Jump to content


Photo

Help please, my home page has been hijacked!


  • This topic is locked This topic is locked
11 replies to this topic

#1 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 16 June 2004 - 01:45 PM

Hello everyone! I am new to this forum and would like to say thank you for all the help everyone has been contributing to remove these spywares. They really are a pain in the butt. You guys have been doing an awesome job.

Now to the point. I have read the FAQ's about what to do first, but I'm really scared to fix anything from the HijackThis log. I fear I might remove some important files or whatnot. So I'm asking you guys to please fix my problem. I have HomeSearch as my Internet Explorer home page and everytime I change it to something else, it would change it back to Home Search. Also, while I'm surfing, I would be getting really annoying and nasty popups such as pornography and whatnot. I've been trying to fix it, but being a rookie, I can not fix the problem. I have run Adaware and Spybot already to remove any spyware, but the problem still remains. Here is my HijackThis log. I hope you guys can find the time to fix my problem. Thanks a bunch! It is very much appreciated.


Logfile of HijackThis v1.97.7
Scan saved at 11:41:18 AM, on 6/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\apiwa.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\apikw.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\rage3dtweak\gameutil.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cuong Huynh\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\brdbm.dll/sp.html#628582961
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://brdbm.dll/index.html#628582961
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\brdbm.dll/sp.html#628582961
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://brdbm.dll/index.html#628582961
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\brdbm.dll/sp.html#628582961
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {F4B038DE-77A5-45A4-0B4D-EEBA715F1EA7} - C:\WINDOWS\apisv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RegTweak] C:\Program Files\Rage3DTweak\RegTwk.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [crhy.exe] C:\WINDOWS\system32\crhy.exe
O4 - HKLM\..\Run: [mfcis32.exe] C:\WINDOWS\system32\mfcis32.exe
O4 - HKLM\..\Run: [apikw.exe] C:\WINDOWS\system32\apikw.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - HKLM\..\RunOnce: [ipxu32.exe] C:\WINDOWS\system32\ipxu32.exe
O4 - HKLM\..\RunOnce: [crcw32.exe] C:\WINDOWS\crcw32.exe
O4 - HKLM\..\RunOnce: [crty.exe] C:\WINDOWS\crty.exe
O4 - HKLM\..\RunOnce: [sysrf32.exe] C:\WINDOWS\sysrf32.exe
O4 - Global Startup: gameutil.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WallSmart!.lnk = C:\Program Files\MediaKritet\WallSmart\WallSmart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ATI TV (HKLM)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...B?38134.9434375
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

Edited by luvpkl, 16 June 2004 - 02:59 PM.


#2 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 16 June 2004 - 02:52 PM

bump

#3 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 16 June 2004 - 02:53 PM

bump

Now my internet is getting totally slow :(

edit: sorry, didn't mean to bump twice. My internet is acting really screwy.

Edited by luvpkl, 16 June 2004 - 02:55 PM.


#4 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 16 June 2004 - 05:22 PM

bump

#5 Bugbatter

Bugbatter

    Forum Deity

  • Trusted Advisor
  • PipPipPipPipPip
  • 939 posts

Posted 16 June 2004 - 09:08 PM

Hi, luvplk,

Please Download CoolWebShredder, from http://www.zerosreal.../CWShredder.zip or http://www.spywarein.../cwshredder.zip
Extract CWShredder to its own folder, Reboot in Safe Mode*** and run the program. Click the 'Fix ->' button. Make sure you let it fix all CWS Remnants. Afterwards Reboot.

Please download AdAware, a good anti-spyware program from http://www.computerc...s-file-292.html
Install by double-clicking on the downloaded file.
After installing but before running, update Ad-aware by using its Globe icon.
After updating, shutdown and restart Ad-aware.
Ad-aware is ready to scan and clean your system following these steps:

Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
"Unload recognized processes during scanning."
Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
"Let Windows remove files in use after reboot."
Press "Scan Now"
Check option "Use Custom scanning options"
Check option "Activate In-Depth Scan"
Press "Select drives\folders to scan"
Select the active partition which is usually C:
Press "Next" to let Ad-aware scan your drives...
If it finds "bad" files and registry keys, press "Next" again
Right-click in that pane and choose "Select All"
Press "Next"
When it asks to remove all checked items, Press "OK"
Close Ad-aware, reboot your computer and go on to the step below.


Please download Spybot: Search and Destroy from http://www.computerc...s-file-108.html
Install by double-clicking on the downloaded file.
Run Spybot S&D from desktop icon or Start menu.
Press "Search for updates" button to get list of updates available.
Press "Download updates" button.
Close all IE windows and close & restart Spybot S&D.
Press "Check for Problems" button.
Have SpyBot remove all it marks in RED by pressing "Fix Selected Problems".
Close Spybot S&D, reboot your computer.

Scan with HJT and please post a fresh log.
Microsoft MVP - Consumer Security

#6 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 16 June 2004 - 10:02 PM

Hi Bugbatter,

Thanks for helping me out so much! While I was waiting for some help, I decided to go fix my problem alone despite being a noobie at it. I tracked down all the .exe and .dll files (I hope) and removed everything. I also used HijackThis, Adaware, and Spybot to clean out everything. To my surprise, my homepage now is back to normal, and my internet seems back up to speed!!!! Here is my HJT log just in case I'm missing out on something else.

edit: As you can see, I did a lot of deleting after my first HJT log. :) I think I've gotten rid of the problem that many have recently got, which is when the homepage gets hijacked.

Logfile of HijackThis v1.97.7
Scan saved at 7:56:43 PM, on 6/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\rage3dtweak\gameutil.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RegTweak] C:\Program Files\Rage3DTweak\RegTwk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - Global Startup: gameutil.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WallSmart!.lnk = C:\Program Files\MediaKritet\WallSmart\WallSmart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ATI TV (HKLM)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...B?38134.9434375
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

Edited by luvpkl, 16 June 2004 - 10:05 PM.


#7 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 16 June 2004 - 10:20 PM

These are the steps to cure the problem that I had. I think many would find this useful.

1) Use Bugbatter's suggestion in this thread
2) Look at your task manager for any suspicious .exe files that are running. Write them down. End the processes.
3) Go to start > search > all files and folder > "insert file names that you wrote down here"
4) Delete all these files
5) Run Hijackthis and post the log in this thread for further examination.

********** IMPORTANT ***********
1) make sure that you bookmark this website

2) When you load up your internet browser, go to start < my computer < your c dirve or whatever it is < documents and settings < folder with your name ie. jack < favorites < and click on the file with the link to this website

I did step 2 because I noticed if I just clicked the internet explorer browser on my desktop I will be creating another one of those .dll monsters :grrr:

#8 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 16 June 2004 - 10:51 PM

I've been surfing the internet and reloading the internet browser and so far there have been no problems. So I guess I've fixed it. The only thing that irks me now is that I have this program called "Home Search Assistant" listed in the "Add or Remove Programs" that I can not get rid of. Does anyone know of a program or something that will get rid of it?
Thanks

#9 Bugbatter

Bugbatter

    Forum Deity

  • Trusted Advisor
  • PipPipPipPipPip
  • 939 posts

Posted 17 June 2004 - 12:24 PM

Good work! Is your computer configured to "Show All Files and Folders"?
I would have mentioned that in my next steps -- before searching for those bad files.

To remove unwanted entries listed in Add/Remove read Backup the registry. HOW:http://www.annoyances.org/exec/show/registry

Then proceed with:Run the Registry Editor (REGEDIT.EXE).
Open HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Uninstall.
Remove any unwanted keys under "Uninstall."

Reboot into Safemode, run HJT.

If you did not intentionally install this and do not know what it is, check this for fixing:
O4 - Global Startup: gameutil.exe.lnk = ?

I could find no information on this one. If you do not know what it is, please check it to be fixed:
O4 - Global Startup: WallSmart!.lnk = C:\Program Files\MediaKritet\WallSmart\WallSmart.exe

Optional: These items do not need to be running at Startup and are optional to fix:
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

Reboot and please post a fresh log so we can be sure some hidden .DLL is not still active.
Tip* If you don't use Windows Messenger, you can disable it as follows: Start -> Programs -> Windows Messenger -> Tools -> Options -> Preferences. Uncheck "Run this program when Windows Starts". All this stuff running in the background uses resources.

Finally, empty your temporary internet files and history via "Tools" in IE.

After something like this it is also a good idea to flush the Restore Points and start fresh.
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)

Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.

Reboot. Go back in and turn System Restore back on. A new Restore Point will be created.

That should do it!
Microsoft MVP - Consumer Security

#10 luvpkl

luvpkl

    Member

  • Full Member
  • Pip
  • 24 posts

Posted 17 June 2004 - 05:50 PM

Hi again Bugbatter,

I followed all your instructions and everything was fine.
These two right here that you pointed out are programs that I have running so I am aware of them:
O4 - Global Startup: gameutil.exe.lnk = ?
O4 - Global Startup: WallSmart!.lnk = C:\Program Files\MediaKritet\WallSmart\WallSmart.exe


Here is my new HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 3:40:27 PM, on 6/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Rage3DTweak\RegTwk.exe
C:\Program Files\rage3dtweak\gameutil.exe
C:\Program Files\MediaKritet\WallSmart\WallSmart.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [RegTweak] C:\Program Files\Rage3DTweak\RegTwk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - Global Startup: gameutil.exe.lnk = ?
O4 - Global Startup: WallSmart!.lnk = C:\Program Files\MediaKritet\WallSmart\WallSmart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ATI TV (HKLM)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...B?38134.9434375
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab


I hope everything seems right. Thank you very much for your help!

#11 Bugbatter

Bugbatter

    Forum Deity

  • Trusted Advisor
  • PipPipPipPipPip
  • 939 posts

Posted 17 June 2004 - 06:06 PM

You are very welcome. You did a great job! It looks clean. :D
Microsoft MVP - Consumer Security

#12 dave38

dave38

    Devout Murphyite!

  • Emeritus
  • PipPipPipPipPip
  • 8,508 posts

Posted 03 August 2004 - 02:21 PM

Glad we could help!

If you need this topic reopened, please request this by sending the moderating team an email with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
Be wary of strong drink. It may make you shoot at tax collectors, and miss!
Please support SWI forum




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button