Can someone take a look at this log from HJT and give me some pointers on how to rid myself of some of my problems.
Thanks,
Sean
Logfile of HijackThis v1.99.0
Scan saved at 4:56:05 PM, on 12/03/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\COMMON~1\AOL\A
CS\acsd.ex
e
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
C:\WINDOWS\system32\rundll
32.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.
exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\Program Files\Dell\AccessDirect\da
dapp.exe
C:\Program Files\Dell\QuickSet\quicks
et.exe
C:\WINDOWS\System32\DSentr
y.exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
C:\Program Files\MusicMatch\MusicMatc
h Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mm_tray.exe
C:\Program Files\Dell\AccessDirect\Da
dTray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.ex
e
C:\PROGRA~1\COMMON~1\AOL\A
OLSPY~1\AO
LSP Scheduler.exe
c:\progra~1\mcafee.com\vso
\mcvsescn.
exe
C:\WINDOWS\System32\ebqyvc
aq\lcspwo.
exe
C:\WINDOWS\System32\hlcdbb
hw\iivbild
.exe
C:\WINDOWS\System32\ilotmp
\toximmg.e
xe
C:\Program Files\Dell\Support\Alert\b
in\NotifyA
lert.exe
C:\WINDOWS\System32\secure
.exe
C:\WINDOWS\System32\gpkdv.
exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
C:\WINDOWS\System32\getcor
e2.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\WINDOWS\System32\wbem\w
miapsrv.ex
e
C:\Documents and Settings\doris mucci\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.
exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.dell4me.com/mywayR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.oemji.com/side_search.htmlR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.oemji.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.oemji.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://websearch.drsnsrch.com/sidesearch.cgi?id=R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://websearch.drsnsrch.com/sidesearch.cgi?id=R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.dell4me.com/mywayR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://websearch.drsnsrch.com/sidesearch.cgi?id=R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://www.oemji.com/side_search.htmlR1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://www.dell4me.com/mywayR3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\da
dapp.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quicks
et.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
y.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vs
o\mcmnhdlr
.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
nt\McUpdat
e.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatc
h Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.ex
e
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vs
o\mcvsshld
.exe"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\
AOLSPY~1\A
OLSP Scheduler.exe"
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySp
otter.exe
O4 - HKLM\..\Run: [lcspwo] C:\WINDOWS\System32\ebqyvc
aq\lcspwo.
exe
O4 - HKLM\..\Run: [iivbild] C:\WINDOWS\System32\hlcdbb
hw\iivbild
.exe
O4 - HKLM\..\Run: [xtie] C:\WINDOWS\System32\tvnn\x
tie.exe
O4 - HKLM\..\Run: [toximmg] C:\WINDOWS\System32\ilotmp
\toximmg.e
xe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\secure
.exe
O4 - HKLM\..\Run: [USB controller] "C:\DOCUME~1\DORISM~1\LOCA
LS~1\Temp\
ICD3.tmp\s
vcmm32.exe
" /startup
O4 - HKLM\..\Run: [o3mP32S] gpkdv.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [Z05FRSe7T] getcore2.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\System32\Shdocv
w.dll
O10 - Unknown file in Winsock LSP: c:\program files\oemji\oemjisearchplu
s\sfbnsp.d
ll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} (McAfee.com Operating System Class) -
http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C
18E1ADA438
9} (DwnldGroupMgr Class) -
http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cabO23 - Service: AOL Connectivity Service - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\A
CS\acsd.ex
e
O23 - Service: AOL Spyware Protection Service - Unknown - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso
\mcshield.
exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age
nt\mcupdmg
r.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso
\mcvsrte.e
xe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe (file missing)