Logfile of HijackThis v1.99.1 Scan saved at 3:03:54 PM, on 8/7/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\NETGEAR\WG311TSU\Utility\Gear311T.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\hijakthis\HijackThis.exe O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM) O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM) O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM) O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM) O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM) O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file) O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe —-ADS LOG —— C:\WINDOWS\HKCLFNK.ini : ymmxm (11591 bytes) C:\WINDOWS\IEPatchUninstall.log : uqlgc (3063 bytes) C:\WINDOWS\iis6.log : mqwmw (56832 bytes) C:\WINDOWS\IsUninst.exe : boivc (11591 bytes) C:\WINDOWS\IsUninst.exe : frorq (0 bytes) C:\WINDOWS\KB822603.log : mpaae (56832 bytes) C:\WINDOWS\KB826939.log : qfapw (93184 bytes) C:\WINDOWS\KB835221.log : annbd (100127 bytes) C:\WINDOWS\KB835732.log : tglit (93184 bytes) C:\WINDOWS\KB840374.log : indnv (18944 bytes) C:\WINDOWS\msgsocm.log : oyvvo (11591 bytes) C:\WINDOWS\nsreg.dat : zrhgk (56832 bytes) C:\WINDOWS\n_gevqml.txt : jorpp (100127 bytes) C:\WINDOWS\n_ixegpo.txt : bpjck (11801 bytes) C:\WINDOWS\ocgen.log : bssrf (100127 bytes) C:\WINDOWS\Prairie Wind.bmp : tbrpk (26624 bytes) C:\WINDOWS\Q329909.log : kmqpi (93184 bytes) C:\WINDOWS\Q811114.log : nffsni (13581 bytes) C:\WINDOWS\Q811114.log : sdnbc (10240 bytes) C:\WINDOWS\QFE.log : naecq (100127 bytes) C:\WINDOWS\regedit.exe : ggyxpk (11151 bytes) C:\WINDOWS\Rhododendron.bmp : yhqcju (3567 bytes) C:\WINDOWS\Santa Fe Stucco.bmp : fkkkj (12143 bytes) C:\WINDOWS\Santa Fe Stucco.bmp : nfizt (11591 bytes) C:\WINDOWS\Santa Fe Stucco.bmp : qchvm (30127 bytes) C:\WINDOWS\setupact.log : gybev (11591 bytes) C:\WINDOWS\setupact.log : lrpdj (93184 bytes) C:\WINDOWS\setupapi.log.0.old : lvane (10240 bytes) C:\WINDOWS\setuplog.txt : ilvbhx (11801 bytes) C:\WINDOWS\setuplog.txt : yzusp (11591 bytes) C:\WINDOWS\setuplog.txt : zvdtj (93184 bytes) C:\WINDOWS\smscfg.ini : wcuzo (100127 bytes) C:\WINDOWS\UNNeroBurnRights.cfg : jwhud (11591 bytes) C:\WINDOWS\vb.ini : bxrhf (11591 bytes) C:\WINDOWS\vb.ini : hhtwg (93184 bytes) C:\WINDOWS\vbaddin.ini : zltod (30127 bytes) C:\WINDOWS\wanmpsvc.exe : kfseb (10240 bytes) C:\WINDOWS\wanmpsvc.exe : uykmz (3063 bytes) C:\WINDOWS\Windows Update.log : dgdje (18944 bytes) C:\WINDOWS\winhelp.exe : jasfv (10240 bytes) C:\WINDOWS\winnt.bmp : ciaxo (100127 bytes) C:\WINDOWS\winnt256.bmp : eqhnh (93184 bytes) C:\WINDOWS\wmsetup.log : wagav (100127 bytes) C:\WINDOWS\wsdu.log : pbqfq (11801 bytes) C:\WINDOWS\zHotkey.exe : mqjwt (11591 bytes) C:\WINDOWS\_default.pif : azowv (100127 bytes) Just concerned about a hidden hijacker…