help
its been patched, running nav all are updated.
so here is my log.
Logfile of HijackThis v1.99.1
Scan saved at 12:07:32 PM, on 3/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: US Class - {1FFED2CB-FC98-49f8-B3D0-678D03350F1E} - C:\WINNT\mscore.dll
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINNT\dlmax.dll
O2 - BHO: Band Class - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - C:\WINNT\enhtb.dll (file missing)
O2 - BHO: RsyncHlpr Class - {16B238D5-80DE-47CE-8F17-B3ECE2C2248D} - C:\WINNT\system32\rsyncmon.dll
O2 - BHO: (no name) - {3669C32C-3ACC-42A3-98E1-5FE0C25274C8} - C:\Program Files\wmguwnvt\wmguwnvt.dll (file missing)
O2 - BHO: (no name) - {3F9FB0CE-349E-745B-D6B8-B1E1C8D881F9} - C:\WINNT\system32\mecowwqe\jqsqjgnp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {D48A68EC-52FD-4018-8BAD-7944D863516A} - C:\Program Files\wmguwnvt\wmguwnvt.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [ptugnsl] c:\winnt\system32\ptugnsl.exe
O4 - HKLM\..\Run: [wmguwnvt] C:\Program Files\wmguwnvt\wmguwnvt.exe
O4 - HKLM\..\Run: [icgbm] C:\WINNT\system32\bkufmt\icgbm.exe
O4 - HKLM\..\Run: [erqnj] C:\WINNT\system32\rarua\erqnj.exe
O4 - HKLM\..\Run: [udfsjys] C:\WINNT\system32\bfgthya\udfsjys.exe
O4 - HKLM\..\Run: [qycksvo] C:\WINNT\system32\fbknw\qycksvo.exe
O4 - HKLM\..\Run: [App32dll] C:\winnt\system32\msnavc32.exe lee0105
O4 - HKLM\..\Run: [RSync] C:\WINNT\system32\netsync.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINNT\SysCheckBop32
O4 - HKLM\..\Run: [Desktop Search] C:\WINNT\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINNT\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [jsjjv] C:\WINNT\system32\ldmcm\jsjjv.exe
O4 - HKLM\..\Run: [urvu] C:\WINNT\system32\uoaealk\urvu.exe
O4 - HKLM\..\Run: [judgx] C:\WINNT\system32\vpty\judgx.exe
O4 - HKLM\..\Run: [jjuy] C:\WINNT\system32\iuptlh\jjuy.exe
O4 - HKLM\..\Run: [qgcxaxgo] C:\WINNT\system32\mwkev\qgcxaxgo.exe
O4 - HKLM\..\Run: [vkhgc] C:\WINNT\system32\qlegxv\vkhgc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [tudtbfv] C:\WINNT\system32\ueuawkt\tudtbfv.exe
O4 - HKLM\..\Run: [nmcyycp] C:\WINNT\system32\ofwvx\nmcyycp.exe
O4 - HKLM\..\Run: [Makarzy] C:\WINNT\nyei.exe
O4 - HKLM\..\Run: [antiware] C:\winnt\system32\elitesav32.exe
O4 - HKLM\..\Run: [skyhn] C:\WINNT\system32\dmvlite.exe
O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [47sR3pS] ippsevt.exe
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Open Client to Monitor &1 - C:\WINNT\web\AOpenClient.htm
O8 - Extra context menu item: Open Client to Monitor &2 - C:\WINNT\web\AOpenClient.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DFC75FB-2F65-4B87-879A-EBA9456DE5C4}: NameServer = 213.139.147.15,198.6.1.122,216.139.128.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{1DFC75FB-2F65-4B87-879A-EBA9456DE5C4}: NameServer = 213.139.147.15,198.6.1.122,216.139.128.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{1DFC75FB-2F65-4B87-879A-EBA9456DE5C4}: NameServer = 213.139.147.15,198.6.1.122,216.139.128.3
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: CWShredder Service - InterMute, Inc. - C:\Documents and Settings\Administrator\Desktop\CWShredder.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\system32\mgabg.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\NavNT\rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe