Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21.33.25, on 13/04/2014
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16386)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
C:\Windows\system32\taskeng.exe
C:\Users\GTE\Downloads\SoftonicDownloader_per_hijackthis.exe
C:\Users\GTE\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.sweet-page.com/?type=hp&ts=1397367130&from=cor&uid=FUJITSUXMHV2060AT_NS59T5825FDFT5825FDFXR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6Xow1K8E36IsV4sG9lrO5sjiiVsN1qT2bdIYlM4i0zwr0q5obuQwgemrw1IKGv-mCG-jdGIVzHBI-Nh2ANdsaPUPfMSu315BN7lJNZOBthzwyor-t1SQYNO0lqZrNMkQPAMpG35-iLmqcni7xbFWUyiqmqSuph10pP0Qmn87Hdm2ywNyuz6IyZA5k,&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6Xow1K8E36IsV4sG9lrO5sjiiVsN1qT2bdIYlM4i0zwr0q5obuQwgemrw1IKGv-mCG-jdGIVzHBI-Nh2ANdsaPUPfMSu315BN7lJNZOBthzwyor-t1SQYNO0lqZrNMkQPAMpG35-iLmqcni7xbFWUyiqmqSuph10pP0Qmn87Hdm2ywNyuz6IyZA5k,&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6Xow1K8E36IsV4sG9lrO5sjiiVsN1qT2bdIYlM4i0zwr0q5obuQwgemrw1IKGv-mCG-jdGIVzHBI-Nh2ANdsaPUPu01_1tH0OMRBSGjXEagEHdF27WvEAGzvPRk6Ro0dyMeC7UT09qloWenNkAm8JcgydxsCUxBbRqEJsyIBswllrYsL1Yu-Sat9I,R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.sweet-page.com/?type=hp&ts=1397367130&from=cor&uid=FUJITSUXMHV2060AT_NS59T5825FDFT5825FDFXR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.sweet-page.com/web/?type=ds&ts=1397367130&from=cor&uid=FUJITSUXMHV2060AT_NS59T5825FDFT5825FDFX&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.sweet-page.com/web/?type=ds&ts=1397367130&from=cor&uid=FUJITSUXMHV2060AT_NS59T5825FDFT5825FDFX&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.sweet-page.com/?type=hp&ts=1397367130&from=cor&uid=FUJITSUXMHV2060AT_NS59T5825FDFT5825FDFXR1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6Xow1K8E36IsV4sG9lrO5sjiiVsN1qT2bdIYlM4i0zwr0q5obuQwgemrw1IKGv-mCG-jdGIVzHBI-Nh2ANdsaPUPfMSu315BN7lJNZOBthzwyor-t1SQYNO0lqZrNMkQPAMpG35-iLmqcni7xbFWUyiqmqSuph10pP0Qmn87Hdm2ywNyuz6IyZA5k,&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6Xow1K8E36IsV4sG9lrO5sjiiVsN1qT2bdIYlM4i0zwr0q5obuQwgemrw1IKGv-mCG-jdGIVzHBI-Nh2ANdsaPUPfMSu315BN7lJNZOBthzwyor-t1SQYNO0lqZrNMkQPAMpG35-iLmqcni7xbFWUyiqmqSuph10pP0Qmn87Hdm2ywNyuz6IyZA5k,&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: CrossriderApp0049074 - {11111111-1111-1111-1111-110411901174} - C:\Program Files\The weDownload Manager\The weDownload Manager-bho.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O20 - AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: IePlugin Service (IePluginService) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginService\PluginService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Update BrowseMark - Unknown owner - C:\Program Files\BrowseMark\updateBrowseMark.exe (file missing)
O23 - Service: Util BrowseMark - Unknown owner - C:\Program Files\BrowseMark\bin\utilBrowseMark.exe (file missing)
O23 - Service: Wpm Service (Wpm) - Cherished Technololgy LIMITED - C:\ProgramData\WPM\wprotectmanager.exe
--
End of file - 5695 bytes