Jump to content


Photo

trojan hunting


  • Please log in to reply
1 reply to this topic

#1 mstqdll

mstqdll

    Member

  • New Member
  • Pip
  • 4 posts

Posted 12 July 2004 - 10:21 PM

Ladies and gents,

I have been struggling with a trojan for a week now and will soon go crazy...

I have done the following:

a. disabled system restore
b. run EZ Anti-Virus, McAffee, No-Adware, Ad Aware, and Spy-Bot
c. Everytime I run Hi-Jack I find a bunch of suspicious files and "fix" them, but everytime I reboot, they are back

Note:
- I still have access to Internet options, but all of my changes are erased after they are applied
- I am now having problems with "free memory" and frequently cannot run applications
- as expected explorer is having a lot of problems and frequently not responding
- I am also having problems scanning the hard drive when I restart


any help would be greatly appreciated

Logfile of HijackThis v1.97.7
Scan saved at 10:13:37 PM, on 7/13/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\CROY32.EXE
C:\WINDOWS\SYSTEM\MSJT32.EXE
C:\WINDOWS\SYSTEM\ATLYB.EXE
C:\WINDOWS\SDKVI.EXE
C:\WINDOWS\SYSTEM\D3BM32.EXE
C:\WINDOWS\APPER32.EXE
C:\WINDOWS\SYSTEM\SYSST32.EXE
C:\WINDOWS\SYSTEM\D3NF.EXE
C:\WINDOWS\SYSKX32.EXE
C:\WINDOWS\SYSUU32.EXE
C:\WINDOWS\JAVAQV32.EXE
C:\WINDOWS\SYSTEM\IPWN.EXE
C:\WINDOWS\IENF32.EXE
C:\WINDOWS\ATLDC.EXE
C:\WINDOWS\APPHH.EXE
C:\WINDOWS\SYSTEM\SDKKR.EXE
C:\WINDOWS\JAVAXN.EXE
C:\WINDOWS\SYSTEM\ATLTN32.EXE
C:\WINDOWS\D3LV.EXE
C:\WINDOWS\SYSTEM\SYSVN.EXE
C:\WINDOWS\SYSTEM\ADDFB32.EXE
C:\WINDOWS\SYSTEM\NTWQ.EXE
C:\WINDOWS\IEIW32.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\MFCHQ32.EXE
C:\WINDOWS\JAVAOG.EXE
C:\WINDOWS\SYSTEM\NTVO.EXE
C:\WINDOWS\SYSTEM\MFCXG32.EXE
C:\WINDOWS\SYSTEM\JAVATW.EXE
C:\WINDOWS\APIGB32.EXE
C:\WINDOWS\SYSTEM\MSJL.EXE
C:\WINDOWS\SDKAN.EXE
C:\WINDOWS\APIQZ32.EXE
C:\WINDOWS\ATLFH32.EXE
C:\WINDOWS\SYSTEM\D3NX32.EXE
C:\WINDOWS\MSIE.EXE
C:\WINDOWS\SYSTEM\APPYT32.EXE
C:\WINDOWS\IPUB.EXE
C:\WINDOWS\IEEZ.EXE
C:\WINDOWS\SYSTEM\APPLI.EXE
C:\WINDOWS\NTWW.EXE
C:\WINDOWS\IELL32.EXE
C:\WINDOWS\SYSTEM\SYSJZ.EXE
C:\WINDOWS\NETKA.EXE
C:\WINDOWS\SYSTEM\D3NX32.EXE
C:\WINDOWS\IPRZ.EXE
C:\WINDOWS\SYSTEM\CRUV.EXE
C:\WINDOWS\SYSTEM\JAVAPA.EXE
C:\WINDOWS\WINNS32.EXE
C:\WINDOWS\ADDWB32.EXE
C:\WINDOWS\SYSTEM\ATLDZ32.EXE
C:\WINDOWS\SYSTEM\NTSX32.EXE
C:\WINDOWS\CROY32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\WINDOWS\SYSTEM\PRPCUI.EXE
C:\WINDOWS\DOCKAPP.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
C:\PROGRAM FILES\LEXMARKX83\ACBTNMGR_X83.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\IPOD\BIN\IPODWATCHER.EXE
C:\PROGRAM FILES\SEALEDMEDIA\SEALMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETTRAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\PLAXO\1.5.2.32\INSTALLSTUB.EXE
C:\PROGRAM FILES\AIM95\AIM.EXE
C:\PROGRAM FILES\NETGEAR\NETGEAR MA521 ADAPTER\WLANCFG5.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSFTSN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\ltgni.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ltgni.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ltgni.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\ltgni.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ltgni.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\ltgni.dll/sp.html#96676
O2 - BHO: (no name) - {DA371525-4626-36A2-15C2-D8474FA5DA8B} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {19838521-6F1A-4B77-A2F7-65C4CEEC94E4} - (no file)
O2 - BHO: (no name) - {A8DDA2EF-C0A5-40AD-B982-B12C116683EE} - C:\WINDOWS\SYSTEM\MECLLM.DLL (file missing)
O2 - BHO: (no name) - {16FA13A1-A8C6-9C47-B99D-2881BA92901E} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {7FF53652-4DA9-7C18-869B-8B90C486CE63} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {9E70277B-6E0B-7FD1-138B-C1671DEFEC09} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {A73797CD-E0F1-C0D9-A6E0-F4ABA6989E8C} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {5A18C97F-F036-B472-8456-D11930DEFBCC} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {ED1F5282-911E-42DA-1F46-77D9E687ADD5} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {3D2849B4-F0D7-1964-E9E0-9065FD249B70} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {83BA9DA4-0586-D81B-E278-F991D0FD61F9} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {BCC38BFC-3D9C-BDCC-4305-1EA0A650C22E} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {DD4B0AF4-235C-1E71-5AE7-979D57465592} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {772CDCDE-0283-D7B5-4A6F-907238D010E3} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {D9FC7D98-66CD-545B-9BFA-5E8984264861} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {EDD4C014-5E70-B6DC-DF81-83233ADC8CB9} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {05E8A3C9-3C64-5EFA-7AAD-7376B28A77F2} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {8741C95A-0FA5-9070-1707-8C63F241D0FE} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {B094EB67-08A6-ADCB-95BB-E3A52338BD44} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {E2CEC674-D1DB-0B3E-6227-7FF265402CAD} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {7071833F-C7CE-DEAE-D543-263FDD1029C0} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {DF37B291-5A31-C9AF-0402-FF497AB5396D} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {C34102CE-6CAF-795E-0E08-3B7627D81F73} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {F394EE63-7C6B-74EF-DB2D-005AC17AF1A3} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {E3367314-1EAE-8F76-CB90-062589DB57E1} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {60DA8036-014A-F21B-D3DA-255CE37683BE} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {0B035E8B-102E-BB31-92AC-144D3DEF24F7} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {098979FC-F6C4-46EC-8A39-3881C4292F10} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {2872E36A-D072-3C6B-0DB0-E93738A6BD69} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {99A71F4B-56B1-EF4A-1FA4-F6A97BB4A9AB} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {80DC868D-2E47-15E2-D4A5-86D3D9AC3987} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {40D7AC6D-9124-CC43-7426-5CD773A0E5E8} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {6B33C2CE-9ABF-CB95-A0D4-C48508827DB6} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {FD544E09-6101-6F75-D278-BEE3BE29FC80} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {3F7618C3-2D3C-827A-E141-B1FB429CC6B2} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {3F6F675E-A4AA-3145-CC43-55B763DBD482} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {C7127238-26C9-795D-5FBE-007A94C0FBA9} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {89B61EC3-C2FA-0FBE-52D6-760CB819A0EC} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {3E7DB320-7E09-59EF-EBB8-1F9DD474D568} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {F6D3608B-22CD-C122-B80D-DF7B4507913C} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {A3C7FD00-E7E0-680C-8B82-6EE7E669B6DF} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {E8BA5CFE-A00A-67B9-116E-2D7CFE9353A2} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {94D80A71-2262-F6B3-E6F3-BA98D478805A} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {2AA0E8D3-99B0-490C-F008-933B99A8C115} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {EC460028-6D2B-783B-38C7-AAE711D3E7CF} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {0AF4904E-9FF4-5931-DA10-FBBFB0373207} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {CBAC5CD8-D7E7-2CF5-346E-9E50A4F45402} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {0CDC00C3-C698-7F19-22CE-1041D267AD05} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {C5AC3C2F-938E-B1D1-0A72-CF4B33A03A14} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {008A5E43-7E04-6264-19E3-CABC19B791F6} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {322A5D80-2B4E-2147-DEFE-2873CBFF84A7} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {44985742-7FEB-AF00-8EF0-6D64A3901DFB} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {72B6633B-BB4F-2088-0376-0879407D9C22} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {B92C210C-1538-F49B-BED9-4D03BE1261CC} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {F201E961-75EB-CA0F-E3A1-C6772CE64F94} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {A948DED9-A932-F519-4943-ADD6D1F8008B} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {8802D7C1-A87E-0568-EFC5-AEBB369A9965} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
O2 - BHO: (no name) - {7335B843-1BBF-D015-5AD0-4848F51264CC} - C:\WINDOWS\MSTQ.DLL
O2 - BHO: (no name) - {D71F86E9-153C-EC16-809D-92D47ADFA43D} - C:\WINDOWS\MSTQ.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [BayMgr] DockApp.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iPodWatcher] C:\Program Files\iPod\Bin\iPodWatcher.exe
O4 - HKLM\..\Run: [ALiUSBfix] C:\WINDOWS\SYSTEM\GREENMK.exe
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.exe
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETTRAY.EXE
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [APIQZ32.EXE] C:\WINDOWS\APIQZ32.EXE
O4 - HKLM\..\RunServices: [D3BM32.EXE] C:\WINDOWS\SYSTEM\D3BM32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - HKLM\..\RunServices: [CROY32.EXE] C:\WINDOWS\CROY32.EXE
O4 - HKLM\..\RunServices: [SYSKX32.EXE] C:\WINDOWS\SYSKX32.EXE
O4 - HKLM\..\RunServices: [APPER32.EXE] C:\WINDOWS\APPER32.EXE
O4 - HKLM\..\RunServices: [MSJT32.EXE] C:\WINDOWS\SYSTEM\MSJT32.EXE
O4 - HKLM\..\RunServices: [IPWN.EXE] C:\WINDOWS\SYSTEM\IPWN.EXE
O4 - HKLM\..\RunServices: [SDKVI.EXE] C:\WINDOWS\SDKVI.EXE
O4 - HKLM\..\RunServices: [IENF32.EXE] C:\WINDOWS\IENF32.EXE
O4 - HKLM\..\RunServices: [ATLYB.EXE] C:\WINDOWS\SYSTEM\ATLYB.EXE
O4 - HKLM\..\RunServices: [JAVAQV32.EXE] C:\WINDOWS\JAVAQV32.EXE
O4 - HKLM\..\RunServices: [SYSUU32.EXE] C:\WINDOWS\SYSUU32.EXE
O4 - HKLM\..\RunServices: [SYSST32.EXE] C:\WINDOWS\SYSTEM\SYSST32.EXE
O4 - HKLM\..\RunServices: [JAVAXN.EXE] C:\WINDOWS\JAVAXN.EXE
O4 - HKLM\..\RunServices: [D3NF.EXE] C:\WINDOWS\SYSTEM\D3NF.EXE
O4 - HKLM\..\RunServices: [ADDFB32.EXE] C:\WINDOWS\SYSTEM\ADDFB32.EXE
O4 - HKLM\..\RunServices: [D3LV.EXE] C:\WINDOWS\D3LV.EXE
O4 - HKLM\..\RunServices: [APPHH.EXE] C:\WINDOWS\APPHH.EXE
O4 - HKLM\..\RunServices: [SDKKR.EXE] C:\WINDOWS\SYSTEM\SDKKR.EXE
O4 - HKLM\..\RunServices: [ATLDC.EXE] C:\WINDOWS\ATLDC.EXE
O4 - HKLM\..\RunServices: [IEIW32.EXE] C:\WINDOWS\IEIW32.EXE
O4 - HKLM\..\RunServices: [NTWQ.EXE] C:\WINDOWS\SYSTEM\NTWQ.EXE
O4 - HKLM\..\RunServices: [ATLTN32.EXE] C:\WINDOWS\SYSTEM\ATLTN32.EXE
O4 - HKLM\..\RunServices: [SYSVN.EXE] C:\WINDOWS\SYSTEM\SYSVN.EXE
O4 - HKLM\..\RunServices: [APIGB32.EXE] C:\WINDOWS\APIGB32.EXE
O4 - HKLM\..\RunServices: [JAVAOG.EXE] C:\WINDOWS\JAVAOG.EXE
O4 - HKLM\..\RunServices: [MSJL.EXE] C:\WINDOWS\SYSTEM\MSJL.EXE
O4 - HKLM\..\RunServices: [JAVATW.EXE] C:\WINDOWS\SYSTEM\JAVATW.EXE
O4 - HKLM\..\RunServices: [MFCXG32.EXE] C:\WINDOWS\SYSTEM\MFCXG32.EXE
O4 - HKLM\..\RunServices: [NTVO.EXE] C:\WINDOWS\SYSTEM\NTVO.EXE
O4 - HKLM\..\RunServices: [MFCHQ32.EXE] C:\WINDOWS\SYSTEM\MFCHQ32.EXE
O4 - HKLM\..\RunServices: [SDKAN.EXE] C:\WINDOWS\SDKAN.EXE
O4 - HKLM\..\RunServices: [ATLFH32.EXE] C:\WINDOWS\ATLFH32.EXE
O4 - HKLM\..\RunServices: [MSIE.EXE] C:\WINDOWS\MSIE.EXE
O4 - HKLM\..\RunServices: [APPLI.EXE] C:\WINDOWS\SYSTEM\APPLI.EXE
O4 - HKLM\..\RunServices: [IPUB.EXE] C:\WINDOWS\IPUB.EXE
O4 - HKLM\..\RunServices: [D3NX32.EXE] C:\WINDOWS\SYSTEM\D3NX32.EXE
O4 - HKLM\..\RunServices: [APPYT32.EXE] C:\WINDOWS\SYSTEM\APPYT32.EXE
O4 - HKLM\..\RunServices: [IEEZ.EXE] C:\WINDOWS\IEEZ.EXE
O4 - HKLM\..\RunServices: [JAVAPA.EXE] C:\WINDOWS\SYSTEM\JAVAPA.EXE
O4 - HKLM\..\RunServices: [IELL32.EXE] C:\WINDOWS\IELL32.EXE
O4 - HKLM\..\RunServices: [ATLDZ32.EXE] C:\WINDOWS\SYSTEM\ATLDZ32.EXE
O4 - HKLM\..\RunServices: [NTWW.EXE] C:\WINDOWS\NTWW.EXE
O4 - HKLM\..\RunServices: [NETKA.EXE] C:\WINDOWS\NETKA.EXE
O4 - HKLM\..\RunServices: [CRUV.EXE] C:\WINDOWS\SYSTEM\CRUV.EXE
O4 - HKLM\..\RunServices: [WINNS32.EXE] C:\WINDOWS\WINNS32.EXE
O4 - HKLM\..\RunServices: [SYSJZ.EXE] C:\WINDOWS\SYSTEM\SYSJZ.EXE
O4 - HKLM\..\RunServices: [IPRZ.EXE] C:\WINDOWS\IPRZ.EXE
O4 - HKLM\..\RunServices: [ADDWB32.EXE] C:\WINDOWS\ADDWB32.EXE
O4 - HKLM\..\RunServices: [NTSX32.EXE] C:\WINDOWS\SYSTEM\NTSX32.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINDOWS\Plaxo\1.5.2.32\InstallStub.exe -a
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Startup: MA521 Configuration Utility.lnk = C:\Program Files\NETGEAR\NETGEAR MA521 Adapter\wlancfg5.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
O8 - Extra context menu item: Web Search - C:\WINDOWS\ex.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Encarta Encyclopedia (HKLM)
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)
O9 - Extra button: Define (HKLM)
O9 - Extra 'Tools' menuitem: Define (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AOL Toolbar (HKLM)
O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Dell Home (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.bitstream...er/tdserver.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.v...oint/index.html
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (WficaCtl Object) - https://webapps.stan.../cabs/wfica.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yaho...talls/yinst.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speeder...meInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...7702.2020601852
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.c...es/PROFILER.CAB
O16 - DPF: {76FACBCF-8EF8-11D4-8A2C-005004425934} (CDToolCtrl Class) - http://www.aol.co.uk...g/aolcdt171.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.co...ease/instub.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivi...n/ravonline.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,20/mcgdmgr.cab
O19 - User stylesheet: (file missing)

#2 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 10 September 2004 - 11:37 AM

Sorry for the delay, if you still have problems post a fresh log please




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button