Hi, anyone read this please help meeverytime i open IE I will be redirect to this 540.filost, I can't remove with adaware.
Logfile of HijackThis v1.99.1
Scan saved at 12:27:51 AM, on 4/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\Winampa.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.makemesearch.com/?said=399
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O1 - Hosts: <html xmlns="urn:schemas-microsoft-com
ffice
ffice"
O1 - Hosts: xmlns:w="urn:schemas-microsoft-comffice:word"
O1 - Hosts: xmlns="http://www.w3.org/TR/REC-html40">
O1 - Hosts: <head>
O1 - Hosts: <meta http-equiv=Content-Type content="text/html; charset=windows-1252">
O1 - Hosts: <meta name=ProgId content=Word.Document>
O1 - Hosts: <meta name=Generator content="Microsoft Word 10">
O1 - Hosts: <meta name=Originator content="Microsoft Word 10">
O1 - Hosts: <link rel=File-List href="hosts_files/filelist.xml">
O1 - Hosts: <!--[if gte mso 9]><xml>
O1 - Hosts: <oocumentProperties>
O1 - Hosts: <o:Author>Jeff</o:Author>
O1 - Hosts: <o:Template>Normal</o:Template>
O1 - Hosts: <o:LastAuthor>Jeff</o:LastAuthor>
O1 - Hosts: <o:Revision>2</o:Revision>
O1 - Hosts: <o:TotalTime>0</o:TotalTime>
O1 - Hosts: <o:Created>2006-04-10T08:16:00Z</o:Created>
O1 - Hosts: <o:LastSaved>2006-04-10T08:16:00Z</o:LastSaved>
O1 - Hosts: <o:Pages>1</o:Pages>
O1 - Hosts: <o:Words>110</o:Words>
O1 - Hosts: <o:Characters>633</o:Characters>
O1 - Hosts: <o:Company>HCData</o:Company>
O1 - Hosts: <o:Lines>5</o:Lines>
O1 - Hosts: <o:Paragraphs>1</o:Paragraphs>
O1 - Hosts: <o:CharactersWithSpaces>742</o:CharactersWithSpaces>
O1 - Hosts: <o:Version>10.4219</o:Version>
O1 - Hosts: </oocumentProperties>
O1 - Hosts: </xml><![endif]--><!--[if gte mso 9]><xml>
O1 - Hosts: <w:WordDocument>
O1 - Hosts: <w:SpellingState>Clean</w:SpellingState>
O1 - Hosts: <w:GrammarState>Clean</w:GrammarState>
O1 - Hosts: <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
O1 - Hosts: </w:WordDocument>
O1 - Hosts: </xml><![endif]-->
O1 - Hosts: <style>
O1 - Hosts: <!--
O1 - Hosts: /* Style Definitions */
O1 - Hosts: p.MsoNormal, li.MsoNormal, div.MsoNormal
O1 - Hosts: {mso-style-parent:"";
O1 - Hosts: margin:0in;
O1 - Hosts: margin-bottom:.0001pt;
O1 - Hosts: mso-pagination:widow-orphan;
O1 - Hosts: font-size:12.0pt;
O1 - Hosts: font-family:"Times New Roman";
O1 - Hosts: mso-fareast-font-family:"Times New Roman";}
O1 - Hosts: pre
O1 - Hosts: {font-size:10.0pt;
O1 - Hosts: font-family:"Courier New";
O1 - Hosts: mso-fareast-font-family:"Times New Roman";}
O1 - Hosts: span.SpellE
O1 - Hosts: {mso-style-name:"";
O1 - Hosts: mso-spl-e:yes;}
O1 - Hosts: span.GramE
O1 - Hosts: {mso-style-name:"";
O1 - Hosts: mso-gram-e:yes;}
O1 - Hosts: @page Section1
O1 - Hosts: {size:8.5in 11.0in;
O1 - Hosts: margin:1.0in 1.25in 1.0in 1.25in;
O1 - Hosts: mso-header-margin:.5in;
O1 - Hosts: mso-footer-margin:.5in;
O1 - Hosts: mso-paper-source:0;}
O1 - Hosts: div.Section1
O1 - Hosts: {page:Section1;}
O1 - Hosts: -->
O1 - Hosts: </style>
O1 - Hosts: <!--[if gte mso 10]>
O1 - Hosts: <style>
O1 - Hosts: /* Style Definitions */
O1 - Hosts: table.MsoNormalTable
O1 - Hosts: {mso-style-name:"Table Normal";
O1 - Hosts: mso-tstyle-rowband-size:0;
O1 - Hosts: mso-tstyle-colband-size:0;
O1 - Hosts: mso-style-noshow:yes;
O1 - Hosts: mso-style-parent:"";
O1 - Hosts: mso-padding-alt:0in 5.4pt 0in 5.4pt;
O1 - Hosts: mso-para-margin:0in;
O1 - Hosts: mso-para-margin-bottom:.0001pt;
O1 - Hosts: mso-pagination:widow-orphan;
O1 - Hosts: font-size:10.0pt;
O1 - Hosts: font-family:"Times New Roman";}
O1 - Hosts: </style>
O1 - Hosts: <![endif]-->
O1 - Hosts: </head>
O1 - Hosts: <body lang=EN-US style='tab-interval:.5in'>
O1 - Hosts: <div class=Section1><pre># Copyright (c) 1993-1999 Microsoft Corp.</pre><pre>#</pre><pre># <span
O1 - Hosts: class=GramE>This</span> is a sample HOSTS file used by Microsoft TCP/IP for Windows.</pre><pre>#</pre><pre># <span
O1 - Hosts: class=GramE>This</span> file contains the mappings of IP addresses to host names. Each</pre><pre># <span
O1 - Hosts: class=GramE>entry</span> should be kept on an individual line. The IP address should</pre><pre># <span
O1 - Hosts: class=GramE>be</span> placed in the first column followed by the corresponding host name.</pre><pre># The IP address and the host name should be separated by at least one</pre><pre># <span
O1 - Hosts: class=GramE>space</span>.</pre><pre>#</pre><pre># <span class=GramE>Additionally</span>, comments (such as these) may be inserted on individual</pre><pre># <span
O1 - Hosts: class=GramE>lines</span> or following the machine name denoted by a '#' symbol.</pre><pre>#</pre><pre># <span
O1 - Hosts: class=GramE>For</span> example:</pre><pre>#</pre><pre>#<span style='mso-spacerun:yes'>***** </span>102.54.94.97<span style='mso-spacerun:yes'>**** </span>rhino.acme.com<span style='mso-spacerun:yes'>********* </span># source server</pre><pre>#<span style='mso-spacerun:yes'>****** </span>38.25.63.10<span style='mso-spacerun:yes'>**** </span>x.acme.com<span style='mso-spacerun:yes'>************* </span># x client host</pre><pre><o> </o
></pre><pre>127.0.0.1<span style='mso-spacerun:yes'>****** </span>localhost</pre><pre><o
> </o
></pre>
O1 - Hosts: 72.20.18.85 jdorama.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.d ll
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.d ll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with &Etomi - res://C:\Program Files\Etomi\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbme s.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbme s.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/ocx/12119/CTSUEng.cab
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1129526711204
O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1135787451687
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/ocx/15008/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{74AC907E-FBA8-4FB4-BCF6-5F624F2B7071}: NameServer = 202.160.8.2 202.160.8.20
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe



everytime i open IE I will be redirect to this 540.filost, I can't remove with adaware.
ocumentProperties>
> </o