Logfile of HijackThis v1.99.0 Scan saved at 1:34:21 PM, on 10/18/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\LEXBCES.EXE C:\WINNT\system32\spoolsv.exe C:\WINNT\system32\LEXPPS.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINNT\Explorer.EXE C:\WINNT\system32\RUNDLL32.EXE C:\WINNT\system32\carpserv.exe C:\Program Files\Support.com\bin\tgcmd.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE C:\Program Files\WinZip\WZQKPICK.EXE C:\Documents and Settings\home1\Desktop\HijackThis.exe C:\WINNT\system32\wuauclt.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://thesims2.ea.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing) O2 - BHO: (no name) - {911C4A8E-0F75-4B83-BEB9-02BDDF29D11E} - (no file) O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: (no name) - {28BC2EC4-5EAD-45E1-9F9F-82CD5E293601} - (no file) O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\\NeroCheck.exe O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [AdBlocker] C:\Program Files\3B Software\3B Ad Blocker Pro\AdBlocker.exe O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.1.4.29/aces/aces-ob-assets.cab O16 - DPF: Ali Baba Slots TM by pogo - http://game1.pogo.com/applet-6.3.0.53/slots/alibaba-ob-assets.cab O16 - DPF: Animal Ark by pogo - http://playweb08.pogo.com/applet-6.1.5.28/animal/animal-ob-assets.cab O16 - DPF: Armored Attack by pogo - http://game1.pogo.com/applet-6.3.4.49/cctank/cctank-ob-assets.cab O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.1.4.29/backgammon/backgammon-ob-assets.cab O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.3.4.49/battlephlinx/battlephlinx-ob-assets.cab O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.46/blackjack/blackjack-ob-assets.cab O16 - DPF: Bump by pogo - http://eaweb01.pogo.com/applet-6.1.5.28/bump/bump-ob-assets.cab O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.1.5.28/checkers2/checkers-ob-assets.cab O16 - DPF: Chess by pogo - http://game1.pogo.com/applet-6.1.5.21/chess2/chess2-ob-assets.cab O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.3.0.46/checkeredflag/checkeredflag-ob-assets.cab O16 - DPF: Dominoes by pogo - http://game1.pogo.com/applet-6.2.1.34/domino/domino-ob-assets.cab O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.1.5.28/euchre/euchre-ob-assets.cab O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.2.0.30/solitaire2/solitaire2-ob-assets.cab O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.1.5.28/superbingo/superbingo-ob-assets.cab O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.1.5.28/greenback/greenback-ob-assets.cab O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.1.5.28/harvest/harvest-ob-assets.cab O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.2.5.28/hearts/hearts-ob-assets.cab O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.1.4.29/drawpoker/drawpoker-ob-assets.cab O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.3.4.49/pool2/pool-ob-assets.cab O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.1.4.29/jigsaw/jigsaw-ob-assets.cab O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.2.1.27/gin/gin-ob-assets.cab O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.3.0.46/lottso/lottso-ob-assets.cab O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.1.4.29/mahjong/mahjong-ob-assets.cab O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.2.1.41/mlslots/mlslots-ob-assets.cab O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.2.1.34/paigow/paigow-ob-assets.cab O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.4.0.41/penguins/penguins-ob-assets.cab O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/applet-6.3.0.46/waterwheel/waterwheel-ob-assets.cab O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.3.0.46/flinger/flinger-ob-assets.cab O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.1.5.28/pinochle/pinochle-ob-assets.cab O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.com/applet-6.2.3.39/piratesgold/piratesgold-ob-assets.cab O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.3.0.46/popfu/popfu-ob-assets.cab O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.3.0.46/poppazoppa/poppazoppa-ob-assets.cab O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.4.0.34/poppit2/poppit2-ob-assets.cab O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.4.0.41/squares/squares-ob-assets.cab O16 - DPF: SciFi Slots by pogo - http://game1.pogo.com/applet-6.2.1.34/slots/scifi-ob-assets.cab O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.3.0.53/slots/showbiz2-ob-assets.cab O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.com/applet-6.2.0.37/slots/showbiz-ob-assets.cab O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.3.0.53/spades/spades-ob-assets.cab O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.3.1.26/spider/spider-ob-assets.cab O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.4.0.41/squelchies/squelchies-ob-assets.cab O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.1.5.28/sweettooth/sweettooth-ob-assets.cab O16 - DPF: Tank Hunter by pogo - http://www.pogo.com/applet-6.3.4.49/tank/tank-ob-assets.cab O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.3.1.26/holdem/holdem-ob-assets.cab O16 - DPF: The Sims Pinball by pogo - http://game1.pogo.com/applet-6.1.5.21/simball/simball-ob-assets.cab O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.3.0.46/peaks/peaks-ob-assets.cab O16 - DPF: Tube Runner by pogo - http://eaweb02.pogo.com/applet-6.1.5.28/tube/tube-ob-assets.cab O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.3.1.26/jumbee/jumbee-ob-assets.cab O16 - DPF: Vert Skater by pogo - http://game1.pogo.com/applet-6.1.5.28/vertskater/vertskater-ob-assets.cab O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.3.0.46/whackdown/whackdown-ob-assets.cab O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab O16 - DPF: {15589FA1-C456-11CE-BF01-000000000000} - http://www.errornuker.com/products/errn2004/installers/default/ErrorNukerInstaller.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdqcpc/downloads/msxml4.cab O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://www.earthlink.net/i/store/SymDlBrg.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://playweb05.pogo.com/game/deluxe/insaniquarium/popcaploader_v6.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4587/mcfscan.cab O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec Licensing Detect Internet Connection - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe