Logfile of HijackThis v1.99.1
Scan saved at 12:27:38 PM, on 10/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\WINNT\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\TIREMOTE\wuser32.exe
C:\WINNT\TIREMOTE\TIRemoteService.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cidaemon.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Funk Software\Proxy Host\PHOST32.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Copernic Desktop Search\CopernicDesktopSearch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Azureus\Azureus.exe
D:\Program Files\AIM95\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Documents and Settings\rscarritt\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - C:\Program Files\Copernic Desktop Search\CopernicDesktopSearchIntegration977.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [Synchronization Manager] "mobsync.exe" /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [ProxyHostTrayIcon] "C:\Program Files\Funk Software\Proxy Host\PHOST32.EXE" -s
O4 - HKLM\..\Run: [Smapp] "C:\Program Files\Analog Devices\SoundMAX\Smtray.exe"
O4 - HKLM\..\Run: [DrvLsnr] "C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "S:\_Computer Rx\Webroot SpySweeper\Spy Sweeper All versions by muiz\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Copernic Desktop Search] "C:\Program Files\Copernic Desktop Search\CopernicDesktopSearch.exe" /tray
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.benefitsinbrief.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imageservr.com
O15 - Trusted Zone: http://admin.spencerfane.com
O15 - Trusted Zone: http://arbitration.spencerfane.com
O15 - Trusted Zone: http://bugtracker.spencerfane.com
O15 - Trusted Zone: http://calendar.spencerfane.com
O15 - Trusted Zone: http://chat.spencerfane.com
O15 - Trusted Zone: http://corpfocus.spencerfane.com
O15 - Trusted Zone: http://development.spencerfane.com
O15 - Trusted Zone: http://directory.spencerfane.com
O15 - Trusted Zone: http://edgar.spencerfane.com
O15 - Trusted Zone: http://elite.spencerfane.com
O15 - Trusted Zone: http://extranet.spencerfane.com
O15 - Trusted Zone: http://help.spencerfane.com
O15 - Trusted Zone: http://inout.spencerfane.com
O15 - Trusted Zone: http://intranet.spencerfane.com
O15 - Trusted Zone: http://jobs.spencerfane.com
O15 - Trusted Zone: http://lawcruit.spencerfane.com
O15 - Trusted Zone: http://ldap.spencerfane.com
O15 - Trusted Zone: http://live1.spencerfane.com
O15 - Trusted Zone: http://live2.spencerfane.com
O15 - Trusted Zone: http://live3.spencerfane.com
O15 - Trusted Zone: http://live4.spencerfane.com
O15 - Trusted Zone: http://live5.spencerfane.com
O15 - Trusted Zone: http://live6.spencerfane.com
O15 - Trusted Zone: http://live7.spencerfane.com
O15 - Trusted Zone: http://outlook.spencerfane.com
O15 - Trusted Zone: http://reports.spencerfane.com
O15 - Trusted Zone: http://SA.spencerfane.com
O15 - Trusted Zone: http://slcorpfocus.spencerfane.com
O15 - Trusted Zone: http://survey.spencerfane.com
O15 - Trusted Zone: http://taskpro.spencerfane.com
O15 - Trusted Zone: http://taskprodev.spencerfane.com
O15 - Trusted Zone: http://test1.spencerfane.com
O15 - Trusted Zone: http://test2.spencerfane.com
O15 - Trusted Zone: http://test3.spencerfane.com
O15 - Trusted Zone: http://test4.spencerfane.com
O15 - Trusted Zone: http://test5.spencerfane.com
O15 - Trusted Zone: http://test6.spencerfane.com
O15 - Trusted Zone: http://test7.spencerfane.com
O15 - Trusted Zone: http://tickets.spencerfane.com
O15 - Trusted Zone: http://training.spencerfane.com
O15 - Trusted Zone: http://trusted.spencerfane.com
O15 - Trusted Zone: http://www.spencerfane.com
O15 - Trusted Zone: http://www.benefitsinbrief.com (HKLM)
O15 - Trusted Zone: http://admin.spencerfane.com (HKLM)
O15 - Trusted Zone: http://bugtracker.spencerfane.com (HKLM)
O15 - Trusted Zone: http://corpfocus.spencerfane.com (HKLM)
O15 - Trusted Zone: http://development.spencerfane.com (HKLM)
O15 - Trusted Zone: http://directory.spencerfane.com (HKLM)
O15 - Trusted Zone: http://elite.spencerfane.com (HKLM)
O15 - Trusted Zone: http://extranet.spencerfane.com (HKLM)
O15 - Trusted Zone: http://help.spencerfane.com (HKLM)
O15 - Trusted Zone: http://inout.spencerfane.com (HKLM)
O15 - Trusted Zone: http://intranet.spencerfane.com (HKLM)
O15 - Trusted Zone: http://jobs.spencerfane.com (HKLM)
O15 - Trusted Zone: http://lawcruit.spencerfane.com (HKLM)
O15 - Trusted Zone: http://live1.spencerfane.com (HKLM)
O15 - Trusted Zone: http://live2.spencerfane.com (HKLM)
O15 - Trusted Zone: http://live3.spencerfane.com (HKLM)
O15 - Trusted Zone: http://live4.spencerfane.com (HKLM)
O15 - Trusted Zone: http://live5.spencerfane.com (HKLM)
O15 - Trusted Zone: http://live6.spencerfane.com (HKLM)
O15 - Trusted Zone: http://live7.spencerfane.com (HKLM)
O15 - Trusted Zone: http://sa.spencerfane.com (HKLM)
O15 - Trusted Zone: http://slcorpfocus.spencerfane.com (HKLM)
O15 - Trusted Zone: http://survey.spencerfane.com (HKLM)
O15 - Trusted Zone: http://taskpro.spencerfane.com (HKLM)
O15 - Trusted Zone: http://test1.spencerfane.com (HKLM)
O15 - Trusted Zone: http://test2.spencerfane.com (HKLM)
O15 - Trusted Zone: http://test3.spencerfane.com (HKLM)
O15 - Trusted Zone: http://test4.spencerfane.com (HKLM)
O15 - Trusted Zone: http://test5.spencerfane.com (HKLM)
O15 - Trusted Zone: http://test6.spencerfane.com (HKLM)
O15 - Trusted Zone: http://test7.spencerfane.com (HKLM)
O15 - Trusted Zone: http://tickets.spencerfane.com (HKLM)
O15 - Trusted Zone: http://training.spencerfane.com (HKLM)
O15 - Trusted Zone: http://www.spencerfane.com (HKLM)
O15 - Trusted IP range: http://192.168.16.16
O15 - Trusted IP range: http://192.168.16.16 (HKLM)
O16 - DPF: Sametime Meeting Room Client ST30SP1 - http://sametime.rete...gRoomClient.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewid...oOnlineScan.cab
O16 - DPF: {24CEC0BF-C8BC-4BCB-B804-226326B319EF} (JNILoader Control) - http://sametime.rete...STJNILoader.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner....leanerstart.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1148398738979
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1147197878170
O16 - DPF: {6F74F92E-8DD8-4DDE-8FB8-CBB882A68048} (Microsoft Office XP Professional Step by Step Interactive) - file://C:\Program Files\Microsoft Interactive Training\O10C\mitm0026.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = spencerfane.com
O17 - HKLM\Software\..\Telephony: DomainName = spencerfane.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = spencerfane.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = spencerfane.com
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Proxy Host Service (ProxyHostService) - Funk Software, Inc. - C:\Program Files\Funk Software\Proxy Host\PH32SVC.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Track-It! Remote Control (TIRmtCtl) - Intuit Track-It! - C:\WINNT\TIREMOTE\wuser32.exe
O23 - Service: Track-It! Workstation Manager (TIRmtSvc) - Numara Software, Inc. - C:\WINNT\TIREMOTE\TIRemoteService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - S:\_Computer Rx\Webroot SpySweeper\Spy Sweeper All versions by muiz\SpySweeper.exe