Logfile of HijackThis v1.99.0
Scan saved at 10:51:01 PM, on 2/2/05
Platform: Windows NT 4 SP5 (WinNT 4.00.1381)
MSIE: Internet Explorer v5.00 (5.00.2314.1000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolss.exe
C:\WINNT\system32\RpcSs.exe
C:\WINNT\System32\LexStart.Exe
c:\winnt\system32\pstores.exe
C:\WINNT\System32\nddeagnt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\SysTray.Exe
C:\WINNT\System32\loadwc.exe
C:\WINNT\System32\HPJETDSC.EXE
C:\WINNT\Profiles\All Users\Start Menu\Programs\Startup\FLSHSTAT.exe
C:\WINNT\system32\starter.exe
C:\WINNT\system32\starter.exe
C:\WINNT\System32\ddhelp.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\WINNT\System32\tsmsetup.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINNT\Profiles\Administrator\Desktop\New Folder\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://clearsurfing.net/srch.php?qq=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O2 - BHO: (no name) - {9DC35253-7586-11D9-BD5C-005043A00977} - C:\WINNT\System32\qwsxp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINNT\System32\iesp2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BrowserWebCheck] loadwc.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\RunOnce: [GrpConv] grpconv.exe -o
O4 - HKCU\..\Run: [HP JetDiscovery] HPJETDSC.EXE
O4 - Startup: Starter.lnk = system32\starter.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: FLSHSTAT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: starter.lnk = system32\starter.exe
O12 - Plugin for .mid: C:\PROGRA~1\Plus!\MICROS~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\Plus!\MICROS~1\PLUGINS\npqtplugin.dll
O13 - WWW. Prefix: http://
O14 - IERESET.INF: SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp
O16 - DPF: {11111111-1111-1111-1111-111111111111} - ms-its:mhtml:file://C:\foo.mht!http://195.225.176.25/user6/mstlb.chm::/1/e.exe
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://69.50.166.214/counter/new/x.chm::/update.exe
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = microbio.ucla.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = microbio.ucla.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = microbio.ucla.edu lifesci.ucla.edu psych.ucla.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 164.67.7.17 164.67.7.18
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = microbio.ucla.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = microbio.ucla.edu lifesci.ucla.edu psych.ucla.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 164.67.7.17 164.67.7.18
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = microbio.ucla.edu lifesci.ucla.edu psych.ucla.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 164.67.7.17 164.67.7.18
O18 - Filter: text/html - {F7B6C936-7588-11D9-BD5C-00509F9A69F1} - C:\WINNT\System32\qwsxp.dll
O18 - Filter: tœ†5òÏTÆR - {9DC35252-7586-11D9-BD5C-00502CECACEC} - C:\WINNT\System32\qwsxp.dll
O18 - Filter: tœ†5òþEÆR - {F7B6C936-7588-11D9-BD5C-00509F9A69F1} - C:\WINNT\System32\qwsxp.dll
Scan saved at 10:51:01 PM, on 2/2/05
Platform: Windows NT 4 SP5 (WinNT 4.00.1381)
MSIE: Internet Explorer v5.00 (5.00.2314.1000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolss.exe
C:\WINNT\system32\RpcSs.exe
C:\WINNT\System32\LexStart.Exe
c:\winnt\system32\pstores.exe
C:\WINNT\System32\nddeagnt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\SysTray.Exe
C:\WINNT\System32\loadwc.exe
C:\WINNT\System32\HPJETDSC.EXE
C:\WINNT\Profiles\All Users\Start Menu\Programs\Startup\FLSHSTAT.exe
C:\WINNT\system32\starter.exe
C:\WINNT\system32\starter.exe
C:\WINNT\System32\ddhelp.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\WINNT\System32\tsmsetup.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINNT\Profiles\Administrator\Desktop\New Folder\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://clearsurfing.net/srch.php?qq=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\System32\qwsxp.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O2 - BHO: (no name) - {9DC35253-7586-11D9-BD5C-005043A00977} - C:\WINNT\System32\qwsxp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINNT\System32\iesp2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BrowserWebCheck] loadwc.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\RunOnce: [GrpConv] grpconv.exe -o
O4 - HKCU\..\Run: [HP JetDiscovery] HPJETDSC.EXE
O4 - Startup: Starter.lnk = system32\starter.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: FLSHSTAT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: starter.lnk = system32\starter.exe
O12 - Plugin for .mid: C:\PROGRA~1\Plus!\MICROS~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\Plus!\MICROS~1\PLUGINS\npqtplugin.dll
O13 - WWW. Prefix: http://
O14 - IERESET.INF: SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp
O16 - DPF: {11111111-1111-1111-1111-111111111111} - ms-its:mhtml:file://C:\foo.mht!http://195.225.176.25/user6/mstlb.chm::/1/e.exe
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://69.50.166.214/counter/new/x.chm::/update.exe
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = microbio.ucla.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = microbio.ucla.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = microbio.ucla.edu lifesci.ucla.edu psych.ucla.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 164.67.7.17 164.67.7.18
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = microbio.ucla.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = microbio.ucla.edu lifesci.ucla.edu psych.ucla.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 164.67.7.17 164.67.7.18
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = microbio.ucla.edu lifesci.ucla.edu psych.ucla.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 164.67.7.17 164.67.7.18
O18 - Filter: text/html - {F7B6C936-7588-11D9-BD5C-00509F9A69F1} - C:\WINNT\System32\qwsxp.dll
O18 - Filter: tœ†5òÏTÆR - {9DC35252-7586-11D9-BD5C-00502CECACEC} - C:\WINNT\System32\qwsxp.dll
O18 - Filter: tœ†5òþEÆR - {F7B6C936-7588-11D9-BD5C-00509F9A69F1} - C:\WINNT\System32\qwsxp.dll