A Windows 98 & ME forum. Win98banter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » Win98banter forum » Windows ME » Internet
Site Map Home Authors List Search Today's Posts Mark Forums Read Web Partners

Hijack This log file please help!!



 
 
Thread Tools Display Modes
  #1  
Old August 11th 04, 01:57 AM
Andria
external usenet poster
 
Posts: n/a
Default Hijack This log file please help!!

I ran the Hijack This program on my computer and this is
the log file:

Logfile of HijackThis v1.98.2
Scan saved at 4:13:06 PM, on 8/10/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MOUSE SOFTWARE\BALLY4D.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NSCHED32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\IMAPD.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TEMP\TD_0005.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = http://www.swvaol.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/cust...defaults/sp/ym
sgr/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://www.netscope.net/
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://red.clientapps.yahoo.com/cust...defaults/stp/y
msgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://red.clientapps.yahoo.com/cust...defaults/su/ym
sgr/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/cust...defaults/sp/ym
sgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,
(Default) =
http://red.clientapps.yahoo.com/cust...defaults/su/ym
sgr/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-
7695ECA05670} - C:\PROGRAM FILES\YAHOO!
\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-
216055BF9918} - (no file)
O2 - BHO: G1.GZ - {79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} -
C:\WINDOWS\ALL USERS\APPLICATION DATA\PRIBI\PRIBI.DLL
O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-16FAC1639198} -
C:\WINDOWS\ALL USERS\APPLICATION
DATA\IESERVICE\IESERVICE.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {82599E0A-8C81-11d7-9F97-
0050FC5441CB} - C:\WINDOWS\SYSTEM\shdocvw.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-
0090271D4F88} - C:\PROGRAM FILES\YAHOO!
\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O4 - HKLM\..\Run: [ScanRegistry]
C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HorngTech4D] C:\PROGRA~1\MOUSES~1
\BALLY4D.EXE
O4 - HKLM\..\Run: [LexStart] LexStart.EXE
O4 - HKLM\..\Run: [QuickTime
Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [obbcyeek] C:\WINDOWS\SYSTEM\yrmxlz.exe
O4 - HKLM\..\Run: [UYLKL] C:\WINDOWS\TEMP\UYLKL.EXE
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1
\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [imapd] C:\WINDOWS\SYSTEM\imapd.exe
O4 - HKLM\..\RunServices: [*StateMgr]
C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN
Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [\IEService.exe] C:\WINDOWS\ALLUSE~1
\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [\Pribi.exe] C:\WINDOWS\ALLUSE~1\APPLIC~1
\PRIBI\Pribi.exe
O4 - Startup: Norton Program Scheduler.lnk = C:\Program
Files\Norton AntiVirus\NSCHED32.EXE
O8 - Extra context menu item: Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-
00010333D0AD} - C:\PROGRAM FILES\YAHOO!
\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-
4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!
\MESSENGER\YHEXBMES0411.DLL (file missing)
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32
Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {1552B1CD-8CB7-4776-B6CB-16EA461928E5} (Cpuid
Control) -
http://powe45.vwh.net/downloads/upgradefinder.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN
Photo Upload Tool) -
http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000}
(YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yaho...installs/yse/y
mmapi_416.dll

Can someone please analyze this and tell me whats wrong
with my computer? I keep getting these annoying frames on
the sides of search engines like Yahoo, MSN, and Google
that say "Server Application Unavailable" and its on the
right side then this other thing in a frame comes up on
the left side that has sponsered links to whatever I'm
searching for and at the top the address it has it
http://fastfinds.org and an X to close. I have Spybot,
Stinger, CW Shredder, and Norton and I have ran all of
these. Spybot has gotten rid of about 12 different
things, stinger 1 and Norton a couple. I did have ad
aware but it kept freezing up my computer and never
finished a scan and never found anything so I un-installed
it. Thank you.
  #2  
Old August 12th 04, 05:40 AM
Lawrence Abrams
external usenet poster
 
Posts: n/a
Default Hijack This log file please help!!

Hijackthis logs are difficult to do in this medium. if you want some help
you are more than welcome to do the following:

Create a directory on your hardrive to save HijackThis.exe. A directory
like c:\hijackthis. If you do not do this, you will not be able to use the
backup/restore features.

Download HijackThis from:

http://www.spywareinfo.com/~merijn/files/hijackthis.zip

or he

http://www.bleepingcomputer.com/file...hijackthis.zip

Save this file into the directory you made previously and then run the
program named hijackthis.exe. When the program opens click on the Config
button, then click on the Misc Tools button, and click on the Check for
update online button. When it completes checking/applying updates press the
back button.

Now click on the Scan button and when it is finished click on the Save Log
button. A Notepad window will open with the contents of this log. Click on
Edit then click on Select all. Then click on Edit and then Click on Copy.

Register an account at http://www.bleepingcomputer.com and post this created
log into the Hijackthis Logs forum at that site. To do this, once you are
registered, create a new post, right click in message area and select paste
to paste the log into the post.

An expert will reply to you after reading this post. DO NOT fix any entries
unless you are absolutely sure you know what you are doing as you may cause
more damage to the system

To see a tutorial on using HijackThis you can click on the link below.
http://www.bleepingcomputer.com/foru...howtutorial=42

--
Lawrence Abrams
http://www.bleepingcomputer.com
Source for Original Content, Tutorials, and Support for the beginning
computer user.
"Andria" wrote in message
...
I ran the Hijack This program on my computer and this is
the log file:

Logfile of HijackThis v1.98.2
Scan saved at 4:13:06 PM, on 8/10/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MOUSE SOFTWARE\BALLY4D.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NSCHED32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\IMAPD.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TEMP\TD_0005.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = http://www.swvaol.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/cust...defaults/sp/ym
sgr/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://www.netscope.net/
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://red.clientapps.yahoo.com/cust...defaults/stp/y
msgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://red.clientapps.yahoo.com/cust...defaults/su/ym
sgr/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/cust...defaults/sp/ym
sgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,
(Default) =
http://red.clientapps.yahoo.com/cust...defaults/su/ym
sgr/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-
7695ECA05670} - C:\PROGRAM FILES\YAHOO!
\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-
216055BF9918} - (no file)
O2 - BHO: G1.GZ - {79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} -
C:\WINDOWS\ALL USERS\APPLICATION DATA\PRIBI\PRIBI.DLL
O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-16FAC1639198} -
C:\WINDOWS\ALL USERS\APPLICATION
DATA\IESERVICE\IESERVICE.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {82599E0A-8C81-11d7-9F97-
0050FC5441CB} - C:\WINDOWS\SYSTEM\shdocvw.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-
0090271D4F88} - C:\PROGRAM FILES\YAHOO!
\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O4 - HKLM\..\Run: [ScanRegistry]
C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HorngTech4D] C:\PROGRA~1\MOUSES~1
\BALLY4D.EXE
O4 - HKLM\..\Run: [LexStart] LexStart.EXE
O4 - HKLM\..\Run: [QuickTime
Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [obbcyeek] C:\WINDOWS\SYSTEM\yrmxlz.exe
O4 - HKLM\..\Run: [UYLKL] C:\WINDOWS\TEMP\UYLKL.EXE
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1
\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [imapd] C:\WINDOWS\SYSTEM\imapd.exe
O4 - HKLM\..\RunServices: [*StateMgr]
C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN
Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [\IEService.exe] C:\WINDOWS\ALLUSE~1
\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [\Pribi.exe] C:\WINDOWS\ALLUSE~1\APPLIC~1
\PRIBI\Pribi.exe
O4 - Startup: Norton Program Scheduler.lnk = C:\Program
Files\Norton AntiVirus\NSCHED32.EXE
O8 - Extra context menu item: Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-
00010333D0AD} - C:\PROGRAM FILES\YAHOO!
\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-
4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!
\MESSENGER\YHEXBMES0411.DLL (file missing)
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32
Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {1552B1CD-8CB7-4776-B6CB-16EA461928E5} (Cpuid
Control) -
http://powe45.vwh.net/downloads/upgradefinder.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN
Photo Upload Tool) -
http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000}
(YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yaho...installs/yse/y
mmapi_416.dll

Can someone please analyze this and tell me whats wrong
with my computer? I keep getting these annoying frames on
the sides of search engines like Yahoo, MSN, and Google
that say "Server Application Unavailable" and its on the
right side then this other thing in a frame comes up on
the left side that has sponsered links to whatever I'm
searching for and at the top the address it has it
http://fastfinds.org and an X to close. I have Spybot,
Stinger, CW Shredder, and Norton and I have ran all of
these. Spybot has gotten rid of about 12 different
things, stinger 1 and Norton a couple. I did have ad
aware but it kept freezing up my computer and never
finished a scan and never found anything so I un-installed
it. Thank you.



  #3  
Old August 15th 04, 07:58 AM
Sandi - Microsoft MVP
external usenet poster
 
Posts: n/a
Default

Hi Andria,

The gang at http://forum.aumha.org/ are experts in HijackThis logs, the
contributors including many top shelf malware experts including Tony Klein,
Siljaline and many others. You are more than welcome to post for assistance
there.

--
_______________________________________
Sandi - Microsoft MVP since 1999 (IE/OE)
http://inetexplorer.mvps.org

"Andria" wrote in message
...
I ran the Hijack This program on my computer and this is
the log file:

Logfile of HijackThis v1.98.2
Scan saved at 4:13:06 PM, on 8/10/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MOUSE SOFTWARE\BALLY4D.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NSCHED32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\IMAPD.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TEMP\TD_0005.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = http://www.swvaol.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/cust...defaults/sp/ym
sgr/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://www.netscope.net/
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://red.clientapps.yahoo.com/cust...defaults/stp/y
msgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://red.clientapps.yahoo.com/cust...defaults/su/ym
sgr/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Page =
http://red.clientapps.yahoo.com/cust...defaults/sp/ym
sgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,
(Default) =
http://red.clientapps.yahoo.com/cust...defaults/su/ym
sgr/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-
7695ECA05670} - C:\PROGRAM FILES\YAHOO!
\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-
216055BF9918} - (no file)
O2 - BHO: G1.GZ - {79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} -
C:\WINDOWS\ALL USERS\APPLICATION DATA\PRIBI\PRIBI.DLL
O2 - BHO: E.HH - {9E992732-295F-4987-8BE3-16FAC1639198} -
C:\WINDOWS\ALL USERS\APPLICATION
DATA\IESERVICE\IESERVICE.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {82599E0A-8C81-11d7-9F97-
0050FC5441CB} - C:\WINDOWS\SYSTEM\shdocvw.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-
0090271D4F88} - C:\PROGRAM FILES\YAHOO!
\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O4 - HKLM\..\Run: [ScanRegistry]
C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HorngTech4D] C:\PROGRA~1\MOUSES~1
\BALLY4D.EXE
O4 - HKLM\..\Run: [LexStart] LexStart.EXE
O4 - HKLM\..\Run: [QuickTime
Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [obbcyeek] C:\WINDOWS\SYSTEM\yrmxlz.exe
O4 - HKLM\..\Run: [UYLKL] C:\WINDOWS\TEMP\UYLKL.EXE
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1
\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [imapd] C:\WINDOWS\SYSTEM\imapd.exe
O4 - HKLM\..\RunServices: [*StateMgr]
C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN
Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [\IEService.exe] C:\WINDOWS\ALLUSE~1
\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [\Pribi.exe] C:\WINDOWS\ALLUSE~1\APPLIC~1
\PRIBI\Pribi.exe
O4 - Startup: Norton Program Scheduler.lnk = C:\Program
Files\Norton AntiVirus\NSCHED32.EXE
O8 - Extra context menu item: Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-
00010333D0AD} - C:\PROGRAM FILES\YAHOO!
\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-
4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!
\MESSENGER\YHEXBMES0411.DLL (file missing)
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32
Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {1552B1CD-8CB7-4776-B6CB-16EA461928E5} (Cpuid
Control) -
http://powe45.vwh.net/downloads/upgradefinder.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN
Photo Upload Tool) -
http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000}
(YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yaho...installs/yse/y
mmapi_416.dll

Can someone please analyze this and tell me whats wrong
with my computer? I keep getting these annoying frames on
the sides of search engines like Yahoo, MSN, and Google
that say "Server Application Unavailable" and its on the
right side then this other thing in a frame comes up on
the left side that has sponsered links to whatever I'm
searching for and at the top the address it has it
http://fastfinds.org and an X to close. I have Spybot,
Stinger, CW Shredder, and Norton and I have ran all of
these. Spybot has gotten rid of about 12 different
things, stinger 1 and Norton a couple. I did have ad
aware but it kept freezing up my computer and never
finished a scan and never found anything so I un-installed
it. Thank you.


 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
rundll dibbley Software & Applications 1 July 22nd 04 03:25 PM
Why is everything saving to notepad? Lestat General 1 July 18th 04 05:38 AM
Please help! Display settings !! Mitzi Monitors & Displays 12 July 11th 04 05:19 AM
Win98SE - problem with USB printer HBYardSale Software & Applications 2 June 20th 04 06:27 PM
Long file name Problem Canapril General 1 June 12th 04 03:36 AM


All times are GMT +1. The time now is 04:14 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 Win98banter.
The comments are property of their posters.