I have gotten another virus from the web and am at a loss on what should or should not be in this HiJack This log file below. Any help given is greatly appreciated.
Logfile of HijackThis v1.98.0
Scan saved at 11:25:21 PM, on 3/19/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon
.exe
D:\WINNT\system32\services
.exe
D:\WINNT\system32\lsass.ex
e
D:\WINNT\system32\svchost.
exe
D:\WINNT\system32\spoolsv.
exe
D:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
D:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
D:\WINNT\System32\svchost.
exe
D:\Program Files\Ahead\InCD\InCDsrv.e
xe
D:\PROGRA~1\Iomega\System3
2\AppServi
ces.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINNT\system32\nvsvc32.
exe
D:\WINNT\system32\regsvc.e
xe
D:\WINNT\system32\MSTask.e
xe
D:\WINNT\system32\stisvc.e
xe
D:\WINNT\system32\ZoneLabs
\vsmon.exe
D:\WINNT\System32\WBEM\Win
Mgmt.exe
D:\WINNT\System32\mspmspsv
.exe
D:\WINNT\system32\svchost.
exe
D:\Program Files\Iomega\AutoDisk\ADSe
rvice.exe
D:\Program Files\Hewlett-Packard\CLJ1
500\Toolbo
x\HPPOUMUI
.EXE
D:\WINNT\Explorer.EXE
D:\Program Files\QuickTime\qttask.exe
D:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe
D:\PROGRA~1\Grisoft\AVGFRE
~1\avgemc.
exe
D:\Program Files\Hewlett-Packard\CLJ1
500\Toolbo
x\HPPOUMUI
.exe
D:\Program Files\Ahead\InCD\InCD.exe
D:\Program Files\Java\jre1.5.0\bin\ju
sched.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
D:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
D:\Documents and Settings\Administrator\My Documents\My Music\iTunes\iTunesHelper.
exe
D:\Program Files\Windows TaskAd\WinTaskAd.exe
D:\Program Files\Internet Optimizer\optimize.exe
D:\Program Files\Windows TaskAd\WinSched.exe
D:\WINNT\system32\ap9h4qmo
.exe
D:\Program Files\BullsEye Network\bin\bargains.exe
D:\WINNT\system32\ctfmon.e
xe
D:\Program Files\iPod\bin\iPodService
.exe
E:\Microsoft_Networking\MS
BNTray.exe
D:\Program Files\SpywareGuard\sgmain.
exe
D:\Program Files\SpywareGuard\sgbhp.e
xe
F:\Spyware Removal\Hijack This\HijackThis1.98.exe
D:\WINZIP~1\winzip32.exe
H:\HP Scanjet\HP Share-to-Web\hpgs2wnf.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.cox.net/O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - d:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dl
l,NvStartu
p
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\Grisoft\AVGFRE
~1\avgemc.
exe
O4 - HKLM\..\Run: [Status Monitor CLJ1500] D:\Program Files\Hewlett-Packard\CLJ1
500\\Toolb
ox\HPPOUMU
I.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINNT\system32\NeroChec
k.exe
O4 - HKLM\..\Run: [InCD] D:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0\bin\ju
sched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] D:\Documents and Settings\Administrator\My Documents\My Music\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [Windows TaskAd] D:\Program Files\Windows TaskAd\WinTaskAd.exe
O4 - HKLM\..\Run: [Internet Optimizer] "D:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ap9h4qmo] D:\WINNT\system32\ap9h4qmo
.exe
O4 - HKLM\..\Run: [BullsEye Network] D:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: DLHelperEXE.exe
O4 - Startup: SpywareGuard.lnk = D:\Program Files\SpywareGuard\sgmain.
exe
O4 - Global Startup: Microsoft Broadband Networking.lnk = E:\Microsoft_Networking\MS
BNTray.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = D:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.E
XE
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - D:\Program Files\Java\jre1.5.0\bin\np
jpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - D:\Program Files\Java\jre1.5.0\bin\np
jpi150.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-4
7cb894244c
d} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-4
7cb894244c
d} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - D:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O16 - DPF: ppctlcab -
http://www.pestscan.com/scanner/ppctlcab.cabO16 - DPF: YExplorer1_8US.CAB -
http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cabO16 - DPF: {01113300-3E00-11D2-8470-0
060089874E
D} (Support.com Configuration Class) -
http://usercenter.cox.net/rsuite/sdccommon/asp/cx_tgctlcm.jspO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
E41684E07B
B} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {2FC9A21E-2069-4E47-8235-3
6318989DB1
3} (PPSDKActiveXScanner.MainS
creen) -
http://www.pestscan.com/scanner/axscanner.cabO16 - DPF: {4E888414-DB8F-11D1-9CD9-0
0C04F98436
A} (Microsoft.WinRep) -
https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cabO16 - DPF: {5EFF8B09-B211-42B7-805E-C
4670BF8C83
0} -
http://mediaplayer.walmart.com/installer/install.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E
099162EEEC
5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-0
0C04F9A3B6
1} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-0
0105A1F0D6
8} (InstallShield International Setup Player) -
http://www.installengine.com/engine/isetup.cabO16 - DPF: {A7E092C3-692A-11D0-A7E5-0
8002B322F3
B} (WebResponseAttachments Control) -
https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cabO16 - DPF: {AED98630-0251-4E83-917D-4
3A23D66D50
7} (WebHandler Class) -
http://activex.microgaming.com/DLhelper/version7/dlhelper.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-5
95F0A5519F
F} (MsnMessengerSetupDownload
Control Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cabO16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0
F47A330807
8} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/activedata/SymAData.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9
B663A28DFC
B} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cabO16 - DPF: {E77C0D62-882A-456F-AD8F-7
C6C9569B8C
7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/activedata/ActiveData.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0
010B556D97
8} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cabStart Free Trial