Ok, below is a fresh log. Yeah, I want that problem removed first, it is crazy. I am going crazy as well. By the way, the hompage (res://) keeps changing to a different one. One more think, I have another problem. I have to type in www before the website name and before .com . Usually I just type in the website name.com (EX: yahoo.com <<<< no www.). Please help me fix the problems. One last thing also. My problem got worse. Now it loads to my desktop, shows the backround picture, and now takes 6 MINUTES TO LOAD!!!!! This is crazy.
Logfile of HijackThis v1.98.0
Scan saved at 8:10:32 PM, on 7/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\WINDOWS\ntnr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\MoreResults\MoreResults.exe
C:\WINDOWS\System32\oiqpkqp.exe
C:\WINDOWS\system32\apiny32.exe
C:\Program Files\Common Files\WinTools\WToolsA.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\system32\DfrgNtfs.exe
C:\WINDOWS\system32\dmremote.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Bilal\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\danfd.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://danfd.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://danfd.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\danfd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\danfd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://danfd.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://yahoo.com/
R3 - Default URLSearchHook is missing
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {B856C014-733A-E7C2-BA3A-B880A9541D36} - C:\WINDOWS\ntwk.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CPLDBL10] C:\Program Files\EzButton\CPLDBL10.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [MoreResults] C:\Program Files\MoreResults\MoreResults.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automove.exe
O4 - HKLM\..\Run: [xbnjtberp] C:\WINDOWS\System32\oiqpkqp.exe
O4 - HKLM\..\Run: [apiny32.exe] C:\WINDOWS\system32\apiny32.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\Bilal\LOCALS~1\Temp\tb_setup.exe /dcheck
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
O4 - HKLM\..\RunOnce: [sdkwb32.exe] C:\WINDOWS\sdkwb32.exe
O4 - HKLM\..\RunOnce: [d3de32.exe] C:\WINDOWS\system32\d3de32.exe
O4 - HKLM\..\RunOnce: [applu32.exe] C:\WINDOWS\applu32.exe
O4 - HKLM\..\RunOnce: [javavo.exe] C:\WINDOWS\javavo.exe
O4 - HKLM\..\RunOnce: [sdkyy32.exe] C:\WINDOWS\system32\sdkyy32.exe
O4 - HKLM\..\RunOnce: [appfa.exe] C:\WINDOWS\appfa.exe
O4 - HKLM\..\RunOnce: [netaz.exe] C:\WINDOWS\netaz.exe
O4 - HKLM\..\RunOnce: [apiiw.exe] C:\WINDOWS\apiiw.exe
O4 - HKLM\..\RunOnce: [ipqh.exe] C:\WINDOWS\system32\ipqh.exe
O4 - HKLM\..\RunOnce: [apint32.exe] C:\WINDOWS\system32\apint32.exe
O4 - HKLM\..\RunOnce: [javaco.exe] C:\WINDOWS\system32\javaco.exe
O4 - HKLM\..\RunOnce: [mfcvb32.exe] C:\WINDOWS\system32\mfcvb32.exe
O4 - HKLM\..\RunOnce: [atlfx.exe] C:\WINDOWS\atlfx.exe
O4 - HKLM\..\RunOnce: [addig.exe] C:\WINDOWS\addig.exe
O4 - HKLM\..\RunOnce: [netmq32.exe] C:\WINDOWS\netmq32.exe
O4 - HKLM\..\RunOnce: [apiem.exe] C:\WINDOWS\system32\apiem.exe
O4 - HKLM\..\RunOnce: [sysxd32.exe] C:\WINDOWS\sysxd32.exe
O4 - HKLM\..\RunOnce: [ipvf32.exe] C:\WINDOWS\ipvf32.exe
O4 - HKLM\..\RunOnce: [d3bl32.exe] C:\WINDOWS\d3bl32.exe
O4 - HKLM\..\RunOnce: [nttk32.exe] C:\WINDOWS\system32\nttk32.exe
O4 - HKLM\..\RunOnce: [mfced32.exe] C:\WINDOWS\mfced32.exe
O4 - HKLM\..\RunOnce: [ipix32.exe] C:\WINDOWS\system32\ipix32.exe
O4 - HKLM\..\RunOnce: [ntnr32.exe] C:\WINDOWS\ntnr32.exe
O4 - HKLM\..\RunOnce: [addih32.exe] C:\WINDOWS\addih32.exe
O4 - HKLM\..\RunOnce: [mfcee.exe] C:\WINDOWS\system32\mfcee.exe
O4 - HKLM\..\RunOnce: [javato.exe] C:\WINDOWS\system32\javato.exe
O4 - HKLM\..\RunOnce: [winzp.exe] C:\WINDOWS\winzp.exe
O4 - HKLM\..\RunOnce: [mfcjt.exe] C:\WINDOWS\system32\mfcjt.exe
O4 - HKLM\..\RunOnce: [sdkho.exe] C:\WINDOWS\sdkho.exe
O4 - HKLM\..\RunOnce: [appac32.exe] C:\WINDOWS\appac32.exe
O4 - HKLM\..\RunOnce: [mfczp.exe] C:\WINDOWS\mfczp.exe
O4 - HKLM\..\RunOnce: [addyf.exe] C:\WINDOWS\system32\addyf.exe
O4 - HKLM\..\RunOnce: [mspf.exe] C:\WINDOWS\system32\mspf.exe
O4 - HKLM\..\RunOnce: [sysro.exe] C:\WINDOWS\sysro.exe
O4 - HKLM\..\RunOnce: [ntby32.exe] C:\WINDOWS\ntby32.exe
O4 - HKLM\..\RunOnce: [winwi.exe] C:\WINDOWS\winwi.exe
O4 - HKLM\..\RunOnce: [winrr.exe] C:\WINDOWS\winrr.exe
O4 - HKLM\..\RunOnce: [apicn.exe] C:\WINDOWS\system32\apicn.exe
O4 - HKLM\..\RunOnce: [syskj.exe] C:\WINDOWS\system32\syskj.exe
O4 - HKLM\..\RunOnce: [ntxy32.exe] C:\WINDOWS\ntxy32.exe
O4 - HKLM\..\RunOnce: [ntzs32.exe] C:\WINDOWS\ntzs32.exe
O4 - HKLM\..\RunOnce: [mfcwc.exe] C:\WINDOWS\mfcwc.exe
O4 - HKLM\..\RunOnce: [javagu.exe] C:\WINDOWS\javagu.exe
O4 - HKLM\..\RunOnce: [apiqs.exe] C:\WINDOWS\system32\apiqs.exe
O4 - HKLM\..\RunOnce: [ntgc.exe] C:\WINDOWS\system32\ntgc.exe
O4 - HKLM\..\RunOnce: [appfj.exe] C:\WINDOWS\system32\appfj.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\WebRebates\System\Temp\topr1150_script0.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yaho...st20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_42.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/0631ccf5...p/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
http://us.games2.yimg.com/download.g...tl_0_0_0_1.ocx
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
http://launch.gamespyarcade.com/soft...ch/alaunch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} -
http://download.websearch.com/Dnl/T_50038/QDow_AS2.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.com/download.yaho...tocomplete.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX/kdx.cab
O18 - Protocol: icoo - {2CC63CCE-A945-4D6A-9FA0-3669D7C3C22C} - C:\Program Files\ICOO Loader\addons7\icoourl.dll