Can someone give me some advice on this hijackthis log?
Logfile of HijackThis v1.98.0
Scan saved at 10:08:21 PM, on 7/28/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32
.DLL
C:\WINDOWS\SYSTEM\MSGSRV32
.EXE
C:\WINDOWS\SYSTEM\mmtask.t
sk
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\MPREXE.E
XE
C:\WINDOWS\SYSTEM\MSTASK.E
XE
C:\WINDOWS\SYSTEM\SSDPSRV.
EXE
C:\WINDOWS\SYSTEM\ATI2EVXX
.EXE
C:\WINDOWS\SYSTEM\STIMON.E
XE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\DEVLDR16
.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\WBEM\WIN
MGMT.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDI
OHQ\AHQTB.
EXE
C:\WINDOWS\SYSTEM\RESTORE\
STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.E
XE
C:\WINDOWS\SYSTEM\ATIPTAXX
.EXE
C:\WINDOWS\SYSTEM\SK9910DM
.EXE
C:\PROGRAM FILES\MICROSOFT WORKS\WKSSB.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIR
ECTCD.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATC
H JUKEBOX\MM_TRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REAL
PLAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\VISIONEER ONETOUCH\ONETOUCHMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.
EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\GAME CONTROLLERS\COMMON\SWTRAYV
4.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.EXE
C:\WINDOWS\SYSTEM\QTTASK.E
XE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EX
E
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\WINDOWS\SYSTEM\DDHELP.E
XE
C:\PROGRAM FILES\SPYWARE DOCTOR\SPYDOCTOR.EXE
C:\WINDOWS\DLLHLP.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\GAME CONTROLLERS\SWTRAY.EXE
C:\PROGRAM FILES\SONY CORPORATION\IMAGE TRANSFER\SONYTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\SYSTEM\SPOOL32.
EXE
A:\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\In
ternet Explorer,Search =
http://realtime.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer,SearchURL =
http://solongas.com/sp.htm?id=191R1 - HKLM\Software\Microsoft\In
ternet Explorer,Search =
http://realtime.directwebsearch.net/search.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer,SearchURL =
http://realtime.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://realtime.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://yourpoiskovik.com/sp.htmR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://yourpoiskovik.com/index.htmR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://yourpoiskovik.com/index.htmR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://realtime.directwebsearch.net/search.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://realtime.directwebsearch.net/search.phpR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://realtime.directwebsearch.net/search.phpR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://realtime.directwebsearch.net/index.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://solongas.com/sp.htm?id=191R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://realtime.directwebsearch.net/search.phpR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://yourpoiskovik.com/sp.htmR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://realtime.directwebsearch.net/search.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://yourpoiskovik.com/index.htmR1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,SearchU
RL =
http://yourpoiskovik.com/sp.htmR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = sas.se1.attbb.net:8000
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = sas.se1.attbb.net
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2
A4752CA7F4
E} - C:\WINDOWS\SYSTEM\KI8VI6FD
21JC.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radi
o - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\SYSTEM\MSDXM.OC
X
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A
37C9A5676A
7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt
.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Suppor
t\PCHSchd.
exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\Run: [OEMRUNONCE] c:\windows\options\cabs\oe
mrun.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [BCMDMMSG] BCMDMMSG.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.e
xe /DEVID:*PNP0320 /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECT
CD\DIRECTC
D.EXE
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\Audi
oHQ\AHQTB.
EXE
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\
CTSRReg.ex
e
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatc
h Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [InkWatch] C:\PROGRA~1\GATEWAY\GATEWA
~2\INKWATC
H.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
Play.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAP
W32.EXE /LOADQUIET
O4 - HKLM\..\Run: [HWINFN] C:\WINDOWS\HWINFN.EXE
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~1\ONETO
U~2.EXE
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~8\GAMEC
O~1\COMMON
\SWTRAYV4.
EXE
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Norton AntiVirus\POPROXY.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.
EXE" -atboottime
O4 - HKLM\..\Run: [winupd] C:\WINDOWS\SYSTEM\winupd.e
xe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e start
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMO
N.EXE
O4 - HKLM\..\Run: [romahere] C:\WINDOWS\SYSTEM\MATRIXHE
RE.EXE
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD
~1\CREATEC
D\CREATECD
.EXE -r
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16
.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.
exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\
StateMgr.e
xe
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [GoBack Polling Service] C:\Program Files\Adaptec\GoBack\GBPol
l.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.E
XE
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMAN
T~1\CCPROX
Y.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMAN
T~1\SNDSRV
C.EXE
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\SCANSOFT\PAPER
P~1\PPWebC
ap.exe
O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SPYDOCTOR.EXE" /Q
O4 - HKCU\..\Run: [romahere] C:\WINDOWS\SYSTEM\MATRIXHE
RE.EXE
O4 - HKCU\..\Run: [dllhelp] c:\windows\dllhlp.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Check for OneTouch Updates.lnk = C:\Program Files\Visioneer OneTouch\WiseUpdt.exe
O4 - Startup: America Online 6.0 Tray Icon.lnk = C:\America Online 6.0\aoltray.exe
O4 - Startup: SwTray.lnk = C:\Program Files\MICROSOFT HARDWARE\GAME CONTROLLERS\SWTRAY.EXE
O4 - Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\PROGRA~1\MESSEN~1\MSMSG
S.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\PROGRA~1\MESSEN~1\MSMSG
S.EXE
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-0
06097DBED3
7} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-0
06097DBED3
7} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-0
06097DBED3
7} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-0
06097DBED3
7} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\SYSTEM\Shdocvw.
dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
2A255F085E
1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSI
ON.DLL
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-1
2A255F085E
1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSI
ON.DLL
O14 - IERESET.INF: START_PAGE_URL=
http://gateway.yahoo.comO15 - Trusted Zone: *.greg-search.com
O16 - DPF: {11010101-1001-1111-1000-1
1011234567
8} - ms-its:mhtml:file://c:\nos
uch.mht!
http://69.50.179.52/winsearchie32.chm::/winsearchie32.exeO21 - SSODL: AUHook - {BCBCD383-3E06-11D3-91A9-0
0C04F68105
C} - C:\WINDOWS\SYSTEM\AUHOOK.D
LL
Thank you.