Scan saved at 10:57:25 AM, on 4/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\Explorer.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.compaq.com...DT/0409/bl7.asp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.javacools...m/sbupdate.html
F2 - REG:system.ini: Shell=Explorer.exe C:\Windows\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\Windows\Bolger.dll
O2 - BHO: (no name) - {4035A52E-F1CA-3C49-B1A1-685F56F6731F} - C:\Windows\system32\lrcjvhkm\icqygtpe.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {78F4ADE0-9879-2A73-5C23-E015AB720063} - C:\Windows\system32\lkgnrppl\sufwyxfe.dll
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\Windows\system32\nsyB1.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.ex
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.ex" -atboottime
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [PaciSoft] C:\Windows\System32\pacis.ex
O4 - HKLM\..\Run: [exp.exe] C:\Windows\System32\exp.ex
O4 - HKLM\..\Run: [WinTask driver] C:\Windows\System32\wintask.ex
O4 - HKLM\..\Run: [ohnhcrk] C:\Windows\System32\twarkmi\ohnhcrk.exe
O4 - HKLM\..\Run: [ewbrfsvp] C:\Windows\System32\wtrrxn\ewbrfsvp.ex
O4 - HKLM\..\Run: [nsbjlhrq] C:\Windows\System32\mxkrjfeu\nsbjlhrq.ex
O4 - HKLM\..\Run: [gbmkyv] C:\Windows\System32\bmuvkwxc\gbmkyv.ex
O4 - HKLM\..\Run: [txqxwven] C:\Windows\System32\pumlohx\txqxwven.exe
O4 - HKLM\..\Run: [jnavtutg] C:\Windows\System32\xdyrwe\jnavtutg.exe
O4 - HKLM\..\Run: [uyti] C:\Windows\System32\nbipphth\uyti.exe
O4 - HKLM\..\Run: [vgtd] C:\Windows\System32\jbxvd\vgtd.exe
O4 - HKLM\..\Run: [eyjghcg] C:\Windows\System32\cgpac\eyjghcg.exe
O4 - HKLM\..\Run: [yqnxays] C:\Windows\System32\jqtfs\yqnxays.exe
O4 - HKLM\..\Run: [cjviswag] C:\Windows\System32\pccvwpa\cjviswag.exe
O4 - HKLM\..\Run: [awneonxp] C:\Windows\system32\wnqdyowv\awneonxp.ex
O4 - HKLM\..\Run: [ebyw] C:\Windows\system32\jsikm\ebyw.ex
O4 - HKLM\..\Run: [rvtdunb] C:\Windows\system32\vjoxpqaq\rvtdunb.ex
O4 - HKLM\..\Run: [qdqaiqby] C:\Windows\System32\fkksb\qdqaiqby.exe
O4 - HKLM\..\Run: [forjcxgo] C:\Windows\system32\euchwhee\forjcxgo.exe
O4 - HKLM\..\Run: [siknbmjv] C:\Windows\system32\syxbbke\siknbmjv.ex
O4 - HKLM\..\Run: [aqkqspw] C:\Windows\system32\umghbsr\aqkqspw.ex
O4 - HKLM\..\Run: [nwwahhb] C:\Windows\system32\xkjnuni\nwwahhb.ex
O4 - HKLM\..\Run: [axcxg] C:\Windows\system32\cwmuhg\axcxg.ex
O4 - HKLM\..\Run: [jgld] C:\Windows\system32\ghlrtft\jgld.ex
O4 - HKLM\..\Run: [eqpras] C:\Windows\system32\remrv\eqpras.ex
O4 - HKLM\..\Run: [woysq] C:\Windows\system32\qrwwbo\woysq.exe
O4 - HKLM\..\Run: [bjfn] C:\Windows\system32\vvexmtnh\bjfn.exe
O4 - HKLM\..\Run: [jepfvu] C:\Windows\system32\lqgtop\jepfvu.exe
O4 - HKLM\..\Run: [vwiqahlw] C:\Windows\system32\rfdus\vwiqahlw.exe
O4 - HKLM\..\Run: [gxmprh] C:\Windows\system32\dhrmwf\gxmprh.exe
O4 - HKLM\..\Run: [ap9h4qmo] C:\Windows\system32\ap9h4qmo.exe
O4 - HKLM\..\Run: [njpxcyjd] C:\Windows\system32\kmsak\njpxcyjd.exe
O4 - HKLM\..\Run: [ocytxmwh] C:\Windows\system32\pqjm\ocytxmwh.exe
O4 - HKLM\..\Run: [cangyy] C:\Windows\system32\cyejexv\cangyy.exe
O4 - HKLM\..\Run: [SkyH2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\autiw.exe
O4 - HKLM\..\Run: [rbsh] C:\Windows\system32\mlbdpbbj\rbsh.exe
O4 - HKLM\..\Run: [vhylaurj] C:\Windows\system32\yrtgusb\vhylaurj.exe
O4 - HKLM\..\Run: [mxwgo] C:\Windows\system32\clhw\mxwgo.exe
O4 - HKLM\..\Run: [jbvk] C:\Windows\system32\slhib\jbvk.exe
O4 - HKLM\..\Run: [sxxef] C:\Windows\system32\cjdohce\sxxef.exe
O4 - HKLM\..\Run: [bxjcqkmu] C:\Windows\system32\xrfia\bxjcqkmu.exe
O4 - HKLM\..\Run: [hshnin] C:\DOCUME~1\seiverse\LOCALS~1\Temp\ssux.exe
O4 - HKLM\..\Run: [Nsv] C:\Windows\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\Windows\system32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [abasa5jrp] C:\Windows\system32\abasa5jrp.exe
O4 - HKLM\..\Run: [un2k3pV] gpugnt.exe
O4 - HKLM\..\Run: [qssr] C:\Windows\system32\nhytvqgd\qssr.exe
O4 - HKLM\..\Run: [eojlls] C:\Windows\system32\sdecjcj\eojlls.exe
O4 - HKLM\..\Run: [stgtnqt] C:\Windows\system32\ydssn\stgtnqt.exe
O4 - HKLM\..\Run: [irvji] C:\Windows\system32\hjgw\irvji.exe
O4 - HKLM\..\Run: [mqoukg] c:\windows\system32\xtipgld.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\Windows\Cpqdiag\CpqDfwAg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\ieSpell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\ieSpell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\ieSpell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\ieSpell.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtec...DjVuControl.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weat...porter.cab?RND=
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1113493352365
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai....23/cpbrkpie.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rpl.org
O17 - HKLM\Software\..\Telephony: DomainName = rpl.org
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = rpl.org
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rpl.org
O20 - Winlogon Notify: NavLogon - C:\Windows\System32\NavLogon.dll
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\COMPAQ\ACLIENT\ACLIENT.exe
O23 - Service: awneonxpwnqdyowv - Unknown owner - C:\Windows\system32\wnqdyowv\awneonxp.exe
O23 - Service: bjfnvvexmtnh - Unknown owner - C:\Windows\system32\vvexmtnh\bjfn.exe
O23 - Service: Compaq Local Alerter (CPQALERT) - Compaq Computer Corporation - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: Compaq Remote Diagnostics Enabling Agent (CpqDfwWebAgent) - Compaq Computer Corporation - C:\Windows\Cpqdiag\Cpqdfwag.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Compaq DMI Web Agent (cpqWebDmi) - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ebywjsikm - Unknown owner - C:\Windows\system32\jsikm\ebyw.exe
O23 - Service: htxhqwvcrkeh - Unknown owner - C:\Windows\System32\wvcrkeh\htxhq.exe
O23 - Service: ialwocfdcqc - Unknown owner - C:\Windows\System32\fdcqc\ialwoc.exe
O23 - Service: jepfvulqgtop - Unknown owner - C:\Windows\system32\lqgtop\jepfvu.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\Windows\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: poagesqskgqeu - Unknown owner - C:\Windows\System32\sqskgqeu\poage.exe
O23 - Service: qdqaiqbyfkksb - Unknown owner - C:\Windows\System32\fkksb\qdqaiqby.exe
O23 - Service: rvtdunbvjoxpqaq - Unknown owner - C:\Windows\system32\vjoxpqaq\rvtdunb.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\Windows\svcproc.exe
O23 - Service: uytinbipphth - Unknown owner - C:\Windows\System32\nbipphth\uyti.exe
O23 - Service: vgtdjbxvd - Unknown owner - C:\Windows\System32\jbxvd\vgtd.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
O23 - Service: yqnxaysjqtfs - Unknown owner - C:\Windows\System32\jqtfs\yqnxays.exe