• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0

What the $#@* is this?

4 posts in this topic

Everytime I use the interent I get some words underlined in green. I can't get rid of it. Here's my log, what do I get rid of?


Logfile of HijackThis v1.97.7

Scan saved at 11:50:43 AM, on 5/21/2004

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


Running processes:







C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe







C:\Program Files\TightVNC\WinVNC.exe



C:\Program Files\Network Associates\VirusScan\VsStat.exe

C:\Program Files\Network Associates\VirusScan\Vshwin32.exe

C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe

C:\Program Files\Network Associates\VirusScan\Webscanx.exe

C:\Program Files\Network Associates\VirusScan\Avconsol.exe

C:\Program Files\Citrix\ICA Client\ssonsvr.exe


C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe



C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\r.barron\Local Settings\Temporary Internet Files\Content.IE5\WHQFOHIJ\HijackThis[1].exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C:\WINNT\system32\mskhhe.dll

O2 - BHO: (no name) - {0BA1C6EB-D062-4E37-9DB5-B07743276324} - (no file)

O2 - BHO: (no name) - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C:\WINNT\system32\msibkd.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {94927A13-4AAA-476A-989D-392456427688} - C:\WINNT\system32\msjfbl.dll

O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:\WINNT\dealhlpr.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

O3 - Toolbar: Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:\WINNT\dealhlpr.dll

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot

O4 - HKLM\..\Run: [ijwzkdgn] C:\WINNT\ijwzkdgn.exe

O4 - HKLM\..\Run: [DealHelperUpdate] C:\WINNT\DHUpdt.exe

O4 - HKLM\..\Run: [DealHelperBrwsr] C:\WINNT\dhbrwsr.exe

O4 - HKCU\..\Run: [msmc] C:\WINNT\system32\msgked.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Willow Road Screen Saver.lnk = C:\Program Files\WillowRD\WillowRd.exe

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {0006F063-0000-0000-C000-000000000046} (Microsoft Outlook View Control) - http://mail.citrix.utah.edu/AntiSpamGatewa...bs/outlctlx.cab

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab

O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://i.a.cnn.net/cnn/resources/cult3d/cult.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212...meInstaller.exe

O16 - DPF: {42780420-E62F-490A-82FC-D626BE90B302} (ASAP! Session Class) - http://mail.citrix.utah.edu/AntiSpamGateway/Cabs/Mapicom.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...37875.342962963

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.companion....ebio5_1_6_0.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = citrix.utah.edu

O17 - HKLM\System\CCS\Services\Tcpip\..\{33CD517A-5C99-4448-A752-2A9D76481621}: Domain = citrix.utah.edu

O17 - HKLM\System\CCS\Services\Tcpip\..\{33CD517A-5C99-4448-A752-2A9D76481621}: NameServer =,

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = citrix.utah.edu

O17 - HKLM\System\CS1\Services\Tcpip\..\{33CD517A-5C99-4448-A752-2A9D76481621}: Domain = citrix.utah.edu

O17 - HKLM\System\CS1\Services\Tcpip\..\{33CD517A-5C99-4448-A752-2A9D76481621}: NameServer =,

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = citrix.utah.edu

O17 - HKLM\System\CS2\Services\Tcpip\..\{33CD517A-5C99-4448-A752-2A9D76481621}: Domain = citrix.utah.edu

O17 - HKLM\System\CS2\Services\Tcpip\..\{33CD517A-5C99-4448-A752-2A9D76481621}: NameServer =,



Share this post

Link to post
Share on other sites

Hi there.


I'm looking over your log to see what needs to be done next. I'll be back in a bit.


-- LB

Share this post

Link to post
Share on other sites

I'm back.


First off, make a new folder/directory called C:\HJT and move HijackThis to it. Running HijackThis directly from the zip file is not a good idea as it won't be able to make backups of removed stuff.


Next, download and install both Spybot S&D and Ad-Aware. Update both of them before doing any scans. After updating, run them (but not at the same time).


Reboot and post a new log.


-- LB

Share this post

Link to post
Share on other sites

If you need this topic reopened, please request this by sending the moderating team an email with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

Share this post

Link to post
Share on other sites
This topic is now closed to further replies.
Sign in to follow this  
Followers 0