Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

HJT Log


  • Please log in to reply

#16
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts
Click on start button, then search. Type in "services.msc" into the search, double click on it when found to start.
  • 0

Advertisements


#17
Archie

Archie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
Still no luck, search comes up empty.
  • 0

#18
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts
Looks like you have some OS corruption. Do you have a Windows XP CD? Consider a repair installation: http://www.geekstogo...p?showtopic=138
  • 0

#19
Archie

Archie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
I'm running ME on this computer. Could that be why I can't find that file?
  • 0

#20
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts
I should have noticed that! I as looking at your profile instead of looking in the log. <_<

Please go offline, close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items, then click fix checked.
O4 - HKLM\..\RunServices: [MSJS32.EXE] C:\WINDOWS\MSJS32.EXE
O4 - HKLM\..\RunServices: [ATLRF32.EXE] C:\WINDOWS\ATLRF32.EXE
O4 - HKLM\..\RunServices: [ATLHL32.EXE] C:\WINDOWS\ATLHL32.EXE

Reboot in safe mode (by tapping F8 at startup and select safe mode from the menu).
Be sure you're able to view hidden files, and remove the following files in bold (if found):
C:\WINDOWS\MSJS32.EXE
C:\WINDOWS\ATLRF32.EXE
C:\WINDOWS\ATLHL32.EXE

Reboot your PC.

If you would please, rescan with HijackThis and post a fresh log. :D
  • 0

#21
Archie

Archie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
I was unable to locate some of the files. Also, what is CRRO.DLL? It keeps popping up.



Logfile of HijackThis v1.98.0
Scan saved at 11:34:46 AM, on 7/27/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\MSJS32.EXE
C:\WINDOWS\MSJS32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\btjss.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekstogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ecpfg.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\ecpfg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\ecpfg.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ecpfg.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL (file missing)
O2 - BHO: EspIEObj Class - {2F4F8CC3-FF89-11D1-9F63-0020182D7E20} - C:\PROGRAM FILES\ESAFE\PROTECT\espie.dll (file missing)
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\SPEECH\DRAGON\WEB_IE.DLL (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL (file missing)
O2 - BHO: Class - {4D48529B-74F6-988B-1896-ABE0AA392AA1} - C:\WINDOWS\SYSTEM\CRRO.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL (file missing)
O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
O4 - HKLM\..\Run: [WinPatrol] "C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2.0\BHODemon.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
O12 - Plugin for .doc: C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\PLUGINS\NPDOC.DLL
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.c.../ymmapi_416.dll
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real...ArcadeRdxIE.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pog...n-ob-assets.cab
O16 - DPF: Fortune Bingo by pogo - http://superbingo.po...o-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://bingoe.pogo.c...e-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://peaks.pogo.co...s-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.po...s-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://popfu.pogo.co...u-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://greenback.pog...k-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://turbo12.pogo....1-ob-assets.cab
O16 - DPF: Tumble Bees by pogo - http://jumbee.pogo.c...e-ob-assets.cab
O16 - DPF: Dice Derby by pogo - http://checkeredflag...g-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://freecell.pogo...l-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo - http://sweet05.pogo....h-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://whomp.pogo.co...p-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://klondike.pogo...s-ob-assets.cab
O16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) - http://mirror.worldw...ared/dephlp.cab
O16 - DPF: First Class Solitaire by pogo - http://solitaire.pog...2-ob-assets.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.116...2/View22RTE.cab
O16 - DPF: Mah Jong Garden by pogo - http://mahjong2.pogo...g-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo....m-ob-assets.cab
O16 - DPF: Keno by pogo - http://keno.pogo.com...o-ob-assets.cab
O16 - DPF: Pirate's Gold by pogo - http://swashbucks07....d-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://showbiz.pogo....z-ob-assets.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldw...jo/wordmojo.cab
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homes...ive/HS_live.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.c...ropper1_2us.cab
O16 - DPF: Checkers by pogo - http://checkers.pogo...s-ob-assets.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://vbjack.pogo.c...k-ob-assets.cab
O16 - DPF: Top Down Baseball Challenge by pogo - http://topdown2.pogo...2-ob-assets.cab
O16 - DPF: Euchre by pogo - http://euchre.pogo.c...e-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://flinger.pogo....r-ob-assets.cab
O16 - DPF: Cribbage by pogo - http://crib.pogo.com...e-ob-assets.cab
O16 - DPF: Animal Ark by pogo - http://play05.pogo.c...l-ob-assets.cab
O16 - DPF: Ali Baba Slots TM by pogo - http://slots.pogo.co...a-ob-assets.cab
O16 - DPF: Showbiz Slots 2 by pogo - http://showbiz2.pogo...2-ob-assets.cab
O16 - DPF: SciFi Slots by pogo - http://scifi.pogo.co...i-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://roulet.pogo.c...e-ob-assets.cab
O16 - DPF: Perfect Passer by pogo - http://perfectpasser...r-ob-assets.cab
O16 - DPF: Spades by pogo - http://spades.pogo.c...s-ob-assets.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-cent...bin/actxcab.cab
O16 - DPF: Dominoes by pogo - http://domino.pogo.c...o-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://waterwheel.po...l-ob-assets.cab
O16 - DPF: Hearts by pogo - http://hearts.pogo.c...s-ob-assets.cab
  • 0

#22
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts
Thanks for sticking with us. As you can tell this variant of CWSearch can be difficult to remove. About:Buster has been updated again. Version 1.32, it looks like this should help remove your infection.

Please download (again) About:Buster and unzip it to your desktop. Start it, hit Ok, Start, And Ok again to start the scan. It will generate a log. Post that log along with a new Hijack this log here.

Download About:Buster here: http://www.geekstogo...=download&id=25
  • 0

#23
Archie

Archie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
About:Buster Version 1.25
Removed! : C:\WINDOWS\pcsux.dat
Removed! : C:\WINDOWS\System\ecpfg.dll
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!




Logfile of HijackThis v1.98.0
Scan saved at 7:00:57 AM, on 7/28/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\BHODEMON 2.0\BHODEMON.EXE
C:\PROGRAM FILES\AMERICA ONLINE 8.0\AOL.EXE
C:\PROGRAM FILES\AMERICA ONLINE 8.0\WAOL.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\MSJS32.EXE
C:\WINDOWS\MSJS32.EXE
C:\WINDOWS\MSJS32.EXE
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\btjss.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekstogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ecpfg.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\ecpfg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\ecpfg.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ecpfg.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL (file missing)
O2 - BHO: EspIEObj Class - {2F4F8CC3-FF89-11D1-9F63-0020182D7E20} - C:\PROGRAM FILES\ESAFE\PROTECT\espie.dll (file missing)
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\SPEECH\DRAGON\WEB_IE.DLL (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL (file missing)
O2 - BHO: Class - {4D48529B-74F6-988B-1896-ABE0AA392AA1} - C:\WINDOWS\SYSTEM\CRRO.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL (file missing)
O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
O4 - HKLM\..\Run: [WinPatrol] "C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2.0\BHODemon.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
O12 - Plugin for .doc: C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\PLUGINS\NPDOC.DLL
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.c.../ymmapi_416.dll
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real...ArcadeRdxIE.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pog...n-ob-assets.cab
O16 - DPF: Fortune Bingo by pogo - http://superbingo.po...o-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://bingoe.pogo.c...e-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://peaks.pogo.co...s-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.po...s-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://popfu.pogo.co...u-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://greenback.pog...k-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://turbo12.pogo....1-ob-assets.cab
O16 - DPF: Tumble Bees by pogo - http://jumbee.pogo.c...e-ob-assets.cab
O16 - DPF: Dice Derby by pogo - http://checkeredflag...g-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://freecell.pogo...l-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo - http://sweet05.pogo....h-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://whomp.pogo.co...p-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://klondike.pogo...s-ob-assets.cab
O16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) - http://mirror.worldw...ared/dephlp.cab
O16 - DPF: First Class Solitaire by pogo - http://solitaire.pog...2-ob-assets.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.116...2/View22RTE.cab
O16 - DPF: Mah Jong Garden by pogo - http://mahjong2.pogo...g-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo....m-ob-assets.cab
O16 - DPF: Keno by pogo - http://keno.pogo.com...o-ob-assets.cab
O16 - DPF: Pirate's Gold by pogo - http://swashbucks07....d-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://showbiz.pogo....z-ob-assets.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldw...jo/wordmojo.cab
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homes...ive/HS_live.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.c...ropper1_2us.cab
O16 - DPF: Checkers by pogo - http://checkers.pogo...s-ob-assets.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://vbjack.pogo.c...k-ob-assets.cab
O16 - DPF: Top Down Baseball Challenge by pogo - http://topdown2.pogo...2-ob-assets.cab
O16 - DPF: Euchre by pogo - http://euchre.pogo.c...e-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://flinger.pogo....r-ob-assets.cab
O16 - DPF: Cribbage by pogo - http://crib.pogo.com...e-ob-assets.cab
O16 - DPF: Animal Ark by pogo - http://play05.pogo.c...l-ob-assets.cab
O16 - DPF: Ali Baba Slots TM by pogo - http://slots.pogo.co...a-ob-assets.cab
O16 - DPF: Showbiz Slots 2 by pogo - http://showbiz2.pogo...2-ob-assets.cab
O16 - DPF: SciFi Slots by pogo - http://scifi.pogo.co...i-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://roulet.pogo.c...e-ob-assets.cab
O16 - DPF: Perfect Passer by pogo - http://perfectpasser...r-ob-assets.cab
O16 - DPF: Spades by pogo - http://spades.pogo.c...s-ob-assets.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-cent...bin/actxcab.cab
O16 - DPF: Dominoes by pogo - http://domino.pogo.c...o-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://waterwheel.po...l-ob-assets.cab
O16 - DPF: Hearts by pogo - http://hearts.pogo.c...s-ob-assets.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
  • 0

#24
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts

About:Buster Version 1.25

You're still using an old version of AboutBuster. Did you download it again?
  • 0

#25
Archie

Archie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
That's the version you linked me to. I just downloaded it again and ran it again.



About:Buster Version 1.25
Removed! : C:\WINDOWS\pcsux.dat
Removed! : C:\WINDOWS\System\ecpfg.dll
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
  • 0

Advertisements


#26
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts
Okay, download it again now. <_< There was a bug in the download script that kept the file from updating. I just tested it an it works now. :D
  • 0

#27
Archie

Archie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
I just tried to download it again , but I got a "Site is closed" message. I guess I'll try again later.
  • 0

#28
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts
Oops! Will work now. <_<
  • 0

#29
Archie

Archie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
[bleep], someone's been busy with this program. Here's the results.



-- Scan 1 --------
About:Buster Version 1.32
Removed! : C:\WINDOWS\yclpxy.dat
Removed! : C:\WINDOWS\ppqycb.dat
Removed! : C:\WINDOWS\syste32.exe
Removed! : C:\WINDOWS\lheoua.dat
Error Removing! : C:\WINDOWS\wgiyis.dat
Removed! : C:\WINDOWS\zshjdx.dat
Removed! : C:\WINDOWS\sysge32.exe
Removed! : C:\WINDOWS\eovug.dat
Removed! : C:\WINDOWS\appnk32.exe
Error Removing! : C:\WINDOWS\ksqlab.dat
Removed! : C:\WINDOWS\mdbhni.dat
Removed! : C:\WINDOWS\nqpbv.dat
Removed! : C:\WINDOWS\avzfqd.dat
Removed! : C:\WINDOWS\jwmmh.dat
Removed! : C:\WINDOWS\addpa32.exe
Removed! : C:\WINDOWS\atlrf32.exe
Removed! : C:\WINDOWS\epdlki.dat
Removed! : C:\WINDOWS\ysvhxp.dat
Removed! : C:\WINDOWS\appdl.exe
Removed! : C:\WINDOWS\atlhl32.exe
Error Removing! : C:\WINDOWS\ndfcpv.dat
Removed! : C:\WINDOWS\mzjnpc.dat
Removed! : C:\WINDOWS\mslw.exe
Error Removing! : C:\WINDOWS\jqwfcu.dat
Removed! : C:\WINDOWS\ktpbxa.dat
Error Removing! : C:\WINDOWS\lluehe.dat
Removed! : C:\WINDOWS\nofsuk.dat
Removed! : C:\WINDOWS\ipay32.exe
Removed! : C:\WINDOWS\apiwz.exe
Error Removing! : C:\WINDOWS\kwinco.dat
Removed! : C:\WINDOWS\hxpuiv.dat
Removed! : C:\WINDOWS\aaarvc.dat
Removed! : C:\WINDOWS\appvx.exe
Error Removing! : C:\WINDOWS\tnlocy.dat
Removed! : C:\WINDOWS\wijnzi.dat
Error Removing! : C:\WINDOWS\wtohjl.dat
Removed! : C:\WINDOWS\yehdws.dat
Removed! : C:\WINDOWS\netyr.exe
Removed! : C:\WINDOWS\aqptiu.dat
Removed! : C:\WINDOWS\clnsge.dat
Removed! : C:\WINDOWS\eoyoak.dat
Removed! : C:\WINDOWS\xarknr.dat
Removed! : C:\WINDOWS\bczbxn.dat
Removed! : C:\WINDOWS\ncbjcj.dat
Error Removing! : C:\WINDOWS\bvhrxu.dat
Removed! : C:\WINDOWS\dysoka.dat
Removed! : C:\WINDOWS\ntmt32.exe
Removed! : C:\WINDOWS\ipyb32.exe
Removed! : C:\WINDOWS\sysyg.exe
Removed! : C:\WINDOWS\zzhfkg.dat
Removed! : C:\WINDOWS\wvvtlh.dat
Removed! : C:\WINDOWS\qzoqxn.dat
Removed! : C:\WINDOWS\sdkhb32.exe
Removed! : C:\WINDOWS\xdohp.dat
Removed! : C:\WINDOWS\msjs32.exe
Error Removing! : C:\WINDOWS\oezele.dat
Removed! : C:\WINDOWS\xmixmi.dat
Removed! : C:\WINDOWS\wukgbw.dat
Error Removing! : C:\WINDOWS\zmeosk.dat
Removed! : C:\WINDOWS\mfckl32.exe
Removed! : C:\WINDOWS\virup.dat
Removed! : C:\WINDOWS\jvndce.dat
Removed! : C:\WINDOWS\adduj.exe
Removed! : C:\WINDOWS\pisivi.dat
Error Removing! : C:\WINDOWS\kzzceu.dat
Removed! : C:\WINDOWS\iemq32.exe
Removed! : C:\WINDOWS\ejibw.dat
Removed! : C:\WINDOWS\xmitwi.dat
Error Removing! : C:\WINDOWS\jodhuw.dat
Removed! : C:\WINDOWS\addsk.exe
Error Removing! : C:\WINDOWS\xqqira.dat
Removed! : C:\WINDOWS\lozxw.dat
Removed! : C:\WINDOWS\ghczfa.dat
Removed! : C:\WINDOWS\yiqli.dat
Removed! : C:\WINDOWS\winve.exe
Error Removing! : C:\WINDOWS\tifabd.dat
Error Removing! : C:\WINDOWS\sycmct.dat
Removed! : C:\WINDOWS\addzm32.exe
Removed! : C:\WINDOWS\bspdon.dat
Removed! : C:\WINDOWS\sdkme.exe
Error Removing! : C:\WINDOWS\clfaod.dat
Removed! : C:\WINDOWS\rnstuh.dat
Removed! : C:\WINDOWS\fbxby.dat
Removed! : C:\WINDOWS\javarm32.exe
Removed! : C:\WINDOWS\bdkjrk.dat
Removed! : C:\WINDOWS\atlva.exe
Removed! : C:\WINDOWS\nlxie.dat
Error Removing! : C:\WINDOWS\lysyxt.dat
Error Removing! : C:\WINDOWS\pdvgqh.dat
Removed! : C:\WINDOWS\ejxbp.dat
Error Removing! : C:\WINDOWS\phusqo.dat
Removed! : C:\WINDOWS\sdknq.exe
Removed! : C:\WINDOWS\vunbwq.dat
Removed! : C:\WINDOWS\atlxy.exe
Error Removing! : C:\WINDOWS\aovpwg.dat
Removed! : C:\WINDOWS\rexhr.dat
Error Removing! : C:\WINDOWS\ihjxom.dat
Removed! : C:\WINDOWS\msjw.exe
Removed! : C:\WINDOWS\omdcnr.dat
Removed! : C:\WINDOWS\xyxva.dat
Removed! : C:\WINDOWS\vfvur.dat
Removed! : C:\WINDOWS\jbymq.dat
Removed! : C:\WINDOWS\enbjg.dat
Removed! : C:\WINDOWS\zywvz.dat
Removed! : C:\WINDOWS\netwq32.exe
Removed! : C:\WINDOWS\netgc32.exe
Removed! : C:\WINDOWS\ntkq.exe
Removed! : C:\WINDOWS\msbl.exe
Removed! : C:\WINDOWS\lqmca.dat
Removed! : C:\WINDOWS\trzls.dat
Removed! : C:\WINDOWS\nhkmn.dat
Removed! : C:\WINDOWS\wzliq.dat
Removed! : C:\WINDOWS\sndcv.dat
Removed! : C:\WINDOWS\sjgig.dat
Removed! : C:\WINDOWS\obwax.dat
Removed! : C:\WINDOWS\gqtif.dat
Removed! : C:\WINDOWS\zzavh.dat
Removed! : C:\WINDOWS\lnsht.dat
Removed! : C:\WINDOWS\cigjg.dat
Removed! : C:\WINDOWS\aupsh.dat
Removed! : C:\WINDOWS\mumda.dat
Removed! : C:\WINDOWS\n_yijbzm.dat
Removed! : C:\WINDOWS\d3xy32.exe
Removed! : C:\WINDOWS\mfcxb32.exe
Removed! : C:\WINDOWS\crpd.exe
Removed! : C:\WINDOWS\ntup.exe
Removed! : C:\WINDOWS\winnf32.dll
Removed! : C:\WINDOWS\unhots.dat
Removed! : C:\WINDOWS\eovugs.dat
Removed! : C:\WINDOWS\sdkki32.exe
Removed! : C:\WINDOWS\dynakq.dat
Removed! : C:\WINDOWS\kzzcbz.dat
Removed! : C:\WINDOWS\lfeibf.dat
Removed! : C:\WINDOWS\bggsrd.dat
Removed! : C:\WINDOWS\apikw32.exe
Error Removing! : C:\WINDOWS\kxsrev.dat
Removed! : C:\WINDOWS\ntqm32.exe
Removed! : C:\WINDOWS\bpmbfc.dat
Removed! : C:\WINDOWS\ipap.exe
Removed! : C:\WINDOWS\SYSTEM\ntmi32.exe
Removed! : C:\WINDOWS\SYSTEM\crro.dll
Removed! : C:\WINDOWS\SYSTEM\crro.exe
Removed! : C:\WINDOWS\SYSTEM\xeyag.dat
Removed! : C:\WINDOWS\SYSTEM\iadqq.dat
Removed! : C:\WINDOWS\SYSTEM\ipwu32.exe
Removed! : C:\WINDOWS\SYSTEM\sysli.exe
Removed! : C:\WINDOWS\SYSTEM\addnr.exe
Removed! : C:\WINDOWS\SYSTEM\fhssx.dat
Removed! : C:\WINDOWS\SYSTEM\iexy.exe
Removed! : C:\WINDOWS\SYSTEM\ipaj32.exe
Removed! : C:\WINDOWS\SYSTEM\winwr.exe
Removed! : C:\WINDOWS\SYSTEM\ipmj32.exe
Removed! : C:\WINDOWS\SYSTEM\d3nu32.exe
Removed! : C:\WINDOWS\SYSTEM\msxm32.exe
Removed! : C:\WINDOWS\SYSTEM\ipih.exe
Removed! : C:\WINDOWS\SYSTEM\neteo32.exe
Removed! : C:\WINDOWS\SYSTEM\addls32.exe
Removed! : C:\WINDOWS\SYSTEM\msic.exe
Removed! : C:\WINDOWS\SYSTEM\addbp32.exe
Removed! : C:\WINDOWS\SYSTEM\sdkyi32.exe
Removed! : C:\WINDOWS\SYSTEM\netly32.exe
Removed! : C:\WINDOWS\SYSTEM\mfclz.exe
Removed! : C:\WINDOWS\SYSTEM\addrp32.exe
Removed! : C:\WINDOWS\SYSTEM\mfcxf32.exe
Removed! : C:\WINDOWS\SYSTEM\msmi32.exe
Removed! : C:\WINDOWS\SYSTEM\sysjo.exe
Removed! : C:\WINDOWS\SYSTEM\mfcgx.exe
Removed! : C:\WINDOWS\SYSTEM\ntbm.exe
Removed! : C:\WINDOWS\SYSTEM\javafr.exe
Removed! : C:\WINDOWS\SYSTEM\atlej.exe
Removed! : C:\WINDOWS\SYSTEM\mfcjp32.exe
Removed! : C:\WINDOWS\SYSTEM\netud32.exe
Removed! : C:\WINDOWS\SYSTEM\crkk.exe
Removed! : C:\WINDOWS\SYSTEM\netwb.exe
Removed! : C:\WINDOWS\SYSTEM\mfckc.exe
Removed! : C:\WINDOWS\SYSTEM\netlg.exe
Removed! : C:\WINDOWS\SYSTEM\msdc32.exe
Removed! : C:\WINDOWS\SYSTEM\iesj32.exe
Removed! : C:\WINDOWS\SYSTEM\ippu32.exe
Removed! : C:\WINDOWS\SYSTEM\ieol.exe
Removed! : C:\WINDOWS\SYSTEM\msfc.exe
Removed! : C:\WINDOWS\SYSTEM\winbs32.exe
Removed! : C:\WINDOWS\SYSTEM\iphn.exe
Removed! : C:\WINDOWS\SYSTEM\msvv32.exe
Removed! : C:\WINDOWS\SYSTEM\apivy32.exe
Removed! : C:\WINDOWS\SYSTEM\mfcjn.exe
Removed! : C:\WINDOWS\SYSTEM\javafz.exe
Removed! : C:\WINDOWS\SYSTEM\msvw.exe
Removed! : C:\WINDOWS\SYSTEM\mfcez.exe
Removed! : C:\WINDOWS\SYSTEM\ieyb32.exe
Removed! : C:\WINDOWS\SYSTEM\mijxh.dat
Removed! : C:\WINDOWS\SYSTEM\netvt32.exe
Removed! : C:\WINDOWS\SYSTEM\javagc.exe
Removed! : C:\WINDOWS\SYSTEM\cvudy.dat
Removed! : C:\WINDOWS\SYSTEM\rzoic.dat
Removed! : C:\WINDOWS\SYSTEM\qpyxi.dat
Removed! : C:\WINDOWS\SYSTEM\vkvwf.dat
Removed! : C:\WINDOWS\SYSTEM\yhvty.dat
Removed! : C:\WINDOWS\SYSTEM\xgnvn.dat
Removed! : C:\WINDOWS\SYSTEM\poaep.dat
Removed! : C:\WINDOWS\SYSTEM\enblw.dat
Removed! : C:\WINDOWS\SYSTEM\ivozl.dat
Removed! : C:\WINDOWS\SYSTEM\mrmcn.dat
Removed! : C:\WINDOWS\SYSTEM\tsmds.dat
Removed! : C:\WINDOWS\SYSTEM\gzizm.dat
Removed! : C:\WINDOWS\SYSTEM\zmvto.dat
Removed! : C:\WINDOWS\SYSTEM\asheq.dat
Removed! : C:\WINDOWS\SYSTEM\vbhph.dat
Removed! : C:\WINDOWS\SYSTEM\ipib.exe
Removed! : C:\WINDOWS\SYSTEM\rtqht.dat
Removed! : C:\WINDOWS\SYSTEM\ilrdv.dat
Removed! : C:\WINDOWS\SYSTEM\egvzc.dat
Removed! : C:\WINDOWS\SYSTEM\sumjk.dat
Removed! : C:\WINDOWS\SYSTEM\vkiib.dat
Removed! : C:\WINDOWS\SYSTEM\kvgik.dat
Removed! : C:\WINDOWS\SYSTEM\bowmi.dat
Removed! : C:\WINDOWS\SYSTEM\uzzxg.dat
Removed! : C:\WINDOWS\SYSTEM\ptwex.dat
Removed! : C:\WINDOWS\SYSTEM\nvxjg.dat
Removed! : C:\WINDOWS\SYSTEM\nawkx.dat
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!

-- Scan 2 --------
About:Buster Version 1.32
Error Removing! : C:\WINDOWS\wgiyis.dat
Removed! : C:\WINDOWS\ksqlab.dat
Removed! : C:\WINDOWS\ndfcpv.dat
Error Removing! : C:\WINDOWS\jqwfcu.dat
Error Removing! : C:\WINDOWS\lluehe.dat
Removed! : C:\WINDOWS\kwinco.dat
Removed! : C:\WINDOWS\tnlocy.dat
Error Removing! : C:\WINDOWS\wtohjl.dat
Removed! : C:\WINDOWS\bvhrxu.dat
Removed! : C:\WINDOWS\oezele.dat
Error Removing! : C:\WINDOWS\zmeosk.dat
Removed! : C:\WINDOWS\kzzceu.dat
Removed! : C:\WINDOWS\jodhuw.dat
Error Removing! : C:\WINDOWS\xqqira.dat
Removed! : C:\WINDOWS\tifabd.dat
Error Removing! : C:\WINDOWS\sycmct.dat
Error Removing! : C:\WINDOWS\clfaod.dat
Removed! : C:\WINDOWS\lysyxt.dat
Removed! : C:\WINDOWS\pdvgqh.dat
Removed! : C:\WINDOWS\phusqo.dat
Removed! : C:\WINDOWS\aovpwg.dat
Error Removing! : C:\WINDOWS\ihjxom.dat
Error Removing! : C:\WINDOWS\kxsrev.dat
Attempted Clean Of Temp folder.
Pages Reset... Done!


And, here's a new HJT Log. Just in case you wanted to see it.

Logfile of HijackThis v1.98.0
Scan saved at 11:42:29 AM, on 7/29/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\THE CLEANER\TCA.EXE
C:\PROGRAM FILES\THE CLEANER\TCM.EXE
C:\PROGRAM FILES\AMERICA ONLINE 8.0\AOL.EXE
C:\PROGRAM FILES\AMERICA ONLINE 8.0\WAOL.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\PROGRAM FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\btjss.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekstogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL (file missing)
O2 - BHO: EspIEObj Class - {2F4F8CC3-FF89-11D1-9F63-0020182D7E20} - C:\PROGRAM FILES\ESAFE\PROTECT\espie.dll (file missing)
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\SPEECH\DRAGON\WEB_IE.DLL (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL (file missing)
O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
O4 - HKLM\..\Run: [WinPatrol] "C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [tcactive] C:\PROGRAM FILES\THE CLEANER\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\PROGRAM FILES\THE CLEANER\tcm.exe
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2.0\BHODemon.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL
O12 - Plugin for .doc: C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\PLUGINS\NPDOC.DLL
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.c.../ymmapi_416.dll
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real...ArcadeRdxIE.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pog...n-ob-assets.cab
O16 - DPF: Fortune Bingo by pogo - http://superbingo.po...o-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://bingoe.pogo.c...e-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://peaks.pogo.co...s-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.po...s-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://popfu.pogo.co...u-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://greenback.pog...k-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://turbo12.pogo....1-ob-assets.cab
O16 - DPF: Tumble Bees by pogo - http://jumbee.pogo.c...e-ob-assets.cab
O16 - DPF: Dice Derby by pogo - http://checkeredflag...g-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://freecell.pogo...l-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo - http://sweet05.pogo....h-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://whomp.pogo.co...p-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://klondike.pogo...s-ob-assets.cab
O16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) - http://mirror.worldw...ared/dephlp.cab
O16 - DPF: First Class Solitaire by pogo - http://solitaire.pog...2-ob-assets.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://66.242.36.116...2/View22RTE.cab
O16 - DPF: Mah Jong Garden by pogo - http://mahjong2.pogo...g-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo....m-ob-assets.cab
O16 - DPF: Keno by pogo - http://keno.pogo.com...o-ob-assets.cab
O16 - DPF: Pirate's Gold by pogo - http://swashbucks07....d-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://showbiz.pogo....z-ob-assets.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://mirror.worldw...jo/wordmojo.cab
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homes...ive/HS_live.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.c...ropper1_2us.cab
O16 - DPF: Checkers by pogo - http://checkers.pogo...s-ob-assets.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://vbjack.pogo.c...k-ob-assets.cab
O16 - DPF: Top Down Baseball Challenge by pogo - http://topdown2.pogo...2-ob-assets.cab
O16 - DPF: Euchre by pogo - http://euchre.pogo.c...e-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://flinger.pogo....r-ob-assets.cab
O16 - DPF: Cribbage by pogo - http://crib.pogo.com...e-ob-assets.cab
O16 - DPF: Animal Ark by pogo - http://play05.pogo.c...l-ob-assets.cab
O16 - DPF: Ali Baba Slots TM by pogo - http://slots.pogo.co...a-ob-assets.cab
O16 - DPF: Showbiz Slots 2 by pogo - http://showbiz2.pogo...2-ob-assets.cab
O16 - DPF: SciFi Slots by pogo - http://scifi.pogo.co...i-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://roulet.pogo.c...e-ob-assets.cab
O16 - DPF: Perfect Passer by pogo - http://perfectpasser...r-ob-assets.cab
O16 - DPF: Spades by pogo - http://spades.pogo.c...s-ob-assets.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-cent...bin/actxcab.cab
O16 - DPF: Dominoes by pogo - http://domino.pogo.c...o-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://waterwheel.po...l-ob-assets.cab
O16 - DPF: Hearts by pogo - http://hearts.pogo.c...s-ob-assets.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net

Edited by Archie, 29 July 2004 - 09:48 AM.

  • 0

#30
admin

admin

    Founder Geek

  • Administrator
  • 24,504 posts
Better, but still there. Restart in safe mode, run About:Buster and Ad-ware. When finisehd, reboot and post a fresh log. <_<

Restarting in safe mode:
1. Start Windows, or if it is running, shut Windows down, and then turn off the computer.
2. Restart the computer. The computer begins processing a set of instructions known as the Basic Input/Output System (BIOS). What is displayed depends on the BIOS manufacturer. Some computers display a progress bar that refers to the word BIOS, while others may not display any indication that this process is happening.
3. As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard. Continue to do so until the Windows Advanced Options menu appears. 4. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
Using the arrow keys on the keyboard, scroll to and select the Safe mode menu item, and then press Enter.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP