1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Remove win fixer 2005 [HJT log]

Discussion in 'Malware and Virus Removal Archive' started by BrokeBroker, 2005/10/08.

  1. 2005/10/08
    BrokeBroker

    BrokeBroker Inactive Thread Starter

    Joined:
    2005/10/08
    Messages:
    1
    Likes Received:
    0
    I have a problem with removing a program called Win Fixer 2005.
    Can anyone help me please,I will be grateful. :p

    I have included the hijackthis.log below.

    Logfile of HijackThis v1.99.1
    Scan saved at 17:32:11, on 08.10.2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
    C:\Programfiler\Norton Internet Security\ISSVC.exe
    C:\WINNT\system32\svchost.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
    C:\WINNT\System32\svchost.exe
    C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\windowsupdate.exe
    C:\Program Files\Bmqlqh\Mygrz.exe
    C:\Programfiler\QuickTime\qttask.exe
    C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe
    C:\WINNT\system32\LVCOMSX.EXE
    C:\Programfiler\Logitech\Video\LogiTray.exe
    C:\Programfiler\Skype\Phone\Skype.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Programfiler\Logitech\Video\FxSvr2.exe
    C:\Programfiler\MSN Messenger\msnmsgr.exe
    C:\Programfiler\WinMX\WinMX.exe
    C:\Programfiler\Internet Explorer\IEXPLORE.EXE
    C:\Programfiler\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\marita er søt\Lokale innstillinger\Temporary Internet Files\Content.IE5\6HLM3QH4\HijackThis[1].exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {EC177377-B79B-9449-B4C8-924BCF465DCA} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programfiler\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programfiler\Fellesfiler\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programfiler\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: AdwareFilter - {1028F737-81E7-452B-A860-E50CAD90A08C} - C:\Programfiler\AdwareFilterToolbar\AdwareFilter.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [REGRUN32] C:\windowsupdate.exe
    O4 - HKLM\..\Run: [Fjwljqj] C:\Program Files\Bmqlqh\Mygrz.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programfiler\Fellesfiler\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [NI.UWFX5] "C:\WINNT\Downloaded Program Files\UWFX5NetInstaller.exe "
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programfiler\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programfiler\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\RunServices: [DJSNetCN] C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Programfiler\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programfiler\Logitech\Video\ManifestEngine.exe boot
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [WinMX] C:\Programfiler\WinMX\WinMX.exe -m
    O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://www.icanal.no/spill/commerce/catalog/classes/ExentCtl.ocx
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/systemprofiler/PROFILER.CAB
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\DJSNETCN.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Programfiler\Norton Internet Security\ISSVC.exe
    O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe (file missing)
    O23 - Service: SAVScan - Symantec Corporation - C:\Programfiler\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FELLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\CCPD-LC\symlcsvc.exe

    regards,

    Confused Girl, Merethe alias LulaGirl.
     
  2. 2005/10/09
    oshwyn5

    oshwyn5 Inactive

    Joined:
    2005/08/25
    Messages:
    736
    Likes Received:
    0
    This is not safe
    C:\Documents and Settings\marita er søt\Lokale innstillinger\Temporary Internet Files\Content.IE5\6HLM3QH4\HijackThis[1].exe

    We will be clearing temp and temp internet files which, if you leave hijackthis here will delete it and its backup and recovery files.
    Please move hijackthis to a permanent folder.
    I recommend creating one C:\Programfiles\Hijackthis\
    and put hijackthis.exe there and right click and send to desktop as shortcut. You could just create a folder in MyDocuments (MyDocuments\Hijackthis\hijackthis.exe) the main thing is make a folder, do not leave it in a temp folder.

    Please download
    Mcafee stinger multivirus removal tool
    Install and run

    Spybot search and destroy
    Ad aware personal form Lavasoft
    Install, update,run, check for problems , fix problems.
    A Squared trojan remover
    Download, install, update, scan and fix.

    Codestuf starter startup manager and process viewer

    Then, please download Ewido security suite it is a free version of the program.

    1. Install Ewido security suite
    2. When installing, under "Additional Options" uncheck..
    * Install background guard
    * Install scan via context menu
    3. Launch Ewido, there should be an icon on your desktop, double-click it.
    4. The program will now open to the main screen.
    5. When you run Ewido for the first time, you may get a warning "Database could not be found! ". Click OK. We will fix this in a moment.
    6. You will need to update Ewido to the latest definition files.
    * On the left hand side of the main screen click update.
    * Then click on Start Update.
    7. The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display "Update successful ")

    If you are having problems with the updater, you can use this link to manually update Ewido.
    Ewido manual updates

    (O4 - HKLM\..\Run: [REGRUN32] C:\windowsupdate.exe This is a worm, one of the w32 ones, but not sure if it is rbot http://www.sophos.com/virusinfo/analyses/w32rbotace.html
    rspan, forbot, or which)

    Please go to add/ remove programs and uninstall any of these you find Adware Filter,AdwareX, AdwareSafe, & SpyAssassin which are a rogue programs and not related to Ad-aware from lavasoft.

    Okay, now launch Hijackthis with all other windows closed, put a check by the following and choose fix (If they remain)

    O2 - BHO: (no name) - {EC177377-B79B-9449-B4C8-924BCF465DCA} - (no file)
    O3 - Toolbar: AdwareFilter - {1028F737-81E7-452B-A860-E50CAD90A08C} - C:\Programfiler\AdwareFilterToolbar\AdwareFilter.dll
    O4 - HKLM\..\Run: [REGRUN32] C:\windowsupdate.exe
    O4 - HKLM\..\Run: [Fjwljqj] C:\Program Files\Bmqlqh\Mygrz.exe
    O4 - HKLM\..\Run: [NI.UWFX5] "C:\WINNT\Downloaded Program Files\UWFX5NetInstaller.exe "(This is your winfixer entry)
    O4 - HKCU\..\Run: [WinMX] C:\Programfiler\WinMX\WinMX.exe -m
    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://www.icanal.no/spill/commerce...es/ExentCtl.ocx


    Use task manager or the process viewer in code stuff starter to kill the following processes
    REGRUN32
    Fjwljqj
    NI.UWFX5
    WinMX

    How to show hidden files
    Go to control panel/ folder options/ view
    set to show hidden and system files, uncheck hide protected files and uncheck hide known file extensions.
    Locate and delete the following files
    C:\windowsupdate.exe
    C:\WINNT\Downloaded Program Files\UWFX5NetInstaller.exe

    And these folders
    C:\Programfiler
    (note how it ends in r not s)
    C:\Program Files\Bmqlqh



    If necessary, boot to safe mode to do it
    [l=How to boot to safe mode]http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406[/l]
    [l=Alternate method]http://www.pchell.com/support/safemode.shtml[/l]



    If you have uninstalled norman antivirus have hijackthis fix this entry
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe (file missing)
    Otherwise, it may need to be reinstalled, but is most likely just hiding its file from Hijackthis.

    Reboot to safe mode.
    Empty all Temp folders (delete all files within):

    C:\Documents and Settings\(profile)\Local Settings\Temp\
    C:\Windows\Temp\
    C:\Temp\ (if it exists)


    Go to: Control Panel > Internet Options
    General tab > Temporary Internet Files > Delete Files:
    Checkmark "Delete all offline content "
    Click OK

    Reboot and make sure you can go online.
    Then disable system restore
    How to disable system restore


    Reboot and reenable system restore, create a new restore point and run hijackthis again to make sure no new entries have appeared (post again if there is any question)
     

  3. to hide this advert.

  4. 2005/10/09
    Lucky Kitten

    Lucky Kitten Inactive

    Joined:
    2003/04/12
    Messages:
    77
    Likes Received:
    0
    i am having the same problem. here is my hijackthis log thingy. i have ewido, its been updated and ran it this morning. cleaned out 31 files. help please

    Logfile of HijackThis v1.99.1
    Scan saved at 12:23:34 PM, on 10/9/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\D-Tools\daemon.exe
    C:\Program

    Files\Logitech\MouseWare\system\em_exec.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Lavasoft\Ad-Aware SE

    Personal\Ad-Aware.exe
    C:\Amazing Rita

    ****\downloads\removedesktopvirus\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Search Bar =

    http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Search Page =

    http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

    Page = http://login.passport.net/uilogin.srf?lc=1033&id=2
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\SearchURL,(Default) =

    http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R1 -

    HKCU\Software\Microsoft\Windows\CurrentVersion\Interne

    t Settings,ProxyOverride = localhost;<local>
    R3 - Default URLSearchHook is missing
    O2 - BHO: MSEvents Object -

    {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} -

    C:\WINDOWS\system32\mljge.dll
    O2 - BHO: MSEvents Object -

    {827DC836-DD9F-4A68-A602-5812EB50A834} -

    C:\WINDOWS\system32\ssttt.dll
    O2 - BHO: MSN Search Toolbar Helper -

    {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -

    C:\Program Files\MSN Toolbar

    Suite\TB\02.05.0000.1082\en-us\msntb.dll
    O3 - Toolbar: (no name) -

    {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: MSN Search Toolbar -

    {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -

    C:\Program Files\MSN Toolbar

    Suite\TB\02.05.0000.1082\en-us\msntb.dll
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program

    Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

    Files\QuickTime\qttask.exe" -atboottime
    O8 - Extra context menu item: &AIM Search -

    res://C:\Program Files\AIM

    Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: &MSN Search -

    res://C:\Program Files\MSN Toolbar

    Suite\TB\02.05.0000.1082\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &WordWeb... -

    res://C:\WINDOWS\wweb32.dll/lookup.html
    O9 - Extra button: (no name) -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger -

    {4528BBE0-4E08-11D5-AD55-00010333D0AD} -

    C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger -

    {4528BBE0-4E08-11D5-AD55-00010333D0AD} -

    C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: AIM -

    {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -

    C:\PROGRA~1\aim\aim.exe
    O9 - Extra button: PartyPoker.com -

    {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} -

    C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com -

    {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} -

    C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra button: Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: WeatherBug -

    {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} -

    C:\Program Files\AWS\WeatherBug\Weather.exe (file

    missing) (HKCU)
    O16 - DPF: {01234567-1234-1234-1234-012345678921}

    - http://images.neopets.com/glophone/neoblue5.cab
    O16 - DPF:

    {0E5F0222-96B9-11D3-8997-00104BD12D94}

    (PCPitstop Utility) -

    http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF:

    {17492023-C23A-453E-A040-C7C580BBF700} (Windows

    Genuine Advantage Validation Tool) -

    http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF:

    {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC

    Class) -

    http://www.pcpitstop.com/internet/pcpConnCheck.cab
    O16 - DPF:

    {41F17733-B041-4099-A042-B518BB6A408C} -

    http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.inf

    o.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF:

    {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

    http://download.mcafee.com/molbin/shared/mcinsctl/en-us/

    4,0,0,84/mcinsctl.cab
    O16 - DPF:

    {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN

    Photo Upload Tool) -

    http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.

    cab
    O16 - DPF:

    {62475759-9E84-458E-A1AB-5D2C442ADFDE} -

    http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.inf

    o.apple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF:

    {6EE39BFC-2FB6-4B69-9D05-CFC10E4F5B3E}

    (MavenBootInstallerAXControl Class) -

    http://client.maven.net/client/mavenBootInstaller.cab
    O16 - DPF:

    {80DD2229-B8E4-4C77-B72F-F22972D723EA}

    (AvxScanOnline Control) -

    http://www.bitdefender.com/scan/Msie/bitdefender.cab
    O16 - DPF:

    {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller

    Class) -

    http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O16 - DPF:

    {90C9629E-CD32-11D3-BBFB-00105A1F0D68}

    (InstallShield International Setup Player) -

    http://www.installengine.com/engine/isetup.cab
    O16 - DPF:

    {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6}

    (BatchDownloader Class) -

    http://appdirectory.messenger.msn.com/AppDirectory/P4A

    pps/PhotoSwap/DigWXMSN.cab
    O16 - DPF:

    {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}

    (MsnMessengerSetupDownloadControl Class) -

    http://messenger.msn.com/download/MsnMessengerSetup

    Downloader.cab
    O16 - DPF:

    {B8BE5E93-A60C-4D26-A2DC-220313175592}

    (ZoneIntro Class) -

    http://zone.msn.com/binFramework/v10/ZIntro.cab34246.c

    ab
    O16 - DPF:

    {B9191F79-5613-4C76-AA2A-398534BB8999}

    (YAddBook Class) -

    http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite

    /autocomplete.cab
    O16 - DPF:

    {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -

    http://download.mcafee.com/molbin/shared/mcgdmgr/en-u

    s/1,0,0,21/mcgdmgr.cab
    O16 - DPF:

    {DEAB05BD-24DD-46F2-887D-77D04CE7E41D}

    (APUploadX Control) -

    http://www.ialmond.com/ocx/APUploadX.cab
    O16 - DPF:

    {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}

    (PopCapLoader Object) -

    http://download.games.yahoo.com/games/web_games/pop

    cap/bejeweled2/popcaploader_v6.cab
    O16 - DPF:

    {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}

    (McFreeScan Class) -

    http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/

    mcfscan/2,0,0,4364/mcfscan.cab
    O16 - DPF:

    {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV

    Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
    O18 - Protocol: mavencache -

    {DB47FDC2-8C38-4413-9C78-D1A68BF24EED} -

    C:\Program Files\Maven\protocolHandlers.dll
    O20 - Winlogon Notify: igfxcui -

    C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: mljge -

    C:\WINDOWS\system32\mljge.dll
    O20 - Winlogon Notify: ssttt -

    C:\WINDOWS\system32\ssttt.dll
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.