Logfile of HijackThis v1.99.1
Scan saved at 9:34:35 AM, on 5/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\iRiver\Service\Updater.exe
C:\WINDOWS\sys3236.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\init32m.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Netscape\Netscape Browser\netscape.exe
C:\Documents and Settings\Dave\Desktop\antivirus stuff\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe init32m.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: FlashEnhancer Extnder - {A749B4BC-7621-4a80-9220-D0A283367DD5} - c:\Program Files\Fln\fln.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\Service\Updater.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [vdcjaeg] c:\windows\xuwcvdb.exe
O4 - HKCU\..\Run: [sys3236] C:\WINDOWS\sys3236.exe
O4 - HKCU\..\Run: [nngntnq] c:\windows\xuwcvdb.exe
O4 - HKCU\..\Run: [sudviug] c:\windows\xuwcvdb.exe
O4 - HKCU\..\Run: [kbenvkb] c:\windows\xuwcvdb.exe
O4 - HKCU\..\Run: [xeqssld] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [ibqtqrh] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [mwmgarr] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [slfkfon] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [cfiacgv] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [iioeohf] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [qvnaslj] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [cfspvaw] c:\windows\tlawqvr.exe
O4 - HKCU\..\Run: [trrpqqw] c:\windows\twmrvye.exe
O4 - HKCU\..\Run: [yauwgdu] c:\windows\itvjscq.exe
O4 - HKCU\..\Run: [tmlgfbp] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [jsqnqsl] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [qeweepx] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [cgmxpnp] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [cegbjhk] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [loudhkc] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [latywsa] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [cxnnobx] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [bfydyfl] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [qijcjkb] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [iycoqgp] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [klqihlo] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [bcuoohh] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [hvmlokr] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [indkbol] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [irymknr] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [hjovkco] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [ieanjud] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [rtceyln] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [trivpns] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [ivppsxn] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [hyqorgg] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [iumrfom] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [cllrkor] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [ybcrqgv] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [xuyylaa] c:\windows\dgmdkuk.exe
O4 - HKCU\..\Run: [qmqfwat] c:\windows\glmngbn.exe
O4 - HKCU\..\Run: [hvpqkrk] c:\windows\glmngbn.exe
O4 - HKCU\..\Run: [jmnsatt] c:\windows\glmngbn.exe
O4 - HKCU\..\Run: [djethmm] c:\windows\glmngbn.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {61790D8F-B8D1-4200-8F89-4C566F77BC7C} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {61790D8F-B8D1-4200-8F89-4C566F77BC7C} - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O15 - Trusted Zone: *.vladzone.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE