Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I ran Norton Antivirus 2003 Professional and it found a vius called Backdoor.Beasty and it can't remove it automatically, I go on the site to see what they say and it tells me that I have to remove it easily by deleting a Registry key and Registry value the trojan has made, then I have to modify another Registry value to read differently, I tried that but none of the Registry keys or values that Symantec is telling me to delete are not even in the Registry Editor, The file infected is called Comdlg.dll, I even called Symantec but they could not help me, and I still ended up paying the money per minute. My Virus definitions are up to date also. Please Help, THANKS A LOT.

hello
you might try a diferant online tool from anther virus maker.
or try these scans
free trojin scan
http://www.trojanscan.com/trojanscan
panda scan
http://www.pandasoftware.es/activescan/
housecall
http://housecall.trendmicro.com/housecall/start_corp.asp
nrav av
http://www.ravantivirus.com/scan/
virus scan
http://www.bitdefender.com/scan/licence.php
avast cleaning tool
http://www.avast.com/i_idt_171.html
mcafee avert stinger
http://vil.nai.com/vil/stinger/
scans for open trojin ports
http://scan.sygate.com/pretrojanscan.html
test my sheilds grc
https://nanoprobe.grc.com/x/ne.dll?bh0bkyd2

Download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, click "Save Log", and copy and paste it in a reply.
HijackThis!

This is my Hijack this Log for anyone who can help, I have tried a lot of things Trojan Hunter, Norton and a whole bunch of other programs I even ran Norton in Safe Mode it deleted the file but when I went back onto normal mode the trojan was there again. The next step for me is Reformatting!
Logfile of HijackThis v1.97.6
Scan saved at 3:29:52 PM, on 11/15/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Norton Utilities\SYSDOC32.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NPROTECT.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe
C:\WINDOWS\System32\dwwin.exe
C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.exe
C:\Program Files\Verizon Online\Verizon Online Control Pad\UIEngines\FlashUIEngine\cpskin.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\John\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=5.1&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_2_3_0.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_2_3_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe /disabled
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IELoader32] iexplore32.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~4\AdvTools\ADVCHK.exe
O4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 3.7\THGuard.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSNet\RSEDNClient.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Anti-Virus&Trojan.lnk = C:\Program Files\Anti-Virus&Trojan\Anti-Virus&Trojan.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.exe
O4 - Global Startup: Trojan Guarder.lnk = C:\Program Files\Trojan Guarder\Trojan Guarder.exe
O4 - Global Startup: Verizon Online Dialer.lnk = C:\Program Files\Common Files\Verizon Online\ConnMgr\Verizon Online.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Control Pad (HKLM)
O9 - Extra 'Tools' menuitem: Control Pad (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinstc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d052c1d7d32ead/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partners/verizon/meninblackII/install.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4302/mcfscan.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/104/rsinstaller.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9C02E943-F8C0-41D4-B926-B8EBD58F16C1}: NameServer = 151.202.0.84 151.203.0.84

Run HT again and check the following items. Next, close all browser Windows, and have HT 'fix checked'.
You Must restart your computer when you're done.
O4 - HKLM\..\Run: [IELoader32] iexplore32.exe
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSNet\RSEDNClient.exe
O8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htm
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} - http://download.redswoosh.net/Installer/104/rsinstaller.cabAfter restarting delete the following:
iexplore32.exe
C:\Program Files\RSNet folder.

I have the same problem this guy is having, here is my Hijack this log. could someone please give me advice

Logfile of HijackThis v1.97.5
Scan saved at 7:11:26 PM, on 12/2/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\program files\quicktime\qttask.exe
C:\Program Files\WildTangent\Apps\GameChannel.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\WINDOWS\Mixer.exe
C:\PROGRA~1\COMMON~3\Toolbar\comwiz.exe
C:\Program Files\RSNet\RSEDNClient.exe
C:\Program Files\AdsGone\adsgone.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Anthony\Local Settings\Temp\HijackThis.exe
C:\PROGRA~1\COMMON~3\Toolbar\winnet.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://dev.ntcor.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.broadband.rogers.com/custom.jsp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://dev.ntcor.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.broadband.rogers.com/custom.jsp
R3 - Default URLSearchHook is missing
O1 - Hosts: 203.161.127.141 www.dcsresearch.com
O2 - BHO: BabeIE - {00000000-0000-0000-0000-000000000000} - C:\PROGRA~1\COMMON~3\Toolbar\cnbabe.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E1B2879-88FF-11D2-8D96-D7ACAC31337F} - C:\WINDOWS\system32\Mslink32.dll
O2 - BHO: (no name) - {49404cfb-6f00-4305-93a6-baadaac32368} - C:\DOCUME~1\Anthony\APPLIC~1\sseepckierk.dll
O2 - BHO: Httper - {A5483501-070C-41DD-AF44-9BD8864B3015} - C:\Program Files\Httper\httper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar_en_2.0.95-big.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FB8CBA0F-78C0-03FA-8032-0E460DA5DEBB} - C:\WINDOWS\system32\fhwarsmv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar_en_2.0.95-big.dll
O3 - Toolbar: Adult Links - {965E6B07-6832-4738-BDBE-25F226BA2AB0} - C:\WINDOWS\system32\QaBar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe /IMEName
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Launcher] "C:\Program Files\KFH\cl\launcher.exe" /P
O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~3\Toolbar\winnet.exe
O4 - HKLM\..\Run: [SysComp] C:\WINDOWS\System32\msabiy.com
O4 - HKLM\..\Run: [PAV.EXE] C:\WINDOWS
O4 - HKLM\..\Run: [SafeSurfingUpdate] C:\Program Files\SafeSurfing\SSUpdate.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [WinFavorites] c:\program files\winfavorites\WinFavorites.exe1
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Content-Type: text/] c:\WINDOWS\System32\Content-Type: text/html
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [66004] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\66004.cpl
O4 - HKCU\..\Run: [65922] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65922.cpl
O4 - HKCU\..\Run: [66002] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\66002.cpl
O4 - HKCU\..\Run: [65912] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65912.cpl
O4 - HKCU\..\Run: [131438] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131438.cpl
O4 - HKCU\..\Run: [65958] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65958.cpl
O4 - HKCU\..\Run: [131414] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131414.cpl
O4 - HKCU\..\Run: [131360] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131360.cpl
O4 - HKCU\..\Run: [262484] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262484.cpl
O4 - HKCU\..\Run: [2949356] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\2949356.cpl
O4 - HKCU\..\Run: [5571108] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\5571108.cpl
O4 - HKCU\..\Run: [524344] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\524344.cpl
O4 - HKCU\..\Run: [262420] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262420.cpl
O4 - HKCU\..\Run: [66000] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\66000.cpl
O4 - HKCU\..\Run: [131456] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131456.cpl
O4 - HKCU\..\Run: [65980] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65980.cpl
O4 - HKCU\..\Run: [65986] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65986.cpl
O4 - HKCU\..\Run: [131490] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131490.cpl
O4 - HKCU\..\Run: [196940] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196940.cpl
O4 - HKCU\..\Run: [262402] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262402.cpl
O4 - HKCU\..\Run: [131494] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131494.cpl
O4 - HKCU\..\Run: [327924] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\327924.cpl
O4 - HKCU\..\Run: [262426] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262426.cpl
O4 - HKCU\..\Run: [328042] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\328042.cpl
O4 - HKCU\..\Run: [131404] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131404.cpl
O4 - HKCU\..\Run: [393444] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\393444.cpl
O4 - HKCU\..\Run: [131370] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131370.cpl
O4 - HKCU\..\Run: [327996] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\327996.cpl
O4 - HKCU\..\Run: [262478] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262478.cpl
O4 - HKCU\..\Run: [327994] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\327994.cpl
O4 - HKCU\..\Run: [524460] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\524460.cpl
O4 - HKCU\..\Run: [131286] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131286.cpl
O4 - HKCU\..\Run: [131262] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131262.cpl
O4 - HKCU\..\Run: [196832] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196832.cpl
O4 - HKCU\..\Run: [131256] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131256.cpl
O4 - HKCU\..\Run: [196824] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196824.cpl
O4 - HKCU\..\Run: [393450] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\393450.cpl
O4 - HKCU\..\Run: [196842] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196842.cpl
O4 - HKCU\..\Run: [393470] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\393470.cpl
O4 - HKCU\..\Run: [131300] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131300.cpl
O4 - HKCU\..\Run: [196770] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196770.cpl
O4 - HKCU\..\Run: [196892] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196892.cpl
O4 - HKCU\..\Run: [459024] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\459024.cpl
O4 - HKCU\..\Run: [131386] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131386.cpl
O4 - HKCU\..\Run: [196760] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196760.cpl
O4 - HKCU\..\Run: [131504] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131504.cpl
O4 - HKCU\..\Run: [196826] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196826.cpl
O4 - HKCU\..\Run: [65902] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65902.cpl
O4 - HKCU\..\Run: [328002] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\328002.cpl
O4 - HKCU\..\Run: [196854] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196854.cpl
O4 - HKCU\..\Run: [131506] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131506.cpl
O4 - HKCU\..\Run: [196942] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196942.cpl
O4 - HKCU\..\Run: [131348] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131348.cpl
O4 - HKCU\..\Run: [131354] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131354.cpl
O4 - HKCU\..\Run: [197058] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\197058.cpl
O4 - HKCU\..\Run: [196802] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196802.cpl
O4 - HKCU\..\Run: [459004] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\459004.cpl
O4 - HKCU\..\Run: [262448] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262448.cpl
O4 - HKCU\..\Run: [327980] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\327980.cpl
O4 - HKCU\..\Run: [393382] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\393382.cpl
O4 - HKCU\..\Run: [262300] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262300.cpl
O4 - HKCU\..\Run: [328004] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\328004.cpl
O4 - HKCU\..\Run: [196836] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196836.cpl
O4 - HKCU\..\Run: [721108] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\721108.cpl
O4 - HKCU\..\Run: [131412] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131412.cpl
O4 - HKCU\..\Run: [262378] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262378.cpl
O4 - HKCU\..\Run: [1245486] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\1245486.cpl
O4 - HKCU\..\Run: [65828] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65828.cpl
O4 - HKCU\..\Run: [131388] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131388.cpl
O4 - HKCU\..\Run: [786750] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\786750.cpl
O4 - HKCU\..\Run: [131332] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131332.cpl
O4 - HKCU\..\Run: [196956] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196956.cpl
O4 - HKCU\..\Run: [590148] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\590148.cpl
O4 - HKCU\..\Run: [393514] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\393514.cpl
O4 - HKCU\..\Run: [65934] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65934.cpl
O4 - HKCU\..\Run: [65906] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\65906.cpl
O4 - HKCU\..\Run: [131284] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131284.cpl
O4 - HKCU\..\Run: [131474] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131474.cpl
O4 - HKCU\..\Run: [458996] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\458996.cpl
O4 - HKCU\..\Run: [131430] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131430.cpl
O4 - HKCU\..\Run: [66078] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\66078.cpl
O4 - HKCU\..\Run: [262372] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262372.cpl
O4 - HKCU\..\Run: [262374] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262374.cpl
O4 - HKCU\..\Run: [393554] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\393554.cpl
O4 - HKCU\..\Run: [327890] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\327890.cpl
O4 - HKCU\..\Run: [66042] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\66042.cpl
O4 - HKCU\..\Run: [131326] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131326.cpl
O4 - HKCU\..\Run: [196844] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196844.cpl
O4 - HKCU\..\Run: [327908] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\327908.cpl
O4 - HKCU\..\Run: [524578] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\524578.cpl
O4 - HKCU\..\Run: [196882] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\196882.cpl
O4 - HKCU\..\Run: [131400] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131400.cpl
O4 - HKCU\..\Run: [66236] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\66236.cpl
O4 - HKCU\..\Run: [524444] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\524444.cpl
O4 - HKCU\..\Run: [524586] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\524586.cpl
O4 - HKCU\..\Run: [262370] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262370.cpl
O4 - HKCU\..\Run: [262456] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\262456.cpl
O4 - HKCU\..\Run: [5177512] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\5177512.cpl
O4 - HKCU\..\Run: [524618] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\524618.cpl
O4 - HKCU\..\Run: [327998] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\327998.cpl
O4 - HKCU\..\Run: [66010] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\66010.cpl
O4 - HKCU\..\Run: [131246] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131246.cpl
O4 - HKCU\..\Run: [787512] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\787512.cpl
O4 - HKCU\..\Run: [197186] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\197186.cpl
O4 - HKCU\..\Run: [131732] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\131732.cpl
O4 - HKCU\..\Run: [197284] rundll32.exe shell32.dll,Control_RunDLL C:\WINDOWS\197284.cpl
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSNet\RSEDNClient.exe
O4 - HKCU\..\Run: [ContentService] C:\WINDOWS\System32\winservn.exe
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Content-Type: text/] c:\WINDOWS\System32\Content-Type: text/html
O4 - Startup: AdsGone.lnk = C:\Program Files\AdsGone\adsgone.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O8 - Extra context menu item: &Google Search - res://c:\windows\downloaded program files\GoogleToolbar_en_2.0.95-big.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\windows\downloaded program files\GoogleToolbar_en_2.0.95-big.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\downloaded program files\GoogleToolbar_en_2.0.95-big.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\windows\downloaded program files\GoogleToolbar_en_2.0.95-big.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://c:\windows\downloaded program files\GoogleToolbar_en_2.0.95-big.dll/cmtrans.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {407F5185-3B2E-4196-982B-1E258C46F8FD} - ftp://ftp.ea.com/pub/easports/patches/nhl2003/en-us/nhl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/ssoap/pptproactauthakamai/systemsoappro.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/1512f9dfac0305ccfb20/netzip/RdxIE2.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37613.3965509259
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://www.wildtangent.com/install/wdriver/ddc/shockwave/blasterballwild/wtinst.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BD11A280-2E73-11CF-B6CF-00AA00A74DAF} - http://images.bonzi.com/freebuddy/wd/bbsetupad1.exe
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab

Add me to the list.
Any advice on the log below?
Logfile of HijackThis v1.97.5
Scan saved at 8:52:36 AM, on 12/4/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
C:\Program Files\ClearSearch\Loader.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\Program Files\WildTangent\Apps\GameChannel.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Microsoft Office\Office\OSA.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe
c:\program files\mcafee.com\shared\mghtml.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Don\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.netscape.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.oberlin.net:3128
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dellnet.com/
R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)
O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\Program Files\Lycos\Sidesearch\sidesearch1311.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: Clear Search - {947E6D5A-4B9F-4CF4-91B3-562CA8D03313} - C:\Program Files\ClearSearch\IE_ClrSch.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [ClrSchLoader] C:\Program Files\ClearSearch\Loader.exe
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: Sidesearch (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.imbum.com/Imbum.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab
O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://dst.trafficsyndicate.com/Dnl/T_50014/btiein.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,77/mcinsctl.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/nike/nikemagiafootball/install.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,18/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EE2589EB-7FC8-44DB-A892-573F2C4B41E0} - http://pdf.forbes.com/forbesnews/triggernews/ForbesDownloaderSigned.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://mirror.worldwinner.com//games/v43/h2hpool/h2hpool.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://http.gamezone.tukati.com/tukati/1.7.20.20/tukati.cab

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |