• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
flip

VX2.betterinternet help please

8 posts in this topic

thats what i got from HJT and when i use ad-aware i get the VX2.betterinternet and ive tried alot of stuff and still cant get it to go away

 

 

Logfile of HijackThis v1.97.7

Scan saved at 4:08:25 PM, on 6/4/2004

Platform: Windows ME (Win9x 4.90.3000)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL

C:\WINDOWS\SYSTEM\MSGSRV32.EXE

C:\WINDOWS\SYSTEM\mmtask.tsk

C:\WINDOWS\SYSTEM\MPREXE.EXE

C:\WINDOWS\SYSTEM\MSTASK.EXE

C:\WINDOWS\SYSTEM\NVSVC.EXE

C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE

C:\WINDOWS\SYSTEM\DEVLDR16.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\RUNDLL32.EXE

C:\WINDOWS\TASKMON.EXE

C:\WINDOWS\SYSTEM\SYSTRAY.EXE

C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE

C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE

C:\PROGRAM FILES\SUPPORT.COM\BIN\TGCMD.EXE

C:\WINDOWS\LOADQM.EXE

C:\WINDOWS\SYSTEM\VETMSG9X.EXE

C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETTRAY.EXE

C:\WINDOWS\SYSTEM\WMIEXE.EXE

C:\WINDOWS\SYSTEM\LRKPHD.EXE

C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ FIREWALL\CA.EXE

C:\PROGRAM FILES\STEAM\STEAM.EXE

C:\WINDOWS\RUNDLL32.EXE

C:\WINDOWS\SYSTEM\DDHELP.EXE

C:\WINDOWS\SYSTEM\SPOOL32.EXE

C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE

C:\WINDOWS\SYSTEM\PSTORES.EXE

C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ampednews.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.ce1.attbb.net:8000

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.ce1.attbb.net

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa

R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL (file missing)

O1 - Hosts: 207.36.196.189 auto.search.msn.com

O1 - Hosts: 207.36.196.189 search.netscape.com

O1 - Hosts: 207.36.196.189 ieautosearch

O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\TWAINTEC.DLL

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL (file missing)

O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun

O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe

O4 - HKLM\..\Run: [systemTray] SysTray.Exe

O4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

O4 - HKLM\..\Run: [sAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck

O4 - HKLM\..\Run: [sAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"

O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [LoadQM] loadqm.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime

O4 - HKLM\..\Run: [Vet Alert] C:\WINDOWS\System\VetMsg9x.exe

O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETTRAY.EXE

O4 - HKLM\..\Run: [fldnmpsckkre] C:\WINDOWS\SYSTEM\lrkphd.exe

O4 - HKLM\..\Run: [AutoLoaderEnvoloAutoUpdater] "C:\WINDOWS\TEMP\~COMPOUNDINST0\AUTO_UPDATE_LOADER.EXE"

O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe

O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe

O4 - HKLM\..\Run: [ALCHEM] C:\WINDOWS\ALCHEM.exe

O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe

O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe

O4 - HKLM\..\RunServices: [NVSvc] C:\WINDOWS\SYSTEM\nvsvc.exe -runservice

O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service

O4 - HKCU\..\Run: [steam] "c:\program files\steam\steam.exe" -silent

O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1

O9 - Extra button: AIM (HKLM)

O9 - Extra button: ComcastHSI (HKCU)

O9 - Extra button: Help (HKCU)

O9 - Extra button: Support (HKCU)

O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...8050.8177083333

O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw11fd.law11.hotmail.msn.com/activex/HMAtchmt.ocx

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab

O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab

O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab

O16 - DPF: {6697AFA6-1CD3-462E-AC0A-363EF8BCD102} (SyScan2 Control) - http://www.evga.com/Support/SyScan/SyScan.cab

O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} - http://www.stop-sign.com/pub/download/stop-sign_stp.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab

O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...s/yinst0401.cab

O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr...etup1.0.0.8.cab

O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab

O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://downloads.aaa1screensavers.com/download/yesup_acx.exe

O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.zestyfind.com/app/DS4/DS4.cab

Edited by flip

Share this post


Link to post
Share on other sites

Let's do the following theree things first - We'll deal with the rest later:

 

We need to remove a program called "Twain-Tec". To do this, first you need to disable System restore as per the instructions at here . Twiantec.dll is a transponder. HijackThis will detect it as a BHO but it must not be removed using HijackThis. This is because of the remaining registry entries and files which can be dangerous. Instead the following method of removal is preferable and complete:

Go to "Add/Remove Programs" => Uninstall "Twain-Tech". Reboot the computer to SAFE mode - How do I boot into "Safe" mode?. Delete twaintech.dll and twaintec.ini If twaintech.dll is in use, then you would need to rename it, reboot the computer, and then delete it.

 

How to Remove CoolWebSearch with CoolWeb Shredder <= Please click on this link for instructions on how to download and use CoolWebSearch Shredder which will help remove a CWS infection on your computer. Make sure you close all programs and windows before running it and be sure to click on the "Fix" button.

 

Download this: http://www.downloads.subratam.org/VX2Finder.exe and run it

  1. Click "Click To find Find VX2.Abetterinternet"
  2. Delete all files found. You will get a message about "cannot delete this one" matching the same name in the Guardian Key.
  3. Click "Open regedit" will take you right to the Guardian Key(no need to search for it)
  4. Highlight "Guardian", RightClick and choose Security/permissions, you'll get another window with 'advanced'...DE-select (uncheck) the lower box with "inheritable permissions". Hit 'ok' and 'remove' on the following security prompts.
  5. Restart computer.
  6. On restart use VX2Finder again, select + delete the last file, click "User Agent$" will remove that entry from the registry.
  7. Click "Open regedit" again, this time restoring the checkmark in "inheritable permissions"
  8. Click "Guardian.reg" in VX2Finder Deletes the Guardian Key.
  9. Use Find again should produce a clean log of blank values.
  10. Click "Restore Policy" to restore the Debug policy altered in the look2Me installation.(requires reboot to apply, but not immediatley neccessary)

Please post another HijackThis log into this post once you have completed the three fixes for Twain-Tec, CollWebSearch and Look2Me.

Share this post


Link to post
Share on other sites

"Twain-Tec" was not in my add/remove programs and when i try to use VX2finder it says "This finder is currently on forNT based systems"

Share this post


Link to post
Share on other sites

ok twain-tec was not in my add/remove programs and the vx2finder worked this time and here is the log:

 

Log for VX2.BetterInternet File Finder

 

Files Found---

C:\WINDOWS\SYSTEM\BeTMETER.DLL

C:\WINDOWS\SYSTEM\BfTMETER.DLL

C:\WINDOWS\SYSTEM\CfSYNC.DLL

C:\WINDOWS\SYSTEM\ChBVIEW.DLL

C:\WINDOWS\SYSTEM\CkSYNC.DLL

C:\WINDOWS\SYSTEM\CpMPOBJ.DLL

C:\WINDOWS\SYSTEM\CqBVIEW.DLL

C:\WINDOWS\SYSTEM\CrBVIEW.DLL

C:\WINDOWS\SYSTEM\CtETCFG.DLL

C:\WINDOWS\SYSTEM\CvUTIL.DLL

C:\WINDOWS\SYSTEM\CwBVIEW.DLL

C:\WINDOWS\SYSTEM\CxCFG32.DLL

C:\WINDOWS\SYSTEM\CyFG95.DLL

C:\WINDOWS\SYSTEM\danetlib.dll

C:\WINDOWS\SYSTEM\denetlib.dll

C:\WINDOWS\SYSTEM\dfnetlib.dll

C:\WINDOWS\SYSTEM\dgnetlib.dll

C:\WINDOWS\SYSTEM\dlnetlib.dll

C:\WINDOWS\SYSTEM\dmnetlib.dll

C:\WINDOWS\SYSTEM\dvnetlib.dll

C:\WINDOWS\SYSTEM\DwNIM.DLL

C:\WINDOWS\SYSTEM\dxnetlib.dll

C:\WINDOWS\SYSTEM\HaTPLUG.DLL

C:\WINDOWS\SYSTEM\HfTPLUG.DLL

C:\WINDOWS\SYSTEM\HlTPLUG.DLL

C:\WINDOWS\SYSTEM\HpTPLUG.DLL

C:\WINDOWS\SYSTEM\HqTPLUG.DLL

C:\WINDOWS\SYSTEM\HyTPLUG.DLL

C:\WINDOWS\SYSTEM\IaFRARED.DLL

C:\WINDOWS\SYSTEM\IaSETUP.DLL

C:\WINDOWS\SYSTEM\IcFRARED.DLL

C:\WINDOWS\SYSTEM\IcSETUP.DLL

C:\WINDOWS\SYSTEM\IdFRARED.DLL

C:\WINDOWS\SYSTEM\IdSETUP.DLL

C:\WINDOWS\SYSTEM\IfFRARED.DLL

C:\WINDOWS\SYSTEM\IfSETUP.DLL

C:\WINDOWS\SYSTEM\IgFRARED.DLL

C:\WINDOWS\SYSTEM\IgSETUP.DLL

C:\WINDOWS\SYSTEM\IhFRARED.DLL

C:\WINDOWS\SYSTEM\IhSETUP.DLL

C:\WINDOWS\SYSTEM\IiFRARED.DLL

C:\WINDOWS\SYSTEM\IiSETUP.DLL

C:\WINDOWS\SYSTEM\IjFRARED.DLL

C:\WINDOWS\SYSTEM\IjSETUP.DLL

C:\WINDOWS\SYSTEM\IkFRARED.DLL

C:\WINDOWS\SYSTEM\IkSETUP.DLL

C:\WINDOWS\SYSTEM\IlFRARED.DLL

C:\WINDOWS\SYSTEM\IlSETUP.DLL

C:\WINDOWS\SYSTEM\ImSETUP.DLL

C:\WINDOWS\SYSTEM\IoFRARED.DLL

C:\WINDOWS\SYSTEM\IoSETUP.DLL

C:\WINDOWS\SYSTEM\IpSETUP.DLL

C:\WINDOWS\SYSTEM\IqFRARED.DLL

C:\WINDOWS\SYSTEM\IqSETUP.DLL

C:\WINDOWS\SYSTEM\IrFRARED.DLL

C:\WINDOWS\SYSTEM\IrSETUP.DLL

C:\WINDOWS\SYSTEM\ItFRARED.DLL

C:\WINDOWS\SYSTEM\ItSETUP.DLL

C:\WINDOWS\SYSTEM\IuFRARED.DLL

C:\WINDOWS\SYSTEM\IuSETUP.DLL

C:\WINDOWS\SYSTEM\IvSETUP.DLL

C:\WINDOWS\SYSTEM\IwSETUP.DLL

C:\WINDOWS\SYSTEM\IxFRARED.DLL

C:\WINDOWS\SYSTEM\IxSETUP.DLL

C:\WINDOWS\SYSTEM\IyFRARED.DLL

C:\WINDOWS\SYSTEM\IySETUP.DLL

C:\WINDOWS\SYSTEM\IzFRARED.DLL

C:\WINDOWS\SYSTEM\IzSETUP.DLL

C:\WINDOWS\SYSTEM\JbCRIPT.DLL

C:\WINDOWS\SYSTEM\JdCRIPT.DLL

C:\WINDOWS\SYSTEM\JhCRIPT.DLL

C:\WINDOWS\SYSTEM\JlCRIPT.DLL

C:\WINDOWS\SYSTEM\JqCRIPT.DLL

C:\WINDOWS\SYSTEM\JtCRIPT.DLL

C:\WINDOWS\SYSTEM\JyCRIPT.DLL

C:\WINDOWS\SYSTEM\MaLOCUSR.DLL

C:\WINDOWS\SYSTEM\McLOCUSR.DLL

C:\WINDOWS\SYSTEM\MdLOCUSR.DLL

C:\WINDOWS\SYSTEM\MeLOCUSR.DLL

C:\WINDOWS\SYSTEM\MfLOCUSR.DLL

C:\WINDOWS\SYSTEM\MgLOCUSR.DLL

C:\WINDOWS\SYSTEM\MhLOCUSR.DLL

C:\WINDOWS\SYSTEM\MiLOCUSR.DLL

C:\WINDOWS\SYSTEM\MjLOCUSR.DLL

C:\WINDOWS\SYSTEM\MkLOCUSR.DLL

C:\WINDOWS\SYSTEM\MmLOCUSR.DLL

C:\WINDOWS\SYSTEM\MnLOCUSR.DLL

C:\WINDOWS\SYSTEM\MoLOCUSR.DLL

C:\WINDOWS\SYSTEM\MpLOCUSR.DLL

C:\WINDOWS\SYSTEM\MrLOCUSR.DLL

C:\WINDOWS\SYSTEM\MtLOCUSR.DLL

C:\WINDOWS\SYSTEM\MuLOCUSR.DLL

C:\WINDOWS\SYSTEM\muoert2.dll

C:\WINDOWS\SYSTEM\MvLOCUSR.DLL

C:\WINDOWS\SYSTEM\MwLOCUSR.DLL

C:\WINDOWS\SYSTEM\MxLOCUSR.DLL

C:\WINDOWS\SYSTEM\MyLOCUSR.DLL

C:\WINDOWS\SYSTEM\RaCLTS5.DLL

C:\WINDOWS\SYSTEM\RaCRTP.DLL

C:\WINDOWS\SYSTEM\RbCLTC5.DLL

C:\WINDOWS\SYSTEM\RbCLTS5.DLL

C:\WINDOWS\SYSTEM\RcCLTC5.DLL

C:\WINDOWS\SYSTEM\RdCLTC5.DLL

C:\WINDOWS\SYSTEM\RdCLTS5.DLL

C:\WINDOWS\SYSTEM\ReCLTC5.DLL

C:\WINDOWS\SYSTEM\ReCLTS5.DLL

C:\WINDOWS\SYSTEM\ReCRTP.DLL

C:\WINDOWS\SYSTEM\RfCLTC5.DLL

C:\WINDOWS\SYSTEM\RfCRTP.DLL

C:\WINDOWS\SYSTEM\RhCLTC5.DLL

C:\WINDOWS\SYSTEM\RiCLTC5.DLL

C:\WINDOWS\SYSTEM\RiCRTP.DLL

C:\WINDOWS\SYSTEM\RjCLTC5.DLL

C:\WINDOWS\SYSTEM\RjCLTS5.DLL

C:\WINDOWS\SYSTEM\RkCLTC5.DLL

C:\WINDOWS\SYSTEM\RkCLTS5.DLL

C:\WINDOWS\SYSTEM\RkCRTP.DLL

C:\WINDOWS\SYSTEM\RlCLTC5.DLL

C:\WINDOWS\SYSTEM\RlCLTS5.DLL

C:\WINDOWS\SYSTEM\RmCLTC5.DLL

C:\WINDOWS\SYSTEM\RmCLTS5.DLL

C:\WINDOWS\SYSTEM\RoCLTS5.DLL

C:\WINDOWS\SYSTEM\RqCLTC5.DLL

C:\WINDOWS\SYSTEM\RqCLTS5.DLL

C:\WINDOWS\SYSTEM\RrCLTC5.DLL

C:\WINDOWS\SYSTEM\RsCLTC5.DLL

C:\WINDOWS\SYSTEM\RtCLTC5.DLL

C:\WINDOWS\SYSTEM\RuCLTC5.DLL

C:\WINDOWS\SYSTEM\RvCLTC5.DLL

C:\WINDOWS\SYSTEM\RvCLTS5.DLL

C:\WINDOWS\SYSTEM\RxCLTC5.DLL

C:\WINDOWS\SYSTEM\RxCLTS5.DLL

C:\WINDOWS\SYSTEM\RyCLTC5.DLL

C:\WINDOWS\SYSTEM\RyCLTS5.DLL

C:\WINDOWS\SYSTEM\RzCLTC5.DLL

C:\WINDOWS\SYSTEM\RzCLTS5.DLL

C:\WINDOWS\SYSTEM\SaDOCVW.DLL

C:\WINDOWS\SYSTEM\SdLWAPI.DLL

C:\WINDOWS\SYSTEM\SoDOCVW.DLL

C:\WINDOWS\SYSTEM\SwDOCVW.DLL

C:\WINDOWS\SYSTEM\UaBUI.DLL

C:\WINDOWS\SYSTEM\UcBUI.DLL

C:\WINDOWS\SYSTEM\UdBUI.DLL

C:\WINDOWS\SYSTEM\UeBUI.DLL

C:\WINDOWS\SYSTEM\UfBUI.DLL

C:\WINDOWS\SYSTEM\UhBUI.DLL

C:\WINDOWS\SYSTEM\UjBUI.DLL

C:\WINDOWS\SYSTEM\UlBUI.DLL

C:\WINDOWS\SYSTEM\UnBUI.DLL

C:\WINDOWS\SYSTEM\UpBUI.DLL

C:\WINDOWS\SYSTEM\UqBUI.DLL

C:\WINDOWS\SYSTEM\UrBUI.DLL

C:\WINDOWS\SYSTEM\UtBUI.DLL

C:\WINDOWS\SYSTEM\UuBUI.DLL

C:\WINDOWS\SYSTEM\UvBUI.DLL

C:\WINDOWS\SYSTEM\UwBUI.DLL

C:\WINDOWS\SYSTEM\UyBUI.DLL

C:\WINDOWS\SYSTEM\VbWWDM32.DLL

C:\WINDOWS\SYSTEM\VdWWDM32.DLL

C:\WINDOWS\SYSTEM\VeWWDM32.DLL

C:\WINDOWS\SYSTEM\VhWWDM32.DLL

C:\WINDOWS\SYSTEM\ViWWDM32.DLL

C:\WINDOWS\SYSTEM\VjWWDM32.DLL

C:\WINDOWS\SYSTEM\VkWWDM32.DLL

C:\WINDOWS\SYSTEM\VlWWDM32.DLL

C:\WINDOWS\SYSTEM\VmWWDM32.DLL

C:\WINDOWS\SYSTEM\VpWWDM32.DLL

C:\WINDOWS\SYSTEM\VrWWDM32.DLL

C:\WINDOWS\SYSTEM\VsWWDM32.DLL

C:\WINDOWS\SYSTEM\VvWWDM32.DLL

C:\WINDOWS\SYSTEM\VwWWDM32.DLL

C:\WINDOWS\SYSTEM\VxWWDM32.DLL

C:\WINDOWS\SYSTEM\VzWWDM32.DLL

C:\WINDOWS\SYSTEM\WbNINET.DLL

C:\WINDOWS\SYSTEM\WfNINET.DLL

C:\WINDOWS\SYSTEM\WgNINET.DLL

C:\WINDOWS\SYSTEM\WiBCHECK.DLL

C:\WINDOWS\SYSTEM\WjNINET.DLL

C:\WINDOWS\SYSTEM\WqNINET.DLL

C:\WINDOWS\SYSTEM\WsNINET.DLL

C:\WINDOWS\SYSTEM\WwNINET.DLL

C:\WINDOWS\SYSTEM\WxBCHECK.DLL

 

 

User Agent String---

{84219F6B-BA3B-4549-BB3A-DBCFCF366B52}

Share this post


Link to post
Share on other sites
Try booting into safe mode ... How do I boot into "Safe" mode?

 

From there run through the procedure ... Using Ad-Aware - Pay specific attention to adding the VX2 plug in for ad-aware.

51378[/snapback]

 

 

Does anyone know how this ended? I have many of the same problems in this thread and want to run through the process tonight. The comment about the PC locking after the file deletion was a concern.

 

Jay23

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0