Logfile of HijackThis v1.99.1
Scan saved at 6:12:09 PM, on 11/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Updater.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Doug\Desktop\Hijackthis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thottbot.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://thottbot.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Insight Broadband
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Insight\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?48ba519546ff4732a8db13790c2f0df
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?48ba519546ff4732a8db13790c2f0df
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.insightbb.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: ActiveGS.cab - http://www.virtualap...om/activegs.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-bet...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123719093937
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {93CEA8A4-6059-4E0B-ADDD-73848153DD5E} (CWebLaunchCtl Object) - http://support.gatew...h/weblaunch.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcaf...,21/mcgdmgr.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.co....cab?10,0,910,0
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Spyware doctor log:
Spyware Doctor Activity Report
Generated on 11/28/2005 4:49:17 PM Spyware Doctor Homepage PC Tools Homepage Technical Support
Scans (basic information only):
Scan Results:
scan start: 11/28/2005 5:24:46 PM
scan stop: 11/28/2005 5:40:00 PM
scanned items: 87023
found items: 64
found and ignored: 0
tools used: General Scanner, Process Scanner, Hosts scanner, LSP Scanner, Registry Scanner, Browser Defaults, Favorites and ZoneMap Scanner, ActiveX Scanner, Browser Activity Scanner, Disk Scanner
Infection Name Location Risk
AproposMedia C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\I9FCLSJ2\RedMcCombs_720x300_US_Nov05_RON_I[1].htm Medium
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\573JL50E\bg[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SZ5NEUF5\BuyNowBar_r1_c3[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\NIORZ1C1\shieldlanding_new_06[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\NE03ZT0H\download_red[1].gif High
AproposMedia C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\NE03ZT0H\cpi[1] Medium
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\MHX27E1K\shieldlanding_new_07[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\573JL50E\shieldlanding_new_04[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\MHX27E1K\email[1].gif High
Anti-Phishing C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SN1JEUN9\default[1].css High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\1JVBXHSE\shieldlanding_new_08[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\I9FCLSJ2\alert[1].gif High
AproposMedia C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\2P9IF6LK\nonbranded[1].htm Medium
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\573JL50E\shieldbox_5[1].gif High
AproposMedia C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\573JL50E\SoftwareOnline_CPM_US_Nov05_Banner%202[1].gif Medium
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\NIORZ1C1\competition[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\JYX0P3B3\paypal[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SVJFA8T1\img_multicard_flip[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\I9FCLSJ2\commentssp2[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\KR69MNU9\arrow[2].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\PXG2OZTN\box_top[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\6YBL5VDJ\shield2004[1].css High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\MNWJMR6P\Instant-Rebate[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\PXG2OZTN\saying[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\5WOJDXCT\100percent[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\KR69MNU9\prodfeatures[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\23OBOVWR\features[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SN1JEUN9\shieldlanding_new_05[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SZ5NEUF5\shieldlanding_new_09[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\NIORZ1C1\checkmark[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\1JVBXHSE\BuyNowBar_r1_c2[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\2P9IF6LK\shield2005_blue[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\23OBOVWR\shieldlanding_new_11[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\MHX27E1K\BuyNowBar_r1_c1[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\ININ4T2X\shieldlanding_new_12[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\5WOJDXCT\mostwanted[1].gif High
AproposMedia C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\I9FCLSJ2\B&TMay05-720x300[1].gif Medium
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\072NMBUD\shieldlanding_new_10[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SVJFA8T1\box_bottom[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\JFD77DSW\reliabilityseal[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\2P9IF6LK\box_fill[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SN1JEUN9\getitnowsp2[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\JFD77DSW\system[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\ININ4T2X\designed_fo_windows_xp[1].gif High
Rogue Anti-Spyware Products C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\6YBL5VDJ\90023f[1].htm High
WinFixer 2005 C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\SN1JEUN9\scanner[1].htm Elevated
Known Bad Sites C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\PXG2OZTN\get[1].htm High
AproposMedia C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\JYX0P3B3\DishNetwork_QuinStreet_720x300_DISHswitchIA_US_Nov05[1].gif Medium
Starware C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\I9FCLSJ2\index[1].gif Low
I-Search Desktop Search Toolbar C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\KR69MNU9\LRS_housetop_MtNr40b_120x90[1].gif Elevated
Known Bad Sites C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\JFD77DSW\get[1].media High
AproposMedia C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\NIORZ1C1\CABEY9ZF.swf Medium
Known Bad Sites C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\6YBL5VDJ\v4flash[1].js High
Known Bad Sites C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\MHX27E1K\pop[1].8&c=41 High
Known Bad Sites C:\Documents and Settings\Doug\Local Settings\Temporary Internet Files\Content.IE5\MNWJMR6P\iPod_vid_grn_468-60[1].swf High
eXact Advertising C:\Documents and Settings\Doug\Cookies\doug@trafficmp[1].txt Elevated
Tracking Cookie(s) C:\Documents and Settings\Doug\Cookies\[email protected][2].txt Medium
Known Bad Sites C:\Documents and Settings\Doug\Cookies\doug@directtrack[1].txt High
Tracking Cookie(s) C:\Documents and Settings\Doug\Cookies\doug@atwola[1].txt Medium
Tracking Cookie(s) C:\Documents and Settings\Doug\Cookies\doug@2o7[1].txt Medium
Starware C:\Documents and Settings\Doug\Cookies\doug@starware[2].txt Low
Tracking Cookie(s) C:\Documents and Settings\Doug\Cookies\doug@exitexchange[1].txt Medium
Tracking Cookie(s) C:\Documents and Settings\Doug\Cookies\doug@zedo[2].txt Medium
Known Bad Sites C:\Documents and Settings\Doug\Cookies\[email protected][2].txt High
Please let me know what I need to do from here. Iam still getting pop ups none stop.
