Here is my log..... plz plz help me!!!!! ><
Logfile of HijackThis v1.99.1
Scan saved at 7:55:07 AM, on 10/04/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVIRA Desktop\AVWUPSRV.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
D:\Program Files\ImTOO\ER2002\EasyRead.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\paytime.exe
C:\WINDOWS\Gsk.exe
C:\WINDOWS\System32\ap9h4qmo.exe
C:\Program Files\AVIRA Desktop\AVGNT.EXE
C:\windows\system32\whohkkrg.exe
C:\windows\system32\packager.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\paytime.exe
D:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\eBay\eBay Toolbar\4.4.0.2\ebaytbar.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\wuauclt.exe
D:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Tracy Liu.TRACY\Local Settings\Temp\HijackThis.exe
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: eBay Helper Object - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - C:\Program Files\eBay\eBay Toolbar\4.4.0.2\eBayBand.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {A0269420-A638-4509-889C-8FC3CC85DA7E} - C:\WINDOWS\drexinit.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - blank (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:\Program Files\eBay\eBay Toolbar\4.4.0.2\eBayBand.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [ER2002] D:\Program Files\ImTOO\ER2002\EasyRead.exe
O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [MediaFace Integration] D:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKLM\..\Run: [Glm] C:\WINDOWS\Gsk.exe
O4 - HKLM\..\Run: [Disk Keeper] C:\DOCUME~1\TRACYL~1.TRA\LOCALS~1\Temp\keep.exe
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\System32\ap9h4qmo.exe
O4 - HKLM\..\Run: [Cmo] C:\WINDOWS\Unk.exe
O4 - HKLM\..\Run: [Tbj] C:\WINDOWS\System32\Oba.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVIRA Desktop\AVGNT.EXE" /min
O4 - HKLM\..\Run: [AVWUpd32] "C:\PROGRA~1\AVIRAD~1\Avwupd32.EXE" /min
O4 - HKLM\..\Run: [Mah] C:\WINDOWS\Gmi.exe
O4 - HKLM\..\Run: [whohkkrg] c:\windows\system32\whohkkrg.exe
O4 - HKLM\..\Run: [Jth] C:\WINDOWS\Gtp.exe
O4 - HKLM\..\Run: [Bms] C:\WINDOWS\Rkt.exe
O4 - HKLM\..\Run: [Osa] C:\WINDOWS\System32\Tjd.exe
O4 - HKLM\..\Run: [Jmc] C:\WINDOWS\System32\Evm.exe
O4 - HKLM\..\Run: [Udp] C:\WINDOWS\System32\Ofp.exe
O4 - HKLM\..\Run: [Noo] C:\WINDOWS\Grp.exe
O4 - HKLM\..\Run: [Arn] C:\WINDOWS\System32\Ftu.exe
O4 - HKLM\..\Run: [Sda] C:\WINDOWS\System32\Liq.exe
O4 - HKLM\..\Run: [Snk] C:\WINDOWS\System32\Pie.exe
O4 - HKLM\..\Run: [Hrk] C:\WINDOWS\Cjd.exe
O4 - HKLM\..\Run: [Vao] C:\WINDOWS\Nnk.exe
O4 - HKLM\..\Run: [Acg] C:\WINDOWS\System32\Evh.exe
O4 - HKLM\..\Run: [Dcv] C:\WINDOWS\System32\Bgg.exe
O4 - HKLM\..\Run: [Ehj] C:\WINDOWS\Lvp.exe
O4 - HKLM\..\Run: [Adr] C:\WINDOWS\System32\Hkk.exe
O4 - HKLM\..\Run: [Usd] C:\WINDOWS\Jhj.exe
O4 - HKLM\..\Run: [Hbe] C:\WINDOWS\System32\Npf.exe
O4 - HKLM\..\Run: [AGBMonitor] d:\Program Files\Antiy Labs\AGB4\Monitor.exe
O4 - HKLM\..\Run: [Trc] C:\WINDOWS\System32\Bgp.exe
O4 - HKLM\..\Run: [Ecc] C:\WINDOWS\Jur.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Glm] C:\WINDOWS\Gsk.exe
O4 - HKCU\..\Run: [Cmo] C:\WINDOWS\Unk.exe
O4 - HKCU\..\Run: [Tbj] C:\WINDOWS\System32\Oba.exe
O4 - HKCU\..\Run: [Mah] C:\WINDOWS\Gmi.exe
O4 - HKCU\..\Run: [Jth] C:\WINDOWS\Gtp.exe
O4 - HKCU\..\Run: [Bms] C:\WINDOWS\Rkt.exe
O4 - HKCU\..\Run: [Osa] C:\WINDOWS\System32\Tjd.exe
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Jmc] C:\WINDOWS\System32\Evm.exe
O4 - HKCU\..\Run: [Udp] C:\WINDOWS\System32\Ofp.exe
O4 - HKCU\..\Run: [Noo] C:\WINDOWS\Grp.exe
O4 - HKCU\..\Run: [Arn] C:\WINDOWS\System32\Ftu.exe
O4 - HKCU\..\Run: [Sda] C:\WINDOWS\System32\Liq.exe
O4 - HKCU\..\Run: [Snk] C:\WINDOWS\System32\Pie.exe
O4 - HKCU\..\Run: [Hrk] C:\WINDOWS\Cjd.exe
O4 - HKCU\..\Run: [Vao] C:\WINDOWS\Nnk.exe
O4 - HKCU\..\Run: [Acg] C:\WINDOWS\System32\Evh.exe
O4 - HKCU\..\Run: [Dcv] C:\WINDOWS\System32\Bgg.exe
O4 - HKCU\..\Run: [Ehj] C:\WINDOWS\Lvp.exe
O4 - HKCU\..\Run: [Adr] C:\WINDOWS\System32\Hkk.exe
O4 - HKCU\..\Run: [Usd] C:\WINDOWS\Jhj.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Hbe] C:\WINDOWS\System32\Npf.exe
O4 - HKCU\..\Run: [Trc] C:\WINDOWS\System32\Bgp.exe
O4 - HKCU\..\Run: [Ecc] C:\WINDOWS\Jur.exe
O4 - Global Startup: eBay Toolbar.LNK = C:\Program Files\eBay\eBay Toolbar\4.4.0.2\ebaytbar.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: EasyRead Translate - C:\Program Files\Common Files\ImTOO\ER2002\TransAll.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: EasyRead - {008B57BE-DA82-4b30-9A3E-D1A216A22939} - C:\Program Files\Common Files\ImTOO\ER2002\TransAll.html
O9 - Extra 'Tools' menuitem: EasyRead - {008B57BE-DA82-4b30-9A3E-D1A216A22939} - C:\Program Files\Common Files\ImTOO\ER2002\TransAll.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: eBay - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\Program Files\eBay\eBay Toolbar\4.4.0.2\eBayBand.dll
O9 - Extra 'Tools' menuitem: eBay - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:\Program Files\eBay\eBay Toolbar\4.4.0.2\eBayBand.dll
O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\qq\QQ.exe
O9 - Extra 'Tools' menuitem: Tencent QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - D:\Program Files\Tencent\qq\QQ.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Tornado 21 -
http://download.games.yahoo.com/games/clients/y/t21t0_x.cabO16 - DPF: Yahoo! Blackjack -
http://download.games.yahoo.com/games/clients/y/jt0_x.cabO16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/games/clients/y/ct2_x.cabO16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-24.cabO16 - DPF: {54771E6F-A5A2-4413-8FB8-7B8F85398174} -
http://dl.lygo.com/Sidesearch/en_US/angelfire/Sidesearch.cabO16 - DPF: {637BB540-6ABA-11D4-901D-00D0090CB3BC} (FMClass Class) -
http://www.myplay.com.tw/service/fmplayerKland.cabO16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
http://99liao.net/talk.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.macromedia.com/pub/shockwa...ash/swflash.cabO23 - Service: AVIRA Update (AVWUpSrv) - AVIRA GmbH - C:\Program Files\AVIRA Desktop\AVWUPSRV.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe