Logfile of HijackThis v1.99.1 Scan saved at 5:06:10 PM, on 5/27/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss[Caution: ExecutableFile] C:\WINDOWS\System32\winlogon[Caution: ExecutableFile] C:\WINDOWS\system32\services[Caution: ExecutableFile] C:\WINDOWS\system32\lsass[Caution: ExecutableFile] C:\WINDOWS\system32\svchost[Caution: ExecutableFile] C:\WINDOWS\System32\svchost[Caution: ExecutableFile] C:\WINDOWS\system32\spoolsv[Caution: ExecutableFile] C:\WINDOWS\Explorer[Caution: ExecutableFile] C:\Program Files\Common Files\AOL\ACS\AOLAcsd[Caution: ExecutableFile] C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon[Caution: ExecutableFile] c:\Program Files\Common Files\Symantec Shared\ccSetMgr[Caution: ExecutableFile] C:\WINDOWS\System32\svchost[Caution: ExecutableFile] C:\WINDOWS\wanmpsvc[Caution: ExecutableFile] c:\Program Files\Common Files\Symantec Shared\ccEvtMgr[Caution: ExecutableFile] C:\Program Files\Java\j2re1.4.2_03\bin\jusched[Caution: ExecutableFile] C:\windows\system\hpsysdrv[Caution: ExecutableFile] C:\WINDOWS\System32\hkcmd[Caution: ExecutableFile] C:\Program Files\Common Files\Symantec Shared\ccApp[Caution: ExecutableFile] C:\WINDOWS\LTMSG[Caution: ExecutableFile] C:\WINDOWS\system32\ps2[Caution: ExecutableFile] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04[Caution: ExecutableFile] C:\WINDOWS\System32\hphmon03[Caution: ExecutableFile] C:\Program Files\Common Files\AOL\ACS\AOLDial[Caution: ExecutableFile] C:\WINDOWS\Nmkluxh[Caution: ExecutableFile] C:\WINDOWS\system32\avifile7[Caution: ExecutableFile] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler[Caution: ExecutableFile] C:\WINDOWS\ALCXMNTR[Caution: ExecutableFile] C:\WINDOWS\system32\MUSICMATCH32[Caution: ExecutableFile] C:\WINDOWS\system32\ccfgnt05[Caution: ExecutableFile] C:\Program Files\Blubster\Blubster[Caution: ExecutableFile] C:\Program Files\Spyware Doctor\swdoctor[Caution: ExecutableFile] C:\PROGRA~1\COMMON~1\AOL\110208~1\EE\AOLHOS~1[Caution: ExecutableFile] C:\Program Files\interMute\SpamSubtract\SpamSub[Caution: ExecutableFile] C:\WINDOWS\system32\LVComS[Caution: ExecutableFile] C:\WINDOWS\system32\wscntfy[Caution: ExecutableFile] C:\WINDOWS\System32\HPHipm09[Caution: ExecutableFile] C:\PROGRA~1\COMMON~1\AOL\110208~1\EE\AOLServiceHost[Caution: ExecutableFile] C:\WINDOWS\system32\wuauclt[Caution: ExecutableFile] c:\Program Files\Norton AntiVirus\navapsvc[Caution: ExecutableFile] C:\Program Files\Windows Media Player\wmplayer[Caution: ExecutableFile] C:\Program Files\America Online 9.0c\waol[Caution: ExecutableFile] C:\Program Files\America Online 9.0c\shellmon[Caution: ExecutableFile] C:\Documents and Settings\Owner\Desktop\bubba's stuff\HijackThis[Caution: ExecutableFile] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customi ... .yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm R3 - Default URLSearchHook is missing O2 - BHO: MyQuickSearch Search Assistant BHO - {04011C11-2F3B-44ed-977C-270CA669C6B2} - C:\Program Files\MyQuickSearch\SrchAstt\1.bin\MQSSRCAS.DLL (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: mqsBar BHO - {0E677221-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: My &Quick Search - {0E677229-E309-4341-81BD-3CC3018BF5B3} - C:\Program Files\MyQuickSearch\bar\1.bin\MQSBAR.DLL (file missing) O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched[Caution: ExecutableFile] O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv[Caution: ExecutableFile] O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd[Caution: ExecutableFile] O4 - HKLM\..\Run: [updateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray[Caution: ExecutableFile]" /r O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD[Caution: ExecutableFile] O4 - HKLM\..\Run: [VTTimer] VTTimer[Caution: ExecutableFile] O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp[Caution: ExecutableFile]" O4 - HKLM\..\Run: [LTMSG] LTMSG[Caution: ExecutableFile] 7 O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2[Caution: ExecutableFile] O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04[Caution: ExecutableFile] O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03[Caution: ExecutableFile] O4 - HKLM\..\Run: [bbqiipi] C:\WINDOWS\System32\bretiuxh[Caution: ExecutableFile] O4 - HKLM\..\Run: [ozir] C:\WINDOWS\ozir[Caution: ExecutableFile] O4 - HKLM\..\Run: [wlqr] C:\WINDOWS\wlqr[Caution: ExecutableFile] O4 - HKLM\..\Run: [wjkd] C:\WINDOWS\wjkd[Caution: ExecutableFile] O4 - HKLM\..\Run: [gxkn] C:\WINDOWS\gxkn[Caution: ExecutableFile] O4 - HKLM\..\Run: [odohofwh] C:\WINDOWS\odohofwh[Caution: ExecutableFile] O4 - HKLM\..\Run: [abqxsbup] C:\WINDOWS\abqxsbup[Caution: ExecutableFile] O4 - HKLM\..\Run: [gpyb] C:\WINDOWS\gpyb[Caution: ExecutableFile] O4 - HKLM\..\Run: [bmvul] C:\WINDOWS\bmvul[Caution: ExecutableFile] O4 - HKLM\..\Run: [hcv] C:\WINDOWS\hcv[Caution: ExecutableFile] O4 - HKLM\..\Run: [crcjwf] C:\WINDOWS\crcjwf[Caution: ExecutableFile] O4 - HKLM\..\Run: [ozqf] C:\WINDOWS\ozqf[Caution: ExecutableFile] O4 - HKLM\..\Run: [ajin] C:\WINDOWS\ajin[Caution: ExecutableFile] O4 - HKLM\..\Run: [bij] C:\WINDOWS\bij[Caution: ExecutableFile] O4 - HKLM\..\Run: [ab2f6] C:\WINDOWS\gntfngu[Caution: ExecutableFile] O4 - HKLM\..\Run: [X91lncD] C:\documents and settings\dawn\local settings\temp\X91lncD[Caution: ExecutableFile] O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial[Caution: ExecutableFile] O4 - HKLM\..\Run: [srnm] C:\WINDOWS\Nmkluxh[Caution: ExecutableFile] O4 - HKLM\..\Run: [Jawa322] C:\WINDOWS\jawa32[Caution: ExecutableFile] O4 - HKLM\..\Run: [xbeo] C:\WINDOWS\oqrt[Caution: ExecutableFile] O4 - HKLM\..\Run: [YS2Ck] C:\documents and settings\owner\local settings\temp\YS2Ck[Caution: ExecutableFile] O4 - HKLM\..\Run: [575711536d96] C:\WINDOWS\system32\avifile7[Caution: ExecutableFile] O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102085546\EE\AOLHostManager[Caution: ExecutableFile] O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler[Caution: ExecutableFile]" O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL[Caution: ExecutableFile]" -Run O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR[Caution: ExecutableFile] O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart[Caution: ExecutableFile] O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray[Caution: ExecutableFile] O4 - HKLM\..\Run: [Musicmatch Jukebox Player] MUSICMATCH32[Caution: ExecutableFile] O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost[Caution: ExecutableFile] O4 - HKLM\..\Run: [a0f8f94ecfbb] C:\WINDOWS\system32\ccfgnt05[Caution: ExecutableFile] O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay[Caution: ExecutableFile] SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [blubster] C:\Program Files\Blubster\Blubster[Caution: ExecutableFile] SILENT O4 - HKLM\..\Run: [v3tg3nR] ipvta[Caution: ExecutableFile] O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS[Caution: ExecutableFile]" /background O4 - HKCU\..\Run: [Jawa322] C:\WINDOWS\jawa32[Caution: ExecutableFile] O4 - HKCU\..\Run: [spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor[Caution: ExecutableFile]" /Q O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0c\AOL[Caution: ExecutableFile]" -b O4 - HKCU\..\Run: [e02mRhd2U] inkfaxui[Caution: ExecutableFile] O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480[Caution: ExecutableFile] O4 - HKCU\..\RunOnce: [Musicmatch Jukebox Player] MUSICMATCH32[Caution: ExecutableFile] O4 - Startup: PowerReg Scheduler[Caution: ExecutableFile] O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub[Caution: ExecutableFile] O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576[Caution: ExecutableFile] O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08[Caution: ExecutableFile] O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf[Caution: ExecutableFile] O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL[Caution: ExecutableFile]/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs[Caution: ExecutableFile] O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs[Caution: ExecutableFile] O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409 O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wo ... rdmojo.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1437/ ... brkpie.cab O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promot ... WebAAS.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZI ... b34246.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolweb01.pogo.com/game/deluxe/in ... der_v6.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://moviefone.kontiki.com/securedeli ... in/kdx.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{240DEFAB-6439-462A-AEAE-04186A914523}: NameServer = 205.188.146.145 O17 - HKLM\System\CS1\Services\Tcpip\..\{240DEFAB-6439-462A-AEAE-04186A914523}: NameServer = 205.188.146.145 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd[Caution: ExecutableFile] O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon[Caution: ExecutableFile] O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv[Caution: ExecutableFile] O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr[Caution: ExecutableFile] O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc[Caution: ExecutableFile] O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr[Caution: ExecutableFile] O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc[Caution: ExecutableFile] O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09[Caution: ExecutableFile] O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan[Caution: ExecutableFile] O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc[Caution: ExecutableFile] peez and ty, o and w/e crap you find, i dont know about cus 6 people use this pc :lol: and my b-day wa sin jan. its now may. and im so glad my dad "got me my own pc,like he promised" :lol: :lol: :lol: :roll: :roll: :evil: :( w/e thx guys :twisted: 8) bubba 8) :twisted: