• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
    • Budfred

      PLEASE READ - Reversing upgrade   02/23/2017

      We have found that this new upgrade is somewhat of a disaster.  We are finding lots of glitches in being able to post and administer the forum.  Additionally, there are new costs associated with the upgrade that we simply cannot afford.  As a result, we have decided to reverse course and go back to the previous version of our software.  Since this will involve restoring it from a backup, we will lose posts that have been added since January 30 or possibly even some before that.    If you started a topic during that time, we urge you to make backups of your posts and you will need to start the topics over again after the change.  You can simply paste the copies of your posts that you created at that point.    If you joined the forum this month, you will need to re-register since your membership will be lost along with the posts.  Since you have a concealed password, we cannot simply restore your membership for you.   We are going to backup as much as we can so that it will reduce inconvenience for our members.  Unfortunately we cannot back everything up since much will be incompatible with the old version of our software.  We apologize for the confusion and regret the need to do this even though it is not viable to continue with this version of the software.   We plan to begin the process tomorrow evening and, if it goes smoothly, we shouldn't be offline for very long.  However, since we have not done this before, we are not sure how smoothly it will go.  We ask your patience as we proceed.   EDIT: I have asked our hosting service to do the restore at 9 PM Central time and it looks like it will go forward at that time.  Please prepare whatever you need to prepare so that we can restore your topics when the forum is stable again.
Sign in to follow this  
Followers 0
momofsixgirls

hijacked by "your-searcher.com/index.htm"

13 posts in this topic

Help, I have been hijacked. My home page continually goes to "your-searcher.com/index.htm". I have updated Hijack This, Ad Aware, Spybot, and CW Shredder and run them all. Although they "fixed" a few things, my home page still goes to "your-searcher.com". The last time this happened, I had to boot up in the 'safe mode' to fix it, but I don't remember how to do this.

 

Following is my hijack log

 

Logfile of HijackThis v1.98.0

Scan saved at 9:09:35 PM, on 7/9/2004

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

C:\WINDOWS\System32\hphmon03.exe

C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlgn.exe

C:\Program Files\Palm\HOTSYNC.EXE

C:\WINDOWS\System32\HPHipm09.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Outlook Express\msimn.exe

C:\Documents and Settings\Mom\Local Settings\Temp\Temporary Directory 7 for hijackthis.zip\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://your-searcher.com/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://your-searcher.com/index.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://your-searcher.com/index.htm

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.keyboardmall.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://your-searcher.com/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://your-searcher.com/index.htm

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: ie - {2FF5573C-0EB5-43db-A1B2-C4326813468E} - c:\windows\iehr.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe

O4 - HKLM\..\Run: [inetCntrl] C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

O4 - HKCU\..\Run: [cvchost] c:\windows\svchost.exe

O4 - Startup: Billminder.lnk = C:\QUICKENW\billmind.exe

O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE

O4 - Global Startup: winlgn.exe

O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.keyboardmall.com

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...ol_v1-0-3-9.cab

O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{1E115E48-D468-4F65-9DF2-ADBA2B21EBCA}: NameServer = 209.165.193.5 216.103.190.235

Share this post


Link to post
Share on other sites

I don't know a whole lot but ad-aware has a new update that has found some insidious little things on my system - grab the update and deep scan your registry.

Share this post


Link to post
Share on other sites

Hi there,

 

 

I suggest you proceed as follows:

Download the latest version of CWShredder Here by Merijn Bellekom, the creator of Hijack This. Check for updates!!

Run it, press 'Fix', and allow it to fix all it finds.

 

 

Next;

 

I strongly recommend this,

 

You also need to Update Windows and InternetExplorer, to get all the Latest Security Patches that Protects Your Computer.

 

This can be accessed by going Here and following the prompts.

 

 

When you have done that run HijackThis again and repost a fresh logfile.

Share this post


Link to post
Share on other sites

Thanks 12g,

 

Okay - (I must not have gotten the latest version of CW afterall before) It did take care of the hijacker & the favorites that had been added. But now - now my homepage goes to about:blank and I can't change that from tools.

 

I am running from dial up and have tried running those security updates before. It takes like 10 hours and usually gets knocked off in the process. Is there a way around this step? Can I get the updates on CD or do I have to buy a whole new Windows system?

 

Anyway, Here's my new log without running the windows updates.

 

Logfile of HijackThis v1.97.7

Scan saved at 8:50:19 AM, on 7/10/2004

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

C:\WINDOWS\System32\hphmon03.exe

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlgn.exe

C:\Program Files\Palm\HOTSYNC.EXE

C:\WINDOWS\System32\HPHipm09.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\Mom\Local Settings\Temp\Temporary Directory 9 for hijackthis.zip\HijackThis.exe

 

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [inetCntrl] C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

O4 - HKCU\..\Run: [cvchost] c:\windows\svchost.exe

O4 - Startup: Billminder.lnk = C:\QUICKENW\billmind.exe

O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE

O4 - Global Startup: winlgn.exe

O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.keyboardmall.com

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...ol_v1-0-3-9.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSCon

Share this post


Link to post
Share on other sites

Hi there,

 

Please do this,

 

You are running hijackthis out of a temporary directory. Can you please create a folder in My Documents and call it Hijack (or something similar) like this C:\My Documents\hjt\HijackThis. Then extract hijackthis into the folder you have created and run it from there. The reason for this is that Hijackthis cannot create the backup files that you may need whilst it is being run from a temporary folder

 

When you have done this, then make sure all browsers and windows are closed except for hijackthis and put a check against the following and click 'fix checked';

 

Please read carefully

 

 

O4 - HKCU\..\Run: [cvchost] c:\windows\svchost.exe

 

O14 - IERESET.INF: START_PAGE_URL=http://www.keyboardmall.com<<<<if you set this, or know about it leave it. If not fix check it.

 

 

 

 

 

Restart your computer in

Safe Mode Also make sure you show hidden files Then delete the following files or folders as indicated below if they still show:

 

This may not still show,

 

 

c:\windows\svchost.exe<<<<File Be careful if removing this file, only remove this one

 

(ie C:\WINDOWS\system32\svchost.exe<<<<NOT THIS ONE!)

 

 

Reboot, then post a fresh logfile so that I can check to see if it is clean.

Share this post


Link to post
Share on other sites

Okay 12g,

 

I followed your instructions. fixed the 04-HKCU. I think the keyboardmall is something having to do with the buttons at the top of my keyboard so I left it there.

 

In safe mode, I looked for the c:\windows\svchost.exe file. The one I found read "svchost" with no extension. Is this the one I should be deleting?

 

By this way, on this reboot, all the "your-searcher.com" stuff is back on my homepage!!! and bad favorites readded. Something I forgot to mention. Everytime I shut the computer down, a message comes up "Ending program Win Min". Then it says "program not responding". I press the End Now button and the computer shuts down. Is this important?

 

Here's the log. I did not delete files yet.

 

Logfile of HijackThis v1.98.0

Scan saved at 10:08:40 AM, on 7/10/2004

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

C:\WINDOWS\System32\hphmon03.exe

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlgn.exe

C:\Program Files\Palm\HOTSYNC.EXE

C:\WINDOWS\System32\HPHipm09.exe

C:\Documents and Settings\Mom\My Documents\hjt\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://your-searcher.com/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://your-searcher.com/index.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://your-searcher.com/index.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://your-searcher.com/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://your-searcher.com/index.htm

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [inetCntrl] C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

O4 - Startup: Billminder.lnk = C:\QUICKENW\billmind.exe

O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE

O4 - Global Startup: winlgn.exe

O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.keyboardmall.com

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...ol_v1-0-3-9.cab

O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab

Share this post


Link to post
Share on other sites

Hi there,

 

Make sure all browsers and windows are closed except for hijackthis and put a check against the following and click 'fix checked';

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://your-searcher.com/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://your-searcher.com/index.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://your-searcher.com/index.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://your-searcher.com/sp.htm

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://your-searcher.com/index.htm

 

O4 - Global Startup: winlgn.exe

 

Restart your computer inSafe Mode Also make sure you show hidden files Then delete the following files or folders as indicated below:

 

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\winlgn.exe<<<<File

 

Reboot, then post afresh log so I can check to see if it is clean.

Share this post


Link to post
Share on other sites

12g (my savior!)

 

Okay, I fixed the R1 & R0's that you said. Then deleted the suspect file in safe mode. When I rebooted, the "your-searcher" was still taking over my homepage. I ran CWshredder again. Reset my homepage (cruzers.com) and rebooted. Things seem to be fine now. No more Win Min on shutdown either. Here is my final (I hope) log. Thanks so much for all of your help. You guys provide a great service! I will attempt to get all of those security updates that you mentioned over the next few weeks. I'll check back to see if you've given me the "all clear"

 

Logfile of HijackThis v1.98.0

Scan saved at 9:01:52 PM, on 7/10/2004

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

C:\WINDOWS\System32\hphmon03.exe

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Palm\HOTSYNC.EXE

C:\WINDOWS\System32\HPHipm09.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\Mom\My Documents\hjt\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cruzers.com/

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [inetCntrl] C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

O4 - Startup: Billminder.lnk = C:\QUICKENW\billmind.exe

O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE

O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.keyboardmall.com

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...ol_v1-0-3-9.cab

O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab

Share this post


Link to post
Share on other sites

By the way, 12g

 

I did not delete the C:\windows\svchost file. (See your post 7/10 11:43am) I asked if I was supposed to see the .exe when I looked at the file but you didn't answer. I assume that I don't see the .exe looking at the file in a window. Should I delete that still?

 

back at ya,

momofsixgirls

Share this post


Link to post
Share on other sites

Hi there.

 

Yes the news is good!! your log is clean. For the file that needs deleting, it must be this file path c:\windows\svchost.exe, if it has no extension, but it is indeed that path, then delete it. Please be careful. For your updates, I can understand the situation with dialup, what I would advise is to select a manageable amount each day, or whenever you can be online, you will soon catch up.

 

To provide future protection - I would advise you to download and install:

 

SpywareBlaster will block bad ActiveX and malevolent cookies. Download from Here

 

IE-SPYAD puts over 4000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. Download

Here

Both are very small free programs that you run once, and then just weekly to check for updates.

 

And also see

So how did I get infected in the first place?

Share this post


Link to post
Share on other sites

Okay 12G, thanks much. I've deleted that file svchost in the windows directory. I was very careful!. thanks. This is my final log. I appreciate your help.

 

 

 

Logfile of HijackThis v1.98.0

Scan saved at 9:12:48 AM, on 7/11/2004

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

C:\WINDOWS\System32\hphmon03.exe

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Palm\HOTSYNC.EXE

C:\WINDOWS\System32\HPHipm09.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\ntvdm.exe

C:\Documents and Settings\Mom\My Documents\hjt\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cruzers.com/

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [inetCntrl] C:\WINDOWS\System32\InetCntrl\InetCntrl.exe

O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msmc.exe

O4 - Startup: Billminder.lnk = C:\QUICKENW\billmind.exe

O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE

O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.keyboardmall.com

O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...ol_v1-0-3-9.cab

O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{1E115E48-D468-4F65-9DF2-ADBA2B21EBCA}: NameServer = 209.165.193.5 216.103.190.235

Share this post


Link to post
Share on other sites

You are very welcome, all is well :wave:

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0