Windows XP
--
Questions
--
Followers
Top Experts
I was hoping someone could help me clean up my log file and make some suggestions. I used Hijackthis to generate the log file and don't want to delete things that might cause me more problems.
Any help would be greatly appreciated!
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_01\bin
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Support.com\bin\tgcm
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
C:\Program Files\iTunes\iTunesHelper.
C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
C:\windows\system32\uGqtkZ
C:\WINDOWS\isrvs\desktop.e
C:\temp\salm.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe
C:\WINDOWS\system32\w?nlog
C:\Documents and Settings\Michael E. Burman.PUNCH-VRFIOE4OW\App
C:\PROGRA~1\COMMON~1\riow\
C:\WINDOWS\System32\nvsvc3
C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\PROGRA~1\INCRED~1\bin\I
C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
C:\PROGRA~1\COMMON~1\riow\
C:\Program Files\Common Files\Intuit\QuickBooks\QB
C:\QUICKEN2004\QWDLLS.EXE
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54Cfg.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\INCRED~1\bin\I
C:\PROGRA~1\INCRED~1\bin\I
C:\hijackthis\HijackThis.e
N1 - Netscape 4: user_pref("browser.startup
N3 - Netscape 7: user_pref("browser.startup
N3 - Netscape 7: user_pref("browser.search.
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4
O2 - BHO: F1 Organizer Class - {00000EF1-0786-4633-87C6-1
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-2
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E
O2 - BHO: NavErrRedir Class - {0199DF25-9820-4bd5-9FEE-5
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: ohb - {086CEFD5-A88D-4981-8915-D
O2 - BHO: (no name) - {1C78AB3F-A857-482e-80C0-3
O2 - BHO: (no name) - {221CBAEE-5E70-2489-2E8A-5
O2 - BHO: ohb - {285B5CCD-C3F0-4EB6-9632-7
O2 - BHO: (no name) - {488B642C-9A64-0EB7-D450-6
O2 - BHO: (no name) - {4B8B6D7E-9566-05ED-D653-6
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-B
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0
O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-8
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-7
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcm
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YF.exe] C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [iCpbNu.exe] C:\windows\iCpbNu.exe
O4 - HKLM\..\Run: [U.exe] C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
O4 - HKLM\..\Run: [ptD4q.exe] C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
O4 - HKLM\..\Run: [HiLhgot9.exe] C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
O4 - HKLM\..\Run: [g.exe] C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
O4 - HKLM\..\Run: [Lu3HAC.exe] C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
O4 - HKLM\..\Run: [3jbUqhNp5.exe] C:\documents and settings\michael e. burman.punch-vrfioe4ow\loc
O4 - HKLM\..\Run: [uGqtkZaa.exe] C:\windows\system32\uGqtkZ
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.e
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch
O4 - HKLM\..\Run: [KAV50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe" -run -n PersonalPro -v 5.0.0.0
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [aZBZcMe.exe] C:\windows\system32\aZBZcM
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\I
O4 - HKCU\..\Run: [Taqackxd] C:\WINDOWS\system32\w?nlog
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Michael E. Burman.PUNCH-VRFIOE4OW\App
O4 - HKCU\..\Run: [riow] C:\PROGRA~1\COMMON~1\riow\
O4 - Global Startup: Billminder.lnk = C:\QUICKEN2004\BILLMIND.EX
O4 - Global Startup: eFax Live Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 3.3.lnk = C:\Program Files\eFax Messenger Plus 3.3\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\MSOFFICE\Office\OSA9
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKEN2004\QWDLLS.EXE
O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\r
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {1C78AB3F-A857-482E-80C0-3
O16 - DPF: {99802379-7362-40E2-9D28-8
O16 - DPF: {B9191F79-5613-4C76-AA2A-3
O16 - DPF: {F00F4763-7355-4725-82F7-0
O18 - Filter: text/html - {950238FB-C706-4791-8674-4
O23 - Service: CAISafe - Unknown - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: ISEXEng - Unknown - C:\WINDOWS\System32\angele
O23 - Service: Kaspersky Anti-Virus Service - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NICSer_WPC54G - Unknown - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
O23 - Service: VET Message Service - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
http://hijackthis.de
After it has examined the log remove any thing marked as Nasty, unless you know what it is.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Thank you very much for your time and help!
Michael

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
After scanning for viruses and spyware in Safe Mode, run HijackThis again and post your log file again.
Windows XP
--
Questions
--
Followers
Top Experts
Microsoft Windows XP is the sixth release of the NT series of operating systems, and was the first to be marketed in a variety of editions: XP Home and XP Professional, designed for business and power users. The advanced features in XP Professional are generally disabled in Home Edition, but are there and can be activated. There were two 64-bit editions, an embedded edition and a tablet edition.