HiJackThis LOG:[COLOR=red]
Logfile of HijackThis v1.99.0
Scan saved at 10:55:53 AM, on 04/02/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Master\My Documents\download\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DataCaching] C:\PROGRA~1\DATACA~1\FLashKsk.exe
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe -onreboot
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitekjw32.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
O4 - HKCU\..\Run: [bDx6Rgeng] prifil32.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.bangthumbs.com
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Ad-Aware SE LOG:[COLOR=red]
TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=IECache Entry : Cookie:[email protected]/
obj[1]=IECache Entry : Cookie:[email protected]/
obj[2]=IECache Entry : Cookie:[email protected]/
obj[3]=IECache Entry : Cookie:[email protected]/
obj[4]=IECache Entry : Cookie:[email protected]/
obj[5]=IECache Entry : Cookie:[email protected]/
obj[6]=IECache Entry : Cookie:[email protected]/
obj[7]=IECache Entry : Cookie:[email protected]/
obj[8]=IECache Entry : Cookie:[email protected]/
obj[9]=IECache Entry : Cookie:[email protected]/
obj[10]=IECache Entry : Cookie:[email protected]/
obj[11]=IECache Entry : Cookie:[email protected]/
obj[12]=IECache Entry : Cookie:[email protected]/
obj[13]=IECache Entry : Cookie:[email protected]/
obj[14]=IECache Entry : Cookie:[email protected]/
obj[15]=IECache Entry : Cookie:[email protected]/
obj[16]=IECache Entry : Cookie:[email protected]/
MAINPEAN DIALER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[17]=Regkey : S-1-5-21-573932041-814398359-559015469-1006\software\microsoft\windows\currentversion\explorer\menuorder\start menu2\programs\- clevercrackers -
EZULA
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[18]=Regkey : software\microsoft\downloadmanager
obj[62]=File : C:\WINDOWS\system32\xcite2.exe
ELITUM.ELITEBARBHO
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[19]=Regkey : clsid\{be8d0059-d24d-4919-b76f-99f4a2203647}
obj[20]=RegValue : clsid\{be8d0059-d24d-4919-b76f-99f4a2203647} ""
obj[21]=Regkey : clsid\{0a1d22c3-37be-470c-9c29-e3074ee0574b}
obj[22]=RegValue : S-1-5-21-573932041-814398359-559015469-1006\software\microsoft\internet explorer\toolbar\webbrowser "{825CF5BD-8862-4430-B771-0C15C5CA8DEF}"
obj[23]=Regkey : software\lq
obj[24]=RegValue : software\lq "U"
obj[25]=RegValue : software\lq "ohb_ie_plugin"
obj[26]=RegValue : software\lq "AD"
obj[27]=RegValue : software\lq "AC"
obj[28]=RegValue : software\lq "TM"
obj[29]=RegValue : software\lq "I"
obj[30]=RegValue : software\lq "AT"
obj[31]=RegValue : software\lq "AM"
obj[32]=RegValue : software\lq "TR"
obj[33]=RegValue : software\lq "country"
obj[34]=RegValue : software\lq "city"
obj[35]=RegValue : software\lq "state"
obj[36]=RegValue : software\lq "RX"
obj[37]=RegValue : software\lq "RX2.8"
obj[38]=RegValue : software\lq "RX2.9"
obj[39]=RegValue : software\lq "RX3.0"
obj[40]=RegValue : software\lq "RX3.1"
obj[41]=RegValue : software\lq "RX3.2"
obj[42]=RegValue : software\lq "RX3.3"
obj[43]=RegValue : software\lq "FU3.4"
obj[44]=RegValue : software\lq "FU3.5"
EBATES MONEYMAKER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[45]=RegValue : S-1-5-21-573932041-814398359-559015469-1006\software\lq "AC"
SAHAGENT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[46]=File : C:\WINDOWS\system32\shagentnew.dll
obj[47]=File : C:\WINDOWS\system32\sahagent1006.exe
obj[48]=File : C:\WINDOWS\system32\sahagent1021.exe
POSSIBLE BROWSER HIJACK ATTEMPT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[49]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Online Casinos.url
obj[50]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Sport Betting.url
obj[51]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Sportsbooks.url
obj[52]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Online Betting.url
obj[53]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Blackjack.url
obj[54]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Baccarat.url
obj[55]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Online Gaming.url
obj[56]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Poker.url
obj[57]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Bingo.url
obj[58]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Horse Racing.url
obj[59]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Slot Machines.url
obj[60]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Betting.url
obj[61]=File : C:\Documents and Settings\Master\Favorites\Casino & Carrers\Roulette.url