Logfile of HijackThis v1.99.1
Scan saved at 7:33:56 PM, on 7/11/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\PROGRAM FILES\ACCELERATION SOFTWARE\PHANTOMCD\BPLAYER.EXE
C:\WINDOWS\SYSTEM\USBMONIT.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\PASSWORD MANAGER\ACCTMGR.EXE
C:\WINDOWS\SYSTEM\WINIV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\NTJN32.EXE
C:\WINDOWS\MSAR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\MICROCORE\DIALER.EXE
C:\WINDOWS\MSAR.EXE
C:\WINDOWS\MSAR.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\SYSTEM\IEWS32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\NETGW.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\ADDQR32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\wacdq.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Joey Loves Charles
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: Class - {0B77DD19-4507-15E8-A38D-0DA38C44E22B} - C:\WINDOWS\SYSTEM\IPXJ.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [NPROTECT] c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [CTFMon] C:\WINDOWS\SYSTEM\CTF\CTFMON.EXE
O4 - HKLM\..\Run: [bplayer.exe] "C:\PROGRA~1\ACCELE~1\PHANTO~1\BPLAYER.EXE"
O4 - HKLM\..\Run: [Gene USB Monitor] c:\windows\SYSTEM\USBMonit.exe
O4 - HKLM\..\Run: [AcctMgr] C:\PROGRAM FILES\NORTON SYSTEMWORKS\PASSWORD MANAGER\ACCTMGR.EXE /startup
O4 - HKLM\..\Run: [SpyFighterMonitor] "D:\PROGRAM FILES\SPYFIGHTER.EXE" monitor
O4 - HKLM\..\Run: [WINIV.EXE] C:\WINDOWS\SYSTEM\WINIV.EXE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [CSINJECT.EXE] c:\Program Files\Norton SystemWorks\Norton CleanSweep\csinject.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] c:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [NPROTECT] c:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\RunServices: [MSAR.EXE] C:\WINDOWS\MSAR.EXE /s
O4 - HKLM\..\RunServices: [APPNR.EXE] C:\WINDOWS\SYSTEM\APPNR.EXE /s
O4 - HKLM\..\RunServices: [ADDOW.EXE] C:\WINDOWS\SYSTEM\ADDOW.EXE /s
O4 - HKLM\..\RunServices: [CRQR32.EXE] C:\WINDOWS\SYSTEM\CRQR32.EXE /s
O4 - HKLM\..\RunServices: [ADDPB32.EXE] C:\WINDOWS\ADDPB32.EXE /s
O4 - HKLM\..\RunServices: [NTJN32.EXE] C:\WINDOWS\SYSTEM\NTJN32.EXE /s
O4 - HKLM\..\RunServices: [APIZS.EXE] C:\WINDOWS\SYSTEM\APIZS.EXE /s
O4 - HKLM\..\RunServices: [D3ZG32.EXE] C:\WINDOWS\SYSTEM\D3ZG32.EXE /s
O4 - HKLM\..\RunServices: [SYSZR.EXE] C:\WINDOWS\SYSZR.EXE /s
O4 - HKLM\..\RunServices: [D3HA.EXE] C:\WINDOWS\D3HA.EXE /s
O4 - HKLM\..\RunServices: [NETWW32.EXE] C:\WINDOWS\NETWW32.EXE /s
O4 - HKLM\..\RunServices: [MSBJ32.EXE] C:\WINDOWS\MSBJ32.EXE /s
O4 - HKLM\..\RunServices: [ADDEZ32.EXE] C:\WINDOWS\SYSTEM\ADDEZ32.EXE /s
O4 - HKLM\..\RunServices: [IPGX.EXE] C:\WINDOWS\IPGX.EXE /s
O4 - HKLM\..\RunServices: [SYSYH.EXE] C:\WINDOWS\SYSYH.EXE /s
O4 - HKLM\..\RunServices: [NTMC32.EXE] C:\WINDOWS\SYSTEM\NTMC32.EXE /s
O4 - HKLM\..\RunServices: [MSJE32.EXE] C:\WINDOWS\SYSTEM\MSJE32.EXE /s
O4 - HKLM\..\RunServices: [ATLNM.EXE] C:\WINDOWS\ATLNM.EXE /s
O4 - HKLM\..\RunServices: [ATLDP.EXE] C:\WINDOWS\SYSTEM\ATLDP.EXE /s
O4 - HKLM\..\RunServices: [NETCE.EXE] C:\WINDOWS\SYSTEM\NETCE.EXE /s
O4 - HKLM\..\RunServices: [IEOA.EXE] C:\WINDOWS\IEOA.EXE /s
O4 - HKLM\..\RunServices: [ADDQH32.EXE] C:\WINDOWS\ADDQH32.EXE /s
O4 - HKLM\..\RunServices: [IEWS32.EXE] C:\WINDOWS\SYSTEM\IEWS32.EXE /s
O4 - HKLM\..\RunServices: [NETGW.EXE] C:\WINDOWS\SYSTEM\NETGW.EXE /s
O4 - HKLM\..\RunServices: [ADDQR32.EXE] C:\WINDOWS\ADDQR32.EXE /s
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - Startup: birthen.exe.lnk = C:\WINDOWS\Profiles\Pandora\Desktop\Tolkien stuff\elvish calendar dowloaded\birthen.exe
O4 - User Startup: birthen.exe.lnk = C:\WINDOWS\Profiles\Pandora\Desktop\Tolkien stuff\elvish calendar dowloaded\birthen.exe
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414XXUS
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\PROGRAM FILES\ATI MULTIMEDIA\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c3.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) -
http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
Thank you very much! i saw that some people had a hijack this log, but was not sure what it was!
Jo