PPRuNe Forums - View Single Post - Yet another hijackthis log...
View Single Post
Old 17th Nov 2004, 22:37
  #5 (permalink)  
Naples Air Center, Inc.
The Oracle
 
Join Date: Aug 2001
Location: Naples, Florida U.S.A.
Posts: 2,902
Likes: 0
Received 0 Likes on 0 Posts
Memetic,

Next time, when you run HJT, please shut down all the programs before running it, so we do not have to search though so many programs.

My guess is you were hit by:

BookedSpace

I took a quick look and these looked suspect:

C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe

C:\Program Files\NaviSearch\bin\nls.exe

C:\Program Files\BullsEye Network\bin\bargains.exe


Then these are ones you will want HJT to fix:

R3 - URLSearchHook: (no name) - {D273C035-12EB-D6AB-3B62-3244E4BEFAE4} - C:\WINDOWS\Ewdmcwkm.dll

O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-AB2D-8D32436313D9} - C:\WINDOWS\bsx5.dll

O2 - BHO: (no name) - {689B1528-F725-4AA8-F5DA-91711D3A7353} - C:\WINDOWS\Ewdmcwkm.dll

O2 - BHO: CExtension Object - {A85C4A1B-BD36-44E5-A70F-8EC347D9B24F} - C:\WINDOWS\bs3.dll

O2 - BHO: (no name) - {689B1528-F725-4AA8-F5DA-91711D3A7353} - C:\WINDOWS\Ewdmcwkm.dll

O2 - BHO: CExtension Object - {A85C4A1B-BD36-44E5-A70F-8EC347D9B24F} - C:\WINDOWS\bs3.dll

O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll

O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll

O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O3 - Toolbar: Search - {7806034E-68D6-FFDE-318F-789556D24A27} - C:\WINDOWS\Ewdmcwkm.dll

O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


There could be more, I did not get to go though everything.

Take Care,

Richard

P.S. If you like, you could also remove fastfind.exe from your Startup Directory. It has never worked right for M$.
Naples Air Center, Inc. is offline