Hummm I have the same problem...
Could you please help me??
Logfile of HijackThis v1.98.1
Scan saved at 18:05:00, on 9/7/2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARQUIV~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\WINNT\htpatch.exe
C:\WINNT\System32\khooker.exe
C:\Arquivos de programas\PCI Audio Applications\Mixer.exe
C:\Arquivos de programas\Grisoft\AVG6\avgcc32.exe
C:\Arquivos de programas\BroadJump\Client Foundation\CFD.exe
C:\SCANJET\PrecisionScanLT\hppwrsav.exe
C:\WINNT\loadqm.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
C:\Arquivos de programas\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\System32\internat.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe
C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE
C:\Arquivos de programas\AntiPop-up UOL\ubphost.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://www.boredlife.com/search/R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
.rompl.com/?bbs2]http://girl[bleep].rompl.com/?bbs2R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://radaruol.uol.com.br/ie/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.uol.com.brR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &
http://home.microsof...ss/allinone.aspR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
.rompl.com/?bbs2]http://girl[bleep].rompl.com/?bbs2R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
.rompl.com/?bbs2]http://girl[bleep].rompl.com/?bbs2R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.uol.com.brR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.boredlife.com/sweb/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
.rompl.com/?bbs2]http://girl[bleep].rompl.com/?bbs2R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://e-plus.cc/hardcore/128R1 - HKLM\Software\Microsoft\Internet Explorer\Main,YAHOOSubst =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,YAHOOSubst =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\System32\userinit.exe,C:\WINNT\System32\svcinit.exe
O2 - BHO: Clear Search - {00000000-0000-0000-0000-000000000240} - C:\Arquivos de programas\ClearSearch\IE_ClrSch.DLL (file missing)
O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - C:\WINNT\mslagent\4b_1,0,1,0_mslagent.dll (file missing)
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\MSDXM.OCX
O3 - Toolbar: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
O3 - Toolbar: AntiPop-up UOL - {5BBFC00A-312C-4777-A5DF-DDA65C67120C} - C:\Arquivos de programas\AntiPop-up UOL\ubp.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HTpatch] C:\WINNT\htpatch.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\System32\khooker.exe
O4 - HKLM\..\Run: [C-Media Mixer] C:\Arquivos de programas\PCI Audio Applications\Mixer.exe /startup
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Arquivos de programas\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [CFD] C:\Arquivos de programas\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [hppwrsav] C:\SCANJET\PrecisionScanLT\hppwrsav.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Arquivos de programas\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [OrbitUpdate] C:\Arquivos de programas\Orbit\update.exe
O4 - HKLM\..\Run: [OrbitView] C:\Arquivos de programas\Orbit\view.exe
O4 - HKLM\..\Run: [EVOBMWF] C:\WINNT\EVOBMWF.exe
O4 - HKLM\..\Run: [CJQX] C:\WINNT\CJQX.exe
O4 - HKLM\..\Run: [CFI] C:\WINNT\CFI.exe
O4 - HKLM\..\Run: [RYMTA] C:\WINNT\RYMTA.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1014.dll,InstantAccess
O4 - HKCU\..\Run: [mslagent] C:\WINNT\mslagent\mslagent.exe
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Liberar pop-ups desta página - res://C:\Arquivos de programas\AntiPop-up UOL\ubp.dll/3028
O8 - Extra context menu item: Liberar pop-ups deste site - res://C:\Arquivos de programas\AntiPop-up UOL\ubp.dll/3027
O9 - Extra button: (no name) - {173F3521-8FBE-4d0c-B14D-C4D8513A06C0} - (no file)
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\ARQUIV~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\ARQUIV~1\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Arquivos de programas\AIM95\aim.exe
O9 - Extra button: (no name) - {173F3521-8FBE-4d0c-B14D-C4D8513A06C0} - (no file) (HKCU)
O14 - IERESET.INF: SEARCH_PAGE_URL=&
http://home.microsof...ss/allinone.aspO16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...ry/msgrchkr.cabO16 - DPF: {02607DF4-D40B-4FFB-B054-1CAC03468E28} (DNLCertificate Control) -
http://www.fmn-media...Certificate.ocxO16 - DPF: {0594AF7E-573B-40DF-8165-E47AB2EAEFE8} -
http://akamai.downlo...UTH_1014_EN.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.co...etup1.0.0.8.cabO16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -
http://host.cycore.n...E_5.3.0.228.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {4AE9E3BF-409D-4F61-9804-920968603919} -
http://www.7adpower....global_ver2.CABO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://207.188.7.150...RdxIE601_br.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...StatsClient.cabO16 - DPF: {91BE8DAC-957E-416C-B735-E2B63CDB915B} (MyEMessengerSetup Control) -
http://www.myemessen...etupProject.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) -
http://download.uol....tiveInstall.cabO16 - DPF: {DA4EB021-5F1C-11D4-B006-00104B98E2C7} (McAfee Clinic Installer Control) -
http://download.mcaf...ed/MInstall.cabO16 - DPF: {EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} -
http://akamai.downlo.../netpe32_EN.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{47320A00-B3A6-4C72-AB60-B6F13977307D}: Domain = @
O17 - HKLM\System\CS1\Services\Tcpip\..\{47320A00-B3A6-4C72-AB60-B6F13977307D}: Domain = @
O17 - HKLM\System\CS2\Services\Tcpip\..\{47320A00-B3A6-4C72-AB60-B6F13977307D}: Domain = @