Newbie dot Org HomePage
Visit one of our web buddies
Win min problem
sreekanth
sreeku_2002@yahoo.com
06/19/04
friends i have a win min problem whem shutting windows 2000.It always shows end task. i ran CWShredder.exe and
miniremoval_coolwebsearch_smartkiller.exe.home page was redirecting to some site .

i ran hijack this can u tell me what to delete from the folowing log file

Logfile of HijackThis v1.97.7
Scan saved at 2:37:37 AM, on 6/20/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINNT\System32\smss.exe
E:\WINNT\system32\winlogon.exe
E:\WINNT\system32\services.exe
E:\WINNT\system32\lsass.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\System32\msdtc.exe
E:\WINNT\System32\svchost.exe
E:\WINNT\System32\llssrv.exe
E:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
E:\Program Files\Norton Internet Security\NISUM.EXE
E:\WINNT\system32\regsvc.exe
E:\WINNT\system32\MSTask.exe
E:\WINNT\system32\stisvc.exe
E:\Program Files\Norton Internet Security\SymProxySvc.exe
E:\WINNT\System32\WBEM\WinMgmt.exe
E:\WINNT\System32\mspmspsv.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\system32\Dfssvc.exe
E:\WINNT\System32\inetsrv\inetinfo.exe
E:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
E:\Program Files\Norton Internet Security\NISSERV.EXE
E:\WINNT\System32\svchost.exe
E:\WINNT\System32\svchost.exe
E:\WINNT\Explorer.EXE
E:\winnt\dllhlp.exe
E:\Program Files\Norton Internet Security\ATRACK.EXE
c:\windows\scvhost.exe
E:\WINNT\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
E:\WINNT\System32\msiexec.exe
E:\WINNT\System32\MsiExec.exe
E:\WINNT\System32\MsiExec.exe
E:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlredis.exe
E:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\setupre.exe
E:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
E:\WINNT\System32\rundll32.exe
E:\Program Files\Norton Internet Security\IAMAPP.EXE
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Documents and Settings\Administrator\Desktop\HijackThis.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://E:\WINNT\System32/left.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://greatsearch.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://69.31.79.104/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://69.31.79.104/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://69.31.79.104/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://69.31.79.104/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.31.79.104/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://greatsearch.biz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://greatsearch.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://69.31.79.104/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://69.31.79.104/search.php
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - E:\WINNT\twaintec.dll (file missing)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\Adobe\Acrobat Reader 5\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {087173EF-9829-4F49-8340-A524177D3F60} - E:\WINNT\System32\inetp60.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] E:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] E:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [windows auto update] msblast.exe
O4 - HKLM\..\Run: [iamapp] E:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [jxfyjwg] rundll32 E:\WINNT\System32:jxfyjwg.dll,Init 1
O4 - HKLM\..\Run: [System Service] E:\WINNT\System32\msrexe.exe
O4 - HKLM\..\Run: [Upgrade Service] E:\WINNT\winupd.exe
O4 - HKLM\..\Run: [alchem] E:\WINNT\alchem.exe
O4 - HKLM\..\Run: [winupd] E:\WINNT\System32\winupd.exe
O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe E:\WINNT\System32\STLBCL~1.DLL,DllRunMain
O4 - HKLM\..\Run: [RunWindowsUpdate] E:\WINNT\uptodate.exe
O4 - HKLM\..\Run: [Rundll32_8] rundll32.exe E:\WINNT\System32\inetp60.dll,DllRunServer
O4 - HKLM\..\Run: [LVCOMS] E:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [RealTray] E:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKCU\..\Run: [Yahoo! Pager] E:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] E:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Irtr] E:\Documents and Settings\Administrator\Application Data\coer.exe
O4 - HKCU\..\Run: [Windows Deafult Configuration] E:\WINNT\svchost.exe
O4 - HKCU\..\Run: [IEengine] C:\Program Files\Internet Explorer\IEengine.exe
O4 - HKCU\..\Run: [cvchost] c:\windows\svchost.exe
O4 - HKCU\..\Run: [dllhelp] e:\winnt\dllhlp.exe
O4 - HKCU\..\Run: [Wandows Deafult Configuration] E:\WINNT\svchost.exe
O4 - HKLM\..\RunOnce: [*jxfyjwg] rundll32 E:\WINNT\System32:jxfyjwg.dll,Init 1
O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe E:\WINNT\System32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\"
O4 - Startup: Siebel QuickStart.lnk = C:\sea752\client\BIN\siebel.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = E:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .spop: E:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {11111111-1111-1111-1111-1123} - file://c:\Recycled\1.exe
O16 - DPF: {14325268-79E0-4D2A-89A4-FFFC6E22741E} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_3_EN.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2F2B9D0-96B9-4B25-B90C-636ECB207D18} - http://www.whenusearch.com/WUInstSEWC.cab
O16 - DPF: {E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} (MoneyTree Dialer) - http://xbscc1.mtree.com/mt/dialers/fc/UniDist.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F34363C-5F19-4E34-9C3D-269FB8F2C6FD}: NameServer = 202.54.12.162 203.197.12.42

ed

06/19/04
my goodness what a disaster
run online virus scans ALL of these and fix what they find
housecal (trend micro)
rav online
panda
bit defender
sygate trojan scan
download and install cwshredder run it and let it fix what it finds
Reboot to
safe mode navigate to
E:\winnt and delete dllhlp.exe
c:\windows and delete scvhost.exe
E:\WINNT\System32 and delete msiexec.exe--virus
E:\WINNT\System32 and delete MsiExec.exe
E:\WINNT\System32 delete MsiExec.exe
restart back to normal
run hjt and select these and click fix

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://E:\WINNT\System32/left.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://greatsearch.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://69.31.79.104/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://69.31.79.104/search.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://69.31.79.104/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://69.31.79.104/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://69.31.79.104/search.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://greatsearch.biz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://greatsearch.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://69.31.79.104/search.php
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://69.31.79.104/search.php
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - E:\WINNT\twaintec.dll (file missing)
O2 - BHO: (no name) - {087173EF-9829-4F49-8340-A524177D3F60} -
O4 - HKLM\..\Run: [windows auto update] msblast.exe---left by blaster virus
O4 - HKLM\..\Run: [jxfyjwg] rundll32 E:\WINNT\System32:jxfyjwg.dll,Init 1
O4 - HKLM\..\Run: [System Service] E:\WINNT\System32\msrexe.exe-left by icq worm
O4 - HKLM\..\Run: [Upgrade Service] E:\WINNT\winupd.exe -adult dialler
O4 - HKLM\..\Run: [alchem] E:\WINNT\alchem.exe
O4 - HKLM\..\Run: [winupd] E:\WINNT\System32\winupd.exe
O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe E:\WINNT\System32\STLBCL~1.DLL,DllRunMain
O4 - HKLM\..\Run: [Rundll32_8] rundll32.exe E:\WINNT\System32\inetp60.dll,DllRunServer
O4 - HKCU\..\Run: [Irtr] E:\Documents and Settings\Administrator\Application Data\coer.exe
O4 - HKCU\..\Run: [Windows Deafult Configuration] E:\WINNT\svchost.exe
O4 - HKCU\..\Run: [IEengine] C:\Program Files\Internet Explorer\IEengine.exe
O4 - HKCU\..\Run: [cvchost] c:\windows\svchost.exe
O4 - HKCU\..\Run: [dllhelp] e:\winnt\dllhlp.exe
O4 - HKCU\..\Run: [Wandows Deafult Configuration] E:\WINNT\svchost.exe
O4 - HKLM\..\RunOnce: [*jxfyjwg] rundll32 E:\WINNT\System32:jxfyjwg.dll,Init 1
O4 - HKLM\..\RunOnce: [wextract_cleanup0] rundll32.exe E:\WINNT\System32\advpack.dll,DelNodeRunDLL32 "E:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\"
O16 - DPF: {11111111-1111-1111-1111-1123} - file://c:\Recycled\1.exe
O16 - DPF: {E2F2B9D0-96B9-4B25-B90C-636ECB207D18} - http://www.whenusearch.com/WUInstSEWC.cab
O16 - DPF: {E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} (MoneyTree Dialer) - http://xbscc1.mtree.com/mt/dialers/fc/UniDist.CAB

Paige
cherenee_2000@yahoo.com
07/11/04
I ran the cwshredder and rebooted because of the missing image.dll error. I then downloaded and ran the hijackthis after seeing the missing winnt\system32\inetp60.dll error. What do I do now?

Logfile of HijackThis v1.97.7
Scan saved at 3:12:44 PM, on 7/11/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\WinTools\WToolsA.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Internet Explorer\Iesearch.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\WINNT\uptodate.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Tasks\tapidns.exe
C:\WINNT\rundll16.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Administrator.HOME-W7JA60KF3L\Application Data\lpsw.exe
C:\WINNT\system32\NDrv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Administrator.HOME-W7JA60KF3L\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50019
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50019
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50019
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINNT\twaintec.dll (file missing)
O2 - BHO: (no name) - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - (no file)
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0DDBB570-0396-44C9-986A-8F6F61A51C2F} - C:\WINNT\system32\msiefr40.dll
O2 - BHO: (no name) - {1B7D753B-1981-4bd2-91F3-6D055EE113A0} - C:\WINNT\system32\NDrv.dll
O2 - BHO: (no name) - {80672997-D58C-4190-9843-C6C61AF8FE97} - C:\WINNT\rundll16.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D34F08C5-4F18-477c-86CB-1A9BEECFE37B} - C:\Documents and Settings\Administrator.HOME-W7JA60KF3L\Application Data\winkm\winkm32.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [Iesearch.exe] C:\Program Files\Internet Explorer\Iesearch.exe
O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe C:\WINNT\system32\STLBCL~1.DLL,DllRunMain
O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINNT\uptodate.exe
O4 - HKLM\..\Run: [Rundll32_8] rundll32.exe C:\WINNT\system32\inetp60.dll,DllRunServer
O4 - HKLM\..\Run: [qtwlpxwmsrykp] C:\WINNT\system32\udsudn.exe
O4 - HKLM\..\Run: [SysUpd] C:\Documents and Settings\Kween2006\Application Data\sysupd.exe
O4 - HKLM\..\Run: [antiav] C:\WINNT\Tasks\antiav.exe
O4 - HKLM\..\Run: [mfcanti] C:\WINNT\system\mfcanti.exe
O4 - HKLM\..\Run: [Rundll32_7] rundll32.exe C:\WINNT\system32\msiefr40.dll,DllRunServer
O4 - HKLM\..\Run: [tapidns] C:\WINNT\Tasks\tapidns.exe
O4 - HKLM\..\Run: [Rundll16] C:\WINNT\rundll16.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Rrcu] C:\Documents and Settings\Administrator.HOME-W7JA60KF3L\Application Data\lpsw.exe
O4 - HKCU\..\Run: [Mail Scanner] C:\Program Files\Astonsoft\Spam OFF\SpamOff.exe
O4 - HKCU\..\Run: [sex] C:\WINNT\system32\sexxx.exe
O4 - HKCU\..\Run: [NDrv] C:\WINNT\system32\NDrv.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} - http://download.websearch.com/Dnl/T_50019/QDow.cab
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/LOT64106/thin.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/116e21d5febe7e7f3420/netzip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8522F9B3-0000-0000-0000-00} - http://38.144.58.87/sex/xxxmovies.cab
O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} - http://38.144.58.87/sex/xxxmovies.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37954.802662037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebiof5_3_12_0.cab

Anti-Virus: AVG AntiVirus
Browser: IE
OS: Win2000


© Copyright 1998-2004 Newbie dot Org -- All rights reserved --



This site maintained by Galaxy Website Design


--|--