hijack log, please help, thank u

Discussion in 'adware, spyware & hijack cleaning' started by glenn2004, Jun 15, 2004.

Thread Status:
Not open for further replies.
  1. glenn2004

    glenn2004 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    Logfile of HijackThis v1.97.7
    Scan saved at 2:45:26 AM, on 6/15/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\ICO.EXE
    C:\Program Files\Sony\HotKey Utility\HKserv.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\WINDOWS\netzg.exe
    C:\Program Files\Sony\HotKey Utility\HKWnd.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wincz32.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Documents and Settings\chrismiz2\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ggjkl.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ggjkl.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ggjkl.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ggjkl.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ggjkl.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ggjkl.dll/sp.html#96676
    O2 - BHO: (no name) - {E3C75ADD-28CA-1552-C53A-CB5117FD483C} - C:\WINDOWS\winei.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [netzg.exe] C:\WINDOWS\netzg.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

    My internet is going much slower, and I can't play any videos or audios on my computer anymore whether i'm trying to access it from my files or the net, it just pops up a box that says "windows cannot find.........." and my browser used to be blank, but now it has this "Home Search" page whenever I open internet explorer, the link is:
    res://ggjkl.dll/index.html#96676

    If anyone can please help me fix this, I'd appreciate it so much.
     
  2. glenn2004

    glenn2004 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    bump, please help
     
  3. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi glenn2004,

    Before you start, please unzip hijackthis to a separate folder. The program will make backups in the folder in the folder it's in.
    These will now end up on your desktop.

    Click Start > Run > Services.msc > OK
    In the services window find Network Security Service.
    Rightclick and stop it. Put the Startup type to disabled under Properties > General tab

    Then open TaskManager and stop these two processes:
    C:\WINDOWS\netzg.exe
    C:\WINDOWS\system32\wincz32.exe

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ggjkl.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ggjkl.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ggjkl.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ggjkl.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ggjkl.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ggjkl.dll/sp.html#96676
    O2 - BHO: (no name) - {E3C75ADD-28CA-1552-C53A-CB5117FD483C} - C:\WINDOWS\winei.dll

    O4 - HKLM\..\Run: [netzg.exe] C:\WINDOWS\netzg.exe

    O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML

    Then reboot into safe mode and delete:
    C:\WINDOWS\netzg.exe
    C:\WINDOWS\system32\wincz32.exe
    C:\WINDOWS\winei.dat
    C:\WINDOWS\system32\ggjkl.dll

    Post a new log when you are done, so we can see if everything worked out as planned.

    Regards,

    Pieter
     
  4. glenn2004

    glenn2004 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    I did what you told me, and you mentioned to stop these two processes:

    C:\WINDOWS\netzg.exe
    C:\WINDOWS\system32\wincz32.exe

    However, I didn't see it. So I went to the next step. I fixed the hijack names you told me, but for some reason, I could not find these two, unless it dissappeared somewhere:

    O4 - HKLM\..\Run: [netzg.exe] C:\WINDOWS\netzg.exe
    O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML

    Then I rebooted into safe mode, and you told me to delete these:

    C:\WINDOWS\netzg.exe
    C:\WINDOWS\system32\wincz32.exe
    C:\WINDOWS\winei.dat
    C:\WINDOWS\system32\ggjkl.dll

    However, I searched in my C:\Windows and never found any of these.

    Here's my new log, it looks like it's still messed up:

    Logfile of HijackThis v1.97.7
    Scan saved at 4:16:22 PM, on 6/18/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\sysre.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\ICO.EXE
    C:\Program Files\Sony\HotKey Utility\HKserv.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\WINDOWS\system32\sdkde32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Sony\HotKey Utility\HKWnd.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Documents and Settings\chrismiz2\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ltbns.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ltbns.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ltbns.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ltbns.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ltbns.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ltbns.dll/sp.html#96676
    O2 - BHO: (no name) - {8BA8C35E-205B-6D84-9540-DED6DAD4A44C} - C:\WINDOWS\system32\javauj32.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [sdkde32.exe] C:\WINDOWS\system32\sdkde32.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKLM\..\RunOnce: [sdkzx32.exe] C:\WINDOWS\sdkzx32.exe
    O4 - HKLM\..\RunOnce: [netdh.exe] C:\WINDOWS\netdh.exe
    O4 - HKLM\..\RunOnce: [javajs32.exe] C:\WINDOWS\system32\javajs32.exe
    O4 - HKLM\..\RunOnce: [javafz.exe] C:\WINDOWS\system32\javafz.exe
    O4 - HKLM\..\RunOnce: [sdkrn32.exe] C:\WINDOWS\system32\sdkrn32.exe
    O4 - HKLM\..\RunOnce: [netba.exe] C:\WINDOWS\netba.exe
    O4 - HKLM\..\RunOnce: [netev32.exe] C:\WINDOWS\system32\netev32.exe
    O4 - HKLM\..\RunOnce: [iewr.exe] C:\WINDOWS\iewr.exe
    O4 - HKLM\..\RunOnce: [d3jy.exe] C:\WINDOWS\system32\d3jy.exe
    O4 - HKLM\..\RunOnce: [netrm32.exe] C:\WINDOWS\netrm32.exe
    O4 - HKLM\..\RunOnce: [d3wz32.exe] C:\WINDOWS\system32\d3wz32.exe
    O4 - HKLM\..\RunOnce: [atlot.exe] C:\WINDOWS\system32\atlot.exe
    O4 - HKLM\..\RunOnce: [winij.exe] C:\WINDOWS\winij.exe
    O4 - HKLM\..\RunOnce: [javadd.exe] C:\WINDOWS\javadd.exe
    O4 - HKLM\..\RunOnce: [netvh.exe] C:\WINDOWS\netvh.exe
    O4 - HKLM\..\RunOnce: [systg32.exe] C:\WINDOWS\system32\systg32.exe
    O4 - HKLM\..\RunOnce: [sdkzd.exe] C:\WINDOWS\system32\sdkzd.exe
    O4 - HKLM\..\RunOnce: [winzd32.exe] C:\WINDOWS\system32\winzd32.exe
    O4 - HKLM\..\RunOnce: [ntww32.exe] C:\WINDOWS\ntww32.exe
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

    Help please.
     
  5. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Post a new log and repeat that everytime you reboot. We need a view of the current situation to be able to guide you. At boot the filenames change.

    Regards,

    Pieter
     
  6. glenn2004

    glenn2004 Registered Member

    Joined:
    Jun 15, 2004
    Posts:
    4
    Logfile of HijackThis v1.97.7
    Scan saved at 12:51:57 PM, on 6/21/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\javadd.exe
    C:\WINDOWS\system32\javauj32.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\ICO.EXE
    C:\Program Files\Sony\HotKey Utility\HKserv.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Sony\HotKey Utility\HKWnd.exe
    C:\Documents and Settings\chrismiz2\Desktop\HijackThis.exe

    O2 - BHO: (no name) - {07E2FBBF-C64A-1972-227E-82FA4861EB78} - C:\WINDOWS\apibk.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [mfcqw32.exe] C:\WINDOWS\system32\mfcqw32.exe
    O4 - HKLM\..\Run: [javauj32.exe] C:\WINDOWS\system32\javauj32.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKLM\..\RunOnce: [systg32.exe] C:\WINDOWS\system32\systg32.exe
    O4 - HKLM\..\RunOnce: [sdkzd.exe] C:\WINDOWS\system32\sdkzd.exe
    O4 - HKLM\..\RunOnce: [winzd32.exe] C:\WINDOWS\system32\winzd32.exe
    O4 - HKLM\..\RunOnce: [ntww32.exe] C:\WINDOWS\ntww32.exe
    O4 - HKLM\..\RunOnce: [sdksj32.exe] C:\WINDOWS\sdksj32.exe
    O4 - HKLM\..\RunOnce: [netha.exe] C:\WINDOWS\netha.exe
    O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
    O4 - HKLM\..\RunOnce: [d3hb32.exe] C:\WINDOWS\system32\d3hb32.exe
    O4 - HKLM\..\RunOnce: [ntbz.exe] C:\WINDOWS\ntbz.exe
    O4 - HKLM\..\RunOnce: [sysmg.exe] C:\WINDOWS\system32\sysmg.exe
    O4 - HKLM\..\RunOnce: [ipfb.exe] C:\WINDOWS\system32\ipfb.exe
    O4 - HKLM\..\RunOnce: [atltq32.exe] C:\WINDOWS\system32\atltq32.exe
    O4 - HKLM\..\RunOnce: [atlwl.exe] C:\WINDOWS\atlwl.exe
    O4 - HKLM\..\RunOnce: [sdkud.exe] C:\WINDOWS\system32\sdkud.exe
    O4 - HKLM\..\RunOnce: [netgx.exe] C:\WINDOWS\netgx.exe
    O4 - HKLM\..\RunOnce: [apphs32.exe] C:\WINDOWS\apphs32.exe
    O4 - HKLM\..\RunOnce: [ipnx.exe] C:\WINDOWS\ipnx.exe
    O4 - HKLM\..\RunOnce: [sysre.exe] C:\WINDOWS\system32\sysre.exe
    O4 - HKLM\..\RunOnce: [javank32.exe] C:\WINDOWS\system32\javank32.exe

    The log seems better (as seen on top), but whenever I click on my IE browser icon to open a page, the "home search" page comes right back on again and my hijack log gets messed up again(as seen below):

    Logfile of HijackThis v1.97.7
    Scan saved at 12:56:42 PM, on 6/21/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\javadd.exe
    C:\WINDOWS\system32\javauj32.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\System32\ICO.EXE
    C:\Program Files\Sony\HotKey Utility\HKserv.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Sony\HotKey Utility\HKWnd.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\chrismiz2\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ekaxm.dll/sp.html#96676
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ekaxm.dll/index.html#96676
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ekaxm.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ekaxm.dll/sp.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ekaxm.dll/index.html#96676
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ekaxm.dll/sp.html#96676
    O2 - BHO: (no name) - {07E2FBBF-C64A-1972-227E-82FA4861EB78} - C:\WINDOWS\apibk.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [mfcqw32.exe] C:\WINDOWS\system32\mfcqw32.exe
    O4 - HKLM\..\Run: [javauj32.exe] C:\WINDOWS\system32\javauj32.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKLM\..\RunOnce: [systg32.exe] C:\WINDOWS\system32\systg32.exe
    O4 - HKLM\..\RunOnce: [sdkzd.exe] C:\WINDOWS\system32\sdkzd.exe
    O4 - HKLM\..\RunOnce: [winzd32.exe] C:\WINDOWS\system32\winzd32.exe
    O4 - HKLM\..\RunOnce: [ntww32.exe] C:\WINDOWS\ntww32.exe
    O4 - HKLM\..\RunOnce: [sdksj32.exe] C:\WINDOWS\sdksj32.exe
    O4 - HKLM\..\RunOnce: [netha.exe] C:\WINDOWS\netha.exe
    O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
    O4 - HKLM\..\RunOnce: [d3hb32.exe] C:\WINDOWS\system32\d3hb32.exe
    O4 - HKLM\..\RunOnce: [ntbz.exe] C:\WINDOWS\ntbz.exe
    O4 - HKLM\..\RunOnce: [sysmg.exe] C:\WINDOWS\system32\sysmg.exe
    O4 - HKLM\..\RunOnce: [ipfb.exe] C:\WINDOWS\system32\ipfb.exe
    O4 - HKLM\..\RunOnce: [atltq32.exe] C:\WINDOWS\system32\atltq32.exe
    O4 - HKLM\..\RunOnce: [atlwl.exe] C:\WINDOWS\atlwl.exe
    O4 - HKLM\..\RunOnce: [sdkud.exe] C:\WINDOWS\system32\sdkud.exe
    O4 - HKLM\..\RunOnce: [netgx.exe] C:\WINDOWS\netgx.exe
    O4 - HKLM\..\RunOnce: [apphs32.exe] C:\WINDOWS\apphs32.exe
    O4 - HKLM\..\RunOnce: [ipnx.exe] C:\WINDOWS\ipnx.exe
    O4 - HKLM\..\RunOnce: [sysre.exe] C:\WINDOWS\system32\sysre.exe
    O4 - HKLM\..\RunOnce: [javank32.exe] C:\WINDOWS\system32\javank32.exe
    O4 - HKLM\..\RunOnce: [atlnp32.exe] C:\WINDOWS\atlnp32.exe
    O4 - HKLM\..\RunOnce: [netuv.exe] C:\WINDOWS\system32\netuv.exe

    Help please.
     
Thread Status:
Not open for further replies.