Browser Hijacked - assistance required

Discussion in 'adware, spyware & hijack cleaning' started by timockj, Jun 21, 2004.

Thread Status:
Not open for further replies.
  1. timockj

    timockj Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    My ie6 browser has been hijacked (res://kpiww.dll/index.html#96676). I would appreciate any help on getting it sorted.

    Below is the HijackThis log
    Thanks in advance

    Logfile of HijackThis v1.97.7
    Scan saved at 13:58:59, on 21/06/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    E:\WINNT\System32\smss.exe
    E:\WINNT\system32\winlogon.exe
    E:\WINNT\system32\services.exe
    E:\WINNT\system32\lsass.exe
    E:\WINNT\system32\svchost.exe
    E:\WINNT\system32\spoolsv.exe
    E:\Program Files\NavNT\defwatch.exe
    E:\WINNT\System32\svchost.exe
    E:\WINNT\system32\GEARSEC.EXE
    E:\Program Files\NMapWin\bin\nmapserv.exe
    E:\Program Files\NavNT\rtvscan.exe
    E:\WINNT\system32\regsvc.exe
    E:\WINNT\system32\MSTask.exe
    E:\WINNT\system32\stisvc.exe
    E:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
    E:\WINNT\System32\vmnetdhcp.exe
    E:\WINNT\System32\vmnat.exe
    E:\WINNT\System32\WBEM\WinMgmt.exe
    E:\WINNT\system32\svchost.exe
    E:\WINNT\system32\MsgSys.EXE
    E:\WINNT\System32\svchost.exe
    E:\WINNT\Explorer.EXE
    E:\Program Files\ahead\InCD\InCD.exe
    E:\Program Files\NavNT\vptray.exe
    E:\Program Files\iTunes\iTunesHelper.exe
    E:\Program Files\iPod\bin\iPodService.exe
    E:\Program Files\QuickTime\qttask.exe
    E:\WINNT\system32\internat.exe
    E:\Program Files\NETGEAR\MA101 USB Adapter Configuration Utility\WlanMonitor.exe
    E:\Program Files\WinZip\WZQKPICK.EXE
    E:\WINNT\system32\ipas.exe
    E:\WINNT\netjw32.exe
    E:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\Documents and Settings\tim\My Documents\Software Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {19566FBD-41F9-AF6D-EC17-1B05DDF77AC6} - E:\WINNT\system32\appdk32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [NeroCheck] E:\WINNT\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] E:\Program Files\ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [KAZAA] E:\Program Files\KaZaA Lite\kpp.exe "E:\Program Files\KaZaA Lite\kazaa.exe" /SYSTRAY
    O4 - HKLM\..\Run: [vptray] E:\Program Files\NavNT\vptray.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ipas.exe] E:\WINNT\system32\ipas.exe
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - Global Startup: MA101 Configuration Utility .lnk = E:\Program Files\NETGEAR\MA101 USB Adapter Configuration Utility\WlanMonitor.exe
    O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = E:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38016.4278125
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{286C2314-3AB8-4151-B27F-45D09E61ABB4}: NameServer = 158.152.1.58,158.152.1.43
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi timockj,


    I hope you haven't rebooted before you read this.

    Click Start > Run > Services.msc > OK
    In the services window find Network Security Service.
    Rightclick and stop it. Put the Startup type to disabled under Properties > General tab

    Then open TaskManager and stop these two processes:
    E:\WINNT\system32\ipas.exe
    E:\WINNT\netjw32.exe

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://E:\WINNT\kpiww.dll/sp.html#96676

    O2 - BHO: (no name) - {19566FBD-41F9-AF6D-EC17-1B05DDF77AC6} - E:\WINNT\system32\appdk32.dll

    O4 - HKLM\..\Run: [KAZAA] E:\Program Files\KaZaA Lite\kpp.exe "E:\Program Files\KaZaA Lite\kazaa.exe" /SYSTRAY

    O4 - HKLM\..\Run: [ipas.exe] E:\WINNT\system32\ipas.exe

    Then reboot into safe mode and delete:
    E:\WINNT\system32\ipas.exe
    E:\WINNT\netjw32.exe
    E:\WINNT\system32\appdk32.dat
    E:\WINNT\kpiww.dll

    Read some additional info here:
    https://www.wilderssecurity.com/showpost.php?p=198412&postcount=26

    Regards,

    Pieter
     
  3. timockj

    timockj Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    Thanks for the swift reply.

    I have rebooted since posting. I presume you need another log ? I include one below if you do

    Cheers t

    Logfile of HijackThis v1.97.7
    Scan saved at 16:10:58, on 21/06/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    E:\WINNT\System32\smss.exe
    E:\WINNT\system32\winlogon.exe
    E:\WINNT\system32\services.exe
    E:\WINNT\system32\lsass.exe
    E:\WINNT\system32\svchost.exe
    E:\WINNT\system32\spoolsv.exe
    E:\Program Files\NavNT\defwatch.exe
    E:\WINNT\System32\svchost.exe
    E:\WINNT\system32\GEARSEC.EXE
    E:\Program Files\NMapWin\bin\nmapserv.exe
    E:\Program Files\NavNT\rtvscan.exe
    E:\WINNT\system32\regsvc.exe
    E:\WINNT\system32\MSTask.exe
    E:\WINNT\system32\stisvc.exe
    E:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
    E:\WINNT\System32\vmnetdhcp.exe
    E:\WINNT\System32\vmnat.exe
    E:\WINNT\System32\WBEM\WinMgmt.exe
    E:\WINNT\system32\svchost.exe
    E:\WINNT\netjw32.exe
    E:\WINNT\system32\MsgSys.EXE
    E:\WINNT\Explorer.EXE
    E:\Program Files\ahead\InCD\InCD.exe
    E:\Program Files\NavNT\vptray.exe
    E:\Program Files\iTunes\iTunesHelper.exe
    E:\Program Files\iPod\bin\iPodService.exe
    E:\Program Files\QuickTime\qttask.exe
    E:\WINNT\system32\internat.exe
    E:\Program Files\NETGEAR\MA101 USB Adapter Configuration Utility\WlanMonitor.exe
    E:\Program Files\WinZip\WZQKPICK.EXE
    E:\Program Files\NavNT\vpc32.exe
    E:\WINNT\system32\mszy.exe
    E:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\Documents and Settings\tim\My Documents\Software Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {19566FBD-41F9-AF6D-EC17-1B05DDF77AC6} - E:\WINNT\system32\appdk32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [NeroCheck] E:\WINNT\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] E:\Program Files\ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [KAZAA] E:\Program Files\KaZaA Lite\kpp.exe "E:\Program Files\KaZaA Lite\kazaa.exe" /SYSTRAY
    O4 - HKLM\..\Run: [vptray] E:\Program Files\NavNT\vptray.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ipas.exe] E:\WINNT\system32\ipas.exe
    O4 - HKLM\..\Run: [mszy.exe] E:\WINNT\system32\mszy.exe
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - Global Startup: MA101 Configuration Utility .lnk = E:\Program Files\NETGEAR\MA101 USB Adapter Configuration Utility\WlanMonitor.exe
    O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = E:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38016.4278125
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{286C2314-3AB8-4151-B27F-45D09E61ABB4}: NameServer = 158.152.1.58,158.152.1.43
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi timockj,

    Indeed I did need a new one.

    Click Start > Run > Services.msc > OK
    In the services window find Network Security Service.
    Rightclick and stop it. Put the Startup type to disabled under Properties > General tab

    Then open TaskManager and stop these two processes:
    E:\WINNT\system32\mszy.exe
    E:\WINNT\netjw32.exe

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://E:\WINNT\kpiww.dll/sp.html#96676

    O2 - BHO: (no name) - {19566FBD-41F9-AF6D-EC17-1B05DDF77AC6} - E:\WINNT\system32\appdk32.dll

    O4 - HKLM\..\Run: [KAZAA] E:\Program Files\KaZaA Lite\kpp.exe "E:\Program Files\KaZaA Lite\kazaa.exe" /SYSTRAY

    O4 - HKLM\..\Run: [ipas.exe] E:\WINNT\system32\ipas.exe
    O4 - HKLM\..\Run: [mszy.exe] E:\WINNT\system32\mszy.exe

    Then reboot into safe mode and delete:
    E:\WINNT\system32\mszy.exe
    E:\WINNT\netjw32.exe
    E:\WINNT\system32\appdk32.dat
    E:\WINNT\kpiww.dll

    Read some additional info here:
    https://www.wilderssecurity.com/showpost.php?p=198412&postcount=26

    Regards,

    Pieter
     
  5. timockj

    timockj Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    Thanks again,

    Access is denied when I try to end the two processes:

    E:\WINNT\system32\mszy.exe

    E:\WINNT\netjw32.exe

    Any ideas very welcome.
    Cheers
    t

    latest log included

    Logfile of HijackThis v1.97.7
    Scan saved at 16:26:50, on 21/06/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    E:\WINNT\System32\smss.exe
    E:\WINNT\system32\winlogon.exe
    E:\WINNT\system32\services.exe
    E:\WINNT\system32\lsass.exe
    E:\WINNT\system32\svchost.exe
    E:\WINNT\system32\spoolsv.exe
    E:\Program Files\NavNT\defwatch.exe
    E:\WINNT\System32\svchost.exe
    E:\WINNT\system32\GEARSEC.EXE
    E:\Program Files\NMapWin\bin\nmapserv.exe
    E:\Program Files\NavNT\rtvscan.exe
    E:\WINNT\system32\regsvc.exe
    E:\WINNT\system32\MSTask.exe
    E:\WINNT\system32\stisvc.exe
    E:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
    E:\WINNT\System32\vmnetdhcp.exe
    E:\WINNT\System32\vmnat.exe
    E:\WINNT\System32\WBEM\WinMgmt.exe
    E:\WINNT\system32\svchost.exe
    E:\WINNT\system32\MsgSys.EXE
    E:\WINNT\Explorer.EXE
    E:\Program Files\ahead\InCD\InCD.exe
    E:\Program Files\NavNT\vptray.exe
    E:\Program Files\iTunes\iTunesHelper.exe
    E:\Program Files\iPod\bin\iPodService.exe
    E:\Program Files\QuickTime\qttask.exe
    E:\WINNT\system32\internat.exe
    E:\Program Files\NETGEAR\MA101 USB Adapter Configuration Utility\WlanMonitor.exe
    E:\Program Files\WinZip\WZQKPICK.EXE
    E:\WINNT\system32\mszy.exe
    E:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\Documents and Settings\tim\My Documents\Software Downloads\HijackThis.exe
    E:\WINNT\system32\taskmgr.exe
    E:\WINNT\netjw32.exe
    E:\WINNT\system32\NOTEPAD.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://kpiww.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://E:\WINNT\kpiww.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {19566FBD-41F9-AF6D-EC17-1B05DDF77AC6} - E:\WINNT\system32\appdk32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [NeroCheck] E:\WINNT\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] E:\Program Files\ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [KAZAA] E:\Program Files\KaZaA Lite\kpp.exe "E:\Program Files\KaZaA Lite\kazaa.exe" /SYSTRAY
    O4 - HKLM\..\Run: [vptray] E:\Program Files\NavNT\vptray.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ipas.exe] E:\WINNT\system32\ipas.exe
    O4 - HKLM\..\Run: [mszy.exe] E:\WINNT\system32\mszy.exe
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKLM\..\RunOnce: [apizu32.exe] E:\WINNT\system32\apizu32.exe
    O4 - Global Startup: MA101 Configuration Utility .lnk = E:\Program Files\NETGEAR\MA101 USB Adapter Configuration Utility\WlanMonitor.exe
    O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = E:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38016.4278125
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{286C2314-3AB8-4151-B27F-45D09E61ABB4}: NameServer = 158.152.1.58,158.152.1.43
     
  6. timockj

    timockj Registered Member

    Joined:
    Jun 21, 2004
    Posts:
    4
    Pieter,

    All resolved now. Thanks for you assistance.

    t
     
Thread Status:
Not open for further replies.