Logfile of HijackThis v1.99.1
Scan saved at 9:11:16 PM, on 4/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\xpsp2fw.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\MouseWare\system\em_exec.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\QBDAgent.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\System32\mrtMngr.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [QBCD Autorun] D:\autorun.exe restart TIMER_SEQUENCE first
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [XPSP2 Firewall] C:\WINDOWS\system32\xpsp2fw.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [Windows Update Client ] C:\WINDOWS\system32\wuclient.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickBooks Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\QBDAgent.exe
O9 - Extra button: TREND MICRO HouseCall - {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} -
http://uk.trendmicro-europe.com/enterprise...usecall_pre.php (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fltmgr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fltmgr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\fltmgr.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CABO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/244e0aed5985bc...ip/RdxIE601.cabO16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) -
http://de.trendmicro-europe.com/file_downl...eCallButton.CABO23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
plus the shredder log
(4/14/05 9:04:50 PM) SPSeHjFix started v1.1.2
(4/14/05 9:04:50 PM) OS: WinXP Service Pack 1 (5.1.2600)
(4/14/05 9:04:50 PM) Language: english
(4/14/05 9:04:50 PM) Win-Path: C:\WINDOWS
(4/14/05 9:04:50 PM) System-Path: C:\WINDOWS\System32
(4/14/05 9:04:50 PM) Temp-Path: C:\DOCUME~1\ALAN~1.DJJ\LOCALS~1\Temp\
(4/14/05 9:04:52 PM) Disinfection started
(4/14/05 9:04:52 PM) Bad-Dll(IEP): (not found)
(4/14/05 9:04:52 PM) Bad-Dll(IEP) in BHO: (not found)
(4/14/05 9:04:52 PM) UBF: 7 - UBB: 3 - UBR: 22
(4/14/05 9:04:52 PM) UBF: 7 - UBB: 3 - UBR: 22
(4/14/05 9:04:52 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\DOCUME~1\ALAN~1.DJJ\LOCALS~1\Temp\se.dll,DllInstall (deleted)
(4/14/05 9:04:52 PM) Bad IE-pages: (none)
(4/14/05 9:04:52 PM) Stealth-String not found
(4/14/05 9:04:52 PM) File added to delete: c:\docume~1\alan~1.djj\locals~1\temp\se.dll
(4/14/05 9:04:52 PM) Reboot
(4/14/05 9:06:05 PM) SPSeHjFix started v1.1.2
(4/14/05 9:06:05 PM) OS: WinXP Service Pack 1 (5.1.2600)
(4/14/05 9:06:05 PM) Language: english
(4/14/05 9:06:05 PM) Win-Path: C:\WINDOWS
(4/14/05 9:06:05 PM) System-Path: C:\WINDOWS\System32
(4/14/05 9:06:05 PM) Temp-Path: C:\DOCUME~1\ALAN~1.DJJ\LOCALS~1\Temp\
(4/14/05 9:06:58 PM) SPSeHjFix started v1.1.2
(4/14/05 9:06:58 PM) OS: WinXP Service Pack 1 (5.1.2600)
(4/14/05 9:06:58 PM) Language: english
(4/14/05 9:06:58 PM) Win-Path: C:\WINDOWS
(4/14/05 9:06:58 PM) System-Path: C:\WINDOWS\System32
(4/14/05 9:06:58 PM) Temp-Path: C:\DOCUME~1\ALAN~1.DJJ\LOCALS~1\Temp\
(4/14/05 9:07:00 PM) Disinfection started
(4/14/05 9:07:00 PM) Bad-Dll(IEP): (not found)
(4/14/05 9:07:00 PM) Bad-Dll(IEP) in BHO: (not found)
(4/14/05 9:07:00 PM) UBF: 7 - UBB: 3 - UBR: 21
(4/14/05 9:07:00 PM) UBF: 7 - UBB: 3 - UBR: 21
(4/14/05 9:07:00 PM) Bad IE-pages: (none)
(4/14/05 9:07:00 PM) Stealth-String not found
(4/14/05 9:07:00 PM) Not infected->END
(4/14/05 9:15:07 PM) SPSeHjFix started v1.1.2
(4/14/05 9:15:07 PM) OS: WinXP Service Pack 1 (5.1.2600)
(4/14/05 9:15:07 PM) Language: english
(4/14/05 9:15:07 PM) Win-Path: C:\WINDOWS
(4/14/05 9:15:07 PM) System-Path: C:\WINDOWS\System32
(4/14/05 9:15:07 PM) Temp-Path: C:\DOCUME~1\ALAN~1.DJJ\LOCALS~1\Temp\
(4/14/05 9:15:25 PM) SPSeHjFix started v1.1.2
(4/14/05 9:15:25 PM) OS: WinXP Service Pack 1 (5.1.2600)
(4/14/05 9:15:25 PM) Language: english
(4/14/05 9:15:25 PM) Win-Path: C:\WINDOWS
(4/14/05 9:15:25 PM) System-Path: C:\WINDOWS\System32
(4/14/05 9:15:25 PM) Temp-Path: C:\DOCUME~1\ALAN~1.DJJ\LOCALS~1\Temp\
(4/14/05 9:15:28 PM) Disinfection started
(4/14/05 9:15:28 PM) Bad-Dll(IEP): (not found)
(4/14/05 9:15:28 PM) Bad-Dll(IEP) in BHO: (not found)
(4/14/05 9:15:28 PM) UBF: 7 - UBB: 3 - UBR: 21
(4/14/05 9:15:28 PM) UBF: 7 - UBB: 3 - UBR: 21
(4/14/05 9:15:28 PM) Bad IE-pages: (none)
(4/14/05 9:15:28 PM) Stealth-String not found
(4/14/05 9:15:28 PM) Not infected->END