1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Help browser problems and virus.

Discussion in 'Virus & Other Malware Removal' started by Neo151, Sep 2, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    Please help i have just installed win xp pro and had a lot of problems.
    But all were fixed and was all runing ok i installed my modem a nd all was fine. I then spoke to a friend who has xp and he told me to download sp2 so i did nd it waz fine then i thought aw i need some virus cheekers so i installed all the ones i used before on my old computer (Adaware Spy Bot AVG and HJT) I ran all of these and adaware picked up quite alot i then ran spybot that picked up alot then avg it icked up 41. They where all removed sucesfully. I then booted up internet explorer and all was fine untill i typed in a new url and it just goes onto the web page can not be displayed. I thought nothing of it and tryed again i eventurly got it to work then i booted up msn and now that stoped IE from working so now its really hard to get Ie to work as i have to boot it up then push refresh 5 times.
    Also i noticed the url i tytped at the bottom where it loads infront of it was www.ads234.com what is that also i copied a HJT. Please help thanks..


    Logfile of HijackThis v1.97.7
    Scan saved at 17:51:26, on 02/09/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\Program Files\Common Files\WinTools\WToolsS.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\msxml32.exe
    C:\windows\temp\dUlj.exe
    C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-gb\msnappau.exe
    C:\Program Files\Common Files\WinTools\WToolsA.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\WinTools\WSup.exe
    C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
    C:\WINDOWS\system32\videosd32.exe
    C:\WINDOWS\system32\scvhosting.exe
    C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
    C:\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
    O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
    O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-gb\msntb.dll
    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Ben\Local Settings\Temp\4.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-gb\msntb.dll
    O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
    O4 - HKLM\..\Run: [SYSTEM] lsas.exe
    O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe
    O4 - HKLM\..\Run: [XML Service] msxml32.exe
    O4 - HKLM\..\Run: [dUlj] C:\windows\temp\dUlj.exe
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-gb\msnappau.exe"
    O4 - HKLM\..\Run: [I1CLBD] C:\windows\temp\I1CLBD.exe
    O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
    O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\Run: [starter] scvhosting.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\RunServices: [SYSTEM] lsas.exe
    O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe
    O4 - HKLM\..\RunServices: [XML Service] msxml32.exe
    O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\RunServices: [starter] scvhosting.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WindowsRegKeys update] winsysi.exe
    O4 - HKCU\..\Run: [SYSTEM] lsas.exe
    O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKCU\..\Run: [starter] scvhosting.exe
    O4 - HKLM\..\RunOnce: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\RunOnce: [starter] scvhosting.exe
    O4 - HKCU\..\RunOnce: [starter] scvhosting.exe
    O4 - HKCU\..\RunOnce: [Win32 Configuration] videosd32.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1094066768751
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0E0E5B45-AEF5-4CE5-9682-BB9A225009F8}: NameServer = 212.74.114.129 212.74.114.193
     
  2. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,253
    First Name:
    Derek
    first copy these files and zip them and send to [email protected] with a short note referring to this thread
    C:\WINDOWS\system32\msxml32.exe I am not sure if it's good or bad and need to check before doing anything with it

    then uninstall wintools from add/remove programs in control panel

    Run hijackthis, tick these entries listed below and ONLY these entries, double check to make sure, then make sure all browser & email windows are closed and press fix checked

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll

    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Ben\Local Settings\Temp\4.dll

    O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
    O4 - HKLM\..\Run: [SYSTEM] lsas.exe
    O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe
    O4 - HKLM\..\Run: [dUlj] C:\windows\temp\dUlj.exe
    O4 - HKLM\..\Run: [I1CLBD] C:\windows\temp\I1CLBD.exe
    O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
    O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\Run: [starter] scvhosting.exe
    O4 - HKLM\..\RunServices: [SYSTEM] lsas.exe
    O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe
    O4 - HKLM\..\RunServices: [XML Service] msxml32.exe
    O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\RunServices: [starter] scvhosting.exe
    O4 - HKCU\..\Run: [WindowsRegKeys update] winsysi.exe
    O4 - HKCU\..\Run: [SYSTEM] lsas.exe
    O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
    O4 - HKCU\..\Run: [starter] scvhosting.exe
    O4 - HKLM\..\RunOnce: [Win32 Configuration] videosd32.exe
    O4 - HKLM\..\RunOnce: [starter] scvhosting.exe
    O4 - HKCU\..\RunOnce: [starter] scvhosting.exe
    O4 - HKCU\..\RunOnce: [Win32 Configuration] videosd32.exe


    Reboot into safe mode by following instructions here: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
    then as some of the files or folders you need to delete may be hidden do this:
    Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
    Click "Apply" then "OK"

    Delete these files be very careful and watch the spelling and only these files not any similar named ones


    C:\WINDOWS\system32\videosd32.exe
    C:\WINDOWS\system32\scvhosting.exe
    C:\WINDOWS\system32\winsysi.exe
    C:\WINDOWS\system32\lsas.exe

    and Delete these folders

    C:\Program Files\Common Files\WinTools
    C:\PROGRAM FILES\Toolbar
    then go to C:\Documents and Settings\USER NAME\Local Settings\Temp and select everything in that folder and delete it

    as XP will not let you delete files less than 24 hours old as it thinks it might need them please also do this
    while in the temp folder, select view and select details.
    then right click a blank part and select arrange icons by, and select show in groups and modified, that will give a list of all files in date order with today at the top of the page.
    select all the files/folders except the today ones and delete them all.

    and select EVERYTHING in C:\windows\temp except temporary internet files, cookies and history folders and delete all that as well

    1) Open Control Panel
    2) Click on Internet Options
    3) On the General Tab, in the middle of the screen, click on Delete Files
    4) You may also want to check the box "Delete all offline content"
    5) Click on OK and wait for the hourglass icon to stop after it deletes the temporary internet files
    6) You can now click on Delete Cookies and click OK to delete cookies that websites have placed on your hard drive

    then
    Reboot normally &

    Download and unzip or install these programs/applications if you haven't already got them. If you have them, then make sure they are updated and configured as described

    Spybot - Search & Destroy from http://security.kolla.de
    AdAware SE from http://www.lavasoft.de/support/download


    Run Sybot S&D

    After installing, first press Online, press search for updates, then tick the updates it finds, then press download updates. Beside the download button is a little down pointed arrow, select one of the servers listed. If it doesn't work or you get an error message then try a different server

    Next, close all Internet Explorer and OE windows, press 'Check for Problems', and have SpyBot remove all it finds that is marked in RED.

    then reboot &

    Run ADAWARE

    Before you scan with AdAware, check for updates of the reference file by using the "webupdate".
    the current ref file should read at least SE1R5 22.08.2004 or a higher number/later date
    Then ........
    click the "Scan" button. and select full scan

    When scan is finished, mark everything for removal and get rid of it. (Right-click the window and choose"select all" from the drop down menu) then press next and then say yes to the prompt, do you want to remove all these entries. You can safely ignore any MRU entries though and not delete them

    reboot again

    then post a new hijackthis log to check what is left
     
  3. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    Hi cheers for the help im about to run all that but the first bit you said something about emailing files which ones and i iwll not be able to do this as i only have a hotmail account and cant get online to send themfrom that computer.
    Thanks very much
     
  4. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,253
    First Name:
    Derek
    save the file until you get it working then send it to me to check out

    it might be a part of your problem as well or it might be a good file and part of some graphics program, I'm just not sure by it's name & location
     
  5. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    That file you told me to save i searched for it but only found a file called MSXML32.EXE-0C02918F.pf and was in fold C:\WINDOWS\Prefetch and was 31 KB There was defiently wasnt a file that you said to copy in that location.
    Cheers i will save the file to a floppy nd send to you at a later stage. Thanks
     
  6. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    These files where not there to delete in HJT

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dllC:\WINDOWS\system32\videosd32.exe

    Also when i was looking to delete these couldnt be found.
    C:\WINDOWS\system32\winsysi.exe
    C:\WINDOWS\system32\lsas.exe

    then go to C:\Documents and Settings\USER NAME\Local Settings\Temp and select everything in that folder and delete it/ I did delete it all...

    But then you said this:
    as XP will not let you delete files less than 24 hours old as it thinks it might need them please also do this
    while in the temp folder, select view and select details.
    then right click a blank part and select arrange icons by, and select show in groups and modified, that will give a list of all files in date order with today at the top of the page.
    select all the files/folders except the today ones and delete them all.
    I do not no what you mean what files???
    Cheers so far m8..
     
  7. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,253
    First Name:
    Derek
    post a new log please and we'll see what's left
     
  8. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    New log.Logfile of HijackThis v1.97.7
    Scan saved at 20:15:43, on 02/09/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\msxml32.exe
    C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-gb\msnappau.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
    C:\HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband/
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
    O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-gb\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-gb\msntb.dll
    O4 - HKLM\..\Run: [XML Service] msxml32.exe
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-gb\msnappau.exe"
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\RunServices: [XML Service] msxml32.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
    O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1094066768751
     
  9. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,253
    First Name:
    Derek
    Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
    Click "Apply" then "OK"

    then look for C:\WINDOWS\system32\msxml32.exe

    i am pretty sure it is up to no good but I need to see it first

    it definitely is there because it's in the running processes so if you can't find it then it's possibly one of the new baddies who mask themselves from view
     
  10. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    I found the file what would you like be to do with it?
    Thanks so far
     
  11. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    I seem to be still having the problems i thinks there are some more baddies Please help.. Thanks so far. P.S i find that Ie works for a bit then cuts out also when i acess msn it signs in then cuts out when i speak to some one then the Ie goes as well and i fell xml is doin all this to my computer. Another thing is i have noticed one of my friends has got the same viruses on his computer thread loacted at http://forums.techguy.org/showthread.php?p=1912661#post1912661
    Cheers
     
  12. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
  13. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    dvk01 do you think this is what is causing the problem i really need to no i opened another topic asking if any one had heard of it but no one has replied please help i really need ,my computer working. Thanks
     
  14. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,253
    First Name:
    Derek
    if you are sure that it's dodgy and I am 99% sure the do this

    Run hijackthis, tick these entries listed below and ONLY these entries, double check to make sure, then make sure all browser & email windows are closed and press fix checked

    O4 - HKLM\..\RunServices: [XML Service] msxml32.exe

    Reboot into safe mode by following instructions here: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
    then as some of the files or folders you need to delete may be hidden do this:
    Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
    Click "Apply" then "OK"

    Delete these files
    C:\WINDOWS\system32\msxml32.exe

    reboot and hopefully your probl;ems willbe cured
     
  15. Neo151

    Neo151 Thread Starter

    Joined:
    Mar 22, 2004
    Messages:
    117
    Cheers mate looks like it did the trick.. Ive done a hjt just to check.
    But ive noticed a problem as i have 4 user accounts the other 3 still have the viruses. So looks like il have to repeat all the steps again 3 times never mind lol. Cheers

    Logfile of HijackThis v1.98.2
    Scan saved at 21:26:09, on 03/09/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-gb\msnappau.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HJT\HijackThisnew.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband/
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.0002.1001\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-gb\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.2001.0001\en-gb\msntb.dll
    O4 - HKLM\..\Run: [XML Service] msxml32.exe
    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.0002.1001\en-gb\msnappau.exe"
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM [email protected] 800-840\dslmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1094066768751
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0E0E5B45-AEF5-4CE5-9682-BB9A225009F8}: NameServer = 212.74.114.129 212.74.114.193
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/269411

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice