:\Program Files\Trend Micro\Hijackthis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - (no file) O2 - BHO: (no name) - AutorunsDisabled - (no file) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\Java\JRE\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast\aswWebRepIE.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - I:\SYSTEM~2\Visio\Office14\URLREDIR.DLL O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\Java\JRE\bin\jp2ssv.dll O3 - Toolbar: (no name) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - (no file) O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast\aswWebRepIE.dll O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Samsung Display Manager] C:\PROGRAM FILES\Samsung\EASY DISPLAY MANAGER\dmhkcore.exe O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [IMDisks] "D:\Scripts & Gadgets\BAT\IMDisks.bat" O4 - HKLM\..\Run: [Run StartupMonitor] C:\Windows\StartupMonitor.exe O4 - HKLM\..\Run: [avast] "C:\Program Files\Avast\avastUI.exe" /nogui O4 - HKLM\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe O4 - HKCU\..\Run: [Steam] "G:\Steam\steam.exe" -silent O4 - HKCU\..\Run: [DiskLED] C:\Program Files\Tools\DiskLED\DiskLED.exe O4 - HKCU\..\Run: [Everything] C:\PROGRAM FILES\EVERYTHING\EVERYTHING.EXE -startup O4 - HKCU\..\Run: [Launchy] "C:\Program Files\Launchy\Launchy.exe" O4 - HKCU\..\Run: [Meminfo] "C:\Program Files\Carthago Software\Meminfo\meminfo.exe" O4 - HKCU\..\Run: [Ditto] C:\Program Files\Ditto\Ditto.exe O4 - HKCU\..\Run: [WizMouse] "C:\Program Files\Wizmouse\WizMouse.exe" O4 - HKCU\..\Run: [TrueCrypt] "C:\Program Files\Truecrypt\TrueCrypt.exe" /q preferences /a logon O4 - HKCU\..\Run: [Dropbox] C:\Users\Marnick\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup O4 - HKCU\..\Run: [Minibin] C:\Program Files\Minibin\Minibin.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [Aquasnap] C:\Program Files\Nurgo\Aquasnap\AquaSnap.Daemon.exe O4 - HKCU\..\Run: [Printscreen] C:\PROGRAM FILES\GADWIN SYSTEMS\PRINTSCREEN\PRINTSCREEN.EXE /nosplash O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: Dropbox.lnk = Marnick\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Global Startup: Taakbeheer.lnk = C:\Windows\System32\taskmgr.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file) O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - AppInit_DLLs: O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Avast\AvastSvc.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe O23 - Service: FreemakeVideoCapture - Freemake - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: ImDisk Virtual Disk Driver Helper (ImDskSvc) - Olof Lagerkvist - C:\windows\system32\imdsksvc.exe O23 - Service: lxeaCATSCustConnectService - Lexmark International, Inc. - C:\windows\system32\spool\DRIVERS\W32X86\3\\lxeaserv.exe O23 - Service: lxea_device - - C:\windows\system32\lxeacoms.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Nitro\PDF Reader\NitroPDFReaderDriverService2.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe O23 - Service: OracleJobSchedulerXE - Unknown owner - c:\oracle_db_11g_express\app\oracle\product\11.2.0\server\Bin\extjob.exe O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\Oracle_DB_11G_Express\app\oracle\product\11.2.0\server\BIN\omtsreco.exe O23 - Service: OracleServiceXE - Oracle Corporation - c:\oracle_db_11g_express\app\oracle\product\11.2.0\server\bin\ORACLE.EXE O23 - Service: OracleXEClrAgent - Oracle Corporation - C:\Oracle_DB_11G_Express\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe O23 - Service: OracleXETNSListener - Oracle Corporation - C:\Oracle_DB_11G_Express\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe O23 - Service: Macrium Reflect Image Mounting Service (ReflectService.exe) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe O23 - Service: Windows7FirewallService - Sphinx Software - C:\Program Files\Firewall Control\Windows7FirewallService.exe -- End of file - 9024 bytes