Jump to content


Photo

Please in major need of help!


  • Please log in to reply
1 reply to this topic

#1 theedge

theedge

    Member

  • Full Member
  • Pip
  • 43 posts

Posted 21 July 2004 - 10:07 AM

Hey,

Hopefully I will be allowed to post this. A few days ago I had 9-13 trojans slip in to my PC. This hijacked my homepage and now other things. I ran a virus scan and it said all were off the system. With in days my computer started acting wierd. I would log on and it would slow down or it wouldn't allow me to open new browswers. It would say system resources are gone after some time surfing. Now I even log on to my computer and my system resources are gone just from logging on. I have never had a problem of memory dying so fast and thats why I think something nasty is hiding. Even when I try to log in to this site it won't let me most of the time or hijackthis won't open my log. So here is my hijackthis log. I need help as soon as possible. I thank you very much for your time!

Logfile of HijackThis v1.97.7
Scan saved at 10:34:34 AM, on 21/07/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\IPMP32.EXE
C:\WINDOWS\SYSTEM\WINWI.EXE
C:\WINDOWS\NTXI32.EXE
C:\WINDOWS\SYSTEM\IPJY.EXE
C:\WINDOWS\SYSTEM\IEBI.EXE
C:\WINDOWS\D3BO32.EXE
C:\WINDOWS\SYSTEM\ATLLJ.EXE
C:\WINDOWS\SYSTEM\MFCBE32.EXE
C:\WINDOWS\MSPR.EXE
C:\WINDOWS\NETAM32.EXE
C:\WINDOWS\SYSTEM\MSOF.EXE
C:\WINDOWS\APIFA.EXE
C:\WINDOWS\D3OF32.EXE
C:\WINDOWS\IEAG.EXE
C:\WINDOWS\ADDIY.EXE
C:\WINDOWS\NTFS32.EXE
C:\WINDOWS\ADDNZ.EXE
C:\WINDOWS\SYSTEM\IETU.EXE
C:\WINDOWS\SYSTEM\ADDBK32.EXE
C:\WINDOWS\NTEC.EXE
C:\WINDOWS\SYSTEM\SYSGG.EXE
C:\WINDOWS\SYSTEM\SDKFO32.EXE
C:\WINDOWS\SYSTEM\APIXK32.EXE
C:\WINDOWS\SDKZA.EXE
C:\WINDOWS\CRBP32.EXE
C:\WINDOWS\SYSTEM\ADDIF.EXE
C:\WINDOWS\SYSTEM\APIYN.EXE
C:\WINDOWS\SYSTEM\NTND.EXE
C:\WINDOWS\APPCC.EXE
C:\WINDOWS\SYSTEM\NETIH32.EXE
C:\WINDOWS\SYSTEM\SYSNQ32.EXE
C:\WINDOWS\IPXK32.EXE
C:\WINDOWS\SYSTEM\ADDKA.EXE
C:\WINDOWS\MFCLP32.EXE
C:\WINDOWS\MFCVB32.EXE
C:\WINDOWS\SYSTEM\NTOS32.EXE
C:\WINDOWS\SYSTEM\MSIQ.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\APPQF32.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSML.EXE
C:\WINDOWS\SYSQM.EXE
C:\WINDOWS\SYSTEM\WINFV32.EXE
C:\WINDOWS\SYSTEM\APIQR.EXE
C:\WINDOWS\SYSTEM\APPHB32.EXE
C:\WINDOWS\D3HQ32.EXE
C:\WINDOWS\SYSTEM\CRBQ32.EXE
C:\WINDOWS\APPYO.EXE
C:\WINDOWS\MSBE.EXE
C:\WINDOWS\IPLX.EXE
C:\WINDOWS\SYSTEM\IESG.EXE
C:\WINDOWS\ADDZR32.EXE
C:\WINDOWS\SYSTEM\IEAO32.EXE
C:\WINDOWS\IEYD.EXE
C:\WINDOWS\JAVAUG32.EXE
C:\WINDOWS\SYSTEM\D3KI32.EXE
C:\WINDOWS\SYSRM.EXE
C:\WINDOWS\D3QE.EXE
C:\WINDOWS\SYSTEM\IPEN.EXE
C:\WINDOWS\SYSTEM\NETYS32.EXE
C:\WINDOWS\SYSTEM\D3IO32.EXE
C:\WINDOWS\IEEG.EXE
C:\WINDOWS\JAVAOQ32.EXE
C:\WINDOWS\SYSTEM\SDKKM.EXE
C:\WINDOWS\SYSTEM\SDKJI32.EXE
C:\WINDOWS\SYSTEM\MSJC.EXE
C:\WINDOWS\SYSTEM\MFCPV.EXE
C:\WINDOWS\SYSTEM\IESV32.EXE
C:\WINDOWS\MSSS32.EXE
C:\WINDOWS\SYSTEM\ATLJI32.EXE
C:\WINDOWS\MFCEV.EXE
C:\WINDOWS\SYSTEM\APPHR.EXE
C:\WINDOWS\SYSTEM\NTJX.EXE
C:\WINDOWS\ATLGH.EXE
C:\WINDOWS\SYSTEM\D3UW32.EXE
C:\WINDOWS\SDKZL.EXE
C:\WINDOWS\SYSTEM\MSOH.EXE
C:\WINDOWS\SYSTEM\IPMT32.EXE
C:\WINDOWS\D3EP32.EXE
C:\WINDOWS\APIPU32.EXE
C:\WINDOWS\APPEM.EXE
C:\WINDOWS\SYSTEM\SYSPK32.EXE
C:\WINDOWS\D3OJ32.EXE
C:\WINDOWS\SYSTEM\SYSAS.EXE
C:\WINDOWS\JAVAFX.EXE
C:\WINDOWS\APPOV32.EXE
C:\WINDOWS\SYSVB.EXE
C:\WINDOWS\IEPA32.EXE
C:\WINDOWS\SYSTEM\WINCK32.EXE
C:\WINDOWS\SYSTEM\CRQD.EXE
C:\WINDOWS\MSDP32.EXE
C:\WINDOWS\MSFN32.EXE
C:\WINDOWS\SYSTEM\APPAW.EXE
C:\WINDOWS\NTYU.EXE
C:\WINDOWS\SYSTEM\JAVAPR.EXE
C:\WINDOWS\SYSTEM\D3WR.EXE
C:\WINDOWS\SYSTEM\APISC32.EXE
C:\WINDOWS\SYSTEM\ATLOL32.EXE
C:\WINDOWS\CRBU.EXE
C:\WINDOWS\APPHL32.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\APPNE32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\ATLOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pgrbe.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pgrbe.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pgrbe.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pgrbe.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pgrbe.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pgrbe.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchwww.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.canoe.ca/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\gnmtwd0l.slt\prefs.js)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_19_0.DLL (file missing)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - C:\SYSFWB\8536482463\IEFWBAR.DLL (file missing)
O2 - BHO: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: (no name) - {DBFCA164-5C46-B7BA-9FE0-E92A8DEC53BA} - (no file)
O2 - BHO: (no name) - {C8BFB1F8-6B02-5880-8993-6C955AAC22D9} - C:\WINDOWS\APPUE32.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_19_0.DLL (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Inet Delivery] C:\Program Files\Inet Delivery\INETDL_2.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [APPNE32.EXE] C:\WINDOWS\APPNE32.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [WINWI.EXE] C:\WINDOWS\SYSTEM\WINWI.EXE
O4 - HKLM\..\RunServices: [D3BO32.EXE] C:\WINDOWS\D3BO32.EXE
O4 - HKLM\..\RunServices: [IPJY.EXE] C:\WINDOWS\SYSTEM\IPJY.EXE
O4 - HKLM\..\RunServices: [IEBI.EXE] C:\WINDOWS\SYSTEM\IEBI.EXE
O4 - HKLM\..\RunServices: [MSPR.EXE] C:\WINDOWS\MSPR.EXE
O4 - HKLM\..\RunServices: [IPMP32.EXE] C:\WINDOWS\SYSTEM\IPMP32.EXE
O4 - HKLM\..\RunServices: [MFCBE32.EXE] C:\WINDOWS\SYSTEM\MFCBE32.EXE
O4 - HKLM\..\RunServices: [NTXI32.EXE] C:\WINDOWS\NTXI32.EXE
O4 - HKLM\..\RunServices: [NETAM32.EXE] C:\WINDOWS\NETAM32.EXE
O4 - HKLM\..\RunServices: [NTFS32.EXE] C:\WINDOWS\NTFS32.EXE
O4 - HKLM\..\RunServices: [D3OF32.EXE] C:\WINDOWS\D3OF32.EXE
O4 - HKLM\..\RunServices: [MSOF.EXE] C:\WINDOWS\SYSTEM\MSOF.EXE
O4 - HKLM\..\RunServices: [ADDIY.EXE] C:\WINDOWS\ADDIY.EXE
O4 - HKLM\..\RunServices: [IETU.EXE] C:\WINDOWS\SYSTEM\IETU.EXE
O4 - HKLM\..\RunServices: [IEAG.EXE] C:\WINDOWS\IEAG.EXE
O4 - HKLM\..\RunServices: [ATLLJ.EXE] C:\WINDOWS\SYSTEM\ATLLJ.EXE
O4 - HKLM\..\RunServices: [APIFA.EXE] C:\WINDOWS\APIFA.EXE
O4 - HKLM\..\RunServices: [ADDNZ.EXE] C:\WINDOWS\ADDNZ.EXE
O4 - HKLM\..\RunServices: [APIXK32.EXE] C:\WINDOWS\SYSTEM\APIXK32.EXE
O4 - HKLM\..\RunServices: [ADDBK32.EXE] C:\WINDOWS\SYSTEM\ADDBK32.EXE
O4 - HKLM\..\RunServices: [NTEC.EXE] C:\WINDOWS\NTEC.EXE
O4 - HKLM\..\RunServices: [SYSGG.EXE] C:\WINDOWS\SYSTEM\SYSGG.EXE
O4 - HKLM\..\RunServices: [SDKFO32.EXE] C:\WINDOWS\SYSTEM\SDKFO32.EXE
O4 - HKLM\..\RunServices: [SDKZA.EXE] C:\WINDOWS\SDKZA.EXE
O4 - HKLM\..\RunServices: [ADDIF.EXE] C:\WINDOWS\SYSTEM\ADDIF.EXE
O4 - HKLM\..\RunServices: [CRBP32.EXE] C:\WINDOWS\CRBP32.EXE
O4 - HKLM\..\RunServices: [APIYN.EXE] C:\WINDOWS\SYSTEM\APIYN.EXE
O4 - HKLM\..\RunServices: [NTND.EXE] C:\WINDOWS\SYSTEM\NTND.EXE
O4 - HKLM\..\RunServices: [APPCC.EXE] C:\WINDOWS\APPCC.EXE
O4 - HKLM\..\RunServices: [NETIH32.EXE] C:\WINDOWS\SYSTEM\NETIH32.EXE
O4 - HKLM\..\RunServices: [SYSNQ32.EXE] C:\WINDOWS\SYSTEM\SYSNQ32.EXE
O4 - HKLM\..\RunServices: [IPXK32.EXE] C:\WINDOWS\IPXK32.EXE
O4 - HKLM\..\RunServices: [MFCLP32.EXE] C:\WINDOWS\MFCLP32.EXE
O4 - HKLM\..\RunServices: [ADDKA.EXE] C:\WINDOWS\SYSTEM\ADDKA.EXE
O4 - HKLM\..\RunServices: [MFCVB32.EXE] C:\WINDOWS\MFCVB32.EXE
O4 - HKLM\..\RunServices: [MSIQ.EXE] C:\WINDOWS\SYSTEM\MSIQ.EXE
O4 - HKLM\..\RunServices: [NTOS32.EXE] C:\WINDOWS\SYSTEM\NTOS32.EXE
O4 - HKLM\..\RunServices: [APPQF32.EXE] C:\WINDOWS\SYSTEM\APPQF32.EXE
O4 - HKLM\..\RunServices: [SYSQM.EXE] C:\WINDOWS\SYSQM.EXE
O4 - HKLM\..\RunServices: [APPHB32.EXE] C:\WINDOWS\SYSTEM\APPHB32.EXE
O4 - HKLM\..\RunServices: [SYSML.EXE] C:\WINDOWS\SYSML.EXE
O4 - HKLM\..\RunServices: [WINFV32.EXE] C:\WINDOWS\SYSTEM\WINFV32.EXE
O4 - HKLM\..\RunServices: [APIQR.EXE] C:\WINDOWS\SYSTEM\APIQR.EXE
O4 - HKLM\..\RunServices: [D3HQ32.EXE] C:\WINDOWS\D3HQ32.EXE
O4 - HKLM\..\RunServices: [APPYO.EXE] C:\WINDOWS\APPYO.EXE
O4 - HKLM\..\RunServices: [CRBQ32.EXE] C:\WINDOWS\SYSTEM\CRBQ32.EXE
O4 - HKLM\..\RunServices: [IESG.EXE] C:\WINDOWS\SYSTEM\IESG.EXE
O4 - HKLM\..\RunServices: [MSBE.EXE] C:\WINDOWS\MSBE.EXE
O4 - HKLM\..\RunServices: [IPLX.EXE] C:\WINDOWS\IPLX.EXE
O4 - HKLM\..\RunServices: [IEYD.EXE] C:\WINDOWS\IEYD.EXE
O4 - HKLM\..\RunServices: [IEAO32.EXE] C:\WINDOWS\SYSTEM\IEAO32.EXE
O4 - HKLM\..\RunServices: [SYSRM.EXE] C:\WINDOWS\SYSRM.EXE
O4 - HKLM\..\RunServices: [D3QE.EXE] C:\WINDOWS\D3QE.EXE
O4 - HKLM\..\RunServices: [ADDZR32.EXE] C:\WINDOWS\ADDZR32.EXE
O4 - HKLM\..\RunServices: [JAVAUG32.EXE] C:\WINDOWS\JAVAUG32.EXE
O4 - HKLM\..\RunServices: [D3KI32.EXE] C:\WINDOWS\SYSTEM\D3KI32.EXE
O4 - HKLM\..\RunServices: [IPEN.EXE] C:\WINDOWS\SYSTEM\IPEN.EXE
O4 - HKLM\..\RunServices: [NETYS32.EXE] C:\WINDOWS\SYSTEM\NETYS32.EXE
O4 - HKLM\..\RunServices: [D3IO32.EXE] C:\WINDOWS\SYSTEM\D3IO32.EXE
O4 - HKLM\..\RunServices: [JAVAOQ32.EXE] C:\WINDOWS\JAVAOQ32.EXE
O4 - HKLM\..\RunServices: [IEEG.EXE] C:\WINDOWS\IEEG.EXE
O4 - HKLM\..\RunServices: [SDKJI32.EXE] C:\WINDOWS\SYSTEM\SDKJI32.EXE
O4 - HKLM\..\RunServices: [SDKKM.EXE] C:\WINDOWS\SYSTEM\SDKKM.EXE
O4 - HKLM\..\RunServices: [MSJC.EXE] C:\WINDOWS\SYSTEM\MSJC.EXE
O4 - HKLM\..\RunServices: [MFCPV.EXE] C:\WINDOWS\SYSTEM\MFCPV.EXE
O4 - HKLM\..\RunServices: [ATLGH.EXE] C:\WINDOWS\ATLGH.EXE
O4 - HKLM\..\RunServices: [MSSS32.EXE] C:\WINDOWS\MSSS32.EXE
O4 - HKLM\..\RunServices: [IESV32.EXE] C:\WINDOWS\SYSTEM\IESV32.EXE
O4 - HKLM\..\RunServices: [ATLJI32.EXE] C:\WINDOWS\SYSTEM\ATLJI32.EXE
O4 - HKLM\..\RunServices: [MFCEV.EXE] C:\WINDOWS\MFCEV.EXE
O4 - HKLM\..\RunServices: [APPHR.EXE] C:\WINDOWS\SYSTEM\APPHR.EXE
O4 - HKLM\..\RunServices: [NTJX.EXE] C:\WINDOWS\SYSTEM\NTJX.EXE
O4 - HKLM\..\RunServices: [SDKZL.EXE] C:\WINDOWS\SDKZL.EXE
O4 - HKLM\..\RunServices: [D3UW32.EXE] C:\WINDOWS\SYSTEM\D3UW32.EXE
O4 - HKLM\..\RunServices: [MSOH.EXE] C:\WINDOWS\SYSTEM\MSOH.EXE
O4 - HKLM\..\RunServices: [IPMT32.EXE] C:\WINDOWS\SYSTEM\IPMT32.EXE
O4 - HKLM\..\RunServices: [D3EP32.EXE] C:\WINDOWS\D3EP32.EXE
O4 - HKLM\..\RunServices: [APIPU32.EXE] C:\WINDOWS\APIPU32.EXE
O4 - HKLM\..\RunServices: [APPEM.EXE] C:\WINDOWS\APPEM.EXE
O4 - HKLM\..\RunServices: [SYSPK32.EXE] C:\WINDOWS\SYSTEM\SYSPK32.EXE
O4 - HKLM\..\RunServices: [D3OJ32.EXE] C:\WINDOWS\D3OJ32.EXE
O4 - HKLM\..\RunServices: [SYSAS.EXE] C:\WINDOWS\SYSTEM\SYSAS.EXE
O4 - HKLM\..\RunServices: [SYSVB.EXE] C:\WINDOWS\SYSVB.EXE
O4 - HKLM\..\RunServices: [JAVAFX.EXE] C:\WINDOWS\JAVAFX.EXE
O4 - HKLM\..\RunServices: [APPOV32.EXE] C:\WINDOWS\APPOV32.EXE
O4 - HKLM\..\RunServices: [IEPA32.EXE] C:\WINDOWS\IEPA32.EXE
O4 - HKLM\..\RunServices: [WINCK32.EXE] C:\WINDOWS\SYSTEM\WINCK32.EXE
O4 - HKLM\..\RunServices: [CRQD.EXE] C:\WINDOWS\SYSTEM\CRQD.EXE
O4 - HKLM\..\RunServices: [MSDP32.EXE] C:\WINDOWS\MSDP32.EXE
O4 - HKLM\..\RunServices: [NTYU.EXE] C:\WINDOWS\NTYU.EXE
O4 - HKLM\..\RunServices: [MSFN32.EXE] C:\WINDOWS\MSFN32.EXE
O4 - HKLM\..\RunServices: [APPAW.EXE] C:\WINDOWS\SYSTEM\APPAW.EXE
O4 - HKLM\..\RunServices: [D3WR.EXE] C:\WINDOWS\SYSTEM\D3WR.EXE
O4 - HKLM\..\RunServices: [JAVAPR.EXE] C:\WINDOWS\SYSTEM\JAVAPR.EXE
O4 - HKLM\..\RunServices: [APPHL32.EXE] C:\WINDOWS\APPHL32.EXE
O4 - HKLM\..\RunServices: [APISC32.EXE] C:\WINDOWS\SYSTEM\APISC32.EXE
O4 - HKLM\..\RunServices: [ATLOL32.EXE] C:\WINDOWS\SYSTEM\ATLOL32.EXE
O4 - HKLM\..\RunServices: [CRBU.EXE] C:\WINDOWS\CRBU.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O15 - Trusted Zone: http://ad.searchsquire.com
O15 - Trusted Zone: http://search.searchsquire.com
O15 - Trusted Zone: http://update.searchsquire.com
O15 - Trusted Zone: http://www.searchsquire.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: Yahoo! Sheepshead - http://download.game...nts/y/dt0_x.cab
O16 - DPF: Yahoo! Canasta - http://download.game...nts/y/yt1_x.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8118.6022337963
O16 - DPF: {5F05A225-0F66-43DE-89E4-6FFD589C4F04} (Download Coach Installer) - http://www.objectcub...CubeInstall.cab
O16 - DPF: {086A694F-91FB-4068-B44C-124FB69BF05D} - http://www.searchwww.com/search.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://delivery.inet....com/inetdl.exe
O16 - DPF: {034CC2DC-3245-4B26-B5C7-7B8777739CB7} - http://64.156.31.98/060112ca.exe
O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-downlo...tsInstaller.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\tfyfbpxw.exe

#2 theedge

theedge

    Member

  • Full Member
  • Pip
  • 43 posts

Posted 21 July 2004 - 09:24 PM

Alright I read the post that was made about this virus and to download that buster thing. I was very lucky it got so bad that even turning my computer on killed all my resources. I then went and downloaded that from a friend only to find I have no unzipping software lol I then found software on another PC so I could do it.
here is my new hijack log

Logfile of HijackThis v1.97.7
Scan saved at 10:24:10 PM, on 21/07/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\D3KI32.EXE
C:\WINDOWS\D3BO32.EXE
C:\WINDOWS\SYSTEM\WINWI.EXE
C:\WINDOWS\ADDNZ.EXE
C:\WINDOWS\APPYO.EXE
C:\WINDOWS\IEAG.EXE
C:\WINDOWS\ATLGH.EXE
C:\WINDOWS\SYSTEM\ADDBK32.EXE
C:\WINDOWS\SYSRM.EXE
C:\WINDOWS\SYSTEM\D3IO32.EXE
C:\WINDOWS\SDKZL.EXE
C:\WINDOWS\MFCEV.EXE
C:\WINDOWS\SYSTEM\SYSAS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\CRBU.EXE
C:\WINDOWS\MSGM32.EXE
C:\WINDOWS\SYSTEM\CRQD.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\MSGM32.EXE
C:\WINDOWS\APPNE32.EXE
C:\WINDOWS\MSGM32.EXE
C:\PROGRAM FILES\SYMPATICO\ACCESS MANAGER\APP\ENTERNET.EXE
C:\WINDOWS\APPOC.EXE
C:\WINDOWS\SYSRM.EXE
C:\WINDOWS\MSGM32.EXE
C:\WINDOWS\SYSTEM\IPTS.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.shareware.us/srchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.canoe.ca/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\gnmtwd0l.slt\prefs.js)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_19_0.DLL (file missing)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - C:\SYSFWB\8536482463\IEFWBAR.DLL (file missing)
O2 - BHO: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: (no name) - {DBFCA164-5C46-B7BA-9FE0-E92A8DEC53BA} - (no file)
O2 - BHO: (no name) - {C8BFB1F8-6B02-5880-8993-6C955AAC22D9} - C:\WINDOWS\APPUE32.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_19_0.DLL (file missing)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Inet Delivery] C:\Program Files\Inet Delivery\INETDL_2.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [APPNE32.EXE] C:\WINDOWS\APPNE32.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [WINWI.EXE] C:\WINDOWS\SYSTEM\WINWI.EXE
O4 - HKLM\..\RunServices: [D3BO32.EXE] C:\WINDOWS\D3BO32.EXE
O4 - HKLM\..\RunServices: [IPJY.EXE] C:\WINDOWS\SYSTEM\IPJY.EXE
O4 - HKLM\..\RunServices: [IEBI.EXE] C:\WINDOWS\SYSTEM\IEBI.EXE
O4 - HKLM\..\RunServices: [MSPR.EXE] C:\WINDOWS\MSPR.EXE
O4 - HKLM\..\RunServices: [IPMP32.EXE] C:\WINDOWS\SYSTEM\IPMP32.EXE
O4 - HKLM\..\RunServices: [MFCBE32.EXE] C:\WINDOWS\SYSTEM\MFCBE32.EXE
O4 - HKLM\..\RunServices: [NTXI32.EXE] C:\WINDOWS\NTXI32.EXE
O4 - HKLM\..\RunServices: [NETAM32.EXE] C:\WINDOWS\NETAM32.EXE
O4 - HKLM\..\RunServices: [NTFS32.EXE] C:\WINDOWS\NTFS32.EXE
O4 - HKLM\..\RunServices: [D3OF32.EXE] C:\WINDOWS\D3OF32.EXE
O4 - HKLM\..\RunServices: [MSOF.EXE] C:\WINDOWS\SYSTEM\MSOF.EXE
O4 - HKLM\..\RunServices: [ADDIY.EXE] C:\WINDOWS\ADDIY.EXE
O4 - HKLM\..\RunServices: [IETU.EXE] C:\WINDOWS\SYSTEM\IETU.EXE
O4 - HKLM\..\RunServices: [IEAG.EXE] C:\WINDOWS\IEAG.EXE
O4 - HKLM\..\RunServices: [ATLLJ.EXE] C:\WINDOWS\SYSTEM\ATLLJ.EXE
O4 - HKLM\..\RunServices: [APIFA.EXE] C:\WINDOWS\APIFA.EXE
O4 - HKLM\..\RunServices: [ADDNZ.EXE] C:\WINDOWS\ADDNZ.EXE
O4 - HKLM\..\RunServices: [APIXK32.EXE] C:\WINDOWS\SYSTEM\APIXK32.EXE
O4 - HKLM\..\RunServices: [ADDBK32.EXE] C:\WINDOWS\SYSTEM\ADDBK32.EXE
O4 - HKLM\..\RunServices: [NTEC.EXE] C:\WINDOWS\NTEC.EXE
O4 - HKLM\..\RunServices: [SYSGG.EXE] C:\WINDOWS\SYSTEM\SYSGG.EXE
O4 - HKLM\..\RunServices: [SDKFO32.EXE] C:\WINDOWS\SYSTEM\SDKFO32.EXE
O4 - HKLM\..\RunServices: [SDKZA.EXE] C:\WINDOWS\SDKZA.EXE
O4 - HKLM\..\RunServices: [ADDIF.EXE] C:\WINDOWS\SYSTEM\ADDIF.EXE
O4 - HKLM\..\RunServices: [CRBP32.EXE] C:\WINDOWS\CRBP32.EXE
O4 - HKLM\..\RunServices: [APIYN.EXE] C:\WINDOWS\SYSTEM\APIYN.EXE
O4 - HKLM\..\RunServices: [NTND.EXE] C:\WINDOWS\SYSTEM\NTND.EXE
O4 - HKLM\..\RunServices: [APPCC.EXE] C:\WINDOWS\APPCC.EXE
O4 - HKLM\..\RunServices: [NETIH32.EXE] C:\WINDOWS\SYSTEM\NETIH32.EXE
O4 - HKLM\..\RunServices: [SYSNQ32.EXE] C:\WINDOWS\SYSTEM\SYSNQ32.EXE
O4 - HKLM\..\RunServices: [IPXK32.EXE] C:\WINDOWS\IPXK32.EXE
O4 - HKLM\..\RunServices: [MFCLP32.EXE] C:\WINDOWS\MFCLP32.EXE
O4 - HKLM\..\RunServices: [ADDKA.EXE] C:\WINDOWS\SYSTEM\ADDKA.EXE
O4 - HKLM\..\RunServices: [MFCVB32.EXE] C:\WINDOWS\MFCVB32.EXE
O4 - HKLM\..\RunServices: [MSIQ.EXE] C:\WINDOWS\SYSTEM\MSIQ.EXE
O4 - HKLM\..\RunServices: [NTOS32.EXE] C:\WINDOWS\SYSTEM\NTOS32.EXE
O4 - HKLM\..\RunServices: [APPQF32.EXE] C:\WINDOWS\SYSTEM\APPQF32.EXE
O4 - HKLM\..\RunServices: [SYSQM.EXE] C:\WINDOWS\SYSQM.EXE
O4 - HKLM\..\RunServices: [APPHB32.EXE] C:\WINDOWS\SYSTEM\APPHB32.EXE
O4 - HKLM\..\RunServices: [SYSML.EXE] C:\WINDOWS\SYSML.EXE
O4 - HKLM\..\RunServices: [WINFV32.EXE] C:\WINDOWS\SYSTEM\WINFV32.EXE
O4 - HKLM\..\RunServices: [APIQR.EXE] C:\WINDOWS\SYSTEM\APIQR.EXE
O4 - HKLM\..\RunServices: [D3HQ32.EXE] C:\WINDOWS\D3HQ32.EXE
O4 - HKLM\..\RunServices: [APPYO.EXE] C:\WINDOWS\APPYO.EXE
O4 - HKLM\..\RunServices: [CRBQ32.EXE] C:\WINDOWS\SYSTEM\CRBQ32.EXE
O4 - HKLM\..\RunServices: [IESG.EXE] C:\WINDOWS\SYSTEM\IESG.EXE
O4 - HKLM\..\RunServices: [MSBE.EXE] C:\WINDOWS\MSBE.EXE
O4 - HKLM\..\RunServices: [IPLX.EXE] C:\WINDOWS\IPLX.EXE
O4 - HKLM\..\RunServices: [IEYD.EXE] C:\WINDOWS\IEYD.EXE
O4 - HKLM\..\RunServices: [IEAO32.EXE] C:\WINDOWS\SYSTEM\IEAO32.EXE
O4 - HKLM\..\RunServices: [SYSRM.EXE] C:\WINDOWS\SYSRM.EXE
O4 - HKLM\..\RunServices: [D3QE.EXE] C:\WINDOWS\D3QE.EXE
O4 - HKLM\..\RunServices: [ADDZR32.EXE] C:\WINDOWS\ADDZR32.EXE
O4 - HKLM\..\RunServices: [JAVAUG32.EXE] C:\WINDOWS\JAVAUG32.EXE
O4 - HKLM\..\RunServices: [D3KI32.EXE] C:\WINDOWS\SYSTEM\D3KI32.EXE
O4 - HKLM\..\RunServices: [IPEN.EXE] C:\WINDOWS\SYSTEM\IPEN.EXE
O4 - HKLM\..\RunServices: [NETYS32.EXE] C:\WINDOWS\SYSTEM\NETYS32.EXE
O4 - HKLM\..\RunServices: [D3IO32.EXE] C:\WINDOWS\SYSTEM\D3IO32.EXE
O4 - HKLM\..\RunServices: [JAVAOQ32.EXE] C:\WINDOWS\JAVAOQ32.EXE
O4 - HKLM\..\RunServices: [IEEG.EXE] C:\WINDOWS\IEEG.EXE
O4 - HKLM\..\RunServices: [SDKJI32.EXE] C:\WINDOWS\SYSTEM\SDKJI32.EXE
O4 - HKLM\..\RunServices: [SDKKM.EXE] C:\WINDOWS\SYSTEM\SDKKM.EXE
O4 - HKLM\..\RunServices: [MSJC.EXE] C:\WINDOWS\SYSTEM\MSJC.EXE
O4 - HKLM\..\RunServices: [MFCPV.EXE] C:\WINDOWS\SYSTEM\MFCPV.EXE
O4 - HKLM\..\RunServices: [ATLGH.EXE] C:\WINDOWS\ATLGH.EXE
O4 - HKLM\..\RunServices: [MSSS32.EXE] C:\WINDOWS\MSSS32.EXE
O4 - HKLM\..\RunServices: [IESV32.EXE] C:\WINDOWS\SYSTEM\IESV32.EXE
O4 - HKLM\..\RunServices: [ATLJI32.EXE] C:\WINDOWS\SYSTEM\ATLJI32.EXE
O4 - HKLM\..\RunServices: [MFCEV.EXE] C:\WINDOWS\MFCEV.EXE
O4 - HKLM\..\RunServices: [APPHR.EXE] C:\WINDOWS\SYSTEM\APPHR.EXE
O4 - HKLM\..\RunServices: [NTJX.EXE] C:\WINDOWS\SYSTEM\NTJX.EXE
O4 - HKLM\..\RunServices: [SDKZL.EXE] C:\WINDOWS\SDKZL.EXE
O4 - HKLM\..\RunServices: [D3UW32.EXE] C:\WINDOWS\SYSTEM\D3UW32.EXE
O4 - HKLM\..\RunServices: [MSOH.EXE] C:\WINDOWS\SYSTEM\MSOH.EXE
O4 - HKLM\..\RunServices: [IPMT32.EXE] C:\WINDOWS\SYSTEM\IPMT32.EXE
O4 - HKLM\..\RunServices: [D3EP32.EXE] C:\WINDOWS\D3EP32.EXE
O4 - HKLM\..\RunServices: [APIPU32.EXE] C:\WINDOWS\APIPU32.EXE
O4 - HKLM\..\RunServices: [APPEM.EXE] C:\WINDOWS\APPEM.EXE
O4 - HKLM\..\RunServices: [SYSPK32.EXE] C:\WINDOWS\SYSTEM\SYSPK32.EXE
O4 - HKLM\..\RunServices: [D3OJ32.EXE] C:\WINDOWS\D3OJ32.EXE
O4 - HKLM\..\RunServices: [SYSAS.EXE] C:\WINDOWS\SYSTEM\SYSAS.EXE
O4 - HKLM\..\RunServices: [SYSVB.EXE] C:\WINDOWS\SYSVB.EXE
O4 - HKLM\..\RunServices: [JAVAFX.EXE] C:\WINDOWS\JAVAFX.EXE
O4 - HKLM\..\RunServices: [APPOV32.EXE] C:\WINDOWS\APPOV32.EXE
O4 - HKLM\..\RunServices: [IEPA32.EXE] C:\WINDOWS\IEPA32.EXE
O4 - HKLM\..\RunServices: [WINCK32.EXE] C:\WINDOWS\SYSTEM\WINCK32.EXE
O4 - HKLM\..\RunServices: [CRQD.EXE] C:\WINDOWS\SYSTEM\CRQD.EXE
O4 - HKLM\..\RunServices: [MSDP32.EXE] C:\WINDOWS\MSDP32.EXE
O4 - HKLM\..\RunServices: [NTYU.EXE] C:\WINDOWS\NTYU.EXE
O4 - HKLM\..\RunServices: [MSFN32.EXE] C:\WINDOWS\MSFN32.EXE
O4 - HKLM\..\RunServices: [APPAW.EXE] C:\WINDOWS\SYSTEM\APPAW.EXE
O4 - HKLM\..\RunServices: [D3WR.EXE] C:\WINDOWS\SYSTEM\D3WR.EXE
O4 - HKLM\..\RunServices: [JAVAPR.EXE] C:\WINDOWS\SYSTEM\JAVAPR.EXE
O4 - HKLM\..\RunServices: [APPHL32.EXE] C:\WINDOWS\APPHL32.EXE
O4 - HKLM\..\RunServices: [APISC32.EXE] C:\WINDOWS\SYSTEM\APISC32.EXE
O4 - HKLM\..\RunServices: [ATLOL32.EXE] C:\WINDOWS\SYSTEM\ATLOL32.EXE
O4 - HKLM\..\RunServices: [CRBU.EXE] C:\WINDOWS\CRBU.EXE
O4 - HKLM\..\RunServices: [APPRN32.EXE] C:\WINDOWS\SYSTEM\APPRN32.EXE
O4 - HKLM\..\RunServices: [ADDWY.EXE] C:\WINDOWS\SYSTEM\ADDWY.EXE
O4 - HKLM\..\RunServices: [IPWU32.EXE] C:\WINDOWS\SYSTEM\IPWU32.EXE
O4 - HKLM\..\RunServices: [D3HR32.EXE] C:\WINDOWS\SYSTEM\D3HR32.EXE
O4 - HKLM\..\RunServices: [WINWL.EXE] C:\WINDOWS\SYSTEM\WINWL.EXE
O4 - HKLM\..\RunServices: [IEUQ32.EXE] C:\WINDOWS\IEUQ32.EXE
O4 - HKLM\..\RunServices: [APPIW.EXE] C:\WINDOWS\APPIW.EXE
O4 - HKLM\..\RunServices: [NTDX32.EXE] C:\WINDOWS\NTDX32.EXE
O4 - HKLM\..\RunServices: [WINCI32.EXE] C:\WINDOWS\SYSTEM\WINCI32.EXE
O4 - HKLM\..\RunServices: [MSGM32.EXE] C:\WINDOWS\MSGM32.EXE
O4 - HKLM\..\RunServices: [APPIU32.EXE] C:\WINDOWS\APPIU32.EXE
O4 - HKLM\..\RunServices: [IPBQ.EXE] C:\WINDOWS\SYSTEM\IPBQ.EXE
O4 - HKLM\..\RunServices: [ATLGB32.EXE] C:\WINDOWS\SYSTEM\ATLGB32.EXE
O4 - HKLM\..\RunServices: [MSJT.EXE] C:\WINDOWS\SYSTEM\MSJT.EXE
O4 - HKLM\..\RunServices: [ADDNX32.EXE] C:\WINDOWS\SYSTEM\ADDNX32.EXE
O4 - HKLM\..\RunServices: [APPOC.EXE] C:\WINDOWS\APPOC.EXE
O4 - HKLM\..\RunServices: [IPTS.EXE] C:\WINDOWS\SYSTEM\IPTS.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: Shorten URL - http://www.cjb.net/menuext.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O15 - Trusted Zone: http://ad.searchsquire.com
O15 - Trusted Zone: http://search.searchsquire.com
O15 - Trusted Zone: http://update.searchsquire.com
O15 - Trusted Zone: http://www.searchsquire.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: Yahoo! Sheepshead - http://download.game...nts/y/dt0_x.cab
O16 - DPF: Yahoo! Canasta - http://download.game...nts/y/yt1_x.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8118.6022337963
O16 - DPF: {5F05A225-0F66-43DE-89E4-6FFD589C4F04} (Download Coach Installer) - http://www.objectcub...CubeInstall.cab
O16 - DPF: {086A694F-91FB-4068-B44C-124FB69BF05D} - http://www.searchwww.com/search.cab
O16 - DPF: {3717DF57-0396-463D-98B7-647C7DC6898A} - http://delivery.inet....com/inetdl.exe
O16 - DPF: {034CC2DC-3245-4B26-B5C7-7B8777739CB7} - http://64.156.31.98/060112ca.exe
O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-downlo...tsInstaller.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\tfyfbpxw.exe

Im sure there is more to do, and I apprecaite all your help!!!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button