Page 1 of 2 12 LastLast
Results 1 to 10 of 11

Thread: Spyware

  1. #1
    I'd just like to apologise if this is the wrong place to post this, i had a look around and thought this would be my best bet.

    The other night i was online and i got a message from Norton Anti Virus saying that it had blocked some kind of Trojan thing. Now i keep getting messages from Spyware guard telling me that something is trying to change all my internet options. I downloaded a new program called Spyware doctor which found stuff my other anti spyware software couldn't it said it removed the problems and i restarted my PC but i still get the same message when opening webpages. Can any one help?

    This is the software i run on my PC, none of it seems to be helping and a full Norton Anti Virus Scan couldn't find anything.

    Spyware Blaster
    Spybot Search and Destroy
    Spyware Doctor
    Spyware Guard

    Any help would be much appreciated, this is driving me mad. :helpsmile:
    My Tracks:
    http://www.twotech.co.uk/dmc/Mkkxx-TheFall.mp3 (<span style='color:red'>3</span> plays in Taste&#33
    http://www.twotech.co.uk/dmc/Mkkxx-Untitled.mp3 (New track)

  2. Software & Hardware   -   #2
    vidcc's Avatar there is no god
    Join Date
    Dec 2003
    Location
    USA
    Posts
    5,606
    try to find the name of the trojan/dialer and google it or look it up here that&#39;s the Mcafee virus/trojan library..you should be able to get removal advice there

    it’s an election with no Democrats, in one of the whitest states in the union, where rich candidates pay $35 for your votes. Or, as Republicans call it, their vision for the future.

  3. Software & Hardware   -   #3
    TRshady
    Guest
    You could try running an trend call online scan for example, and of course once you have the name you&#39;ll be able to search symantec.com for example and get the appropriate removal tools. Good luck

  4. Software & Hardware   -   #4
    Poster
    Join Date
    Mar 2003
    Posts
    365
    Check for updates in spybot, if any are found run it again.

    Download and run Ad-Aware.
    Before you run it, check for updates.Click the gear at the top and change these settings:
    general> activate:automatically save log file,automatically quarantine objects prior to removal

    scanning> activate:scan within archives, scan active processes, scan registry, deep scan registry,
    scan my IE Favorites for banned sites and scan my hosts file


    tweaks>scanning engine>activate:unload recognized processes during scanning.

    tweaks>cleaning engine>activate:automatically try to unregister objects prior to deletion and let windows remove
    files in use after reboot


    click proceed to save your settings.

    Now run it, make sure "activate in-depth scan " is checked. Fix anything it finds.


    Download HiJackThis.
    Place hjt in its own folder like C:&#092;HiJackThis&#092;hijackthis.exe
    Close all browser windows,click scan,then save log.
    Post the log file here from hjt.

    The hjt server appears to be offline, try one of these to download..
    http://tomcoyote.com/hjt/
    http://www.snapfiles.com/get/hijackthis.html
    http://www.wilderssecurity.com/showthread.php?t=12516

  5. Software & Hardware   -   #5
    I appear to have &#39;Trojan Horse: BackDoor.Agent.BA&#39; and apparently it is currently impossible to cure since no virus scanning software can recognise and delete it. Link to thread below. Any thoughts?


    http://www.computing.net/security/ww...rum/12291.html
    My Tracks:
    http://www.twotech.co.uk/dmc/Mkkxx-TheFall.mp3 (<span style='color:red'>3</span> plays in Taste&#33
    http://www.twotech.co.uk/dmc/Mkkxx-Untitled.mp3 (New track)

  6. Software & Hardware   -   #6
    Poster
    Join Date
    Mar 2003
    Posts
    365
    Any thoughts?
    Yes, did you run adaware?

    Run hjt and post the log.

  7. Software & Hardware   -   #7
    Logfile of HijackThis v1.97.7
    Scan saved at 19:32:30, on 24/06/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:&#092;WINDOWS&#092;System32&#092;smss.exe
    C:&#092;WINDOWS&#092;system32&#092;winlogon.exe
    C:&#092;WINDOWS&#092;system32&#092;services.exe
    C:&#092;WINDOWS&#092;system32&#092;lsass.exe
    C:&#092;WINDOWS&#092;system32&#092;svchost.exe
    C:&#092;WINDOWS&#092;System32&#092;svchost.exe
    C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe
    C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccEvtMgr.exe
    C:&#092;WINDOWS&#092;system32&#092;CTsvcCDA.EXE
    C:&#092;PROGRA~1&#092;NORTON~1&#092;NORTON~2&#092;GHOSTS~2.EXE
    C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton AntiVirus&#092;navapsvc.exe
    C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton Utilities&#092;NPROTECT.EXE
    C:&#092;WINDOWS&#092;System32&#092;nvsvc32.exe
    C:&#092;PROGRA~1&#092;NORTON~1&#092;SPEEDD~1&#092;nopdb.exe
    C:&#092;WINDOWS&#092;System32&#092;MsPMSPSv.exe
    C:&#092;WINDOWS&#092;Explorer.EXE
    C:&#092;Program Files&#092;Adaptec&#092;Easy CD Creator 5&#092;DirectCD&#092;DirectCD.exe
    C:&#092;WINDOWS&#092;SOUNDMAN.EXE
    C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccApp.exe
    C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton Ghost&#092;GhostStartTrayApp.exe
    C:&#092;Program Files&#092;Creative&#092;ShareDLL&#092;CtNotify.exe
    C:&#092;WINDOWS&#092;System32&#092;RunDll32.exe
    C:&#092;Program Files&#092;Creative&#092;ShareDLL&#092;MediaDet.exe
    C:&#092;WINDOWS&#092;System32&#092;ezSP_Px.exe
    C:&#092;WINDOWS&#092;System32&#092;ctfmon.exe
    C:&#092;Program Files&#092;Sonique&#092;sqstart.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;RcMan.EXE
    C:&#092;program files&#092;HaldexLtd&#092;stnd246&#092;3056094.exe
    C:&#092;WINDOWS&#092;System32&#092;RUNDLL32.EXE
    C:&#092;Program Files&#092;LightSurf&#092;Common&#092;IconMgr.exe
    C:&#092;Program Files&#092;LightSurf&#092;Color Indicator&#092;TICIcon.exe
    C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Works Shared&#092;wkcalrem.exe
    C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;sgmain.exe
    C:&#092;Program Files&#092;MSN Messenger&#092;msnmsgr.exe
    C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE
    C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE
    C:&#092;Program Files&#092;Spyware Doctor&#092;spydoctor.exe
    C:&#092;Program Files&#092;GetRight&#092;getright.exe
    C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;sgbhp.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;EAX.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Center&#092;RCenter.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;OSDMenu.EXE
    C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE
    C:&#092;WINDOWS&#092;notepad.exe
    C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe
    C:&#092;Documents and Settings&#092;New User&#092;My Documents&#092;Documents&#092;assessment&#092;New Folder&#092;Programs&#092;Applications&#092;HijackThis.exe

    R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://www.cpbb.co.uk/
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;NEWUSE~1&#092;LOCALS~1&#092;Temp&#092;sp.html
    R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;NEWUSE~1&#092;LOCALS~1&#092;Temp&#092;sp.html
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings,ProxyServer = http://www-cache.freeserve.com:8080
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Adobe&#092;Acrobat 6.0&#092;Reader&#092;ActiveX&#092;AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;dlprotect.dll
    O2 - BHO: (no name) - {6CF16B2C-327C-4B88-B66B-A9F48B15569D} - C:&#092;WINDOWS&#092;System32&#092;fbgjld.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton AntiVirus&#092;NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:&#092;WINDOWS&#092;System32&#092;msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton AntiVirus&#092;NavShExt.dll
    O4 - HKLM&#092;..&#092;Run: [AdaptecDirectCD] "C:&#092;Program Files&#092;Adaptec&#092;Easy CD Creator 5&#092;DirectCD&#092;DirectCD.exe"
    O4 - HKLM&#092;..&#092;Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM&#092;..&#092;Run: [ccApp] "C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccApp.exe"
    O4 - HKLM&#092;..&#092;Run: [ccRegVfy] "C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccRegVfy.exe"
    O4 - HKLM&#092;..&#092;Run: [GhostStartTrayApp] C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton Ghost&#092;GhostStartTrayApp.exe
    O4 - HKLM&#092;..&#092;Run: [Disc Detector] C:&#092;Program Files&#092;Creative&#092;ShareDLL&#092;CtNotify.exe
    O4 - HKLM&#092;..&#092;Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKLM&#092;..&#092;Run: [UpdReg] C:&#092;WINDOWS&#092;UpdReg.EXE
    O4 - HKLM&#092;..&#092;Run: [CTStartup] C:&#092;Program Files&#092;Creative&#092;Splash Screen&#092;CTEaxSpl.EXE /run
    O4 - HKLM&#092;..&#092;Run: [ezShieldProtector for Px] C:&#092;WINDOWS&#092;System32&#092;ezSP_Px.exe
    O4 - HKLM&#092;..&#092;Run: [NvCplDaemon] RUNDLL32.EXE C:&#092;WINDOWS&#092;System32&#092;NvCpl.dll,NvStartup
    O4 - HKLM&#092;..&#092;Run: [nwiz] nwiz.exe /install
    O4 - HKLM&#092;..&#092;Run: [PinnacleDriverCheck] C:&#092;WINDOWS&#092;System32&#092;PSDrvCheck.exe
    O4 - HKLM&#092;..&#092;Run: [TkBellExe] "C:&#092;Program Files&#092;K-Lite Codec Pack&#092;real&#092;Update_OB&#092;realsched.exe" -osboot
    O4 - HKCU&#092;..&#092;Run: [CTFMON.EXE] C:&#092;WINDOWS&#092;System32&#092;ctfmon.exe
    O4 - HKCU&#092;..&#092;Run: [SoniqueQuickStart] C:&#092;Program Files&#092;Sonique&#092;sqstart.exe -nostick
    O4 - HKCU&#092;..&#092;Run: [RemoteCenter] C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;RcMan.EXE
    O4 - HKCU&#092;..&#092;Run: [sws.exe] c:&#092;program files&#092;HaldexLtd&#092;stnd246&#092;3056094.exe -remove
    O4 - HKCU&#092;..&#092;Run: [NvMediaCenter] RUNDLL32.EXE C:&#092;WINDOWS&#092;System32&#092;NVMCTRAY.DLL,NvTaskbarInit
    O4 - Startup: SpywareGuard.lnk = C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;sgmain.exe
    O4 - Global Startup: LightSurf.lnk = C:&#092;Program Files&#092;LightSurf&#092;Common&#092;IconMgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:&#092;Program Files&#092;Microsoft Office&#092;Office&#092;OSA9.EXE
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O6 - HKCU&#092;Software&#092;Policies&#092;Microsoft&#092;Internet Explorer&#092;Restrictions present
    O6 - HKCU&#092;Software&#092;Policies&#092;Microsoft&#092;Internet Explorer&#092;Control Panel present
    O8 - Extra context menu item: Download with GetRight - C:&#092;Program Files&#092;GetRight&#092;GRdownload.htm
    O8 - Extra context menu item: Open with GetRight Browser - C:&#092;Program Files&#092;GetRight&#092;GRbrowse.htm
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra &#39;Tools&#39; menuitem: Messenger (HKLM)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/patch/EARTPX.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7690.5254861111
    O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/SassCln.CAB
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/patch/MaxisSimCity4PatcherX.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
    My Tracks:
    http://www.twotech.co.uk/dmc/Mkkxx-TheFall.mp3 (<span style='color:red'>3</span> plays in Taste&#33
    http://www.twotech.co.uk/dmc/Mkkxx-Untitled.mp3 (New track)

  8. Software & Hardware   -   #8
    Poster
    Join Date
    Mar 2003
    Posts
    365
    Haldex is a dialer application. (O4 - HKCU&#092;..&#092;Run: [sws.exe] c:&#092;program files&#092;HaldexLtd&#092;stnd246&#092;3056094.exe -remove)

    Close all browser windows, run hjt and checkmark to fix:

    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;NEWUSE~1&#092;LOCALS~1&#092;Temp&#092;sp.html
    R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;NEWUSE~1&#092;LOCALS~1&#092;Temp&#092;sp.html

    Are you using this proxy, if not fix:
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Windows&#092;CurrentVersion&#092;Internet Settings,ProxyServer = http://www-cache.freeserve.com:8080
    fix:
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,HomeOldSP = about:blank

    O2 - BHO: (no name) - {6CF16B2C-327C-4B88-B66B-A9F48B15569D} - C:&#092;WINDOWS&#092;System32&#092;fbgjld.dll

    O4 - HKCU&#092;..&#092;Run: [sws.exe] c:&#092;program files&#092;HaldexLtd&#092;stnd246&#092;3056094.exe -remove

    Fix these unless you set spybot to lock them:
    O6 - HKCU&#092;Software&#092;Policies&#092;Microsoft&#092;Internet Explorer&#092;Restrictions present
    O6 - HKCU&#092;Software&#092;Policies&#092;Microsoft&#092;Internet Explorer&#092;Control Panel present

    Reboot into safemode and delete in bold
    C:&#092;program files&#092;HaldexLtd&#092;stnd246&#092;3056094.exe < delete the haldex folder
    C:&#092;WINDOWS&#092;System32&#092;fbgjld.dll
    C:&#092;Documents and Settings&#092;username&#092;Local Settings&#092;Temp&#092;sp.html

    boot into normal mode, run a new hjt log and post it.

  9. Software & Hardware   -   #9
    Poster
    Join Date
    Jun 2003
    Posts
    182
    do a norton system scan in the specific folder, if you cant delete it then quarantine it and forget about it also def run adaware

    i only run 2 spyware pros and they work perfecty (Spybot SandD and Adaware)

  10. Software & Hardware   -   #10
    Done what you said. Messages appear to have stopped. Here is new log file:

    Logfile of HijackThis v1.97.7
    Scan saved at 23:21:03, on 24/06/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:&#092;WINDOWS&#092;System32&#092;smss.exe
    C:&#092;WINDOWS&#092;system32&#092;winlogon.exe
    C:&#092;WINDOWS&#092;system32&#092;services.exe
    C:&#092;WINDOWS&#092;system32&#092;lsass.exe
    C:&#092;WINDOWS&#092;system32&#092;svchost.exe
    C:&#092;WINDOWS&#092;System32&#092;svchost.exe
    C:&#092;WINDOWS&#092;system32&#092;spoolsv.exe
    C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccEvtMgr.exe
    C:&#092;WINDOWS&#092;system32&#092;CTsvcCDA.EXE
    C:&#092;PROGRA~1&#092;NORTON~1&#092;NORTON~2&#092;GHOSTS~2.EXE
    C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton AntiVirus&#092;navapsvc.exe
    C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton Utilities&#092;NPROTECT.EXE
    C:&#092;WINDOWS&#092;System32&#092;nvsvc32.exe
    C:&#092;PROGRA~1&#092;NORTON~1&#092;SPEEDD~1&#092;nopdb.exe
    C:&#092;WINDOWS&#092;System32&#092;MsPMSPSv.exe
    C:&#092;WINDOWS&#092;Explorer.EXE
    C:&#092;Program Files&#092;Adaptec&#092;Easy CD Creator 5&#092;DirectCD&#092;DirectCD.exe
    C:&#092;WINDOWS&#092;SOUNDMAN.EXE
    C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccApp.exe
    C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton Ghost&#092;GhostStartTrayApp.exe
    C:&#092;Program Files&#092;Creative&#092;ShareDLL&#092;CtNotify.exe
    C:&#092;WINDOWS&#092;System32&#092;RunDll32.exe
    C:&#092;WINDOWS&#092;System32&#092;ezSP_Px.exe
    C:&#092;WINDOWS&#092;System32&#092;ctfmon.exe
    C:&#092;Program Files&#092;Sonique&#092;sqstart.exe
    C:&#092;Program Files&#092;Creative&#092;ShareDLL&#092;MediaDet.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;RcMan.EXE
    C:&#092;WINDOWS&#092;System32&#092;RUNDLL32.EXE
    C:&#092;Program Files&#092;LightSurf&#092;Common&#092;IconMgr.exe
    C:&#092;Program Files&#092;Common Files&#092;Microsoft Shared&#092;Works Shared&#092;wkcalrem.exe
    C:&#092;Program Files&#092;LightSurf&#092;Color Indicator&#092;TICIcon.exe
    C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;sgmain.exe
    C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;sgbhp.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;EAX.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Center&#092;RCenter.exe
    C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;OSDMenu.EXE
    C:&#092;WINDOWS&#092;System32&#092;wuauclt.exe
    C:&#092;Documents and Settings&#092;New User&#092;My Documents&#092;Documents&#092;assessment&#092;New Folder&#092;Programs&#092;Applications&#092;HijackThis.exe
    C:&#092;Program Files&#092;Internet Explorer&#092;IEXPLORE.EXE
    C:&#092;Program Files&#092;Messenger&#092;msmsgs.exe

    R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://www.cpbb.co.uk/
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;NEWUSE~1&#092;LOCALS~1&#092;Temp&#092;sp.html
    R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Search,SearchAssistant = file://C:&#092;DOCUME~1&#092;NEWUSE~1&#092;LOCALS~1&#092;Temp&#092;sp.html
    R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:&#092;Program Files&#092;Adobe&#092;Acrobat 6.0&#092;Reader&#092;ActiveX&#092;AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;dlprotect.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton AntiVirus&#092;NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:&#092;WINDOWS&#092;System32&#092;msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton AntiVirus&#092;NavShExt.dll
    O4 - HKLM&#092;..&#092;Run: [AdaptecDirectCD] "C:&#092;Program Files&#092;Adaptec&#092;Easy CD Creator 5&#092;DirectCD&#092;DirectCD.exe"
    O4 - HKLM&#092;..&#092;Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM&#092;..&#092;Run: [ccApp] "C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccApp.exe"
    O4 - HKLM&#092;..&#092;Run: [ccRegVfy] "C:&#092;Program Files&#092;Common Files&#092;Symantec Shared&#092;ccRegVfy.exe"
    O4 - HKLM&#092;..&#092;Run: [GhostStartTrayApp] C:&#092;Program Files&#092;Norton SystemWorks&#092;Norton Ghost&#092;GhostStartTrayApp.exe
    O4 - HKLM&#092;..&#092;Run: [Disc Detector] C:&#092;Program Files&#092;Creative&#092;ShareDLL&#092;CtNotify.exe
    O4 - HKLM&#092;..&#092;Run: [AudCtrl] RunDll32 AudCtrl.dll,RCMonitor
    O4 - HKLM&#092;..&#092;Run: [UpdReg] C:&#092;WINDOWS&#092;UpdReg.EXE
    O4 - HKLM&#092;..&#092;Run: [CTStartup] C:&#092;Program Files&#092;Creative&#092;Splash Screen&#092;CTEaxSpl.EXE /run
    O4 - HKLM&#092;..&#092;Run: [ezShieldProtector for Px] C:&#092;WINDOWS&#092;System32&#092;ezSP_Px.exe
    O4 - HKLM&#092;..&#092;Run: [NvCplDaemon] RUNDLL32.EXE C:&#092;WINDOWS&#092;System32&#092;NvCpl.dll,NvStartup
    O4 - HKLM&#092;..&#092;Run: [nwiz] nwiz.exe /install
    O4 - HKLM&#092;..&#092;Run: [PinnacleDriverCheck] C:&#092;WINDOWS&#092;System32&#092;PSDrvCheck.exe
    O4 - HKLM&#092;..&#092;Run: [TkBellExe] "C:&#092;Program Files&#092;K-Lite Codec Pack&#092;real&#092;Update_OB&#092;realsched.exe" -osboot
    O4 - HKCU&#092;..&#092;Run: [CTFMON.EXE] C:&#092;WINDOWS&#092;System32&#092;ctfmon.exe
    O4 - HKCU&#092;..&#092;Run: [SoniqueQuickStart] C:&#092;Program Files&#092;Sonique&#092;sqstart.exe -nostick
    O4 - HKCU&#092;..&#092;Run: [RemoteCenter] C:&#092;Program Files&#092;Creative&#092;SBExtigy&#092;RemoteCenter&#092;Rc&#092;RcMan.EXE
    O4 - HKCU&#092;..&#092;Run: [NvMediaCenter] RUNDLL32.EXE C:&#092;WINDOWS&#092;System32&#092;NVMCTRAY.DLL,NvTaskbarInit
    O4 - Startup: SpywareGuard.lnk = C:&#092;Program Files&#092;Internet Tools&#092;SpywareGuard&#092;sgmain.exe
    O4 - Global Startup: LightSurf.lnk = C:&#092;Program Files&#092;LightSurf&#092;Common&#092;IconMgr.exe
    O4 - Global Startup: Microsoft Office.lnk = C:&#092;Program Files&#092;Microsoft Office&#092;Office&#092;OSA9.EXE
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O8 - Extra context menu item: Download with GetRight - C:&#092;Program Files&#092;GetRight&#092;GRdownload.htm
    O8 - Extra context menu item: Open with GetRight Browser - C:&#092;Program Files&#092;GetRight&#092;GRbrowse.htm
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra &#39;Tools&#39; menuitem: Messenger (HKLM)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/patch/EARTPX.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7690.5254861111
    O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/SassCln.CAB
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/patch/MaxisSimCity4PatcherX.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

    Does that look ok?
    My Tracks:
    http://www.twotech.co.uk/dmc/Mkkxx-TheFall.mp3 (<span style='color:red'>3</span> plays in Taste&#33
    http://www.twotech.co.uk/dmc/Mkkxx-Untitled.mp3 (New track)

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •