Logfile of HijackThis v1.99.0
Scan saved at 10:42:20 PM, on 12/23/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\documents and settings\gray family\local settings\temp\mQlLZ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\??chost.exe
C:\Documents and Settings\Gray Family\Application Data\eetu.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\LimeWire\LimeWire 4.2.3 Pro\LimeWire.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Gray Family\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.dell4me.com...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.optonline.net...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
www.dell4me.com...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
www.optonline.net...
O2 - BHO: AcroIEHlprObj Class - [06849E9F-C8D7-4D59-B87D-784B7D6BE0B3] - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DriveLetterAccess - [5CA3D70E-1895-11CF-8E15-001234567890] - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security - [9ECB9560-04F9-4bbc-943D-298DDF1699E1] - C:\Program Files\Common Files\Symantec
Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - [BDF3E430-B101-42AD-A544-FADC6B084872] - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Search Help - [E8EAEB34-F7B5-4C55-87FF-720FAF53D841] - C:\Documents and Settings\Gray Family\Local Settings\Temp\UB.dll
O2 - BHO: (no name) - [F49DE469-22FE-070B-883D-08C53E0810B6] - C:\WINDOWS\System32\lookwqmv.dll
O3 - Toolbar: Norton Internet Security - [0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7] - C:\Program Files\Common Files\Symantec
Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - [42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6] - C:\Program Files\Norton Internet Security\Norton
AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mQlLZ] C:\documents and settings\gray family\local settings\temp\mQlLZ.exe
O4 - HKLM\..\Run: [LexPPS.exe] C:\WINDOWS\system32\lexpps.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Leusrazz] C:\WINDOWS\System32\??chost.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Gray Family\Application Data\eetu.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - [08B0E5C0-4FCB-11CF-AAA5-00401C608501] - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - [08B0E5C0-4FCB-11CF-AAA5-00401C608501] - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - [AC9E2541-2814-11d5-BC6D-00B0D0A1DE45] - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - [CD67F990-D8E9-11d2-98FE-00C0F0318AFE] - (no file)
O9 - Extra button: Messenger - [FB5F1910-F110-11d2-BB9E-00C04F795683] - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - [FB5F1910-F110-11d2-BB9E-00C04F795683] - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: RaptisoftGameLoader -
www.miniclip.com...
O16 - DPF: [39B0684F-D7BF-4743-B050-FDC3F48F7E3B] (FilePlanet Download Control Class) -
www.fileplanet.com...
O16 - DPF: [56336BCB-3D8A-11D6-A00B-0050DA18DE71] (RdxIE Class) -
software-dl.real.com...
O16 - DPF: [62475759-9E84-458E-A1AB-5D2C442ADFDE] -
a1540.g.akamai.net...
O16 - DPF: [6414512B-B978-451D-A0D8-FCFDF33E833C] (WUWebControl Class) -
v5.windowsupdate.microsoft.com...
O16 - DPF: [70BA88C8-DAE8-4CE9-92BB-979C4A75F53B] (GSDACtl Class) -
launch.gamespyarcade.com...
O16 - DPF: [77E32299-629F-43C6-AB77-6A1E6D7663F6] -
www.nick.com...
O16 - DPF: [90C9629E-CD32-11D3-BBFB-00105A1F0D68] -
www.installengine.com...
O16 - DPF: [AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A] -
install.wildtangent.com...
O16 - DPF: [B942A249-D1E7-4C11-98AE-FCB76B08747F] (RealArcadeRdxIE Class) -
games-dl.real.com...
O16 - DPF: [DF780F87-FF2B-4DF8-92D0-73DB16A1543A] (PopCapLoader Object) -
anu.popcap.com...
O16 - DPF: [F54C1137-5E34-4B95-95A5-BA56D4D8D743] (Secure Delivery) -
www.gamespot.com...
O16 - DPF: [FA13A9FA-CA9B-11D2-9780-00104B242EA3] -
install.wildtangent.com...
O23 - Service: Adobe LM Service - Unknown - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton
AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TuneUp WinStyler Theme Service - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
thats it...