Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

PC crash tonight

Thread Tools
 
Search this Thread
 
Old 29th Sep 2004, 21:07
  #1 (permalink)  
Thread Starter
 
Join Date: Apr 2004
Location: The 245 bulkhead
Posts: 62
Likes: 0
Received 0 Likes on 0 Posts
PC crash tonight

Hi guys, hope you can help on this one........
Was visiting a flight sim website tonight and clicking on one of the icons on the site led to lots of pop up boxes and a shut down by the pc. Upon trying to restart the pc would get to the XP screeen where I click on my profile and enter the administrator password, but after entering said password it will restart shortly after saying 'loadind personal settings'. I've tried a repair and reload from my OEM disc but same same. With the repair though it says I've entered the wrong administrator password, which I haven't (after 6 attempts I'm sure). I'm now logged in on my flatmates profile that seems to work fine. I've scanned for adware using McAfee internet security suite, but nothing. The funny thing is I'm getting all sorts of pop ups when logged in, mostly about 'your pc is not secure' and dixons has somehow made itself my home page? Even my pprune password had to be reset before I could log in. I've run the hijackthis program and results are below. Can anyone help, please? Please tolerate my removal of the wiggly red faces when posting the log file. Thanks. LPS

Logfile of HijackThis v1.98.2
Scan saved at 21:42:27, on 29/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C: \WINDOWS\system32\rundll32.exe
C: \WINDOWS\Explorer.EXE
C: \Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C: \WINDOWS\Dit.exe
C: \WINDOWS\DitExp.exe
C: \WINDOWS\mHotkey.exe
C: \WINDOWS\System32\RunDll32.exe
C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
C: \Program Files\Logitech\Video\LogiTray.exe
C: \Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C: \PROGRA~1\mcafee.com\agent\mcagent.exe
C: \Program Files\Logitech\MouseWare\system\em_exec.exe
C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C: \PROGRA~1\mcafee.com\vso\mcvsshld.exe
c: \progra~1\mcafee.com\vso\mcvsescn.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C: \Program Files\iTunes\iTunesHelper.exe
C: \Program Files\QuickTime\qttask.exe
C: \PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\knlwrap.exe
C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
C: \PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C: \WINDOWS\System32\ctfmon.exe
C: \WINDOWS\System32\LVComS.exe
C: \Program Files\Yahoo!\Messenger\ypager.exe
C: \Program Files\Logitech\Video\LowLight.exe
C: \Program Files\BTopenworld NetHelp\bin\mpbtn.exe
c: \progra~1\mcafee.com\vso\mcvsftsn.exe
C: \Program Files\Messenger\msmsgs.exe
C: \PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe
C: \PROGRA~1\Yahoo!\browser\ycommon.exe
C: \Program Files\Yahoo!\browser\ybrwicon.exe
C: \PROGRA~1\McAfee.com\Agent\mcupdui.exe
C: \Program Files\Internet Explorer\IEXPLORE.EXE
C: \Documents and Settings\Julia\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //uk.red.clientapps.yahoo.com/..._side.html</a>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/c...yahoo.com/</a>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http: //www.dixons.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http: //uk.red.clientapps.yahoo.com/..._side.html</a>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.zestyfind.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http: //www.dixons.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c: \progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c: \program files\google\googletoolbar1.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C: \Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C: \WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCMService] "C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C: \Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C: \Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C: \Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C: \Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C: \Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c: \PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C: \PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c: \PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [VirusScan Online] "c: \PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C: \PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] C: \Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C: \Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] CWINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C: \WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C: \WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CleanUp] C: \PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon
O4 - HKLM\..\Run: [DXDllRegExe] C: \WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C: \WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C: \Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Logitech Desktop Messenger.lnk = C: \Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C: \Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetHelp.lnk = C: \Program Files\BTopenworld NetHelp\bin\matcli.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: BT Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra 'Tools' menuitem: BT &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \WINDOWS\web\related.htm
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C: \Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C: \Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C: \Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.zestyfind.com/app/DS4/DS4.cab

In case it helps a lot of pop ups are coming from this site:

http://e.rnll.com/a/a174-amed-ron

Thanks once again.
LPS500 is offline  
Old 29th Sep 2004, 23:29
  #2 (permalink)  
 
Join Date: Jan 2004
Location: Bracknell UK
Posts: 357
Likes: 0
Received 0 Likes on 0 Posts
Hi LP500,

The first thing you need to do, is to place Hijack This in it’s own folder (e.g. C:\HJT\….) so it can generate backup files to the same folder; needed should an entry be accidentally deleted. Then please run a new HJT! Scan, and check to fix the following entries, being sure to double check that you haven't missed any. Next, close all browser windows and click the Fix checked button…

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.zestyfind.com/

O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.zestyfind.com/app/DS4/DS4.cab


Then boot into safe mode, (see here for info if needed) and delete the entire contents of the C:\Windows\Temp folder, but not the folder itself.

Then please boot back into normal mode and download AdAware SE from here.

First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files.

Next, we need to configure Ad-aware for a full scan.

Click on the Gear icon (second from the left) to access the preferences/settings window

1. In the General window make sure the following are selected:
· Automatically save log-file
· Automatically quarantine objects prior to removal
· Safe Mode (always request confirmation)

2. Click on the Scanning button on the left and select :
· Scan Within Archives
· Scan Active Processes
· Scan Registry
· Deep Scan Registry
· Scan my IE favorites for banned URL’s
· Scan my Hosts file

· Under Click here to select drives + folders, choose:
· All of your hard drives | Proceed

3. Click on the Advanced button on the left and select:
· Include additional process information
· Include additional file information
· Include environment information

4. Click the Tweak button and select:
· Under the Scanning Engine:
· Unload recognized processes & modules during scan
· Include additional Ad-aware settings in logfile
· Under the Cleaning Engine:
· Let Windows remove files in use at next reboot

5. Click on Proceed to save the settings.

6. Click Start and on the next screen choose:
· Use Custom Scanning Options

7. Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.

When finished, mark everything for removal and get rid of it. (Right-click the window and choose Select All from the drop down menu and click Next).

Next, please reboot again and download Spybot - Search & Destroy 1.3 from here: if you haven't already got the program.

Click on Updates | Download Updates, and follow the prompts.

Next, close all Internet Explorer windows, and click Check for Problems. Once the scan is complete, have SpyBot remove all it finds marked in RED.

Next, please reboot and post a new log for a final once over.

As far as Dixons now being your home page, you can change it back to what ever page you want. It's probably the default setting from your setup disc.. I'm guessing that's where the PC came from??

Cheers

Liam
E-Liam is offline  
Old 2nd Oct 2004, 10:41
  #3 (permalink)  
Thread Starter
 
Join Date: Apr 2004
Location: The 245 bulkhead
Posts: 62
Likes: 0
Received 0 Likes on 0 Posts
Thanks very much for your help Liam. The pc is up and running again just fine. The ad-aware found just over 100 problems and spybot about 20, and there I was thinking things were fine using McAfee Internet security suite!

Thanks once again for your help. I've done another hjt scan and posted the log.

Cheers, LPS.

Logfile of HijackThis v1.98.2
Scan saved at 11:33:21, on 02/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C: \WINDOWS\System32\smss.exe
C: \WINDOWS\system32\winlogon.exe
C: \WINDOWS\system32\services.exe
C: \WINDOWS\system32\lsass.exe
C: \WINDOWS\system32\svchost.exe
C: \WINDOWS\System32\svchost.exe
C: \WINDOWS\system32\spoolsv.exe
C: \Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C: \Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
c: \PROGRA~1\mcafee.com\vso\mcvsrte.exe
C: \Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C: \PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C: \WINDOWS\System32\svchost.exe
c: \PROGRA~1\mcafee.com\vso\mcshield.exe
C: \PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C: \WINDOWS\Explorer.EXE
C: \Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C: \WINDOWS\Dit.exe
C: \WINDOWS\mHotkey.exe
C: \WINDOWS\System32\RunDll32.exe
C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe
C: \Program Files\Logitech\Video\LogiTray.exe
C: \PROGRA~1\mcafee.com\agent\mcagent.exe
C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C: \WINDOWS\DitExp.exe
C: \PROGRA~1\mcafee.com\vso\mcvsshld.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C: \Program Files\iTunes\iTunesHelper.exe
C: \Program Files\QuickTime\qttask.exe
C: \Program Files\Logitech\MouseWare\system\em_exec.exe
C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
C: \Program Files\iPod\bin\iPodService.exe
C: \WINDOWS\System32\ctfmon.exe
c: \progra~1\mcafee.com\vso\mcvsescn.exe
C: \Program Files\Star Alliance Timetable\StarUpdater.exe
C: \WINDOWS\System32\LVComS.exe
C: \Program Files\BTopenworld NetHelp\bin\mpbtn.exe
C: \PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C: \Program Files\Logitech\Video\LowLight.exe
C: \PROGRA~1\Yahoo!\browser\ycommon.exe
c: \progra~1\mcafee.com\vso\mcvsftsn.exe
C: \Program Files\Yahoo!\browser\ybrwicon.exe
C: \Program Files\Messenger\msmsgs.exe
C: \PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C: \Program Files\Yahoo!\browser\ybrowser.exe
C: \HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/c..._side.html</a>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.2.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C: \Program Files\Yahoo!\Messenger\ycomp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C: \PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c: \progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c: \program files\google\googletoolbar1.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C: \Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C: \Program Files\Yahoo!\Messenger\ycomp.dll
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C: \WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCMService] "C: \Program Files\Medion Home Cinema XL II\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C: \Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C: \Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C: \Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c: \PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C: \PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C: \PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c: \PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C: \Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [VirusScan Online] "c: \PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C: \PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C: \PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] C: \Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C: \Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C: \WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C: \WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C: \WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C: \Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [EPSON Stylus C66 Series] C: \WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /M "Stylus C66" /EF "HKCU"
O4 - Startup: Registration-InstantCopy.lnk = C: \Program Files\Pinnacle\Shared Files\InstantCDDVD\Pixie\RegTool.exe
O4 - Startup: StarUpdater.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C: \Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C: \Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NetHelp.lnk = C: \Program Files\BTopenworld NetHelp\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://C: \Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C: \Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://C: \Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C: \Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C: \PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C: \Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C: \Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C: \Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C: \Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C: \Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: BT Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra 'Tools' menuitem: BT &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C: \Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C: \Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C: \Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C: \Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C: \Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab
LPS500 is offline  
Old 2nd Oct 2004, 12:07
  #4 (permalink)  
 
Join Date: Jan 2004
Location: Bracknell UK
Posts: 357
Likes: 0
Received 0 Likes on 0 Posts
Hi LPS,

All clean now..

Just a little houseclaering, please fix the following entry. It's just a broken shortcut, and nothing sinister..

O4 - Startup: StarUpdater.exe.lnk = ?

Cheers

Liam
E-Liam is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.