Newbie dot Org HomePage
Visit one of our web buddies
homepage reset to qwsxs.dll and unwanted popups
John N

08/05/04
Help, my homepage is getting reset to res://qwsxs.dll/index.html#37049 and I am getting unwanted popups. I've removed the "qwsxs" entries from hjt, but it doesn't resolve it. Here is the hjt log. My pc is a Sony PCG-C1VN laptop.

Logfile of HijackThis v1.97.7
Scan saved at 1:56:02 PM, on 8/5/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\NTRR32.EXE
C:\WINDOWS\SYSTEM\NTWH32.EXE
C:\WINDOWS\APIII32.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\SUPPORT.COM\CLIENT\BIN\TGCMD.EXE
C:\WINDOWS\SYSTEM\DAEMON.EXE
C:\PROGRAM FILES\SONY\JOG DIAL UTILITY\JOGSERV2.EXE
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SONY\SMART CAPTURE\SSCRDY.EXE
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\D3BH32.EXE
C:\WINDOWS\APIII32.EXE
C:\AMERICA ONLINE 5.0\WAOL.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
C:\WINDOWS\SYSTEM\NTWH32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\APPDC32.EXE
C:\WINDOWS\APPWZ32.EXE
C:\WINDOWS\SYSTEM\NTRR32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\APPDC32.EXE
C:\WINDOWS\WINNO.EXE
C:\WINDOWS\APPDC32.EXE
C:\WINDOWS\IPUF32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\WINNO.EXE
C:\WINDOWS\SYSTEM\APPFD.EXE
C:\WINDOWS\IPUF32.EXE
C:\WINDOWS\WINNO.EXE
C:\WINDOWS\SYSTEM\APPFD.EXE
C:\WINDOWS\APPDC32.EXE
C:\WINDOWS\WINNO.EXE
C:\WINDOWS\SYSTEM\NTWH32.EXE
C:\MY DOCUMENTS\DOWNLOADS FIXES\HijackTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\qwsxs.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://qwsxs.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://qwsxs.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\qwsxs.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://qwsxs.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\qwsxs.dll/sp.html#37049
O2 - BHO: (no name) - {D6CBD3AB-30EF-1CBB-4E37-94C9041EB792} - C:\WINDOWS\MFCXH32.DLL
O2 - BHO: (no name) - {708BF05B-B350-F0FF-A9C3-C17875E896F6} - C:\WINDOWS\NETOD.DLL (file missing)
O2 - BHO: (no name) - {717A1A49-72D7-C9BA-1F99-F5172B3EA227} - C:\WINDOWS\NTXX.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\Client\bin\tgcmd.exe" /server /nosystray
O4 - HKLM\..\Run: [TrackPointSrv] daemon.exe
O4 - HKLM\..\Run: [JOGSERV2.EXE] C:\Program Files\Sony\Jog Dial Utility\JogServ2.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSEcomR.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM\..\RunServices: [NTWH32.EXE] C:\WINDOWS\SYSTEM\NTWH32.EXE
O4 - HKLM\..\RunServices: [NTRR32.EXE] C:\WINDOWS\SYSTEM\NTRR32.EXE
O4 - HKLM\..\RunServices: [APIII32.EXE] C:\WINDOWS\APIII32.EXE
O4 - HKLM\..\RunServices: [APPDC32.EXE] C:\WINDOWS\APPDC32.EXE
O4 - HKLM\..\RunServices: [APPWZ32.EXE] C:\WINDOWS\APPWZ32.EXE
O4 - HKLM\..\RunServices: [WINNO.EXE] C:\WINDOWS\WINNO.EXE
O4 - HKLM\..\RunServices: [IPUF32.EXE] C:\WINDOWS\IPUF32.EXE
O4 - HKLM\..\RunServices: [APPFD.EXE] C:\WINDOWS\SYSTEM\APPFD.EXE
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Global Startup: Smart Capture Ready.lnk = C:\Program Files\Sony\Smart Capture\SSCrdy.exe
O4 - Global Startup: PowerPanel.lnk = C:\Program Files\PowerPanel\Program\PcfMgr.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople

Anti-SpyWare: Spysweeper
Anti-Virus: MacAfree
Browser: IE
OS: WinME


© Copyright 1998-2004 Newbie dot Org -- All rights reserved --



This site maintained by Galaxy Website Design


--|--