Jump to content


Photo

Help please


  • Please log in to reply
1 reply to this topic

#1 Fiona&James

Fiona&James

    Member

  • New Member
  • Pip
  • 1 posts

Posted 18 July 2004 - 02:51 PM

Please can someone let me know which of the following items I should delete to clean my PC. Many thanks.

Logfile of HijackThis v1.97.7
Scan saved at 08:40:36, on 18/07/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\NETUK.EXE
C:\WINDOWS\NTGR.EXE
C:\WINDOWS\ATLDA32.EXE
C:\WINDOWS\SYSTEM\WINHJ32.EXE
C:\WINDOWS\APPRL.EXE
C:\WINDOWS\SDKBW32.EXE
C:\WINDOWS\SYSTEM\SYSQX.EXE
C:\WINDOWS\MFCGK.EXE
C:\WINDOWS\ADDGJ.EXE
C:\WINDOWS\SYSTEM\ADDJN.EXE
C:\WINDOWS\WINIX.EXE
C:\WINDOWS\APIRK.EXE
C:\WINDOWS\ADDEH32.EXE
C:\WINDOWS\SYSTEM\SDKVM.EXE
C:\WINDOWS\SYSTEM\MSVX.EXE
C:\WINDOWS\CRIX.EXE
C:\WINDOWS\SYSWW.EXE
C:\WINDOWS\JAVAEX32.EXE
C:\WINDOWS\SYSTEM\JAVAEM32.EXE
C:\WINDOWS\SYSTEM\SYSEU.EXE
C:\WINDOWS\SYSTO32.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\ADDFP32.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\IPMC.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\MFCHW32.EXE
C:\WINDOWS\SYSTEM\JAVAEE.EXE
C:\WINDOWS\D3FW.EXE
C:\WINDOWS\SYSTEM\JAVAEM32.EXE
C:\WINDOWS\SYSTEM\APPCS.EXE
C:\WINDOWS\NTSK32.EXE
C:\WINDOWS\SYSTEM\SDKPL.EXE
C:\WINDOWS\SYSTEM\IPOK.EXE
C:\WINDOWS\NETXX.EXE
C:\WINDOWS\SYSTEM\SDKQN32.EXE
C:\WINDOWS\NTAI.EXE
C:\WINDOWS\NTRV32.EXE
C:\WINDOWS\SYSTEM\ATLJZ32.EXE
C:\WINDOWS\NTOH32.EXE
C:\WINDOWS\SYSTEM\SYSTI.EXE
C:\WINDOWS\APPRU.EXE
C:\WINDOWS\SYSTEM\APIAZ32.EXE
C:\WINDOWS\SYSTEM\APIAD.EXE
C:\WINDOWS\IPZJ32.EXE
C:\WINDOWS\APPKI.EXE
C:\WINDOWS\SYSTEM\APPMH.EXE
C:\WINDOWS\D3OE32.EXE
C:\WINDOWS\SDKOL.EXE
C:\WINDOWS\SYSTEM\MSRJ32.EXE
C:\WINDOWS\JAVATT32.EXE
C:\WINDOWS\SYSTEM\MFCFK.EXE
C:\WINDOWS\SYSTEM\APIJV.EXE
C:\WINDOWS\SYSTEM\D3GD.EXE
C:\WINDOWS\SYSTEM\SDKJE32.EXE
C:\WINDOWS\SYSTEM\IEKV.EXE
C:\WINDOWS\MSWJ.EXE
C:\WINDOWS\SYSTEM\NETRN32.EXE
C:\WINDOWS\WINSW.EXE
C:\WINDOWS\IEGD32.EXE
C:\WINDOWS\D3LE32.EXE
C:\WINDOWS\SYSTEM\IESZ32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\SYSTEM.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\FINEPIXVIEWER\QUICKDCF.EXE
C:\PROGRAM FILES\SAGEM\SAGEM F@ST 800-840\DSLMON.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\NETRN32.EXE
C:\WINDOWS\SYSTEM\APIPO32.EXE
C:\WINDOWS\SYSTEM\APIPO32.EXE
C:\WINDOWS\SYSTEM\MFCDV32.EXE
C:\WINDOWS\SYSTEM\MFCGC.EXE
C:\WINDOWS\SYSTEM\NETUK.EXE
C:\UNZIPPED\HIJACKTHIS1977[1]\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\vtqsh.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://vtqsh.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://vtqsh.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\vtqsh.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://vtqsh.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\vtqsh.dll/sp.html#96676
F1 - win.ini: run=C:\WINDOWS\SYSTEM\SERVICES\MSXMIDI.EXE
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL (file missing)
O2 - BHO: (no name) - {23BC1CCF-4BE7-497F-B154-6ADA68425FBB} - C:\WINDOWS\SYSTEM\EXPEXT.DLL (file missing)
O2 - BHO: (no name) - {98DBBF16-CA43-4c33-BE80-99E6694468A4} - C:\WINDOWS\SYSTEM\MSMK.DLL (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {62160EEF-9D84-4C19-B7B8-6AC2526CD726} - C:\WINDOWS\SYSTEM\IDUMOUE.DLL (file missing)
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\SYSTEM\services\2.01.00.dll (file missing)
O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL (file missing)
O2 - BHO: (no name) - {2AC970B7-9D60-15AA-747F-18EE664D61F5} - C:\WINDOWS\SYSTEM\NTOS32.DLL
O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - C:\WINDOWS\MSLAGENT\4B_1,0,1,0_MSLAGENT.DLL (file missing)
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\NEM219.DLL (file missing)
O2 - BHO: (no name) - {5DD23F4D-430F-ABA4-F97A-C96F50B71734} - C:\WINDOWS\SYSTEM\NTOS32.DLL
O2 - BHO: (no name) - {AF6F74FC-738A-7566-B5AD-5500C3BCCF24} - C:\WINDOWS\SYSTEM\NTOS32.DLL
O2 - BHO: (no name) - {BD499123-D1A0-5AE4-289E-FF22AB060EE0} - C:\WINDOWS\SYSTEM\NTOS32.DLL
O2 - BHO: OsbornTech Popup Blocker - {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} - C:\WINDOWS\SYSTEM\MSHELPER.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NVQuickTweak] RUNDLL32.EXE NVQTWK.DLL,NvTaskbarInit
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [BayMgr] DockApp.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [RegShave] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [Explkw] C:\WINDOWS\SYSTEM\expup.exe
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\host32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [APPTL32.EXE] C:\WINDOWS\SYSTEM\APPTL32.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [APPRL.EXE] C:\WINDOWS\APPRL.EXE
O4 - HKLM\..\RunServices: [ATLDA32.EXE] C:\WINDOWS\ATLDA32.EXE
O4 - HKLM\..\RunServices: [SDKBW32.EXE] C:\WINDOWS\SDKBW32.EXE
O4 - HKLM\..\RunServices: [NETUK.EXE] C:\WINDOWS\SYSTEM\NETUK.EXE
O4 - HKLM\..\RunServices: [NTGR.EXE] C:\WINDOWS\NTGR.EXE
O4 - HKLM\..\RunServices: [ADDGJ.EXE] C:\WINDOWS\ADDGJ.EXE
O4 - HKLM\..\RunServices: [WINHJ32.EXE] C:\WINDOWS\SYSTEM\WINHJ32.EXE
O4 - HKLM\..\RunServices: [ADDJN.EXE] C:\WINDOWS\SYSTEM\ADDJN.EXE
O4 - HKLM\..\RunServices: [SYSQX.EXE] C:\WINDOWS\SYSTEM\SYSQX.EXE
O4 - HKLM\..\RunServices: [MFCGK.EXE] C:\WINDOWS\MFCGK.EXE
O4 - HKLM\..\RunServices: [WINIX.EXE] C:\WINDOWS\WINIX.EXE
O4 - HKLM\..\RunServices: [APIRK.EXE] C:\WINDOWS\APIRK.EXE
O4 - HKLM\..\RunServices: [SDKVM.EXE] C:\WINDOWS\SYSTEM\SDKVM.EXE
O4 - HKLM\..\RunServices: [MSVX.EXE] C:\WINDOWS\SYSTEM\MSVX.EXE
O4 - HKLM\..\RunServices: [CRIX.EXE] C:\WINDOWS\CRIX.EXE
O4 - HKLM\..\RunServices: [JAVAEM32.EXE] C:\WINDOWS\SYSTEM\JAVAEM32.EXE
O4 - HKLM\..\RunServices: [ADDEH32.EXE] C:\WINDOWS\ADDEH32.EXE
O4 - HKLM\..\RunServices: [JAVAEX32.EXE] C:\WINDOWS\JAVAEX32.EXE
O4 - HKLM\..\RunServices: [SYSWW.EXE] C:\WINDOWS\SYSWW.EXE
O4 - HKLM\..\RunServices: [ADDFP32.EXE] C:\WINDOWS\ADDFP32.EXE
O4 - HKLM\..\RunServices: [SYSEU.EXE] C:\WINDOWS\SYSTEM\SYSEU.EXE
O4 - HKLM\..\RunServices: [SYSTO32.EXE] C:\WINDOWS\SYSTO32.EXE
O4 - HKLM\..\RunServices: [IPMC.EXE] C:\WINDOWS\SYSTEM\IPMC.EXE
O4 - HKLM\..\RunServices: [D3FW.EXE] C:\WINDOWS\D3FW.EXE
O4 - HKLM\..\RunServices: [JAVAEE.EXE] C:\WINDOWS\SYSTEM\JAVAEE.EXE
O4 - HKLM\..\RunServices: [MFCHW32.EXE] C:\WINDOWS\SYSTEM\MFCHW32.EXE
O4 - HKLM\..\RunServices: [SDKPL.EXE] C:\WINDOWS\SYSTEM\SDKPL.EXE
O4 - HKLM\..\RunServices: [APPCS.EXE] C:\WINDOWS\SYSTEM\APPCS.EXE
O4 - HKLM\..\RunServices: [NTAI.EXE] C:\WINDOWS\NTAI.EXE
O4 - HKLM\..\RunServices: [NTSK32.EXE] C:\WINDOWS\NTSK32.EXE
O4 - HKLM\..\RunServices: [NETXX.EXE] C:\WINDOWS\NETXX.EXE
O4 - HKLM\..\RunServices: [APIAD.EXE] C:\WINDOWS\SYSTEM\APIAD.EXE
O4 - HKLM\..\RunServices: [ATLJZ32.EXE] C:\WINDOWS\SYSTEM\ATLJZ32.EXE
O4 - HKLM\..\RunServices: [IPZJ32.EXE] C:\WINDOWS\IPZJ32.EXE
O4 - HKLM\..\RunServices: [APPKI.EXE] C:\WINDOWS\APPKI.EXE
O4 - HKLM\..\RunServices: [IPOK.EXE] C:\WINDOWS\SYSTEM\IPOK.EXE
O4 - HKLM\..\RunServices: [NTOH32.EXE] C:\WINDOWS\NTOH32.EXE
O4 - HKLM\..\RunServices: [NTRV32.EXE] C:\WINDOWS\NTRV32.EXE
O4 - HKLM\..\RunServices: [APPRU.EXE] C:\WINDOWS\APPRU.EXE
O4 - HKLM\..\RunServices: [SDKQN32.EXE] C:\WINDOWS\SYSTEM\SDKQN32.EXE
O4 - HKLM\..\RunServices: [APIAZ32.EXE] C:\WINDOWS\SYSTEM\APIAZ32.EXE
O4 - HKLM\..\RunServices: [SYSTI.EXE] C:\WINDOWS\SYSTEM\SYSTI.EXE
O4 - HKLM\..\RunServices: [D3OE32.EXE] C:\WINDOWS\D3OE32.EXE
O4 - HKLM\..\RunServices: [APPMH.EXE] C:\WINDOWS\SYSTEM\APPMH.EXE
O4 - HKLM\..\RunServices: [MSRJ32.EXE] C:\WINDOWS\SYSTEM\MSRJ32.EXE
O4 - HKLM\..\RunServices: [SDKOL.EXE] C:\WINDOWS\SDKOL.EXE
O4 - HKLM\..\RunServices: [APIJV.EXE] C:\WINDOWS\SYSTEM\APIJV.EXE
O4 - HKLM\..\RunServices: [MFCFK.EXE] C:\WINDOWS\SYSTEM\MFCFK.EXE
O4 - HKLM\..\RunServices: [JAVATT32.EXE] C:\WINDOWS\JAVATT32.EXE
O4 - HKLM\..\RunServices: [SDKJE32.EXE] C:\WINDOWS\SYSTEM\SDKJE32.EXE
O4 - HKLM\..\RunServices: [D3GD.EXE] C:\WINDOWS\SYSTEM\D3GD.EXE
O4 - HKLM\..\RunServices: [IEKV.EXE] C:\WINDOWS\SYSTEM\IEKV.EXE
O4 - HKLM\..\RunServices: [MSWJ.EXE] C:\WINDOWS\MSWJ.EXE
O4 - HKLM\..\RunServices: [D3LE32.EXE] C:\WINDOWS\D3LE32.EXE
O4 - HKLM\..\RunServices: [NETRN32.EXE] C:\WINDOWS\SYSTEM\NETRN32.EXE
O4 - HKLM\..\RunServices: [WINSW.EXE] C:\WINDOWS\WINSW.EXE
O4 - HKLM\..\RunServices: [IEGD32.EXE] C:\WINDOWS\IEGD32.EXE
O4 - HKLM\..\RunServices: [IESZ32.EXE] C:\WINDOWS\SYSTEM\IESZ32.EXE
O4 - HKLM\..\RunServices: [APIPO32.EXE] C:\WINDOWS\SYSTEM\APIPO32.EXE
O4 - HKLM\..\RunServices: [MFCDV32.EXE] C:\WINDOWS\SYSTEM\MFCDV32.EXE
O4 - HKLM\..\RunServices: [MFCGC.EXE] C:\WINDOWS\SYSTEM\MFCGC.EXE
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1016.dll,InstantAccess
O4 - HKCU\..\Run: [mslagent] C:\WINDOWS\mslagent\MSLAGENT.EXE
O4 - HKCU\..\Run: [ssgrate.exe] C:\WINDOWS\SYSTEM\SYSTEM.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - User Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - User Startup: PowerReg Scheduler.exe
O4 - User Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - User Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with Go!Zilla - file://C:\PROGRAM FILES\GO!ZILLA\download-with-gozilla.html
O8 - Extra context menu item: Web Search - C:\WINDOWS\ex.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Dell Home (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzill...ller/dwnldr.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8032.3782523148
O19 - User stylesheet: C:\WINDOWS\color.css
O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp (file missing) (HKLM)

#2 MrCharlie

MrCharlie

    Member

  • Helper Trainee
  • Pip
  • 25 posts

Posted 18 July 2004 - 03:43 PM

Welcome to the forum.

They really got you good, but I'll do my best to help you.

Please look in your control panels add/remove programs and see if there's any programs you don't recognize or didn't install like toolbars, searchbars, etc; and uninstall them. If you're not sure, please ask first.

Next.
Please download and run AD-Aware, here's how.

First thing to do is click on "Check For Updates Now", download the lastest updates.

Then:

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."

Scanning > activate these: "Scan within archives", "Scan active processes", "Scan registry", "Deep scan registry", "Scan my IE Favorites for banned sites" and "Scan my Hosts file"

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister objects prior to deletion" and "Let Windows remove files in use after reboot."

Press "Scan Now"

- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"

Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys. Click 'Next' again
Right-click in that pane and choose "select all"

If it finds "bad" files and registry keys, press "Next" again
It will ask you whether you'd like to remove all checked items. Click OK.

Finally, close Ad-Aware, and reboot .

Next, if you have an anti virus, update and run it, if not here's three links to free scans, use them and let them delete what they find:


http://housecall.tre.../start_corp.asp

http://www.pandasoft...n_principal.htm

http://www.bitdefend...can/licence.php

Reboot, then download , unzip and run AboutBuster to get rid of the hijacker, try it in regular mode and safe mode, you may have to run it several times to delete all the files. Just run the program, you don't have to delete any entries as it mentions. It may not completely fix the hijacker, but will help in deleting some of the files.

http://malwarebytes....AboutBuster.zip

Reboot and see how it is.

If hijacker is still present, see if you can follow the directions at this link, they don't all apply to Windows ME.
If not, post a fresh HJT log and we'll go from there:

http://www.pchell.co...lythebest.shtml

Let me know, MrC

from - TomCoyote forum

anyone can buy a new one, but not everyone can fix the old one

Major & Lindsay




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button