Logfile of HijackThis v1.99.1
Scan saved at 4:46:59 AM, on 7/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\mspp32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dreyc Hawking\Desktop\Online Services\SpywareMalware\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nsxlc.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nsxlc.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\nsxlc.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nsxlc.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nsxlc.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\nsxlc.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8l.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {150875DE-94E1-E8C9-27DC-1267DD628704} - C:\WINDOWS\apixg.dll
O2 - BHO: Class - {FBED823A-D55D-5FC4-3371-07A8B14B3237} - C:\WINDOWS\sdkxp.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [mspp32.exe] C:\WINDOWS\system32\mspp32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [iebi32.exe] C:\WINDOWS\iebi32.exe
O4 - HKLM\..\RunOnce: [netty.exe] C:\WINDOWS\netty.exe
O4 - HKLM\..\RunOnce: [d3mm32.exe] C:\WINDOWS\system32\d3mm32.exe
O4 - HKLM\..\RunOnce: [adddo32.exe] C:\WINDOWS\adddo32.exe
O4 - HKLM\..\RunOnce: [d3we.exe] C:\WINDOWS\system32\d3we.exe
O4 - HKLM\..\RunOnce: [ipch32.exe] C:\WINDOWS\ipch32.exe
O4 - HKLM\..\RunOnce: [ieln.exe] C:\WINDOWS\system32\ieln.exe
O4 - HKLM\..\RunOnce: [sdkyh32.exe] C:\WINDOWS\sdkyh32.exe
O4 - HKLM\..\RunOnce: [ieif.exe] C:\WINDOWS\system32\ieif.exe
O4 - HKLM\..\RunOnce: [wintb.exe] C:\WINDOWS\system32\wintb.exe
O4 - HKLM\..\RunOnce: [appkp32.exe] C:\WINDOWS\system32\appkp32.exe
O4 - HKLM\..\RunOnce: [d3pj.exe] C:\WINDOWS\system32\d3pj.exe
O4 - HKLM\..\RunOnce: [atltt.exe] C:\WINDOWS\system32\atltt.exe
O4 - HKLM\..\RunOnce: [d3eg.exe] C:\WINDOWS\d3eg.exe
O4 - HKLM\..\RunOnce: [netji32.exe] C:\WINDOWS\system32\netji32.exe
O4 - HKLM\..\RunOnce: [ntuu.exe] C:\WINDOWS\system32\ntuu.exe
O4 - HKLM\..\RunOnce: [iegb32.exe] C:\WINDOWS\system32\iegb32.exe
O4 - HKLM\..\RunOnce: [ntxl.exe] C:\WINDOWS\system32\ntxl.exe
O4 - HKLM\..\RunOnce: [atlcf32.exe] C:\WINDOWS\system32\atlcf32.exe
O4 - HKLM\..\RunOnce: [syssp.exe] C:\WINDOWS\system32\syssp.exe
O4 - HKLM\..\RunOnce: [msdt32.exe] C:\WINDOWS\msdt32.exe
O4 - HKLM\..\RunOnce: [ntin.exe] C:\WINDOWS\ntin.exe
O4 - HKLM\..\RunOnce: [iesw.exe] C:\WINDOWS\system32\iesw.exe
O4 - HKLM\..\RunOnce: [iesw32.exe] C:\WINDOWS\system32\iesw32.exe
O4 - HKLM\..\RunOnce: [sdkln32.exe] C:\WINDOWS\sdkln32.exe
O4 - HKLM\..\RunOnce: [mfcqp.exe] C:\WINDOWS\mfcqp.exe
O4 - HKLM\..\RunOnce: [winut.exe] C:\WINDOWS\system32\winut.exe
O4 - HKLM\..\RunOnce: [crzv32.exe] C:\WINDOWS\crzv32.exe
O4 - HKLM\..\RunOnce: [ntst.exe] C:\WINDOWS\system32\ntst.exe
O4 - HKLM\..\RunOnce: [iehr32.exe] C:\WINDOWS\system32\iehr32.exe
O4 - HKLM\..\RunOnce: [sdkml.exe] C:\WINDOWS\system32\sdkml.exe
O4 - HKLM\..\RunOnce: [mfcfb32.exe] C:\WINDOWS\mfcfb32.exe
O4 - HKLM\..\RunOnce: [sdkge32.exe] C:\WINDOWS\sdkge32.exe
O4 - HKLM\..\RunOnce: [crgk.exe] C:\WINDOWS\system32\crgk.exe
O4 - HKLM\..\RunOnce: [ntvz.exe] C:\WINDOWS\ntvz.exe
O4 - HKLM\..\RunOnce: [msov32.exe] C:\WINDOWS\msov32.exe
O4 - HKLM\..\RunOnce: [apiab32.exe] C:\WINDOWS\system32\apiab32.exe
O4 - HKLM\..\RunOnce: [javahs32.exe] C:\WINDOWS\system32\javahs32.exe
O4 - HKLM\..\RunOnce: [sdkhu.exe] C:\WINDOWS\system32\sdkhu.exe
O4 - HKLM\..\RunOnce: [mfcmw32.exe] C:\WINDOWS\system32\mfcmw32.exe
O4 - HKLM\..\RunOnce: [javahi32.exe] C:\WINDOWS\system32\javahi32.exe
O4 - HKLM\..\RunOnce: [sdktx.exe] C:\WINDOWS\system32\sdktx.exe
O4 - HKLM\..\RunOnce: [mswa32.exe] C:\WINDOWS\system32\mswa32.exe
O4 - HKLM\..\RunOnce: [syskl.exe] C:\WINDOWS\syskl.exe
O4 - HKLM\..\RunOnce: [iezd.exe] C:\WINDOWS\system32\iezd.exe
O4 - HKLM\..\RunOnce: [wintm.exe] C:\WINDOWS\wintm.exe
O4 - HKLM\..\RunOnce: [javakm.exe] C:\WINDOWS\javakm.exe
O4 - HKLM\..\RunOnce: [apixo32.exe] C:\WINDOWS\apixo32.exe
O4 - HKLM\..\RunOnce: [ieoq32.exe] C:\WINDOWS\ieoq32.exe
O4 - HKLM\..\RunOnce: [sdklc32.exe] C:\WINDOWS\system32\sdklc32.exe
O4 - HKLM\..\RunOnce: [msfz.exe] C:\WINDOWS\system32\msfz.exe
O4 - HKLM\..\RunOnce: [ipkt32.exe] C:\WINDOWS\ipkt32.exe
O4 - HKLM\..\RunOnce: [adddm32.exe] C:\WINDOWS\system32\adddm32.exe
O4 - HKLM\..\RunOnce: [ievt32.exe] C:\WINDOWS\system32\ievt32.exe
O4 - HKLM\..\RunOnce: [javami.exe] C:\WINDOWS\javami.exe
O4 - HKLM\..\RunOnce: [apirc32.exe] C:\WINDOWS\apirc32.exe
O4 - HKLM\..\RunOnce: [winkt.exe] C:\WINDOWS\system32\winkt.exe
O4 - HKLM\..\RunOnce: [crpv32.exe] C:\WINDOWS\system32\crpv32.exe
O4 - HKLM\..\RunOnce: [addsh32.exe] C:\WINDOWS\system32\addsh32.exe
O4 - HKLM\..\RunOnce: [d3yb32.exe] C:\WINDOWS\system32\d3yb32.exe
O4 - HKLM\..\RunOnce: [mfcxl.exe] C:\WINDOWS\mfcxl.exe
O4 - HKLM\..\RunOnce: [sdkih32.exe] C:\WINDOWS\system32\sdkih32.exe
O4 - HKLM\..\RunOnce: [sysxx.exe] C:\WINDOWS\sysxx.exe
O4 - HKLM\..\RunOnce: [winlt32.exe] C:\WINDOWS\winlt32.exe
O4 - HKLM\..\RunOnce: [javaqn32.exe] C:\WINDOWS\system32\javaqn32.exe
O4 - HKLM\..\RunOnce: [sysrq32.exe] C:\WINDOWS\system32\sysrq32.exe
O4 - HKLM\..\RunOnce: [javaek32.exe] C:\WINDOWS\javaek32.exe
O4 - HKLM\..\RunOnce: [crqv32.exe] C:\WINDOWS\crqv32.exe
O4 - HKLM\..\RunOnce: [netdy.exe] C:\WINDOWS\system32\netdy.exe
O4 - HKLM\..\RunOnce: [apiva32.exe] C:\WINDOWS\system32\apiva32.exe
O4 - HKLM\..\RunOnce: [mfcsv32.exe] C:\WINDOWS\system32\mfcsv32.exe
O4 - HKLM\..\RunOnce: [ipjc.exe] C:\WINDOWS\system32\ipjc.exe
O4 - HKLM\..\RunOnce: [appow32.exe] C:\WINDOWS\system32\appow32.exe
O4 - HKLM\..\RunOnce: [ienk32.exe] C:\WINDOWS\ienk32.exe
O4 - HKLM\..\RunOnce: [ieem32.exe] C:\WINDOWS\system32\ieem32.exe
O4 - HKLM\..\RunOnce: [ntxf32.exe] C:\WINDOWS\ntxf32.exe
O4 - HKLM\..\RunOnce: [addtc.exe] C:\WINDOWS\system32\addtc.exe
O4 - HKLM\..\RunOnce: [javaqa.exe] C:\WINDOWS\system32\javaqa.exe
O4 - HKLM\..\RunOnce: [apimi.exe] C:\WINDOWS\apimi.exe
O4 - HKLM\..\RunOnce: [atlnb.exe] C:\WINDOWS\atlnb.exe
O4 - HKLM\..\RunOnce: [iead32.exe] C:\WINDOWS\iead32.exe
O4 - HKLM\..\RunOnce: [sysuu32.exe] C:\WINDOWS\system32\sysuu32.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Free WebSite Tools.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c46.cab
O16 - DPF: {430DDE24-C051-11CF-95BE-0020AFF75E4F} (ichat xchat Control) - http://tank.wizards....sie/msichat.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...83/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1121068852781
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,20/mcgdmgr.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://www.cramster....nt/FileOpen.CAB
O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
O18 - Filter hijack: text/xml - (no CLSID) - (no file)
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\iebi32.exe" /s (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe