-----Original Message-----
on your Internet Explorer toolbar.
Alexa technology does use a 'web crawler' (bot) that
records the information found on webpages accessed when
the 'Whats related feature' is being used in Internet
Explorer.
When the 'Whats related feature' in IE is not being used,
no information is sent to Alexa.
If you remove "Alexa", it will be reinstalled if you
repair or reinstall IE.
I don't know what "spyware program" you use but Ad-aware
will safely remove Alexa if you so choose. As stated
above, no information is transmitted unless you use the
mentioned link in IE. I can't really say because I don't
know if you've tried to remove it (successfully or not?)
with another program but Alexa isn't something that would
cause those error messages. However, other "unwanted
objects" on your computer can cause explorer.exe messages
although,naturally, I can't say for sure if that's what's
causing yours. I would suggest that if you haven't
already done so, you download Adaware (free version) from
http://majorgeeks.com/download.php?det=506
It detects and safely removes dataminers, tracking
cookies, trackware, dialers, BHO's and other objects from
your computer. This link will help you configure AAW for
your first scan:
http://www.lavasoftsupport.com/index.php?
showtopic=11613
If you have any questions, their forums are here:
http://www.lavasoftsupport.com/
It's VERY IMPORTANT that you are use the correct build
(6.181) and update your ref files after installing and
before each scan because they are updated frequently.
Click on the globe or "Check For Updates Now".
.
I updated my AdAware and Spybot software and got rid of a
lot more. Seems to have cured the Internet problem, but
I'm still getting the error message when I boot up and a
dialup connection box. Here is the HJT log. Any experts
out there who can tell me what to delete? Thanks much.
Logfile of HijackThis v1.97.3
Scan saved at 02:25:25, on 28/10/2003
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\NORTON~1\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\ZipToA.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\pctspk.exe
C:\WINNT\System32\RUNDLL32.EXE
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Stomp\DLA\dlatray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\PROGRA~1\Wanadoo\taskbaricon.exe
C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\DOCUME~1\User\LOCALS~1\Temp\g181511.exe
C:\Program Files\Iomega\Tools_NT\IMGICON.EXE
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\User\LOCALS~1\Temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page =
http://www.usatoday.com/
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window
Title = Wanadoo, Internet avec France Télécom
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,
(Default) = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06 - (no file)
O2 - BHO: (no name) - {068 - (no file)
O2 - BHO: (no name) - {0684 - (no file)
O2 - BHO: (no name) - {06849 - (no file)
O2 - BHO: (no name) - {06849E - (no file)
O2 - BHO: (no name) - {06849E9 - (no file)
O2 - BHO: (no name) - {06849E9F - (no file)
O2 - BHO: (no name) - {06849E9F- - (no file)
O2 - BHO: (no name) - {06849E9F-C - (no file)
O2 - BHO: (no name) - {06849E9F-C8 - (no file)
O2 - BHO: (no name) - {06849E9F-C8D - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7 - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7- - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4 - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D5 - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59- - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0
\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A - (no file)
O2 - BHO: (no name) - {AA - (no file)
O2 - BHO: (no name) - {AA5 - (no file)
O2 - BHO: (no name) - {AA58 - (no file)
O2 - BHO: (no name) - {AA58E - (no file)
O2 - BHO: (no name) - {AA58ED - (no file)
O2 - BHO: (no name) - {AA58ED5 - (no file)
O2 - BHO: (no name) - {AA58ED58 - (no file)
O2 - BHO: (no name) - {AA58ED58- - (no file)
O2 - BHO: (no name) - {AA58ED58-0 - (no file)
O2 - BHO: (no name) - {AA58ED58-01 - (no file)
O2 - BHO: (no name) - {AA58ED58-01D - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD- - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4 - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d9 - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91- - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8 - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-83 - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-833 - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333 - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333- - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C - (no
file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF - (no
file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF1 - (no
file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10 - (no
file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF105 - (no
file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF1057 -
(no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577 -
(no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF105774 -
(no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF1057747 -
(no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473 -
(no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-
CF10577473F - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-
CF10577473F7} - c:\winnt\googletoolbar_en_2.0.95-big.dll
O2 - BHO: (no name) - {B - (no file)
O2 - BHO: (no name) - {BD - (no file)
O2 - BHO: (no name) - {BDF - (no file)
O2 - BHO: (no name) - {BDF3 - (no file)
O2 - BHO: (no name) - {BDF3E - (no file)
O2 - BHO: (no name) - {BDF3E4 - (no file)
O2 - BHO: (no name) - {BDF3E43 - (no file)
O2 - BHO: (no name) - {BDF3E430 - (no file)
O2 - BHO: (no name) - {BDF3E430- - (no file)
O2 - BHO: (no name) - {BDF3E430-B - (no file)
O2 - BHO: (no name) - {BDF3E430-B1 - (no file)
O2 - BHO: (no name) - {BDF3E430-B10 - (no file)
O2 - BHO: (no name) - {BDF3E430-B101 - (no file)
O2 - BHO: (no name) - {BDF3E430-B101- - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-4 - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42 - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42A - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD- - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A5 - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A54 - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544 - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544- - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F - (no
file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FA - (no
file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FAD - (no
file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC - (no
file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6 - (no
file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B -
(no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B0 -
(no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B08 -
(no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084 -
(no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B0848 -
(no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-
FADC6B08487 - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-
FADC6B084872} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-
11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-
009027A5CD4F} - c:\winnt\googletoolbar_en_2.0.95-big.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
7859DF00B1D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager]
mobsync.exe /logon
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Apoint] C:\Program
Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [CPortPatch]
C:\WINNT\DockQuickInstall\cppch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32
\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Stomp DLA] "C:\Program
Files\Stomp\DLA\dlatray.exe" /t
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1
\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\Program
Files\Panicware\Pop-Up Stopper\dpps2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1
\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common
Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [cpr] C:\WINNT\cpr
O4 - HKLM\..\Run: [PGStub.exe] C:\DOCUME~1\User\LOCALS~1
\Temp\g181511.exe
O4 - HKLM\..\Run: [IEDriver] C:\WINNT\System32
\IEDriver\IExplore.exe /U
O4 - HKLM\..\RunServices: [TASK MANAGER] taskmgr.exe
O4 - HKCU\..\Run: [TClockEx] C:\Program
Files\TClockEx\TCLOCKEX.EXE
O4 - Global Startup: Iomega Icons.lnk = C:\Program
Files\Iomega\Tools_NT\IMGICON.EXE
O4 - Global Startup: Iomega Startup Options.lnk =
C:\Program Files\Iomega\Tools_NT\STARTNT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Refresh.lnk = C:\Program
Files\Iomega\Tools_NT\REFRESH.EXE
O8 - Extra context menu item: &Google Search -
res://c:\winnt\GoogleToolbar_en_2.0.95-
big.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links -
res://c:\winnt\GoogleToolbar_en_2.0.95-
big.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://c:\winnt\GoogleToolbar_en_2.0.95-big.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages -
res://c:\winnt\GoogleToolbar_en_2.0.95-
big.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page -
res://c:\winnt\GoogleToolbar_en_2.0.95-big.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: Wanadoo (HKCU)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
(QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvS
niff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info
..apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}
(HouseCall Control) -
http://a840.g.akamai.net/7/840/537/bcd48c18cb7498/housecall
..antivirus.com/housecall/xscan53.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} -
http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
(ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl
..CAB?37837.3584837963
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE}
(Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin
/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swf
lash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
(McFreeScan Class) -
http://download.mcafee.com/molbin/iss-
loc/vso/en-us/tools/mcfscan/1,5,0,4299/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{35A3EA58-B6FF-
42DE-A002-03992ED074A0}: NameServer = 193.252.19.3
193.252.19.4