Logfile of HijackThis v1.99.0
Scan saved at 3:15:06 PM, on 1/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\Packet
hSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\System32\ScsiAc
cess.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\wscntf
y.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\hpz
tsb05.exe
C:\WINDOWS\system32\rundll
32.exe
C:\PROGRA~1\VBouncer\Virtu
alBouncer.
exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe
C:\Program Files\ScreenArt\WillowRd.e
xe
C:\Program Files\Weatherscope\Weather
scope.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\system32\NOTEPA
D.EXE
D:\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.myexcel.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://search.search-exe.com/nph-search.cgi?tcode=exebar1&look=sbar1_srchbtnR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.myexcel.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://search.search-exe.com/nph-search.cgi?tcode=exebar1&look=sbar1_srchbtnR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.dellnet.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=R1 - HKLM\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=R3 - URLSearchHook: WebSearch Class - {9368D063-44BE-49B9-BD14-B
B9663FD38F
C} - C:\Program Files\se\v11\se.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\System
32\Userini
t.exe
O2 - BHO: WebBho Class - {00041A26-7033-432C-94C7-6
371DE34382
2} - C:\Program Files\se\v11\se.DLL
O3 - Toolbar: (no name) - {57E69D5A-6539-4d7d-9637-7
75DE8A385B
4} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn2
\ycomp5_3_
16_0.dll
O3 - Toolbar: DashBar Toolbar - {CC90CDA0-74A0-45b4-80EF-D
89CA8C249B
8} - C:\Program Files\DashBar\DashBar15.dl
l
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\MSN Toolbar\01.01.1601.0\en-us
\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [IM] C:\PROGRA~1\MYEXCE~1\IM.ex
e
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\hpz
tsb05.exe
O4 - HKLM\..\Run: [89C7B28B] C:\WINDOWS\System32\yygvni
dlqjeqd.ex
e
O4 - HKLM\..\Run: [OSS] c:\windows\system32\osspro
xy.exe -boot
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDO
T~2.DLL,Ne
wDotNetSta
rtup -s
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\Virtu
alBouncer.
exe
O4 - HKLM\..\Run: [Search-Exe] "C:\Program Files\se\v11\se.EXE" /H
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe
O4 - Global Startup: ScreenArt.lnk = C:\Program Files\ScreenArt\WillowRd.e
xe
O4 - Global Startup: Weatherscope.lnk = C:\Program Files\Weatherscope\Weather
scope.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Messenger\yhe
xbmes0521.
dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-0
0010333D0A
D} - C:\Program Files\Yahoo!\Messenger\yhe
xbmes0521.
dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.
dll
O10 - Broken Internet access because of LSP provider 'osmim.dll' missing
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cabO16 - DPF: {1223B679-3A38-4EB0-A170-A
58F703ACCA
5} (ImStarter Class) -
http://www2.incredimail.com/contents/setup/downloader_sp1_t/incredimail_install.cabO16 - DPF: {1C44E9F2-4B84-11D4-9B88-0
0902788921
2} (Ontrack ASP Web Tools) -
http://www.askdrtech.com/ontrack/bin/nppcfix.cabO16 - DPF: {2119776A-F1AD-4FCD-9548-F
1E1C615350
C} -
http://defender.veloz.com/pub/download/scandl_cnry.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-0
0A0C970049
8} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-0
0C04F9A3B6
1} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0
09027A35D7
3} (Yahoo! Audio UI1) -
http://chat.yahoo.com/cab/yacsui.cabO16 - DPF: {AE1C01E3-0283-11D3-9B3F-0
0C04F8EF46
6} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0
F47A330807
8} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/activedata/SymAData.dllO16 - DPF: {DDFFA75A-E81D-4454-89FC-B
9FD0631E72
6} -
http://www.bundleware.com/activeX/DS3/DS3.cabO16 - DPF: {E77C0D62-882A-456F-AD8F-7
C6C9569B8C
7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/activedata/ActiveData.cabO23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
2.exe
O23 - Service: Virtual NIC Service - America Online, Inc. - C:\WINDOWS\System32\Packet
hSvc.exe
O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAc
cess.EXE
This is a friends computer internet will no longer work. I don't understand how to get rid of LSP. I ran stinger and spybot and a cool shredder program this does not help.
Thanks
123