Logfile of HijackThis v1.99.1
Scan saved at 15:58:29, on 27/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\BT Yahoo\BT Yahoo Help\bin\mpbtn.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Documents and Settings\Ewan\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Yahoo! Broadband
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: BT Yahoo! Help.lnk = C:\Program Files\BT Yahoo\BT Yahoo Help\bin\matcli.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: BT Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra 'Tools' menuitem: BT &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) -
https://register.btinternet.com/temp...control023.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B69813C-DB16-4304-8AFC-28508370BA36}: NameServer = 194.72.9.34 194.74.65.68
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\appoy.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
Incident Status
Adware:Adware/MyWay No disinfected C:\Program Files\MyWay
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Ewan\Favorites\Only sex website.url
Adware:Adware/MediaTickets No disinfected C:\eied_s7.cab
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msxmidi.exe
Adware:Adware/SearchRelevancy No disinfected Windows Registry
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Ab scissor.url
Adware:Adware/Adsmart No disinfected C:\WINDOWS\sys????.exe
Adware:Adware/IGuard No disinfected Windows Registry
Adware:Adware/Hotoffers No disinfected C:\!Submit\guninst.exe
Adware:Adware/Hotoffers No disinfected C:\!Submit\param32.dll
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Ewan\Desktop\backups\backup-20050519-192510-845.dll
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Ewan\Favorites\Only sex website.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Ewan\Favorites\Search the web.url
Adware:Adware/SearchAid No disinfected C:\Documents and Settings\Ewan\Favorites\Seven days of free porn.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Ab scissor.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Broadband comparison.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Credit counseling.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Credit report.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Crm software.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Debt credit card.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Escorts.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Fha.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Health insurance.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Help desk software.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Insurance home.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Loan for debt consolidation.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Loan for people with bad credit.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Marketing email.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Mortgage insurance.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Mortgage life insurance.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Nevada corporations.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Online Betting Site.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Online gambling casino.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Online instant loan.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Order phentermine.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Payroll advance.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Personal loans online.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Personal loans with bad credit.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Prescription Drugs Rx Online.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Refinancing my mortgage.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Tahoe vacation rental.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Unsecured bad credit loans.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\Videos.url
Spyware

pyware/Petro-Line No disinfected C:\Documents and Settings\Ewan\Favorites\Sites about\What is hydrocodone.url
Adware:Adware/MediaTickets No disinfected C:\eied_s7.cab
Adware:Adware/SearchAid No disinfected C:\msinfo.exe
Adware:Adware/SearchAid No disinfected C:\Program Files\Internet Explorer\ctwyljfd.exe
Possible Virus. No disinfected C:\Program Files\Internet Explorer\iiygelox.exe
Possible Virus. No disinfected C:\Program Files\Internet Explorer\kxcpdnqx.exe
Adware:Adware/MyWay No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3B.tmp\mysearch.cab
Adware:Adware/MyWay No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3B.tmp\mysearch.cab[mySetp.exe]
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addds32.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apieq.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\atlwg32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\crgo.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crxm32.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1019.inf
Adware:Adware/EasySearch No disinfected C:\WINDOWS\dusfy.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\eqmof.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\fwzql.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\gajoh.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\gjbnj.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\hhwoy.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\iebe.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\iejhr.dll
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msxmidi.exe
Adware:Adware/QuickWeb No disinfected C:\WINDOWS\ntdi32.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\n_jsoihe.dat
Adware:Adware/SearchAid No disinfected C:\WINDOWS\n_zxtcei.log
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\sdkee32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sysnm32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\system32\apikf.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\appgv.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\atlnc32.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\cruw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\d3fb.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ddesz.dll
Adware:Adware/OneMore.A No disinfected C:\WINDOWS\system32\duncf.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\faujn.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\gqdsn.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipmt.dll
Adware:Adware/SearchExe No disinfected C:\WINDOWS\system32\javash32.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\lxayu.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\rxkdh.dll
Adware:Adware/QuickWeb No disinfected C:\WINDOWS\system32\syspc32.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\winkb.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\ytjfb.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\system32\zjcxv.dll
Adware:Adware/Adsmart No disinfected C:\WINDOWS\syswd32.exe
Adware:Adware/CWS.Aboutblank No disinfected C:\WINDOWS\sysyh.exe
Adware:Adware/EasySearch No disinfected C:\WINDOWS\yhouc.dll
Adware:Adware/EasySearch No disinfected C:\WINDOWS\zfjtt.dll