Browser Hijacked

Discussion in 'adware, spyware & hijack cleaning' started by ennyoueffsea, May 5, 2004.

Thread Status:
Not open for further replies.
  1. ennyoueffsea

    ennyoueffsea Registered Member

    Joined:
    May 5, 2004
    Posts:
    28
    Location:
    Newcastle Upon Tyne, U.K.
    Hi everyone,

    Can you please help. Am writing for a friend. She actually uses AOL as her ISP and Internet Explorer runs in the background. She has found that the IE browser has been taken over by something called 4-counter.com.
    Despite trying to reset the home page on IE. It constantly reverts to the hi-jacker. Having run Adaware last night, there were 28 files found, that had been previously deleted. Though they appear to been deleted since, this site still is in control of the home page.
    Her son plays on an AOL games site and it also appears that quite a lot of garbage has attached itself. I had her run Hijack This and her results are as follows. Any help would be really appreciated.

    Terry :)



    logfile of HijackThis v1.97.7
    Scan saved at 00:43:21, on 06/05/04
    Platform: Windows 98 Gold (Win9x 4.10.199:cool:
    MSIE: Internet Explorer v5.50 (5.50.4134.0600)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\DISKSERV.EXE
    C:\WINDOWS\SYSTEM32\WINPROC32.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
    C:\PROGRAM FILES\CALIBRE INC\XCONNECT\XCONNECT.EXE
    C:\PROGRAM FILES\AOL 7.0\AOLTRAY.EXE
    C:\PROGRAM FILES\CALIBRE INC\PRINTCONNECT\XSENDREG.EXE
    C:\WINDOWS\SYSTEM\IRMON.EXE
    C:\WINDOWS\IRXFER.EXE
    C:\PROGRAM FILES\AOL 7.0\WAOL.EXE
    C:\PROGRAM FILES\AOL 7.0\DOWNLOAD\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://4-counter.com/?a=2&b=cr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = C:\WINDOWS\system32\searchbar.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://4-counter.com/?a=2&b=cr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://4-counter.com/?a=2&b=cr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://4-counter.com/?b=cr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://4-counter.com/?a=2&b=cr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = C:\WINDOWS\system32\searchbar.html
    R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://4-counter.com/?a=2&b=cr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://4-counter.com/?a=2&b=cr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://4-counter.com/?a=2&b=cr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = C:\WINDOWS\system32\searchbar.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://4-counter.com/?a=2&b=cr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AOL
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://e-plus.cc/search.php?aff_id=46&keyword=%s
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [Disk Master] C:\windows\diskserv.exe
    O4 - HKCU\..\Run: [Service Manager] C:\windows\dxsound.exe
    O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\SYSTEM32\WINPROC32.EXE
    O4 - HKCU\..\RunOnce: [DoXSendReg] C:\PROGRAM FILES\CALIBRE INC\PRINTCONNECT\XSENDREG.exe PrintConnect
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: xConnect.lnk = C:\Program Files\Calibre Inc\xConnect\xConnect.exe
    O4 - Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
    O9 - Extra button: Real.com (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.aol.co.uk
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://V:\SuperCD\IntraLaunch.CAB
    O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo.com/applet-5.8....m-ob-assets.cab
    O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://c:\MAIN.MHT!http://213.159.117.236/buka.chm::/x.exe
    O16 - DPF: Tri-Peaks by pogo - http://peaks.pogo.com/applet-5.8.1....s-ob-assets.cab
    O16 - DPF: Mah Jong Garden by pogo - http://mahjong2.pogo.com/applet-5.8...g-ob-assets.cab
    O16 - DPF: High Stakes Pool by pogo - http://pool2.pogo.com/applet-5.8.1....l-ob-assets.cab
    O16 - DPF: Showbiz Slots by pogo - http://showbiz.pogo.com/applet-5.8....z-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://klondike.pogo.com/applet-5.8...s-ob-assets.cab
    O16 - DPF: EZ Win Bingo by pogo - http://bingoe.pogo.com/applet-5.8.1...e-ob-assets.cab
    O16 - DPF: 3 Point Showdown by pogo - http://threepoint01.pogo.com/applet...t-ob-assets.cab
    O16 - DPF: Word Whomp by pogo - http://whomp.pogo.com/applet-5.8.1....p-ob-assets.cab
    O16 - DPF: Big Shot Roulette TM by pogo - http://roulet.pogo.com/applet-5.8.1...e-ob-assets.cab
    O16 - DPF: Buckaroo Blackjack TM by pogo - http://vbjack.pogo.com/applet-5.8.1...k-ob-assets.cab
    O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/apple...g-ob-assets.cab
    O16 - DPF: Tumble Bees by pogo - http://jumbee.pogo.com/applet-5.8.2...e-ob-assets.cab
     
  2. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Hi ennyoueffsea,

    Save this removal tool on a floppydisk, in case you can't get it from your friend's PC :

    CWShredder

    Run that proggy on your friends PC and repost another log here after doing so

    Thnx!

    Cheers,
     
  3. ennyoueffsea

    ennyoueffsea Registered Member

    Joined:
    May 5, 2004
    Posts:
    28
    Location:
    Newcastle Upon Tyne, U.K.
    Hi Unzy,

    Many thanks for your help. I have pasted her reply mail to me below. See what you think of it.

    Thanks again,

    Terry

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~
    We ran CW Shredder and it only found one thing which is
    C:\\windows\discserve.exe which it said check if you dont recognise. So, we haveleft it. After running Hijack this, the log is as follows.

    It has got rid of the global counter though.

    Tx
    E

    Logfile of HijackThis v1.97.7
    Scan saved at 17:49:45, on 06/05/04
    Platform: Windows 98 Gold (Win9x 4.10.199:cool:
    MSIE: Internet Explorer v5.50 (5.50.4134.0600)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\RunDLL.exe
    C:\WINDOWS\DISKSERV.EXE
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
    C:\PROGRAM FILES\CALIBRE INC\XCONNECT\XCONNECT.EXE
    C:\PROGRAM FILES\AOL 7.0\AOLTRAY.EXE
    C:\PROGRAM FILES\CALIBRE INC\PRINTCONNECT\XSENDREG.EXE
    C:\WINDOWS\SYSTEM\IRMON.EXE
    C:\WINDOWS\IRXFER.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\PROGRAM FILES\AOL 7.0\DOWNLOAD\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AOL
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\Run: [Disk Master] C:\windows\diskserv.exe
    O4 - HKCU\..\Run: [Service Manager] C:\windows\dxsound.exe
    O4 - HKCU\..\RunOnce: [DoXSendReg] C:\PROGRAM FILES\CALIBRE INC\PRINTCONNECT\XSENDREG.exe PrintConnect
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: xConnect.lnk = C:\Program Files\Calibre Inc\xConnect\xConnect.exe
    O4 - Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
    O9 - Extra button: Real.com (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.aol.co.uk
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://V:\SuperCD\IntraLaunch.CAB
    O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo.com/applet-5.8.2.19/holdem/holdem-ob-assets.cab
    O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://c:\MAIN.MHT!http://213.159.117.236/buka.chm::/x.exe
    O16 - DPF: Tri-Peaks by pogo - http://peaks.pogo.com/applet-5.8.1.28/peaks/peaks-ob-assets.cab
    O16 - DPF: Mah Jong Garden by pogo - http://mahjong2.pogo.com/applet-5.8.1.28/mahjong/mahjong-ob-assets.cab
    O16 - DPF: High Stakes Pool by pogo - http://pool2.pogo.com/applet-5.8.1.28/pool2/pool-ob-assets.cab
    O16 - DPF: Showbiz Slots by pogo - http://showbiz.pogo.com/applet-5.8.1.28/slots/showbiz-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://klondike.pogo.com/applet-5.8.1.28/worldclass/worldclass-ob-assets.cab
    O16 - DPF: EZ Win Bingo by pogo - http://bingoe.pogo.com/applet-5.8.1.28/bingo/bingoe-ob-assets.cab
    O16 - DPF: 3 Point Showdown by pogo - http://threepoint01.pogo.com/applet-5.8.1.28/threepoint/threepoint-ob-assets.cab
    O16 - DPF: Word Whomp by pogo - http://whomp.pogo.com/applet-5.8.1.28/wordwhomp/wordwhomp-ob-assets.cab
    O16 - DPF: Big Shot Roulette TM by pogo - http://roulet.pogo.com/applet-5.8.1.28/roulette/roulette-ob-assets.cab
    O16 - DPF: Buckaroo Blackjack TM by pogo - http://vbjack.pogo.com/applet-5.8.1.28/videoblackjack/videoblackjack-ob-assets.cab
    O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet-5.8.1.28/checkeredflag/checkeredflag-ob-assets.cab
    O16 - DPF: Tumble Bees by pogo - http://jumbee.pogo.com/applet-5.8.2.19/jumbee/jumbee-ob-assets.cab
     
  4. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Ok, looking much better!

    Still fix the following :

    O4 - HKCU\..\Run: [Disk Master] C:\windows\diskserv.exe
    O4 - HKCU\..\Run: [Service Manager] C:\windows\dxsound.exe

    O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://c:\MAIN.MHT!http://213.159.117.236/buka.chm::/x.exe

    Restart PC after doing so and remove :

    C:\windows\diskserv.exe <- this file
    C:\windows\dxsound.exe <- this file

    Clean temp internet files

    Update IE to latest patches at windowsupdate.com

    Cheers,
     
  5. ennyoueffsea

    ennyoueffsea Registered Member

    Joined:
    May 5, 2004
    Posts:
    28
    Location:
    Newcastle Upon Tyne, U.K.
    Thanks Unzy,

    Have forwarded on your reply to her. Will get back to you as soon as I can.

    Many thanks again,

    Terry
     
  6. ennyoueffsea

    ennyoueffsea Registered Member

    Joined:
    May 5, 2004
    Posts:
    28
    Location:
    Newcastle Upon Tyne, U.K.
    Hi Unzy,

    Below is the reply received after carrying out your instructions.

    Regards,

    Terry

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    This is the results of the scan after following the instructions that you sent. I had noticed that the global 4 counter had stopped trying to gain access but the disk serve. exe had started trying. Adaware has found nothing for the last 2 days and was updated this morning and still nothing. The pop ups from the firewall for discserve have stopped as well, and things are running a lot faster.



    Logfile of HijackThis v1.97.7
    Scan saved at 05:09:51, on 11/05/04
    Platform: Windows 98 Gold (Win9x 4.10.199:cool:
    MSIE: Internet Explorer v5.50 (5.50.4134.0600)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\RunDLL.exe
    C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
    C:\PROGRAM FILES\CALIBRE INC\XCONNECT\XCONNECT.EXE
    C:\PROGRAM FILES\AOL 7.0\AOLTRAY.EXE
    C:\PROGRAM FILES\CALIBRE INC\PRINTCONNECT\XSENDREG.EXE
    C:\WINDOWS\SYSTEM\IRMON.EXE
    C:\WINDOWS\IRXFER.EXE
    C:\PROGRAM FILES\AOL 7.0\DOWNLOAD\HIJACKTHIS.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\AOL 7.0\WAOL.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.co.uk/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AOL
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    O4 - HKCU\..\RunOnce: [DoXSendReg] C:\PROGRAM FILES\CALIBRE INC\PRINTCONNECT\XSENDREG.exe PrintConnect
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: xConnect.lnk = C:\Program Files\Calibre Inc\xConnect\xConnect.exe
    O4 - Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
    O9 - Extra button: Real.com (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.aol.co.uk
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://V:\SuperCD\IntraLaunch.CAB
    O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo.com/applet-5.8.2.19/holdem/holdem-ob-assets.cab
    O16 - DPF: Tri-Peaks by pogo - http://peaks.pogo.com/applet-5.8.1.28/peaks/peaks-ob-assets.cab
    O16 - DPF: Mah Jong Garden by pogo - http://mahjong2.pogo.com/applet-5.8.1.28/mahjong/mahjong-ob-assets.cab
    O16 - DPF: High Stakes Pool by pogo - http://pool2.pogo.com/applet-5.8.1.28/pool2/pool-ob-assets.cab
    O16 - DPF: Showbiz Slots by pogo - http://showbiz.pogo.com/applet-5.8.1.28/slots/showbiz-ob-assets.cab
    O16 - DPF: World Class Solitaire by pogo - http://klondike.pogo.com/applet-5.8.1.28/worldclass/worldclass-ob-assets.cab
    O16 - DPF: EZ Win Bingo by pogo - http://bingoe.pogo.com/applet-5.8.1.28/bingo/bingoe-ob-assets.cab
    O16 - DPF: 3 Point Showdown by pogo - http://threepoint01.pogo.com/applet-5.8.1.28/threepoint/threepoint-ob-assets.cab
    O16 - DPF: Word Whomp by pogo - http://whomp.pogo.com/applet-5.8.1.28/wordwhomp/wordwhomp-ob-assets.cab
    O16 - DPF: Big Shot Roulette TM by pogo - http://roulet.pogo.com/applet-5.8.1.28/roulette/roulette-ob-assets.cab
    O16 - DPF: Buckaroo Blackjack TM by pogo - http://vbjack.pogo.com/applet-5.8.1.28/videoblackjack/videoblackjack-ob-assets.cab
    O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet-5.8.1.28/checkeredflag/checkeredflag-ob-assets.cab
    O16 - DPF: Tumble Bees by pogo - http://jumbee.pogo.com/applet-5.8.2.19/jumbee/jumbee-ob-assets.cab
    O16 - DPF: Top Down Baseball Challenge by pogo - http://topdown2.pogo.com/applet-5.8.2.19/topdown2/topdown2-ob-assets.cab
    O16 - DPF: Pop Fu by pogo - http://popfu.pogo.com/applet-5.8.2.19/popfu/popfu-ob-assets.cab
    O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pogo.com/applet-5.8.2.19/whackdown/whackdown-ob-assets.cab
    O16 - DPF: Fortune Bingo by pogo - http://superbingo.pogo.com/applet-5.8.2.19/superbingo/superbingo-ob-assets.cab
    O16 - DPF: Greenback Bayou by pogo - http://greenback.pogo.com/applet-5.8.2.19/greenback/greenback-ob-assets.cab
     
  7. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Hi Terry,

    Good job that looks like a clean log again :)

    Just make sure you update IE to the latest security patches at windowsupdate.com!

    Hope all is well again

    take care

    Cheers,
     
  8. ennyoueffsea

    ennyoueffsea Registered Member

    Joined:
    May 5, 2004
    Posts:
    28
    Location:
    Newcastle Upon Tyne, U.K.
    Hi Unzy,

    Many thanks again for all of your help. Your an absolute star. I'm going to try and sort mine next. If I post a log of my own over the next couple of days, could you cast an eye over it?
    Out oftime for posting tonight as i'm just leaving for work on nightshift.

    Many many thanks again Unzy.

    Terry :D
     
  9. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Sure Terry!

    Glad all is well again

    take care

    Cheers,
     
  10. ennyoueffsea

    ennyoueffsea Registered Member

    Joined:
    May 5, 2004
    Posts:
    28
    Location:
    Newcastle Upon Tyne, U.K.
    Thanks again Unzy.

    Would you suggest I posted my Hijack This log on this thread? Or start a new one?

    Very best regards,

    Terry
     
  11. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    If it's a different computer than please start a new thread and make sure you state it's a different computer otherwise we get confused o_O and wonder how alll the cleaning hasn't worked and move the posts back here
     
Thread Status:
Not open for further replies.