Logfile of HijackThis v1.97.
Scan saved at 5:22:17 PM, on 3/21/200
Platform: Windows XP SP1 (WinNT 5.01.2600
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106
Running processes
C:\WINNT\System32\smss.ex
C:\WINNT\system32\winlogon.ex
C:\WINNT\system32\services.ex
C:\WINNT\system32\lsass.ex
C:\WINNT\system32\svchost.ex
C:\WINNT\System32\svchost.ex
C:\WINNT\system32\LEXBCES.EX
C:\WINNT\system32\spoolsv.ex
C:\WINNT\system32\LEXPPS.EX
C:\WINNT\system32\netdde.ex
C:\WINNT\System32\msdtc.ex
C:\WINNT\system32\cisvc.ex
C:\WINNT\system32\clipsrv.ex
C:\WINNT\System32\dllhost.ex
c:\PROGRA~1\mcafee.com\vso\mcvsrte.ex
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.ex
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SY
C:\WINNT\system32\slserv.ex
C:\WINNT\System32\snmp.ex
C:\WINNT\System32\svchost.ex
C:\WINNT\System32\dllhost.ex
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
C:\WINNT\System32\vssvc.ex
C:\WINNT\Explorer.EX
C:\WINNT\wanmpsvc.ex
C:\WINNT\System32\wbem\wmiapsrv.ex
C:\WINNT\System32\dmadmin.ex
C:\PROGRA~1\mcafee.com\agent\mcagent.ex
C:\PROGRA~1\mcafee.com\vso\mcvsshld.ex
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.ex
C:\Program Files\Common Files\Real\Update_OB\realsched.ex
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.ex
c:\progra~1\mcafee.com\vso\mcvsescn.ex
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.ex
C:\Program Files\Gateway Utilities\GWInkMonitor.ex
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.ex
C:\Program Files\QuickTime\qttask.ex
C:\Program Files\Winamp\winampa.ex
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.ex
C:\Program Files\Messenger Plus! 2\MsgPlus.ex
C:\Program Files\Lexmark X1100 Series\lxbkbmon.ex
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.ex
C:\PROGRA~1\COMETS~1\DM\bin\dmserver.ex
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.ex
C:\WINNT\System32\hkcmd.ex
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.ex
C:\PROGRA~1\BYTEBI~1\file dale stop.ex
C:\Program Files\Netscape\Netscape\Netscp.ex
C:\Program Files\MSN Messenger\msnmsgr.ex
c:\progra~1\mcafee.com\vso\mcvsftsn.ex
C:\Program Files\Messenger\msmsgs.ex
c:\PROGRA~1\mcafee.com\vso\mcshield.ex
C:\WINNT\system32\cidaemon.ex
C:\Program Files\Internet Explorer\IEXPLORE.EX
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EX
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.ex
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.your-search.info/search.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://hispeed.rogers.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.your-search.info/start.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.your-search.info/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.your-search.info/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.your-search.info/search.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.your-search.info/start.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.your-search.info/search.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.your-search.info/search.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.your-search.info/search.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.your-search.info/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Interne
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://search.yahoo.com/search?p=%
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =
http://cache:808
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file
R3 - URLSearchHook: TvmBho Class - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {103297E0-0D97-E33D-7D80-B83966423A9A} - (no file)
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: (no name) - {0AAF602E-72A1-45FE-BAB1-06971E07EAA2} - (no file)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: RHSI Toolbar - {4DF5B116-4FD9-4039-B377-1130953A980F} - C:\Program Files\Rogers Hi-Speed Internet\RHSI Toolbar\Toolband.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mm_server] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [PCDRealtime] C:\WINNT\realtime.exe
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "c:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [Name dart] C:\PROGRA~1\BYTEBI~1\file dale stop.exe
O4 - HKLM\..\Run: [system32.dll] C:\WINNT\system\systeminit.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers Hi-Speed Internet\RHSI SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: PartyPoker.com (HKLM)
O9 - Extra 'Tools' menuitem: PartyPoker.com (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O15 - Trusted Zone:
www.hotmail.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) -
http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} -
http://akamai.downloadv3.com/binaries/IA/dtc32_EN_XP.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {197AB1D7-A7DD-4C86-A938-1FCC0DB21B85} (DMProxyCtl Class) -
http://dm.cometsystems.com/dm/dm_286.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) -
http://download.microsoft.com/downl...-a3de-373c3e5552fc/msSecAdv.cab?1074125675248
O16 - DPF: {35F49483-7BB9-46A0-90EB-9278FE8771F7} (Project1.AddChild) -
http://www.rogershelp.com/help/content/trouble/oneclickfixes/addchild/addchild.cab
O16 - DPF: {3734A957-FBD5-4F87-A404-4289C6F3DDFF} (DownloadScanEngine.ctlDSE296315) -
http://downloads.rogershelp.com/updates.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
http://office.microsoft.com/officeua