Scan saved at 14:50:13, on 09/04/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\fubevtl.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CashBack\bin\cashback.exe
C:\WINDOWS\System32\m4d9ugmv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\System32\CTFMON.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\roylk\xsmsek.exe
C:\WINDOWS\system32\xmvvuct\vrhv.exe
C:\WINDOWS\system32\piocu\ouwgvo.exe
C:\WINDOWS\System32\nnjdhv\yukijcg.exe
C:\WINDOWS\system32\xhvfs\gsmbmbe.exe
C:\WINDOWS\system32\gllhdkia\lvgu.exe
C:\WINDOWS\system32\vtxjxf\tgtvoffv.exe
C:\WINDOWS\system32\wowpatpc\ommdmi.exe
C:\WINDOWS\system32\oiish\jsohpr.exe
C:\WINDOWS\system32\wqgckwtt\ouxklk.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\autodrop.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\maarjkvy.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.c...pE 3yxo1VM/bEo=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://newupdates.lz...ff5f
R3 - Default URLSearchHook is missing
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll
O2 - BHO: (no name) - {65FDB720-9E0D-269C-4AB4-EC61926D67F7} - C:\WINDOWS\Rxwjhbgy.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
O2 - BHO: Starware - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - C:\Program Files\Starware\bin\Starware.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
O2 - BHO: Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:\WINDOWS\dealhlpr.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: Search - {40F8F242-0BA4-12D7-7546-B665FD349F27} - C:\WINDOWS\Rxwjhbgy.dll
O3 - Toolbar: Starware - {D49E9D35-254C-4c6a-9D17-95018D228FF5} - C:\Program Files\Starware\bin\Starware.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\fubevtl.exe
O4 - HKLM\..\Run: [WebInstall2] C:\Program Files\ClipGenie\WebInstall.exe /R
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [towfezv] C:\WINDOWS\Lbczxs.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [HorngTech4D] C:\PROGRA~1\MOUSES~1\bally4d.exe
O4 - HKLM\..\Run: [ewiqvdc] C:\WINDOWS\System32\lcgrxbdu\ewiqvdc.exe
O4 - HKLM\..\Run: [yukijcg] C:\WINDOWS\System32\nnjdhv\yukijcg.exe
O4 - HKLM\..\Run: [raukedp] C:\WINDOWS\System32\jolxk\raukedp.exe
O4 - HKLM\..\Run: [vbkuys] C:\WINDOWS\System32\lqsj\vbkuys.exe
O4 - HKLM\..\Run: [nxlid] C:\WINDOWS\System32\tsacg\nxlid.exe
O4 - HKLM\..\Run: [xqmdpom] C:\WINDOWS\System32\bplkleb\xqmdpom.exe
O4 - HKLM\..\Run: [vits] C:\WINDOWS\System32\ggljso\vits.exe
O4 - HKLM\..\Run: [grmweu] C:\WINDOWS\System32\butud\grmweu.exe
O4 - HKLM\..\Run: [osvijj] C:\WINDOWS\System32\khgmhwkn\osvijj.exe
O4 - HKLM\..\Run: [wnmspln] C:\WINDOWS\System32\vdrdgbe\wnmspln.exe
O4 - HKLM\..\Run: [aivdmwhm] C:\WINDOWS\System32\tngdknh\aivdmwhm.exe
O4 - HKLM\..\Run: [fefhvyvi] C:\WINDOWS\System32\clwbt\fefhvyvi.exe
O4 - HKLM\..\Run: [ehyq] C:\WINDOWS\System32\xalqxqcf\ehyq.exe
O4 - HKLM\..\Run: [ggmbrjfn] C:\WINDOWS\System32\omsaup\ggmbrjfn.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [ucyf] C:\WINDOWS\System32\qrbjk\ucyf.exe
O4 - HKLM\..\Run: [dcmys] C:\WINDOWS\System32\dggfypyx\dcmys.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [ebyjfuyf] C:\WINDOWS\System32\mucnyrup\ebyjfuyf.exe
O4 - HKLM\..\Run: [tjktie] C:\WINDOWS\System32\ookenv\tjktie.exe
O4 - HKLM\..\Run: [jajgww] C:\WINDOWS\System32\ppdht\jajgww.exe
O4 - HKLM\..\Run: [rwtmm] C:\WINDOWS\System32\qdsgb\rwtmm.exe
O4 - HKLM\..\Run: [ajhxym] C:\WINDOWS\System32\nlfkxu\ajhxym.exe
O4 - HKLM\..\Run: [yeraei] C:\WINDOWS\System32\hvmr\yeraei.exe
O4 - HKLM\..\Run: [qebpddv] C:\WINDOWS\System32\bjdfeh\qebpddv.exe
O4 - HKLM\..\Run: [ailwopn] C:\WINDOWS\System32\hqicm\ailwopn.exe
O4 - HKLM\..\Run: [ejoifaov] C:\WINDOWS\System32\mehf\ejoifaov.exe
O4 - HKLM\..\Run: [mwjdfey] C:\WINDOWS\System32\pqwp\mwjdfey.exe
O4 - HKLM\..\Run: [vseifwnb] C:\WINDOWS\System32\xdlejbs\vseifwnb.exe
O4 - HKLM\..\Run: [igngiyw] C:\WINDOWS\System32\irklweef\igngiyw.exe
O4 - HKLM\..\Run: [sklumm] C:\WINDOWS\System32\eyyojv\sklumm.exe
O4 - HKLM\..\Run: [dctfgrx] C:\WINDOWS\System32\nrnshjo\dctfgrx.exe
O4 - HKLM\..\Run: [bvgjhn] C:\WINDOWS\System32\sdpmog\bvgjhn.exe
O4 - HKLM\..\Run: [chhe] C:\WINDOWS\System32\omldrr\chhe.exe
O4 - HKLM\..\Run: [brspofmt] C:\WINDOWS\System32\eynghm\brspofmt.exe
O4 - HKLM\..\Run: [oicpvxu] C:\WINDOWS\System32\aohaubol\oicpvxu.exe
O4 - HKLM\..\Run: [bbhys] C:\WINDOWS\System32\tosp\bbhys.exe
O4 - HKLM\..\Run: [cbsimut] C:\WINDOWS\System32\kmtk\cbsimut.exe
O4 - HKLM\..\Run: [cnmk] C:\WINDOWS\System32\bden\cnmk.exe
O4 - HKLM\..\Run: [afbt] C:\WINDOWS\System32\xlcxv\afbt.exe
O4 - HKLM\..\Run: [nfcjt] C:\WINDOWS\System32\wbyqtheq\nfcjt.exe
O4 - HKLM\..\Run: [yrtdgfti] C:\WINDOWS\System32\pyfvmi\yrtdgfti.exe
O4 - HKLM\..\Run: [obtyhdm] C:\WINDOWS\System32\qylk\obtyhdm.exe
O4 - HKLM\..\Run: [rnpia] C:\WINDOWS\System32\hrpr\rnpia.exe
O4 - HKLM\..\Run: [matc] C:\WINDOWS\System32\qifjq\matc.exe
O4 - HKLM\..\Run: [hgsd] C:\WINDOWS\System32\vkdnxmi\hgsd.exe
O4 - HKLM\..\Run: [m4d9ugmv] C:\WINDOWS\System32\m4d9ugmv.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [svchost] C:\WINDOWS\svchost.exe .
O4 - HKLM\..\Run: [twaqv] C:\WINDOWS\system32\jyigh\twaqv.exe
O4 - HKLM\..\Run: [ougn] C:\WINDOWS\system32\fjtyiasq\ougn.exe
O4 - HKLM\..\Run: [ouxklk] C:\WINDOWS\system32\wqgckwtt\ouxklk.exe
O4 - HKLM\..\Run: [vrhv] C:\WINDOWS\system32\xmvvuct\vrhv.exe
O4 - HKLM\..\Run: [xaai] C:\WINDOWS\system32\anwrk\xaai.exe
O4 - HKLM\..\Run: [xsmsek] C:\WINDOWS\system32\roylk\xsmsek.exe
O4 - HKLM\..\Run: [jsohpr] C:\WINDOWS\system32\oiish\jsohpr.exe
O4 - HKLM\..\Run: [ouwgvo] C:\WINDOWS\system32\piocu\ouwgvo.exe
O4 - HKLM\..\Run: [lvgu] C:\WINDOWS\system32\gllhdkia\lvgu.exe
O4 - HKLM\..\Run: [csfilyfy] C:\WINDOWS\system32\tvwk\csfilyfy.exe
O4 - HKLM\..\Run: [iidaswkw] C:\WINDOWS\system32\slred\iidaswkw.exe
O4 - HKLM\..\Run: [gsmbmbe] C:\WINDOWS\system32\xhvfs\gsmbmbe.exe
O4 - HKLM\..\Run: [ommdmi] C:\WINDOWS\system32\wowpatpc\ommdmi.exe
O4 - HKLM\..\Run: [tgtvoffv] C:\WINDOWS\system32\vtxjxf\tgtvoffv.exe
O4 - HKLM\..\Run: [oorpnhvw] C:\WINDOWS\system32\vnsho\oorpnhvw.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Whistle - {220E39C3-B081-4719-AB1A-9A884DCBD05C} - C:\Program Files\WhistleSoftware\WselServices\webband.dll
O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...etup1.0.0.8.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1109925413343
O16 - DPF: {EC9C20C4-FF24-11D3-81B7-00902776CF54} (InstallerActiveX Class) - http://www.netex.co....e/Installer.CAB
O16 - DPF: {F59AB0C4-3443-4551-A78F-C101F9DE0215} (LauncherV1 Class) - http://irc.nana.co.i.../launcher39.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C6928589-27B6-43C0-85EA-D5E8F3221E5C}: NameServer = 62.219.186.7 192.115.106.35
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe