Logfile of HijackThis v1.99.1
Scan saved at 8:20:17 PM, on 4/4/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\Fast.exe
C:\WINDOWS\Explorer.EXE
D:\MsgPlus.exe
C:\WINDOWS\System32\Sjb.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Real\RealPlayer\realplay.exe
D:\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\mpomp\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapp...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\mpomp\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.102:110
R3 - Default URLSearchHook is missing
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C1567E5F-072D-4FEC-8F6D-3338A6EFACDA} - C:\WINDOWS\System32\ckmg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_2_3_0.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "D:\\MsgPlus.exe"
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\System32\Services\{F5471D14-75DC-43D5-A00B-9085A0A3EE51}\SVCHOST.EXE
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Csp] C:\WINDOWS\Vtf.exe
O4 - HKLM\..\Run: [Lru] C:\WINDOWS\Rud.exe
O4 - HKLM\..\Run: [Nrj] C:\WINDOWS\System32\Arc.exe
O4 - HKLM\..\Run: [Brl] C:\WINDOWS\System32\Som.exe
O4 - HKLM\..\Run: [Ddp] C:\WINDOWS\Cnf.exe
O4 - HKLM\..\Run: [Vth] C:\WINDOWS\Jab.exe
O4 - HKLM\..\Run: [Pda] C:\WINDOWS\Sde.exe
O4 - HKLM\..\Run: [Pmp] C:\WINDOWS\System32\Sjb.exe
O4 - HKLM\..\Run: [Jlg] C:\WINDOWS\Hmd.exe
O4 - HKLM\..\Run: [Ofc] C:\WINDOWS\Mrs.exe
O4 - HKLM\..\Run: [Ofk] C:\WINDOWS\System32\Bpp.exe
O4 - HKLM\..\Run: [Disk Keeper] C:\DOCUME~1\mpomp\LOCALS~1\Temp\keep.exe
O4 - HKLM\..\Run: [Nra] C:\WINDOWS\Jpf.exe
O4 - HKLM\..\Run: [Nmt] C:\WINDOWS\System32\Jti.exe
O4 - HKLM\..\Run: [Dnd] C:\WINDOWS\System32\Abl.exe
O4 - HKLM\..\Run: [Upj] C:\WINDOWS\Ake.exe
O4 - HKLM\..\Run: [Als] C:\WINDOWS\Kke.exe
O4 - HKLM\..\Run: [Jqa] C:\WINDOWS\System32\Igd.exe
O4 - HKLM\..\Run: [Idq] C:\WINDOWS\System32\Ect.exe
O4 - HKLM\..\Run: [Ltd] C:\WINDOWS\System32\Viq.exe
O4 - HKLM\..\Run: [Fdg] C:\WINDOWS\Epc.exe
O4 - HKLM\..\Run: [Muu] C:\WINDOWS\System32\Edq.exe
O4 - HKLM\..\Run: [Qna] C:\WINDOWS\Uli.exe
O4 - HKLM\..\Run: [Tkk] C:\WINDOWS\System32\Ndi.exe
O4 - HKLM\..\Run: [Dre] C:\WINDOWS\System32\Laa.exe
O4 - HKLM\..\Run: [Cgi] C:\WINDOWS\System32\Lbf.exe
O4 - HKLM\..\Run: [Mfe] C:\WINDOWS\System32\Uhg.exe
O4 - HKLM\..\Run: [Sjt] C:\WINDOWS\System32\Evo.exe
O4 - HKLM\..\Run: [Qdc] C:\WINDOWS\System32\Nan.exe
O4 - HKLM\..\Run: [Kda] C:\WINDOWS\Utc.exe
O4 - HKLM\..\Run: [Bln] C:\WINDOWS\Kkg.exe
O4 - HKLM\..\Run: [Akl] C:\WINDOWS\System32\Eni.exe
O4 - HKLM\..\Run: [Tud] C:\WINDOWS\System32\Jsg.exe
O4 - HKLM\..\Run: [Gpm] C:\WINDOWS\System32\Qds.exe
O4 - HKLM\..\Run: [Ill] C:\WINDOWS\Gml.exe
O4 - HKLM\..\Run: [Jrs] C:\WINDOWS\System32\Anp.exe
O4 - HKLM\..\Run: [Ams] C:\WINDOWS\Cdn.exe
O4 - HKLM\..\Run: [Mcs] C:\WINDOWS\Fpa.exe
O4 - HKLM\..\Run: [Ief] C:\WINDOWS\Qgi.exe
O4 - HKLM\..\Run: [Tqc] C:\WINDOWS\System32\Jua.exe
O4 - HKLM\..\Run: [Lfk] C:\WINDOWS\System32\Ucl.exe
O4 - HKLM\..\Run: [Qiq] C:\WINDOWS\System32\Adm.exe
O4 - HKLM\..\Run: [Iqq] C:\WINDOWS\Ieh.exe
O4 - HKLM\..\Run: [Jsn] C:\WINDOWS\System32\Vvl.exe
O4 - HKLM\..\Run: [Hip] C:\WINDOWS\Amq.exe
O4 - HKLM\..\Run: [Bim] C:\WINDOWS\System32\Kpu.exe
O4 - HKLM\..\Run: [Qfj] C:\WINDOWS\Tdo.exe
O4 - HKLM\..\Run: [Ksq] C:\WINDOWS\Vtv.exe
O4 - HKLM\..\Run: [Tld] C:\WINDOWS\Ddb.exe
O4 - HKLM\..\Run: [Bls] C:\WINDOWS\System32\Nsb.exe
O4 - HKLM\..\Run: [Uik] C:\WINDOWS\Dco.exe
O4 - HKLM\..\Run: [Lhq] C:\WINDOWS\Ior.exe
O4 - HKLM\..\Run: [Uek] C:\WINDOWS\Ikf.exe
O4 - HKLM\..\Run: [Bgi] C:\WINDOWS\System32\Shh.exe
O4 - HKLM\..\Run: [Abt] C:\WINDOWS\Ahb.exe
O4 - HKLM\..\Run: [Bmj] C:\WINDOWS\System32\Cro.exe
O4 - HKLM\..\Run: [Edd] C:\WINDOWS\Deq.exe
O4 - HKLM\..\Run: [Ccj] C:\WINDOWS\System32\Uad.exe
O4 - HKLM\..\Run: [Bbp] C:\WINDOWS\Qnf.exe
O4 - HKLM\..\Run: [Fnn] C:\WINDOWS\System32\Tfq.exe
O4 - HKLM\..\Run: [Gop] C:\WINDOWS\Rbl.exe
O4 - HKLM\..\Run: [Hqc] C:\WINDOWS\System32\Lkg.exe
O4 - HKLM\..\Run: [Srn] C:\WINDOWS\System32\Nkp.exe
O4 - HKLM\..\Run: [Kjr] C:\WINDOWS\Tvu.exe
O4 - HKLM\..\Run: [Fag] C:\WINDOWS\System32\Jlj.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\mpomp\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\Run: [Ken] C:\WINDOWS\System32\Ngc.exe
O4 - HKLM\..\Run: [Aat] C:\WINDOWS\System32\Uef.exe
O4 - HKLM\..\Run: [Vqa] C:\WINDOWS\System32\Vte.exe
O4 - HKLM\..\Run: [Nhp] C:\WINDOWS\System32\Ois.exe
O4 - HKLM\..\Run: [Ers] C:\WINDOWS\Net.exe
O4 - HKLM\..\Run: [Rpm] C:\WINDOWS\System32\Csa.exe
O4 - HKLM\..\Run: [Tae] C:\WINDOWS\Npm.exe
O4 - HKLM\..\Run: [Vss] C:\WINDOWS\Igq.exe
O4 - HKLM\..\RunServices: [ntddetect] C:\WINDOWS\System32\ntddetect.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.iframedollars.biz
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted IP range: 213.159.117.202
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...ry/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip....pGameLoader.dll
O16 - DPF: {2CDA4FA9-4A2B-4925-8EB4-61BDDE935A84} (OutlookVerification.vOutlook) - http://www.rogershel...tp/voutlook.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16....es/MsnPUpld.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yim...ctl_0_0_0_0.ocx
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.14...tiveXImgCtl.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! WebCam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8842C6C0-E428-11D5-A74F-0008C7DA2EA8} (prjRogersMail.ctlMail) - http://www.rogershelp.com/addemail.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensave.../sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installen...gine/isetup.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.c.../ymmapi_416.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FC} (PCUploader Class) - http://www.walmartph...x/PCAXSetup.cab?
O18 - Filter: text/html - {53942938-06C0-42EC-BABA-ED6066F3C03C} - C:\WINDOWS\System32\ckmg.dll
O18 - Filter: text/plain - {53942938-06C0-42EC-BABA-ED6066F3C03C} - C:\WINDOWS\System32\ckmg.dll
O20 - Winlogon Notify: drct16 - drct16.dll (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe