Scan saved at 9:11:24 PM, on 6/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\xwusuhzh.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {b3e673e1-2553-189a-3a04-bee3813853f1} - {1f358318-3eeb-40a3-a981-35521e376e3b} - C:\WINDOWS\system32\ldoejblr.dll
O2 - BHO: (no name) - {438310B5-1EB7-4D38-924B-2D73F71783EE} - C:\WINDOWS\system32\mlJAsqpo.dll
O2 - BHO: (no name) - {4DD4C0BF-CD61-4E87-8CCC-4B073DDEAE6B} - C:\WINDOWS\system32\awtqoLEw.dll
O2 - BHO: (no name) - {5AFC6C91-01DA-456B-9BFD-7CC77964DA78} - C:\WINDOWS\system32\cbXNHYoM.dll
O2 - BHO: (no name) - {84276A31-F98E-498D-9490-DEEB3DB482D2} - C:\WINDOWS\system32\geBroLEv.dll
O2 - BHO: (no name) - {874DBF50-5162-45CC-95FB-D17BA449B8F8} - C:\WINDOWS\system32\fccccDvV.dll
O2 - BHO: (no name) - {8DC8CB63-1B2B-4544-875B-6B3A81E03A07} - C:\WINDOWS\system32\mlJBSlKB.dll
O2 - BHO: (no name) - {8EE72EA5-918F-4A65-AC89-3A0B5FA0D115} - C:\WINDOWS\system32\xxyaabCt.dll
O2 - BHO: (no name) - {A1CA2CFC-F1D2-4604-86BE-78135B48C367} - C:\WINDOWS\system32\cbXNHAsq.dll
O2 - BHO: (no name) - {A20D223E-6798-4533-BFBD-E8FF3A0C36A0} - C:\WINDOWS\system32\vtUmJBTm.dll
O2 - BHO: (no name) - {AC1DFC31-09E7-4116-92E4-4C13942EDDF1} - C:\WINDOWS\system32\mlJCSlMg.dll
O2 - BHO: (no name) - {C0F39D64-B51E-4D8F-82AB-22BA4D9128C5} - C:\WINDOWS\system32\ssqrssRL.dll (file missing)
O2 - BHO: (no name) - {CD6FFED6-6535-45F8-A714-DBA7800835B6} - C:\WINDOWS\system32\byXQIAqp.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\arpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [{F4-4D-DD-DA-DW}] C:\windows\system32\jnwnw64m.exe DWramXX
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\ocntokdm.exe DWramXX
O4 - HKLM\..\Run: [74df4d75] rundll32.exe "C:\WINDOWS\system32\drjjbttw.dll",b
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinMedia] C:\361101032253584.exe
O4 - HKCU\..\Run: [Winsvr] C:\3611010322516384.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [WinUpdater] "C:\Program Files\winvi\update.exe" /background
O4 - HKCU\..\Run: [WebSUpdater] "C:\Program Files\winvi\wupda.exe" /background
O4 - HKCU\..\Run: [QdrModule16] "C:\Program Files\QdrModule\QdrModule16.exe"
O4 - HKCU\..\Run: [BM77ec7ee9] Rundll32.exe "C:\WINDOWS\system32\rkokaqmd.dll",s
O4 - HKCU\..\Run: [A00F24DDBE.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F24DDBE.exe
O4 - HKCU\..\Run: [A00F281971.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F281971.exe
O4 - HKCU\..\Run: [A00F72CCA.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F72CCA.exe
O4 - HKCU\..\Run: [A00F41048.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F41048.exe
O4 - HKCU\..\Run: [A00F77EE2.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F77EE2.exe
O4 - HKCU\..\Run: [A00FB4DFB.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00FB4DFB.exe
O4 - HKCU\..\Run: [A00F120B14.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F120B14.exe
O4 - HKCU\..\Run: [A00F100A8C5.exe] C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\_A00F100A8C5.exe
O4 - HKLM\..\Policies\Explorer\Run: [isamonitor.exe] C:\Program Files\Video ActiveX Object\isamonitor.exe
O4 - HKLM\..\Policies\Explorer\Run: [pmsngr.exe] C:\Program Files\Video ActiveX Object\pmsngr.exe
O4 - Global Startup: IEEE802.11b WLAN Card Utility.lnk = C:\Program Files\Wireless\WE302R\Gcc.exe
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.v...od/install.html
O16 - DPF: {33331111-1111-1111-1111-615111193427} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1172278013125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1211753611000
O16 - DPF: {CT id=e codeBase=http://www.www2.p0rt2.com/files/epl99bf2.cab classid=clsid:33331111-1111-1111-1111-615111193427} -
O20 - Winlogon Notify: __c00957C6 - C:\WINDOWS\system32\__c00957C6.dat
O23 - Service: F-Secure BlackLight Sensor - F-Secure Corporation - C:\WINDOWS\TEMP\F-Secure\Anti-Virus\fsblsrv.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 8433 bytes