1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

help with hijack this log plese

Discussion in 'Security and Privacy' started by newdawnuk, 2004/08/23.

Thread Status:
Not open for further replies.
  1. 2004/08/23
    newdawnuk

    newdawnuk Inactive Thread Starter

    Joined:
    2004/08/21
    Messages:
    4
    Likes Received:
    0
    hi im new but having same problem as paddy inan earlier post, i hav removed msnplus but having problem with the new search bar that pops up at bottom of screen , here is the log that hijack this found, can somebody in the know help me with it plese . thanks in advance
    hi , im new here and am having same problem as paddy here is a copy of my hijack this log what do i need to delete
    thanks in advance
    Logfile of HijackThis v1.98.2
    Scan saved at 09:48:55, on 23/08/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    F:\WINDOWS\system32\spoolsv.exe
    F:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
    F:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
    F:\WINDOWS\System32\nvsvc32.exe
    F:\WINDOWS\Explorer.EXE
    F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    F:\WINDOWS\system32\ZoneLabs\vsmon.exe
    F:\Program Files\Common Files\Symantec Shared\ccApp.exe
    F:\Program Files\Winamp\winampa.exe
    F:\Program Files\Messenger Plus! 3\MsgPlus.exe
    F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    F:\WINDOWS\System32\ctfmon.exe
    F:\Program Files\Spyware Doctor\spydoctor.exe
    F:\Program Files\Messenger\msmsgs.exe
    f:\progra~1\intern~1\iexplore.exe
    F:\Program Files\Internet Explorer\iexplore.exe
    F:\Program Files\MSN Messenger\msnmsgr.exe
    F:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
    F:\Program Files\MSN\MSNCoreFiles\msn6.exe
    F:\Program Files\ICQLite\ICQLite.exe
    F:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-aware.exe
    F:\Documents and Settings\All Users\Documents\mums\downloads\HijackThis.exe
    F:\Documents and Settings\All Users\Application Data\64 link dart bird\64Support.exe
    F:\Program Files\Internet Explorer\iexplore.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/Default.asp?Ath=t
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gimqmrclxmqxkyhunesmjib....1XmUcqgQd3.html
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {B6502581-B143-F8DF-E904-E03D5A3B8E9A} - F:\PROGRA~1\FunkMp3\Send Find.exe
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\Updreg.exe
    O4 - HKLM\..\Run: [CTStartup] F:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [Jet Detection] F:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
    O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe "
    O4 - HKLM\..\Run: [Errorhole] F:\PROGRA~1\freeexit\lite grey.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [SSC_UserPrompt] F:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [dart bird the mix] F:\Documents and Settings\All Users\Application Data\64 link dart bird\64Support.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Spyware Doctor] "F:\Program Files\Spyware Doctor\spydoctor.exe" /Q
    O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\RunOnce: [ICQ Lite] F:\Program Files\ICQLite\ICQLite.exe -trayboot
    O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: &Google Search - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://F:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://F:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://F:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/gam...nts/y/tt3_x.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
     
  2. 2004/08/23
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Download CWShredder from here. Save it to the desktop.

    Open Ad-aware and check for updates.

    Scan again with HijackThis and place a check next to the following entries. Close ALL other windows and click fix.


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gimqmrclxmqxkyhunesmjib....1XmUcqgQd3.html
    O2 - BHO: (no name) - {B6502581-B143-F8DF-E904-E03D5A3B8E9A} - F:\PROGRA~1\FunkMp3\Send Find.exe
    O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\Updreg.exe
    O4 - HKLM\..\Run: [Jet Detection] F:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe "
    O4 - HKLM\..\Run: [Errorhole] F:\PROGRA~1\freeexit\lite grey.exe
    O4 - HKLM\..\Run: [dart bird the mix] F:\Documents and Settings\All Users\Application Data\64 link dart bird\64Support.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background

    Go to start>run, type services.msc and hit enter. Locate Messenger in the list, right click and select properties. Stop the service and set to disabled. Apply and OK out. Locate Nvidia Driver Helper service and do the same.

    Open CWShredder, close ALL other windows and click fix. Reboot.

    You will need to show hidden files and folders, as well as system files.

    Open F:\Program Files and delete the folder Messenger Plus! 3.
    Do you know what this program is? freeexit If not, delete that folder also.
    Do you know what this one is? 64 link dart bird If not, open F:\Documents and Settings\All Users\Application Data and delete that folder also.
    Open F:\Temp if present, select all and delete.
    Open F:\Windows\Temp, select all and delete.
    Open F:\Documents and settings\username\Local Settings\temp, select all and delete. Do this for all usernames.
    Open F:\Windows\Prefetch, select all and delete.
    Open My Computer, right click Local disk C: and choose properties, then disk cleanup. Check all boxes except compress old files and OK.

    Run Ad-aware in full scan mode. Delete all it finds.

    Reboot, surf a bit and do another HJT scan, then post the new log.
     

  3. to hide this advert.

  4. 2004/08/23
    newdawnuk

    newdawnuk Inactive Thread Starter

    Joined:
    2004/08/21
    Messages:
    4
    Likes Received:
    0
    hijack log

    thanks . did as u said, and adaware didnt find anything, did hijack this and here is the log i got from
    Logfile of HijackThis v1.98.2
    Scan saved at 18:41:06, on 23/08/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    F:\WINDOWS\system32\spoolsv.exe
    F:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
    F:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
    F:\WINDOWS\System32\nvsvc32.exe
    F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    F:\WINDOWS\system32\ZoneLabs\vsmon.exe
    F:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
    F:\WINDOWS\Explorer.EXE
    F:\Program Files\Common Files\Symantec Shared\ccApp.exe
    F:\Program Files\Winamp\winampa.exe
    F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    F:\WINDOWS\System32\ctfmon.exe
    F:\Program Files\Messenger\msmsgs.exe
    F:\Program Files\MSN Messenger\msnmsgr.exe
    F:\Program Files\ICQLite\ICQLite.exe
    F:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-aware.exe
    F:\Program Files\Internet Explorer\IEXPLORE.EXE
    F:\Program Files\Internet Explorer\IEXPLORE.EXE
    F:\WINDOWS\notepad.exe
    F:\Documents and Settings\All Users\Documents\mums\downloads\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gimqmrclxmqxkyhunesmjib....KBiu0UysImmLWZ5EtNrT3bhgNdefTA1XmUcqgQd3.html
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\Updreg.exe
    O4 - HKLM\..\Run: [CTStartup] F:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [Jet Detection] F:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
    O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [SSC_UserPrompt] F:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Spyware Doctor] "F:\Program Files\Spyware Doctor\spydoctor.exe" /Q
    O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\RunOnce: [ICQ Lite] F:\Program Files\ICQLite\ICQLite.exe -trayboot
    O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: &Google Search - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://F:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://F:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://F:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
     
  5. 2004/08/23
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    It looks as though you missed a step in my last post. Did you do this?
    Scan again with HijackThis and place a check next to the following entries. Close all other windows and click fix.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gimqmrclxmqxkyhunesmjib....1XmUcqgQd3.html
    O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\Updreg.exe
    O4 - HKLM\..\Run: [Jet Detection] F:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
    O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background


    Then reboot, scan again and post a new log.

    Do you use Windows Messenger? **Note - not the same as MSN Messenger
    If not, go to start>run and copy/paste the following command into the dialog box, then hit enter, to remove it.

    RunDll32 advpack.dll,LaunchINFSection %windir%\INF\msmsgs.inf,BLC.Remove
     
  6. 2004/08/24
    newdawnuk

    newdawnuk Inactive Thread Starter

    Joined:
    2004/08/21
    Messages:
    4
    Likes Received:
    0
    hijack log

    ok think everything is ok now but here is the log as requested , dont think i missed anything this time thanks again

    Logfile of HijackThis v1.98.2
    Scan saved at 06:57:25, on 24/08/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    F:\WINDOWS\system32\spoolsv.exe
    F:\WINDOWS\Explorer.EXE
    F:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
    F:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
    F:\Program Files\Common Files\Symantec Shared\ccApp.exe
    F:\Program Files\Winamp\winampa.exe
    F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    F:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    F:\WINDOWS\System32\ctfmon.exe
    F:\Program Files\MSN Messenger\msnmsgr.exe
    F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    F:\WINDOWS\system32\ZoneLabs\vsmon.exe
    F:\Program Files\Symantec\LiveUpdate\AUpdate.exe
    F:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
    F:\Documents and Settings\All Users\Documents\mums\downloads\HijackThis.exe
    F:\WINDOWS\System32\wuauclt.exe
    F:\Program Files\Messenger\msmsgs.exe

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [CTStartup] F:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
    O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [SSC_UserPrompt] F:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Spyware Doctor] "F:\Program Files\Spyware Doctor\spydoctor.exe" /Q
    O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: &Google Search - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://F:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://F:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://F:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
     
  7. 2004/08/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Looks good. :) Now I recommend you open Spybot and click mode on the toolbar, then advanced mode. Click immunize in the left pane, then immunize again, this time from above with the green + beside it. Click the link below that for SpywareBlaster, download, install, enable all protection and update. Check for updates weekly.
    Then download and install IESpyad.

    That will give you an added layer of protection against unwanted parasites.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.