Logfile of HijackThis v1.99.1
Scan saved at 11:12:34 PM, on 5/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\efuaooi\gydnw.exe
C:\WINDOWS\system32\joprdv\jersfcw.exe
C:\WINDOWS\system32\nysp\erme.exe
C:\WINDOWS\system32\swgfxri\gkbh.exe
C:\WINDOWS\system32\ckplk\kuahlsni.exe
C:\WINDOWS\system32\flqa\khqw.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\qctaclf\fhetyaxt.exe
C:\WINDOWS\system32\xtbhlg\tqaq.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cwfc\bguxm.exe
C:\WINDOWS\system32\gfqk\silo.exe
C:\WINDOWS\system32\fjnru\urwki.exe
C:\WINDOWS\system32\tunb\smvpg.exe
C:\WINDOWS\system32\rvqdq\cxqkhow.exe
C:\WINDOWS\system32\sfauyj\vdeiq.exe
C:\WINDOWS\system32\tfihha\uxpusbs.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\system32\nubdaa\xagx.exe
C:\WINDOWS\system32\hmuijbbw\bgyhnl.exe
C:\WINDOWS\system32\yklfjv\aqcenpfk.exe
C:\WINDOWS\system32\kogk\idsi.exe
C:\WINDOWS\system32\nueqkput\adlixyl.exe
C:\WINDOWS\system32\jnfi\mytjnkk.exe
C:\WINDOWS\system32\svuos\cvblnwuo.exe
C:\WINDOWS\system32\knxdlwc\jauxacso.exe
C:\WINDOWS\system32\veohqa\objfcag.exe
C:\WINDOWS\system32\vvppayy\baevoe.exe
C:\WINDOWS\system32\tina\kpalfb.exe
C:\WINDOWS\system32\xymwww\vkkgm.exe
C:\WINDOWS\system32\bgyvssql\tobvf.exe
C:\WINDOWS\system32\ijcdkmf\wxfdhl.exe
C:\WINDOWS\system32\nfimue\wyohdeoy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\lwtfats\cqiqv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\uqyixqk\bmqecm.exe
C:\WINDOWS\system32\qdcoo\ohkgcfbi.exe
C:\WINDOWS\system32\bnwwwv\wrys.exe
C:\WINDOWS\system32\hmmcuno\qmdqhd.exe
C:\WINDOWS\system32\gndw\yfhd.exe
C:\WINDOWS\system32\vnuaoni\mhyw.exe
C:\WINDOWS\system32\ilsbiy\bqcoubc.exe
C:\WINDOWS\system32\kmkeu\gbfws.exe
C:\WINDOWS\system32\jgcf\ybvfai.exe
C:\WINDOWS\system32\vjyy\bikndou.exe
C:\WINDOWS\system32\suarh\feeqtmbw.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\jvoit\cuqi.exe
C:\WINDOWS\system32\ntvscr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Documents and Settings\Evan\Desktop\Cleaning Equipment\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MI948F~1\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ymbip] C:\WINDOWS\system32\qxpooqko\ymbip.exe
O4 - HKLM\..\Run: [hhbukh] C:\WINDOWS\system32\hiba\hhbukh.exe
O4 - HKLM\..\Run: [myxsx] C:\WINDOWS\system32\enba\myxsx.exe
O4 - HKLM\..\Run: [buqgacy] C:\WINDOWS\system32\ijfij\buqgacy.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [jersfcw] C:\WINDOWS\system32\joprdv\jersfcw.exe
O4 - HKLM\..\Run: [ikuhp] C:\WINDOWS\system32\crawmpqj\ikuhp.exe
O4 - HKLM\..\Run: [futd] C:\WINDOWS\system32\rjlpqgwe\futd.exe
O4 - HKLM\..\Run: [doulew] C:\WINDOWS\system32\wnpjrk\doulew.exe
O4 - HKLM\..\Run: [erme] C:\WINDOWS\system32\nysp\erme.exe
O4 - HKLM\..\Run: [gkbh] C:\WINDOWS\system32\swgfxri\gkbh.exe
O4 - HKLM\..\Run: [khqw] C:\WINDOWS\system32\flqa\khqw.exe
O4 - HKLM\..\Run: [jbrdy] C:\WINDOWS\system32\njlyipxa\jbrdy.exe
O4 - HKLM\..\Run: [tqaq] C:\WINDOWS\system32\xtbhlg\tqaq.exe
O4 - HKLM\..\Run: [bguxm] C:\WINDOWS\system32\cwfc\bguxm.exe
O4 - HKLM\..\Run: [silo] C:\WINDOWS\system32\gfqk\silo.exe
O4 - HKLM\..\Run: [urwki] C:\WINDOWS\system32\fjnru\urwki.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteidk32.exe
O4 - HKLM\..\Run: [smvpg] C:\WINDOWS\system32\tunb\smvpg.exe
O4 - HKLM\..\Run: [cxqkhow] C:\WINDOWS\system32\rvqdq\cxqkhow.exe
O4 - HKLM\..\Run: [vdeiq] C:\WINDOWS\system32\sfauyj\vdeiq.exe
O4 - HKLM\..\Run: [uxpusbs] C:\WINDOWS\system32\tfihha\uxpusbs.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [xagx] C:\WINDOWS\system32\nubdaa\xagx.exe
O4 - HKLM\..\Run: [bgyhnl] C:\WINDOWS\system32\hmuijbbw\bgyhnl.exe
O4 - HKLM\..\Run: [aqcenpfk] C:\WINDOWS\system32\yklfjv\aqcenpfk.exe
O4 - HKLM\..\Run: [idsi] C:\WINDOWS\system32\kogk\idsi.exe
O4 - HKLM\..\Run: [adlixyl] C:\WINDOWS\system32\nueqkput\adlixyl.exe
O4 - HKLM\..\Run: [mytjnkk] C:\WINDOWS\system32\jnfi\mytjnkk.exe
O4 - HKLM\..\Run: [cvblnwuo] C:\WINDOWS\system32\svuos\cvblnwuo.exe
O4 - HKLM\..\Run: [jauxacso] C:\WINDOWS\system32\knxdlwc\jauxacso.exe
O4 - HKLM\..\Run: [objfcag] C:\WINDOWS\system32\veohqa\objfcag.exe
O4 - HKLM\..\Run: [baevoe] C:\WINDOWS\system32\vvppayy\baevoe.exe
O4 - HKLM\..\Run: [kpalfb] C:\WINDOWS\system32\tina\kpalfb.exe
O4 - HKLM\..\Run: [vkkgm] C:\WINDOWS\system32\xymwww\vkkgm.exe
O4 - HKLM\..\Run: [tobvf] C:\WINDOWS\system32\bgyvssql\tobvf.exe
O4 - HKLM\..\Run: [wxfdhl] C:\WINDOWS\system32\ijcdkmf\wxfdhl.exe
O4 - HKLM\..\Run: [wyohdeoy] C:\WINDOWS\system32\nfimue\wyohdeoy.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cqiqv] C:\WINDOWS\system32\lwtfats\cqiqv.exe
O4 - HKLM\..\Run: [bmqecm] C:\WINDOWS\system32\uqyixqk\bmqecm.exe
O4 - HKLM\..\Run: [ohkgcfbi] C:\WINDOWS\system32\qdcoo\ohkgcfbi.exe
O4 - HKLM\..\Run: [wrys] C:\WINDOWS\system32\bnwwwv\wrys.exe
O4 - HKLM\..\Run: [qmdqhd] C:\WINDOWS\system32\hmmcuno\qmdqhd.exe
O4 - HKLM\..\Run: [yfhd] C:\WINDOWS\system32\gndw\yfhd.exe
O4 - HKLM\..\Run: [mhyw] C:\WINDOWS\system32\vnuaoni\mhyw.exe
O4 - HKLM\..\Run: [gydnw] C:\WINDOWS\system32\efuaooi\gydnw.exe
O4 - HKLM\..\Run: [bqcoubc] C:\WINDOWS\system32\ilsbiy\bqcoubc.exe
O4 - HKLM\..\Run: [gbfws] C:\WINDOWS\system32\kmkeu\gbfws.exe
O4 - HKLM\..\Run: [ybvfai] C:\WINDOWS\system32\jgcf\ybvfai.exe
O4 - HKLM\..\Run: [bikndou] C:\WINDOWS\system32\vjyy\bikndou.exe
O4 - HKLM\..\Run: [kuahlsni] C:\WINDOWS\system32\ckplk\kuahlsni.exe
O4 - HKLM\..\Run: [feeqtmbw] C:\WINDOWS\system32\suarh\feeqtmbw.exe
O4 - HKLM\..\Run: [fhetyaxt] C:\WINDOWS\system32\qctaclf\fhetyaxt.exe
O4 - HKLM\..\Run: [cuqi] C:\WINDOWS\system32\jvoit\cuqi.exe
O4 - HKLM\..\Run: [oghgna] c:\windows\system32\fzojel.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ZBqFRQenh] ntvscr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe