Raman-
Thanks for replying so quickly. Here is the log file you requested from HijackThis. I look forward to your reply.
Logfile of HijackThis v1.97.7
Scan saved at 8:44:49 AM, on 12/8/2003
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://www.008i.com/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.008i.com/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://66.98.142.163/search.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hotmail.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://66.98.142.163R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://66.98.142.163/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://66.98.142.163/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://66.98.142.163/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.easy-search.netR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://66.98.142.163/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://66.98.142.163/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://66.98.142.163/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://66.98.142.163/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant =
http://www.008i.com/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch =
http://www.008i.com/search.htmlR3 - URLSearchHook: (no name) - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - (no file)
O1 - Hosts: 66.98.142.163 auto.search.msn.com
O1 - Hosts: 66.98.142.163 search.msn.com
O1 - Hosts: 66.98.142.163 msn.com
O1 - Hosts: 66.98.142.163
www.msn.comO1 - Hosts: 66.98.142.163 yahoo.com
O1 - Hosts: 66.98.142.163
www.yahoo.comO1 - Hosts: 66.98.142.163 google.com
O1 - Hosts: 66.98.142.163
www.google.comO1 - Hosts: 66.98.142.163 thenun.com
O1 - Hosts: 66.98.142.163
www.thehun.comO1 - Hosts: 66.98.142.163 thehun.net
O1 - Hosts: 66.98.142.163
www.thehun.netO2 - BHO: winlink module - {6CC1C91A-AE8B-4373-A5B4-28BA1851E39A} - C:\Documents and Settings\Jeff Davis\Application Data\winlink\winlink.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Msoffice] C:\WINNT\Fonts\msoffice.hta
O4 - HKLM\..\Run: [Online Service] C:\WINNT\svchost.exe
O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37960.7453472222O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
http://by2fd.bay2.hotmail.msn.com/activex/HMAtchmt.ocx