Logfile of HijackThis v1.99.1
Scan saved at 12:13:50 PM, on 8/20/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
D:\PROGRAM FILES\MCAFEE FIREWALL\CPD.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
D:\PROGRAM FILES\MCAFEE FIREWALL\CPD.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\GUARDIAN\CMGRDIAN.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT UPDATER\RULAUNCH.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
D:\PROGRAM FILES\ICQ\ICQ.EXE
C:\WINDOWS\SYSTEM\INTELL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.refdesk.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r21.mchsi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r21.mchsi.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Window Shades - {B5B57F4F-EFA5-11D4-A971-444553540000} - D:\PROGRA~1\WINDOW~1\WINDOW~1.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CloneCDTray] "D:\Program Files\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [McAfee Guardian] "C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\GUARDIAN\CMGRDIAN.EXE" /SU
O4 - HKLM\..\Run: [vptray] C:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\SYSTEM\intell32.exe
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\RunServices: [McAfee Firewall] "D:\PROGRAM FILES\MCAFEE FIREWALL\CPD.EXE" /SERVICE
O4 - HKLM\..\RunServices: [rtvscn95] C:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\Program Files\Norton AntiVirus\defwatch.exe
O4 - HKLM\..\RunServicesOnce: [CleanIEDAT] \xen\clean9xdat.bat
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - Startup: xenclean 9x.bat
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\Program Files\PartyPoker\PartyPoker.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX 5.5 Basic) -
http://learn.sdstate...12A/ScriptX.cabO16 - DPF: {BD346F41-52BB-11D6-873F-0004AC28D799} (WebpHMeter.TechnologyBasedLabs) -
http://learn.sdstate...abs/phmeter.cabO16 - DPF: {D5277CD5-A7F1-11D6-8743-9162B7216474} (VSG1.TechnologyBasedLabs) -
http://learn.sdstate...tr/cabs/VSG.CABO16 - DPF: {BD346EA1-52BB-11D6-873F-0004AC28D799} (MolecularGeometry.TechnologyBasedLabs) -
http://learn.sdstate...cabs/molgeo.cabO16 - DPF: {BD346E3F-52BB-11D6-873F-0004AC28D799} (LabTechniques.TechnologyBasedLabs) -
http://learn.sdstate.../techniques.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg...v45/yacscom.cabO16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
http://chat.yahoo.com/cab/yacsui.cabO16 - DPF: {BD34716B-52BB-11D6-873F-0004AC28D799} (SpecLab.TechnologyBasedLabs) -
http://learn.sdstate...pectroscopy.cabO16 - DPF: {9FD82800-52A6-11D6-873F-825E3BF38072} (GasLab.TechnologyBasedLabs) -
http://learn.sdstate.../cabs/gases.cabO16 - DPF: {C4712F16-5263-11D6-873F-995E98353173} (ThermChem.TechnologyBasedLabs) -
http://learn.sdstate...mochemistry.cabO16 - DPF: {C47130A4-5263-11D6-873F-995E98353173} (Chromat.TechnologyBasedLabs) -
http://learn.sdstate...abs/chromat.cabO16 - DPF: {C47131A2-5263-11D6-873F-995E98353173} (ColligProp.TechnologyBasedLabs) -
http://learn.sdstate...eproperties.cabO16 - DPF: {54D0BF3A-FA81-11D6-874A-F9F469F1D476} (EquilCon.TechnologyBasedLabs) -
http://learn.sdstate...iumconstant.cabO16 - DPF: {F49EEA0A-6E84-11D6-8740-98249CA57959} (Borax.TechnologyBasedLabs) -
http://learn.sdstate.../cabs/borax.cabO16 - DPF: {EA4E41D4-52BA-11D6-873F-0004AC28D799} (JobsLaw.TechnologyBasedLabs) -
http://learn.sdstate...r/cabs/jobs.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://fdl.msn.com/p...t/msnchat45.cabO16 - DPF: {687589B8-1501-11D7-8685-E0D0A4FE9926} (ScientificObs.TechnologyBasedLabs) -
http://learn.sdstate...bservations.CABO16 - DPF: {83420F81-0005-11D7-874A-AF75C5156375} (WeakAcid.TechnologyBasedLabs) -
http://learn.sdstate...idTitration.CABO16 - DPF: {EA4E42EE-52BA-11D6-873F-0004AC28D799} (KspProject.TechnologyBasedLabs) -
http://learn.sdstate...tr/cabs/Ksp.CABO16 - DPF: {C4712FE4-5263-11D6-873F-995E98353173} (Bromothymol.TechnologyBasedLabs) -
http://learn.sdstate...Bromothymol.CABO16 - DPF: {77F2F812-0004-11D7-874A-AF75C5156375} (CopperLab.TechnologyBasedLabs) -
http://learn.sdstate...erChemistry.CABO16 - DPF: {C471329D-5263-11D6-873F-995E98353173} (Electrochem.TechnologyBasedLabs) -
http://learn.sdstate...rochemistry.CABO16 - DPF: {EA4E4258-52BA-11D6-873F-0004AC28D799} (KineticsLab.TechnologyBasedLabs) -
http://learn.sdstate...bs/Kinetics.CABO16 - DPF: {74DA02DF-0005-11D7-874A-AF75C5156375} (Water.TechnologyBasedLabs) -
http://learn.sdstate...ontaminants.CABO16 - DPF: {BD346F15-52BB-11D6-873F-0004AC28D799} (OrganicCompds.TechnologyBasedLabs) -
http://learn.sdstate...abs/Organic.CABO16 - DPF: {261D269B-0005-11D7-874A-AF75C5156375} (RedoxTitrationLab.TechnologyBasedLabs) -
http://learn.sdstate...oxTitration.CABO16 - DPF: {BD346FB4-52BB-11D6-873F-0004AC28D799} (Photosyn.TechnologyBasedLabs) -
http://learn.sdstate...bs/Photosyn.CABO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cab