Cant find Trojan!
Thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:20:23 AM, on 12/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
E:\Other Applications\Spyware Doctor\pctsAuxs.exe
E:\Other Applications\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
E:\Other Applications\Java\bin\jusched.exe
E:\Other Applications\Microsoft Office\Office12\GrooveMonitor.exe
E:\Other Applications\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
E:\Other Applications\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
E:\Other Applications\HijackThis\HijackThis.exe
O2 – BHO: Adobe PDF Reader Link Helper – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 – BHO: (no name) – {4fbdaf71-f4eb-4192-9ecd-459ecdd3e0fa} – C:\WINDOWS\system32\suvekesa.dll (file missing)
O2 – BHO: Groove GFS Browser Helper – {72853161-30C5-4D22-B7F9-0BBC1D38A37E} – E:\Other Applications\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 – BHO: SSVHelper Class – {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} – E:\Other Applications\Java\bin\ssv.dll
O2 – BHO: scriptproxy – {7DB2D5A0-7241-4E79-B68D-6309F01C5231} – C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 – BHO: (no name) – {7E853D72-626A-48EC-A868-BA8D5E23E045} – (no file)
O2 – BHO: Windows Live Sign-in Helper – {9030D464-4C02-4ABF-8ECC-5164760863C6} – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 – BHO: McAfee SiteAdvisor BHO – {B164E929-A1B6-4A06-B104-2CD0E90A88FF} – c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 – Toolbar: McAfee SiteAdvisor Toolbar – {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} – c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 – HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 – HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 – HKLM\..\Run: [nwiz] nwiz.exe /install
O4 – HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 – HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 – HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 – HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 – HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 – HKLM\..\Run: [SunJavaUpdateSched] "E:\Other Applications\Java\bin\jusched.exe"
O4 – HKLM\..\Run: [GrooveMonitor] "E:\Other Applications\Microsoft Office\Office12\GrooveMonitor.exe"
O4 – HKLM\..\Run: [metokugiwe] Rundll32.exe "C:\WINDOWS\system32\raramuge.dll",s
O4 – HKLM\..\Run: [CPM0305ced7] Rundll32.exe "c:\windows\system32\hididofu.dll",a
O4 – HKLM\..\Run: [ISTray] "E:\Other Applications\Spyware Doctor\pctsTray.exe"
O4 – HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 – HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 – HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [Uniblue RegistryBooster 2] E:\Other Applications\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 – HKUS\S-1-5-19\..\Run: [metokugiwe] Rundll32.exe "C:\WINDOWS\system32\raramuge.dll",s (User ‘LOCAL SERVICE’)
O4 – HKUS\S-1-5-20\..\Run: [metokugiwe] Rundll32.exe "C:\WINDOWS\system32\raramuge.dll",s (User ‘NETWORK SERVICE’)
O4 – Startup: OneNote 2007 Screen Clipper and Launcher.lnk = E:\Other Applications\Microsoft Office\Office12\ONENOTEM.EXE
O4 – Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 – Extra context menu item: E&xport to Microsoft Excel – res://E:\OTHERA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – E:\Other Applications\Java\bin\ssv.dll
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – E:\Other Applications\Java\bin\ssv.dll
O9 – Extra button: Send to OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – E:\OTHERA~1\MICROS~1\Office12\ONBttnIE.dll
O9 – Extra ‘Tools’ menuitem: S&end to OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – E:\OTHERA~1\MICROS~1\Office12\ONBttnIE.dll
O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – E:\OTHERA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 – Extra button: (no name) – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 – Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O18 – Protocol: grooveLocalGWS – {88FED34C-F0CA-4636-A375-3CB6248B04CD} – E:\Other Applications\Microsoft Office\Office12\GrooveSystemServices.dll
O18 – Protocol: sacore – {5513F07E-936B-4E52-9B00-067394E91CC5} – c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 – AppInit_DLLs: C:\WINDOWS\system32\vorehuye.dll c:\windows\system32\hididofu.dll
O21 – SSODL: SSODL – {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} – c:\windows\system32\hididofu.dll
O22 – SharedTaskScheduler: STS – {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} – c:\windows\system32\hididofu.dll
O23 – Service: InstallDriver Table Manager (IDriverT) – Macrovision Corporation – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 – Service: InCD Helper (InCDsrv) – Nero AG – C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 – Service: LightScribeService Direct Disc Labeling Service (LightScribeService) – Hewlett-Packard Company – C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 – Service: McAfee SiteAdvisor Service – Unknown owner – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 – Service: McAfee Services (mcmscsvc) – McAfee, Inc. – C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 – Service: McAfee Network Agent (McNASvc) – McAfee, Inc. – c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 – Service: McAfee Scanner (McODS) – McAfee, Inc. – C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 – Service: McAfee Proxy Service (McProxy) – McAfee, Inc. – c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 – Service: McAfee Real-time Scanner (McShield) – McAfee, Inc. – C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 – Service: McAfee SystemGuards (McSysmon) – McAfee, Inc. – C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 – Service: McAfee Personal Firewall Service (MpfService) – McAfee, Inc. – C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 – Service: NBService – Nero AG – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 – Service: NMIndexingService – Nero AG – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 – Service: NVIDIA Display Driver Service (NVSvc) – NVIDIA Corporation – C:\WINDOWS\system32\nvsvc32.exe
O23 – Service: PnkBstrA – Unknown owner – C:\WINDOWS\system32\PnkBstrA.exe
O23 – Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) – CACE Technologies – C:\Program Files\WinPcap\rpcapd.exe
O23 – Service: PC Tools Auxiliary Service (sdAuxService) – PC Tools – E:\Other Applications\Spyware Doctor\pctsAuxs.exe
O23 – Service: PC Tools Security Service (sdCoreService) – PC Tools – E:\Other Applications\Spyware Doctor\pctsSvc.exe
–
End of file – 9218 bytes