Logfile of HijackThis v1.99.1
Scan saved at 8:04:57 PM, on 11/11/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\JNNN\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.zukdhnczniwixw.com/Aw9fQ07/pljOsVPPCYN/ByWA5o0vtFryQdDxQ7y0SQ9Y7zsUJbEYHfpHyr3z44yI.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.free-popup-killer.com/ie/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.kqojoihisbovr.com/Aw9fQ07/plj5NQxvKOMGUlwGr1LWeUG7NcKVDqF6WUE.htm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.free-popup-killer.com/ie/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.free-popup-killer.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.free-popup-killer.com/ie/?q=%s R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 222.89.98.219
www.wo365.com O1 - Hosts: 222.89.98.219 cmfu.com
O1 - Hosts: 222.89.98.219
www.cmfu.com O1 - Hosts: 222.89.98.219 9i0.com
O1 - Hosts: 222.89.98.219
www.9flash.com O1 - Hosts: 222.89.98.219 9flash.com
O1 - Hosts: 222.89.98.219
www.nowok.net O1 - Hosts: 222.89.98.219 nowok.net
O1 - Hosts: 222.89.98.219 wisa.com.cn
O1 - Hosts: 222.89.98.219
www.sia.com.cn O1 - Hosts: 222.89.98.219
www.wisa.cn O1 - Hosts: 222.89.98.219 wisa.cn
O1 - Hosts: 222.89.98.219
www.zhao99.com O1 - Hosts: 222.89.98.219 zhao99.com
O1 - Hosts: 222.89.98.219
www.wo123.com O1 - Hosts: 222.89.98.219 wo123.com
O1 - Hosts: 222.89.98.219 wo99.com
O1 - Hosts: 222.89.98.219
www.wo99.com O1 - Hosts: 222.89.98.219
www.page.com.cn O1 - Hosts: 222.89.98.219 page.com.cn
O1 - Hosts: 222.89.98.219
www.432.cn O1 - Hosts: 222.89.98.219 432.cn
O1 - Hosts: 222.89.98.219 wysw.com
O1 - Hosts: 222.89.98.219 14.com.cn
O1 - Hosts: 222.89.98.219
www.14.com.cn O1 - Hosts: 222.89.98.219 cnww.net
O1 - Hosts: 222.89.98.219
www.mv99.com O1 - Hosts: 222.89.98.219 mv99.com
O1 - Hosts: 222.89.98.219
www.youav.com O1 - Hosts: 222.89.98.219
www.mtvav.com O1 - Hosts: 222.89.98.219
www.98983.com O1 - Hosts: 222.89.98.219 98983.com
O1 - Hosts: 222.89.98.219
www.114.com.cn O1 - Hosts: 222.89.98.219 114.com.cn
O1 - Hosts: 222.89.98.219
www.net114.com O1 - Hosts: 222.89.98.219
www.skywz.com O1 - Hosts: 222.89.98.219 skywz.com
O1 - Hosts: 222.89.98.219
www.hao6.com O1 - Hosts: 222.89.98.219 hao6.com
O1 - Hosts: 222.89.98.219
www.678a.com O1 - Hosts: 222.89.98.219 678a.com
O1 - Hosts: 222.89.98.219
www.7510.com O1 - Hosts: 222.89.98.219 7510.com
O1 - Hosts: 222.89.98.219
www.zzkan.com O1 - Hosts: 222.89.98.219 zzkan.com
O1 - Hosts: 222.89.98.219
www.ca183.com O1 - Hosts: 222.89.98.219 ca183.com
O1 - Hosts: 222.89.98.219 3tom.com
O1 - Hosts: 222.89.98.219
www.yhjm.com O1 - Hosts: 222.89.98.219 yhjm.com
O1 - Hosts: 222.89.98.219
www.k369.com O1 - Hosts: 222.89.98.219
www.xxwww.com O1 - Hosts: 222.89.98.219 xxwww.com
O1 - Hosts: 222.89.98.219
www.fm1000.net O1 - Hosts: 222.89.98.219 fm1000.net
O1 - Hosts: 222.89.98.219
www.ok135.com O1 - Hosts: 222.89.98.219 ok135.com
O1 - Hosts: 222.89.98.219
www.link999.com O1 - Hosts: 222.89.98.219 link999.com
O1 - Hosts: 222.89.98.219
www.001wz.com O1 - Hosts: 222.89.98.219 001wz.com
O1 - Hosts: 222.89.98.219
www.7t7t.com O1 - Hosts: 222.89.98.219 7t7t.com
O1 - Hosts: 222.89.98.219
www.7k7k.com O1 - Hosts: 222.89.98.219 7k7k.com
O1 - Hosts: 222.89.98.219
www.webcool.net O1 - Hosts: 222.89.98.219 webcool.net
O1 - Hosts: 222.89.98.219
www.51sobu.com O1 - Hosts: 222.89.98.219 51sobu.com
O1 - Hosts: 222.89.98.219 cy.51sobu.com
O1 - Hosts: 222.89.98.219
www.fj3721.com O1 - Hosts: 222.89.98.219 fj3721.com
O1 - Hosts: 222.89.98.219
www.msncn.com O1 - Hosts: 222.89.98.219 msncn.com
O1 - Hosts: 222.89.98.219
www.6235.com O1 - Hosts: 222.89.98.219 6235.com
O1 - Hosts: 222.89.98.219
www.8goo.com O1 - Hosts: 222.89.98.219 8goo.com
O1 - Hosts: 222.89.98.219
www.baimin.com O1 - Hosts: 222.89.98.219 baimin.com
O1 - Hosts: 222.89.98.219
www.bwwz.com O1 - Hosts: 222.89.98.219 bwwz.com
O1 - Hosts: 222.89.98.219
www.howow.net O1 - Hosts: 222.89.98.219 howow.net
O1 - Hosts: 222.89.98.219
www.tongchi.com O1 - Hosts: 222.89.98.219 tongchi.com
O1 - Hosts: 222.89.98.219
www.65658.com O1 - Hosts: 222.89.98.219 65658.com
O1 - Hosts: 222.89.98.219
www.7o7o.com O1 - Hosts: 222.89.98.219 7o7o.com
O1 - Hosts: 222.89.98.219 5126.net
O1 - Hosts: 222.89.98.219
www.5126.net O1 - Hosts: 222.89.98.219
www.wangzhiku.com O1 - Hosts: 222.89.98.219 wangzhiku.com
O1 - Hosts: 222.89.98.219
www.soyeah.com O1 - Hosts: 222.89.98.219 soyeah.com
O1 - Hosts: 222.89.98.219
www.sowang.cn O1 - Hosts: 222.89.98.219 sowang.cn
O1 - Hosts: 222.89.98.219
www.77177.com O1 - Hosts: 222.89.98.219 77177.com
O1 - Hosts: 222.89.98.219
www.look8.net O2 - BHO: Freedom Popup Killer - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [regsvc32] C:\WINDOWS\System32\regsvc32.exe
O4 - HKLM\..\Run: [MSRegSvc] C:\WINDOWS\System32\regsvc32.exe
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Eq For Debug Audio] C:\Documents and Settings\All Users\Application Data\ListPollEqFor\deadbold.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MMSystem] C:\windows\rundll32.exe "c:\windows\system32\mmsystem.dll"", RunDll32
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\RunServices: [NvMsnW] C:\WINDOWS\System32\Isass.exe
O4 - HKLM\..\RunServices: [Anti] C:\WINDOWS\System32\Isass.exe
O4 - HKLM\..\RunServices: [Isass] C:\WINDOWS\System32\Isass.exe
O4 - HKLM\..\RunOnce: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus /ro
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [person] try.exe
O4 - HKCU\..\Run: [CoalCamp] C:\DOCUME~1\JNNN\APPLIC~1\CORNSU~1\Face Plus.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MMSystem] C:\windows\rundll32.exe "c:\windows\system32\mmsystem.dll"", RunDll32
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Messenger Addon - {FB5F1911-F110-11d2-BB9E-00C04F795683} -
http://messenger.ipfox.com (file missing)
O9 - Extra 'Tools' menuitem: &Messenger Addon - {FB5F1911-F110-11d2-BB9E-00C04F795683} -
http://messenger.ipfox.com (file missing)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/FunBuddyIconsFWBInitialSetup1.0.0.8.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/2550deaf279660773423/netzip/RdxIE601.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131755761390 O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) -
http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) -
http://messenger.zone.msn.com/binary/WoF.cab31267.cab O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) -
http://runonce.msn.com/setacceptlang.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O19 - User stylesheet: C:\WINDOWS\win32.bmp
O21 - SSODL: System - {A48C6B86-4EBE-47E5-BAC9-3204AB3EB902} - dgflib.dll (file missing)
thnx..