appreciated. I'm a novice at the computer so PLEASE type S L O W L Y!
Seriously, most of this stuff flys over my head. Here's my log. I hope it entertains you. I suspect a moderating weasel at a site I visit (subguns) messed up my Firefox Browser. Every time I try to use Firefox it loads some damn site and will only return back to it no matter what I type. At the bottom of this is Adaware's quarantined stuff. Some of it is very graphic so I've XXX'd some out. I've no idea how to remove this crap. Thanks for your time!
Idjutt
Logfile of HijackThis v1.97.7
Scan saved at 10:59:13 PM, on 5/18/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFALERT.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\GAME CONTROLLERS\COMMON\SWTRAYV4.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\SIERRA IMAGING\IMAGE EXPERT 2000\IXAPPLET.EXE
C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\AD-AWARE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\QWICKCONNECT\DIALER.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htmR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://google.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://drudgereport.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://usseek.net/qwickconnectR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://google.comR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htmR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://usseek.net/qwickconnectR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://google.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearchO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\DEFALERT.EXE
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~8\GAMECO~1\COMMON\SWTRAYV4.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [iedll] C:\WINDOWS\iedll.exe
O4 - HKCU\..\Run: [Adaware Bootup] C:\PROGRAM FILES\LAVASOFT AD-AWARE\AD-AWARE.EXE /Auto /Log "C:\PROGRAM FILES\LAVASOFT AD-AWARE\"
O4 - Startup: MICROSOFT OFFICE.LNK = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: MICROSOFT WORKS CALENDAR REMINDERS.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: CAMIO VIEWER 3.2.LNK = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Encarta Encyclopedia (HKLM)
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)
O9 - Extra button: Define (HKLM)
O9 - Extra 'Tools' menuitem: Define (HKLM)
O9 - Extra button: Dell Home (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.dellnet.com/
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.0) -
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://proxify.com/nph-proxy.cgi/111111A/6...22f73772e636162O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150/0210315bd9d748f42d04/...ip/RdxIE601.cabO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/...s/yinst0401.cabAdaware's stuff
ArchiveData(auto-quarantine- 18-05-2004 21-41-31.bckp)
======================================================
ALEXA
obj[0]=RegKey : SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
CRONTEL LTD
obj[1]=RegKey : SOFTWARE\DiallerProgram
obj[22]=Folder : c:\program files\DiallerProgram
obj[34]=File : c:\program files\diallerprogram\028125.exe
obj[35]=File : c:\program files\log.txt
DOWNLOADWARE
obj[2]=RegKey : SOFTWARE\DownloadWare
obj[3]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\uninstall\MediaLoads Installer
obj[36]=File : c:\windows\digital signature 20020616.htm
EACCELERATION
obj[4]=RegKey : MSEaid.Gd\GLSID
obj[23]=RegKey : MSEaid.Gd
HI-WIRE
obj[5]=RegKey : CLSID\{28f00b04-dc4e-11d3-abec-005004a44eeb}
obj[6]=RegKey : CLSID\{28f00b20-dc4e-11d3-abec-005004a44eeb}
obj[7]=RegKey : CLSID\{28f00b21-dc4e-11d3-abec-005004a44eeb}
obj[8]=RegKey : hiwire.configurator
obj[9]=RegKey : hiwire.configurator.1
obj[10]=RegKey : hiwire.transportcenter
obj[11]=RegKey : hiwire.transportcenter.1
obj[12]=RegKey : hiwire.userregrequest
obj[13]=RegKey : hiwire.userregrequest.1
obj[14]=RegKey : Software\HIWIRE
obj[37]=File : c:\windows\downloaded program files\hwutils.dll
obj[38]=File : c:\windows\downloaded program files\hwaudio.dll
obj[39]=File : c:\windows\downloaded program files\hwmedia.exe
COMMONNAME
obj[15]=RegValue : Software\Microsoft\Windows\CurrentVersion\Explorer
obj[16]=RegValue : Software\Microsoft\Windows\CurrentVersion\Explorer
obj[24]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run
COOLWEBSEARCH
obj[17]=RegValue : SOFTWARE\Microsoft\Internet Explorer\Main
obj[25]=RegValue : Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
obj[40]=File : c:\windows\favorites\links\!!! exclusive youngest porn !!!.url
obj[41]=File : c:\windows\favorites\links\80 old daddies brutally XXXXX their daughters.url
obj[42]=File : c:\windows\favorites\links\censored youngest porn.url
obj[43]=File : c:\windows\favorites\links\fresh xxx pics & movie.url
obj[44]=File : c:\windows\favorites\links\XXXing young virginz !!!.url
obj[45]=File : c:\windows\favorites\links\innocent girls brutally XXXed.url
obj[46]=File : c:\windows\favorites\links\little bleepes getting XXX.url
obj[47]=File : c:\windows\favorites\links\virgin girls in action.url
obj[48]=File : c:\windows\favorites\links\young masha XXX obj[49]=File : c:\windows\favorites\links\youngest girls only.url
obj[50]=File : c:\windows\favorites\links\youngest hardcore action.url
POSSIBLE BROWSER HIJACK ATTEMPT
obj[18]=RegData : Software\Microsoft\Internet Explorer
obj[19]=RegData : .Default\Software\Microsoft\Internet Explorer
obj[20]=RegData : Software\Microsoft\Internet Explorer\Search
obj[21]=RegData : .Default\Software\Microsoft\Internet Explorer\Search
TRACKING COOKIE
obj[26]=File : c:\windows\cookies\default@fastclick[1].txt
obj[27]=File : c:\windows\cookies\default@zedo[2].txt
obj[28]=File : c:\windows\cookies\default@zedo[1].txt
obj[29]=File : c:\windows\cookies\default@edge.ru4[1].txt
obj[30]=File : c:\windows\cookies\default@centrport[1].txt
obj[31]=File : c:\windows\cookies\default@tribalfusion[1].txt
obj[32]=File : c:\windows\cookies\default@ads.addynamix[1].txt
obj[33]=File : c:\windows\cookies\default@tribalfusion[2].txt