i need some help..not real important but im having trouble finding information.

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
Ok ill start with a little information about my pc. Dell WinXP Home Sp2 1.7ghz p4 512mb, firefox browser, f-secure(charter high speed security suite)....i have a few things so ill list em...
1)why are there so many processes for f-secure running(should i put a hijack this log on here? where do i get hijack this?)
2)can backweb harm my computer(from what ive read from googling yes and no, whats the truth?)
3)sort of has to do with 1. there are some process which im not sure about, i have went to a few sites with process lists and they do not show up and when i google em i cant find anyreal information
ok, thats about it for now, nothing serious, no real problems, just need some info and advice,
links to valuable information highly appreciated.

about hijackthis, since im not really having problems should i just list the processes im not sure about or should i do a ht log just in case? im sure these should probably be seperate threads but in my mind at least they are all similar topics. thanks in advance for any help.
 

Byteman

Gone but Never Forgotten
Joined
Jan 24, 2002
Messages
17,742
Hi, You can post a hijackthis log here in this thread:

You must create a new, separate folder to hold hijackthis.exe...someplace like Program Files, or My Documents folder would be good, or right on the C: drive.

Rename the new folder something you will recognize, such as HJT.

www.radiosplace.com

Download the file hijackthis.exe to the folder you made, not the temp location, the desktop, etc.

Run the program and use the "Scan and make a log" option. Save the log as hijackthis.txt, which opens with Notepad, copy and past the entire log into a reply here and someone will have a look at it.
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
Logfile of HijackThis v1.99.0
Scan saved at 4:30:19 AM, on 2.13.05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = bbsm:80
F2 - REG:system.ini: UserInit=C:\WINDOWS\regedit /s C:\pav.reg,C:\WINDOWS\system32\pavdr.exe,C:\WINDOWS\system32\userinit.exe,
O2 - BHO: (no name) - {039C79B0-E174-928C-7D60-9CDC4F3FE7C1} - C:\WINDOWS\system32\qaehca.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (disabled by BHODemon)
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NADaemon] C:\WINDOWS\NADAEMON.EXE

while browsing Http"//terraserver.microsoft.com/ my web browser froze and things started to lock up and i got this alert "the document contains no dat" after this happend process fssm32.exe, was using a large amount of the cpu during an adaware scan, sometimes more than adaware, unloaded f-secure(charter high speed internet suite) which i have since removed because i felt it was a huge resource hog with something like 9 processes running at all times, but after unloading fssm32.exe remained active and i thought this might be of interest the IO read bytes for this process were 3.7 billion about 100 times more than anyother process, i dont know if this matters just want to know more, im actually runnin without AV willing to listen to suggestions but ive tried several and have not been satisfied by any, have not tried mcaffee but i have not heard a lot of good things about it, please dont mention...norton, panda, avg, i think that is all that i have tried was happy with none still tryin to get rid of part of norton some file that didnt complety install maybe hjt log will be of help in that matter
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
now things have changed since i first posted ive done some searching and have ajusted quite a few things and went from 37-22 processes but now i wonder if i NEED one thats not there, must not be too serious but sometimes when tryin to open a file or program will get no response, like i just didnt click
 
Joined
Mar 17, 2004
Messages
2,735
http://forums.techguy.org/t110854.html

Go here Download AVG 7 and install it until you decide what antivirus program will do for you . Having any updated antivirus program running is better than NO antivirus program . This is a good one and is free

Also download Spybot Search and Destroy and ad-Aware Se
Update do a scan and get rid of all they find Do this weekly

Do a scan with Housecall and Panda

Post another Hijack This log here please Post the complete log . It looks like much is missing from your last post.
 

Byteman

Gone but Never Forgotten
Joined
Jan 24, 2002
Messages
17,742
Hi, As well- it looks like your entire Hijack log did not copy in your reply- could you try it again with a new log? See if this works better:

With your saved HJT log open, at the top of it's window select EDIT>Select All and then EDIT>Copy and then go to your already open blank reply for the thread and click once in the reply space...then, at top of your browser window, hit EDIT>Paste which should put the log into your reply, then submit it.
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
i have some protection tho because im using zonealarm firewall, bot no antivirus. i have had adaware and spybot and there are no problems except for the dso exploit in IE which wont go away. ill post anohter hjt. and ive tried panda and avg didnt like either.
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
i dunno what happend last time just was payin enough attention i guess, hope this helps, i dunno, but any suggestions will be taking into consideration

Logfile of HijackThis v1.99.0
Scan saved at 2:06:40 AM, on 2.14.05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = bbsm:80
F2 - REG:system.ini: UserInit=C:\WINDOWS\regedit /s C:\pav.reg,C:\WINDOWS\system32\pavdr.exe,C:\WINDOWS\system32\userinit.exe,
O2 - BHO: (no name) - {039C79B0-E174-928C-7D60-9CDC4F3FE7C1} - C:\WINDOWS\system32\qaehca.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (disabled by BHODemon)
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NADaemon] C:\WINDOWS\NADAEMON.EXE
O4 - HKLM\..\Run: [3hqrIyWX.exe] c:\documents and settings\me\local settings\temp\3hqrIyWX.exe
O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\b.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Irhrtilm] C:\WINDOWS\system32\r?gsvr32.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: PowerReg SchedulerV2.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://fileforum.betanews.com
O15 - Trusted Zone: www.betanews.com
O15 - Trusted Zone: http://www.gamefly.com
O15 - Trusted Zone: http://azureus.sourceforge.net
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potb_x.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {A3D6BDDA-B170-11D4-BB16-0001023ACEE3} (NAScheduler Class) - http://www.arushgames.com/gamecapsule/scheduler.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_207/webolr/OCX/FlashAX.cab
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
i did not really even look at the hjt log before i rescanned it but i wanted to learn about it and while looking through it i saw something i thought i had removed completly---O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\b.exe----i believe this is from a virus that i have removed but when u take a look at my COMPLETE LOG you will prolly know what is up with it and anything else thanks
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
have you heard anything about V-Com System Suite 5 (i guess it uses pc-illin and housecall engine and sygate firewall engine, all which ive heard good things about and aparently it uses only one process)
 

Byteman

Gone but Never Forgotten
Joined
Jan 24, 2002
Messages
17,742
Hi, I have one small request> it looks like you renamed hijackthis.exe to hjt.exe> but you are running it directly from Program Files...not good, as the backups will be scattered or even worse, lost> and you might need them.

What you need to do is CREATE a new folder Inside Program Files> just use Windows Explorer, navigate to Program Files on the left side, while it is highlighted, go to File at the top of window, and select New>Folder, then, rename the New Folder TO HJT, and download a new copy of hijackthis.exe TO that folder. ((When the Save In box comes up, tell it to put the file in Program Files\HJT folder, and run hijackthis.exe from that folder to make a new log, please, after we do some things:

When you get the new copy in a folder, run it and use the Scan button> Important>>>you MUST not have any browser windows open, only Hijackthis> one exception would be a Notepad file with the steps here so you can have it as a guide> copy and paste my directions to a Notepad and save it on the desktop.

You will be booting to Safe Mode as a part of the fix> it will say when you are to do that later. To get to Safe Mode, when you restart, simply tap the F8 key quickly several times, when you get the menu, select Safe Mode using arrow key, and then hit Enter key once...give it plenty of time to get to the desktop.

Run Hijackthis first in Normal mode....put checks by each of the items in my list below, then click "Fix Checked":

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
O2 - BHO: (no name) - {039C79B0-E174-928C-7D60-9CDC4F3FE7C1} - C:\WINDOWS\system32\qaehca.dll (file missing)
O4 - HKLM\..\Run: [3hqrIyWX.exe] c:\documents and settings\me\local settings\temp\3hqrIyWX.exe
O4 - HKCU\..\Run: [Irhrtilm] C:\WINDOWS\system32\r?gsvr32.exe

O4 - Startup: PowerReg SchedulerV2.exe

And, if you have uninstalled Messenger, you can fix those, if you are going to put it back on, leave the entries for it.

Weatherbug---if you have uninstalled it and have no further use, fix the entry for that, too.

((You should uninstall from Add/Remove Programs first, if you did, good, fix the entry in HJT)) I will leave those items to you- leave them if you are not sure what to do now.


You need to do the steps in the quote box:


flrman1 said:
Because XP will not always show you hidden files and folders by default, Go to Start > Search>Files and Folders>> and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"

Next click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Go to Start > Run and type %temp% in the Run box, and OK. The Temp folder will open. Click Edit > Select All then File > Delete to delete the entire contents of the Temp folder.
Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK.
Next, navigate in Windows Explorer, to the folders holding the files we need to delete> the files are the ones at end of lines: You might not find them all, that is OK but you must look carefully for them>

C:\WINDOWS\system32\qaehca.dll <<look for it or a copy of it

C:\WINDOWS\system32\r?gsvr32.exe

c:\documents and settings\me\local settings\temp\3hqrIyWX.exe <<these guys like to hang around even after you empty temp files, so look for it!!!

Empty the Recycle Bin and restart, back to normal mode>


Run AdAware SE and/or SpyBot, check for updates to each program, and reboot between scans with them.

You must have "Full" scan selected in AdAware:

First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.

From main window :Click Start then under Select a scan Mode tick Perform full system scan.

Next deselect Search for negligible risk entries.

Now to scan just click the Next button.

Post a new log when you are ready/done.
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
ive uninstaled weatherbug and windows messenger lets get those f*ckers outta there. do i do the steps in your quote before the first scan with hjt or after i have completed it? unsure so i want to make sure before i do nething and also put the hjt log for msmsng and weatherbug so i know what im lookin for im sure its obvious.but i just want to be sure. and about my temp files folder i have some things in there that i know i want to keep so i guess i should move them or is there some reason that that may harm my computer because they were infected somehow, i know what they are i created them, but they are "private" files we'll say, at least i wont mention what they are anyway, nothing serious but just not something i should/would put on a public forum, for my sake and the administrators too, hope that isnt too blunt or something that might affect my membership here, but i needed to you to know that i need some of the files i am supposed to delete in your instructions, but i would never have thought to do any of this on my own so i already appreciate the help even though i havent done anything yet, ive been trying to find a place where i could recieve help like this for a long time, im really starting to like this forum
 

Byteman

Gone but Never Forgotten
Joined
Jan 24, 2002
Messages
17,742
Hi, Move your files someplace--keeping something you need in the Temp directory is kind of taking a chance- if someone ever does disk cleanup for instance, they may disappear.

When you start the fix, you use Hijackthis, scan, and follow the steps I put in the last reply. It should be done all as one continuous procedure. You will have to have the directions either printed out or saved as I said to a Notepad text file to read from in Safe Mode.
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
just wanted to make a quick statement before i move on to the log...i wasnt sure what but i knew i had something that i needed in temp folder , thought it might be something but it was just some image files i remembered when i found em that was what all that nonsense was about.. sorry...
 

dmonixed

Thread Starter
Joined
Feb 11, 2005
Messages
73
Logfile of HijackThis v1.99.0
Scan saved at 12:48:53 AM, on 2.15.05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = bbsm:80
F2 - REG:system.ini: UserInit=C:\WINDOWS\regedit /s C:\pav.reg,C:\WINDOWS\system32\pavdr.exe,C:\WINDOWS\system32\userinit.exe,
O2 - BHO: (no name) - {039C79B0-E174-928C-7D60-9CDC4F3FE7C1} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (disabled by BHODemon)
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [NADaemon] C:\WINDOWS\NADAEMON.EXE
O4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\b.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://fileforum.betanews.com
O15 - Trusted Zone: www.betanews.com
O15 - Trusted Zone: http://www.gamefly.com
O15 - Trusted Zone: http://azureus.sourceforge.net
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potb_x.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {A3D6BDDA-B170-11D4-BB16-0001023ACEE3} (NAScheduler Class) - http://www.arushgames.com/gamecapsule/scheduler.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_207/webolr/OCX/FlashAX.cab
O23 - Service: TrueVector Internet Monitor - Zone Labs LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe



alright a little info on how it went for me, scanned with adaware no problem but i cant get updates for spybot, so i used definitions from 1-6-05 should be good enough but if not oh well cuz im gettin rid of spybot i dont like the program functionality ive got firefox and dont see spybot being of anymore use especially with no updates
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Top