Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:55:41, on 26/08/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Unable to get Internet Explorer version! Boot mode: Normal Running processes: C:\windows\system32\taskeng.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\windows\system32\taskhost.exe C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\EveryThing\Everything.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe C:\Program Files\Lexmark S300-S400 Series\ezprint.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Avast\AvastUI.exe C:\Program Files\7Switch\vswitch.exe C:\Program Files\Launchy\Launchy.exe C:\Program Files\AquaSnap\AquaSnap.Daemon.exe C:\Program Files\CursorFX\CursorFX.exe C:\Windows\System32\taskmgr.exe C:\Program Files\Tools\TDF.exe G:\Steam\Steam.exe C:\Program Files\MemInfo\meminfo.exe C:\Windows\System32\cmd.exe C:\windows\system32\conhost.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.autocompletepro.com/?si=10196&bi=400 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.autocompletepro.com/?si=10196&bi=400 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.autocompletepro.com/?si=10196&bi=400 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Lexmark - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Everything] "C:\Program Files\EveryThing\Everything.exe" -startup O4 - HKLM\..\Run: [Luxand Blink!] C:\Program Files\Blink\LuxandBlinkTray.exe /s O4 - HKLM\..\Run: [lxeamon.exe] "C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark S300-S400 Series\ezprint.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [avast] "C:\Program Files\Avast\avastUI.exe" /nogui O4 - HKCU\..\Run: [VistaSwitcher] "C:\Program Files\7Switch\vswitch.exe" /startup O4 - HKCU\..\Run: [BootTasks] "D:\My Documents\Scripts & Gadgets\BAT\BootTasks.bat" O4 - HKCU\..\Run: [Launchy] "C:\Program Files\Launchy\Launchy.exe" O4 - HKCU\..\Run: [AquaSnap] C:\Program Files\AquaSnap\AquaSnap.Daemon.exe O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\CursorFX\CursorFX.exe" O4 - HKCU\..\Run: [Task Manager] C:\Windows\System32\taskmgr.exe O4 - HKCU\..\Run: [Steam] "G:\Steam\steam.exe" -silent O4 - HKCU\..\Run: [MemInfo] "C:\Program Files\MemInfo\meminfo.exe" O4 - HKCU\..\Run: [DropBox] C:\Users\Marnick\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - HKCU\..\Run: [AlwaysMouseWheel] "C:\Program Files\Win7 Tools\AlwaysMouseWheel\AlwaysMouseWheel.exe" -bg O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [Xvid] C:\Program Files\XVid\CheckUpdate.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Marnick\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [VistaSwitcher] "C:\Program Files\7Switch\vswitch.exe" /startup (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [AquaSnap] C:\Program Files\AquaSnap\AquaSnap.Daemon.exe (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [CursorFX] "C:\Program Files\CursorFX\CursorFX.exe" (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [Task Manager] C:\Windows\System32\taskmgr.exe (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [Steam] "G:\Steam\steam.exe" -silent (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [MemInfo] "C:\Program Files\MemInfo\meminfo.exe" (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [DropBox] C:\Users\Marnick\AppData\Roaming\Dropbox\bin\Dropbox.exe (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [AlwaysMouseWheel] "C:\Program Files\Win7 Tools\AlwaysMouseWheel\AlwaysMouseWheel.exe" -bg (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [Xvid] C:\Program Files\XVid\CheckUpdate.exe (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1001\..\Run: [Google Update] "C:\Users\Marnick\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1014\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User '?') O4 - HKUS\S-1-5-21-2360047747-3816379452-1845821570-1014\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User '?') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\skype\skype4com.dll O23 - Service: AppBooster Service (AppBoosterService) - Unknown owner - C:\Program Files\Common Files\2ToX Common\BoostService.exe (file missing) O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Avast\AvastSvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: ImDisk Virtual Disk Driver Helper (ImDskSvc) - Olof Lagerkvist - C:\windows\system32\imdsksvc.exe O23 - Service: lxeaCATSCustConnectService - Lexmark International, Inc. - C:\windows\system32\spool\DRIVERS\W32X86\3\\lxeaserv.exe O23 - Service: lxea_device - - C:\windows\system32\lxeacoms.exe O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Nitro PDF Reader\NitroPDFReaderDriverService2.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe O23 - Service: appsmaker SpeedBooster 2.0 Service (SpeedBoosterSvc) - Unknown owner - C:\Program Files\Common Files\OptimalSuite Common\BoostService.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe -- End of file - 8443 bytes