3 pop-ups ctd.

  • Thread starter Thread starter cps
  • Start date Start date
C

cps

I have tried Ad-aware and Spybot and cannot get rid of 3
pop-ups in IE 6.0. Following is the HiJackThis report.
Anything suspicious here? Thanks.

-------------

Logfile of HijackThis v1.98.0
Scan saved at 9:49:35 AM, on 7/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\mcc.exe
C:\Program Files\SETI@home\[email protected]
C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971
\Program\Kodak Software Updater.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-
LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\cs\Desktop\HijackThis.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://novascotia.cbc.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local
Page = C:\WINDOWS\SYSTEM\blank.htm
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-
072E-44cf-8957-5838F569A31D} - C:\Program
Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-
8333-CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-
FADC6B084872} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-
423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32
\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common
Files\Symantec Shared\CfgWiz.exe /GUID
NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1
\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Multimedia Codecs] C:\WINDOWS\System32
\mcc.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!
\Stopzilla.exe" /autorun
O4 - HKCU\..\Run: [seticlient] C:\Program
Files\SETI@home\[email protected] -min
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk =
C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk =
C:\Program Files\Kodak\KODAK Software Updater\7288971
\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search -
res://c:\program
files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links -
res://c:\program
files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://c:\program
files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages -
res://c:\program
files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://c:\program
files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-
983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-
11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} -
http://dl.filekicker.com/send/file/128985-
NZIL/PhPSetup.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E}
(MetaStreamCtl Class) -
https://components.viewpoint.com/MTSInstallers/MetaStream3
..cab?url=http://www.viewpoint.com/cgi-
bin/vet_install_popup.pl?
1&04.00.07.02&http://www.bhg.com/bhg/category.jhtml;jsessi
onid=HTHBBJS2A5OFFQFIBQNSCZWAVABB4IV0?
categoryid=/templatedata/bhg/category/data/coloraroom_bedr
oom1.xml
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/Av
Sniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
(Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bi
n/cabsa.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove
Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D}
(Toontown Installer ActiveX Control) -
http://download.toontown.com/sv1.0.12.17/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C}
(Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.c
ab
 
Hey..

First pls let us know if the pop-ups you get are
Advertisments on webpages OR windows messages pop-ups.

1) Click on Start --> Run --> Services.msc --> press
Enter --> from the services list select and
open "Messenger" --> in there from the drop-down in the
center select "Disabled" and then click on the "Start"
button just below it.
The above step will help you to resolve the windows
message pop-ups issues.

Now, to resolve webpage pop-up issues open -
http://www.doxdesk.com/parasite/ weblink in an Internet
Explorer browser window , this is a very efective online
tool, this will scan for spywares on your computer
automatically and will provide you with the steps to
remove them from your computer.


-----Original Message-----
I have tried Ad-aware and Spybot and cannot get rid of 3
pop-ups in IE 6.0. Following is the HiJackThis report.
Anything suspicious here? Thanks.

-------------

Logfile of HijackThis v1.98.0
Scan saved at 9:49:35 AM, on 7/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\mcc.exe
C:\Program Files\SETI@home\[email protected]
C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971
\Program\Kodak Software Updater.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-
LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\cs\Desktop\HijackThis.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://novascotia.cbc.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local
Page = C:\WINDOWS\SYSTEM\blank.htm
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-
072E-44cf-8957-5838F569A31D} - C:\Program
Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-
8333-CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-
FADC6B084872} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-
423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32
\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common
Files\Symantec Shared\CfgWiz.exe /GUID
NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1
\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Multimedia Codecs] C:\WINDOWS\System32
\mcc.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!
\Stopzilla.exe" /autorun
O4 - HKCU\..\Run: [seticlient] C:\Program
Files\SETI@home\[email protected] -min
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk =
C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk =
C:\Program Files\Kodak\KODAK Software Updater\7288971
\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search -
res://c:\program
files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links -
res://c:\program
files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://c:\program
files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages -
res://c:\program
files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://c:\program
files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-
983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-
11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} -
http://dl.filekicker.com/send/file/128985-
NZIL/PhPSetup.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E}
(MetaStreamCtl Class) -
https://components.viewpoint.com/MTSInstallers/MetaStream3
..cab?url=http://www.viewpoint.com/cgi-
bin/vet_install_popup.pl?
1&04.00.07.02&http://www.bhg.com/bhg/category.jhtml;jsessi
onid=HTHBBJS2A5OFFQFIBQNSCZWAVABB4IV0?
categoryid=/templatedata/bhg/category/data/coloraroom_bedr
oom1.xml
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/Av
Sniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
(Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bi
n/cabsa.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove
Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D}
(Toontown Installer ActiveX Control) -
http://download.toontown.com/sv1.0.12.17/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C}
(Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.c
ab


.
 
Update your virus definition files.
You possibly have this one in your computer.

http://www.symantec.com/avcenter/venc/data/backdoor.bigfoot.html

Not sure if the pop ups are from this malware.
This may help.
How To: Deal with Unwanted Pop-ups
http://www.mvps.org/winhelp2002/nopopups.htm
--

Henri Leboeuf
Web page: http://www.colba.net/~hlebo49/index.htm
===
cps said:
IE actually opens a new webpage.
-----Original Message-----
Hey..

First pls let us know if the pop-ups you get are
Advertisments on webpages OR windows messages pop-ups.

1) Click on Start --> Run --> Services.msc --> press
Enter --> from the services list select and
open "Messenger" --> in there from the drop-down in the
center select "Disabled" and then click on the "Start"
button just below it.
The above step will help you to resolve the windows
message pop-ups issues.

Now, to resolve webpage pop-up issues open -
http://www.doxdesk.com/parasite/ weblink in an Internet
Explorer browser window , this is a very efective online
tool, this will scan for spywares on your computer
automatically and will provide you with the steps to
remove them from your computer.


-----Original Message-----
I have tried Ad-aware and Spybot and cannot get rid of 3
pop-ups in IE 6.0. Following is the HiJackThis report.
Anything suspicious here? Thanks.

-------------

Logfile of HijackThis v1.98.0
Scan saved at 9:49:35 AM, on 7/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\mcc.exe
C:\Program Files\SETI@home\[email protected]
C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971
\Program\Kodak Software Updater.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-
LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\cs\Desktop\HijackThis.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://novascotia.cbc.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local
Page = C:\WINDOWS\SYSTEM\blank.htm
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-
072E-44cf-8957-5838F569A31D} - C:\Program
Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-
8333-CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-
FADC6B084872} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-
423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32
\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238- 8AD1-
7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common
Files\Symantec Shared\CfgWiz.exe /GUID
NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1
\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Multimedia Codecs] C:\WINDOWS\System32
\mcc.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!
\Stopzilla.exe" /autorun
O4 - HKCU\..\Run: [seticlient] C:\Program
Files\SETI@home\[email protected] -min
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk =
C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk =
C:\Program Files\Kodak\KODAK Software Updater\7288971
\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search -
res://c:\program
files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links -
res://c:\program
files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://c:\program
files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages -
res://c:\program
files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://c:\program
files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-
983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-
11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1 \MSMSGS.EXE
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} -
http://dl.filekicker.com/send/file/128985-
NZIL/PhPSetup.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E}
(MetaStreamCtl Class) -
https://components.viewpoint.com/MTSInstallers/MetaStrea m3
..cab?url=http://www.viewpoint.com/cgi-
bin/vet_install_popup.pl?
1&04.00.07.02&http://www.bhg.com/bhg/category.jhtml;jses si
onid=HTHBBJS2A5OFFQFIBQNSCZWAVABB4IV0?
categoryid=/templatedata/bhg/category/data/coloraroom_be dr
oom1.xml
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/ Av
Sniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
(Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/ bi
n/cabsa.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove
Control) -
http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D}
(Toontown Installer ActiveX Control) -
http://download.toontown.com/sv1.0.12.17/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C}
(Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr .c
ab


.
.
 
Back
Top