I have a Windows ME OS. My machine has been attacked by spyware......My Internet explorer browser homepage has serach extender. i also have shopping wizard & home search assistant in the control panel. However cannot remove them from Ad remove programs. I have also tried running adaware-se programs but no luck so far. My machine has become quite slow. I have also installed Spybot serach & detsroy but it is taking very long to run through......
1.Pls...Pls.. help removing this spyware
2.& also suggest how I can avoiid getting spyware in my machine
3.what is the best firewall which i can install???
Many Thanks in advance!!
I have attached Hijackthis log file here...........
Logfile of HijackThis v1.99.1
Scan saved at 12:59:32 PM, on 6/5/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\SYSAH32.EXE
C:\WINDOWS\SYSTEM\MFCEZ.EXE
C:\WINDOWS\JAVAQZ.EXE
C:\WINDOWS\SYSTEM\MFCDT.EXE
C:\WINDOWS\SYSTEM\APPSC.EXE
C:\WINDOWS\SYSTEM\APIHM.EXE
C:\WINDOWS\SYSTEM\APPMV32.EXE
C:\WINDOWS\SYSTEM\CRCX.EXE
C:\WINDOWS\SYSFP.EXE
C:\WINDOWS\SYSTEM\NTGT.EXE
C:\WINDOWS\SYSTEM\MSKR.EXE
C:\WINDOWS\APIHK32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\WINDOWS\SYSTEM\MFCKB.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\APIRD32.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\JAVAUZ.EXE
C:\WINDOWS\SDKWW.EXE
C:\WINDOWS\SYSTEM\SDKJD32.EXE
C:\WINDOWS\ATLXG.EXE
C:\WINDOWS\SYSTEM\APPTN.EXE
C:\WINDOWS\APIPY32.EXE
C:\WINDOWS\SYSSQ.EXE
C:\WINDOWS\SYSTEM\MFCYU.EXE
C:\WINDOWS\ADDFV.EXE
C:\WINDOWS\SYSTEM\NTYV32.EXE
C:\WINDOWS\WINAF32.EXE
C:\WINDOWS\SYSTEM\MFCTO.EXE
C:\WINDOWS\SYSTEM\IPYA.EXE
C:\WINDOWS\APPXU.EXE
C:\WINDOWS\NETZU.EXE
C:\WINDOWS\CRYO.EXE
C:\WINDOWS\SYSTEM\APPSZ.EXE
C:\WINDOWS\SYSTEM\JAVAJF.EXE
C:\WINDOWS\SYSTEM\MFCGE.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\SYSTEM\IPDA.EXE
C:\WINDOWS\APIZU.EXE
C:\WINDOWS\SYSTEM\JAVAFX.EXE
C:\WINDOWS\SYSTEM\APIZB32.EXE
C:\WINDOWS\JAVAFN32.EXE
C:\WINDOWS\CRPW.EXE
C:\WINDOWS\APIZG32.EXE
C:\WINDOWS\NTLC.EXE
C:\WINDOWS\SYSTEM\NETOE.EXE
C:\WINDOWS\SYSTEM\NETBD32.EXE
C:\WINDOWS\SYSTEM\NETNL.EXE
C:\WINDOWS\APPDK32.EXE
C:\WINDOWS\SYSTEM\JAVAXF.EXE
C:\WINDOWS\SDKHB32.EXE
C:\WINDOWS\MSMD32.EXE
C:\WINDOWS\SYSTEM\MSSP.EXE
C:\WINDOWS\SYSTEM\IPHM.EXE
C:\WINDOWS\SYSTEM\IPUO32.EXE
C:\WINDOWS\ATLHY.EXE
C:\WINDOWS\CRBD.EXE
C:\WINDOWS\CRXI.EXE
C:\WINDOWS\CRVY.EXE
C:\WINDOWS\SYSTEM\IPDA32.EXE
C:\WINDOWS\SYSTEM\NETSH32.EXE
C:\WINDOWS\SYSTEM\D3LJ32.EXE
C:\WINDOWS\ADDQH32.EXE
C:\WINDOWS\APPQR.EXE
C:\WINDOWS\MFCOT.EXE
C:\WINDOWS\SYSTEM\MFCLK.EXE
C:\WINDOWS\SYSTEM\ADDZI32.EXE
C:\WINDOWS\SYSTEM\SYSBB32.EXE
C:\WINDOWS\SYSTEM\ADDOX.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\MFCRA32.EXE
C:\WINDOWS\WINQM.EXE
C:\WINDOWS\APPNS32.EXE
C:\WINDOWS\D3JE32.EXE
C:\WINDOWS\SYSTEM\MSEH.EXE
C:\WINDOWS\SYSTEM\IEMN32.EXE
C:\WINDOWS\SYSTEM\IPKO.EXE
C:\WINDOWS\MFCWN.EXE
C:\WINDOWS\MFCRF32.EXE
C:\WINDOWS\JAVACV32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\MFCKD32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\MFCEZ.EXE
C:\WINDOWS\MFCWN.EXE
C:\WINDOWS\JAVACV32.EXE
C:\WINDOWS\CRVY.EXE
C:\WINDOWS\CRVY.EXE
C:\WINDOWS\WINLY32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\CRVY.EXE
C:\WINDOWS\CRVY.EXE
C:\WINDOWS\JAVANG32.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vopin.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vopin.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vopin.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vopin.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vopin.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vopin.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vopin.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {A1A5FDC6-2A40-1A25-7BB6-11463E35B30F} - C:\WINDOWS\SYSTEM\APIFP32.DLL
O2 - BHO: Class - {7572E089-B1FF-8266-C5C3-33B8232C7FF7} - C:\WINDOWS\ATLTU32.DLL
O2 - BHO: Class - {388C35E4-4B37-F24C-BB6E-80FD25B9D6EA} - C:\WINDOWS\SYSTEM\IEFF.DLL
O2 - BHO: Class - {6AA092A7-509F-0125-3521-4319AB07EE2B} - C:\WINDOWS\SYSTEM\D3AS.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN1\YCOMP5_6_2_0.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [MFCKD32.EXE] C:\WINDOWS\MFCKD32.EXE
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [SYSAH32.EXE] C:\WINDOWS\SYSTEM\SYSAH32.EXE /s
O4 - HKLM\..\RunServices: [MFCEZ.EXE] C:\WINDOWS\SYSTEM\MFCEZ.EXE /s
O4 - HKLM\..\RunServices: [JAVAQZ.EXE] C:\WINDOWS\JAVAQZ.EXE /s
O4 - HKLM\..\RunServices: [MFCDT.EXE] C:\WINDOWS\SYSTEM\MFCDT.EXE /s
O4 - HKLM\..\RunServices: [APPSC.EXE] C:\WINDOWS\SYSTEM\APPSC.EXE /s
O4 - HKLM\..\RunServices: [APIHM.EXE] C:\WINDOWS\SYSTEM\APIHM.EXE /s
O4 - HKLM\..\RunServices: [APPMV32.EXE] C:\WINDOWS\SYSTEM\APPMV32.EXE /s
O4 - HKLM\..\RunServices: [CRCX.EXE] C:\WINDOWS\SYSTEM\CRCX.EXE /s
O4 - HKLM\..\RunServices: [SYSFP.EXE] C:\WINDOWS\SYSFP.EXE /s
O4 - HKLM\..\RunServices: [NTGT.EXE] C:\WINDOWS\SYSTEM\NTGT.EXE /s
O4 - HKLM\..\RunServices: [MSKR.EXE] C:\WINDOWS\SYSTEM\MSKR.EXE /s
O4 - HKLM\..\RunServices: [APIHK32.EXE] C:\WINDOWS\APIHK32.EXE /s
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [MFCKB.EXE] C:\WINDOWS\SYSTEM\MFCKB.EXE /s
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKLM\..\RunServices: [APIRD32.EXE] C:\WINDOWS\APIRD32.EXE /s
O4 - HKLM\..\RunServices: [JAVAUZ.EXE] C:\WINDOWS\JAVAUZ.EXE /s
O4 - HKLM\..\RunServices: [SDKWW.EXE] C:\WINDOWS\SDKWW.EXE /s
O4 - HKLM\..\RunServices: [SDKJD32.EXE] C:\WINDOWS\SYSTEM\SDKJD32.EXE /s
O4 - HKLM\..\RunServices: [ATLXG.EXE] C:\WINDOWS\ATLXG.EXE /s
O4 - HKLM\..\RunServices: [APPTN.EXE] C:\WINDOWS\SYSTEM\APPTN.EXE /s
O4 - HKLM\..\RunServices: [APIPY32.EXE] C:\WINDOWS\APIPY32.EXE /s
O4 - HKLM\..\RunServices: [SYSSQ.EXE] C:\WINDOWS\SYSSQ.EXE /s
O4 - HKLM\..\RunServices: [MFCYU.EXE] C:\WINDOWS\SYSTEM\MFCYU.EXE /s
O4 - HKLM\..\RunServices: [ADDFV.EXE] C:\WINDOWS\ADDFV.EXE /s
O4 - HKLM\..\RunServices: [NTYV32.EXE] C:\WINDOWS\SYSTEM\NTYV32.EXE /s
O4 - HKLM\..\RunServices: [WINAF32.EXE] C:\WINDOWS\WINAF32.EXE /s
O4 - HKLM\..\RunServices: [MFCTO.EXE] C:\WINDOWS\SYSTEM\MFCTO.EXE /s
O4 - HKLM\..\RunServices: [IPYA.EXE] C:\WINDOWS\SYSTEM\IPYA.EXE /s
O4 - HKLM\..\RunServices: [APPXU.EXE] C:\WINDOWS\APPXU.EXE /s
O4 - HKLM\..\RunServices: [NETZU.EXE] C:\WINDOWS\NETZU.EXE /s
O4 - HKLM\..\RunServices: [CRYO.EXE] C:\WINDOWS\CRYO.EXE /s
O4 - HKLM\..\RunServices: [APPSZ.EXE] C:\WINDOWS\SYSTEM\APPSZ.EXE /s
O4 - HKLM\..\RunServices: [JAVAJF.EXE] C:\WINDOWS\SYSTEM\JAVAJF.EXE /s
O4 - HKLM\..\RunServices: [MFCGE.EXE] C:\WINDOWS\SYSTEM\MFCGE.EXE /s
O4 - HKLM\..\RunServices: [IPDA.EXE] C:\WINDOWS\SYSTEM\IPDA.EXE /s
O4 - HKLM\..\RunServices: [APIZU.EXE] C:\WINDOWS\APIZU.EXE /s
O4 - HKLM\..\RunServices: [JAVAFX.EXE] C:\WINDOWS\SYSTEM\JAVAFX.EXE /s
O4 - HKLM\..\RunServices: [APIZB32.EXE] C:\WINDOWS\SYSTEM\APIZB32.EXE /s
O4 - HKLM\..\RunServices: [JAVAFN32.EXE] C:\WINDOWS\JAVAFN32.EXE /s
O4 - HKLM\..\RunServices: [CRPW.EXE] C:\WINDOWS\CRPW.EXE /s
O4 - HKLM\..\RunServices: [APIZG32.EXE] C:\WINDOWS\APIZG32.EXE /s
O4 - HKLM\..\RunServices: [NTLC.EXE] C:\WINDOWS\NTLC.EXE /s
O4 - HKLM\..\RunServices: [NETOE.EXE] C:\WINDOWS\SYSTEM\NETOE.EXE /s
O4 - HKLM\..\RunServices: [NETBD32.EXE] C:\WINDOWS\SYSTEM\NETBD32.EXE /s
O4 - HKLM\..\RunServices: [NETNL.EXE] C:\WINDOWS\SYSTEM\NETNL.EXE /s
O4 - HKLM\..\RunServices: [APPDK32.EXE] C:\WINDOWS\APPDK32.EXE /s
O4 - HKLM\..\RunServices: [JAVAXF.EXE] C:\WINDOWS\SYSTEM\JAVAXF.EXE /s
O4 - HKLM\..\RunServices: [SDKHB32.EXE] C:\WINDOWS\SDKHB32.EXE /s
O4 - HKLM\..\RunServices: [MSMD32.EXE] C:\WINDOWS\MSMD32.EXE /s
O4 - HKLM\..\RunServices: [MSSP.EXE] C:\WINDOWS\SYSTEM\MSSP.EXE /s
O4 - HKLM\..\RunServices: [IPHM.EXE] C:\WINDOWS\SYSTEM\IPHM.EXE /s
O4 - HKLM\..\RunServices: [IPUO32.EXE] C:\WINDOWS\SYSTEM\IPUO32.EXE /s
O4 - HKLM\..\RunServices: [ATLHY.EXE] C:\WINDOWS\ATLHY.EXE /s
O4 - HKLM\..\RunServices: [CRBD.EXE] C:\WINDOWS\CRBD.EXE /s
O4 - HKLM\..\RunServices: [CRXI.EXE] C:\WINDOWS\CRXI.EXE /s
O4 - HKLM\..\RunServices: [CRVY.EXE] C:\WINDOWS\CRVY.EXE /s
O4 - HKLM\..\RunServices: [IPDA32.EXE] C:\WINDOWS\SYSTEM\IPDA32.EXE /s
O4 - HKLM\..\RunServices: [NETSH32.EXE] C:\WINDOWS\SYSTEM\NETSH32.EXE /s
O4 - HKLM\..\RunServices: [D3LJ32.EXE] C:\WINDOWS\SYSTEM\D3LJ32.EXE /s
O4 - HKLM\..\RunServices: [ADDQH32.EXE] C:\WINDOWS\ADDQH32.EXE /s
O4 - HKLM\..\RunServices: [APPQR.EXE] C:\WINDOWS\APPQR.EXE /s
O4 - HKLM\..\RunServices: [MFCOT.EXE] C:\WINDOWS\MFCOT.EXE /s
O4 - HKLM\..\RunServices: [MFCLK.EXE] C:\WINDOWS\SYSTEM\MFCLK.EXE /s
O4 - HKLM\..\RunServices: [ADDZI32.EXE] C:\WINDOWS\SYSTEM\ADDZI32.EXE /s
O4 - HKLM\..\RunServices: [SYSBB32.EXE] C:\WINDOWS\SYSTEM\SYSBB32.EXE /s
O4 - HKLM\..\RunServices: [ADDOX.EXE] C:\WINDOWS\SYSTEM\ADDOX.EXE /s
O4 - HKLM\..\RunServices: [MFCRA32.EXE] C:\WINDOWS\SYSTEM\MFCRA32.EXE /s
O4 - HKLM\..\RunServices: [WINQM.EXE] C:\WINDOWS\WINQM.EXE /s
O4 - HKLM\..\RunServices: [APPNS32.EXE] C:\WINDOWS\APPNS32.EXE /s
O4 - HKLM\..\RunServices: [D3JE32.EXE] C:\WINDOWS\D3JE32.EXE /s
O4 - HKLM\..\RunServices: [MSEH.EXE] C:\WINDOWS\SYSTEM\MSEH.EXE /s
O4 - HKLM\..\RunServices: [IEMN32.EXE] C:\WINDOWS\SYSTEM\IEMN32.EXE /s
O4 - HKLM\..\RunServices: [IPKO.EXE] C:\WINDOWS\SYSTEM\IPKO.EXE /s
O4 - HKLM\..\RunServices: [MFCWN.EXE] C:\WINDOWS\MFCWN.EXE /s
O4 - HKLM\..\RunServices: [MFCRF32.EXE] C:\WINDOWS\MFCRF32.EXE /s
O4 - HKLM\..\RunServices: [JAVACV32.EXE] C:\WINDOWS\JAVACV32.EXE /s
O4 - HKLM\..\RunServices: [WINLY32.EXE] C:\WINDOWS\WINLY32.EXE /s
O4 - HKLM\..\RunServices: [JAVANG32.EXE] C:\WINDOWS\JAVANG32.EXE /s
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: IncrediBar - {023FA804-DCE1-4817-94ED-6BA4200F9AF2} - C:\PROGRAM FILES\INCREDIBAR\BIN\IBTOOLBAR.DLL (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AOL DOWNLOADS\AIM.EXE
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra button: Microsoft AntiSpyware helper - {30E16E43-4DA2-4D2E-BFDA-F84911F3BB21} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {30E16E43-4DA2-4D2E-BFDA-F84911F3BB21} - (no file) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.adorons.com
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.6.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,23/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...484/mcfscan.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
Edited by ppt, 06 June 2005 - 09:41 AM.