ok so first new hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 13:25:22, on 13.5.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Windows\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\Up2Date.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.fastweb.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.fastweb.itR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.fastweb.it/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by FastWeb
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\Windows\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [KAV50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe" -run -n PersonalPro -v 5.0.0.0
O4 - HKCU\..\Run: [ctfmon.exe] C:\Windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [GPTCR2] C:\Windows\GPT
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {CC42FB49-697E-4392-A1AE-B945CD6B97C5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {CC42FB49-697E-4392-A1AE-B945CD6B97C5} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.fastweb.it
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) -
https://components.viewpoint.com/MTSInstall...mputers_TSeriesO16 - DPF: {3BB4FE3B-7A37-11D3-A41E-0060080C03B3} (Entire Screen Builder Web Viewer) -
http://vblu.uni-bocconi.it/vblu/NWWClientFull.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO23 - Service: Kaspersky Anti-Virus Service (KLBLMain) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
then from get2 :
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:000000ff
"_NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktopChanges"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"WallpaperStyle"=dword:00000000
"NoDispBackgroundPage"=dword:00000001
"NoDispAppearancePage"=dword:00000001
"Wallpaper"="c:\\wp.bmp"
now find1:
Volume in drive C has no label.
Volume Serial Number is E027-3C3A
Directory of C:\WINDOWS\Resources\Themes
18.09.2001 22:45 <DIR> .
18.09.2001 22:45 <DIR> ..
11.05.2005 02:20 <DIR> Luna
18.08.2001 15:00 1.222 Luna.theme
18.08.2001 15:00 3.025 Windows Classic.theme
2 File(s) 4.247 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna
11.05.2005 02:20 <DIR> .
11.05.2005 02:20 <DIR> ..
04.08.2004 07:33 4.190.352 luna.msstyles
23.12.2002 02:52 <DIR> MUI
18.09.2001 22:45 <DIR> Shell
1 File(s) 4.190.352 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\MUI
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
23.12.2002 02:52 <DIR> 041a
23.12.2002 02:52 <DIR> 0424
0 File(s) 0 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\MUI\041a
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 49.152 Luna.msstyles.mui
1 File(s) 49.152 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\MUI\0424
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 49.152 Luna.msstyles.mui
1 File(s) 49.152 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell
18.09.2001 22:45 <DIR> .
18.09.2001 22:45 <DIR> ..
18.09.2001 22:45 <DIR> Homestead
18.09.2001 22:45 <DIR> Metallic
18.09.2001 22:45 <DIR> NormalColor
0 File(s) 0 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead
18.09.2001 22:45 <DIR> .
18.09.2001 22:45 <DIR> ..
23.12.2002 02:52 <DIR> MUI
18.08.2001 15:00 362.496 shellstyle.dll
1 File(s) 362.496 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead\MUI
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
23.12.2002 02:52 <DIR> 041a
23.12.2002 02:52 <DIR> 0424
0 File(s) 0 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead\MUI\041a
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 16.384 ShellStyle.dll.mui
1 File(s) 16.384 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead\MUI\0424
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 8.192 ShellStyle.dll.mui
1 File(s) 8.192 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic
18.09.2001 22:45 <DIR> .
18.09.2001 22:45 <DIR> ..
23.12.2002 02:52 <DIR> MUI
18.08.2001 15:00 362.496 shellstyle.dll
1 File(s) 362.496 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic\MUI
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
23.12.2002 02:52 <DIR> 041a
23.12.2002 02:52 <DIR> 0424
0 File(s) 0 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic\MUI\041a
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 16.384 ShellStyle.dll.mui
1 File(s) 16.384 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic\MUI\0424
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 8.192 ShellStyle.dll.mui
1 File(s) 8.192 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor
18.09.2001 22:45 <DIR> .
18.09.2001 22:45 <DIR> ..
23.12.2002 02:52 <DIR> MUI
18.08.2001 15:00 361.472 shellstyle.dll
1 File(s) 361.472 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor\MUI
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
23.12.2002 02:52 <DIR> 041a
23.12.2002 02:52 <DIR> 0424
0 File(s) 0 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor\MUI\041a
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 16.384 ShellStyle.dll.mui
1 File(s) 16.384 bytes
Directory of C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor\MUI\0424
23.12.2002 02:52 <DIR> .
23.12.2002 02:52 <DIR> ..
04.03.2002 21:00 8.192 ShellStyle.dll.mui
1 File(s) 8.192 bytes
Total Files Listed:
14 File(s) 5.453.095 bytes
53 Dir(s) 2.645.479.424 bytes free
and finally from export:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Themes"
"Group"="UIGroup"
"ObjectName"="LocalSystem"
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,74,00,65,\
00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
"Description"="Provides user experience theme management."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
73,00,68,00,73,00,76,00,63,00,73,00,2e,00,64,00,6c,00,6c,00,00,00
"ServiceMain"="ThemeServiceMain"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Themes\Enum]
"0"="Root\\LEGACY_THEMES\\0000"
"Count"=dword:00000001
"NextInstance"=dword:00000001
that s all...hope to hear from you soon.
thanks