There seems to be some spyware that my computer scans can't pick up. You guys have aways helped me weed out my bad files and registry items in the past. I would really appreciate it if you could isolate the problem for me again.
Thank you so much
Zach
Logfile of HijackThis v1.99.1
Scan saved at 3:14:16 PM, on 11/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Retail STAR\dbntsrv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\mfcsu32.exe
C:\WINDOWS\system32\netzl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Retail STAR\StarSchd.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\The Village Hat Shop\Desktop\Adware stuff\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\eavqd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\eavqd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\eavqd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\eavqd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\eavqd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\eavqd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\eavqd.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {00A88ECE-D542-06D0-B1E9-091150D86D41} - C:\WINDOWS\system32\msxj32.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {0B49DBF5-766B-A933-707E-C0D543F141BB} - C:\WINDOWS\crqy.dll
O2 - BHO: Class - {0B937114-0E13-062A-9867-38F38B2CC09F} - C:\WINDOWS\system32\addvr.dll (file missing)
O2 - BHO: Class - {13C5BB54-5447-119B-46D2-63264CDBEC0F} - C:\WINDOWS\atlxm.dll (file missing)
O2 - BHO: Class - {14ACC8C5-5DB2-26C5-6B40-0B8750DAAFDE} - C:\WINDOWS\system32\javaro.dll (file missing)
O2 - BHO: Class - {17399FDF-699F-E10C-F790-3872A961BD8F} - C:\WINDOWS\system32\d3kh.dll (file missing)
O2 - BHO: Class - {24A9B7CC-0A40-BEE6-67C3-A5771F0A62F7} - C:\WINDOWS\system32\atlba32.dll (file missing)
O2 - BHO: Class - {257D6D3D-1C77-15FB-6BF6-9347E8F69CEB} - C:\WINDOWS\system32\ipia.dll (file missing)
O2 - BHO: Class - {2B56AA49-1949-09E1-63C4-F9A683F6EB92} - C:\WINDOWS\system32\addov32.dll (file missing)
O2 - BHO: Class - {2E34D0ED-0B55-5C98-05DD-51F59AB52E3A} - C:\WINDOWS\crla.dll (file missing)
O2 - BHO: Class - {3090709C-6EA7-0316-84DA-2AC3A09FD1CB} - C:\WINDOWS\crug32.dll
O2 - BHO: Class - {325EAD02-95B5-830B-5E5C-CD067BAA172B} - C:\WINDOWS\system32\sysmt.dll (file missing)
O2 - BHO: Class - {41FF1819-6FA4-A22B-A9BB-7621D02FEE43} - C:\WINDOWS\javaff32.dll (file missing)
O2 - BHO: Class - {47AC66D0-CE97-D311-E35F-40428823161F} - C:\WINDOWS\system32\cryr32.dll (file missing)
O2 - BHO: Class - {4BE23432-C392-D735-5711-ADB1E652BF8E} - C:\WINDOWS\system32\atlzk.dll (file missing)
O2 - BHO: Class - {5883D979-5C1C-5AE9-C370-C39713BB8756} - C:\WINDOWS\addfg32.dll (file missing)
O2 - BHO: Class - {58E19DDB-FF55-C80E-005C-675F6F8331B0} - C:\WINDOWS\system32\apivy.dll (file missing)
O2 - BHO: Class - {646F6A47-24D0-2033-3709-4F9D79ED6FC9} - C:\WINDOWS\atlpe.dll (file missing)
O2 - BHO: Class - {67376861-75B6-22CE-83C5-3D32CF86C703} - C:\WINDOWS\system32\addcn.dll
O2 - BHO: Class - {69C2D265-3B93-BC0A-676E-D0FD27DA5AC6} - C:\WINDOWS\system32\winvw.dll
O2 - BHO: Class - {70958982-9286-4C4E-3FD3-FEC16A115FBF} - C:\WINDOWS\javakk.dll
O2 - BHO: Class - {75FF0CF0-2B28-1964-55E8-CDEF044A53AC} - C:\WINDOWS\system32\ipyf32.dll
O2 - BHO: Class - {8044BFB2-40EC-C70A-C711-736B0EE1248F} - C:\WINDOWS\system32\winuw32.dll
O2 - BHO: Class - {8C2CBD99-0FCD-5C08-EDD5-4E5F4A8D33A0} - C:\WINDOWS\system32\javamy32.dll
O2 - BHO: Class - {8C38E844-57F2-3EDD-FEEA-F53BAA76633A} - C:\WINDOWS\crgs32.dll
O2 - BHO: Class - {8C69AF50-B4D5-7388-4CA4-3D0EEF96193F} - C:\WINDOWS\netaz.dll
O2 - BHO: Class - {8D1F9E37-0A0E-42B8-D6EE-2A8A3257FE9F} - C:\WINDOWS\iedt32.dll
O2 - BHO: Class - {8D565590-A209-9855-93F1-821B80B1EAD4} - C:\WINDOWS\iewq.dll
O2 - BHO: Class - {8EDB05B3-5843-24CB-46FB-6FA177E65713} - C:\WINDOWS\ntsp32.dll
O2 - BHO: Class - {927E57D6-F30D-0656-3454-9DCE557E5E8E} - C:\WINDOWS\system32\sysxr32.dll
O2 - BHO: Class - {9291DF23-029D-DC8D-B7E6-64BEFF3F25AF} - C:\WINDOWS\system32\winyt32.dll
O2 - BHO: Class - {92E41AF0-C151-25C6-66EF-4B3CE41A3E92} - C:\WINDOWS\system32\sysye.dll
O2 - BHO: Class - {933B6E2E-FEA0-1AF1-B7C0-9FE2EF16849A} - C:\WINDOWS\javayp32.dll
O2 - BHO: Class - {992CC6B0-F19C-96EB-B2AC-26F988029CAD} - C:\WINDOWS\ippf.dll
O2 - BHO: Class - {9FD3E41B-894A-375B-D1FB-85FBCC6A9DFF} - C:\WINDOWS\system32\netua.dll
O2 - BHO: Class - {A0F1D4D8-ADE0-D9D7-4BE2-92D771F1BC8A} - C:\WINDOWS\ntor32.dll
O2 - BHO: Class - {A0FC711E-2AC4-5B52-9D75-90B797E38DED} - C:\WINDOWS\system32\mfcab.dll
O2 - BHO: Class - {A77FBB24-6758-A44E-FEB7-E7CF6EE350DB} - C:\WINDOWS\mfcdg.dll
O2 - BHO: Class - {AC152C0C-381B-A230-6B29-1A23741F4A9A} - C:\WINDOWS\ipki.dll
O2 - BHO: Class - {B35C1647-FF47-9FEF-3DE2-7B4BBD5741D3} - C:\WINDOWS\mfcgv.dll
O2 - BHO: Class - {B661DFA3-1238-16D4-3926-4935BAF6CB6F} - C:\WINDOWS\system32\ntud32.dll
O2 - BHO: Class - {B912E0DE-C5DE-D46B-A8B0-802D6CB6F68C} - C:\WINDOWS\appyc32.dll
O2 - BHO: Class - {BE2BEA96-036C-1422-910E-62600A0061B9} - C:\WINDOWS\system32\javafn.dll
O2 - BHO: Class - {C29B2852-3733-DE06-C399-8E0A964E2124} - C:\WINDOWS\system32\d3ur32.dll
O2 - BHO: Class - {C6D6D264-D1BF-2B26-E95A-909FFD54938F} - C:\WINDOWS\sdkkt.dll
O2 - BHO: Class - {C8C69528-DCF0-EAE8-04F8-ADE94307B6EE} - C:\WINDOWS\ipig.dll
O2 - BHO: Class - {D27E597C-B77D-B4D7-FB04-A926F90AF9B2} - C:\WINDOWS\system32\iehc32.dll
O2 - BHO: Class - {E5ABA926-4A51-C5FD-9089-0E3741C5ED04} - C:\WINDOWS\system32\netuf32.dll
O2 - BHO: Class - {E61BC869-33C7-AC36-F015-C0910E22E342} - C:\WINDOWS\system32\wintz32.dll
O2 - BHO: Class - {E97180CF-0651-4CEB-8F0C-B9D3C4877FE2} - C:\WINDOWS\system32\apitk32.dll
O2 - BHO: Class - {EAC75C37-4B26-E9E1-9622-A78D21C5DB24} - C:\WINDOWS\system32\javamu.dll
O2 - BHO: Class - {EC5F1AF3-CF0D-5AC3-A2FD-C4AD27BAD24A} - C:\WINDOWS\sysyl32.dll
O2 - BHO: Class - {F0369D81-D189-AC88-E454-02C0B2632F5E} - C:\WINDOWS\d3cc.dll
O2 - BHO: Class - {F8F6985E-5F1E-9567-733D-D3264B60E41C} - C:\WINDOWS\d3oy.dll
O2 - BHO: (no name) - {FA368488-8008-3889-4E2F-86BBFD486BD2} - (no file)
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [systx.exe] C:\WINDOWS\systx.exe
O4 - HKLM\..\Run: [ipui32.exe] C:\WINDOWS\ipui32.exe
O4 - HKLM\..\Run: [netzl.exe] C:\WINDOWS\system32\netzl.exe
O4 - HKLM\..\RunOnce: [mfcsu32.exe] C:\WINDOWS\system32\mfcsu32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - Startup: SBC.lnk = ?
O4 - Startup: Schedule STAR.lnk = C:\Program Files\Retail STAR\StarSchd.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/16756ba3...p/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1129243595906
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://supporttrial.webex.com/clien...rt/ieatgpc.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EADB5F57-B4C5-4584-B2D8-8DD5B3F5A13E}: NameServer = 206.13.31.12 206.13.28.12
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\netst32.exe (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Centura SQLBase - Centura Software - C:\Program Files\Retail STAR\dbntsrv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe