I need help on getting it removed
completely.
Logfile of HijackThis v1.99.1
Scan saved at 11:53:41 AM, on 3/1/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\Hlydit.exe
C:\WINDOWS\isrvs\desktop.exe
C:\WINDOWS\System32\wsxsvc\wsxsvc.exe
C:\WINDOWS\System32\vmss\vmss.exe
C:\WINDOWS\yfqtjj.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\System32\wqfd.exe
C:\WINDOWS\System32\sysmonnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Jonathan\Desktop\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.games-fusion.net/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {30BCA8E3-FF20-4DDF-A2B7-6D3F52968687} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: (no name) - {5D622B03-DDE4-4A9B-9317-88F566295870} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {69B5361E-9587-48C8-8728-8BEA535D9125} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {6E38529C-92CC-4DAD-B1F2-7C5BD2B17D31} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {88672CB8-70F5-47E2-A0FE-199AE9FA40BB} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {96C14148-16C6-4F84-8E2D-58EC607A8F56} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {B6631E1D-972F-4C5A-B0F4-68C8AB81326A} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {C5CFA7F2-F8F8-4083-9E75-7DB6A4E3D265} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {C8D94F0D-B747-4C49-83B6-B09B511196C4} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {CC05116D-6DD8-4575-9F53-ADEA1684ED42} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {CE05A11D-4D5B-4460-B9E8-EA996327261C} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {CF4F48FA-3581-44BF-B453-B835A96074CC} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {D210A0C2-9AED-422D-8113-8CD0CCC38913} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {EA41E789-C3E8-4B05-9FE6-B653665BFC15} - C:\Program Files\nqabump8\nqabump8.dll
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O2 - BHO: (no name) - {F950E67B-696C-4ACE-BCED-6479B056E403} - C:\Program Files\nqabump8\nqabump8.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Zpdlkt.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Hlydit.exe
O4 - HKLM\..\Run: [tjeizc] C:\WINDOWS\System32\tjeizc.exe
O4 - HKLM\..\Run: [qhwftc] C:\WINDOWS\System32\qhwftc.exe
O4 - HKLM\..\Run: [HPNT] C:\Program Files\hpdll\hpdll.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\System32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINDOWS\System32\vmss\vmss.exe
O4 - HKLM\..\Run: [nqabump8] C:\Program Files\nqabump8\nqabump8.exe
O4 - HKLM\..\Run: [rwydfc] C:\WINDOWS\System32\rwydfc.exe
O4 - HKLM\..\Run: [Ap9BAae] C:\WINDOWS\yfqtjj.exe
O4 - HKLM\..\Run: [rnd] C:\WINDOWS\System32\rnd.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [JVM0.12] C:\WINDOWS\System32\wqfd.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - HKCU\..\Run: [warez] "C:\Program Files\Warez P2P Client\Warez.exe" -h
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: ÁåÉù - {7FA48D98-F2F7-4FAD-9762-2F7165D51650} -
http://soft.jily.net/redirect/ring.htm (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: µ¼º½ - {B252D7FF-47B3-4B41-9E69-69D6C1ED523A} -
http://www.jily.net/site.htm (file missing)
O9 - Extra button: Ìý¸è - {CC56C5BE-005C-4F82-BC68-E2FD0F819CDB} -
http://soft.jily.net/redirect/music.htm (file missing)
O15 - Trusted Zone:
http://www.neededware.comO16 - DPF: NDWCab -
http://www.neededware.com/NDWCab.CABO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cabO16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) -
http://player.bugs.co.kr/install/mv/XTools.cabO16 - DPF: {BF628973-1E86-4D0E-B42C-EDDECFFABDBC} (Bugs AoD Class) -
http://player.bugs.co.kr/install/bugsLoader20041018.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cabO18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (Omega 1.6177) (P) (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe