help about spywares!! :( my desktop changed to this
[IMG]http://img.photobucket.com/albums/v644/maderpaker01/taena.jpg[/IMG]
heres my hjlog
Logfile of HijackThis v1.99.1
Scan saved at 2:19:37 PM, on 3/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\WINDOWS\System32\Fec.exe
C:\WINDOWS\gbxivopi.exe
C:\WINDOWS\Mke.exe
C:\WINDOWS\Mln.exe
C:\WINDOWS\System32\Ihs.exe
C:\WINDOWS\Epb.exe
C:\WINDOWS\Lig.exe
C:\WINDOWS\Kmn.exe
C:\WINDOWS\Bio.exe
C:\WINDOWS\Jtb.exe
C:\WINDOWS\System32\Tti.exe
C:\WINDOWS\Gmr.exe
C:\WINDOWS\System32\Sfa.exe
C:\WINDOWS\System32\Rck.exe
C:\WINDOWS\Uor.exe
C:\WINDOWS\System32\Ejo.exe
C:\WINDOWS\System32\Gcl.exe
C:\WINDOWS\System32\Roc.exe
C:\WINDOWS\Dus.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\Fec.exe
C:\WINDOWS\Mke.exe
C:\WINDOWS\Mln.exe
C:\WINDOWS\System32\Ihs.exe
C:\WINDOWS\Epb.exe
C:\WINDOWS\Lig.exe
C:\WINDOWS\Kmn.exe
C:\WINDOWS\Bio.exe
C:\WINDOWS\Jtb.exe
C:\WINDOWS\System32\Tti.exe
C:\WINDOWS\Gmr.exe
C:\WINDOWS\System32\Sfa.exe
C:\WINDOWS\System32\Rck.exe
C:\WINDOWS\Uor.exe
C:\WINDOWS\System32\Ejo.exe
C:\WINDOWS\System32\Gcl.exe
C:\WINDOWS\System32\Roc.exe
C:\WINDOWS\Dus.exe
C:\WINDOWS\System32\Rno.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\System32\connmie.exe
C:\WINDOWS\System32\truettf.exe
C:\WINDOWS\System32\dxconf.exe
C:\Program Files\Opera\opera.exe
C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {1C09F143-07FA-49BF-A729-90460914F0B3} - C:\WINDOWS\System32\nfo.dll
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\System32\DSMANA~1.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [Gtn] C:\WINDOWS\System32\Fec.exe
O4 - HKLM\..\Run: [wval8GZ] C:\WINDOWS\gbxivopi.exe
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [Rgk] C:\WINDOWS\Mke.exe
O4 - HKLM\..\Run: [Lmm] C:\WINDOWS\Mln.exe
O4 - HKLM\..\Run: [Sof] C:\WINDOWS\System32\Ihs.exe
O4 - HKLM\..\Run: [Ngl] C:\WINDOWS\Epb.exe
O4 - HKLM\..\Run: [Drk] C:\WINDOWS\System32\Run.exe
O4 - HKLM\..\Run: [Sgg] C:\WINDOWS\Lig.exe
O4 - HKLM\..\Run: [Euo] C:\WINDOWS\Kmn.exe
O4 - HKLM\..\Run: [Tsa] C:\WINDOWS\Bio.exe
O4 - HKLM\..\Run: [Ibl] C:\WINDOWS\Jtb.exe
O4 - HKLM\..\Run: [Nmk] C:\WINDOWS\System32\Tti.exe
O4 - HKLM\..\Run: [Onj] C:\WINDOWS\Gmr.exe
O4 - HKLM\..\Run: [Vup] C:\WINDOWS\System32\Sfa.exe
O4 - HKLM\..\Run: [Hts] C:\WINDOWS\System32\Rck.exe
O4 - HKLM\..\Run: [Huh] C:\WINDOWS\Uor.exe
O4 - HKLM\..\Run: [Ftb] C:\WINDOWS\System32\Ejo.exe
O4 - HKLM\..\Run: [Fri] C:\WINDOWS\System32\Gcl.exe
O4 - HKLM\..\Run: [Kek] C:\WINDOWS\System32\Roc.exe
O4 - HKLM\..\Run: [Hmj] C:\WINDOWS\Dus.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Qhd] C:\WINDOWS\System32\Rno.exe
O4 - HKLM\..\Run: [Lbj] C:\WINDOWS\Ovo.exe
O4 - HKLM\..\Run: [Egs] C:\WINDOWS\System32\Rua.exe
O4 - HKLM\..\Run: [Ioq] C:\WINDOWS\Jll.exe
O4 - HKLM\..\Run: [Qaa] C:\WINDOWS\System32\Hnl.exe
O4 - HKLM\..\Run: [Uep] C:\WINDOWS\System32\Pap.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [ChikkaIM] C:\PROGRA~1\CHIKKA\Chikka.exe
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1034.dll,InstantAccess
O4 - HKCU\..\Run: [Gtn] C:\WINDOWS\System32\Fec.exe
O4 - HKCU\..\Run: [Rgk] C:\WINDOWS\Mke.exe
O4 - HKCU\..\Run: [Lmm] C:\WINDOWS\Mln.exe
O4 - HKCU\..\Run: [Sof] C:\WINDOWS\System32\Ihs.exe
O4 - HKCU\..\Run: [Ngl] C:\WINDOWS\Epb.exe
O4 - HKCU\..\Run: [Drk] C:\WINDOWS\System32\Run.exe
O4 - HKCU\..\Run: [Sgg] C:\WINDOWS\Lig.exe
O4 - HKCU\..\Run: [Euo] C:\WINDOWS\Kmn.exe
O4 - HKCU\..\Run: [Tsa] C:\WINDOWS\Bio.exe
O4 - HKCU\..\Run: [Ibl] C:\WINDOWS\Jtb.exe
O4 - HKCU\..\Run: [Nmk] C:\WINDOWS\System32\Tti.exe
O4 - HKCU\..\Run: [Onj] C:\WINDOWS\Gmr.exe
O4 - HKCU\..\Run: [Vup] C:\WINDOWS\System32\Sfa.exe
O4 - HKCU\..\Run: [Hts] C:\WINDOWS\System32\Rck.exe
O4 - HKCU\..\Run: [Huh] C:\WINDOWS\Uor.exe
O4 - HKCU\..\Run: [Ftb] C:\WINDOWS\System32\Ejo.exe
O4 - HKCU\..\Run: [Fri] C:\WINDOWS\System32\Gcl.exe
O4 - HKCU\..\Run: [Kek] C:\WINDOWS\System32\Roc.exe
O4 - HKCU\..\Run: [Hmj] C:\WINDOWS\Dus.exe
O4 - HKCU\..\Run: [Qhd] C:\WINDOWS\System32\Rno.exe
O4 - HKCU\..\Run: [Lbj] C:\WINDOWS\Ovo.exe
O4 - HKCU\..\Run: [Egs] C:\WINDOWS\System32\Rua.exe
O4 - HKCU\..\Run: [Ioq] C:\WINDOWS\Jll.exe
O4 - HKCU\..\Run: [Qaa] C:\WINDOWS\System32\Hnl.exe
O4 - HKCU\..\Run: [Uep] C:\WINDOWS\System32\Pap.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted IP range: 67.19.185.246
O15 - Trusted IP range: 67.19.185.246 (HKLM)
O16 - DPF: {505098FD-5D61-4BC2-9B82-F969D0E932A2} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1034_EN_XP.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://210.1.70.65/nProtect/KeyCrypt/npkcx.cab
O16 - DPF: {DD85FDB7-9363-4873-B50C-CC46F3E4B704} (IGOLauncher6 Control) - http://vitalsign.igamesasia.com.sg/activex/IGOLauncher6.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
O18 - Filter: text/html - {458F46A8-D2AE-4707-93C2-2917078C065B} - C:\WINDOWS\System32\nfo.dll
O18 - Filter: text/plain - {458F46A8-D2AE-4707-93C2-2917078C065B} - C:\WINDOWS\System32\nfo.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe