Logfile of HijackThis v1.98.2
Scan saved at 9:41:08 PM, on 9/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgamsvr.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgcc.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
C:\PROGRA~1\INTERN~2\inetmgr.exe
C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tca.exe
C:\PROGRA~1\INTERN~2\inetsvc.exe
C:\PROGRA~1\COMMON~1\tsa\tsm.exe
C:\Documents and Settings\LSU Brandon\Desktop\Spyware\Spyware Doctor\spydoctor.exe
C:\PROGRA~1\COMMON~1\tsa\ts.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
c:\Program Files\Dell\SolutionCenter\DellSC.exe
C:\Program Files\Dell\Support\bin\ClientApplicationFramework.exe
C:\Program Files\Common Files\Dell\EUSW\support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LSU Brandon\Desktop\HiJack This\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - _{1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Documents and Settings\LSU Brandon\Desktop\Trojan\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [tcactive] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe
O4 - HKCU\..\Run: [Tsa] C:\PROGRA~1\COMMON~1\tsa\tsm.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Documents and Settings\LSU Brandon\Desktop\Spyware\Spyware Doctor\spydoctor.exe" /Q
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML