Scan saved at 7:23:05 PM, on 4/14/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common
Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
A:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://red.clientapp.../ie/defaults/sb
/ymsgr/*http://www.yahoo.com/ext/search/search.html
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page = http://www.midco.net/
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://red.clientapp.../ie/defaults/sb
/ymsgr/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://red.clientapp.../ie/defaults/st
p/ymsgr*http://my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet
Explorer\SearchURL,(Default) =
http://red.clientapp.../ie/defaults/su
/ymsgr/*http://www.yahoo.com
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: UberButton Class -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class -
{65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program
Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: DPCUpdater Object -
{E291663A-2D6F-4B56-B9DF-AE239AEF6A5B} -
C:\WINDOWS\System32\mlljj.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio -
{8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv]
c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray]
C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [APD123]
C:\WINDOWS\System32\APD123.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program
Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AdwareAlert] C:\Program
Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKCU\..\Run: [Acme.PCHButton]
C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program
Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon] C:\WINDOWS\ctfmon.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program
Files\Real\RealPlayer\realplay.exe"
/RunUPGToolCommandReBoot
O8 - Extra context menu item: &AIM Search -
res://C:\Program Files\AIM
Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -
file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program
Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com -
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: RaptisoftGameLoader -
http://www.miniclip....isoftgameloader.
cab
O16 - DPF: Yahoo! Bingo -
http://download.game...ents/y/xt0_x.ca
b
O16 - DPF: Yahoo! Blackjack -
http://download.game...ents/y/jt0_x.ca
b
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg...at/applet/c381/
chat.cab
O16 - DPF: Yahoo! Dominoes -
http://download.game...ents/y/dot8_x.c
ab
O16 - DPF: Yahoo! Gin -
http://download.game...ents/y/nt1_x.ca
b
O16 - DPF: Yahoo! Hearts -
http://download.game...ents/y/ht1_x.ca
b
O16 - DPF: Yahoo! Pinochle -
http://download.game...ents/y/ut2_x.ca
b
O16 - DPF: Yahoo! Pool 2 -
http://download.game...ents/y/pote_x.c
ab
O16 - DPF: Yahoo! Spades -
http://download.game...ents/y/st2_x.ca
b
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C}
(Checkers Class) -
http://messenger.zon...ry/msgrchkr.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3}
(StagingUI Object) -
http://zone.msn.com/...gingUI.cab34120.
cab
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9}
(PlxInstall Class) -
https://www.plaxo.co...laxoInstall.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B}
(Minesweeper Flags Class) -
http://messenger.zon...MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.syma...Content/vc/bin/
AvSniff.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8}
(ZoneBuddy Class) -
http://zone.msn.com/...dy.cab32846.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z....e.com/iTunes4/W
W/win/019-0312.20050111.MmVrT/iTunesSetup.exe
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5
Class) -
http://www102.coolsa...oad/cscmv5X.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE
Class) -
http://software-dl.r...6b18205/netzip/
RdxIE601.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3}
(ZonePAChat Object) -
http://zone.msn.com/...hat.cab32846.ca
b
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akama...530/qtinstall.i
nfo.apple.com/abarth/us/win/QuickTimeInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
(Symantec RuFSI Utility Class) -
http://security.syma...Content/common/
bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
(ExentInf Class) -
http://us.games2.yim...yahoo.com/games
/play/client/exentctl_0_0_0_1.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
(MUWebControl Class) -
http://update.micros...te/v6/V5Control
s/en/x86/client/muweb_site.cab?1144899420499
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE}
(Housecall ActiveX 6.5) -
http://housecall65.t...ll/applet/html/
native/x86/win32/activex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}
(HouseCall Control) -
http://a840.g.akamai...61001/housecall.
trendmicro.com/housecall/xscan53.cab
O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72}
(SystemInfo Class) -
http://getdway.com/d.../dpcsysinfo.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA}
(Sinstaller Class) -
http://dm.screensave...si/1/sinstaller
.cab
O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C}
(CWDL_DownLoadControl Class) -
http://www.callwave....DL_DownLoad.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
(MessengerStatsClient Class) -
http://messenger.zon...engerStatsClien
t.cab
O16 - DPF: {936BB7EE-A1F4-11D5-A27B-0050BA8FE0FD}
(Xstream Media) -
http://www.emc.kquni...rse/Xstream.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C}
(cpbrkpie Control) -
http://a19.g.akamai....p.coupons.com/v
3121/cpbrkpie.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D}
(CRAVOnline Object) -
http://www.ravantivi...n/ravonline.cab
O16 - DPF: {A7196C8E-35A5-4FF0-9E46-E28918B5CAF6}
(GINDOMINO Class) -
http://66.98.132.156...no_2_0_0_19.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542}
(CBSTIEPrint Class) -
http://offers.bright...oad/bin/actxcab.
cab
O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B}
(Download Class) -
http://expressit.bro...in/Download.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
(ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872}
(cpbrxpie Control) -
http://a19.g.akamai....p.coupons.com/r
3120/cpbrxpie.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0}
(CBankshotZoneCtrl Class) -
http://zone.msn.com/...pool.cab36107.c
ab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -
http://ax.phobos.app...detection/ITDet
ector.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937}
(StadiumProxy Class) -
http://zone.msn.com/...oxy.cab35645.ca
b
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF}
(Solitaire Showdown Class) -
http://messenger.zon...taireShowdown.c
ab
O20 - Winlogon Notify: mlljj -
C:\WINDOWS\System32\mlljj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) -
GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) -
GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) -
NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe