1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

what to delete on adaware?

Discussion in 'Virus & Other Malware Removal' started by schnaibel, Sep 5, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. schnaibel

    schnaibel Thread Starter

    Joined:
    Sep 5, 2004
    Messages:
    6
    I used adaware to scan my computer, and i´d like to know if i can delete everything that was found... It found 89 critical objects!

    I hope someone can help....
    Thanks!!! ;)
     
  2. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Do so then Download 'Hijack This to its own folder http://www.dotcomsecurity.org/downloads/HijackThis.exe
    Doubleclick HijackThis.exe, and hit "Scan".

    When the scan is finished, the "Scan" button will change into a "Save Log" button.
    Press that, save the log, load it in Notepad, and copy its contents here. [​IMG]

    Most of what it lists
    will be harmless or even essential, don't fix anything yet.
    __________________
     
  3. schnaibel

    schnaibel Thread Starter

    Joined:
    Sep 5, 2004
    Messages:
    6
    Here´s my log.... It is in portuguese... I hope you can help me anyway Mobo, and thanks already!!!! ;)


    Logfile of HijackThis v1.98.2
    Scan saved at 10:06:45, on 6/9/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\ARQUIV~1\Grisoft\AVG6\avgserv.exe
    C:\WINNT\System32\svchost.exe
    C:\ARQUIV~1\Navnt\navapsvc.exe
    C:\Arquivos de programas\Norton Internet Security\NISUM.EXE
    C:\ARQUIV~1\Navnt\npssvc.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Arquivos de programas\Norton Internet Security\SymProxySvc.exe
    C:\WINNT\system32\Tablet.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Arquivos de programas\Norton Internet Security\NISSERV.EXE
    C:\ARQUIV~1\Navnt\alertsvc.exe
    C:\WINNT\Explorer.EXE
    C:\TBRIDGE\Flatbed.exe
    C:\Arquivos de programas\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    C:\WINNT\System32\svchost.exe
    C:\Arquivos de programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Arquivos de programas\Anjo da Guarda\Anjo.exe
    C:\Arquivos de programas\Norton Internet Security\IAMAPP.EXE
    C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe
    C:\ARQUIV~1\Grisoft\AVG6\avgcc32.exe
    C:\Arquivos de programas\Internet Explorer\iexplore.exe
    C:\Arquivos de programas\Microsoft Office\Office\1046\OLFSNT40.EXE
    C:\Arquivos de programas\Navnt\navapw32.exe
    C:\Arquivos de programas\MSN Messenger\msnmsgr.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Arquivos de programas\WinZip\WZQKPICK.EXE
    C:\WINNT\system32\Wtablet\TabUserW.exe
    C:\Arquivos de programas\Adobe\Photoshop 7.0\Photoshop.exe
    C:\WINNT\system32\wuauclt.exe
    C:\Arquivos de programas\Internet Explorer\iexplore.exe
    C:\Backup\Downloads\hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = www.virtua.com.br;localhost
    F3 - REG:win.ini: load=C:\TBridge\Flatbed.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {497A3003-D4BD-6793-382E-85D8905E94DE} - C:\ARQUIV~1\BOLDOK~1\Bags heck.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINNT\Downloaded Program Files\gbieh.dll
    O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    O4 - HKLM\..\Run: [DeviceDiscovery] C:\Arquivos de programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - HKLM\..\Run: [NPS Event Checker] C:\ARQUIV~1\Navnt\npscheck.exe
    O4 - HKLM\..\Run: [NAV DefAlert] C:\ARQUIV~1\Navnt\defalert.exe
    O4 - HKLM\..\Run: [ANJO] C:\Arquivos de programas\Anjo da Guarda\Anjo.exe
    O4 - HKLM\..\Run: [iamapp] C:\Arquivos de programas\Norton Internet Security\IAMAPP.EXE
    O4 - HKLM\..\Run: [REGSHAVE] C:\Arquivos de programas\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [amen support] C:\ARQUIV~1\INSIDE~1\Vgadrive.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\ARQUIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [aim global pop base] C:\Documents and Settings\All Users\Dados de aplicativos\magsfirstaimglobal\Htm Plus.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Arquivos de programas\Microsoft Office\Office\1046\OLFSNT40.EXE
    O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Arquivos de programas\Navnt\navapw32.exe
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: TabUserW.exe.lnk = C:\WINNT\system32\Wtablet\TabUserW.exe
    O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
    O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab


    (y)
     
  4. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Rescan again now then insert a check next to each of the following then close all browser windows and click "fix checked"

    Also before doing so please leave all the backups in place that are created by hijacks repair until we verify all is well.


    O2 - BHO: (no name) - {497A3003-D4BD-6793-382E-85D8905E94DE} - C:\ARQUIV~1\BOLDOK~1\Bags heck.exe

    O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINNT\Downloaded Program Files\gbieh.dll

    O4 - HKLM\..\Run: [ANJO] C:\Arquivos de programas\Anjo da Guarda\Anjo.exe

    O4 - HKLM\..\Run: [amen support] C:\ARQUIV~1\INSIDE~1\Vgadrive.exe

    .

    Also does this system have a scanner installed ? If so then thats what this is for but if not then I will have to question it (F3 - REG:win.ini: load=C:\TBridge\Flatbed.exe)

    Then reboot, rescan and post an updated logfile please.
     
  5. schnaibel

    schnaibel Thread Starter

    Joined:
    Sep 5, 2004
    Messages:
    6
    This is the new scan:

    Logfile of HijackThis v1.98.2
    Scan saved at 13:05:57, on 6/9/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\ARQUIV~1\Grisoft\AVG6\avgserv.exe
    C:\WINNT\System32\svchost.exe
    C:\ARQUIV~1\Navnt\navapsvc.exe
    C:\Arquivos de programas\Norton Internet Security\NISUM.EXE
    C:\ARQUIV~1\Navnt\npssvc.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Arquivos de programas\Norton Internet Security\SymProxySvc.exe
    C:\WINNT\system32\Tablet.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Arquivos de programas\Norton Internet Security\NISSERV.EXE
    C:\WINNT\Explorer.EXE
    C:\TBRIDGE\Flatbed.exe
    C:\Arquivos de programas\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    C:\WINNT\system32\mobsync.exe
    C:\Arquivos de programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Arquivos de programas\Anjo da Guarda\Anjo.exe
    C:\Arquivos de programas\Norton Internet Security\IAMAPP.EXE
    C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe
    C:\ARQUIV~1\Grisoft\AVG6\avgcc32.exe
    C:\ARQUIV~1\Navnt\alertsvc.exe
    C:\Arquivos de programas\Internet Explorer\iexplore.exe
    C:\Arquivos de programas\MSN Messenger\msnmsgr.exe
    C:\Arquivos de programas\Microsoft Office\Office\1046\OLFSNT40.EXE
    C:\Arquivos de programas\Navnt\navapw32.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Arquivos de programas\WinZip\WZQKPICK.EXE
    C:\WINNT\system32\Wtablet\TabUserW.exe
    C:\Arquivos de programas\Internet Explorer\iexplore.exe
    C:\WINNT\system32\wuauclt.exe
    C:\Backup\Downloads\hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = www.virtua.com.br;localhost
    F3 - REG:win.ini: load=C:\TBridge\Flatbed.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINNT\Downloaded Program Files\gbieh.dll
    O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    O4 - HKLM\..\Run: [DeviceDiscovery] C:\Arquivos de programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - HKLM\..\Run: [NPS Event Checker] C:\ARQUIV~1\Navnt\npscheck.exe
    O4 - HKLM\..\Run: [NAV DefAlert] C:\ARQUIV~1\Navnt\defalert.exe
    O4 - HKLM\..\Run: [ANJO] C:\Arquivos de programas\Anjo da Guarda\Anjo.exe
    O4 - HKLM\..\Run: [iamapp] C:\Arquivos de programas\Norton Internet Security\IAMAPP.EXE
    O4 - HKLM\..\Run: [REGSHAVE] C:\Arquivos de programas\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [AVG_CC] C:\ARQUIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [aim global pop base] C:\Documents and Settings\All Users\Dados de aplicativos\magsfirstaimglobal\Htm Plus.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Arquivos de programas\Microsoft Office\Office\1046\OLFSNT40.EXE
    O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Arquivos de programas\Navnt\navapw32.exe
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: TabUserW.exe.lnk = C:\WINNT\system32\Wtablet\TabUserW.exe
    O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
    O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab

    Now that you´ve mentioned, i have a scanner installed, and when i installed it, the microsoft office was gone....
    I think the problem is still here......

    Please help!
     
  6. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    There are no obvious things in the log that would account for that type of scenario. what are the current troubles though ?
     
  7. schnaibel

    schnaibel Thread Starter

    Joined:
    Sep 5, 2004
    Messages:
    6
    The problem is that when I open a new internet explorer window, there comes this blue bar in the bottom of the page.... The bar is from "search the web"... I was able to close it before... But now it just stays there and won´t go away....

    please help!! :)
     
  8. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    Ok so please reboot then when the toolbar is present I want you to rescan with hijack the post that log .
     
  9. schnaibel

    schnaibel Thread Starter

    Joined:
    Sep 5, 2004
    Messages:
    6
    new log

    Logfile of HijackThis v1.98.2
    Scan saved at 12:51:59, on 11/9/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\ARQUIV~1\Grisoft\AVG6\avgserv.exe
    C:\WINNT\System32\svchost.exe
    C:\ARQUIV~1\Navnt\navapsvc.exe
    C:\Arquivos de programas\Norton Internet Security\NISUM.EXE
    C:\ARQUIV~1\Navnt\npssvc.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Arquivos de programas\Norton Internet Security\SymProxySvc.exe
    C:\WINNT\system32\Tablet.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\Arquivos de programas\Norton Internet Security\NISSERV.EXE
    C:\ARQUIV~1\Navnt\alertsvc.exe
    C:\WINNT\Explorer.EXE
    C:\TBRIDGE\Flatbed.exe
    C:\Arquivos de programas\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\WINNT\system32\mobsync.exe
    C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    C:\Arquivos de programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Arquivos de programas\Anjo da Guarda\Anjo.exe
    C:\Arquivos de programas\Norton Internet Security\IAMAPP.EXE
    C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe
    C:\ARQUIV~1\Grisoft\AVG6\avgcc32.exe
    C:\Arquivos de programas\Internet Explorer\iexplore.exe
    C:\Arquivos de programas\Microsoft Office\Office\1046\OLFSNT40.EXE
    C:\Arquivos de programas\MSN Messenger\msnmsgr.exe
    C:\Arquivos de programas\Navnt\navapw32.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\FinePixViewer\QuickDCF.exe
    C:\Arquivos de programas\WinZip\WZQKPICK.EXE
    C:\WINNT\system32\Wtablet\TabUserW.exe
    C:\Backup\Downloads\hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = www.virtua.com.br;localhost
    F3 - REG:win.ini: load=C:\TBridge\Flatbed.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINNT\Downloaded Program Files\gbieh.dll
    O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    O4 - HKLM\..\Run: [DeviceDiscovery] C:\Arquivos de programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - HKLM\..\Run: [NPS Event Checker] C:\ARQUIV~1\Navnt\npscheck.exe
    O4 - HKLM\..\Run: [NAV DefAlert] C:\ARQUIV~1\Navnt\defalert.exe
    O4 - HKLM\..\Run: [ANJO] C:\Arquivos de programas\Anjo da Guarda\Anjo.exe
    O4 - HKLM\..\Run: [iamapp] C:\Arquivos de programas\Norton Internet Security\IAMAPP.EXE
    O4 - HKLM\..\Run: [REGSHAVE] C:\Arquivos de programas\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [AVG_CC] C:\ARQUIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [aim global pop base] C:\Documents and Settings\All Users\Dados de aplicativos\magsfirstaimglobal\Htm Plus.exe
    O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Arquivos de programas\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Arquivos de programas\Microsoft Office\Office\1046\OLFSNT40.EXE
    O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Arquivos de programas\Navnt\navapw32.exe
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: TabUserW.exe.lnk = C:\WINNT\system32\Wtablet\TabUserW.exe
    O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
    O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://www.makeoversolutions.com/save/makeover.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab30149.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab30149.cab
    O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab
     
  10. mobo

    mobo

    Joined:
    Feb 23, 2003
    Messages:
    16,274
    You have two antivirus programs running there which isnt a good idea to be doing.Also what it the name of the said toolbar ?
     
  11. schnaibel

    schnaibel Thread Starter

    Joined:
    Sep 5, 2004
    Messages:
    6
    Hey :)

    Well, i can delete one of the antivirus program, and the toolbar is from search the web...

    I also found another problem... When a page cannot be found/displayed, the "search the web" thing appears at the window....

    thanks for the tips :)
     
  12. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/270557

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice