-Charles
Here's my HiJackThis File..
Logfile of HijackThis v1.99.1
Scan saved at 1:28:33 PM, on 6/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\TPSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\panda software\panda titanium 2006 antivirus + antispyware\firewall\PNMSRV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\psimsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINDOWS\MMKeybd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\WinPop\winpop.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\tnatnywa.exe
C:\WINDOWS\system32\xvsnfokk.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\o02PrEz\o02PrEz1065.exe
C:\WINDOWS\system32\o02PrEz\o02PrEz1065.exe
C:\WINDOWS\retadpu2000219.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Charles\Application Data\Mozilla\Profiles\default\euyuxbf0.slt\prefs.js)
O1 - Hosts: 66.159.18.187 www.n69.com
O1 - Hosts: 66.159.18.187 www.pillscash.com
O1 - Hosts: 66.159.18.187 cart.penispill.com
O1 - Hosts: 66.159.18.187 www.pillsmoney.com
O1 - Hosts: 66.159.18.187 www.pillmedics.com
O1 - Hosts: 66.159.18.187 www.big-[bleep].com
O1 - Hosts: 66.159.18.187 www.pluspills1.com
O1 - Hosts: 66.159.18.187 www.morepenis.com
O1 - Hosts: 66.159.18.187 www.1shoppingcart.com
O1 - Hosts: 66.159.18.187 www.herbalo.com
O1 - Hosts: 66.159.18.187 www.penilesecrets.com
O1 - Hosts: 66.159.18.187 www.penispill.com
O1 - Hosts: 66.159.18.187 penismedical.net
O1 - Hosts: 66.159.18.187 www.penismedical.net
O1 - Hosts: 66.159.18.187 www.herbalbucks.com
O1 - Hosts: 66.159.18.187 www.tv69.com
O1 - Hosts: 66.159.18.184 the.sextracker.com
O1 - Hosts: 66.159.18.184 lobby.sexlist.com
O1 - Hosts: 66.159.18.184 in.paycounter.com
O1 - Hosts: 66.159.18.184 adv.sexcounter.com
O1 - Hosts: 66.159.18.184 select.2000charge.com
O1 - Hosts: 66.159.18.184 secure.2000charge.com
O1 - Hosts: 66.159.18.184 www.signup.globill-systems.com
O1 - Hosts: 66.159.18.184 secure.visionbill.net
O1 - Hosts: 66.159.18.184 www.dibill.com
O1 - Hosts: 66.159.18.184 secure.dpbill.com
O1 - Hosts: 66.159.18.184 secure.dutchbilling.com
O1 - Hosts: 66.159.18.184 secure.pswbilling.com
O1 - Hosts: 66.159.18.184 www.maximumcash.com
O1 - Hosts: 66.159.18.184 www.adultrevenueservice.com
O1 - Hosts: 66.159.18.184 www.eroticacash.com
O1 - Hosts: 66.159.18.184 www.oxcash.com
O1 - Hosts: 66.159.18.184 track.oxcash.com
O1 - Hosts: 66.159.18.184 potd.oxcash.com
O1 - Hosts: 66.159.18.184 clicks2.oxcash.com
O1 - Hosts: 66.159.18.184 www.webmastersmakemoney.com
O1 - Hosts: 66.159.18.184 clicks.nastydollars.com
O1 - Hosts: 66.159.18.184 www.lightspeedcash.com
O1 - Hosts: 66.159.18.184 db.fetishcash.com
O1 - Hosts: 66.159.18.184 ctc.amateurpages.com
O1 - Hosts: 66.159.18.184 www2.karupspc.com
O1 - Hosts: 66.159.18.184 www.iteens.com
O1 - Hosts: 66.159.18.184 click.payserve.com
O1 - Hosts: 66.159.18.184 vip.mtree.com
O1 - Hosts: 66.159.18.184 c.fsx.com
O1 - Hosts: 66.159.18.184 adultfriendfinder.com
O1 - Hosts: 66.159.18.184 php.offshoreclicks.com
O1 - Hosts: 66.159.18.184 links.lifetimebucks.com
O1 - Hosts: 66.159.18.184 cgi.gammae.com
O1 - Hosts: 66.159.18.184 click.passiondollars.com
O1 - Hosts: 66.159.18.184 www.fatpockets.com
O1 - Hosts: 66.159.18.184 link.siccash.com
O1 - Hosts: 66.159.18.184 www.clickcash.com
O1 - Hosts: 66.159.18.184 www.scoreland.com
O1 - Hosts: 66.159.18.184 www.makingitpay.com
O1 - Hosts: 66.159.18.184 www.hpic.com
O1 - Hosts: 66.159.18.184 referral.topbucks.com
O1 - Hosts: 66.159.18.184 partner.globill-systems.com
O1 - Hosts: 66.159.18.184 www.pornstardollars.com
O1 - Hosts: 66.159.18.184 traffic.acpay.com
O1 - Hosts: 66.159.18.184 www.cashforlink.com
O1 - Hosts: 66.159.18.184 clickcash.webpower.com
O1 - Hosts: 66.159.18.184 www.dollars4babes.com
O1 - Hosts: 66.159.18.184 www.sexfantasyzone.com
O1 - Hosts: 66.159.18.184 www.twistyscash.com
O1 - Hosts: 66.159.18.184 www.freeticketcash.com
O1 - Hosts: 66.159.18.184 www.hawgscash.com
O1 - Hosts: 66.159.18.184 www.freeezinebucks.com
O1 - Hosts: 66.159.18.184 www.nastydollars.com
O1 - Hosts: 66.159.18.184 www.deluxepass.com
O1 - Hosts: 66.159.18.184 clicks.oxcash.com
O1 - Hosts: 66.159.18.184 ww2.amateur-pages.com
O1 - Hosts: 66.159.18.184 stats.allliquid.com
O1 - Hosts: 66.159.18.184 secure1.websitebilling.com
O1 - Hosts: 66.159.18.184 www.adultmovienetwork.com
O1 - Hosts: 66.159.18.184 www.totally4freecash.com
O1 - Hosts: 66.159.18.184 php.offshoreclicks.com
O1 - Hosts: 66.159.18.184 www.nocreditcard.com
O1 - Hosts: 66.159.18.184 clicks.uni-cash.com
O1 - Hosts: 66.159.18.184 www.clubpix.com
O1 - Hosts: 66.159.18.184 programs.wegcash.com
O1 - Hosts: 66.159.18.184 in.cybererotica.com
O1 - Hosts: 66.159.18.184 www.cybererotica.com
O1 - Hosts: 66.159.18.184 cybererotica.com
O1 - Hosts: 66.159.18.184 dollartraffic.com
O1 - Hosts: 66.159.18.184 www.xxxesscash.com
O1 - Hosts: 66.159.18.184 www.maturemoney.com
O1 - Hosts: 66.159.18.184 www.xpays.com
O1 - Hosts: 66.159.18.184 www.trueclicks.com
O1 - Hosts: 66.159.18.184 www.sexhit.com
O1 - Hosts: 66.159.18.184 www.blacksonblondes.com
O1 - Hosts: 66.159.18.184 partners.hotgold.com
O1 - Hosts: 66.159.18.184 www.thecashzone.com
O1 - Hosts: 66.159.18.184 db.smutcash.com
O1 - Hosts: 66.159.18.184 www.eroticcash.com
O1 - Hosts: 66.159.18.184 home.vividvip.com
O1 - Hosts: 66.159.18.184 www.stiffycash.com
O1 - Hosts: 66.159.18.184 gotd.stiffycash.com
O1 - Hosts: 66.159.18.184 cash.helmy.com
O1 - Hosts: 66.159.18.184 adultmegacash.com
O1 - Hosts: 66.159.18.184 amc2.adultmegacash.com
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102131130\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Registry Toolkit] C:\Program Files\Registry Toolkit\RegToolkit.exe /scan
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\jvcvnciu.dll",forkonce
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu2000219.exe 61A847B5BBF72810329B385473F001F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\RunOnce: [Panda_cleaner_145083] C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavdr.exe 145083
O4 - HKLM\..\RunOnce: [Panda_cleaner_96188] C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavdr.exe 96188
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantispyware.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.drivecleaner.com (HKLM)
O15 - Trusted Zone: *.errorprotector.com (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantispyware.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://www.imgag.com...tall/AxCtp2.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6DED4415-9792-4E32-A720-1B988D69DB7A}: NameServer = 71.250.0.12 68.237.161.12
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\xvsnfokk.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Network Manager (PNMSRV) - Panda Software - c:\program files\panda software\panda titanium 2006 antivirus + antispyware\firewall\PNMSRV.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\psimsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\TPSrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe