Options
AD 234 Please HELP!!!
My HT log is below. The AD 234 is killing me, please help 
===================HT Log ===============
Logfile of HijackThis v1.97.7
Scan saved at 10:26:56 AM, on 11/23/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\system32\DRIVERS\dcfssvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\PRPCUI.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\WINNT\system32\RunDll32.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\system32\hzemdl.exe
C:\documents and settings\administrator\local settings\temp\Tmys9.exe
C:\documents and settings\administrator\local settings\temp\KQwTW.exe
C:\documents and settings\administrator\local settings\temp\DIs1w.exe
C:\documents and settings\administrator\local settings\temp\NaT.exe
C:\documents and settings\administrator\local settings\temp\w9b14u.exe
C:\documents and settings\administrator\local settings\temp\Fu.exe
C:\documents and settings\administrator\local settings\temp\6Mu.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINNT\system32\??rvices.exe
C:\Documents and Settings\Administrator\Application Data\mroh.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\WINNT\system32\wuauclt.exe
c:\documents and settings\administrator\local settings\temp\K4.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\System32\cidaemon.exe
c:\documents and settings\administrator\local settings\temp\grvF.exe
C:\WINNT\system32\cmd.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://autoproxy.gm.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=144.72.253.1:3128;https=144.72.253.1:3128;ftp=144.72.253.1:3128;gopher=144.72.253.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\m33es542.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\m33es542.slt\prefs.js)
O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINNT\localNRD.dll (file missing)
O2 - BHO: (no name) - {17A6417B-E539-2DE8-8755-635579A17A12} - C:\WINNT\system32\jkmud.dll (file missing)
O2 - BHO: (no name) - {19AF1D79-E961-2AE0-8755-635579AF234D} - C:\WINNT\system32\jeleknwu.dll (file missing)
O2 - BHO: (no name) - {1AFC4B2D-B66E-29B2-8755-635579AE2F11} - C:\WINNT\system32\fve.dll (file missing)
O2 - BHO: (no name) - {1BA74625-B16C-2DE5-8755-635579F77F46} - C:\WINNT\system32\ibek.dll (file missing)
O2 - BHO: (no name) - {1DAE132D-E234-2DE2-8755-635579A12D17} - C:\WINNT\system32\qgeb.dll (file missing)
O2 - BHO: (no name) - {1EA91A7B-B765-78B6-8755-635579A12645} - C:\WINNT\system32\iohr.dll (file missing)
O2 - BHO: (no name) - {1EAB1770-B462-7FE3-8755-635579F57340} - C:\WINNT\system32\nnkfhm.dll (file missing)
O2 - BHO: (no name) - {1FAA132E-E363-77B6-8755-635579A07D4A} - C:\WINNT\system32\jmmglvvy.dll (file missing)
O2 - BHO: (no name) - {1FF9467B-E233-7BB1-8755-635579A07C45} - C:\WINNT\system32\bvwbq.dll (file missing)
O2 - BHO: (no name) - {45AC492C-E567-2CB7-8755-635579F72D11} - C:\WINNT\system32\sepgs.dll (file missing)
O2 - BHO: (no name) - {48A41478-B633-2EB3-8755-635579A02646} - C:\WINNT\system32\qggtcb.dll (file missing)
O2 - BHO: (no name) - {4DAA402D-B13E-23E5-8755-635579AE2C46} - C:\WINNT\system32\gkbimamv.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AC109D01-32D6-4EB5-8300-D3C5EBAC7C83} - (no file)
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator\Local Settings\Temp\n.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [tqmnpqrxzlrjs] C:\WINNT\system32\hzemdl.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [Tmys9] C:\documents and settings\administrator\local settings\temp\Tmys9.exe
O4 - HKLM\..\Run: [KQwTW] C:\documents and settings\administrator\local settings\temp\KQwTW.exe
O4 - HKLM\..\Run: [DIs1w] C:\documents and settings\administrator\local settings\temp\DIs1w.exe
O4 - HKLM\..\Run: [NaT] C:\documents and settings\administrator\local settings\temp\NaT.exe
O4 - HKLM\..\Run: [w9b14u] C:\documents and settings\administrator\local settings\temp\w9b14u.exe
O4 - HKLM\..\Run: [Fu] C:\documents and settings\administrator\local settings\temp\Fu.exe
O4 - HKLM\..\Run: [6Mu] C:\documents and settings\administrator\local settings\temp\6Mu.exe
O4 - HKLM\..\Run: [K4] c:\documents and settings\administrator\local settings\temp\K4.exe
O4 - HKLM\..\Run: [grvF] c:\documents and settings\administrator\local settings\temp\grvF.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Tqmc] C:\WINNT\system32\??rvices.exe
O4 - HKCU\..\Run: [Awoa] C:\Documents and Settings\Administrator\Application Data\mroh.exe
O4 - HKLM\..\RunOnce: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" "+b1"
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: KODAK Picture Transfer Software.lnk = C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .aspx: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: Yahoo! Dots - http://download.games.yahoo.com/games/clients/y/dtt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.games.yahoo.com/games/clients/y/ywt0_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://maclegends.viewnetcam.com/kxhcm10.ocx
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {36C0B01C-8031-11D4-A527-00C04F794627} (PVCS Dimensions Client for MSIE) - http://gotdsv20.gotd.gm.com:8080/dim_applet/diminet700ie.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {95EEE69E-27B4-4D13-BD32-766617A16909} (NDTVVideo.MPlayer) - http://www.ndtv.com/video/NDTVseekvideo.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38075.3311805556
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
=================End of Log =================

===================HT Log ===============
Logfile of HijackThis v1.97.7
Scan saved at 10:26:56 AM, on 11/23/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\system32\DRIVERS\dcfssvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\PRPCUI.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\WINNT\system32\RunDll32.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\system32\hzemdl.exe
C:\documents and settings\administrator\local settings\temp\Tmys9.exe
C:\documents and settings\administrator\local settings\temp\KQwTW.exe
C:\documents and settings\administrator\local settings\temp\DIs1w.exe
C:\documents and settings\administrator\local settings\temp\NaT.exe
C:\documents and settings\administrator\local settings\temp\w9b14u.exe
C:\documents and settings\administrator\local settings\temp\Fu.exe
C:\documents and settings\administrator\local settings\temp\6Mu.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINNT\system32\??rvices.exe
C:\Documents and Settings\Administrator\Application Data\mroh.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\WINNT\system32\wuauclt.exe
c:\documents and settings\administrator\local settings\temp\K4.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\System32\cidaemon.exe
c:\documents and settings\administrator\local settings\temp\grvF.exe
C:\WINNT\system32\cmd.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://autoproxy.gm.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=144.72.253.1:3128;https=144.72.253.1:3128;ftp=144.72.253.1:3128;gopher=144.72.253.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\m33es542.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\m33es542.slt\prefs.js)
O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINNT\localNRD.dll (file missing)
O2 - BHO: (no name) - {17A6417B-E539-2DE8-8755-635579A17A12} - C:\WINNT\system32\jkmud.dll (file missing)
O2 - BHO: (no name) - {19AF1D79-E961-2AE0-8755-635579AF234D} - C:\WINNT\system32\jeleknwu.dll (file missing)
O2 - BHO: (no name) - {1AFC4B2D-B66E-29B2-8755-635579AE2F11} - C:\WINNT\system32\fve.dll (file missing)
O2 - BHO: (no name) - {1BA74625-B16C-2DE5-8755-635579F77F46} - C:\WINNT\system32\ibek.dll (file missing)
O2 - BHO: (no name) - {1DAE132D-E234-2DE2-8755-635579A12D17} - C:\WINNT\system32\qgeb.dll (file missing)
O2 - BHO: (no name) - {1EA91A7B-B765-78B6-8755-635579A12645} - C:\WINNT\system32\iohr.dll (file missing)
O2 - BHO: (no name) - {1EAB1770-B462-7FE3-8755-635579F57340} - C:\WINNT\system32\nnkfhm.dll (file missing)
O2 - BHO: (no name) - {1FAA132E-E363-77B6-8755-635579A07D4A} - C:\WINNT\system32\jmmglvvy.dll (file missing)
O2 - BHO: (no name) - {1FF9467B-E233-7BB1-8755-635579A07C45} - C:\WINNT\system32\bvwbq.dll (file missing)
O2 - BHO: (no name) - {45AC492C-E567-2CB7-8755-635579F72D11} - C:\WINNT\system32\sepgs.dll (file missing)
O2 - BHO: (no name) - {48A41478-B633-2EB3-8755-635579A02646} - C:\WINNT\system32\qggtcb.dll (file missing)
O2 - BHO: (no name) - {4DAA402D-B13E-23E5-8755-635579AE2C46} - C:\WINNT\system32\gkbimamv.dll (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AC109D01-32D6-4EB5-8300-D3C5EBAC7C83} - (no file)
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator\Local Settings\Temp\n.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [tqmnpqrxzlrjs] C:\WINNT\system32\hzemdl.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [Tmys9] C:\documents and settings\administrator\local settings\temp\Tmys9.exe
O4 - HKLM\..\Run: [KQwTW] C:\documents and settings\administrator\local settings\temp\KQwTW.exe
O4 - HKLM\..\Run: [DIs1w] C:\documents and settings\administrator\local settings\temp\DIs1w.exe
O4 - HKLM\..\Run: [NaT] C:\documents and settings\administrator\local settings\temp\NaT.exe
O4 - HKLM\..\Run: [w9b14u] C:\documents and settings\administrator\local settings\temp\w9b14u.exe
O4 - HKLM\..\Run: [Fu] C:\documents and settings\administrator\local settings\temp\Fu.exe
O4 - HKLM\..\Run: [6Mu] C:\documents and settings\administrator\local settings\temp\6Mu.exe
O4 - HKLM\..\Run: [K4] c:\documents and settings\administrator\local settings\temp\K4.exe
O4 - HKLM\..\Run: [grvF] c:\documents and settings\administrator\local settings\temp\grvF.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Tqmc] C:\WINNT\system32\??rvices.exe
O4 - HKCU\..\Run: [Awoa] C:\Documents and Settings\Administrator\Application Data\mroh.exe
O4 - HKLM\..\RunOnce: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" "+b1"
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: KODAK Picture Transfer Software.lnk = C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .aspx: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: Yahoo! Dots - http://download.games.yahoo.com/games/clients/y/dtt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.games.yahoo.com/games/clients/y/ywt0_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://maclegends.viewnetcam.com/kxhcm10.ocx
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {36C0B01C-8031-11D4-A527-00C04F794627} (PVCS Dimensions Client for MSIE) - http://gotdsv20.gotd.gm.com:8080/dim_applet/diminet700ie.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {95EEE69E-27B4-4D13-BD32-766617A16909} (NDTVVideo.MPlayer) - http://www.ndtv.com/video/NDTVseekvideo.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38075.3311805556
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
=================End of Log =================
0
Comments
=======================
Logfile of HijackThis v1.98.2
Scan saved at 12:56:14 AM, on 11/24/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\system32\DRIVERS\dcfssvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe
C:\WINNT\System32\QCONSVC.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\PRPCUI.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\WINNT\system32\RunDll32.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINNT\system32\hzemdl.exe
C:\documents and settings\administrator\local settings\temp\Tmys9.exe
C:\documents and settings\administrator\local settings\temp\KQwTW.exe
C:\documents and settings\administrator\local settings\temp\DIs1w.exe
C:\documents and settings\administrator\local settings\temp\NaT.exe
C:\documents and settings\administrator\local settings\temp\w9b14u.exe
C:\documents and settings\administrator\local settings\temp\Fu.exe
C:\documents and settings\administrator\local settings\temp\6Mu.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Documents and Settings\Administrator\Application Data\mroh.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\WINNT\system32\wuauclt.exe
c:\documents and settings\administrator\local settings\temp\K4.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\System32\cidaemon.exe
c:\documents and settings\administrator\local settings\temp\grvF.exe
C:\WINNT\system32\cmd.exe
c:\Program Files\interMute\SpySubtract\SpySub.exe
c:\documents and settings\administrator\local settings\temp\QnkjYtXt.exe
C:\WINNT\system32\cmd.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://autoproxy.gm.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=144.72.253.1:3128;https=144.72.253.1:3128;ftp=144.72.253.1:3128;gopher=144.72.253.1:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\m33es542.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CMozilla%5Csearchplugins%5Cgoogle.src"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\m33es542.slt\prefs.js)
O1 - Hosts: 213.159.117.235 auto.search.msn.com
O2 - BHO: (no name) - {17A6417B-E539-2DE8-8755-635579A17A12} - C:\WINNT\system32\jkmud.dll (file missing)
O2 - BHO: (no name) - {19AF1D79-E961-2AE0-8755-635579AF234D} - C:\WINNT\system32\jeleknwu.dll (file missing)
O2 - BHO: (no name) - {1AFC4B2D-B66E-29B2-8755-635579AE2F11} - C:\WINNT\system32\fve.dll (file missing)
O2 - BHO: (no name) - {1BA74625-B16C-2DE5-8755-635579F77F46} - C:\WINNT\system32\ibek.dll (file missing)
O2 - BHO: (no name) - {1DAE132D-E234-2DE2-8755-635579A12D17} - C:\WINNT\system32\qgeb.dll (file missing)
O2 - BHO: (no name) - {1EA91A7B-B765-78B6-8755-635579A12645} - C:\WINNT\system32\iohr.dll (file missing)
O2 - BHO: (no name) - {1EAB1770-B462-7FE3-8755-635579F57340} - C:\WINNT\system32\nnkfhm.dll (file missing)
O2 - BHO: (no name) - {1FAA132E-E363-77B6-8755-635579A07D4A} - C:\WINNT\system32\jmmglvvy.dll (file missing)
O2 - BHO: (no name) - {1FF9467B-E233-7BB1-8755-635579A07C45} - C:\WINNT\system32\bvwbq.dll (file missing)
O2 - BHO: (no name) - {45AC492C-E567-2CB7-8755-635579F72D11} - C:\WINNT\system32\sepgs.dll (file missing)
O2 - BHO: (no name) - {48A41478-B633-2EB3-8755-635579A02646} - C:\WINNT\system32\qggtcb.dll (file missing)
O2 - BHO: (no name) - {4DAA402D-B13E-23E5-8755-635579AE2C46} - C:\WINNT\system32\gkbimamv.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator\Local Settings\Temp\n.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [tqmnpqrxzlrjs] C:\WINNT\system32\hzemdl.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [Tmys9] C:\documents and settings\administrator\local settings\temp\Tmys9.exe
O4 - HKLM\..\Run: [KQwTW] C:\documents and settings\administrator\local settings\temp\KQwTW.exe
O4 - HKLM\..\Run: [DIs1w] C:\documents and settings\administrator\local settings\temp\DIs1w.exe
O4 - HKLM\..\Run: [NaT] C:\documents and settings\administrator\local settings\temp\NaT.exe
O4 - HKLM\..\Run: [w9b14u] C:\documents and settings\administrator\local settings\temp\w9b14u.exe
O4 - HKLM\..\Run: [Fu] C:\documents and settings\administrator\local settings\temp\Fu.exe
O4 - HKLM\..\Run: [6Mu] C:\documents and settings\administrator\local settings\temp\6Mu.exe
O4 - HKLM\..\Run: [K4] c:\documents and settings\administrator\local settings\temp\K4.exe
O4 - HKLM\..\Run: [grvF] c:\documents and settings\administrator\local settings\temp\grvF.exe
O4 - HKLM\..\Run: [QnkjYtXt] c:\documents and settings\administrator\local settings\temp\QnkjYtXt.exe
O4 - HKLM\..\RunOnce: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" "+b1"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Tqmc] C:\WINNT\system32\??rvices.exe
O4 - HKCU\..\Run: [Awoa] C:\Documents and Settings\Administrator\Application Data\mroh.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: KODAK Picture Transfer Software.lnk = C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O12 - Plugin for .aspx: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: Yahoo! Dots - http://download.games.yahoo.com/games/clients/y/dtt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.games.yahoo.com/games/clients/y/ywt0_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://maclegends.viewnetcam.com/kxhcm10.ocx
O16 - DPF: {36C0B01C-8031-11D4-A527-00C04F794627} (PVCS Dimensions Client for MSIE) - http://gotdsv20.gotd.gm.com:8080/dim_applet/diminet700ie.cab
O16 - DPF: {95EEE69E-27B4-4D13-BD32-766617A16909} (NDTVVideo.MPlayer) - http://www.ndtv.com/video/NDTVseekvideo.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: start - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINNT\system32\HKNQTWZ].dll
O18 - Filter: text/html - {63B95211-7D77-11D2-9F80-00104B107C96} - C:\WINNT\system32\HKNQTWZ].dll
O18 - Filter: text/plain - {63B95211-7D77-11D2-9F80-00104B107C96} - C:\WINNT\system32\HKNQTWZ].dll
O2 - BHO: (no name) - {19AF1D79-E961-2AE0-8755-635579AF234D} - C:\WINNT\system32\jeleknwu.dll (file missing)
O2 - BHO: (no name) - {1AFC4B2D-B66E-29B2-8755-635579AE2F11} - C:\WINNT\system32\fve.dll (file missing)
O2 - BHO: (no name) - {1BA74625-B16C-2DE5-8755-635579F77F46} - C:\WINNT\system32\ibek.dll (file missing)
O2 - BHO: (no name) - {1DAE132D-E234-2DE2-8755-635579A12D17} - C:\WINNT\system32\qgeb.dll (file missing)
O2 - BHO: (no name) - {1EA91A7B-B765-78B6-8755-635579A12645} - C:\WINNT\system32\iohr.dll (file missing)
O2 - BHO: (no name) - {1EAB1770-B462-7FE3-8755-635579F57340} - C:\WINNT\system32\nnkfhm.dll (file missing)
O2 - BHO: (no name) - {1FAA132E-E363-77B6-8755-635579A07D4A} - C:\WINNT\system32\jmmglvvy.dll (file missing)
O2 - BHO: (no name) - {1FF9467B-E233-7BB1-8755-635579A07C45} - C:\WINNT\system32\bvwbq.dll (file missing)
O2 - BHO: (no name) - {45AC492C-E567-2CB7-8755-635579F72D11} - C:\WINNT\system32\sepgs.dll (file missing)
O2 - BHO: (no name) - {48A41478-B633-2EB3-8755-635579A02646} - C:\WINNT\system32\qggtcb.dll (file missing)
O2 - BHO: (no name) - {4DAA402D-B13E-23E5-8755-635579AE2C46} - C:\WINNT\system32\gkbimamv.dll (file missing)
First we'll get rid of the clutter, then move onto the spyware problems.
Fix those entries then post a new log (you don't have to reboot this time)