Logfile of HijackThis v1.99.1
Scan saved at 10:24:58 AM, on 9/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ffsraxj\neovvknh.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\steil\nsxos.exe
C:\WINDOWS\System32\ndco\ehwpf.exe
C:\Program Files\Instant Buzz\IBDaemon.exe
C:\Program Files\Media Gateway\MediaGateway.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\etjtta.exe
C:\Documents and Settings\Antonio\My Documents\Unzipped\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {ADD814A1-3A11-E47D-6526-111F506A3B69} - C:\WINDOWS\rkulywxk.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O1 - Hosts: 216.39.69.102 view.atdmt.com
O2 - BHO: (no name) - {1BAF4F54-80CF-81B3-0965-1891D2D46DB1} - C:\WINDOWS\rkulywxk.dll
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
O2 - BHO: (no name) - {5455BB9B-E46E-7C9B-07F3-B3173770A8AD} - C:\WINDOWS\System32\nuedvrxc\emtmlint.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~1\IBBar.dll
O2 - BHO: (no name) - {BE9B42C6-EA10-976F-1E3D-CBD8BB5E4037} - C:\WINDOWS\System32\xemfbrrh\bcvqmgkw.dll
O2 - BHO: (no name) - {DB85B131-8B32-B963-6BFD-B49E153515FF} - C:\WINDOWS\System32\afkhvmmc\aehdwdhm.dll
O2 - BHO: (no name) - {EC4D7D15-D223-C80B-0817-B7448EBF0C42} - C:\WINDOWS\System32\avntowbf\jnaaxfnu.dll
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll
O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~1\IBBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Search - {5145881A-04D5-4776-44E1-6DFEFCAD631C} - C:\WINDOWS\rkulywxk.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [sfwharci] C:\WINDOWS\System32\jcrgno\sfwharci.exe
O4 - HKLM\..\Run: [txkfkcg] C:\WINDOWS\System32\vlrss\txkfkcg.exe
O4 - HKLM\..\Run: [mtsnk] C:\WINDOWS\System32\epydp\mtsnk.exe
O4 - HKLM\..\Run: [wwgfp] C:\WINDOWS\System32\qsqoc\wwgfp.exe
O4 - HKLM\..\Run: [cdivtoa] C:\WINDOWS\System32\bpeme\cdivtoa.exe
O4 - HKLM\..\Run: [laeul] C:\WINDOWS\System32\apryh\laeul.exe
O4 - HKLM\..\Run: [kfpbivt] C:\WINDOWS\System32\judsudu\kfpbivt.exe
O4 - HKLM\..\Run: [nsxos] C:\WINDOWS\System32\steil\nsxos.exe
O4 - HKLM\..\Run: [tptavwx] C:\WINDOWS\System32\ibre\tptavwx.exe
O4 - HKLM\..\Run: [ehwpf] C:\WINDOWS\System32\ndco\ehwpf.exe
O4 - HKLM\..\Run: [Instant Buzz Daemon] C:\Program Files\Instant Buzz\IBDaemon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [neovvknh] C:\WINDOWS\System32\ffsraxj\neovvknh.exe
O4 - HKLM\..\Run: [vt3um6nk] C:\WINDOWS\System32\vt3um6nk.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\utnian.exe reg_run
O4 - HKLM\..\Run: [ukddxml] C:\WINDOWS\System32\etjtta.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Startup Manager] C:\Documents and Settings\Antonio\Application Data\Systweak\ASO 2\smstartUp manager.exe
O4 - HKCU\..\Run: [dpnbc3] C:\WINDOWS\System32\dpnbc3.exe
O8 - Extra context menu item: &Buscar en Geomundos - res://C:\WINDOWS\Downloaded Program Files\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar &R - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~1\IBBar.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar &R - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.co...laxoInstall.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\syimgvw.dll
O23 - Service: cdivtoabpeme - Unknown owner - C:\WINDOWS\System32\bpeme\cdivtoa.exe
O23 - Service: cmglitlyqtfb - Unknown owner - C:\WINDOWS\System32\lyqtfb\cmglit.exe
O23 - Service: dlmbgrxrjhaw - Unknown owner - C:\WINDOWS\System32\rjhaw\dlmbgrx.exe
O23 - Service: dpsishkwanwwd - Unknown owner - C:\WINDOWS\System32\wanwwd\dpsishk.exe
O23 - Service: gfekopoocqcvx - Unknown owner - C:\WINDOWS\System32\ocqcvx\gfekopo.exe
O23 - Service: guktlcspdjm - Unknown owner - C:\WINDOWS\System32\pdjm\guktlcs.exe
O23 - Service: mnbepnscqrvrv - Unknown owner - C:\WINDOWS\System32\nscqrvrv\mnbep.exe
O23 - Service: neovvknhffsraxj - Unknown owner - C:\WINDOWS\System32\ffsraxj\neovvknh.exe
O23 - Service: nrruamoe - Unknown owner - C:\WINDOWS\System32\amoe\nrru.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: swchvaigrnngkw - Unknown owner - C:\WINDOWS\System32\grnngkw\swchvai.exe
O23 - Service: tifjpcvdwg - Unknown owner - C:\WINDOWS\System32\pcvdwg\tifj.exe
O23 - Service: tkmjwhyniy - Unknown owner - C:\WINDOWS\System32\whyniy\tkmj.exe
O23 - Service: xgdhxdoendrg - Unknown owner - C:\WINDOWS\System32\ndrg\xgdhxdoe.exe
O23 - Service: xtcneunv - Unknown owner - C:\WINDOWS\System32\eunv\xtcn.exe