Logfile of HijackThis v1.99.1 Scan saved at 11:21:57 AM, on 8/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\mnmsrvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\MSTMON_S.EXE C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\PELMICED.EXE C:\WINDOWS\System32\??chost.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url="http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html"]http://red.clientapps.yahoo.com/customize/.../search/ie.html[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url] R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.comcast.net/"]http://www.comcast.net/[/url] R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\WINDOWS\system32\MSTMON_S.EXE STARTUP O4 - HKLM\..\Run: [ptrun32] C:\WINDOWS\system32\ptrun32\ptrun32.exe -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE O4 - HKLM\..\Run: [ccCap] "c:\Program Files\WinCap\svehost.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0 O4 - HKLM\..\RunOnce: [FinishSPRT] "C:\DOCUME~1\Denise\LOCALS~1\Temp\SPR1504.EXE" /clientpath "C:\Program Files\Support.com" /profilepath "C:\Documents and Settings\All Users\Application Data\Support.com\profiles" O4 - HKCU\..\Run: [Yowe] C:\WINDOWS\System32\??chost.exe O4 - HKCU\..\Run: [PTRUN32] C:\WINDOWS\system32\ptrun32\ptr32w.exe O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: (no name) - {629C5DAA-BABC-4d44-983D-97AFF415621C} - file://C:\Program Files\BoxTopsShoppingReminder\System\Temp\boxtopgmills_script0.htm (file missing) (HKCU) O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU) O11 - Options group: [INTERNATIONAL] International* O16 - DPF: World Class Solitaire by pogo - [url="http://game1.pogo.com/applet-8.0.5.30/worldclass/worldclass-en_US.cab"]http://game1.pogo.com/applet-8.0.5.30/worl...class-en_US.cab[/url] O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - [url="http://www.worldwinner.com/games/v46/scrabblecubes/scrabblecubes.cab"]http://www.worldwinner.com/games/v46/scrab...rabblecubes.cab[/url] O16 - DPF: {04063354-A10E-4427-A1EC-F3CC81587BC6} (Mines Control) - [url="http://www.worldwinner.com/games/v41/mines/mines.cab"]http://www.worldwinner.com/games/v41/mines/mines.cab[/url] O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam Control) - [url="http://www.worldwinner.com/games/v47/skillgam/skillgam.cab"]http://www.worldwinner.com/games/v47/skillgam/skillgam.cab[/url] O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - [url="http://www.worldwinner.com/games/v46/shared/FunGamesLoader.cab"]http://www.worldwinner.com/games/v46/share...GamesLoader.cab[/url] O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - [url="http://www.worldwinner.com/games/v48/brickout/brickout.cab"]http://www.worldwinner.com/games/v48/brickout/brickout.cab[/url] O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - [url="http://aolcom.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB"]http://aolcom.pogo.com/cdl/launcher/PogoWe...erInstaller.CAB[/url] O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - [url="http://www.worldwinner.com/games/v50/pool/pool.cab"]http://www.worldwinner.com/games/v50/pool/pool.cab[/url] O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - [url="http://photos.walmart.com/WalmartActivia.cab"]http://photos.walmart.com/WalmartActivia.cab[/url] O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - [url="http://www.worldwinner.com/games/v43/jigsaw/jigsaw.cab"]http://www.worldwinner.com/games/v43/jigsaw/jigsaw.cab[/url] O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - [url="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-30.cab"]http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-30.cab[/url] O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - [url="http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab"]http://www.windowsvistatestdrive.com/Activ...iveXClient1.cab[/url] O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - [url="http://www.worldwinner.com/games/v57/bjattack/bja.cab"]http://www.worldwinner.com/games/v57/bjattack/bja.cab[/url] O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - [url="http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab"]http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab[/url] O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - [url="http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab"]http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab[/url] O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - [url="http://www.worldwinner.com/games/v41/freecell/freecell.cab"]http://www.worldwinner.com/games/v41/freecell/freecell.cab[/url] O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - [url="https://mail.stainlesscenter.net/Remote/msrdp.cab"]https://mail.stainlesscenter.net/Remote/msrdp.cab[/url] O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - [url="http://www.worldwinner.com/games/shared/wwlaunch.cab"]http://www.worldwinner.com/games/shared/wwlaunch.cab[/url] O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - [url="http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab"]http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab[/url] O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - [url="http://a19.g.akamai.net/7/19/7125/1452/ftp.coupons.com/r3302/cpbrkpie.cab"]http://a19.g.akamai.net/7/19/7125/1452/ftp...02/cpbrkpie.cab[/url] O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - [url="http://www.worldwinner.com/games/v57/cubis/cubis.cab"]http://www.worldwinner.com/games/v57/cubis/cubis.cab[/url] O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - [url="http://www.worldwinner.com/games/v46/sol/sol.cab"]http://www.worldwinner.com/games/v46/sol/sol.cab[/url] O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - [url="http://www.worldwinner.com/games/v49/luxor/luxor.cab"]http://www.worldwinner.com/games/v49/luxor/luxor.cab[/url] O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - [url="http://www.worldwinner.com/games/v67/swapit/swapit.cab"]http://www.worldwinner.com/games/v67/swapit/swapit.cab[/url] O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - [url="http://www.worldwinner.com/games/v41/hangman/hangman.cab"]http://www.worldwinner.com/games/v41/hangman/hangman.cab[/url] O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - [url="http://www.worldwinner.com/games/v42/tilecity/tilecity.cab"]http://www.worldwinner.com/games/v42/tilecity/tilecity.cab[/url] O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - [url="http://www.worldwinner.com/games/v45/royal/royal.cab"]http://www.worldwinner.com/games/v45/royal/royal.cab[/url] O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - [url="http://www.worldwinner.com/games/v43/paint/paint.cab"]http://www.worldwinner.com/games/v43/paint/paint.cab[/url] O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - [url="http://www.worldwinner.com/games/v44/golfsol/golfsol.cab"]http://www.worldwinner.com/games/v44/golfsol/golfsol.cab[/url] O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - [url="http://www.worldwinner.com/games/v47/wwspades/wwspades.cab"]http://www.worldwinner.com/games/v47/wwspades/wwspades.cab[/url] O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - [url="http://by131fd.bay131.hotmail.msn.com/activex/HMAtchmt.ocx"]http://by131fd.bay131.hotmail.msn.com/activex/HMAtchmt.ocx[/url] O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)