Logfile of HijackThis v1.98.0
Scan saved at 2:39:31 PM, on 7/30/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32
.DLL
C:\WINDOWS\SYSTEM\MSGSRV32
.EXE
C:\WINDOWS\SYSTEM\MPREXE.E
XE
C:\WINDOWS\SYSTEM\SSDPSRV.
EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\mmtask.t
sk
C:\WINEYES\WINEYES.EXE
C:\WINEYES\SPEECH32.EXE
C:\WINEYES\GWM32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINEYES\BDISPLAY.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.
EXE
C:\WINDOWS\RUNDLL32.EXE
D:\BKUP\PROGRAM FILES\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\WIRELESS DESKTOP\MOUSE32A.EXE
E:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\POPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTS
VC.EXE
C:\WINDOWS\RunDLL.exe
E:\PROGRAM FILES\AUTOSPELL50\ASWATC32
.EXE
C:\PROGRAM FILES\WIRELESS DESKTOP\MAGICKEY.EXE
E:\Program Files\autospell50\aswatc16
.exe
C:\WINDOWS\SYSTEM\WMIEXE.E
XE
D:\PROGRAM FILES\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = http=proxy-server.hawaii.r
r.com:8080
;https=pro
xy-server.
hawaii.rr.
com:8080
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = ams-server.hawaii.rr.com; update-server.hawaii.rr.co
m;<local>
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\PROGRAM FILES\YAHOO!\COMPANION\INS
TALLS\CPN0
\YCOMP5_3_
12_0.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - E:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEH
ELPER.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\windows\downloaded program files\googletoolbar1.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\PROGRAM FILES\YAHOO!\COMPANION\INS
TALLS\CPN0
\YCOMP5_3_
12_0.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\windows\downloaded program files\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\Run: [ICSDCLT] c:\windows\rundll32.exe c:\windows\SYSTEM\icsdclt.
dll,ICSCli
ent
O4 - HKLM\..\Run: [Norton Auto-Protect] D:\bkup\program files\Program Files\Norton SystemWorks\Norton AntiVirus\navapw32.exe /LOADQUIET
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Wireless Desktop\MOUSE32A.EXE
O4 - HKLM\..\Run: [Norton eMail Protect] E:\Program Files\Norton SystemWorks\Norton AntiVirus\POPROXY.EXE
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evnts
vc.exe -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [SSDPSRV] c:\windows\SYSTEM\ssdpsrv.
exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [WinEyes] C:\WINEYES\WINEYES.EXE
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUND
LLENTRY
O4 - Startup: AutoSpell 5.lnk = E:\Program Files\autospell50\Aswatc32
.exe
O4 - Startup: Wireless Desktop.lnk = C:\Program Files\Wireless Desktop\MagicKey.exe
O4 - Startup: Norton Disk Doctor.LNK = E:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Startup: Image.LNK = E:\Program Files\Norton SystemWorks\Norton Utilities\IMAGE32.EXE
O4 - User Startup: AutoSpell 5.lnk = E:\Program Files\autospell50\Aswatc32
.exe
O4 - User Startup: Wireless Desktop.lnk = C:\Program Files\Wireless Desktop\MagicKey.exe
O4 - User Startup: Norton Disk Doctor.LNK = E:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - User Startup: Image.LNK = E:\Program Files\Norton SystemWorks\Norton Utilities\IMAGE32.EXE
O8 - Extra context menu item: Fill this form - e:\Program Files\1ClickFF\loadform.ht
ml
O8 - Extra context menu item: Save this form - e:\Program Files\1ClickFF\saveform.ht
ml
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\DOWNLOADE
D PROGRAM FILES\GOOGLETOOLBAR1.DLL/c
msearch.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\DOWNLOADE
D PROGRAM FILES\GOOGLETOOLBAR1.DLL/c
mcache.htm
l
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\DOWNLOADE
D PROGRAM FILES\GOOGLETOOLBAR1.DLL/c
msimilar.h
tml
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\DOWNLOADE
D PROGRAM FILES\GOOGLETOOLBAR1.DLL/c
mbacklinks
.html
O8 - Extra context menu item: Translate into English - res://C:\WINDOWS\DOWNLOADE
D PROGRAM FILES\GOOGLETOOLBAR1.DLL/c
mtrans.htm
l
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra button: TweakIE 3.0 - {79F436C2-3CA2-45A4-A52E-6
94B23DFFA8
8} - E:\Program Files\TweakIE 3.0\TweakIE.exe
O9 - Extra 'Tools' menuitem: TweakIE 3.0 - {79F436C2-3CA2-45A4-A52E-6
94B23DFFA8
8} - E:\Program Files\TweakIE 3.0\TweakIE.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugi
ns\NPDocBo
x.dll
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugi
ns\NPBelv3
2.dll
O15 - Trusted Zone: *.etrade.com
O15 - Trusted Zone: *.ameritrade.com
O15 - Trusted Zone: *.nytimes.com
O15 - Trusted Zone: *.amazon.com
O15 - Trusted Zone: *.ebay.com
O15 - Trusted Zone: *.netscape.com
O15 - Trusted Zone:
http://*.windowsupdate.microsoft.com O15 - Trusted Zone:
http://*.windowsupdate.com O16 - DPF: {C606BA60-AB76-48B6-96A7-2
C4D5C386F7
0} (PreQualifier Class) - file://G:\Bin\html\files\M
otivePreQu
al.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} -
http://207.188.7.150/17de3a79039c13010422/netzip/RdxIE2.cabO16 - DPF: {A8739816-022C-11D6-A85D-0
0C04F9AEAF
B} (Web Camera Server Control) -
http://66.91.151.66/wg_webeye.cabO16 - DPF: {6CB5E471-C305-11D3-99A8-0
0008639549
5} -
http://toolbar.google.com/data/en/deleon/1.1.63-deleon/GoogleNav.cabO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exeO16 - DPF: {90A29DA5-D020-4B18-8660-6
689520C7CD
7} (DmiReader Class) -
http://ftp.us.dell.com/fixes/PROFILER.CABO16 - DPF: {611CF77F-F7F5-4EA1-B979-6
67671326B4
C} (MarketTrader - ETrade v243a) -
http://etrade.bridge.com/etgmt_prd/java/gmtb_etrade_i.cabO16 - DPF: {E93A06EF-ABD8-4FA5-96BF-9
68614B0853
1} (MarketTrader - Reuters v243b) -
http://etrade.bridge.com/etgmt_prd/java/gmtb_bridge_i.cabO20 - AppInit_DLLs: APITRAP.DLL