Computing.Net > Forums > Security and Virus > spyware cleanup

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

spyware cleanup

Reply to Message Icon

Name: steven1985
Date: December 27, 2003 at 14:13:19 Pacific
OS: Windows XP Home
CPU/Ram: Intel Celeron 1.8GHz, 128
Comment:

I went away to college and when I returned for the holidays, I found that my mom's computer was running very slowly... it's overrun with spyware. I have been working on it for almost a week and have managed to be rid of about 85% of the spyware that was on here. Now, I am having problems with what's left, like this Golden Casino program among others. Here is my Hijack This log:

Logfile of HijackThis v1.97.7
Scan saved at 4:57:33 PM, on 12/27/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programs\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\kimefnun.exe
C:\Program Files\QUICKENW\QAGENT.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\hhxrhxtw.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Programs\AVG\avgcc32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\Keyhost.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\PROGRAMS\AVG\avgserv.exe
C:\WINDOWS\System32\mrtMngr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Programs\Patches\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\programs\Adobe Acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4CE78ADA-45AB-2BD8-0B3A-BE34FD4E1D93} - C:\WINDOWS\system32\txiagdpv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programs\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - c:\progra~1\iesearchbar\iesearchbar.dll__SpybotSDDisabled (file missing)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {BA735014-9EC0-4AAC-A49F-261336A4F657} - C:\WINDOWS\System32\dyskquota.dll
O2 - BHO: (no name) - {BB635CDE-DEAA-CA9F-EA46-ED9A0F1CD1E2} - C:\WINDOWS\system32\xwzswaid.dll
O2 - BHO: (no name) - {D8E25C53-9508-4f5c-9249-D98D438891D5} - C:\WINDOWS\System32\ssurf022.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SSRunScript] "C:\Program Files\Support.com\Charter\bin\SSRunScript.exe" /script "C:\Program Files\Support.com\Charter\vbs\verifyconnection.vbs" /args //b startupdelay
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programs\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [SpamNukeWeb] C:\Program Files\SpamNuker\spamnuker.exe /auto
O4 - HKLM\..\Run: [SafeSurfingUpdate] C:\WINDOWS\System32\SSUpdate.exe
O4 - HKLM\..\Run: [qvipqpfj] C:\WINDOWS\System32\kimefnun.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ftnljjty] C:\WINDOWS\hhxrhxtw.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Programs\AVG\avgcc32.exe /startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Ad-aware] C:\Programs\Ad-Aware\Ad-aware 6\Ad-aware.exe +c
O4 - HKLM\..\Run: [rehxec.exe] C:\WINDOWS\System32\rehxec.exe
O4 - HKLM\..\Run: [WinEssential] C:\WINDOWS\System32\Keyhost.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [MNPAP] C:\Program Files\MNPAntiPopup\MNPAntiPopup.exe
O4 - HKCU\..\Run: [Forbes] C:\Program Files\Forbes\ForbesAlerts.exe
O4 - HKCU\..\Run: [rehxec.exe] C:\WINDOWS\System32\rehxec.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)
O9 - Extra button: Cosmi Popup Blocker (HKLM)
O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! MahJong - http://download.games.yahoo.com/games/clients/y/ot0_x.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.netpaloffers.net/NetpalOffers/DMO1/jv0pt1np.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://support.charter.com/sdccommon/download/tgctlins.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://www.sidestep.com/get/k42037/sb026.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowser/cabfiles/2.5.30/Hiwire.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://download.iwon.com/ct/pm3/iwonpm_6_1,0,2,5.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {A16E6189-A1DD-4696-9806-0324C145D794} (KeyActivex Control) - http://www.jraun.com/activex/src/KeyActivex.ocx
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {BB9BE2FF-06DB-47FA-BC0B-C7BB25348AC2} (CasinoLoader Control) - http://www.casinolasvegas.com/activex/casinoloader.cab
O16 - DPF: {BEC65CAF-8156-CFAD-DD7E-AD4D1E173FBB} (DownloadUL Class) - http://public.searchbarcash.com/cab/005/ocgvprml.cab
O16 - DPF: {CCBDD1DC-5FCF-43E5-6BAD-DA44CB0BA16A} (DownloadUL Class) - http://public.searchbarcash.com/cab/010/esfzpzex.cab
O16 - DPF: {EE2589EB-7FC8-44DB-A892-573F2C4B41E0} - http://pdf.forbes.com/forbesnews/triggernews/ForbesLifestyleSigned.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

I am running ZoneAlarm firewall, AVG Antivirus, and Adaware and Spybot. I have google toolbar as my popup blocker and have recently had to uninstall many other popup blockers that my mom had installed. Any help with getting these spyware programs off would be great.



Sponsored Link
Ads by Google

Response Number 1
Name: Kevin The Tech Dude
Date: December 27, 2003 at 14:47:18 Pacific
Reply:

You are still infected with W32.HLLW.Gaobot.EE for startes.

You might want to download TDS-3 and get the latest Radius File and run it.

Someone posted a link to remove the Casion crap, let me see if I can find it.

KTTD



0

Response Number 2
Name: Kevin The Tech Dude
Date: December 27, 2003 at 14:51:00 Pacific

Response Number 3
Name: Abnormal
Date: December 27, 2003 at 16:47:58 Pacific
Reply:

Removing this will help clean-up,

R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {4CE78ADA-45AB-2BD8-0B3A-BE34FD4E1D93} - C:\WINDOWS\system32\txiagdpv.dll
O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - c:\progra~1\iesearchbar\iesearchbar.dll__SpybotSDDisabled (file missing)
O2 - BHO: (no name) - {BA735014-9EC0-4AAC-A49F-261336A4F657} - C:\WINDOWS\System32\dyskquota.dll
O2 - BHO: (no name) - {BB635CDE-DEAA-CA9F-EA46-ED9A0F1CD1E2} - C:\WINDOWS\system32\xwzswaid.dll
O2 - BHO: (no name) - {D8E25C53-9508-4f5c-9249-D98D438891D5} - C:\WINDOWS\System32\ssurf022.dll

O4 - HKLM\..\Run: [SafeSurfingUpdate] C:\WINDOWS\System32\SSUpdate.exe
http://www.pestpatrol.com/PestInfo/d/dyfuca_safesurfing.asp

O4 - HKLM\..\Run: [qvipqpfj] C:\WINDOWS\System32\kimefnun.exe
O4 - HKLM\..\Run: [ftnljjty] C:\WINDOWS\hhxrhxtw.exe
O4 - HKLM\..\Run: [rehxec.exe] C:\WINDOWS\System32\rehxec.exe
O4 - HKLM\..\Run: [WinEssential] C:\WINDOWS\System32\Keyhost.exe
O4 - HKCU\..\Run: [rehxec.exe] C:\WINDOWS\System32\rehxec.exe
O4 - HKCU\..\Run: [MNPAP] C:\Program Files\MNPAntiPopup\MNPAntiPopup.exe
O8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htm

O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)
O9 - Extra button: Cosmi Popup Blocker (HKLM)
O9 - Extra 'Tools' menuitem: Cosmi Popup Blocker (HKLM)
What to do:
If you don't recognize the name of the button or menuitem, have HijackThis fix it.

O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.netpaloffers.net/NetpalOffers/DMO1/jv0pt1np.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://download.iwon.com/ct/pm3/iwonpm_6_1,0,2,5.cab
O16 - DPF: {A16E6189-A1DD-4696-9806-0324C145D794} (KeyActivex Control) - http://www.jraun.com/activex/src/KeyActivex.ocx
O16 - DPF: {BB9BE2FF-06DB-47FA-BC0B-C7BB25348AC2} (CasinoLoader Control) - http://www.casinolasvegas.com/activex/casinoloader.cab
O16 - DPF: {BEC65CAF-8156-CFAD-DD7E-AD4D1E173FBB} (DownloadUL Class) - http://public.searchbarcash.com/cab/005/ocgvprml.cab
O16 - DPF: {CCBDD1DC-5FCF-43E5-6BAD-DA44CB0BA16A} (DownloadUL Class) - http://public.searchbarcash.com/cab/010/esfzpzex.cab

If you don't recognize the name of the object, or the URL it was downloaded from, have HijackThis fix it. If the name or URL contains words like 'dialer', 'casino', 'free_plugin' etc, definitely fix it.

I may have missed something, too much junk.
Remove those lines with hijackthis, reboot
and post another log.



abnormal


0

Response Number 4
Name: TheKid
Date: December 27, 2003 at 16:49:58 Pacific
Reply:

Nice work Kev...you're as sharp as a bowling ball. LOL


• TheKid •


0

Response Number 5
Name: sxshep
Date: December 27, 2003 at 17:07:26 Pacific
Reply:

Just to add to the august advice posted by our venerated moderator and abnormal.

reboot into safe mode and delete all you find re:
C:\WINDOWS\System32\kimefnun.exe
C:\WINDOWS\hhxrhxtw.exe
C:\WINDOWS\System32\rehxec.exe
C:\WINDOWS\System32\Keyhost.exe

If they made it through the ball return.

shep


0

Related Posts

See More



Response Number 6
Name: steven1985
Date: December 28, 2003 at 10:20:15 Pacific
Reply:

Okay, I cleaned up using all of your suggestions and a few of my own. Hear is my new Highjack This log:

Logfile of HijackThis v1.97.7
Scan saved at 1:15:17 PM, on 12/28/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programs\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\QUICKENW\QAGENT.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Programs\AVG\avgcc32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\WINDOWS\System32\mrtMngr.exe
C:\PROGRAMS\AVG\avgserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Programs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O1 - Hosts: 203.161.127.141 www.dcsresearch.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\programs\Adobe Acrobat\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programs\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SSRunScript] "C:\Program Files\Support.com\Charter\bin\SSRunScript.exe" /script "C:\Program Files\Support.com\Charter\vbs\verifyconnection.vbs" /args //b startupdelay
O4 - HKLM\..\Run: [Zone Labs Client] C:\Programs\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [QuickTime Task] "C:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Programs\AVG\avgcc32.exe /startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Ad-aware] C:\Programs\Ad-Aware\Ad-aware 6\Ad-aware.exe +c
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [Forbes] C:\Program Files\Forbes\ForbesAlerts.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! MahJong - http://download.games.yahoo.com/games/clients/y/ot0_x.cab
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.netpaloffers.net/NetpalOffers/DMO1/jv0pt1np.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://support.charter.com/sdccommon/download/tgctlins.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowser/cabfiles/2.5.30/Hiwire.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {EE2589EB-7FC8-44DB-A892-573F2C4B41E0} - http://pdf.forbes.com/forbesnews/triggernews/ForbesLifestyleSigned.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

If you have any other suggestions, please let me know. Thank you for your help.


0

Response Number 7
Name: Abnormal
Date: December 28, 2003 at 16:17:00 Pacific
Reply:

Steven, may have missed something,
only things left are
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
Part of weather bug, that may cause problems.

O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.netpaloffers.net/NetpalOffers/DMO1/jv0pt1np.cab
This is not good.

If all is well, go to the link under my name.
Some good prevention tools there.

Good luck


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: spyware cleanup

Overall Pc Security Advice www.computing.net/answers/security/overall-pc-security-advice/9214.html

help adware and spyware www.computing.net/answers/security/help-adware-and-spyware-/17032.html

Spyware, iworm_attack www.computing.net/answers/security/spyware-iwormattack/18803.html