Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Throwing in the towel [resolved]


  • This topic is locked This topic is locked

#1
DangerousThing

DangerousThing

    Member

  • Member
  • PipPipPip
  • 259 posts
:tazz: I give up. I have been battling some phantom in my older of two machines for over a week. Ad-aware SE, Spybot S&D, Spyware Guard, Norton Pro 04, CW Shredder, all are current and have been run multiple times. I have also downloaded and installed a HOSTS file.

I continue to find multiple BHO's and various other junk at every start up. My Yahoo browser constantly tires to connect whane running other programs.

Please find my HiJAck This log below.



Logfile of HijackThis v1.99.0
Scan saved at 11:06:27 AM, on 3/29/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\WINDOWS\SYSTEM\HPOOPM07.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBROWSER.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapp...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:2323
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\SYSTEM\hpoopm07.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O10 - Broken Internet access because of LSP provider 'ypclsp.dll' missing
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca05.righ...l/java/RntX.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamesp...nch/alaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab

Any help is much appreciated. This is the machine my kids use to game on, (as do I)

Note: I have tried to delete the "01" search objects dozens of times......
  • 0

Advertisements


#2
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
I have two machines running, one viewing this post and another in the live chat where i found you. i can respond in either venue as you prefer..thank you again for viewing my post
  • 0

#3
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Download L2mfix from:

http://www.atribune....oads/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe.
  • Click the Install button to extract the files and follow the prompts.
  • Then open the newly added l2mfix folder on your desktop.
  • Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter.
    This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log.
  • Copy the contents of that log and paste it into this thread.
Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
  • 0

#4
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
okay...brb
  • 0

#5
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
I get a "not compatable with window 9x or nt" message
  • 0

#6
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Hello,
  • Download findit9xme.zip.
  • Unzip the contents of findit9xme.zip to a convenient location.
  • Navigate to the Find It NT-2K-XP folder and double-click on find.bat.
  • A command prompt will open and it will search your computer for malicious files.
  • Once it has finished a Notepad window will pop up with output.txt.
  • Copy the entire contents of output.txt into your next post.
From the moment you post your list, until you see a detailed fix written up, DO NOT reboot your system or log off. If you do, the files will have changed and the fix provided will not work.

Edited by didom, 01 April 2005 - 09:51 AM.

  • 0

#7
Lightninghawk

Lightninghawk

    Member

  • Member
  • PipPipPip
  • 128 posts
DangerousThing

Please stick with didom and ignore the suggestions from Lightninghawk . You are already in very capable hands.

Lightninghawk

If you want to post help in the Malware Removal forum here at GTG, you need to be a staff member. Click here to join Geek U.

ScHwErV :tazz:

Unwanted advice edited by Geek U Mod

Edited by ScHwErV, 01 April 2005 - 10:21 AM.

  • 0

#8
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

------- System Files in System Directory -------


Volume in drive C has no label
Volume Serial Number is 401E-1AD8
Directory of C:\WINDOWS\SYSTEM

TBPS INI 849 03-20-05 12:32a TBPS.ini
MAACM DLL 227,104 03-18-05 9:08p MAACM.DLL
MJVBVM60 DLL 227,104 03-18-05 9:08p Mjvbvm60.dll
JQPL400 DLL 227,104 03-18-05 9:08p JQPL400.DLL
DQVENUM DLL 227,104 03-18-05 9:08p DQVENUM.DLL
WXNUPDAK DLL 227,104 03-18-05 9:08p wxnupdak.dll
MMOSS DLL 227,104 03-18-05 9:08p MMOSS.DLL
RQVPSP DLL 227,104 03-18-05 9:08p RQVPSP.DLL
OWDBSE32 DLL 227,104 03-18-05 9:08p OWDBSE32.DLL
MGJTER40 DLL 227,104 03-18-05 9:08p MGJTER40.DLL
OQE2 DLL 227,104 03-18-05 9:08p OQE2.DLL
SFD401LC DLL 227,104 03-18-05 9:08p SFD401LC.DLL
MUCMS DLL 227,104 03-18-05 9:08p MUCMS.DLL
MWPRINT2 DLL 227,104 03-18-05 9:08p MWPRINT2.DLL
ORUI400 DLL 227,104 03-18-05 9:08p ORUI400.DLL
HPSETUP DLL 227,104 03-18-05 9:08p HPSETUP.DLL
EMCLI32 DLL 227,104 03-18-05 9:08p emcli32.dll
OUDBSE32 DLL 227,104 03-18-05 9:08p OUDBSE32.DLL
EZLCNS32 DLL 227,104 03-18-05 9:08p EZLCNS32.DLL
CXL3D DLL 227,104 03-18-05 9:08p CXL3D.DLL
DRWSOCK DLL 227,104 03-18-05 9:08p DRWSOCK.DLL
WJNASPI DLL 227,104 03-18-05 9:08p WJNASPI.DLL
DA8VB DLL 227,104 03-18-05 9:08p DA8VB.DLL
HOINK DLL 227,104 03-18-05 9:08p HOINK.DLL
MKOSS DLL 227,104 03-18-05 9:08p MKOSS.DLL
DDMIGR DLL 227,104 03-18-05 9:08p DDMIGR.DLL
CLNEMRES DLL 227,104 03-18-05 9:08p clnemres.dll
27 file(s) 5,905,553 bytes
0 dir(s) 21,411.28 MB free

------- Hidden Files in System Directory -------


Volume in drive C has no label
Volume Serial Number is 401E-1AD8
Directory of C:\WINDOWS\SYSTEM

PICSVR <DIR> 03-26-05 8:25p picsvr
NSVSVC <DIR> 03-26-05 8:24p nsvsvc
ATMENUXX GID 10,842 11-10-04 12:48p ATMenuxx.GID
CPAHLENU GID 10,825 02-23-02 8:53p CPAHLENU.GID
FOLDER HTT 13,122 10-04-01 7:35p folder.htt
DESKTOP INI 266 10-04-01 7:35p desktop.ini
4 file(s) 35,055 bytes
2 dir(s) 21,411.25 MB free

---------------- User Agent ------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{416097EE-FC4A-E167-6011-AF6C211AC428}"=""


------------------ Locate.com Results ------------------

C:\WINDOWS\SYSTEM\
maacm.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mjvbvm60.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
jqpl400.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
tbps.ini Sun Mar 20 2005 12:32:02a ..S.R 849 0.83 K
dqvenum.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
wxnupdak.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mmoss.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
rqvpsp.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
owdbse32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mgjter40.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
oqe2.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
sfd401lc.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mucms.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mwprint2.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
orui400.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
hpsetup.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
emcli32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
oudbse32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ezlcns32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
cxl3d.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
drwsock.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
wjnaspi.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
da8vb.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
hoink.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mkoss.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ddmigr.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
clnemres.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K

27 items found: 27 files, 0 directories.
Total of file sizes: 5,905,553 bytes 5.63 M

------------ Strings.exe Qoologic Results ------------

C:\WINDOWS\installer.exe: e:\Projects\Qoologic\PopupClient\Installer\Release\Installer.pdb
C:\WINDOWS\installer.exe: e:\Projects\Qoologic\PopupClient\FancyUninstall\Release\FancyUninstall.pdb
C:\WINDOWS\unadbeh.exe: e:\Projects\Qoologic\PopupClient\FancyUninstall\Release\FancyUninstall.pdb

-------------- Strings.exe Aspack Results -------------


----------------- HKLM Run Key ------------------

-------------- Strings.exe Umonitor Results -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe"
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"TaskMonitor"="C:\\WINDOWS\\taskmon.exe"
"LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
"AtiPTA"="Atiptaxx.exe"
"HPAIO_PrintFolderMgr"="C:\\WINDOWS\\SYSTEM\\hpoopm07.exe"
"BJCFD"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"YBrowser"="C:\\Program Files\\Yahoo!\\browser\\ybrwicon.exe"
"WinPatrol"="C:\\PROGRAM FILES\\BILLP STUDIOS\\WINPATROL\\winpatrol.exe"
"Symantec Core LC"="C:\\Program Files\\Common Files\\Symantec Shared\\CCPD-LC\\symlcsvc.exe start"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMON.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"


  • 0

#9
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
have you returned?
  • 0

#10
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
fyi.....the constant opening of my yahoo browser has : about:blank

in the address line
  • 0

Advertisements


#11
didom

didom

    Member 1K

  • Member
  • PipPipPipPip
  • 1,919 posts
Download Killbox

Unzip the contents of KillBox.zip to a convenient location and then double-click on KillBox.exe to launch the program.
  • Click killbox.exe.
  • Select the option Replace on Reboot
  • Check the "Use Dummy" box.
  • Now copy the next bold:
C:\WINDOWS\SYSTEM\maacm.dll
C:\WINDOWS\SYSTEM\mjvbvm60.dll
C:\WINDOWS\SYSTEM\jqpl400.dll
C:\WINDOWS\SYSTEM\dqvenum.dll
C:\WINDOWS\SYSTEM\wxnupdak.dll
C:\WINDOWS\SYSTEM\mmoss.dll
C:\WINDOWS\SYSTEM\rqvpsp.dll
C:\WINDOWS\SYSTEM\owdbse32.dll
C:\WINDOWS\SYSTEM\mgjter40.dll
C:\WINDOWS\SYSTEM\oqe2.dll
C:\WINDOWS\SYSTEM\sfd401lc.dll
C:\WINDOWS\SYSTEM\mucms.dll
C:\WINDOWS\SYSTEM\mwprint2.dll
C:\WINDOWS\SYSTEM\orui400.dll
C:\WINDOWS\SYSTEM\hpsetup.dll
C:\WINDOWS\SYSTEM\emcli32.dll
C:\WINDOWS\SYSTEM\oudbse32.dll
C:\WINDOWS\SYSTEM\ezlcns32.dll
C:\WINDOWS\SYSTEM\cxl3d.dll
C:\WINDOWS\SYSTEM\drwsock.dll
C:\WINDOWS\SYSTEM\wjnaspi.dll
C:\WINDOWS\SYSTEM\da8vb.dll
C:\WINDOWS\SYSTEM\hoink.dll
C:\WINDOWS\SYSTEM\mkoss.dll
C:\WINDOWS\SYSTEM\ddmigr.dll
C:\WINDOWS\SYSTEM\clnemres.dll
  • Open file in the killboxmenu on top and choose Paste from clipboard
  • Now you will see, this is pasted in the "Full Path of File to Delete"-field.
    There's a little arrow (dropdown-arrow) next to that field.
    If you expand it, all these must be there together!
  • Then press the button that looks like a red circle with a white X in it.
  • Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
  • When it asks if you would like to Reboot now, click YES
(if you don't get the prompt: would you like to reboot now, reboot manually!)

Your computer must reboot now.

Ignore the errors you get... this is normal.
  • When rebooted, open killbox again.
  • Choose file on top and select: Delete all dummy files.
  • Choose Tools on top and select: Delete Temp Files.
  • After that please run find.bat again and post a new log (output.txt).
  • Download the new version of HijackThis and post a new log!
Didom
  • 0

#12
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
didom...

Sorry to have been out of touch. Unrelated connectivity issues have had me offline until today. I am performing the above requested tasks and will be posting both logs ASAP.

Please be advised that I DID have to reboot. I re-ran the BAT.exe and created an output log prior to continuing. Please advise if additional steps are required.

Thanks to you again for your gracious assistance.
  • 0

#13
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
Here is the latest "Output":

------- System Files in System Directory -------


Volume in drive C has no label
Volume Serial Number is 401E-1AD8
Directory of C:\WINDOWS\SYSTEM

TBPS INI 849 03-20-05 12:32a TBPS.ini
MAACM DLL 227,104 03-18-05 9:08p MAACM.DLL
MJVBVM60 DLL 227,104 03-18-05 9:08p Mjvbvm60.dll
JQPL400 DLL 227,104 03-18-05 9:08p JQPL400.DLL
DQVENUM DLL 227,104 03-18-05 9:08p DQVENUM.DLL
WXNUPDAK DLL 227,104 03-18-05 9:08p wxnupdak.dll
MMOSS DLL 227,104 03-18-05 9:08p MMOSS.DLL
RQVPSP DLL 227,104 03-18-05 9:08p RQVPSP.DLL
OWDBSE32 DLL 227,104 03-18-05 9:08p OWDBSE32.DLL
MGJTER40 DLL 227,104 03-18-05 9:08p MGJTER40.DLL
OQE2 DLL 227,104 03-18-05 9:08p OQE2.DLL
SFD401LC DLL 227,104 03-18-05 9:08p SFD401LC.DLL
MUCMS DLL 227,104 03-18-05 9:08p MUCMS.DLL
MWPRINT2 DLL 227,104 03-18-05 9:08p MWPRINT2.DLL
ORUI400 DLL 227,104 03-18-05 9:08p ORUI400.DLL
HPSETUP DLL 227,104 03-18-05 9:08p HPSETUP.DLL
EMCLI32 DLL 227,104 03-18-05 9:08p emcli32.dll
OUDBSE32 DLL 227,104 03-18-05 9:08p OUDBSE32.DLL
EZLCNS32 DLL 227,104 03-18-05 9:08p EZLCNS32.DLL
CXL3D DLL 227,104 03-18-05 9:08p CXL3D.DLL
DRWSOCK DLL 227,104 03-18-05 9:08p DRWSOCK.DLL
WJNASPI DLL 227,104 03-18-05 9:08p WJNASPI.DLL
DA8VB DLL 227,104 03-18-05 9:08p DA8VB.DLL
HOINK DLL 227,104 03-18-05 9:08p HOINK.DLL
MKOSS DLL 227,104 03-18-05 9:08p MKOSS.DLL
DDMIGR DLL 227,104 03-18-05 9:08p DDMIGR.DLL
NPDLL DLL 227,104 03-18-05 9:08p NPDLL.DLL
CLNEMRES DLL 227,104 03-18-05 9:08p clnemres.dll
RZASETUP DLL 227,104 03-18-05 9:08p RZASETUP.DLL
ANI2Q9AA DLL 227,104 03-18-05 9:08p ANI2Q9AA.DLL
30 file(s) 6,586,865 bytes
0 dir(s) 21,414.91 MB free

------- Hidden Files in System Directory -------


Volume in drive C has no label
Volume Serial Number is 401E-1AD8
Directory of C:\WINDOWS\SYSTEM

PICSVR <DIR> 03-26-05 8:25p picsvr
NSVSVC <DIR> 03-26-05 8:24p nsvsvc
ATMENUXX GID 10,842 11-10-04 12:48p ATMenuxx.GID
CPAHLENU GID 10,825 02-23-02 8:53p CPAHLENU.GID
FOLDER HTT 13,122 10-04-01 7:35p folder.htt
DESKTOP INI 266 10-04-01 7:35p desktop.ini
4 file(s) 35,055 bytes
2 dir(s) 21,414.88 MB free

---------------- User Agent ------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{416097EE-FC4A-E167-6011-AF6C211AC428}"=""


------------------ Locate.com Results ------------------

C:\WINDOWS\SYSTEM\
maacm.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mjvbvm60.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
jqpl400.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
tbps.ini Sun Mar 20 2005 12:32:02a ..S.R 849 0.83 K
dqvenum.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
wxnupdak.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mmoss.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
rqvpsp.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
owdbse32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mgjter40.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
oqe2.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
sfd401lc.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mucms.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mwprint2.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
orui400.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
hpsetup.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
emcli32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
oudbse32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ezlcns32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
cxl3d.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
drwsock.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
wjnaspi.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
da8vb.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
hoink.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mkoss.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ddmigr.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
npdll.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
clnemres.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
rzasetup.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ani2q9aa.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K

30 items found: 30 files, 0 directories.
Total of file sizes: 6,586,865 bytes 6.28 M

------------ Strings.exe Qoologic Results ------------

C:\WINDOWS\installer.exe: e:\Projects\Qoologic\PopupClient\Installer\Release\Installer.pdb
C:\WINDOWS\installer.exe: e:\Projects\Qoologic\PopupClient\FancyUninstall\Release\FancyUninstall.pdb
C:\WINDOWS\unadbeh.exe: e:\Projects\Qoologic\PopupClient\FancyUninstall\Release\FancyUninstall.pdb

-------------- Strings.exe Aspack Results -------------


----------------- HKLM Run Key ------------------

-------------- Strings.exe Umonitor Results -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe"
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"TaskMonitor"="C:\\WINDOWS\\taskmon.exe"
"LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
"AtiPTA"="Atiptaxx.exe"
"HPAIO_PrintFolderMgr"="C:\\WINDOWS\\SYSTEM\\hpoopm07.exe"
"BJCFD"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"YBrowser"="C:\\Program Files\\Yahoo!\\browser\\ybrwicon.exe"
"WinPatrol"="C:\\PROGRAM FILES\\BILLP STUDIOS\\WINPATROL\\winpatrol.exe"
"Symantec Core LC"="C:\\Program Files\\Common Files\\Symantec Shared\\CCPD-LC\\symlcsvc.exe start"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMON.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"



  • 0

#14
DangerousThing

DangerousThing

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 259 posts
Here they are, in the order you requested:

------- System Files in System Directory -------


Volume in drive C has no label
Volume Serial Number is 401E-1AD8
Directory of C:\WINDOWS\SYSTEM

TBPS INI 849 03-20-05 12:32a TBPS.ini
MAACM DLL 227,104 03-18-05 9:08p MAACM.DLL
MJVBVM60 DLL 227,104 03-18-05 9:08p Mjvbvm60.dll
JQPL400 DLL 227,104 03-18-05 9:08p JQPL400.DLL
DQVENUM DLL 227,104 03-18-05 9:08p DQVENUM.DLL
WXNUPDAK DLL 227,104 03-18-05 9:08p wxnupdak.dll
MMOSS DLL 227,104 03-18-05 9:08p MMOSS.DLL
RQVPSP DLL 227,104 03-18-05 9:08p RQVPSP.DLL
OWDBSE32 DLL 227,104 03-18-05 9:08p OWDBSE32.DLL
MGJTER40 DLL 227,104 03-18-05 9:08p MGJTER40.DLL
OQE2 DLL 227,104 03-18-05 9:08p OQE2.DLL
SFD401LC DLL 227,104 03-18-05 9:08p SFD401LC.DLL
MUCMS DLL 227,104 03-18-05 9:08p MUCMS.DLL
MWPRINT2 DLL 227,104 03-18-05 9:08p MWPRINT2.DLL
ORUI400 DLL 227,104 03-18-05 9:08p ORUI400.DLL
HPSETUP DLL 227,104 03-18-05 9:08p HPSETUP.DLL
EMCLI32 DLL 227,104 03-18-05 9:08p emcli32.dll
OUDBSE32 DLL 227,104 03-18-05 9:08p OUDBSE32.DLL
EZLCNS32 DLL 227,104 03-18-05 9:08p EZLCNS32.DLL
CXL3D DLL 227,104 03-18-05 9:08p CXL3D.DLL
DRWSOCK DLL 227,104 03-18-05 9:08p DRWSOCK.DLL
WJNASPI DLL 227,104 03-18-05 9:08p WJNASPI.DLL
DA8VB DLL 227,104 03-18-05 9:08p DA8VB.DLL
HOINK DLL 227,104 03-18-05 9:08p HOINK.DLL
MKOSS DLL 227,104 03-18-05 9:08p MKOSS.DLL
DDMIGR DLL 227,104 03-18-05 9:08p DDMIGR.DLL
NPDLL DLL 227,104 03-18-05 9:08p NPDLL.DLL
CLNEMRES DLL 227,104 03-18-05 9:08p clnemres.dll
RZASETUP DLL 227,104 03-18-05 9:08p RZASETUP.DLL
ANI2Q9AA DLL 227,104 03-18-05 9:08p ANI2Q9AA.DLL
30 file(s) 6,586,865 bytes
0 dir(s) 21,414.91 MB free

------- Hidden Files in System Directory -------


Volume in drive C has no label
Volume Serial Number is 401E-1AD8
Directory of C:\WINDOWS\SYSTEM

PICSVR <DIR> 03-26-05 8:25p picsvr
NSVSVC <DIR> 03-26-05 8:24p nsvsvc
ATMENUXX GID 10,842 11-10-04 12:48p ATMenuxx.GID
CPAHLENU GID 10,825 02-23-02 8:53p CPAHLENU.GID
FOLDER HTT 13,122 10-04-01 7:35p folder.htt
DESKTOP INI 266 10-04-01 7:35p desktop.ini
4 file(s) 35,055 bytes
2 dir(s) 21,414.88 MB free

---------------- User Agent ------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{416097EE-FC4A-E167-6011-AF6C211AC428}"=""


------------------ Locate.com Results ------------------

C:\WINDOWS\SYSTEM\
maacm.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mjvbvm60.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
jqpl400.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
tbps.ini Sun Mar 20 2005 12:32:02a ..S.R 849 0.83 K
dqvenum.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
wxnupdak.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mmoss.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
rqvpsp.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
owdbse32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mgjter40.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
oqe2.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
sfd401lc.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mucms.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mwprint2.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
orui400.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
hpsetup.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
emcli32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
oudbse32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ezlcns32.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
cxl3d.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
drwsock.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
wjnaspi.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
da8vb.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
hoink.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
mkoss.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ddmigr.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
npdll.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
clnemres.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
rzasetup.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K
ani2q9aa.dll Fri Mar 18 2005 9:08:46p ..S.R 227,104 221.78 K

30 items found: 30 files, 0 directories.
Total of file sizes: 6,586,865 bytes 6.28 M

------------ Strings.exe Qoologic Results ------------

C:\WINDOWS\installer.exe: e:\Projects\Qoologic\PopupClient\Installer\Release\Installer.pdb
C:\WINDOWS\installer.exe: e:\Projects\Qoologic\PopupClient\FancyUninstall\Release\FancyUninstall.pdb
C:\WINDOWS\unadbeh.exe: e:\Projects\Qoologic\PopupClient\FancyUninstall\Release\FancyUninstall.pdb

-------------- Strings.exe Aspack Results -------------


----------------- HKLM Run Key ------------------

-------------- Strings.exe Umonitor Results -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe"
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"TaskMonitor"="C:\\WINDOWS\\taskmon.exe"
"LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
"AtiPTA"="Atiptaxx.exe"
"HPAIO_PrintFolderMgr"="C:\\WINDOWS\\SYSTEM\\hpoopm07.exe"
"BJCFD"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"YBrowser"="C:\\Program Files\\Yahoo!\\browser\\ybrwicon.exe"
"WinPatrol"="C:\\PROGRAM FILES\\BILLP STUDIOS\\WINPATROL\\winpatrol.exe"
"Symantec Core LC"="C:\\Program Files\\Common Files\\Symantec Shared\\CCPD-LC\\symlcsvc.exe start"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMON.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"







Logfile of HijackThis v1.99.1
Scan saved at 6:59:49 PM, on 4/3/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\WINDOWS\SYSTEM\HPOOPM07.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP OFFICEJET K SERIES\BIN\HPODEV07.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP OFFICEJET K SERIES\BIN\HPOEVM07.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP OFFICEJET K SERIES\BIN\HPOSTS07.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP OFFICEJET K SERIES\BIN\HPOFXM07.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBROWSER.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapp...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:2323
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\SYSTEM\hpoopm07.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O10 - Broken Internet access because of LSP provider 'ypclsp.dll' missing
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://liveca05.righ...l/java/RntX.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamesp...nch/alaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
  • 0

#15
alexs464

alexs464

    Member

  • Member
  • PipPip
  • 32 posts
it worked for me :tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP