Hi,
I use ZoneAlarm and sometimes i scan with spybot, because it finds things ZA doesnt. Anyway, i found spyware, i think. It was Coolwwwsearch and it was in windows/currentversion/winlogon. I managed to remove it, but i'm worried that it isnt removed completely. So can someone check my hijackthislog, and tell me if its removed?
Thanks in advance,
Vendetta
My software list:
7-Zip 4.42
ACE-HIGH MP3 WAV WMA OGG Converter
Ad-Aware 2007
ADG Aspect 5.3.0.75
ADG Panorama Pro 5.3.0.37
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Photoshop CS
Adobe Reader 8.1.1
Adobe Reader Extended Language Support Font Pack
Adobe Shockwave Player
Age of Mythology
Age of Mythology - The Titans Expansion
Alien Skin Blow Up
Alien Skin Exposure 2
Animation Workshop
AnyDVD
AnyReader 2.4
Apple Mobile Device Support
Apple Software Update
Arcades Interactif 2
Arcades Réseau Interactif 1
AV Voice Changer Software DIAMOND 4.0
AVG Anti-Spyware 7.5
AviSynth 2.5
A-Z iPod Video Converter 4.48
Backup&Synchronize
Bonjour
CC Get MAC Address 2.2
CCleaner (remove only)
Chinese Simplified Fonts Support For Adobe Reader 8
Chinese Traditional Fonts Support For Adobe Reader 8
City Life 2008
CloneCD
CloneDVD2
Colibri
Collab
ConcOrdinateur
Core Center
Cossacks - Back To War
Cossacks - European Wars
Cossacks - The Art Of War
Cossacks II
Crashday
De Interactieve Weergids
De Sims 2
De Sims 2 Gaan het Maken
De Sims 2 Glamour - Accessoires
De Sims 2 Nachtleven
De Sims 2 Studentenleven
De Sims™ 2 Familiepret – Accessoires
De Sims™ 2 Feest! Accessoires
De Sims™ 2 Huisdieren
De Sims™ 2 Seizoenen
Deskcalc Pro
DivX Content Uploader
DivX Web Player
DownloadStudio
dupeGuru Music Edition
DVD Decrypter (Remove Only)
EA.com Update
EarthView V3.7.2
FL Studio 5
Fraps (remove only)
GIF Construction Set Professional 3
Google Desktop
Google Earth
Google Talk (remove only)
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Updater
GtkRadiant-1.4.0
Guild Wars
GWFreaks 3.1.0.0
HijackThis 2.0.2
HLSW v1.1.6
Ikivo Animator 2.1
Image2PDF
ImageSkill TileBuilderDemo (remove only)
IMMonitor MSN Spy
iPod Access for Windows v4.0.5
iTunes
JA+2.3 mod with JA+ Pluginv1.3
JAM's Jedi Knight KT v2.0
Japanese Fonts Support For Adobe Reader 8
Java(TM) 6 Update 3
Jedi Runner
Kill Tracker 5.0 Final
Korean Fonts Support For Adobe Reader 8
Lightroom
LimeWire 4.14.10
Linksys Wireless-G PCI Adapter
Logitech Gaming Software
Magic ISO Maker v5.4 (build 0239)
MagicDisc 2.5.79
Makermod Client Plugin
Mashed
MathType 6
Microsoft .NET Framework 2.0
Microsoft Office Professional Edition 2003
Microsoft Speech SDK 5.1
mIRC
MMM - Pulsar 1
Mozilla Firefox (2.0.0.11)
MSI DigiCell
MSI Live Update 3
MSXML4 Parser
Native Instruments - Traktor 1.06
Need for Speed™ Most Wanted
Need for Speed™ ProStreet
Nero 8
neroxml
NHL 2002
Norton Security Scan
Notepad++
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
Panda ActiveScan
PC DUAL SHOCK
Picasa 2
PixiePack Codec Pack
Power Retouche Pro
PowerQuest PartitionMagic 8.0
Prime95
PrimoPDF
PrimoPDF Redistribution Package
Product Key Explorer 1.9.2
PTLens
Quasar 1.0
Quickphone V1.0
QuickTime
Q-Xpress Installer 1.1.9
Rcon SE
RCT3 Soaked
Realtek High Definition Audio Driver
RollerCoaster Tycoon 3
Safari
SensorsView Pro 3.1
Shockwave
ShopSpezial
Skype™ 3.5
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Spyware Doctor 5.1
Star Wars Jedi Knight Jedi Academy
Star Wars JK II Jedi Outcast
Star Wars JK II Jedi Outcast Demo
Star Wars(R) Knights of the Old Republic(R) II: The Sith Lords(TM)
StarSkin 2.5.2.5
TeamSpeak 2 RC2
Telemeter 3.5g
TimeLiner 5.1
TrackMania Nations ESWC 1.7.9
TrackMania United DVD Patch 2006-12-15
Trillian
TuneUp Utilities 2008
TVAnts 1.0
TVUPlayer 2.3.3.2
TwistingPixels
VCRedistSetup
Ventrilo Client
Verbix 7.3
Vertus Fluid Mask 3 3.0.2
VideoLAN VLC media player 0.8.6c
Videora iPod classic Converter 3.07
Videora iPod Converter 3.04
Videoraptor
Virtual Painter 5 (for Photoshop)
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Media Format Runtime
Windows Messenger 5.1
Windows XP Service Pack 2
WinPcap 3.1 beta3
Xfire (remove only)
XviD MPEG-4 Video Codec
ZoneAlarm Security Suite
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:44, on 21/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
J:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe
C:\Program Files\Colibri\Colibri.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\notepad.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.be/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Crappy Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: IeMonitor - {8170D7DC-BDD6-461e-88EB-F047257898C9} - C:\Program Files\Conceiva\DownloadStudio\DLMonitr.dll
O2 - BHO: VideoRaptorIePlugin Class - {90C8E8F8-A7C9-41E4-92E4-C679AE6FB78D} - C:\Program Files\Videoraptor\VideoRaptorIePlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\sw g.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [STARTRIGHT] "C:\Program Files\Startright\srv134\StartRight.exe" -go
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [Colibri] C:\Program Files\Colibri\Colibri.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - J:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
--
End of file - 7502 bytes