Logfile of HijackThis v1.99.1
Scan saved at 12:18:27 PM, on 8/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Greetings Workshop\GWREMIND.EXE
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\ipjx32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HiJack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qzdca.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qzdca.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qzdca.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qzdca.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qzdca.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qzdca.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qzdca.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapp...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {F462A044-FD7A-92DB-7E68-146D4A5388F8} - C:\WINDOWS\system32\javaqt32.dll
O2 - BHO: Class - {FD36CB53-F43E-C115-ED98-E1F307C77FD6} - C:\WINDOWS\ipjj.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [d3qn32.exe] C:\WINDOWS\system32\d3qn32.exe
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [appqc32.exe] C:\WINDOWS\appqc32.exe
O4 - HKLM\..\Run: [atlsv32.exe] C:\WINDOWS\atlsv32.exe
O4 - HKLM\..\Run: [ntql32.exe] C:\WINDOWS\system32\ntql32.exe
O4 - HKLM\..\Run: [crha.exe] C:\WINDOWS\system32\crha.exe
O4 - HKLM\..\Run: [atlkk.exe] C:\WINDOWS\atlkk.exe
O4 - HKLM\..\Run: [netis32.exe] C:\WINDOWS\netis32.exe
O4 - HKLM\..\Run: [sysvi.exe] C:\WINDOWS\system32\sysvi.exe
O4 - HKLM\..\Run: [d3mr.exe] C:\WINDOWS\system32\d3mr.exe
O4 - HKLM\..\Run: [mspg32.exe] C:\WINDOWS\system32\mspg32.exe
O4 - HKLM\..\Run: [mszs.exe] C:\WINDOWS\system32\mszs.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [sdkdp32.exe] C:\WINDOWS\sdkdp32.exe
O4 - HKLM\..\Run: [sysck.exe] C:\WINDOWS\sysck.exe
O4 - HKLM\..\Run: [ipjk32.exe] C:\WINDOWS\ipjk32.exe
O4 - HKLM\..\Run: [iedp.exe] C:\WINDOWS\system32\iedp.exe
O4 - HKLM\..\Run: [msxd.exe] C:\WINDOWS\system32\msxd.exe
O4 - HKLM\..\Run: [addxt32.exe] C:\WINDOWS\addxt32.exe
O4 - HKLM\..\Run: [ipsp32.exe] C:\WINDOWS\ipsp32.exe
O4 - HKLM\..\Run: [appyg32.exe] C:\WINDOWS\system32\appyg32.exe
O4 - HKLM\..\Run: [ntxe.exe] C:\WINDOWS\ntxe.exe
O4 - HKLM\..\Run: [sysrl32.exe] C:\WINDOWS\system32\sysrl32.exe
O4 - HKLM\..\Run: [apppk.exe] C:\WINDOWS\system32\apppk.exe
O4 - HKLM\..\Run: [ipjx32.exe] C:\WINDOWS\ipjx32.exe
O4 - HKLM\..\RunOnce: [netgq32.exe] C:\WINDOWS\netgq32.exe
O4 - HKLM\..\RunOnce: [sysoh32.exe] C:\WINDOWS\sysoh32.exe
O4 - HKLM\..\RunOnce: [sdkug32.exe] C:\WINDOWS\sdkug32.exe
O4 - HKLM\..\RunOnce: [msfd.exe] C:\WINDOWS\msfd.exe
O4 - HKLM\..\RunOnce: [d3us.exe] C:\WINDOWS\d3us.exe
O4 - HKLM\..\RunOnce: [d3dg.exe] C:\WINDOWS\system32\d3dg.exe
O4 - HKLM\..\RunOnce: [mfcdo32.exe] C:\WINDOWS\mfcdo32.exe
O4 - HKLM\..\RunOnce: [msle32.exe] C:\WINDOWS\msle32.exe
O4 - HKLM\..\RunOnce: [netdu.exe] C:\WINDOWS\netdu.exe
O4 - HKLM\..\RunOnce: [msrg.exe] C:\WINDOWS\system32\msrg.exe
O4 - HKLM\..\RunOnce: [wincz.exe] C:\WINDOWS\wincz.exe
O4 - HKLM\..\RunOnce: [javabp32.exe] C:\WINDOWS\system32\javabp32.exe
O4 - HKLM\..\RunOnce: [ipqi32.exe] C:\WINDOWS\system32\ipqi32.exe
O4 - HKLM\..\RunOnce: [sdkye32.exe] C:\WINDOWS\sdkye32.exe
O4 - HKLM\..\RunOnce: [ntkm.exe] C:\WINDOWS\system32\ntkm.exe
O4 - HKLM\..\RunOnce: [sdksc32.exe] C:\WINDOWS\system32\sdksc32.exe
O4 - HKLM\..\RunOnce: [sysrf32.exe] C:\WINDOWS\system32\sysrf32.exe
O4 - HKLM\..\RunOnce: [winny.exe] C:\WINDOWS\system32\winny.exe
O4 - HKLM\..\RunOnce: [msag32.exe] C:\WINDOWS\system32\msag32.exe
O4 - HKLM\..\RunOnce: [netxz.exe] C:\WINDOWS\system32\netxz.exe
O4 - HKLM\..\RunOnce: [apixm.exe] C:\WINDOWS\system32\apixm.exe
O4 - HKLM\..\RunOnce: [iedy.exe] C:\WINDOWS\system32\iedy.exe
O4 - HKLM\..\RunOnce: [mfcbj.exe] C:\WINDOWS\mfcbj.exe
O4 - HKLM\..\RunOnce: [sdkmx.exe] C:\WINDOWS\sdkmx.exe
O4 - HKLM\..\RunOnce: [crah32.exe] C:\WINDOWS\crah32.exe
O4 - HKLM\..\RunOnce: [sdkvl.exe] C:\WINDOWS\sdkvl.exe
O4 - HKLM\..\RunOnce: [iezv.exe] C:\WINDOWS\system32\iezv.exe
O4 - HKLM\..\RunOnce: [d3rb32.exe] C:\WINDOWS\d3rb32.exe
O4 - HKLM\..\RunOnce: [winbu32.exe] C:\WINDOWS\system32\winbu32.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [ipmh.exe] C:\WINDOWS\ipmh.exe
O4 - HKLM\..\RunOnce: [crin32.exe] C:\WINDOWS\crin32.exe
O4 - HKLM\..\RunOnce: [iewr.exe] C:\WINDOWS\iewr.exe
O4 - HKLM\..\RunOnce: [netqc32.exe] C:\WINDOWS\netqc32.exe
O4 - HKLM\..\RunOnce: [crit32.exe] C:\WINDOWS\system32\crit32.exe
O4 - HKLM\..\RunOnce: [d3ig.exe] C:\WINDOWS\system32\d3ig.exe
O4 - HKLM\..\RunOnce: [iewj32.exe] C:\WINDOWS\system32\iewj32.exe
O4 - HKLM\..\RunOnce: [winwp.exe] C:\WINDOWS\winwp.exe
O4 - HKLM\..\RunOnce: [mfcue.exe] C:\WINDOWS\mfcue.exe
O4 - HKLM\..\RunOnce: [javaih.exe] C:\WINDOWS\system32\javaih.exe
O4 - HKLM\..\RunOnce: [appyi.exe] C:\WINDOWS\system32\appyi.exe
O4 - HKLM\..\RunOnce: [netka32.exe] C:\WINDOWS\system32\netka32.exe
O4 - HKLM\..\RunOnce: [winge.exe] C:\WINDOWS\system32\winge.exe
O4 - HKLM\..\RunOnce: [iezh.exe] C:\WINDOWS\iezh.exe
O4 - HKLM\..\RunOnce: [winft32.exe] C:\WINDOWS\winft32.exe
O4 - HKLM\..\RunOnce: [sysgn32.exe] C:\WINDOWS\sysgn32.exe
O4 - HKLM\..\RunOnce: [d3ao.exe] C:\WINDOWS\d3ao.exe
O4 - HKLM\..\RunOnce: [sysqh32.exe] C:\WINDOWS\system32\sysqh32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/.../GrooveAX27.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.mac...ash/swflash.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe