Logfile of HijackThis v1.99.1
Scan saved at 2:51:23 PM, on 10/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\Explorer.exe
d:\windows\system32\ftpdcau.exe
E:\AntiVir\AVWIN.EXE
E:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe D:\WINDOWS\Nail.exe
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe,,SKEYS /I
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - D:\WINDOWS\dsr.dll
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - D:\WINDOWS\system32\vvpuitut.dll
O4 - HKLM\..\Run: [CAPDPSRV] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CAPDPSRV.EXE
O4 - HKLM\..\Run: [MooQ6Xm7X] D:\documents and settings\niki\local settings\temp\MooQ6Xm7X.exe
O4 - HKLM\..\Run: [0nHfA] D:\WINDOWS\flkbu.exe
O4 - HKLM\..\Run: [09¿Ì*ú]Mú*ÀaîžaaøYD:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\flkbu.exe
O4 - HKLM\..\Run: [09¿Ì*ú*ÀaîžaaøY§ÄD:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\flkbu.exe
O4 - HKLM\..\Run: [09¿Ì*ÀaîžaaøY§Ä_ÜD:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\flkbu.exe
O4 - HKLM\..\Run: [09¿Ì*ÀaîžaîžaaøY§D:\Program Files\ISTsvc\istsvc.exe] D:\WINDOWS\flkbu.exe
O4 - HKLM\..\Run: [4bM] C:\windows\4bM.exe
O4 - HKLM\..\Run: [Wq] C:\windows\Wq.exe
O4 - HKLM\..\Run: [a8BhOLZ] D:\documents and settings\tia\local settings\temp\a8BhOLZ.exe
O4 - HKLM\..\Run: [NRh] D:\documents and settings\tia\local settings\temp\NRh.exe
O4 - HKLM\..\Run: [G] C:\windows\G.exe
O4 - HKLM\..\Run: [R3O] C:\windows\R3O.exe
O4 - HKLM\..\Run: [Wtlloqf] C:\Program Files\Zlqbbt\Kpnuwk.exe
O4 - HKLM\..\Run: [TizzleTalk] D:\Program Files\TizzleTalk\TizzleTalk.exe
O4 - HKLM\..\Run: [IMGrabber2] D:\WINDOWS\system32\IMGrabber2.exe UI
O4 - HKLM\..\Run: [checkrun] D:\windows\system32\elitedfo32.exe
O4 - HKLM\..\Run: [C50RdCVjP] D:\windows\system32\C50RdCVjP.exe
O4 - HKLM\..\Run: [WinNite] D:\WINDOWS\sxconfig.exe
O4 - HKLM\..\Run: [WNMP System] WNMPS.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] D:\PROGRA~1\MYWEBS~1\bar\5.bin\mwsoemon.exe
O4 - HKLM\..\Run: [BlahDefyBall32] D:\Documents and Settings\All Users\Application Data\blue creative blah defy\creative owns.exe
O4 - HKLM\..\Run: [Dinst] D:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [lanbrup] D:\WINDOWS\system32\lanbrup.exe
O4 - HKLM\..\Run: [Sysnet] D:\DOCUME~1\PHONIC~1\LOCALS~1\Temp\sysnet.exe
O4 - HKLM\..\Run: [System service62] D:\WINDOWS\etb\pokapoka63.exe
O4 - HKLM\..\Run: [bindatadalesoftware] D:\Documents and Settings\All Users\Application Data\amen name bin data\PartWindow.exe
O4 - HKLM\..\Run: [lsass] D:\windows\system32\elitexzn32.exe
O4 - HKLM\..\Run: [System service65] D:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [System service66] D:\WINDOWS\etb\pokapoka66.exe
O4 - HKLM\..\Run: [System service67] D:\WINDOWS\\etb\pokapoka67.exe
O4 - HKLM\..\Run: [uqetrre] D:\WINDOWS\uqetrre.EXE
O4 - HKLM\..\Run: [System service68] D:\WINDOWS\\etb\pokapoka68.exe
O4 - HKLM\..\Run: [System service69] D:\WINDOWS\\etb\pokapoka69.exe
O4 - HKLM\..\Run: [System service70] D:\WINDOWS\etb\pokapoka70.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [biopvsa] d:\windows\system32\ftpdcau.exe r
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = D:\Program Files\America Online 9.0\aoltray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downlo...thv32_EN_XP.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX28.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.web...otoUploader.CAB
O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.c...ureUploader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...5.33/ttinst.cab
O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.re...lbar/lexico.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.ao.../ampx_en_dl.cab
O20 - AppInit_DLLs: repairs.dll