Unsolved
This post is more than 5 years old
35 Posts
0
4456
May 6th, 2008 15:00
Please Help E-Mail Account Hijacked Browser Crash Problems
My ISP has advised me that spam is being sent from my email address. It seems to have started when I installed AdAware 2007. It crashes the browser each time I start up. I uninstalled the program. I have used Trend Micro housecall. I have tried Spybot which hangs up on Vurumonde each time I use it. Here is my log please let me know how to clear this up.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:59:54 AM, on 5/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\WINDOWS\system32\10rq77opsx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Henry\Desktop\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0ED59684-B985-41A1-B1DE-BD9948C70B28} - c:\windows\system32\avifil32r.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [10rq77opsx] C:\WINDOWS\system32\10rq77opsx.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [10rq77opsx] C:\WINDOWS\system32\10rq77opsx.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O20 - Winlogon Notify: ddpndavx - C:\WINDOWS\SYSTEM32\avifil32r.dll
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 8235 bytes


bamajim
10.4K Posts
0
May 13th, 2008 18:00
Let me research the best way (safest way) to deal with that. The 2 entries are now empty, so they pose no threat, and I think our efforts would be better served finishing the cleaning of the PC.
1. *NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!
Download CCleaner from here to clean temp files from your computer.
2. Run an online virus scan called Kaspersky from HERE.
2. A new smaller window will pop up. Press on " Accept". After reading the contents.
3. Now Kaspersky will update the anti-virus database. Let it run.
4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK.
5. Then click on " My Computer". And the scan will start.
6. When the scan is complete Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan
"The world is what you make of it"
HLHelms
35 Posts
0
May 13th, 2008 20:00
Part II.
C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\00010009.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP6\A0001009.dll Infected: Trojan-Clicker.Win32.Agent.adg skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP9\change.log Object is locked skipped
C:\VundoFix Backups\avifil32r.dll.bad Infected: Trojan-Clicker.Win32.Agent.adg skipped
C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shlwapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\AppCert\wnl32.dll Infected: Trojan-Spy.Win32.Agent.bzy skipped
C:\WINDOWS\SYSTEM32\ATRACEw.dll Infected: Rootkit.Win32.Podnuha.cb skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS Infected: Trojan.Win32.Qhost skipped
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214022.backup Infected: Trojan.Win32.Qhost skipped
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214407.backup Infected: Trojan.Win32.Qhost skipped
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214516.backup Infected: Trojan.Win32.Qhost skipped
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214654.backup Infected: Trojan.Win32.Qhost skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HLHelms
35 Posts
0
May 13th, 2008 20:00
Here is the report. Nasty stuff. I must have the latest and greatest. Thanks for helping with this. Part I of II.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 13, 2008 2:34:51 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 13/05/2008
Kaspersky Anti-Virus database records: 770742
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 72865
Number of viruses found: 31
Number of infected objects: 64
Number of suspicious objects: 0
Duration of the scan process: 00:44:46
Infected Object Name / Virus Name / Last Action
C:\!KillBox\avifil32r.dll Infected: Trojan-Clicker.Win32.Agent.adg skipped
C:\c6055866124609a34866a5b7ef3e19\sp2\update\update.exe Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7f4a5c38ab58ce7e696c5aa76c483733_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-05062008-022500.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip/MWSBAR.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ba skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip/MWSSRCAS.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3BROVLY.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3DTACTL.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3HISTSW.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3HTMLMU.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3HTTPCT.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3IMSTUB.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3POPSWT.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3PSSAVR.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3REPROX.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3RESTUB.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3SCHMON.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3SCRCTR.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3SHLLVW.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/F3WPHOOK.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3HTML.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3IDLE.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3MSG.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3OUTLCN.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3PLUGIN.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3SKIN.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3SLSRCH.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/M3SRCHMN.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/MWSOEMON.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/MWSOEPLG.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/MWSOESTB.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip/bar/1.bin/NPMYWEBS.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch28.zip ZIP: infected - 26 skipped
C:\Documents and Settings\Henry\.housecall\Quarantine\xpl1[1].wmf.bac_a01028 Infected: Trojan-Downloader.Win32.Agent.acd skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0002/data0005 Infected: Trojan-Downloader.Win32.Agent.ac skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0002/data0006 Infected: Trojan-Downloader.Win32.Turown.h skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0002/data0008 Infected: Trojan-Downloader.Win32.Turown.g skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0002/data0012 Infected: Trojan-Downloader.Win32.VB.cw skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0002 Infected: Trojan-Downloader.Win32.VB.cw skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0003 Infected: Backdoor.Win32.Ruledor.e skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0004 Infected: Trojan-Downloader.Win32.Apropo.h skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0005 Infected: not-a-virus:AdWare.Win32.EZula.l skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0006 Infected: Trojan-Downloader.Win32.QDown.j skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0007/IdmUP.dll Infected: not-a-virus:AdWare.Win32.ToPicks.c skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0007/TPReg.dll Infected: not-a-virus:AdWare.Win32.ToPicks.c skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0007/HtCheck2.dll Infected: not-a-virus:AdWare.Win32.ToPicks.c skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0007/Idhost.exe Infected: not-a-virus:AdWare.Win32.ToPicks.c skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0007 Infected: not-a-virus:AdWare.Win32.ToPicks.c skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392/data0008 Infected: Trojan.Win32.Qhost.bi skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392 NSIS: infected - 15 skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\all_files7.exe.bac_a01392 CryptFF.b: infected - 15 skipped
C:\Documents and Settings\Henry\.housecall6.6\Quarantine\WinGenerics.dll.bac_a01392 Infected: Trojan-Downloader.Win32.Apropo.l skipped
C:\Documents and Settings\Henry\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\gdql_lsa_LinksysAgent.log Object is locked skipped
C:\Documents and Settings\Henry\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\glog.log Object is locked skipped
C:\Documents and Settings\Henry\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent.log Object is locked skipped
C:\Documents and Settings\Henry\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\LinksysAgent_GTActions.log Object is locked skipped
C:\Documents and Settings\Henry\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Henry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Henry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Henry\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{2D53F9F5-98B4-4283-9EF3-9646DBD29EFF} Infected: Trojan.Win32.Qhost skipped
C:\Documents and Settings\Henry\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3E0AC815-C5C1-4C3F-922D-FBB49DE6727F} Infected: Trojan.Win32.Qhost skipped
C:\Documents and Settings\Henry\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9AF92A2F-89FF-478A-AE31-4B68463BC259} Infected: Trojan.Win32.Qhost skipped
C:\Documents and Settings\Henry\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{B7F1B7E8-7564-440A-B15C-6D6148D8FB6A} Infected: Trojan.Win32.Qhost skipped
C:\Documents and Settings\Henry\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Henry\Local Settings\Temp\~DF73.tmp Object is locked skipped
C:\Documents and Settings\Henry\Local Settings\Temp\~DFD727.tmp Object is locked skipped
C:\Documents and Settings\Henry\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Henry\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Henry\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps1 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps2 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\00010002.ci Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.fid Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.hsh Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiCL0001.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP10000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP20000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiPT0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSL0001.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSP0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiST0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiVP0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\INDEX.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk1 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk2 Object is locked skipped
bamajim
10.4K Posts
0
May 14th, 2008 12:00
We have a bunch of junk in various quarantine files, but we still have some work to do.
1.Rerun Killbox
C:\WINDOWS\SYSTEM32\ATRACEw.dll
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214022.backup
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214407.backup
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214516.backup
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20040823-214654.backup
2)Select " Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
5) Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt.
2. Please download HostsXpert 4.0 - Hosts File Manager
3. Reboot your PC ->> Rerun Hijackthis and post a fresh Hiajckthis log.
"The world is what you make of it"
HLHelms
35 Posts
0
May 14th, 2008 13:00
Ran Killbox. There was an error with Hostsexpt can't restore system32/ drivers/ etc/ hosts. Here is the log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:13 AM, on 5/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Henry\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.my.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0ED59684-B985-41A1-B1DE-BD9948C70B28} - c:\windows\system32\avifil32r.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O20 - Winlogon Notify: ddpndavx - avifil32r.dll (file missing)
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 7996 bytes
bamajim
10.4K Posts
0
May 14th, 2008 15:00
Go HERE and Download System Repair Engineer by smallfrogs
Select local download1 or 2
Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREngPS.exe->>Click Run
At the main Window, in the left Pane,Select Smart Scan
At the next window UNCHECK all of the boxes except Hosts File and Select Scan
When the scan is complete Select Save reports
Save it to your desktop and Close the tool
Double Click SREngLog.txt copy and paste that log as a reply to this thread
Do not run any other options with this tool unless instructed to do so.
"The world is what you make of it"
HLHelms
35 Posts
0
May 15th, 2008 05:00
Here it is. My compter is very slow now. The administrator will not let me post the entire log which is very long due to prohibited content. This is a list of hosts from spybot. I uninstalled that program. I ran this twice and got the same log results.
2008-05-14,23:20:16
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
HOSTS File
Boot Items
Registry
N/A
==================================
Startup Folders
N/A
==================================
Services
N/A
==================================
Drivers
N/A
==================================
Browser Add-ons
N/A
==================================
Running Processes
N/A
==================================
File Associations
N/A
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
127.0.0.1 localhost
127.0.0.1 www.f1organizer.com #removed adware url
127.0.0.1 www.netpalnow.com #removed adware url
127.0.0.1 www.addictivetechnologies.com #removed adware url
127.0.0.1 www.mindseti.com #removed adware url
127.0.0.1 www.mindsetinteractive.com #removed adware url
127.0.0.1 coolwebsearch.com
127.0.0.1 stats.coolwebsearch.com
127.0.0.1 www.coolwebsearch.com #[cws/iefeats]
127.0.0.1 1-se.com #[cws.aboutblank][w32.tuoba.trojan]
127.0.0.1 www.1-se.com #[vbs.startpage.c]
127.0.0.1 1stpagehere.com
127.0.0.1 www.1stpagehere.com
127.0.0.1 www.31234.com #[cws.msconfig]
127.0.0.1 356563.net #[win32.winshow.g]
127.0.0.1 www.356563.net
127.0.0.1 4-counter.com #[cws.winproc32][icanfindit.net]
127.0.0.1 75tz.com #[win32.winshow.g]
127.0.0.1 www.75tz.com
127.0.0.1 8ad.com #[parasite.winshow]
127.0.0.1 www.8ad.com
127.0.0.1 adasearch.com
127.0.0.1 www.adasearch.com
127.0.0.1 adulthyperlinks.com #[parasite.coolwebsearch]
127.0.0.1 www.adulthyperlinks.com
127.0.0.1 acc.count-all.com #[cws.tapicfg]
127.0.0.1 aifind.biz
127.0.0.1 www.aifind.biz #[aifind.cc][troj/startpg-bg]
127.0.0.1 aifind.com
127.0.0.1 www.aifind.com
127.0.0.1 aifind.info #[cws.xmlmimefilter][trojan.bookmarker.b,f]
127.0.0.1 allhyperlinks.com #[cws.dnsrelay]
127.0.0.1 www.allhyperlinks.com #[cws.oslogo][cws.oemsyspnp]
127.0.0.1 alfa-search.com #[cws.alfasearch]
127.0.0.1 www.alfa-search.com
127.0.0.1 allneedsearch.com #[troj_startpage.b][find-itnow.com]
127.0.0.1 approvedlinks.com #[super-spider.com]
127.0.0.1 best-search.info #[cws.smartfinder.2]
127.0.0.1 blanksearch.biz #[cws.jksearch]
127.0.0.1 cashsearch.biz #[cws.jksearch]
127.0.0.1 www.clearsearch.net
127.0.0.1 www.coolfreehost.com
127.0.0.1 coolwebsearch.biz
127.0.0.1 www.crooder.com
127.0.0.1 defaultsearching.com #[cws.sounddrv][searchmeup.com]
127.0.0.1 www.e-finder.cc #[cws.addclass.2][startpage-da]
127.0.0.1 ehttp.cc #[cws.addclass][troj_startpage.d]
127.0.0.1 enjoysearch.info #[cws.xxxvideo]
127.0.0.1 www.enjoysearch.info
127.0.0.1 e-plus.cc #[adware.worldsearch]
127.0.0.1 fastsearch.cc #[cws.tapicfg.2][adware.searchcounter]
127.0.0.1 fast-search.us #[cws.docobj]
127.0.0.1 fastwebfinder.com #[app/fastweb-a][adware.fastwebfinder]
127.0.0.1 www.fastwebfinder.com #[cws.aff.tooncomics.2][search.targetwords.com]
127.0.0.1 findemnow.com
127.0.0.1 www.findemnow.com
127.0.0.1 find-itnow.com #[w32.bizten][cws.alfasearch.2]
127.0.0.1 just.find-itnow.com #[startpage-au]
127.0.0.1 www.find-itnow.com #[w32.hostidel.trojan][troj_hostidel.a]
127.0.0.1 findloss.com #[umaxsearch.com]
127.0.0.1 www.findloss.com
127.0.0.1 find-online.net #[troj_startpag.gy]
127.0.0.1 www.find-online.net
127.0.0.1 firstbookmark.com #[parasite.clientman]
127.0.0.1 www.firstbookmark.com
127.0.0.1 www.geo-traffic.com #[redirects to search.msmn.com]
127.0.0.1 globe-finder.cc #[win32.startpage.n]
127.0.0.1 globe-finder.net #[clearsearch.net]
127.0.0.1 www.globe-finder.net
127.0.0.1 global-finder.com #[cws.msinfo]
127.0.0.1 www.global-finder.com
127.0.0.1 gonnasearch.com #[cws.gonnasearch]
127.0.0.1 www.gonnasearch.com #[supaseek.com]
127.0.0.1 greatsearch.biz #[cws.jksearch]
127.0.0.1 greg-search.com #[trojandropper.win32.small.cw]
127.0.0.1 www.greg-search.com
127.0.0.1 hotbookmark.com #[troj/iestart-f]
127.0.0.1 www.hotbookmark.com
127.0.0.1 idgsearch.com #[googlems search helper][cws.googlems]
127.0.0.1 www.idgsearch.com #[trojan.digits]
127.0.0.1 icansearch.net
127.0.0.1 www.icansearch.net
127.0.0.1 ie-search.com #[cws.loadbat][umaxsearch.com]
127.0.0.1 www.ie-search.com
127.0.0.1 iefeadsl.com #[win32.winshow.g]
127.0.0.1 jksearch.biz #[cws.jksearch][startpage-dc]
127.0.0.1 lookfor.cc #[troj_iefeats.a]
127.0.0.1 www.lookfor.cc
127.0.0.1 luckysearch.net #[cws.tapicfg]
127.0.0.1 www.luckysearch.net
127.0.0.1 lustler.com
127.0.0.1 www.lustler.com
127.0.0.1 madfinder.com #[backdoor.madfind][madfinder]
127.0.0.1 www.madfinder.com #[cws.aff.madfinder][downloader-eu]
127.0.0.1 martfinder.com #[adware.startpage][troj/startpa-gh]
127.0.0.1 www.martfinder.com
127.0.0.1 404.msmn.com
127.0.0.1 search.msmn.com
127.0.0.1 gotosearch.msmn.com
127.0.0.1 bjvvhk.t.muxa.cc #[adware.raxums][random sub-domains]
127.0.0.1 myexexex.com #[cws.jsconsole]
127.0.0.1 www.myexexex.com
127.0.0.1 ntsearch.com
127.0.0.1 www.ntsearch.com #[trojan.win32.spooner.d][adware-nsearch]
127.0.0.1 omega-search.com #[cws.olehelp][trojan.bookmarker.d]
127.0.0.1 best.omega-search.com
127.0.0.1 www.omega-search.com
127.0.0.1 payfortraffic.net #[cws.dnsrelay.3][cws.msole]
127.0.0.1 www.payfortraffic.net
127.0.0.1 power-search.info #[trojan.bookmarker.g]
127.0.0.1 www.power-search.info
127.0.0.1 real-yellow-page.com #[cws.realyellowpage]
127.0.0.1 rightfinder.net #[cws.addclass.2]
127.0.0.1 www.rightfinder.net #[troj/startpg-ay]
127.0.0.1 riviera.cc
127.0.0.1 opti.riviera.cc
127.0.0.1 runsearch.com #[cws.mupdate]
127.0.0.1 www.runsearch.com
127.0.0.1 searchcentral.cc
127.0.0.1 searchdesire.com
127.0.0.1 search-dot.com #[cws.systeminit][adware.searchdot]
127.0.0.1 www.search-dot.com
127.0.0.1 searchx.cc #[cws.searchx][trojan.win32.startpage.fw]
127.0.0.1 searchpage.cc
127.0.0.1 search-town.net #[riviera.cc]
127.0.0.1 slawsearch.com #[cws.svchost32]
127.0.0.1 www.slawsearch.com #[cws.ctfmon32]
127.0.0.1 solongas.com #[cws.hputi]
127.0.0.1 start-space.com #[cws.qttasks]
127.0.0.1 www.start-space.com #[search-space.com][navext]
127.0.0.1 supersearch.com
127.0.0.1 www.supersearch.com #[cws.msoffice.3]
127.0.0.1 super-spider.com #[cws.control][troj_krepper.i]
127.0.0.1 tadstore.cc #[cws.addclass.2][rightfinder.net]
127.0.0.1 t.rack.cc #[troj_seeker.b]
127.0.0.1 roquvp.t.rack.cc
127.0.0.1 thebestse.com #[searchmeup.com]
127.0.0.1 www.thebestse.com
127.0.0.1 the-exit.com
127.0.0.1 www.the-exit.com
127.0.0.1 www.the-huns-yellow-pages.com
127.0.0.1 search.thestex.com #[cws.yexe]
127.0.0.1 topfivesearch.com
127.0.0.1 www.topfivesearch.com
127.0.0.1 toteen.com #[trojan.bookmarker.g]
127.0.0.1 out.true-counter.com #[trojan.bootconf][cws.msinfo]
127.0.0.1 true-counter.com #[trojan.slog]
127.0.0.1 www.true-counter.com
127.0.0.1 in.webcounter.cc #[cws.tapicfg.2][adware.searchcounter]
127.0.0.1 www.wholeworldmarket.com #[cws.systeminit.2]
127.0.0.1 www.windowws.cc #[cws.control][search2004.net]
127.0.0.1 world-search.biz #[adware.worldsearch][e-plus.cc]
127.0.0.1 yellow-pages.ws #[searchmeup.com]
127.0.0.1 adult.yellow-pages.ws
127.0.0.1 search.yellow-pages.ws
127.0.0.1 www.yellow500.com #[troj/iestart-f]
127.0.0.1 www.yopta.info #[trojan.bookmarker.c][smart-finder.biz]
127.0.0.1 www.youfindall.com #[cws.aff.winshow]
127.0.0.1 www.your-search.info #[trojan.bookmarker.gen][cws.systeminit]
127.0.0.1 xwebsearch.biz #[cws.svcinit][cws.dreplace][backdoor.sinit
127.0.0.1 search-1.net
127.0.0.1 search-about.net
127.0.0.1 www.search-about.net
127.0.0.1 search-aid.com
127.0.0.1 www.search-aid.com #[coolwebsearch.iefeatsl]
127.0.0.1 search-click.com
127.0.0.1 www.search-click.com
127.0.0.1 search-company.com
127.0.0.1 www.search-company.com
127.0.0.1 search-direct.net
127.0.0.1 www.search-direct.net
127.0.0.1 www.search-and-find.net
127.0.0.1 audioseek.net
127.0.0.1 www.audioseek.net
127.0.0.1 conspy.com
127.0.0.1 conf.conspy.com
127.0.0.1 www.conspy.com
127.0.0.1 searchmyrequest.com #[startpage-bs]
127.0.0.1 conf.searchmyrequest.com #[cws.therealsearch.2]
127.0.0.1 therealsearch.com #[cws.therealsearch]
127.0.0.1 conf.therealsearch.com
127.0.0.1 www.therealsearch.com #[fastwebfinder.com][trojan.realsrch.a]
127.0.0.1 any-find.com
127.0.0.1 www.any-find.com
127.0.0.1 bizonio.com
127.0.0.1 www.bizonio.com
127.0.0.1 dubolom.com
127.0.0.1 www.dubolom.com
127.0.0.1 find4u.net #[cws.ieengine]
127.0.0.1 pilot.find4u.net
127.0.0.1 www.find4u.net
127.0.0.1 free-spy-cam.net
127.0.0.1 getthis4free.com
127.0.0.1 www.getthis4free.com
127.0.0.1 terra.hbison.com
127.0.0.1 hcworld.com
127.0.0.1 free.hcworld.com
127.0.0.1 terra.hcworld.com
127.0.0.1 klounada.com
127.0.0.1 www.klounada.com
HLHelms
35 Posts
0
May 15th, 2008 05:00
127.0.0.1 mypoiskovik.com
127.0.0.1 www.mypoiskovik.com
127.0.0.1 topotun.com #[adware.topotun]
127.0.0.1 www.topotun.com
127.0.0.1 web-cams-chat.com
127.0.0.1 your-searcher.com #[cws.ieengine]
127.0.0.1 activexupdate.com #[cws.oemsyspnp]
127.0.0.1 www.activexupdate.com
127.0.0.1 adult-friends-finder.net
127.0.0.1 coolsearcher.info #[coolsearcher toolbar]
127.0.0.1 www.coolsearcher.info
127.0.0.1 www.coolwebsearch.org
127.0.0.1 fdadfswr.com #[adware.freecomm]
127.0.0.1 www.fdadfswr.com
127.0.0.1 www.netcross.cz #[netcross.cz toolbar]
127.0.0.1 searchcomplete.com #[adware.yellowpages]
127.0.0.1 www.searchcomplete.com
127.0.0.1 searchforge.com
127.0.0.1 ie.searchforge.com #[cws.oemsyspnp.3]
127.0.0.1 www.searchforge.com
127.0.0.1 coolpage.cc #[cws.realyellowpage]
127.0.0.1 ww11.coolpage.cc
127.0.0.1 here4search.com #[downloader.tooncom][cws.aff.tooncomics]
127.0.0.1 www.here4search.com
127.0.0.1 hugesearch.net #[cws.msoffice.3]
127.0.0.1 www.hugesearch.net
127.0.0.1 icanfindit.net
127.0.0.1 www.icanfindit.net #[cws.winproc32]
127.0.0.1 list2004.com #[cws.realyellowpage]
127.0.0.1 linklist.cc #[cws.realyellowpage][adware.raxums][coolpage.cc]
127.0.0.1 ww9.linklist.cc
127.0.0.1 www.linklist.cc
127.0.0.1 my-find.com
127.0.0.1 www.my-find.com
127.0.0.1 royalsearch.net
127.0.0.1 www.royalsearch.net #[vbs.bootconf][cws.msoffice.2]
127.0.0.1 www.search-and-go.com
127.0.0.1 searchdot.net #[cws.msoffice]
127.0.0.1 www.searchdot.net
127.0.0.1 searchmeup.com #[cws.svcinit.3]
127.0.0.1 www.searchmeup.com
127.0.0.1 searchmeup.net
127.0.0.1 www.searchmeup.net
127.0.0.1 thesten.com #[cws.aff.winshow.3]
127.0.0.1 umaxsearch.com #[troj_esepor.a][cws.xplugin]
127.0.0.1 affiliates.umaxsearch.com
127.0.0.1 www.umaxsearch.com
127.0.0.1 uni-dialer.com
127.0.0.1 www.uni-dialer.com
127.0.0.1 00hq.com #[adware.winshow][parasite.winshow]
127.0.0.1 www.00hq.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 008i.com
127.0.0.1 www.008i.com
127.0.0.1 opsex.com
127.0.0.1 www.opsex.com
127.0.0.1 searchv.com #[troj_startpage.u][cws.mupdate]
127.0.0.1 www.searchv.com #[cws.bootconf][searchv.winshow]
127.0.0.1 searchxp.com #[cws.bootconf]
127.0.0.1 www.searchxp.com
127.0.0.1 v61.com #[win32.winshow.g]
127.0.0.1 www.v61.com
127.0.0.1 windowupdate.ws #[cws.aboutblank]
127.0.0.1 winshow.biz
127.0.0.1 www.winshow.biz
127.0.0.1 freescratchandwin.com #[parasite.freescratchandwin]
127.0.0.1 www.freescratchandwin.com
127.0.0.1 free-scratch-cards.com
127.0.0.1 www.free-scratch-cards.com
127.0.0.1 fsc2k.com
127.0.0.1 www.fsc2k.com
127.0.0.1 newtopsites.com
127.0.0.1 servedby.newtopsites.com
127.0.0.1 www.newtopsites.com
127.0.0.1 2nd-thought.com #[parasite.pugi][trojan.win32.secondthought.c]
127.0.0.1 www.2nd-thought.com #[adw_secthought.a][adware.secondthought]
127.0.0.1 xzoomy.com #[freescratchandwin]
127.0.0.1 www.xzoomy.com
127.0.0.1 commonname.com
127.0.0.1 www.commonname.com
127.0.0.1 commonnames.com
127.0.0.1 www.commonnames.com
127.0.0.1 xpsn.com
127.0.0.1 www.xpsn.com
127.0.0.1 info.browserdirect.net
127.0.0.1 search.findsall.info
127.0.0.1 find.greatsearch.info
127.0.0.1 result.goodsearch.info
127.0.0.1 www.esearchandfind.org
127.0.0.1 hit.lookupanything.biz #[qsrch.net]
127.0.0.1 www.new.chat.new.net
127.0.0.1 eps.new.search.new.net
127.0.0.1 client.newdotnet.net
127.0.0.1 upgrade.newdotnet.net
127.0.0.1 www.newdotnet.com
127.0.0.1 www.new.net #[adware.ndotnet]
127.0.0.1 www.onestepsearch.net
127.0.0.1 www.onestepsearch.biz
127.0.0.1 www.qsrch.net
127.0.0.1 bgw.qsrch.com
127.0.0.1 moniker.qsrch.com
127.0.0.1 newnet.qsrch.com
127.0.0.1 regfly.qsrch.com
127.0.0.1 rg.qsrch.com
127.0.0.1 worldwide.qsrch.com
127.0.0.1 www.qsrch.com
127.0.0.1 data.quicksearches.net
127.0.0.1 www.mysearchnet.org
127.0.0.1 web.yoursearchfinder.com
127.0.0.1 windowpatch.info
127.0.0.1 windowpatch.net
127.0.0.1 delfinproject.com
127.0.0.1 content.delfinproject.com
127.0.0.1 mm.delfinproject.com #[delfin media viewer]
127.0.0.1 www.delfinproject.com #[promulgate][kb811270]
127.0.0.1 pgate-basic.com #[pgate-basic]
127.0.0.1 www.pgate-basic.com
127.0.0.1 centralmedia.ws #[flashlightsearch.com]
127.0.0.1 ads.centralmedia.ws
127.0.0.1 c.centralmedia.ws
127.0.0.1 www.centralmedia.ws
127.0.0.1 memorymeter.com #[adware-tvelocity][totalvelocity.memorymeter]
127.0.0.1 www.memorymeter.com
127.0.0.1 totalvelocity.com #[tv t-media display]
127.0.0.1 www.totalvelocity.com
127.0.0.1 zsearchtoolbar.com
127.0.0.1 www.zsearchtoolbar.com
127.0.0.1 bluehavenmedia.com
127.0.0.1 www.bluehavenmedia.com
127.0.0.1 download.bulletproofsoft.com
127.0.0.1 www.bulletproofsoft.com
127.0.0.1 bigbrother.gigatechsoftware.com
127.0.0.1 download.gigatechsoftware.com
127.0.0.1 www.gigatechsoftware.com
127.0.0.1 www.greasycow.com
127.0.0.1 www.nuker.com #[netsource101]
127.0.0.1 www.no-pops.com
127.0.0.1 nopop.net
127.0.0.1 www.nopop.net
127.0.0.1 www.trekblue.com
127.0.0.1 crossroad.trekdata.com
127.0.0.1 1ad2srvr-cpt-v1.com
127.0.0.1 www.srv2cpt.com
127.0.0.1 www.spywarenuker.com #[adware.spywarenuker]
127.0.0.1 twistedhumor.com #[parasite.cometcursor/toolbar]
127.0.0.1 www.twistedhumor.com
127.0.0.1 www.crazydrinks.com
127.0.0.1 www.em5000.com
127.0.0.1 www.rankyou.com
127.0.0.1 www.wayweird.com
127.0.0.1 www.newtonknows.com #[newton knows.bar]
127.0.0.1 virtumundo.com
127.0.0.1 ads3.virtumundo.com
127.0.0.1 ads4.virtumundo.com
127.0.0.1 dyn.virtumundo.com
127.0.0.1 pchi-vtrk.virtumundo.com
127.0.0.1 updates.desktop.virtumundo.com #[targetsoft.inetadpt]
127.0.0.1 vtrack.virtumundo.com
127.0.0.1 www.virtumundo.com
127.0.0.1 www.webhancer.com
127.0.0.1 a1.webhancer.com
127.0.0.1 d.webhancer.com
127.0.0.1 a1.webhancer.com
127.0.0.1 d2.webhancer.com
127.0.0.1 d3.webhancer.com
127.0.0.1 download.webhancer.com
127.0.0.1 prime.webhancer.com
127.0.0.1 reports.webhancer.com
127.0.0.1 server.webhancer.com
127.0.0.1 update.webhancer.com
127.0.0.1 b1-v2-bell.webhancer.com
127.0.0.1 vr1-v1.webhancer.com
127.0.0.1 vws-1.webhancer.com
127.0.0.1 www.realenduser.com
127.0.0.1 www.aadcom.com
127.0.0.1 addictivetechnologies.net
127.0.0.1 www.addictivetechnologies.net #[favoriteman]
127.0.0.1 www.acustat.com
127.0.0.1 www.mindsetinteractive.com
127.0.0.1 mindseti.com #[parasite.transponder]
127.0.0.1 www.mindseti.com
127.0.0.1 netpalnow.com #[adware.netpal]
127.0.0.1 www.netpalnow.com
127.0.0.1 netpaloffers.net #[parasite.netpal]
127.0.0.1 www.netpaloffers.net
127.0.0.1 look2me.com #[spyware.look2me]
127.0.0.1 www.look2me.com #[trojan.loome][download.look2me]
127.0.0.1 www.look2me2.com
127.0.0.1 www.lovetraffic.com
127.0.0.1 nictechnetworks.com
127.0.0.1 www.nictechnetworks.com
127.0.0.1 similarsingles.com
127.0.0.1 www.similarsingles.com
127.0.0.1 zestyfind.com #[adtomi.yahoostocks][adware.adtomi]
127.0.0.1 www.zestyfind.com #[adware.zestyfind]
127.0.0.1 datastorm.biz
127.0.0.1 ipend.datastorm.biz #[parasite.clientman]
127.0.0.1 www.datastorm.biz
127.0.0.1 kazanon.com #[kazanon]
127.0.0.1 www.kazanon.com
127.0.0.1 omi-update.net
127.0.0.1 www.omi-update.net #[adware.omi]
127.0.0.1 messagebroadcaster.net #[messenger pop-up scam]
127.0.0.1 www.messagebroadcaster.net
127.0.0.1 netpopup.net #[messenger pop-up scam]
127.0.0.1 www.netpopup.net
127.0.0.1 odysseusmarketing.com
127.0.0.1 www.odysseusmarketing.com
127.0.0.1 searchassistant.net
127.0.0.1 alpha.searchassistant.net #[7search.com]
127.0.0.1 beta.searchassistant.net #[goclick.com]
127.0.0.1 cassandra.searchassistant.net
127.0.0.1 epsilon.searchassistant.net #[goclick.com]
127.0.0.1 www.searchassistant.net
127.0.0.1 www.unitedvending.net #[affiliate]
127.0.0.1 www.world-portal.com
127.0.0.1 ads.vx2.cc
127.0.0.1 download.vx2.cc
127.0.0.1 internal.vx2.cc
bamajim
10.4K Posts
0
May 15th, 2008 12:00
Rerun SRE2
In the Left Pane Select System Repair
In the Rt Pane Under the Hosts File tab
At the Bottom of the Rt Pane Select Reset ->> Yes to Confirm.
It should delete all of those entries except 127.0.0.1 Local Host.
If it does, Close SRE2 and reboot your PC
If it does not, then you are going to have to Hilite the entries one by one and Select Delete
Do this for all of the entries except 127.0.0.1 Local Host
Then close SRE2 and reboot your PC.
"The world is what you make of it"
HLHelms
35 Posts
0
May 15th, 2008 13:00
Done. Here is the new log.
2008-05-15,07:12:55
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
HOSTS File
Boot Items
Registry
N/A
==================================
Startup Folders
N/A
==================================
Services
N/A
==================================
Drivers
N/A
==================================
Browser Add-ons
N/A
==================================
Running Processes
N/A
==================================
File Associations
N/A
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
127.0.0.1 localhost
==================================
Process Privileges Scan
N/A
==================================
API HOOK
N/A
==================================
Hidden Process
N/A
==================================
HLHelms
35 Posts
0
May 15th, 2008 13:00
Here it is. Part I of II.
CODE]
2008-05-15,07:37:33
System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<> [N/A]
<"C:\Program Files\Microsoft Money\System\mnyexpr.exe"> [N/A]
[(Verified)Microsoft Windows Publisher]
<"C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup> [(Verified)Cisco-Linksys LLC]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[Dell - Advanced Desktop Engineering]
<-> [N/A]
<"C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"> [(Verified)Symantec Corporation]
[Sonic Solutions]
<"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r> [Sonic Solutions]
<"C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l> [Visual Networks]
<"C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"> [Visual Networks]
[(Verified)Symantec Corporation]
[Dell]
<"C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"> [Lexmark International, Inc.]
<"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<"C:\Program Files\iTunes\iTunesHelper.exe"> [(Verified)"Apple Computer, Inc."]
<"C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"> [(Verified)"Seagate Technology, LLC"]
<"C:\Program Files\Windows Defender\MSASCui.exe" -hide> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[(Verified)Microsoft Windows Publisher]
[(Verified)Microsoft Windows Publisher]
[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{81559C35-8464-49F7-BB0E-07A383BEF910}> []
<{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddpndavx]
[N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
[(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
[Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}]
<%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
[Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8b15971b-5355-4c82-8c07-7e181ea07608}]
[(Verified)Microsoft Windows Publisher]
==================================
Startup Folders
[Adobe Reader Speed Launch]
C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE [Adobe Systems Incorporated]>
[SpywareGuard]
C:\PROGRA~1\SPYWAR~2\sgmain.exe []>
[TrueAssistant]
C:\PROGRA~1\TRUEAS~1\TRUEAS~1.EXE [Esaya, Inc.]>
==================================
Services
[Application Management / AppMgmt][Stopped/Disabled]
%SystemRoot%\System32\appmgmts.dll>
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
[Basics Service / Basics Service][Running/Auto Start]
<"C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe">
[Symantec Event Manager / ccEvtMgr][Stopped/Disabled]
<->
[Symantec Password Validation Service / ccPwdSvc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe">
[Human Interface Device Access / HidServ][Stopped/Disabled]
%SystemRoot%\System32\hidserv.dll>
[iPod Service / iPod Service][Running/Manual Start]
<"C:\Program Files\iPod\bin\iPodService.exe">
[LexBce Server / LexBceS][Running/Auto Start]
[Norton AntiVirus Auto Protect Service / navapsvc][Running/Auto Start]
<"C:\Program Files\Norton AntiVirus\navapsvc.exe">
[Intel NCS NetService / NetSvc][Stopped/Manual Start]
[NVIDIA Driver Helper Service / NVSvc][Running/Auto Start]
[ScriptBlocking Service / SBService][Stopped/Auto Start]
[Symantec Network Drivers Service / SNDSrvc][Stopped/Disabled]
<->
[OMCI WDM Device Controller / sqdtronn][Stopped/Auto Start]
C:\WINDOWS\system32\avifil32r.dll>
[SymWMI Service / SymWSC][Running/Auto Start]
<"C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe">
==================================
Drivers
[abp480n5 / abp480n5][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\ABP480N5.SYS>
[adpu160m / adpu160m][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\adpu160m.sys>
[aeaudio / aeaudio][Running/Manual Start]
[Intel AGP Bus Filter / agp440][Running/Boot Start]
<\SystemRoot\\SystemRoot\System32\DRIVERS\agp440.sys>
[Aha154x / Aha154x][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\aha154x.sys>
[aic78u2 / aic78u2][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\aic78u2.sys>
[aic78xx / aic78xx][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\aic78xx.sys>
[AliIde / AliIde][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\aliide.sys>
[AMD AGP Bus Filter Driver / amdagp][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\amdagp.sys>
[asc / asc][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\asc.sys>
[asc3350p / asc3350p][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\asc3350p.sys>
[asc3550 / asc3550][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\asc3550.sys>
[cd20xrnt / cd20xrnt][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\cd20xrnt.sys>
[CmdIde / CmdIde][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\cmdide.sys>
[dac2w2k / dac2w2k][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\dac2w2k.sys>
[dpti2o / dpti2o][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\dpti2o.sys>
[drvmcdb / drvmcdb][Running/Boot Start]
<\SystemRoot\system32\drivers\drvmcdb.sys>
[drvnddm / drvnddm][Running/Auto Start]
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
[3Com EtherLink XL 90XB/C Adapter Driver / EL90XBC][Stopped/Manual Start]
<3Com Corporation>
[GoProto Protocol Driver for LELA / elagopro][Running/Auto Start]
[UniDriver for LELA / elaunidr][Running/Auto Start]
[GEAR CDRom Filter / GEARAspiWDM][Running/Manual Start]
[HSFHWBS2 / HSFHWBS2][Running/Manual Start]
[HSF_DP / HSF_DP][Running/Manual Start]
[i81x / i81x][Stopped/Manual Start]
[iAimFP0 / iAimFP0][Stopped/Manual Start]
[iAimFP1 / iAimFP1][Stopped/Manual Start]
[iAimFP2 / iAimFP2][Stopped/Manual Start]
[iAimFP3 / iAimFP3][Stopped/Manual Start]
[iAimFP4 / iAimFP4][Stopped/Manual Start]
[iAimTV0 / iAimTV0][Stopped/Manual Start]
[iAimTV1 / iAimTV1][Stopped/Manual Start]
[iAimTV2 / iAimTV2][Stopped/Manual Start]
[iAimTV3 / iAimTV3][Stopped/Manual Start]
[iAimTV4 / iAimTV4][Stopped/Manual Start]
[ini910u / ini910u][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\ini910u.sys>
[mdmxsdk / mdmxsdk][Running/Auto Start]
[mraid35x / mraid35x][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\mraid35x.sys>
[MREMPR5 NDIS Protocol Driver / MREMPR5][Stopped/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS>
[MRENDIS5 NDIS Protocol Driver / MRENDIS5][Stopped/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS>
[NAVENG / NAVENG][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20040218.021\NAVENG.Sys>
[NAVEX15 / NAVEX15][Running/Manual Start]
<\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20040218.021\NavEx15.Sys>
[nv / nv][Running/Manual Start]
[OMCI WDM Device Driver / omci][Running/System Start]
[PCAMPR5 NDIS Protocol Driver / PCAMPR5][Stopped/Manual Start]
<\??\C:\WINDOWS\System32\PCAMPR5.SYS>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\DRIVERS\PxHelp20.sys>
[ql1080 / ql1080][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\ql1080.sys>
[Ql10wnt / Ql10wnt][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\ql10wnt.sys>
[ql12160 / ql12160][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\ql12160.sys>
[ql1280 / ql1280][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\ql1280.sys>
[rpljspfv / rpljspfv][Running/Boot Start]
<\SystemRoot\system32\drivers\pgplitna.dat>
[SAVRT / SAVRT][Stopped/Disabled]
<->
HLHelms
35 Posts
0
May 15th, 2008 13:00
Part II.
[SAVRTPEL / SAVRTPEL][Running/Auto Start]
<\??\C:\WINDOWS\System32\Drivers\SAVRTPEL.SYS>
[Secdrv / Secdrv][Stopped/Manual Start]
[SIS AGP Bus Filter / sisagp][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\sisagp.sys>
[smwdm / smwdm][Running/Manual Start]
[Sony Digital Imaging Video2 / sonypvs1][Stopped/Manual Start]
[Sparrow / Sparrow][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\sparrow.sys>
[sscdbhk5 / sscdbhk5][Running/System Start]
[ssrtln / ssrtln][Running/System Start]
[symc810 / symc810][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\symc810.sys>
[symc8xx / symc8xx][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\symc8xx.sys>
[SymEvent / SymEvent][Running/Manual Start]
<\??\C:\Program Files\Symantec\SYMEVENT.SYS>
[SYMREDRV / SYMREDRV][Stopped/Manual Start]
<\SystemRoot\System32\Drivers\SYMREDRV.SYS>
[SYMTDI / SYMTDI][Stopped/Disabled]
<->
[sym_hi / sym_hi][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\sym_hi.sys>
[sym_u3 / sym_u3][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\sym_u3.sys>
[tfsnboio / tfsnboio][Running/Auto Start]
[tfsncofs / tfsncofs][Running/Auto Start]
[tfsndrct / tfsndrct][Running/Auto Start]
[tfsndres / tfsndres][Running/Auto Start]
[tfsnifs / tfsnifs][Running/Auto Start]
[tfsnopio / tfsnopio][Running/Auto Start]
[tfsnpool / tfsnpool][Running/Auto Start]
[tfsnudf / tfsnudf][Running/Auto Start]
[tfsnudfa / tfsnudfa][Running/Auto Start]
[TosIde / TosIde][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\toside.sys>
[ultra / ultra][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\ultra.sys>
[ViaIde / ViaIde][Stopped/Disabled]
<\SystemRoot\System32\DRIVERS\viaide.sys>
[WAN Miniport (ATW) / wanatw][Stopped/Manual Start]
[winachsf / winachsf][Running/Manual Start]
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
==================================
Browser Add-ons
[Yahoo! Companion BHO]
{02478D38-C3F9-4efb-9B51-7695ECA05670}
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[]
{0ED59684-B985-41A1-B1DE-BD9948C70B28}
[SpywareGuardDLBLOCK.CBrowserHelper]
{4A368E80-174F-4872-96B5-0B27DDD11DB2}
[DriveLetterAccess]
{5CA3D70E-1895-11CF-8E15-001234567890}
[CNavExtBho Class]
{BDF3E430-B101-42AD-A544-FADC6B084872}
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683}
[Norton AntiVirus]
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
[Yahoo! Companion]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[HouseCall Control]
{04E214E5-63AF-4236-83C6-A7ADCBF9BD02}
[CKAVWebScan Object]
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}
[Shockwave ActiveX Control]
{166B1BCA-3F9C-11CF-8075-444553540000}
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700}
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A}
[Installation Support]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
[Housecall ActiveX 6.5]
{6E5A37BF-FD42-463A-877C-4EB7002E68AE}
[HouseCall Control]
{74D05D43-3236-11D4-BDCD-00C04F9A3B61}
[Java Plug-in 1.4.2]
{8AD9C840-044E-11D1-B3E9-00805F499D93}
[Java Plug-in 1.4.2]
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000}
[Yahoo! Companion BHO]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[Web Browser Applet Control]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
[CKAVWebScan Object]
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}
[]
{0ED59684-B985-41A1-B1DE-BD9948C70B28}
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700}
[Trend Micro ActiveX Scan Agent 6.6]
{215B8138-A3CF-44C5-803F-8226143CFC0A}
[ActionListener Class]
{2DCCEF96-A260-41CD-91B4-2B30212B5B24}
[Norton AntiVirus]
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
[SpywareGuardDLBLOCK.CBrowserHelper]
{4A368E80-174F-4872-96B5-0B27DDD11DB2}
[DriveLetterAccess]
{5CA3D70E-1895-11CF-8E15-001234567890}
[CKAVReportCtrl Object]
{6117669B-8C2D-41FA-A6D9-9E484B999CF0}
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6}
[Microsoft Scriptlet Component]
{AE24FDAE-03C6-11D1-8B76-0080C744F389}
[SearchAssistantOC]
{B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
[CNavExtBho Class]
{BDF3E430-B101-42AD-A544-FADC6B084872}
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000}
[Yahoo! Companion]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[TreeView Class]
{FEA065BD-91EB-4186-9AAF-76D8F43EB5CE}
==================================
Running Processes
N/A
==================================
File Associations
N/A
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
N/A
==================================
Process Privileges Scan
N/A
==================================
API HOOK
N/A
==================================
Hidden Process
N/A
==================================
[/CODE]
bamajim
10.4K Posts
0
May 15th, 2008 13:00
Nice.
Since SRE2 is useful for admin issues, lets see if we can use it to get rid of those 2 entries that won't delete.
Rerun SRE2
Select Smart Scan
In the Rt pane place checks next to
All Boot Items
Browser Add-ons
And uncheck the other items
Select Scan and post the results of that SRE2 log
"The world is what you make of it"
bamajim
10.4K Posts
0
May 15th, 2008 14:00
Rerun SRE2
In the Left Pane Select " System Repair"
In the Right Pane under the Browser Add-ons tab locate
[] {0ED59684-B985-41A1-B1DE-BD9948C70B28} c:\windows\system32\avifil32r.dll,
Using the image provided you can expand the width of the CLSID columb to locate the entry
Once you find it, Hilite it and Select "Delete Selected"
See if SRE deletes it, then reply and we will go from there.
"The world is what you make of it"
HLHelms
35 Posts
0
May 15th, 2008 14:00