Logfile of HijackThis v1.99.1
Scan saved at 8:22:22 PM, on 9/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\rdso\eetu.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Joshua\Desktop\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{9114D8B1-FB14-FF08-7276-FB56206B6818} - (no file)
O1 - Hosts: view.atdmt.com
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {59451870-D63A-348A-EA32-4CCCAAF5D1B0} - blank (file missing)
O2 - BHO: (no name) - {6B4835A4-DA9B-C445-474E-3A04BCDBF34A} - C:\WINDOWS\Ndnynbwa.dll
O2 - BHO: Accoona Search Assistant - {944864A5-3916-46E2-96A9-A2E84F3F1208} - blank (file missing)
O2 - BHO: AdCom - {D7950AB4-67F5-458e-A37D-9F2DE7F250AC} - C:\WINDOWS\system32\AdCom.dll
O3 - Toolbar: Search - {12BD784A-E09F-C99C-A3E7-996057C11CFE} - C:\WINDOWS\Ndnynbwa.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Documents and Settings\Penny\My Documents\My Music\iTunesHelper.exe"
O4 - HKLM\..\Run: [SysStart] C:\WINDOWS\system32\ghfsysi6.exe lee0105
O4 - HKLM\..\Run: [sunasDtServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [qbyk] C:\WINDOWS\system32\tyywi\qbyk.exe
O4 - HKLM\..\Run: [hrrdnb] C:\WINDOWS\system32\tjkywbj\hrrdnb.exe
O4 - HKLM\..\Run: [tqqpyml] C:\WINDOWS\system32\dcngxfr\tqqpyml.exe
O4 - HKLM\..\Run: [bjhwuwmv] C:\WINDOWS\system32\iqkappem\bjhwuwmv.exe
O4 - HKLM\..\Run: [isyvoo] C:\WINDOWS\system32\wtuwtgyb\isyvoo.exe
O4 - HKLM\..\Run: [xddql] C:\WINDOWS\system32\lpnpri\xddql.exe
O4 - HKLM\..\Run: [oxdw] C:\WINDOWS\system32\tajpn\oxdw.exe
O4 - HKLM\..\Run: [xgymtxgw] C:\WINDOWS\system32\enonjbh\xgymtxgw.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\agrtpu.exe reg_run
O4 - HKLM\..\Run: [vrpvfl] C:\WINDOWS\system32\akiu\vrpvfl.exe
O4 - HKLM\..\Run: [thheqjtb] C:\WINDOWS\system32\prts\thheqjtb.exe
O4 - HKLM\..\Run: [win32091195064702] C:\WINDOWS\win32091195064702.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [TagASaurus] C:\Program Files\TagASaurus\TagASaurus
O4 - HKLM\..\Run: [nmlov] C:\WINDOWS\nmlov.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [adprot] C:\WINDOWS\system32\adprot.exe
O4 - HKLM\..\Run: [yhddon] C:\WINDOWS\system32\yhnia\yhddon.exe
O4 - HKLM\..\Run: [win32082119506470] C:\WINDOWS\win32082119506470.exe
O4 - HKLM\..\Run: [YourMonitor] C:\WINDOWS\YourMonitor
O4 - HKLM\..\Run: [xossd] C:\WINDOWS\system32\ysrrmxxw\xossd.exe
O4 - HKLM\..\Run: [ms046470211950] C:\WINDOWS\ms046470211950.exe
O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\system32\nfomon\nfomon.exe
O4 - HKLM\..\Run: [vidmon] C:\WINDOWS\system32\vidmon\vidmon.exe
O4 - HKLM\..\Run: [ajfbwopi] C:\WINDOWS\system32\ouxtbef\ajfbwopi.exe
O4 - HKLM\..\Run: [nkmg] C:\WINDOWS\system32\qeyt\nkmg.exe
O4 - HKLM\..\Run: [onpj] C:\WINDOWS\system32\plwbal\onpj.exe
O4 - HKLM\..\Run: [epcvipp] C:\WINDOWS\system32\qwwrgolt\epcvipp.exe
O4 - HKLM\..\Run: [tlaqjros] C:\WINDOWS\system32\hllywdxo\tlaqjros.exe
O4 - HKLM\..\Run: [dctrkl] C:\WINDOWS\system32\kqggi\dctrkl.exe
O4 - HKLM\..\Run: [mafkjp] C:\WINDOWS\system32\ovsw\mafkjp.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [ravq] C:\WINDOWS\system32\jgoqrrrt\ravq.exe
O4 - HKLM\..\Run: [uvdelmf] C:\WINDOWS\system32\ajxylp\uvdelmf.exe
O4 - HKLM\..\Run: [udsmapk] C:\WINDOWS\system32\lcqdtoq\udsmapk.exe
O4 - HKLM\..\Run: [cwgghk] C:\WINDOWS\system32\lnse\cwgghk.exe
O4 - HKLM\..\Run: [exeqtsrb] C:\WINDOWS\system32\eucaa\exeqtsrb.exe
O4 - HKLM\..\Run: [pougk] C:\WINDOWS\system32\rbeoyu\pougk.exe
O4 - HKLM\..\Run: [eelaxtuf] C:\WINDOWS\system32\cjqx\eelaxtuf.exe
O4 - HKLM\..\Run: [xbkyha] C:\WINDOWS\system32\wkysaktm\xbkyha.exe
O4 - HKLM\..\Run: [rgibmuow] C:\WINDOWS\system32\yqkvpcfg\rgibmuow.exe
O4 - HKLM\..\Run: [shcwdal] C:\WINDOWS\system32\thkf\shcwdal.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\system32\qeltefg.exe
O4 - HKLM\..\Run: [OSS] C:\windows\rlvknlg.exe -boot
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\system32\vidctrl\vidctrl.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [f0t3RPYmg] iesap.exe
O4 - HKCU\..\Run: [Min] C:\WINDOWS\System32\?hkdsk.exe
O4 - HKCU\..\Run: [SAFESAVE] C:\DOCUME~1\Joshua\APPLIC~1\ACEFLA~1\Warn gpl coal.exe
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE"
O4 - HKCU\..\Run: [Aida] C:\Program Files\rdso\eetu.exe
O4 - HKCU\..\Run: [AssignmentBerlinSetup.exe] C:\MYDOWN~1\ASSIGN~1.EXE /r
O4 - HKCU\..\Run: [YourMonitor] C:\WINDOWS\YourMonitor.exe
O4 - HKCU\..\Run: [Sys98] C:\WINDOWS\Sys98.exe
O4 - HKCU\..\Run: [appere] C:\WINDOWS\system32\appere.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\RunOnce: [appere] C:\WINDOWS\system32\appere.exe
O4 - Global Startup: nupa.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download with Download Accelerator Lite - C:\Program Files\Download Accelerator Lite\dal.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\aim\aim.exe
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4571/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: AVG7 Alert Manager Server - Unknown - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
O23 - Service: AVG7 Update Service - Unknown - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)
O23 - Service: bjhwuwmviqkappem - Unknown - C:\WINDOWS\system32\iqkappem\bjhwuwmv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: duvrmcqqxiqvj - Unknown - C:\WINDOWS\system32\qxiqvj\duvrmcq.exe
O23 - Service: greenstdsystem32 - Unknown - C:\WINDOWS\system32\greenstd.exe (file missing)
O23 - Service: hrrdnbtjkywbj - Unknown - C:\WINDOWS\system32\tjkywbj\hrrdnb.exe
O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: isyvoowtuwtgyb - Unknown - C:\WINDOWS\system32\wtuwtgyb\isyvoo.exe
O23 - Service: kavsvc - Unknown - C:\Program Files\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti-Virus Personal\kavsvc.exe (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel(R) NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: oxdwtajpn - Unknown - C:\WINDOWS\system32\tajpn\oxdw.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: qbyktyywi - Unknown - C:\WINDOWS\system32\tyywi\qbyk.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: thheqjtbprts - Unknown - C:\WINDOWS\system32\prts\thheqjtb.exe
O23 - Service: tqqpymldcngxfr - Unknown - C:\WINDOWS\system32\dcngxfr\tqqpyml.exe
O23 - Service: utxryrrtoubgt - Unknown - C:\WINDOWS\system32\rtoubgt\utxryr.exe
O23 - Service: vrpvflakiu - Unknown - C:\WINDOWS\system32\akiu\vrpvfl.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: xddqllpnpri - Unknown - C:\WINDOWS\system32\lpnpri\xddql.exe
O23 - Service: xgymtxgwenonjbh - Unknown - C:\WINDOWS\system32\enonjbh\xgymtxgw.exe
O23 - Service: xossdysrrmxxw - Unknown - C:\WINDOWS\system32\ysrrmxxw\xossd.exe
O23 - Service: yhddonyhnia - Unknown - C:\WINDOWS\system32\yhnia\yhddon.exe

13 Years
Discussion Span
Last Post by DMR

Ouch; that's a pretty heavily infested system. :(

Please perform the following general cleaning procedures:

You will need to disconnect from the Internet for some of the following, so you should print out the following instructions or save them into a text file with Notepad.

1. Run at least two or three of the following online anti-virus/anti-spyware scans and let them fix what they can:


2. Download, install, and run the following (free) detection and removal tools (use each program's online update function before running them to make sure you have the most current updates installed).

After each utility completes its fixes, reboot before continuing on to the next utility; have the utilities fix all of the problematic/malicious items they find:

ewido Security Suite - http://www.ewido.net/en/download/
Microsoft Anti-Spyware beta - http://www.microsoft.com/downloads/...&displaylang=en
Ad Aware SE Personal - http://www.lavasoftusa.com/
SpyBot Search & Destroy - http://www.safer-networking.org/

3. Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up)

- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".

- For every user account listed under C:\Documents and Settings, delete the entire contents of these folders (but not the folders themselves):

Important: One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if any data that you care about is living in those Temp folders, you need to move it to a safe location now, or it will be erased along with everything else!

1. Cookies
2. Local Settings\Temp
3. Local Settings\History
4. Local Settings\Temporary Internet Files

- Delete the entire content of your C:\Windows\Temp folder.

- Delete the entire content of your C:\Windows\Prefetch folder.

Note- If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed. Windows will allow you to delete the versions of those files which exist in sub-folders within the main Temp/Temorary folders, but might not let you delete the versions of those files that exist in the main Temp folders themselves; this is normal and OK.

- Empty your Recycle Bin.

4. Reboot normally, run HijackThis again, and post the new log. Also post the scan log that ewido generated.

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.