My browser(s) -- both IE and Firefox -- won't go to any microsoft websites, or yahoo, or aol. Sometimes, it redirects me to
www.searchthenet.com -- I have run search and distroy, symantec, and spyware doctor without any luck. Any help would be appreciated. Since it seems that most people ask for the hijack this log -- here goes --
Thanks very much!
Logfile of HijackThis v1.99.1
Scan saved at 11:20:56 PM, on 12/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\csrss.
exe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc0
1a.exe
C:\WINDOWS\system32\brss01
a.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\CTsvcC
DA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\
Binn\sqlse
rvr.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr
.exe
C:\WINDOWS\System32\alg.ex
e
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\VPTra
y.exe
C:\Program Files\Java\jre1.5.0_04\bin
\jusched.e
xe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\SealedMedia\sealmon.
exe
C:\Program Files\Real\RealPlayer\Real
Play.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\PaperPort\p
ptd40nt.ex
e
C:\Program Files\ScanSoft\OmniPageSE2
.0\OpwareS
E2.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe
C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\Program Files\Creative\SBAudigy2ZS
\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELP
ER.EXE
C:\Program Files\Creative\SBAudigy2ZS
\DVDAudio\
CTDVDDET.E
XE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\ScanSoft\PaperPort\x
dcla.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.
exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDispla
y.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\SPYWAR~1\swdoc
tor.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
E
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EX
E
C:\Documents and Settings\roberto\Local Settings\Temporary Internet Files\Content.IE5\6PQ01TUM
\HijackThi
s[1].exe
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.dell4me.com/mywaybizR1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8
AB8210D6D7
5} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D
426709BBFE
B} - C:\PROGRA~1\SPYWAR~1\tools
\iesdsg.dl
l
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
5.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1
7DF180C71A
C} - C:\PROGRA~1\SPYWAR~1\tools
\iesdpb.dl
l
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
5.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dump
rep 0 -u
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra
y.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
ync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin
\jusched.e
xe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgd
update.exe
" -Embedding -boot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.
exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
Play.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\p
ptd40nt.ex
e
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2
.0\OpwareS
E2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\I
ndexSearch
.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS
\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS
\DVDAudio\
CTDVDDET.E
XE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Image Retriever.lnk = C:\Program Files\ScanSoft\PaperPort\x
dcla.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
5.dll/cmse
arch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar
5.dll/cmwo
rdtrans.ht
ml
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
5.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
5.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
5.dll/cmsi
milar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar
5.dll/cmtr
ans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_04\bin
\npjpi150_
04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_04\bin
\npjpi150_
04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4
C56B4E14E8
4} - C:\PROGRA~1\SPYWAR~1\tools
\iesdpb.dl
l
O9 - Extra button: Clip To Tamale - {47CF4C19-D129-4141-9EA9-E
D9C46BA38C
A} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra 'Tools' menuitem: Clip To Tamale - {47CF4C19-D129-4141-9EA9-E
D9C46BA38C
A} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Express Deposit To Tamale - {AE01EF99-9588-4801-BF88-E
6227F79131
7} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra 'Tools' menuitem: Express Deposit To Tamale - {AE01EF99-9588-4801-BF88-E
6227F79131
7} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra button: (no name) - {C850E7CE-1DC7-4e16-8649-0
D728D49B22
F} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra 'Tools' menuitem: Advanced Deposit To Tamale - {C850E7CE-1DC7-4e16-8649-0
D728D49B22
F} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: Open From Tamale - {EF6CF1A9-8B05-4ae6-85BC-2
64C3683B19
3} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra 'Tools' menuitem: Open From Tamale - {EF6CF1A9-8B05-4ae6-85BC-2
64C3683B19
3} - C:\Program Files\Tamale Software\Research Suite\1.0.0.0\plugins\ie\I
EExtension
.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage) -
http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A
7518723BF9
7} (Talisma NetAgent Customer ActiveX Control version 3) -
https://quicken.ehosts.net/netagent/objects/custappx3.cabO16 - DPF: {352797A0-EFD0-4FA6-B229-1
45120EA4B8
A} (Walt Disney Internet Group Hardware Control) -
https://disneyblast.go.com/v3/setup/activex/DIGHardwareControl.cabO16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1119555744500O16 - DPF: {7584C670-2274-4EFB-B00B-D
6AABA6D385
0} (Microsoft RDP Client Control (redist)) -
http://central:8888/tsweb/msrdp.cabO16 - DPF: {CE8267C2-D41A-4A50-A69D-F
32B5C289F1
4} (FileOpenInstaller) -
http://64.106.242.160/0705/FileOpen.CABO16 - DPF: {EB387D2F-E27B-4D36-979E-8
47D1036C65
D} (QDiagHUpdateObj Class) -
http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = mignonenet.local
O17 - HKLM\Software\..\Telephony
: DomainName = mignonenet.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = mignonenet.local
O18 - Protocol: fdstp2 - {EDA30510-6AD8-11D2-A1A4-0
0805F0F069
0} - C:\FACTSET\FDSTP.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLog
on.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc0
1a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcC
DA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe