SlideShare a Scribd company logo
1 of 5
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32acs.exe
C:Program FilesAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe
C:Program FilesCommon FilesAOLTopSpeed2.0aoltsmon.exe
C:Program FilesCommon FilesAppleMobile Device
SupportbinAppleMobileDeviceService.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesTOSHIBAConfigFreeCFSvcs.exe
C:WINDOWSsystem32DVDRAMSV.exe
C:Program FilesJavajre6binjqs.exe
C:WINDOWSsystem32PSIService.exe
c:TOSHIBAIVPswupdateswupdtmr.exe
C:WINDOWSsystem32Tablet.exe
C:Program FilesViewpointCommonViewpointService.exe
C:WINDOWSsystem32WTabletTabUserW.exe
C:WINDOWSsystem32Tablet.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:WINDOWSSystem32DLADLACTRLW.EXE
C:Program FilesApoint2KApoint.exe
C:WINDOWSRTHDCPL.EXE
C:Program FilesltmohLtmoh.exe
C:WINDOWSAGRSMMSG.exe
C:Program FilesApoint2KApntex.exe
C:Program FilesTOSHIBAConfigFreeNDSTray.exe
C:Program FilesTOSHIBAE-KEYCeEKey.exe
C:WINDOWSsystem32TPSMain.exe
C:Program FilesTOSHIBATouch and LaunchPadExe.exe
C:WINDOWSsystem32ZoomingHook.exe
C:Program FilesTOSHIBATOSHIBA Zooming UtilitySmoothView.exe
C:Program FilesToshibaTvsTvsTray.exe
C:Program FilesTOSHIBATouchPadTPTray.exe
C:WINDOWSsystem32TPSBattM.exe
C:WINDOWSsystem32TCtrlIOHook.exe
C:Program FilesTOSHIBATOSHIBA ControlsTFncKy.exe
C:Program FilesTOSHIBAConfigFreeCFSServ.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesMessengermsmsgs.exe
C:WINDOWSsystem32RAMASST.exe
C:Program FilesiPodbiniPodService.exe
C:Program FilesMalwarebytes' Anti-Malwarembam.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Documents and Settingskitty228My
DocumentsDownloadsCIS_Setup_3.13.120417.573_XP_Vista_x32.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = search.net-
studio.org
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = search.net-
studio.org
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = search.net-
studio.org
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Internet
Explorer
O1 - Hosts: 193.125.23.12 updates.sald.
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
- C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -
C:Program FilesYontoo Layers Client for Internet ExplorerYontooIEClient.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-
A2E2-585B10099BFC} - C:Program FilesVeoh
NetworksVeohWebPlayerVeohIEToolbar.dll
O4 - HKLM..Run: [DLA] C:WINDOWSSystem32DLADLACTRLW.EXE
O4 - HKLM..Run: [Apoint] C:Program FilesApoint2KApoint.exe
O4 - HKLM..Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM..Run: [LtMoh] C:Program FilesltmohLtmoh.exe
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM..Run: [HWSetup] C:Program FilesTOSHIBATOSHIBA
AppletHWSetup.exe hwSetUP
O4 - HKLM..Run: [SVPWUTIL] C:Program FilesToshibaWindows
UtilitiesSVPWUTIL.exe SVPwUTIL
O4 - HKLM..Run: [CeEKEY] C:Program FilesTOSHIBAE-KEYCeEKey.exe
O4 - HKLM..Run: [TPSMain] TPSMain.exe
O4 - HKLM..Run: [PadTouch] C:Program FilesTOSHIBATouch and
LaunchPadExe.exe
O4 - HKLM..Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM..Run: [SmoothView] C:Program FilesTOSHIBATOSHIBA Zooming
UtilitySmoothView.exe
O4 - HKLM..Run: [Tvs] C:Program FilesToshibaTvsTvsTray.exe
O4 - HKLM..Run: [TPNF] C:Program FilesTOSHIBATouchPadTPTray.exe
O4 - HKLM..Run: [Pinger] c:toshibaivpismpinger.exe /run
O4 - HKLM..Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM..Run: [TFncKy] TFncKy.exe
O4 - HKLM..Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM..Run: [IPHSend] C:Program FilesCommon
FilesAOLIPHSendIPHSend.exe
O4 - HKLM..Run: [SpamBlocker] C:Program
FilesSpamBlockerUtilityBin4.8.0.0SbOEAddOn.exe
O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [MSKDetectorExe] C:Program
FilesMcAfeeSpamKillerMSKDetct.exe /uninstall
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe"
-atboottime
O4 - HKLM..Run: [Malwarebytes Anti-Malware (reboot)] "C:Program
FilesMalwarebytes' Anti-Malwarembam.exe" /runcleanupscript
O4 - HKLM..Run: [sjsaqvtc] C:Documents and Settingskitty228Local
SettingsApplication Datafrgwkvlsehsysguard.exe
O4 - HKCU..Run: [TOSCDSPD] C:Program
FilesTOSHIBATOSCDSPDtoscdspd.exe
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe"
/background
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [µTorrent] "C:Program Filesutorrentutorrent.exe"
O4 - HKCU..Run: [sjsaqvtc] C:Documents and Settingskitty228Local
SettingsApplication Datafrgwkvlsehsysguard.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft
OfficeOfficeOSA9.EXE
O4 - Global Startup: RAMASST.lnk = C:WINDOWSsystem32RAMASST.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no
file)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} -
C:Documents and Settingskitty228Start MenuProgramsIMVURun IMVU.lnk (file
missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-
f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-
BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O10 - Unknown file in Winsock LSP: c:windowssystem32nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo
Uploader 5 Control) -
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo
Uploader 5 Control) -
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner -
C:WINDOWSsystem32acs.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown
owner - C:Program FilesAdobePhotoshop Elements
5.0PhotoshopElementsFileAgent.exe
O23 - Service: AntiPol (AntipPolice_) - Unknown owner - C:WINDOWSsvchast.exe
(file missing)
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc
- C:Program FilesCommon FilesAOLTopSpeed2.0aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon
FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software -
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -
C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil
SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:Program FilesAlwil
SoftwareAvast4ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:Program FilesAlwil
SoftwareAvast4ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:Program
FilesBonjourmDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:Program
FilesTOSHIBAConfigFreeCFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -
C:WINDOWSsystem32DVDRAMSV.exe
O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodbiniPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -
C:Program FilesJavajre6binjqs.exe
O23 - Service: ProtexisLicensing - Unknown owner -
C:WINDOWSsystem32PSIService.exe
O23 - Service: Swupdtmr - Unknown owner - c:TOSHIBAIVPswupdateswupdtmr.exe
O23 - Service: TabletService - Wacom Technology, Corp. -
C:WINDOWSsystem32Tablet.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:Program Files
ViewpointCommonViewpointService.exe
O24 - Desktop Component 0: (no name) -
http://img457.imageshack.us/img457/8118/piratesofthecaribbeanwallpaper.gif
O24 - Desktop Component 1: (no name) -
http://img172.imageshack.us/img172/8118/piratesofthecaribbeanwallpaper.gif

--
End of file - 9813 bytes

More Related Content

What's hot

Getting root with benign app store apps vsecurityfest
Getting root with benign app store apps vsecurityfestGetting root with benign app store apps vsecurityfest
Getting root with benign app store apps vsecurityfestCsaba Fitzl
 
Mocks, Stubs and Fakes. ¿What Else?
Mocks, Stubs and Fakes. ¿What Else?Mocks, Stubs and Fakes. ¿What Else?
Mocks, Stubs and Fakes. ¿What Else?Alex Soto
 
Reversing Engineering a Web Application - For fun, behavior and detection
Reversing Engineering a Web Application - For fun, behavior and detectionReversing Engineering a Web Application - For fun, behavior and detection
Reversing Engineering a Web Application - For fun, behavior and detectionRodrigo Montoro
 
GateKeeper - bypass or not bypass?
GateKeeper - bypass or not bypass?GateKeeper - bypass or not bypass?
GateKeeper - bypass or not bypass?Csaba Fitzl
 
There's Nothing so Permanent as Temporary
There's Nothing so Permanent as TemporaryThere's Nothing so Permanent as Temporary
There's Nothing so Permanent as TemporaryPositive Hack Days
 
Php File Upload
Php File UploadPhp File Upload
Php File Uploadsaeel005
 
Getting root with benign app store apps
Getting root with benign app store appsGetting root with benign app store apps
Getting root with benign app store appsCsaba Fitzl
 
Secondary authorization code.txt (0.04 kb)
Secondary authorization code.txt (0.04 kb)Secondary authorization code.txt (0.04 kb)
Secondary authorization code.txt (0.04 kb)francescobettin1
 
Exploiting Directory Permissions on macOS
Exploiting Directory Permissions on macOSExploiting Directory Permissions on macOS
Exploiting Directory Permissions on macOSCsaba Fitzl
 
Taming botnets
Taming botnetsTaming botnets
Taming botnetsf00d
 
On Call Engineer Happiness - DevOps Days Galway 2017
On Call Engineer Happiness - DevOps Days Galway 2017On Call Engineer Happiness - DevOps Days Galway 2017
On Call Engineer Happiness - DevOps Days Galway 2017Paul O'Connor
 
Docker Testing
Docker TestingDocker Testing
Docker TestingAlex Soto
 

What's hot (16)

Getting root with benign app store apps vsecurityfest
Getting root with benign app store apps vsecurityfestGetting root with benign app store apps vsecurityfest
Getting root with benign app store apps vsecurityfest
 
Mocks, Stubs and Fakes. ¿What Else?
Mocks, Stubs and Fakes. ¿What Else?Mocks, Stubs and Fakes. ¿What Else?
Mocks, Stubs and Fakes. ¿What Else?
 
Reversing Engineering a Web Application - For fun, behavior and detection
Reversing Engineering a Web Application - For fun, behavior and detectionReversing Engineering a Web Application - For fun, behavior and detection
Reversing Engineering a Web Application - For fun, behavior and detection
 
GateKeeper - bypass or not bypass?
GateKeeper - bypass or not bypass?GateKeeper - bypass or not bypass?
GateKeeper - bypass or not bypass?
 
odt_file.odt
odt_file.odtodt_file.odt
odt_file.odt
 
Life on Clouds: a forensics overview
Life on Clouds: a forensics overviewLife on Clouds: a forensics overview
Life on Clouds: a forensics overview
 
There's Nothing so Permanent as Temporary
There's Nothing so Permanent as TemporaryThere's Nothing so Permanent as Temporary
There's Nothing so Permanent as Temporary
 
Fileice
FileiceFileice
Fileice
 
Php File Upload
Php File UploadPhp File Upload
Php File Upload
 
Getting root with benign app store apps
Getting root with benign app store appsGetting root with benign app store apps
Getting root with benign app store apps
 
Secondary authorization code.txt (0.04 kb)
Secondary authorization code.txt (0.04 kb)Secondary authorization code.txt (0.04 kb)
Secondary authorization code.txt (0.04 kb)
 
Exploiting Directory Permissions on macOS
Exploiting Directory Permissions on macOSExploiting Directory Permissions on macOS
Exploiting Directory Permissions on macOS
 
Taming botnets
Taming botnetsTaming botnets
Taming botnets
 
On Call Engineer Happiness - DevOps Days Galway 2017
On Call Engineer Happiness - DevOps Days Galway 2017On Call Engineer Happiness - DevOps Days Galway 2017
On Call Engineer Happiness - DevOps Days Galway 2017
 
Docker Testing
Docker TestingDocker Testing
Docker Testing
 
Git within RStudio
Git within RStudioGit within RStudio
Git within RStudio
 

Viewers also liked

Introduction to Credit Risk
Introduction to Credit RiskIntroduction to Credit Risk
Introduction to Credit RiskLoanXpress
 
Center of the_bible
Center of the_bibleCenter of the_bible
Center of the_bibleKitty
 
Learning and Training
Learning and TrainingLearning and Training
Learning and Trainingraviktalentus
 
Financial Ratios - Introduction to Efficiency Ratios
Financial Ratios - Introduction to Efficiency RatiosFinancial Ratios - Introduction to Efficiency Ratios
Financial Ratios - Introduction to Efficiency RatiosLoanXpress
 
Hospitalized
HospitalizedHospitalized
HospitalizedKitty
 
A representação da linguagem
A representação da linguagemA representação da linguagem
A representação da linguagemFSBA
 
Wprowadzenie Do Asp
Wprowadzenie Do AspWprowadzenie Do Asp
Wprowadzenie Do AspKelut
 
Human Capital Services , Consulting and Advisory
Human Capital Services , Consulting and AdvisoryHuman Capital Services , Consulting and Advisory
Human Capital Services , Consulting and Advisoryraviktalentus
 
Financial Ratios - Introduction to Solvency Ratios
Financial Ratios - Introduction to Solvency RatiosFinancial Ratios - Introduction to Solvency Ratios
Financial Ratios - Introduction to Solvency RatiosLoanXpress
 
Introduction to SMEs and MSMEs
Introduction to SMEs and MSMEsIntroduction to SMEs and MSMEs
Introduction to SMEs and MSMEsLoanXpress
 
Financial Ratios - Introduction to Profitability Ratios
Financial Ratios - Introduction to Profitability RatiosFinancial Ratios - Introduction to Profitability Ratios
Financial Ratios - Introduction to Profitability RatiosLoanXpress
 
A representação da linguagem
A representação da linguagemA representação da linguagem
A representação da linguagemFSBA
 
Advantages & Disadvantages of Loans
Advantages & Disadvantages of LoansAdvantages & Disadvantages of Loans
Advantages & Disadvantages of LoansLoanXpress
 
Introduction to RBI key policy rates
Introduction to RBI key policy ratesIntroduction to RBI key policy rates
Introduction to RBI key policy ratesLoanXpress
 
Introduction to Debt Financing
Introduction to Debt FinancingIntroduction to Debt Financing
Introduction to Debt FinancingLoanXpress
 
Types of Loans
Types of LoansTypes of Loans
Types of LoansLoanXpress
 
Introduction to Know Your Customer (KYC)
Introduction to Know Your Customer (KYC)Introduction to Know Your Customer (KYC)
Introduction to Know Your Customer (KYC)LoanXpress
 

Viewers also liked (19)

Introduction to Credit Risk
Introduction to Credit RiskIntroduction to Credit Risk
Introduction to Credit Risk
 
Center of the_bible
Center of the_bibleCenter of the_bible
Center of the_bible
 
Learning and Training
Learning and TrainingLearning and Training
Learning and Training
 
Competency Based Leadership
Competency Based LeadershipCompetency Based Leadership
Competency Based Leadership
 
Financial Ratios - Introduction to Efficiency Ratios
Financial Ratios - Introduction to Efficiency RatiosFinancial Ratios - Introduction to Efficiency Ratios
Financial Ratios - Introduction to Efficiency Ratios
 
Hospitalized
HospitalizedHospitalized
Hospitalized
 
A representação da linguagem
A representação da linguagemA representação da linguagem
A representação da linguagem
 
Wprowadzenie Do Asp
Wprowadzenie Do AspWprowadzenie Do Asp
Wprowadzenie Do Asp
 
Human Capital Services , Consulting and Advisory
Human Capital Services , Consulting and AdvisoryHuman Capital Services , Consulting and Advisory
Human Capital Services , Consulting and Advisory
 
Resume Of Vdv
Resume Of VdvResume Of Vdv
Resume Of Vdv
 
Financial Ratios - Introduction to Solvency Ratios
Financial Ratios - Introduction to Solvency RatiosFinancial Ratios - Introduction to Solvency Ratios
Financial Ratios - Introduction to Solvency Ratios
 
Introduction to SMEs and MSMEs
Introduction to SMEs and MSMEsIntroduction to SMEs and MSMEs
Introduction to SMEs and MSMEs
 
Financial Ratios - Introduction to Profitability Ratios
Financial Ratios - Introduction to Profitability RatiosFinancial Ratios - Introduction to Profitability Ratios
Financial Ratios - Introduction to Profitability Ratios
 
A representação da linguagem
A representação da linguagemA representação da linguagem
A representação da linguagem
 
Advantages & Disadvantages of Loans
Advantages & Disadvantages of LoansAdvantages & Disadvantages of Loans
Advantages & Disadvantages of Loans
 
Introduction to RBI key policy rates
Introduction to RBI key policy ratesIntroduction to RBI key policy rates
Introduction to RBI key policy rates
 
Introduction to Debt Financing
Introduction to Debt FinancingIntroduction to Debt Financing
Introduction to Debt Financing
 
Types of Loans
Types of LoansTypes of Loans
Types of Loans
 
Introduction to Know Your Customer (KYC)
Introduction to Know Your Customer (KYC)Introduction to Know Your Customer (KYC)
Introduction to Know Your Customer (KYC)
 

Similar to Hijack This

Batch programming and Viruses
Batch programming and VirusesBatch programming and Viruses
Batch programming and VirusesAkshay Saini
 
Ilomo Clampi Botnet Aug2009
Ilomo Clampi Botnet Aug2009Ilomo Clampi Botnet Aug2009
Ilomo Clampi Botnet Aug2009Trend Micro
 
Антон Наумович, Система автоматической крэш-аналитики своими средствами
Антон Наумович, Система автоматической крэш-аналитики своими средствамиАнтон Наумович, Система автоматической крэш-аналитики своими средствами
Антон Наумович, Система автоматической крэш-аналитики своими средствамиSergey Platonov
 
Black Energy18 - Russian botnet package analysis
Black Energy18 - Russian botnet package analysisBlack Energy18 - Russian botnet package analysis
Black Energy18 - Russian botnet package analysisRoberto Suggi Liverani
 
Windows persistence presentation
Windows persistence presentationWindows persistence presentation
Windows persistence presentationOlehLevytskyi1
 
CHAPTER 3 BASIC DYNAMIC ANALYSIS.ppt
CHAPTER 3 BASIC DYNAMIC ANALYSIS.pptCHAPTER 3 BASIC DYNAMIC ANALYSIS.ppt
CHAPTER 3 BASIC DYNAMIC ANALYSIS.pptManjuAppukuttan2
 
Forensics perspective ERFA-møde marts 2017
 Forensics perspective ERFA-møde marts 2017 Forensics perspective ERFA-møde marts 2017
Forensics perspective ERFA-møde marts 2017J Hartig
 
Reversing & Malware Analysis Training Part 9 - Advanced Malware Analysis
Reversing & Malware Analysis Training Part 9 -  Advanced Malware AnalysisReversing & Malware Analysis Training Part 9 -  Advanced Malware Analysis
Reversing & Malware Analysis Training Part 9 - Advanced Malware Analysissecurityxploded
 
Slide 1 - Oklahoma State University - Welcome
Slide 1 - Oklahoma State University - WelcomeSlide 1 - Oklahoma State University - Welcome
Slide 1 - Oklahoma State University - Welcomebutest
 
Cloud Foundry Command Line
Cloud Foundry Command LineCloud Foundry Command Line
Cloud Foundry Command LineJulia R Nash
 
Windows forensic artifacts
Windows forensic artifactsWindows forensic artifacts
Windows forensic artifactsPardhasaradhi ch
 
How to generate,collect and upload ocum logs
How to generate,collect and upload ocum logsHow to generate,collect and upload ocum logs
How to generate,collect and upload ocum logsAshwin Pawar
 

Similar to Hijack This (20)

Zhp diag
Zhp diagZhp diag
Zhp diag
 
Batch programming and Viruses
Batch programming and VirusesBatch programming and Viruses
Batch programming and Viruses
 
Users guide
Users guideUsers guide
Users guide
 
Ilomo Clampi Botnet Aug2009
Ilomo Clampi Botnet Aug2009Ilomo Clampi Botnet Aug2009
Ilomo Clampi Botnet Aug2009
 
Avgrep
AvgrepAvgrep
Avgrep
 
Антон Наумович, Система автоматической крэш-аналитики своими средствами
Антон Наумович, Система автоматической крэш-аналитики своими средствамиАнтон Наумович, Система автоматической крэш-аналитики своими средствами
Антон Наумович, Система автоматической крэш-аналитики своими средствами
 
Black Energy18 - Russian botnet package analysis
Black Energy18 - Russian botnet package analysisBlack Energy18 - Russian botnet package analysis
Black Energy18 - Russian botnet package analysis
 
Best free tools for w d a
Best free tools for w d aBest free tools for w d a
Best free tools for w d a
 
Best free tools for win database admin
Best free tools for win database adminBest free tools for win database admin
Best free tools for win database admin
 
Windows persistence presentation
Windows persistence presentationWindows persistence presentation
Windows persistence presentation
 
Optimize Your Pc
Optimize Your PcOptimize Your Pc
Optimize Your Pc
 
Freefixer log
Freefixer logFreefixer log
Freefixer log
 
CHAPTER 3 BASIC DYNAMIC ANALYSIS.ppt
CHAPTER 3 BASIC DYNAMIC ANALYSIS.pptCHAPTER 3 BASIC DYNAMIC ANALYSIS.ppt
CHAPTER 3 BASIC DYNAMIC ANALYSIS.ppt
 
Forensics perspective ERFA-møde marts 2017
 Forensics perspective ERFA-møde marts 2017 Forensics perspective ERFA-møde marts 2017
Forensics perspective ERFA-møde marts 2017
 
Reversing & Malware Analysis Training Part 9 - Advanced Malware Analysis
Reversing & Malware Analysis Training Part 9 -  Advanced Malware AnalysisReversing & Malware Analysis Training Part 9 -  Advanced Malware Analysis
Reversing & Malware Analysis Training Part 9 - Advanced Malware Analysis
 
Slide 1 - Oklahoma State University - Welcome
Slide 1 - Oklahoma State University - WelcomeSlide 1 - Oklahoma State University - Welcome
Slide 1 - Oklahoma State University - Welcome
 
Cloud Foundry Command Line
Cloud Foundry Command LineCloud Foundry Command Line
Cloud Foundry Command Line
 
Windows forensic artifacts
Windows forensic artifactsWindows forensic artifacts
Windows forensic artifacts
 
Windows forensic artifacts
Windows forensic artifactsWindows forensic artifacts
Windows forensic artifacts
 
How to generate,collect and upload ocum logs
How to generate,collect and upload ocum logsHow to generate,collect and upload ocum logs
How to generate,collect and upload ocum logs
 

Recently uploaded

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsHyundai Motor Group
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 

Recently uploaded (20)

Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 

Hijack This

  • 1. Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32svchost.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSExplorer.EXE C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe C:Program FilesAlwil SoftwareAvast4ashServ.exe C:WINDOWSsystem32spoolsv.exe C:WINDOWSsystem32acs.exe C:Program FilesAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe C:Program FilesCommon FilesAOLTopSpeed2.0aoltsmon.exe C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe C:Program FilesBonjourmDNSResponder.exe C:Program FilesTOSHIBAConfigFreeCFSvcs.exe C:WINDOWSsystem32DVDRAMSV.exe C:Program FilesJavajre6binjqs.exe C:WINDOWSsystem32PSIService.exe c:TOSHIBAIVPswupdateswupdtmr.exe C:WINDOWSsystem32Tablet.exe C:Program FilesViewpointCommonViewpointService.exe C:WINDOWSsystem32WTabletTabUserW.exe C:WINDOWSsystem32Tablet.exe C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe C:Program FilesAlwil SoftwareAvast4ashWebSv.exe C:WINDOWSSystem32DLADLACTRLW.EXE C:Program FilesApoint2KApoint.exe C:WINDOWSRTHDCPL.EXE C:Program FilesltmohLtmoh.exe C:WINDOWSAGRSMMSG.exe C:Program FilesApoint2KApntex.exe C:Program FilesTOSHIBAConfigFreeNDSTray.exe C:Program FilesTOSHIBAE-KEYCeEKey.exe C:WINDOWSsystem32TPSMain.exe C:Program FilesTOSHIBATouch and LaunchPadExe.exe C:WINDOWSsystem32ZoomingHook.exe C:Program FilesTOSHIBATOSHIBA Zooming UtilitySmoothView.exe C:Program FilesToshibaTvsTvsTray.exe C:Program FilesTOSHIBATouchPadTPTray.exe C:WINDOWSsystem32TPSBattM.exe
  • 2. C:WINDOWSsystem32TCtrlIOHook.exe C:Program FilesTOSHIBATOSHIBA ControlsTFncKy.exe C:Program FilesTOSHIBAConfigFreeCFSServ.exe C:Program FilesiTunesiTunesHelper.exe C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe C:WINDOWSsystem32ctfmon.exe C:Program FilesMessengermsmsgs.exe C:WINDOWSsystem32RAMASST.exe C:Program FilesiPodbiniPodService.exe C:Program FilesMalwarebytes' Anti-Malwarembam.exe C:Program FilesMozilla Firefoxfirefox.exe C:Documents and Settingskitty228My DocumentsDownloadsCIS_Setup_3.13.120417.573_XP_Vista_x32.exe C:Program FilesTrend MicroHijackThisHijackThis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = search.net- studio.org R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = search.net- studio.org R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = search.net- studio.org R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Internet Explorer O1 - Hosts: 193.125.23.12 updates.sald. O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:Program FilesYontoo Layers Client for Internet ExplorerYontooIEClient.dll O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a- A2E2-585B10099BFC} - C:Program FilesVeoh NetworksVeohWebPlayerVeohIEToolbar.dll O4 - HKLM..Run: [DLA] C:WINDOWSSystem32DLADLACTRLW.EXE O4 - HKLM..Run: [Apoint] C:Program FilesApoint2KApoint.exe O4 - HKLM..Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM..Run: [LtMoh] C:Program FilesltmohLtmoh.exe O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM..Run: [NDSTray.exe] NDSTray.exe O4 - HKLM..Run: [HWSetup] C:Program FilesTOSHIBATOSHIBA AppletHWSetup.exe hwSetUP O4 - HKLM..Run: [SVPWUTIL] C:Program FilesToshibaWindows UtilitiesSVPWUTIL.exe SVPwUTIL O4 - HKLM..Run: [CeEKEY] C:Program FilesTOSHIBAE-KEYCeEKey.exe O4 - HKLM..Run: [TPSMain] TPSMain.exe
  • 3. O4 - HKLM..Run: [PadTouch] C:Program FilesTOSHIBATouch and LaunchPadExe.exe O4 - HKLM..Run: [ZoomingHook] ZoomingHook.exe O4 - HKLM..Run: [SmoothView] C:Program FilesTOSHIBATOSHIBA Zooming UtilitySmoothView.exe O4 - HKLM..Run: [Tvs] C:Program FilesToshibaTvsTvsTray.exe O4 - HKLM..Run: [TPNF] C:Program FilesTOSHIBATouchPadTPTray.exe O4 - HKLM..Run: [Pinger] c:toshibaivpismpinger.exe /run O4 - HKLM..Run: [TCtryIOHook] TCtrlIOHook.exe O4 - HKLM..Run: [TFncKy] TFncKy.exe O4 - HKLM..Run: [CFSServ.exe] CFSServ.exe -NoClient O4 - HKLM..Run: [IPHSend] C:Program FilesCommon FilesAOLIPHSendIPHSend.exe O4 - HKLM..Run: [SpamBlocker] C:Program FilesSpamBlockerUtilityBin4.8.0.0SbOEAddOn.exe O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe" O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe O4 - HKLM..Run: [MSKDetectorExe] C:Program FilesMcAfeeSpamKillerMSKDetct.exe /uninstall O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime O4 - HKLM..Run: [Malwarebytes Anti-Malware (reboot)] "C:Program FilesMalwarebytes' Anti-Malwarembam.exe" /runcleanupscript O4 - HKLM..Run: [sjsaqvtc] C:Documents and Settingskitty228Local SettingsApplication Datafrgwkvlsehsysguard.exe O4 - HKCU..Run: [TOSCDSPD] C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background O4 - HKCU..Run: [µTorrent] "C:Program Filesutorrentutorrent.exe" O4 - HKCU..Run: [sjsaqvtc] C:Documents and Settingskitty228Local SettingsApplication Datafrgwkvlsehsysguard.exe O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE O4 - Global Startup: RAMASST.lnk = C:WINDOWSsystem32RAMASST.exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:Documents and Settingskitty228Start MenuProgramsIMVURun IMVU.lnk (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7- f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
  • 4. O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2- BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe O10 - Unknown file in Winsock LSP: c:windowssystem32nwprovau.dll O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:WINDOWSsystem32acs.exe O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:Program FilesAdobePhotoshop Elements 5.0PhotoshopElementsFileAgent.exe O23 - Service: AntiPol (AntipPolice_) - Unknown owner - C:WINDOWSsvchast.exe (file missing) O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:Program FilesCommon FilesAOLTopSpeed2.0aoltsmon.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe O23 - Service: Bonjour Service - Apple Inc. - C:Program FilesBonjourmDNSResponder.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:Program FilesTOSHIBAConfigFreeCFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:WINDOWSsystem32DVDRAMSV.exe O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodbiniPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:Program FilesJavajre6binjqs.exe O23 - Service: ProtexisLicensing - Unknown owner - C:WINDOWSsystem32PSIService.exe O23 - Service: Swupdtmr - Unknown owner - c:TOSHIBAIVPswupdateswupdtmr.exe
  • 5. O23 - Service: TabletService - Wacom Technology, Corp. - C:WINDOWSsystem32Tablet.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:Program Files ViewpointCommonViewpointService.exe O24 - Desktop Component 0: (no name) - http://img457.imageshack.us/img457/8118/piratesofthecaribbeanwallpaper.gif O24 - Desktop Component 1: (no name) - http://img172.imageshack.us/img172/8118/piratesofthecaribbeanwallpaper.gif -- End of file - 9813 bytes