Logfile of HijackThis v1.99.1
Scan saved at 2:13:52 AM, on 5/25/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\NETEI32.EXE
C:\WINDOWS\MSMK32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\JAVAAG.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\WINDOWS\FSSCRCTL.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\MSMK32.EXE
C:\WINDOWS\NETEI32.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pvfrw.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pvfrw.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pvfrw.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\pvfrw.dll/sp.html#55135
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pvfrw.dll/sp.html#55135
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\pvfrw.dll/sp.html#55135
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\pvfrw.dll/sp.html#55135
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8AE8A170-3113-8C93-CBCE-6EBAC7413F23} - C:\WINDOWS\SYSTEM\ADDLL.DLL
O4 - HKLM\..\Run: [JAVAAG.EXE] C:\WINDOWS\JAVAAG.EXE
O4 - HKLM\..\RunServices: [NETEI32.EXE] C:\WINDOWS\NETEI32.EXE /s
O4 - HKLM\..\RunServices: [MSMK32.EXE] C:\WINDOWS\MSMK32.EXE /s
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} -
http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} -
http://online.comcast.net/help/ (file missing)
O9 - Extra button: Dell Home - {24A6FF20-6412-11D4-A864-602351C10000} -
http://www.dellnet.com (file missing) (HKCU)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabHere are the results of the PANDA:
Incident Status Location
Virus:Trj/Downloader.BSU Disinfected Operating system
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\JAVAAG.EXE
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\NETEI32.EXE
Virus:Trj/Downloader.BSU Disinfected Operating system
Adware:Adware/Gator No disinfected Windows Registry
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\CERES.DLL
Adware:Adware/FunWeb No disinfected Windows Registry
Adware:Adware/SearchAid No disinfected C:\windows\favorites\Only sex website.url
Adware:Adware/IPInsight No disinfected C:\WINDOWS\alchem.???
Adware:Adware/DealHelper No disinfected C:\WINDOWS\SYSTEM\dhp?.dll
Adware:Adware/IEPlugin No disinfected C:\WINDOWS\systb.dll
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\SYSTEM\polall1m.exe
Adware:Adware/WUpd No disinfected C:\Program Files\ErrorGuard
Adware:Adware/MyWebSearch No disinfected Windows Registry
Adware:Adware/BTGrab No disinfected C:\WINDOWS\BTGrab.dll
Spyware:Spyware/Petro-Line No disinfected C:\windows\favorites\Sites about\Ab scissor.url
Adware:Adware/CWS.Aboutblank No disinfected Windows Registry
Adware:Adware/Adsmart No disinfected C:\WINDOWS\sys????.exe
Adware:Adware/BootPorn No disinfected C:\BOOT.EXE
Adware:Adware/IGuard No disinfected C:\WINDOWS\SYSTEM\wldr.dll
Adware:Adware/Spywad No disinfected C:\WINDOWS\DESKTOP.HTML
Adware:Adware/BlueScreenWarningNo disinfected Windows Registry
Virus:Trj/Downloader.CFJ Disinfected Operating system
Adware:Adware/Popuper No disinfected C:\WINDOWS\SYSTEM\intmonp.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\SYSTEM\DHPE.DLL
Adware:Adware/Transponder No disinfected C:\WINDOWS\SYSTEM\POLALL1M.EXE
Adware:Adware/Transponder No disinfected C:\WINDOWS\SYSTEM\shmkluuv.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\apihk32.exe
Virus:Trj/Downloader.CFJ Disinfected C:\WINDOWS\SYSTEM\ciaa.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\SYSTEM\javamw32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\ttvju.dll
Adware:Adware/Popuper No disinfected C:\WINDOWS\SYSTEM\msmsgs.exe
Adware:Adware/Virmaid No disinfected C:\WINDOWS\SYSTEM\LogFiles\T54152130.so
Adware:Adware/Gogotools No disinfected C:\WINDOWS\SYSTEM\shnlog.exe
Adware:Adware/Popuper No disinfected C:\WINDOWS\SYSTEM\msole32.exe
Virus:Trj/Puper.A Disinfected C:\WINDOWS\SYSTEM\intmonp.exe
Adware:Adware/BlueScreenWarningNo disinfected C:\WINDOWS\SYSTEM\wldr.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\appml.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\ippp32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\ntyl32.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\SYSTEM\atldg.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\cufab.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\ntok32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\dmxff.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\bfikz.dll
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\SYSTEM\netik32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\wuojw.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\mfcyn32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\ubtya.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\eokkl.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\wenyr.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\apiir32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\winjq32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\netst32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\appox32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\rkcip.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\sysva32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM\aeqct.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\addgq32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\syshl.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\appir32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\winym.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\SYSTEM\javahe32.exe
Adware:Adware/BTGrab No disinfected C:\WINDOWS\BTGRAB.DLL
Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\CERES.INF
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\INF\TWAINTEC.INF
Adware:Adware/IPInsight No disinfected C:\WINDOWS\INF\ALCHEM.INF
Adware:Adware/BTGrab No disinfected C:\WINDOWS\INF\BTGRAB.INF
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\SYSTEM32\stmtreco.exe
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\SYSTEM32\randreco.exe
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\SYSTEM32\tt_reco.exe
Adware:Adware/Adsmart No disinfected C:\WINDOWS\SYSMON.EXE
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\CERES.DLL
Adware:Adware/IWon No disinfected C:\WINDOWS\Desktop\backups\backup-20050524-215350-811.inf
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Credit counseling.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Insurance home.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Mortgage life insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Help desk software.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Ab scissor.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Videos.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\What is hydrocodone.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Online gambling casino.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Refinancing my mortgage.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Debt credit card.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Fha.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Loan for debt consolidation.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Health insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Personal loans online.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Payroll advance.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Marketing email.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Prescription Drugs Rx Online.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Credit report.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Tahoe vacation rental.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Escorts.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Order phentermine.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Mortgage insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Personal loans with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Crm software.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Nevada corporations.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Unsecured bad credit loans.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Loan for people with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Broadband comparison.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Online Betting Site.url
Spyware:Spyware/Petro-Line No disinfected C:\WINDOWS\Favorites\Sites about\Online instant loan.url
Adware:Adware/SearchAid No disinfected C:\WINDOWS\Favorites\Search the web.url
Adware:Adware/SearchAid No disinfected C:\WINDOWS\Favorites\Only sex website.url
Adware:Adware/SearchAid No disinfected C:\WINDOWS\Favorites\Seven days of free [bleep].url
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll
Adware:Adware/IPInsight No disinfected C:\WINDOWS\ALCHEM.INI
Adware:Adware/IPInsight No disinfected C:\WINDOWS\SATMAT.INI
Adware:Adware/Gator No disinfected C:\WINDOWS\GatorHDPlugin.log
Adware:Adware/Transponder No disinfected C:\WINDOWS\POLMX.EXE
Virus:Trj/Downloader.OU Disinfected C:\WINDOWS\wupdt.exe
Adware:Adware/IPInsight No disinfected C:\WINDOWS\ALCHEM.EXE
Adware:Adware/Imibar No disinfected C:\WINDOWS\systb.dll
Virus:Trj/Imiserv.D Disinfected C:\WINDOWS\systb.exe
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\TWAINTEC.DLL
Adware:Adware/Gator No disinfected C:\WINDOWS\GatorHDPlugin.log-old.log
Virus:Trj/Imiserv.D Disinfected C:\WINDOWS\enhupdt.exe
Adware:Adware/IPInsight No disinfected C:\WINDOWS\SATMAT.EXE
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\lxagu.dll
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\javaag.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\mryamm.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\rbqzrh.log
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\Buddy.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\msyi.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\mfcql32.exe
Adware:Adware/Spywad No disinfected C:\WINDOWS\desktop.html
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\snuir.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\qwtyxl.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\pakedh.txt
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\zxqjz.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\ielp32.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\nqahf.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\bwdhap.log
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\gvamo.dll
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\hehqyv.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\uuvfil.log
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\iprt.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\vsdgf.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\juohpm.log
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\nmggxl.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\jqzgi.dll
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\ntmi32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\crcq.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\dqowks.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\ipwc32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\addne.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\oehtwk.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\javauo.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\ntrj.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\owawyk.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\rdjji.dll
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\javacx32.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\ztsffy.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\qqpre.dll
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\cnhpyq.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\addgz.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\axmtet.dat
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\kyantd.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\mgvjpj.log
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\xkkoqc.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\haezn.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\kbmhzp.log
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\syseh32.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\pgjpup.dat
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\wtswpw.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\apiiy.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\gvamou.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\javatx32.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\vpaher.dat
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\uscnne.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\apibd.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\wdwcbp.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\apptj.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\hhyzyl.dat
Adware:Adware/Adsmart No disinfected C:\WINDOWS\syszv32.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\javaex32.exe
Adware:Adware/Startpage.AS No disinfected C:\WINDOWS\wvtzlc.dat
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\netib.exe
Virus:Trj/Downloader.BSU Disinfected C:\WINDOWS\crrx32.exe