Jump to content


Photo

VX2.betterinternet help please


  • Please log in to reply
7 replies to this topic

#1 flip

flip

    Member

  • New Member
  • Pip
  • 4 posts

Posted 04 June 2004 - 04:10 PM

thats what i got from HJT and when i use ad-aware i get the VX2.betterinternet and ive tried alot of stuff and still cant get it to go away


Logfile of HijackThis v1.97.7
Scan saved at 4:08:25 PM, on 6/4/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\NVSVC.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\SUPPORT.COM\BIN\TGCMD.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\VETMSG9X.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LRKPHD.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ FIREWALL\CA.EXE
C:\PROGRAM FILES\STEAM\STEAM.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ampednews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.ce1.attbb.net:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.ce1.attbb.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch...spx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL/sa
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL (file missing)
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\TWAINTEC.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\TOOLBAR\TOOLBAR.DLL (file missing)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [SAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Vet Alert] C:\WINDOWS\System\VetMsg9x.exe
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETTRAY.EXE
O4 - HKLM\..\Run: [fldnmpsckkre] C:\WINDOWS\SYSTEM\lrkphd.exe
O4 - HKLM\..\Run: [AutoLoaderEnvoloAutoUpdater] "C:\WINDOWS\TEMP\~COMPOUNDINST0\AUTO_UPDATE_LOADER.EXE"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\Run: [ALCHEM] C:\WINDOWS\ALCHEM.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [NVSvc] C:\WINDOWS\SYSTEM\nvsvc.exe -runservice
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O9 - Extra button: AIM (HKLM)
O9 - Extra button: ComcastHSI (HKCU)
O9 - Extra button: Help (HKCU)
O9 - Extra button: Support (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8050.8177083333
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://lw11fd.law11....ex/HMAtchmt.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.ma...ash/swflash.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot....ownload/kdx.cab
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ub...s/GSManager.cab
O16 - DPF: {6697AFA6-1CD3-462E-AC0A-363EF8BCD102} (SyScan2 Control) - http://www.evga.com/...Scan/SyScan.cab
O16 - DPF: {2119776A-F1AD-4FCD-9548-F1E1C615350C} - http://www.stop-sign...op-sign_stp.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.micr...922/wmv9VCM.CAB
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...s/yinst0401.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.8.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://downloads.aaa...d/yesup_acx.exe
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.zestyfind...app/DS4/DS4.cab

Edited by flip, 04 June 2004 - 07:15 PM.


#2 PGPhantom

PGPhantom

    Superman of SWI

  • Emeritus
  • PipPipPipPipPip
  • 3,494 posts

Posted 05 June 2004 - 01:34 AM

Let's do the following theree things first - We'll deal with the rest later:

We need to remove a program called "Twain-Tec". To do this, first you need to disable System restore as per the instructions at here . Twiantec.dll is a transponder. HijackThis will detect it as a BHO but it must not be removed using HijackThis. This is because of the remaining registry entries and files which can be dangerous. Instead the following method of removal is preferable and complete:
Go to "Add/Remove Programs" => Uninstall "Twain-Tech". Reboot the computer to SAFE mode - How do I boot into "Safe" mode?. Delete twaintech.dll and twaintec.ini If twaintech.dll is in use, then you would need to rename it, reboot the computer, and then delete it.

How to Remove CoolWebSearch with CoolWeb Shredder <= Please click on this link for instructions on how to download and use CoolWebSearch Shredder which will help remove a CWS infection on your computer. Make sure you close all programs and windows before running it and be sure to click on the "Fix" button.

Download this: http://www.downloads...g/VX2Finder.exe and run it
  • Click "Click To find Find VX2.Abetterinternet"
  • Delete all files found. You will get a message about "cannot delete this one" matching the same name in the Guardian Key.
  • Click "Open regedit" will take you right to the Guardian Key(no need to search for it)
  • Highlight "Guardian", RightClick and choose Security/permissions, you'll get another window with 'advanced'...DE-select (uncheck) the lower box with "inheritable permissions". Hit 'ok' and 'remove' on the following security prompts.
  • Restart computer.
  • On restart use VX2Finder again, select + delete the last file, click "User Agent$" will remove that entry from the registry.
  • Click "Open regedit" again, this time restoring the checkmark in "inheritable permissions"
  • Click "Guardian.reg" in VX2Finder Deletes the Guardian Key.
  • Use Find again should produce a clean log of blank values.
  • Click "Restore Policy" to restore the Debug policy altered in the look2Me installation.(requires reboot to apply, but not immediatley neccessary)
Please post another HijackThis log into this post once you have completed the three fixes for Twain-Tec, CollWebSearch and Look2Me.

#3 flip

flip

    Member

  • New Member
  • Pip
  • 4 posts

Posted 06 July 2004 - 10:28 AM

"Twain-Tec" was not in my add/remove programs and when i try to use VX2finder it says "This finder is currently on forNT based systems"

#4 PGPhantom

PGPhantom

    Superman of SWI

  • Emeritus
  • PipPipPipPipPip
  • 3,494 posts

Posted 06 July 2004 - 12:35 PM

If you would like help, please read and follow the instructions.

#5 flip

flip

    Member

  • New Member
  • Pip
  • 4 posts

Posted 06 July 2004 - 02:56 PM

ok twain-tec was not in my add/remove programs and the vx2finder worked this time and here is the log:

Log for VX2.BetterInternet File Finder

Files Found---
C:\WINDOWS\SYSTEM\BeTMETER.DLL
C:\WINDOWS\SYSTEM\BfTMETER.DLL
C:\WINDOWS\SYSTEM\CfSYNC.DLL
C:\WINDOWS\SYSTEM\ChBVIEW.DLL
C:\WINDOWS\SYSTEM\CkSYNC.DLL
C:\WINDOWS\SYSTEM\CpMPOBJ.DLL
C:\WINDOWS\SYSTEM\CqBVIEW.DLL
C:\WINDOWS\SYSTEM\CrBVIEW.DLL
C:\WINDOWS\SYSTEM\CtETCFG.DLL
C:\WINDOWS\SYSTEM\CvUTIL.DLL
C:\WINDOWS\SYSTEM\CwBVIEW.DLL
C:\WINDOWS\SYSTEM\CxCFG32.DLL
C:\WINDOWS\SYSTEM\CyFG95.DLL
C:\WINDOWS\SYSTEM\danetlib.dll
C:\WINDOWS\SYSTEM\denetlib.dll
C:\WINDOWS\SYSTEM\dfnetlib.dll
C:\WINDOWS\SYSTEM\dgnetlib.dll
C:\WINDOWS\SYSTEM\dlnetlib.dll
C:\WINDOWS\SYSTEM\dmnetlib.dll
C:\WINDOWS\SYSTEM\dvnetlib.dll
C:\WINDOWS\SYSTEM\DwNIM.DLL
C:\WINDOWS\SYSTEM\dxnetlib.dll
C:\WINDOWS\SYSTEM\HaTPLUG.DLL
C:\WINDOWS\SYSTEM\HfTPLUG.DLL
C:\WINDOWS\SYSTEM\HlTPLUG.DLL
C:\WINDOWS\SYSTEM\HpTPLUG.DLL
C:\WINDOWS\SYSTEM\HqTPLUG.DLL
C:\WINDOWS\SYSTEM\HyTPLUG.DLL
C:\WINDOWS\SYSTEM\IaFRARED.DLL
C:\WINDOWS\SYSTEM\IaSETUP.DLL
C:\WINDOWS\SYSTEM\IcFRARED.DLL
C:\WINDOWS\SYSTEM\IcSETUP.DLL
C:\WINDOWS\SYSTEM\IdFRARED.DLL
C:\WINDOWS\SYSTEM\IdSETUP.DLL
C:\WINDOWS\SYSTEM\IfFRARED.DLL
C:\WINDOWS\SYSTEM\IfSETUP.DLL
C:\WINDOWS\SYSTEM\IgFRARED.DLL
C:\WINDOWS\SYSTEM\IgSETUP.DLL
C:\WINDOWS\SYSTEM\IhFRARED.DLL
C:\WINDOWS\SYSTEM\IhSETUP.DLL
C:\WINDOWS\SYSTEM\IiFRARED.DLL
C:\WINDOWS\SYSTEM\IiSETUP.DLL
C:\WINDOWS\SYSTEM\IjFRARED.DLL
C:\WINDOWS\SYSTEM\IjSETUP.DLL
C:\WINDOWS\SYSTEM\IkFRARED.DLL
C:\WINDOWS\SYSTEM\IkSETUP.DLL
C:\WINDOWS\SYSTEM\IlFRARED.DLL
C:\WINDOWS\SYSTEM\IlSETUP.DLL
C:\WINDOWS\SYSTEM\ImSETUP.DLL
C:\WINDOWS\SYSTEM\IoFRARED.DLL
C:\WINDOWS\SYSTEM\IoSETUP.DLL
C:\WINDOWS\SYSTEM\IpSETUP.DLL
C:\WINDOWS\SYSTEM\IqFRARED.DLL
C:\WINDOWS\SYSTEM\IqSETUP.DLL
C:\WINDOWS\SYSTEM\IrFRARED.DLL
C:\WINDOWS\SYSTEM\IrSETUP.DLL
C:\WINDOWS\SYSTEM\ItFRARED.DLL
C:\WINDOWS\SYSTEM\ItSETUP.DLL
C:\WINDOWS\SYSTEM\IuFRARED.DLL
C:\WINDOWS\SYSTEM\IuSETUP.DLL
C:\WINDOWS\SYSTEM\IvSETUP.DLL
C:\WINDOWS\SYSTEM\IwSETUP.DLL
C:\WINDOWS\SYSTEM\IxFRARED.DLL
C:\WINDOWS\SYSTEM\IxSETUP.DLL
C:\WINDOWS\SYSTEM\IyFRARED.DLL
C:\WINDOWS\SYSTEM\IySETUP.DLL
C:\WINDOWS\SYSTEM\IzFRARED.DLL
C:\WINDOWS\SYSTEM\IzSETUP.DLL
C:\WINDOWS\SYSTEM\JbCRIPT.DLL
C:\WINDOWS\SYSTEM\JdCRIPT.DLL
C:\WINDOWS\SYSTEM\JhCRIPT.DLL
C:\WINDOWS\SYSTEM\JlCRIPT.DLL
C:\WINDOWS\SYSTEM\JqCRIPT.DLL
C:\WINDOWS\SYSTEM\JtCRIPT.DLL
C:\WINDOWS\SYSTEM\JyCRIPT.DLL
C:\WINDOWS\SYSTEM\MaLOCUSR.DLL
C:\WINDOWS\SYSTEM\McLOCUSR.DLL
C:\WINDOWS\SYSTEM\MdLOCUSR.DLL
C:\WINDOWS\SYSTEM\MeLOCUSR.DLL
C:\WINDOWS\SYSTEM\MfLOCUSR.DLL
C:\WINDOWS\SYSTEM\MgLOCUSR.DLL
C:\WINDOWS\SYSTEM\MhLOCUSR.DLL
C:\WINDOWS\SYSTEM\MiLOCUSR.DLL
C:\WINDOWS\SYSTEM\MjLOCUSR.DLL
C:\WINDOWS\SYSTEM\MkLOCUSR.DLL
C:\WINDOWS\SYSTEM\MmLOCUSR.DLL
C:\WINDOWS\SYSTEM\MnLOCUSR.DLL
C:\WINDOWS\SYSTEM\MoLOCUSR.DLL
C:\WINDOWS\SYSTEM\MpLOCUSR.DLL
C:\WINDOWS\SYSTEM\MrLOCUSR.DLL
C:\WINDOWS\SYSTEM\MtLOCUSR.DLL
C:\WINDOWS\SYSTEM\MuLOCUSR.DLL
C:\WINDOWS\SYSTEM\muoert2.dll
C:\WINDOWS\SYSTEM\MvLOCUSR.DLL
C:\WINDOWS\SYSTEM\MwLOCUSR.DLL
C:\WINDOWS\SYSTEM\MxLOCUSR.DLL
C:\WINDOWS\SYSTEM\MyLOCUSR.DLL
C:\WINDOWS\SYSTEM\RaCLTS5.DLL
C:\WINDOWS\SYSTEM\RaCRTP.DLL
C:\WINDOWS\SYSTEM\RbCLTC5.DLL
C:\WINDOWS\SYSTEM\RbCLTS5.DLL
C:\WINDOWS\SYSTEM\RcCLTC5.DLL
C:\WINDOWS\SYSTEM\RdCLTC5.DLL
C:\WINDOWS\SYSTEM\RdCLTS5.DLL
C:\WINDOWS\SYSTEM\ReCLTC5.DLL
C:\WINDOWS\SYSTEM\ReCLTS5.DLL
C:\WINDOWS\SYSTEM\ReCRTP.DLL
C:\WINDOWS\SYSTEM\RfCLTC5.DLL
C:\WINDOWS\SYSTEM\RfCRTP.DLL
C:\WINDOWS\SYSTEM\RhCLTC5.DLL
C:\WINDOWS\SYSTEM\RiCLTC5.DLL
C:\WINDOWS\SYSTEM\RiCRTP.DLL
C:\WINDOWS\SYSTEM\RjCLTC5.DLL
C:\WINDOWS\SYSTEM\RjCLTS5.DLL
C:\WINDOWS\SYSTEM\RkCLTC5.DLL
C:\WINDOWS\SYSTEM\RkCLTS5.DLL
C:\WINDOWS\SYSTEM\RkCRTP.DLL
C:\WINDOWS\SYSTEM\RlCLTC5.DLL
C:\WINDOWS\SYSTEM\RlCLTS5.DLL
C:\WINDOWS\SYSTEM\RmCLTC5.DLL
C:\WINDOWS\SYSTEM\RmCLTS5.DLL
C:\WINDOWS\SYSTEM\RoCLTS5.DLL
C:\WINDOWS\SYSTEM\RqCLTC5.DLL
C:\WINDOWS\SYSTEM\RqCLTS5.DLL
C:\WINDOWS\SYSTEM\RrCLTC5.DLL
C:\WINDOWS\SYSTEM\RsCLTC5.DLL
C:\WINDOWS\SYSTEM\RtCLTC5.DLL
C:\WINDOWS\SYSTEM\RuCLTC5.DLL
C:\WINDOWS\SYSTEM\RvCLTC5.DLL
C:\WINDOWS\SYSTEM\RvCLTS5.DLL
C:\WINDOWS\SYSTEM\RxCLTC5.DLL
C:\WINDOWS\SYSTEM\RxCLTS5.DLL
C:\WINDOWS\SYSTEM\RyCLTC5.DLL
C:\WINDOWS\SYSTEM\RyCLTS5.DLL
C:\WINDOWS\SYSTEM\RzCLTC5.DLL
C:\WINDOWS\SYSTEM\RzCLTS5.DLL
C:\WINDOWS\SYSTEM\SaDOCVW.DLL
C:\WINDOWS\SYSTEM\SdLWAPI.DLL
C:\WINDOWS\SYSTEM\SoDOCVW.DLL
C:\WINDOWS\SYSTEM\SwDOCVW.DLL
C:\WINDOWS\SYSTEM\UaBUI.DLL
C:\WINDOWS\SYSTEM\UcBUI.DLL
C:\WINDOWS\SYSTEM\UdBUI.DLL
C:\WINDOWS\SYSTEM\UeBUI.DLL
C:\WINDOWS\SYSTEM\UfBUI.DLL
C:\WINDOWS\SYSTEM\UhBUI.DLL
C:\WINDOWS\SYSTEM\UjBUI.DLL
C:\WINDOWS\SYSTEM\UlBUI.DLL
C:\WINDOWS\SYSTEM\UnBUI.DLL
C:\WINDOWS\SYSTEM\UpBUI.DLL
C:\WINDOWS\SYSTEM\UqBUI.DLL
C:\WINDOWS\SYSTEM\UrBUI.DLL
C:\WINDOWS\SYSTEM\UtBUI.DLL
C:\WINDOWS\SYSTEM\UuBUI.DLL
C:\WINDOWS\SYSTEM\UvBUI.DLL
C:\WINDOWS\SYSTEM\UwBUI.DLL
C:\WINDOWS\SYSTEM\UyBUI.DLL
C:\WINDOWS\SYSTEM\VbWWDM32.DLL
C:\WINDOWS\SYSTEM\VdWWDM32.DLL
C:\WINDOWS\SYSTEM\VeWWDM32.DLL
C:\WINDOWS\SYSTEM\VhWWDM32.DLL
C:\WINDOWS\SYSTEM\ViWWDM32.DLL
C:\WINDOWS\SYSTEM\VjWWDM32.DLL
C:\WINDOWS\SYSTEM\VkWWDM32.DLL
C:\WINDOWS\SYSTEM\VlWWDM32.DLL
C:\WINDOWS\SYSTEM\VmWWDM32.DLL
C:\WINDOWS\SYSTEM\VpWWDM32.DLL
C:\WINDOWS\SYSTEM\VrWWDM32.DLL
C:\WINDOWS\SYSTEM\VsWWDM32.DLL
C:\WINDOWS\SYSTEM\VvWWDM32.DLL
C:\WINDOWS\SYSTEM\VwWWDM32.DLL
C:\WINDOWS\SYSTEM\VxWWDM32.DLL
C:\WINDOWS\SYSTEM\VzWWDM32.DLL
C:\WINDOWS\SYSTEM\WbNINET.DLL
C:\WINDOWS\SYSTEM\WfNINET.DLL
C:\WINDOWS\SYSTEM\WgNINET.DLL
C:\WINDOWS\SYSTEM\WiBCHECK.DLL
C:\WINDOWS\SYSTEM\WjNINET.DLL
C:\WINDOWS\SYSTEM\WqNINET.DLL
C:\WINDOWS\SYSTEM\WsNINET.DLL
C:\WINDOWS\SYSTEM\WwNINET.DLL
C:\WINDOWS\SYSTEM\WxBCHECK.DLL


User Agent String---
{84219F6B-BA3B-4549-BB3A-DBCFCF366B52}

#6 flip

flip

    Member

  • New Member
  • Pip
  • 4 posts

Posted 06 July 2004 - 03:00 PM

and when i try to delete those files i get errors and then my computer freezes

#7 PGPhantom

PGPhantom

    Superman of SWI

  • Emeritus
  • PipPipPipPipPip
  • 3,494 posts

Posted 07 July 2004 - 12:06 PM

Try booting into safe mode ... How do I boot into "Safe" mode?.

From there run through the procedure ... Using Ad-Aware - Pay specific attention to adding the VX2 plug in for ad-aware.

#8 Jay23

Jay23

    Member

  • New Member
  • Pip
  • 1 posts

Posted 06 October 2004 - 12:38 PM

Try booting into safe mode ... How do I boot into "Safe" mode?

From there run through the procedure ... Using Ad-Aware - Pay specific attention to adding the VX2 plug in for ad-aware.

View Post



Does anyone know how this ended? I have many of the same problems in this thread and want to run through the process tonight. The comment about the PC locking after the file deletion was a concern.

Jay23




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button