Here is the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 2:22:53 PM, on 6/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.cox.net/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Mixersel] C:\Program Files\Realtek\InstallShield\mixersel.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\xvlscaju.dll",realset
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
AVG Report here:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:06:02 PM 6/25/2007
+ Scan result:
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054453.dll -> Adware.Agent : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\offun.exe.vir -> Adware.Bagon : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054508.exe -> Adware.Bagon : Ignored.
C:\WINDOWS\system32\ascbalon.dll -> Adware.Balloon : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\cfg32.exe.vir -> Adware.BookedSpace : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\cfg32a.exe.vir -> Adware.BookedSpace : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\cfg32o.dll.vir -> Adware.BookedSpace : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\cfg32r.dll.vir -> Adware.BookedSpace : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\cfg32s.dll.vir -> Adware.BookedSpace : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\stub_mma2.exe.vir -> Adware.BookedSpace : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054500.exe -> Adware.BookedSpace : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054501.exe -> Adware.BookedSpace : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054505.exe -> Adware.BookedSpace : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054510.dll -> Adware.BookedSpace : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054511.dll -> Adware.BookedSpace : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054512.dll -> Adware.BookedSpace : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP169\A0054246.DLL -> Adware.FunWeb : Ignored.
HKLM\SOFTWARE\Classes\CLSID\{C1DF2728-8510-0773-96D8-5D0C1F27821B} -> Adware.Generic : Ignored.
HKLM\SOFTWARE\Classes\CLSID\{aed6f6a3-183c-488d-9f90-23db99f56e7f} -> Adware.Generic : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall6_38.exe.vir -> Adware.NewDotNet : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054502.exe -> Adware.NewDotNet : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\itpb_3.exe.vir -> Adware.Relevant : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054513.exe -> Adware.Relevant : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054387.exe -> Adware.RK : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054344.exe -> Adware.Rond : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054509.exe -> Adware.Softomate : Ignored.
C:\Program Files\Messenger\__delete_on_reboot__q_u_c_o_k_a_4_3_8_5_5_._d_l_l_ -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0055564.dll -> Adware.TTC : Ignored.
C:\WINDOWS\system32\mljjjkl.dll -> Adware.Virtumonde : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\system32\dwdsregt.exe.vir -> Adware.ZenoSearch : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054507.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\itpb_11.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\mldsrego.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\pwinmndt.exe -> Adware.ZenoSearch : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\retadpu1000106.exe.vir -> Downloader.Agent.bls : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\retadpu2000219.exe.vir -> Downloader.Agent.bls : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054503.exe -> Downloader.Agent.bls : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054504.exe -> Downloader.Agent.bls : Ignored.
C:\WINDOWS\system32\F3\wr620.exe -> Downloader.Agent.bls : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054340.exe -> Downloader.PurityScan : Ignored.
C:\WINDOWS\miroydaA.exe -> Downloader.VB.ang : Ignored.
C:\WINDOWS\system32\o02PrEz\o02PrEz1065.exe -> Downloader.VB.awj : Ignored.
C:\QooBox\Quarantine\C\WINDOWS\dls0523pmw.exe.vir -> Downloader.Zlob.bqw : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054515.exe -> Downloader.Zlob.bqw : Ignored.
C:\WINDOWS\system32\F4\wen2.exe -> Dropper.Agent.bfr : Ignored.
C:\WINDOWS\miroyda.exe -> Dropper.Agent.mu : Ignored.
C:\WINDOWS\system32\F1\bk53.exe -> Dropper.Agent.mu : Ignored.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FODN7D6A\acdt-pid67N[1].exe -> Hijacker.Small.jf : Ignored.
C:\QooBox\Quarantine\catchme2007-06-24_230559.75.zip/core.sys -> Rootkit.Agent.eq : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Adbrite : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Adbrite : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@adbrite[2].txt -> TrackingCookie.Adbrite : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.15:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wxcb54ct.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.16:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wxcb54ct.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.17:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wxcb54ct.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.18:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wxcb54ct.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt -> TrackingCookie.Advertising : Ignored.
:mozilla.19:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wxcb54ct.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@bfast[1].txt -> TrackingCookie.Bfast : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt -> TrackingCookie.Casalemedia : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Epilot : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[2].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> TrackingCookie.Questionmarket : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt -> TrackingCookie.Reliablestats : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@revsci[2].txt -> TrackingCookie.Revsci : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Ru4 : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Searchingbooth : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Serving-sys : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@specificclick[2].txt -> TrackingCookie.Specificclick : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Top-banners : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Ignored.
C:\Documents and Settings\Owner\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054484.exe -> Trojan.Agent.anr : Ignored.
C:\VundoFix Backups\sjcrppjv.exe.bad -> Trojan.Agent.anr : Ignored.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GH8Z4HG5\tob_snd_20070616[1] -> Trojan.Agent.aoy : Ignored.
C:\WINDOWS\system32\sdrgiwon.exe -> Trojan.Agent.aoy : Ignored.
C:\WINDOWS\system32\geplxss.dll -> Trojan.Dialer.cs : Ignored.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP170\A0054343.exe -> Trojan.Small.oa : Ignored.
::Report end
Sorry it took so lng to repost, fell asleep last night. An update to how my computer is running: I still get random popups. Some of them come up trying to re-install Winantivirus Pro but I've blocked all that. My computer still seems a little slower than usual..But everything else is running okay. Also random audio clips keep playing on my computer...It's freaking wierd..
Edited by crusader01, 25 June 2007 - 01:59 PM.