Logfile of HijackThis v1.99.1
Scan saved at 3:08:17 AM, on 4/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ron\Desktop\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} -
http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} -
http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://www.comcast.net
O15 - Trusted Zone:
http://flyff.gpotato.com
O15 - Trusted Zone: www.myspace.com
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: winjrs32 - C:\WINDOWS\SYSTEM32\winjrs32.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
********
2:24 AM: | Start of Session, Friday, April 21, 2006 |
2:24 AM: Spy Sweeper started
2:24 AM: Sweep initiated using definitions version 662
2:24 AM: Found Adware: coolwebsearch (cws)
2:24 AM: HKCR\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\inprocserver32\ (2 subtraces) (ID = 1183061)
2:24 AM: winres.dll (ID = 1183061)
2:24 AM: Starting Memory Sweep
2:29 AM: Memory Sweep Complete, Elapsed Time: 00:05:18
2:29 AM: Starting Registry Sweep
2:29 AM: Found Adware: altnet
2:29 AM: HKCR\adm4.adm4.1\ (3 subtraces) (ID = 103443)
2:29 AM: HKCR\adm4.adm4\ (3 subtraces) (ID = 103444)
2:29 AM: HKCR\adm25.adm25.1\ (3 subtraces) (ID = 103445)
2:29 AM: HKCR\adm25.adm25\ (3 subtraces) (ID = 103446)
2:29 AM: HKCR\appid\adm.exe\ (1 subtraces) (ID = 103448)
2:29 AM: HKCR\appid\altnet signing module.exe\ (1 subtraces) (ID = 103449)
2:29 AM: HKLM\software\classes\adm4.adm4.1\ (3 subtraces) (ID = 103484)
2:29 AM: HKLM\software\classes\adm4.adm4\ (3 subtraces) (ID = 103485)
2:29 AM: HKLM\software\classes\adm25.adm25.1\ (3 subtraces) (ID = 103486)
2:29 AM: HKLM\software\classes\adm25.adm25\ (3 subtraces) (ID = 103487)
2:29 AM: HKLM\software\classes\appid\adm.exe\ (1 subtraces) (ID = 103488)
2:29 AM: HKLM\software\classes\appid\altnet signing module.exe\ (1 subtraces) (ID = 103489)
2:29 AM: HKLM\software\classes\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}\ (23 subtraces) (ID = 103494)
2:29 AM: HKCR\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\ (11 subtraces) (ID = 107171)
2:29 AM: HKLM\software\classes\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\ (11 subtraces) (ID = 108560)
2:29 AM: HKLM\software\classes\typelib\{344ee577-2027-4714-82ff-0d7538488547}\ (9 subtraces) (ID = 109797)
2:29 AM: HKLM\software\classes\winres.windowsresources.1\ (3 subtraces) (ID = 109808)
2:29 AM: HKLM\software\classes\winres.windowsresources\ (5 subtraces) (ID = 109809)
2:29 AM: HKCR\typelib\{344ee577-2027-4714-82ff-0d7538488547}\ (9 subtraces) (ID = 112503)
2:29 AM: HKCR\winres.windowsresources.1\ (3 subtraces) (ID = 112518)
2:29 AM: HKCR\winres.windowsresources\ (5 subtraces) (ID = 112519)
2:29 AM: Found Adware: purityscan
2:29 AM: HKLM\software\clickspring\ (2 subtraces) (ID = 137699)
2:29 AM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaticketsinstaller.ocx\ (2 subtraces) (ID = 137986)
2:29 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaticketsinstaller.ocx (ID = 139077)
2:29 AM: Found Adware: topsearch
2:29 AM: HKCR\clsid\{b7156514-a76c-4545-9d5b-a4e1d02c7aec}\ (23 subtraces) (ID = 143925)
2:29 AM: HKLM\software\classes\topsearch.tslink\ (5 subtraces) (ID = 143926)
2:29 AM: HKLM\software\classes\topsearch.tslink.1\ (3 subtraces) (ID = 143927)
2:29 AM: HKLM\software\classes\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (9 subtraces) (ID = 143928)
2:29 AM: HKCR\topsearch.tslink\ (5 subtraces) (ID = 143929)
2:29 AM: HKCR\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (9 subtraces) (ID = 143930)
2:29 AM: Found Adware: rx toolbar
2:29 AM: HKCR\rxresult.rxresultfilter\ (3 subtraces) (ID = 729537)
2:29 AM: HKCR\rxresult.rxresultfilter\clsid\ (1 subtraces) (ID = 729539)
2:29 AM: HKCR\rxresult.rxresultfilter.1\ (3 subtraces) (ID = 729541)
2:29 AM: HKCR\rxresult.rxresultfilter.1\clsid\ (1 subtraces) (ID = 729543)
2:29 AM: HKCR\rxresult.rxresulttracker\ (3 subtraces) (ID = 729545)
2:29 AM: HKCR\rxresult.rxresulttracker\clsid\ (1 subtraces) (ID = 729547)
2:29 AM: HKCR\rxresult.rxresulttracker.1\ (3 subtraces) (ID = 729549)
2:29 AM: HKCR\rxresult.rxresulttracker.1\clsid\ (1 subtraces) (ID = 729551)
2:29 AM: HKCR\clsid\{2ab289ae-4b90-4281-b2ae-1f4bb034b647}\ (10 subtraces) (ID = 729553)
2:29 AM: HKCR\clsid\{59879fa4-4790-461c-a1cc-4ec4de4ca483}\ (8 subtraces) (ID = 729564)
2:29 AM: HKCR\typelib\{05563f82-69a7-40a6-8670-153b635a7ef6}\ (9 subtraces) (ID = 729573)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter\ (3 subtraces) (ID = 729616)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter\clsid\ (1 subtraces) (ID = 729618)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter.1\ (3 subtraces) (ID = 729620)
2:29 AM: HKLM\software\classes\rxresult.rxresultfilter.1\clsid\ (1 subtraces) (ID = 729622)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker\ (3 subtraces) (ID = 729624)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker\clsid\ (1 subtraces) (ID = 729626)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker.1\ (3 subtraces) (ID = 729628)
2:29 AM: HKLM\software\classes\rxresult.rxresulttracker.1\clsid\ (1 subtraces) (ID = 729630)
2:29 AM: HKLM\software\classes\clsid\{2ab289ae-4b90-4281-b2ae-1f4bb034b647}\ (10 subtraces) (ID = 729632)
2:29 AM: HKLM\software\classes\clsid\{59879fa4-4790-461c-a1cc-4ec4de4ca483}\ (8 subtraces) (ID = 729643)
2:29 AM: HKLM\software\classes\typelib\{05563f82-69a7-40a6-8670-153b635a7ef6}\ (9 subtraces) (ID = 729652)
2:29 AM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{59879fa4-4790-461c-a1cc-4ec4de4ca483}\ (ID = 729662)
2:29 AM: Found Trojan Horse: trojan agent winlogonhook
2:29 AM: HKLM\software\microsoft\mssmgr\ (14 subtraces) (ID = 937101)
2:30 AM: Registry Sweep Complete, Elapsed Time:00:00:15
2:30 AM: Starting Cookie Sweep
2:30 AM: Found Spy Cookie: 2o7.net cookie
2:30 AM: ron@2o7[1].txt (ID = 1957)
2:30 AM: Found Spy Cookie: yieldmanager cookie
2:30 AM: ron@ad.yieldmanager[1].txt (ID = 3751)
2:30 AM: Found Spy Cookie: adrevolver cookie
2:30 AM: ron@adrevolver[2].txt (ID = 2088)
2:30 AM: ron@adrevolver[3].txt (ID = 2088)
2:30 AM: Found Spy Cookie: pointroll cookie
2:30 AM: ron@ads.pointroll[1].txt (ID = 3148)
2:30 AM: Found Spy Cookie: advertising cookie
2:30 AM: ron@advertising[2].txt (ID = 2175)
2:30 AM: Found Spy Cookie: aptimus cookie
2:30 AM: ron@aptimus[2].txt (ID = 2233)
2:30 AM: Found Spy Cookie: atwola cookie
2:30 AM: ron@ar.atwola[1].txt (ID = 2256)
2:30 AM: Found Spy Cookie: ask cookie
2:30 AM: ron@ask[1].txt (ID = 2245)
2:30 AM: Found Spy Cookie: atlas dmt cookie
2:30 AM: ron@atdmt[2].txt (ID = 2253)
2:30 AM: ron@atwola[1].txt (ID = 2255)
2:30 AM: Found Spy Cookie: casalemedia cookie
2:30 AM: ron@casalemedia[1].txt (ID = 2354)
2:30 AM: Found Spy Cookie: overture cookie
2:30 AM: ron@data2.perf.overture[2].txt (ID = 3106)
2:30 AM: Found Spy Cookie: ru4 cookie
2:30 AM: ron@edge.ru4[1].txt (ID = 3269)
2:30 AM: Found Spy Cookie: fastclick cookie
2:30 AM: ron@fastclick[1].txt (ID = 2651)
2:30 AM: Found Spy Cookie: mediaplex cookie
2:30 AM: ron@mediaplex[2].txt (ID = 6442)
2:30 AM: ron@network.aptimus[1].txt (ID = 2235)
2:30 AM: Found Spy Cookie: realmedia cookie
2:30 AM: ron@network.realmedia[1].txt (ID = 3236)
2:30 AM: ron@perf.overture[1].txt (ID = 3106)
2:30 AM: Found Spy Cookie: questionmarket cookie
2:30 AM: ron@questionmarket[2].txt (ID = 3217)
2:30 AM: ron@realmedia[1].txt (ID = 3235)
2:30 AM: Found Spy Cookie: revenue.net cookie
2:30 AM: ron@revenue[1].txt (ID = 3257)
2:30 AM: Found Spy Cookie: serving-sys cookie
2:30 AM: ron@serving-sys[2].txt (ID = 3343)
2:30 AM: Found Spy Cookie: trafficmp cookie
2:30 AM: ron@trafficmp[2].txt (ID = 3581)
2:30 AM: Found Spy Cookie: tribalfusion cookie
2:30 AM: ron@tribalfusion[1].txt (ID = 3589)
2:30 AM: Found Spy Cookie: tripod cookie
2:30 AM: ron@tripod[1].txt (ID = 3591)
2:30 AM: Found Spy Cookie: zedo cookie
2:30 AM: ron@zedo[1].txt (ID = 3762)
2:30 AM: Cookie Sweep Complete, Elapsed Time: 00:00:04
2:30 AM: Starting File Sweep
2:30 AM: c:\program files\rxtoolbar (8 subtraces) (ID = -2147476417)
2:30 AM: Found Adware: bullguard popup ad
2:30 AM: c:\windows\temp\bullguard (1 subtraces) (ID = -2147476409)
2:30 AM: c:\windows\temp\altnet (18 subtraces) (ID = -2147481435)
2:35 AM: pminstall.cab (ID = 49857)
2:35 AM: backup-20060417-195630-627.inf (ID = 73158)
2:38 AM: dminfo3.cab (ID = 49824)
2:40 AM: winres.dll (ID = 282896)
2:44 AM: adm4.dll (ID = 49779)
2:44 AM: adm25.dll (ID = 49782)
2:44 AM: admdata.dll (ID = 49784)
2:44 AM: admdloader.dll (ID = 49786)
2:44 AM: admfdi.dll (ID = 49789)
2:44 AM: admprog.dll (ID = 49790)
2:44 AM: adm.exe (ID = 111765)
2:45 AM: asmfiles.cab (ID = 49805)
2:45 AM: dmfiles.cab (ID = 49818)
2:45 AM: dminstall7.cab (ID = 49829)
2:46 AM: bulldownload.exe (ID = 52017)
2:46 AM: pmexe.cab (ID = 49854)
2:46 AM: pmfiles.cab (ID = 49856)
2:49 AM: __unin__.exe (ID = 49793)
2:49 AM: setup.exe (ID = 49875)
2:49 AM: Found Trojan Horse: trojan-downloader-aux
2:49 AM: win38.tmp.exe (ID = 282640)
2:49 AM: Found Trojan Horse: trojan-downloader-errlook
2:49 AM: win44.tmp.exe (ID = 283245)
2:56 AM: File Sweep Complete, Elapsed Time: 00:26:06
2:56 AM: Full Sweep has completed. Elapsed time 00:31:45
2:56 AM: Traces Found: 401
2:58 AM: Removal process initiated
2:58 AM: Quarantining All Traces: purityscan
2:58 AM: Quarantining All Traces: coolwebsearch (cws)
2:58 AM: coolwebsearch (cws) is in use. It will be removed on reboot.
2:58 AM: winres.dll is in use. It will be removed on reboot.
2:58 AM: Quarantining All Traces: trojan agent winlogonhook
2:58 AM: Quarantining All Traces: trojan-downloader-aux
2:58 AM: Quarantining All Traces: trojan-downloader-errlook
2:58 AM: Quarantining All Traces: altnet
2:58 AM: Quarantining All Traces: bullguard popup ad
2:58 AM: Quarantining All Traces: rx toolbar
2:58 AM: Quarantining All Traces: topsearch
2:58 AM: Quarantining All Traces: 2o7.net cookie
2:58 AM: Quarantining All Traces: adrevolver cookie
2:58 AM: Quarantining All Traces: advertising cookie
2:58 AM: Quarantining All Traces: aptimus cookie
2:58 AM: Quarantining All Traces: ask cookie
2:58 AM: Quarantining All Traces: atlas dmt cookie
2:58 AM: Quarantining All Traces: atwola cookie
2:58 AM: Quarantining All Traces: casalemedia cookie
2:58 AM: Quarantining All Traces: fastclick cookie
2:58 AM: Quarantining All Traces: mediaplex cookie
2:58 AM: Quarantining All Traces: overture cookie
2:58 AM: Quarantining All Traces: pointroll cookie
2:58 AM: Quarantining All Traces: questionmarket cookie
2:58 AM: Quarantining All Traces: realmedia cookie
2:58 AM: Quarantining All Traces: revenue.net cookie
2:58 AM: Quarantining All Traces: ru4 cookie
2:58 AM: Quarantining All Traces: serving-sys cookie
2:58 AM: Quarantining All Traces: trafficmp cookie
2:58 AM: Quarantining All Traces: tribalfusion cookie
2:58 AM: Quarantining All Traces: tripod cookie
2:58 AM: Quarantining All Traces: yieldmanager cookie
2:58 AM: Quarantining All Traces: zedo cookie
2:58 AM: Removal process completed. Elapsed time 00:00:44
********
2:23 AM: | Start of Session, Friday, April 21, 2006 |
2:23 AM: Spy Sweeper started
2:23 AM: Sweep initiated using definitions version 662
2:23 AM: Found Adware: coolwebsearch (cws)
2:23 AM: HKCR\clsid\{2d38a51a-23c9-48a1-a33c-48675aa2b494}\inprocserver32\ (2 subtraces) (ID = 1183061)
2:23 AM: winres.dll (ID = 1183061)
2:23 AM: Starting Memory Sweep
2:24 AM: Sweep Canceled
2:24 AM: Memory Sweep Complete, Elapsed Time: 00:00:10
2:24 AM: Traces Found: 4
2:24 AM: | End of Session, Friday, April 21, 2006 |
********
2:23 AM: | Start of Session, Friday, April 21, 2006 |
2:23 AM: Spy Sweeper started
2:23 AM: Your spyware definitions have been updated.
2:23 AM: | End of Session, Friday, April 21, 2006 |