Logfile of HijackThis v1.99.1
Scan saved at 7:38:47 PM, on 2/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLACSD.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Updater.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\YAHOO!\YOP\yop.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Common Files\AOL\1129685037\ee\AOLSoftware.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\2Wire Wireless\Client Manager\CMTWO.EXE
C:\America Online 6.0\aoltray.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\HJT\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] "C:\PROGRA~1\YAHOO!\YOP\yop.exe" /autostart
O4 - HKLM\..\Run: [YBrowser] "C:\Program Files\Yahoo!\browser\ybrwicon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1129685037\ee\AOLSoftware.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: America Online 6.0 Tray Icon.lnk = C:\America Online 6.0\aoltray.exe
O4 - Global Startup: 2Wire Wireless Client Manager.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} -
http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) -
http://www.jetsetpoker.com/setup.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLACSD.EXE
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
hosts.old;C:\WINDOWS\system32\drivers\etc;Trojan.Qhost;Deleted.;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_2.0.6.1;Probably BACKDOOR.Trojan;;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_2.0.7.1;Probably BACKDOOR.Trojan;;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\AIMSUD338;Probably BACKDOOR.Trojan;;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ASP423.tmp\aspapp;Probably BACKDOOR.Trojan;;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\3899.1.16;Probably BACKDOOR.Trojan;;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\3991.4.16;Probably BACKDOOR.Trojan;;
setup.exe;C:\Program Files\Common Files\AOL\Backup\ACS\Current\Suite;Probably BACKDOOR.Trojan;;
aolsetup.exe;C:\Program Files\Common Files\AOL\1129685037\ee\services\softwareUpdate\ver2_14_2_30;Probably BACKDOOR.Trojan;;
setup.exe;C:\Program Files\AOL\Installers\ASP 2.0;Probably BACKDOOR.Trojan;;
A0121194.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1182;Trojan.StatBlasterAd;Incurable.Moved.;
A0121484.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1187;Probably BACKDOOR.Trojan;;
A0123317.old;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1206;Trojan.Qhost;Deleted.;
A0116734.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1143;Trojan.Fakealert;Deleted.;
A0117874.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1145;Probably BACKDOOR.Trojan;;
A0118391.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1148;Trojan.Fakealert;Deleted.;
A0119758.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1169;Trojan.Virtumod;Deleted.;
A0119775.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119776.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119777.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119782.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.DownLoader.17379;Deleted.;
A0119784.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119785.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119786.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119787.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119788.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.MediaTicket;;
A0119789.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.MulDrop.4313;Deleted.;
A0119790.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.MulDrop.4313;Deleted.;
A0119791.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.DownLoader.11426;Deleted.;
A0119794.exe\data001;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171\A0119794.exe;Adware.Bagon;;
A0119794.exe\data002;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171\A0119794.exe;Adware.Bagon;;
A0119794.exe\data003;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171\A0119794.exe;Trojan.DownLoader.10588;;
A0119794.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Archive contains infected objects;Moved.;
A0119795.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Winpop;Deleted.;
A0119797.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.Adrotate;;
A0119799.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.Ezula;;
A0119800.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.ZenoSearch;;
A0119801.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.ZenoSearch;;
A0119802.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.IEDriver;;
A0119803.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.MediaTicket;;
A0119804.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.BookedSpace;;
A0119805.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.DownLoader.10588;Deleted.;
A0119806.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.Relevant;;
A0119807.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.Mirarbar;;
A0119809.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.SurfAcc;;
A0119812.DLL;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Trojan.Virtumod;Deleted.;
A0119832.ocx;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1171;Adware.Gdown;;
A0120083.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1172;Adware.ClickSpring;;
A0120097.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1172;Trojan.Juan;Deleted.;
A0120383.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1172;Trojan.Virtumod;Deleted.;
A0120384.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1172;Trojan.Virtumod;Deleted.;
A0120385.dll;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1172;Trojan.Virtumod;Deleted.;
A0116169.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1140;Trojan.Fakealert;Deleted.;
A0116194.exe;C:\System Volume Information\_restore{5A31A68A-3074-412B-80BD-6AA56718040D}\RP1140;Trojan.DownLoader.10963;Deleted.;
jisrbvfx.dll.bad;C:\VundoFix Backups;Trojan.Juan;Deleted.;
backup-20070115-105435-134.dll;C:\HJT\backups;Adware.ClickSpring;;
Thanks!