1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

DMVlite in Win2K HJT log included.

Discussion in 'Malware and Virus Removal Archive' started by Capricious, 2005/02/03.

Thread Status:
Not open for further replies.
  1. 2005/02/03
    Capricious

    Capricious Inactive Thread Starter

    Joined:
    2005/02/03
    Messages:
    18
    Likes Received:
    0
    I got the DMVlite last night, and I cannot remove it from my Add/Remove programs list. It tries opening it as an image file when I click on the change/remove button. I have Windows 2000, don't know if the procedures are different from XP. Here is the HJT log. Thanks in advance Guys!!

    Logfile of HijackThis v1.99.0
    Scan saved at 9:40:44 AM, on 2/3/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    C:\WINNT\System32\CTsvcCDA.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\devldr32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINNT\system32\Promon.exe
    C:\WINNT\system32\hpha1mon.exe
    C:\SCANJET\PrecisionScanLT\hppwrsav.exe
    C:\WINNT\system32\RUNDLL32.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\kxsa0uyc\kxsa0uyc.exe
    C:\WINNT\system32\rsvmix32.exe
    C:\WINNT\system32\wsxsvc\wsxsvc.exe
    C:\WINNT\system32\vmss\vmss.exe
    C:\WINNT\system32\rapcconf.exe
    C:\WINNT\system32\HPHipm07.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://sharempeg.com/find/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://sharempeg.com/find/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Intel ® Home PC Program
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
    O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINNT\BTGrab.dll
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINNT\Helper101.dll
    O2 - BHO: SDWin32 Class - {2EF94AF4-9C11-495A-8CBF-413BF88E5A54} - C:\WINNT\system32\qwzsl.dll
    O2 - BHO: (no name) - {54614065-1041-4625-87CC-5A116B1F7D53} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {55A9BBE0-7F40-47E5-8B16-9C89766B6ADC} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {8A1C3CEA-5F0D-4869-B72B-C8EA68BC3BAE} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {8EFAAEE6-8A0C-4E07-A7C5-C055E2DE4592} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: SDWin32 Class - {A40B53DD-7A65-4E41-8A07-9F25985FE44A} - C:\WINNT\system32\ejmux.dll
    O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [UpdReg] C:\WINNT\Updreg.exe
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [DSL Connection Tool] C:\Program Files\MSN\MSNIA\dslmon.exe
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [SysTest] C:\WINNT\system32\systest.exe
    O4 - HKLM\..\Run: [MSNSysRestore] C:\WINNT\system32\pc32.exe bg
    O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
    O4 - HKLM\..\Run: [HPHA1MON] C:\WINNT\system32\hpha1mon.exe
    O4 - HKLM\..\Run: [hppwrsav] C:\SCANJET\PrecisionScanLT\hppwrsav.exe
    O4 - HKLM\..\Run: [winupdt] RUNDLL32.EXE c:\winnt\jep1220_32.dll,_mainRD
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [kxsa0uyc] C:\Program Files\kxsa0uyc\kxsa0uyc.exe
    O4 - HKLM\..\Run: [gamebt] c:\winnt\system32\gamebt.exe
    O4 - HKLM\..\Run: [ejmuxc] C:\WINNT\system32\ejmuxc.exe
    O4 - HKLM\..\Run: [qwzslc] C:\WINNT\system32\qwzslc.exe
    O4 - HKLM\..\Run: [u44P37j] rsvmix32.exe
    O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
    O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
    O4 - HKCU\..\Run: [f3vFRXH5Q] rapcconf.exe
    O9 - Extra button: (no name) - {44EFB53C-C965-43CF-9F45-52242D134187} - (no file)
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0522.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0522.dll
    O9 - Extra button: Juegos On Line - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\euro-ricas\local.htm (file missing)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay101.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.141/code/PWActiveXImgCtl.CAB
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://dancecam.as.ua.edu/activex/AxisCamControl.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O23 - Service: AVSync Manager - Unknown - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: McShield - Unknown - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
     
  2. 2005/02/03
    Capricious

    Capricious Inactive Thread Starter

    Joined:
    2005/02/03
    Messages:
    18
    Likes Received:
    0
    I got rid of some stuff.

    I got rid of a few things, here is my new HJT log. Don't really know where to go from here. Everyone else seems to have Windows XP. Can someone help me with Windows 2000? Thanks

    Logfile of HijackThis v1.99.0
    Scan saved at 6:54:28 PM, on 2/3/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    C:\WINNT\System32\CTsvcCDA.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\WINNT\system32\devldr32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINNT\system32\Promon.exe
    C:\WINNT\system32\hpha1mon.exe
    C:\WINNT\system32\RUNDLL32.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\kxsa0uyc\kxsa0uyc.exe
    C:\WINNT\system32\rsvmix32.exe
    C:\WINNT\system32\wsxsvc\wsxsvc.exe
    C:\WINNT\system32\vmss\vmss.exe
    C:\WINNT\system32\rapcconf.exe
    C:\WINNT\system32\HPHipm07.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://sharempeg.com/find/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://sharempeg.com/find/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Intel ® Home PC Program
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
    O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINNT\BTGrab.dll
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINNT\Helper101.dll
    O2 - BHO: SDWin32 Class - {2EF94AF4-9C11-495A-8CBF-413BF88E5A54} - C:\WINNT\system32\qwzsl.dll
    O2 - BHO: (no name) - {54614065-1041-4625-87CC-5A116B1F7D53} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {55A9BBE0-7F40-47E5-8B16-9C89766B6ADC} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {8A1C3CEA-5F0D-4869-B72B-C8EA68BC3BAE} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {8EFAAEE6-8A0C-4E07-A7C5-C055E2DE4592} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {930379B1-5067-435D-9F6A-BF4D335FFA1A} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: SDWin32 Class - {A40B53DD-7A65-4E41-8A07-9F25985FE44A} - C:\WINNT\system32\ejmux.dll
    O2 - BHO: (no name) - {D6CAFAB1-68B9-4B6D-8A50-09133B7A980C} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [UpdReg] C:\WINNT\Updreg.exe
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [DSL Connection Tool] C:\Program Files\MSN\MSNIA\dslmon.exe
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [SysTest] C:\WINNT\system32\systest.exe
    O4 - HKLM\..\Run: [MSNSysRestore] C:\WINNT\system32\pc32.exe bg
    O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
    O4 - HKLM\..\Run: [HPHA1MON] C:\WINNT\system32\hpha1mon.exe
    O4 - HKLM\..\Run: [winupdt] RUNDLL32.EXE c:\winnt\jep1220_32.dll,_mainRD
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [kxsa0uyc] C:\Program Files\kxsa0uyc\kxsa0uyc.exe
    O4 - HKLM\..\Run: [gamebt] c:\winnt\system32\gamebt.exe
    O4 - HKLM\..\Run: [ejmuxc] C:\WINNT\system32\ejmuxc.exe
    O4 - HKLM\..\Run: [qwzslc] C:\WINNT\system32\qwzslc.exe
    O4 - HKLM\..\Run: [u44P37j] rsvmix32.exe
    O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
    O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
    O4 - HKCU\..\Run: [f3vFRXH5Q] rapcconf.exe
    O9 - Extra button: (no name) - {44EFB53C-C965-43CF-9F45-52242D134187} - (no file)
    O9 - Extra button: Juegos On Line - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\euro-ricas\local.htm (file missing)
    O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.141/code/PWActiveXImgCtl.CAB
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: AVSync Manager - Unknown - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: McShield - Unknown - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
     

  3. to hide this advert.

  4. 2005/02/03
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    It's not a matter of the OS version - just the number of folks who can help and the lengh of time the research takes. All assistance on the forums is by volunteers (and staff are volunteer) so we get to stuff as fast as we can.

    I'm not one of the security experts but I do know enough to either tell you what needs removing (and how) or to know when a problem is beyond me. I'll take a look at yours now and get back when I have finished.
     
    Newt,
    #3
  5. 2005/02/03
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Nope. Sorry. You got a couple of things that need removal tools I'm not comfortable with. Gotta wait on an expert.

    You have DMVLite in your title as one of your problems. Where are you seeing it?
     
    Newt,
    #4
  6. 2005/02/03
    Capricious

    Capricious Inactive Thread Starter

    Joined:
    2005/02/03
    Messages:
    18
    Likes Received:
    0
    It's in Add/Remove programs. If I highlight it and click on remove, it tries opening up Kodak imaging for windows.

    Thanks for the help Newt, I wasn't sure if it was OS specific or not.

    Bobby
     
  7. 2005/02/04
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi

    Can you zip up and send this folder to me ?
    C:\Program Files\kxsa0uyc
    It will need to be encrypted so it will be sure to get through
    For now copy the entire folder to somewhere else.

    Download and install CWShredder Version 2.12 here (as of 1/9/2005) by Merijn Bellekom, Dont run it yet.

    Set windows to show hidden extensions file's and folder's.
    >click here for instructions<.

    Start into safe mode
    http://www.microsoft.com/windows2000/techinfo/administration/management/safemode.asp

    Find and delete (ONLY THESE EXACT) files and folder's (If present)
    C:\WINNT\Helper101.dll
    C:\WINNT\BTGrab.dll
    C:\WINNT\system32\wsxsvc
    C:\WINNT\system32\vmss
    C:\WINNT\system32\pc32.exe
    c:\winnt\jep1220_32.dll
    C:\WINNT\system32\ejmux.dll
    C:\Program Files\kxsa0uyc
    c:\winnt\system32\gamebt.exe
    C:\WINNT\system32\ejmuxc.exe
    C:\WINNT\system32\qwzslc.exe
    C:\WINNT\system32\rsvmix32.exe
    C:\WINNT\system32\rapcconf.exe
    ============================
    Run cwshredder hit 'fix' as opposed to 'scan only'.

    Restart back to a normal windows session

    Start Hijackthis and place a check next to these items,
    Close all browser windows and shut down all other programs that show in the taskbar. (even Folders)
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://sharempeg.com/find/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://sharempeg.com/find/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINNT\BTGrab.dll
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINNT\Helper101.dll
    O2 - BHO: SDWin32 Class - {2EF94AF4-9C11-495A-8CBF-413BF88E5A54} - C:\WINNT\system32\qwzsl.dll
    O2 - BHO: (no name) - {54614065-1041-4625-87CC-5A116B1F7D53} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {55A9BBE0-7F40-47E5-8B16-9C89766B6ADC} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {8A1C3CEA-5F0D-4869-B72B-C8EA68BC3BAE} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {8EFAAEE6-8A0C-4E07-A7C5-C055E2DE4592} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: (no name) - {930379B1-5067-435D-9F6A-BF4D335FFA1A} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: SDWin32 Class - {A40B53DD-7A65-4E41-8A07-9F25985FE44A} - C:\WINNT\system32\ejmux.dll
    O2 - BHO: (no name) - {D6CAFAB1-68B9-4B6D-8A50-09133B7A980C} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll
    O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [winupdt] RUNDLL32.EXE c:\winnt\jep1220_32.dll,_mainRD
    O4 - HKLM\..\Run: [kxsa0uyc] C:\Program Files\kxsa0uyc\kxsa0uyc.exe
    O4 - HKLM\..\Run: [gamebt] c:\winnt\system32\gamebt.exe
    O4 - HKLM\..\Run: [ejmuxc] C:\WINNT\system32\ejmuxc.exe
    O4 - HKLM\..\Run: [qwzslc] C:\WINNT\system32\qwzslc.exe
    O4 - HKLM\..\Run: [u44P37j] rsvmix32.exe
    O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
    O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
    O4 - HKCU\..\Run: [f3vFRXH5Q] rapcconf.exe
    O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/diale...Recomendada.cab

    > optional fix's >
    O4 - HKLM\..\Run: [UpdReg] C:\WINNT\Updreg.exe
    O9 - Extra button: (no name) - {44EFB53C-C965-43CF-9F45-52242D134187} - (no file)
    O9 - Extra button: Juegos On Line - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\euro-ricas\local.htm (file missing)=
    ===================
    Hit fix checked and close Hijackthis.


    Post a new log and mention the problems if any.
     
  8. 2005/02/04
    Capricious

    Capricious Inactive Thread Starter

    Joined:
    2005/02/03
    Messages:
    18
    Likes Received:
    0
    Hi Lonny,

    Thanks soo much for the help! You are DA MAN! I tried to send you that zip file, but you don't accept email through here. You can email me:
    Edit to remove email address
    and I will reply with the zip file, or tell me otherwise how to get it to you. I still cannot remove the DMVlite from Add/Remove programs, it still tries to open it up as an image file. Other than that everything is running fine. Browser is fast, and no pop-ups. Here is my new log. There were a couple of items in Hijack This that I didn't delete because they were not exact. Let me know what else to delete.

    Thanks Again,
    Bobby

    Logfile of HijackThis v1.99.0
    Scan saved at 10:43:11 PM, on 2/4/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    C:\WINNT\System32\CTsvcCDA.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
    C:\WINNT\system32\devldr32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINNT\system32\Promon.exe
    C:\WINNT\system32\hpha1mon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\WINNT\system32\subhost.exe
    C:\WINNT\system32\sticert.exe
    C:\WINNT\system32\HPHipm07.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Intel ® Home PC Program
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
    O2 - BHO: (no name) - {395F19ED-FB2A-4776-8936-425D034E1BD5} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [DSL Connection Tool] C:\Program Files\MSN\MSNIA\dslmon.exe
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [SysTest] C:\WINNT\system32\systest.exe
    O4 - HKLM\..\Run: [MSNSysRestore] C:\WINNT\system32\pc32.exe bg
    O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
    O4 - HKLM\..\Run: [HPHA1MON] C:\WINNT\system32\hpha1mon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [u44P37j] subhost.exe
    O4 - HKCU\..\Run: [f3vFRXH5Q] sticert.exe
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.141/code/PWActiveXImgCtl.CAB
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: AVSync Manager - Unknown - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: McShield - Unknown - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
     
  9. 2005/02/05
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi
    I sent my address to you, thans in advance for that folder.

    Close all Browsers
    Delete these file's will Hijackthis tools, cancel the message to restart the PC.
    Run hijackthis Hit "config" then "misc tools" > "delete a file on reboot'
    Copy/paste This into the >File name< box then cick >open<, say no to the prompt to reboot.
    C:\WINNT\system32\subhost.exe
    do the same for >
    C:\WINNT\system32\sticert.exe
    Hit >back< then Scan and Place a check next to these,
    O2 - BHO: (no name) - {395F19ED-FB2A-4776-8936-425D034E1BD5} - C:\Program Files\kxsa0uyc\kxsa0uyc.dll (file missing)
    O4 - HKLM\..\Run: [u44P37j] subhost.exe
    O4 - HKCU\..\Run: [f3vFRXH5Q] sticert.exe
    ================================
    and hit fix checked

    You can delete items that will not uninstall with SpyBots tool's,
    Do you have SpyBot and ad-aware ? if not get them.
    Scanning with Spybot and Ad-Aware : http://www.windowsbbs.com/showpost.php?p=159029&postcount=2

    Post a new hijackthis log, we can explain how to remove dmv from the list in addremove later.
     
  10. 2005/02/07
    Capricious

    Capricious Inactive Thread Starter

    Joined:
    2005/02/03
    Messages:
    18
    Likes Received:
    0
    Hi lonny,

    Here is my new HJT log. The 2 latter files you wanted me to remove in HJT were not exactly the ones you mentioned, so I left them. They are:
    O4 - HKLM\..\Run: [u44P37j] cmulayer.exe
    O4 - HKCU\..\Run: [f3vFRXH5Q] cliuia32.exe

    I have ad-aware, and I will download spybot now. It seems I am still getting a bunch of spyware still. More than before I got this bug. I also emailed that file to you that you wanted.

    Bobby


    Logfile of HijackThis v1.99.0
    Scan saved at 9:24:02 AM, on 2/7/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    C:\WINNT\System32\CTsvcCDA.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
    C:\WINNT\system32\devldr32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINNT\system32\Promon.exe
    C:\WINNT\system32\hpha1mon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\WINNT\system32\cmulayer.exe
    C:\WINNT\system32\cliuia32.exe
    C:\WINNT\system32\HPHipm07.exe
    C:\WINNT\System32\svchost.exe
    C:\HJT\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Intel ® Home PC Program
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [DSL Connection Tool] C:\Program Files\MSN\MSNIA\dslmon.exe
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [SysTest] C:\WINNT\system32\systest.exe
    O4 - HKLM\..\Run: [MSNSysRestore] C:\WINNT\system32\pc32.exe bg
    O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
    O4 - HKLM\..\Run: [HPHA1MON] C:\WINNT\system32\hpha1mon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [u44P37j] cmulayer.exe
    O4 - HKCU\..\Run: [f3vFRXH5Q] cliuia32.exe
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.141/code/PWActiveXImgCtl.CAB
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: AVSync Manager - Unknown - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: McShield - Unknown - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
     
  11. 2005/02/07
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Open Hijackthis, scan
    Look for, place a check next to these and hit fix checked
    O4 - HKLM\..\Run: [u44P37j] any exe here
    O4 - HKCU\..\Run: [f3vFRXH5Q] " " " "

    hit config misc tools > Open process's manager
    Hilight (if they are differant kill them)
    C:\WINNT\system32\cmulayer.exe
    and choose kill process
    C:\WINNT\system32\cliuia32.exe
    do the same for this one ^^, Now you should be able to manualy delete them easily

    Let us know how you make out ?
     
  12. 2005/02/07
    Capricious

    Capricious Inactive Thread Starter

    Joined:
    2005/02/03
    Messages:
    18
    Likes Received:
    0
    Lonny,

    I deleted those files. Here is the HJT log. Thanks again for all your help!!

    Bobby

    Logfile of HijackThis v1.99.0
    Scan saved at 10:16:22 PM, on 2/7/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    C:\WINNT\System32\CTsvcCDA.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
    C:\WINNT\system32\devldr32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINNT\system32\Promon.exe
    C:\WINNT\system32\hpha1mon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\WINNT\system32\HPHipm07.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Intel ® Home PC Program
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [DSL Connection Tool] C:\Program Files\MSN\MSNIA\dslmon.exe
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [SysTest] C:\WINNT\system32\systest.exe
    O4 - HKLM\..\Run: [MSNSysRestore] C:\WINNT\system32\pc32.exe bg
    O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
    O4 - HKLM\..\Run: [HPHA1MON] C:\WINNT\system32\hpha1mon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.141/code/PWActiveXImgCtl.CAB
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: AVSync Manager - Unknown - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: McShield - Unknown - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
     
  13. 2005/02/08
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    I missed one

    Have hijackthis fix

    O4 - HKLM\..\Run: [MSNSysRestore] C:\WINNT\system32\pc32.exe bg

    Restart the PC and delete that file, let us know if any problems
     
  14. 2005/02/08
    Capricious

    Capricious Inactive Thread Starter

    Joined:
    2005/02/03
    Messages:
    18
    Likes Received:
    0
    Lonny,

    Here is the latest. I haven't encountered any problems so far.

    Bobby

    Logfile of HijackThis v1.99.0
    Scan saved at 11:34:47 AM, on 2/8/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    C:\WINNT\System32\CTsvcCDA.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Network Associates\VirusScan\VsStat.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
    C:\Program Files\Network Associates\VirusScan\Avconsol.exe
    C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
    C:\WINNT\system32\devldr32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINNT\system32\Promon.exe
    C:\WINNT\system32\hpha1mon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINNT\system32\HPHipm07.exe
    C:\WINNT\system32\wuauclt.exe
    C:\HJT\HijackThis.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/ymsgr/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Intel ® Home PC Program
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [DSL Connection Tool] C:\Program Files\MSN\MSNIA\dslmon.exe
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [SysTest] C:\WINNT\system32\systest.exe
    O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
    O4 - HKLM\..\Run: [HPHA1MON] C:\WINNT\system32\hpha1mon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.141/code/PWActiveXImgCtl.CAB
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
    O23 - Service: AVSync Manager - Unknown - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
    O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: McShield - Unknown - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
     
  15. 2005/02/09
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Thast's great Bobby, thanks for letting us know


    Happy surfing
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.