Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows VistaWindows XPWindows MeWindows 98Windows 95Virtual PCInternet ExplorerOutlook ExpressWindows MediaSecurity
Related Topics
MS Server ProductsMS OfficePC HardwareMore Topics ...

Windows Forum / Windows 98 / Performance / October 2003

Tip: Looking for answers? Try searching our database.

Swen - Memory - msconfig

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Leta - 28 Oct 2003 23:32 GMT
Help Anyone--

Syst Specs: Win98, 40Gb HDD, 384 Mb RAM(128k & 256k PNY
sticks)

1. SWEN-
Yep, I got the Swen bug somehow.  Ran the fix and now able
to get to msconfig to view for troubleshooting.  I also
see where I need to update virus definitions....!

2. MEMORY-
Now, for the memory situation -- the system seems to hang
when clicking on anything, even on webpages and internal
s/w applications alike.  

Removed the 256k PNY stick but didnt seem to do anything
different.  So, interchanged each stick and rebooted to
see if any noticeable change.  NOPE.  Every time I click
on anything, the response is very slow!

More noticeable when on internet and within applications
at same time.

Did notice that dust all over processor, fan assy, and
power supply, so cleaned it all off.  Noticed that the
processor fan "choked" a little bit after cleaning off
dust.  Thought the bearings were starting to go out, but
has been running fine. Exhaust fan also dusty, so cleaned
the ENTIRE unit.  No change....

Also noticed that the 128k stick was PC100 and the 256k
was PC133.  Talked with the manufacturer before I had them
send me the stick last year.  They said that they were
compatible and would not encounter any clocking
difficulties.  Its been working fine for the past 12-14
months.  Is this common with PNY memory?

Problem noticeable every time I click on anything. Cursor
shows "working hourglass," then locks until it decides to
catch up with itself(almost like a buffering).  This may
take anywhere from 10 seconds to a couple of minutes--even
longer.  Primarily, there is NO immediate response from
the system when I click on anything.

Please let me know if you have other solutions for me on
this situation. Totally stumped.

3. MSCONFIG-
I noticed that there were numerous line items in the
startup tab.  Some duplicates, others that are simply
trash and have nothing to do with anything on the
computer. Searched the computer for these .exe files and
they are nowhere in the computer.  How do I remove this
trash.  I think I remember that it is more effective to
remove the startup option from the application, rather
than from msconfig.  But, if it isnt there....how do I
remove it from this tray.  How do I get inside the tray to
see what is there?  Please help.

Thanks,
Leta
Robert Duffy - 29 Oct 2003 01:20 GMT
http://users.westelcom.com/rogersr/default.htm
Help with Windows
Clean Up Your Startup Group
Duplicate Entries in Msconfig

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SWEN.A
Manual removal Instructions

| Help Anyone--
|
[quoted text clipped - 57 lines]
| Thanks,
| Leta
Leta - 29 Oct 2003 01:41 GMT
1.Cleaned up Swen,
2.Cleaned up Startup Group...somewhat.Still cant remove
 some items.
3.What about memory issues? System still slow response
 times.

Help!!

>-----Original Message-----
>http://users.westelcom.com/rogersr/default.htm
[quoted text clipped - 68 lines]
>
>.
glee - 29 Oct 2003 06:04 GMT
Re-enable anything you have un-checked in Msconfig>Startup tab, and click OK, reboot, prior to running Hijack This, so that all items will be visible to the scan..

Download and run Hijack This, but do not remove anything with it yet:
http://www.spywareinfo.com/downloads.php

Follow the instructions at this Tutorial:
http://www.tomcoyote.org/hjt/
to save the log files and paste them into a reply to this thread....please don't start another thread.

Clean up your startup group:
www.westelcom.com/users/rogersr/clean.htm

Startup Programs Loading:
http://aumha.org/a/loads.htm

Start-ups:
http://www.pacs-portal.co.uk/startup_content.htm

Task List Programs:
http://www.answersthatwork.com/Tasklist_pages/tasklist.htm

StartUps:
http://www2.whidbey.com/djdenham/Uncheck.htm

StartUp List:
http://www.3feetunder.com/krick/startup/list.html

Signature

Glen Ventura, MS MVP W95/98 Systems

> 1.Cleaned up Swen,
> 2.Cleaned up Startup Group...somewhat.Still cant remove
[quoted text clipped - 88 lines]
> >
> >.
Leta - 29 Oct 2003 22:20 GMT
Glen- Log contents for your review below:
==================================================

Logfile of HijackThis v1.97.3
Scan saved at 2:58:43 PM, on 10/29/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE
EDITION\PSFREE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\WINZIP81\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://super-spider.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Bar = http://super-spider.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page = http://super-spider.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = http://super-
spider.com/main/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Bar = +s
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = +s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window
Title = Microsoft Internet Explorer provided by AT&T
WorldNet Service
R3 - Default URLSearchHook is missing
O1 - Hosts: auto.search.msn.com
O1 - Hosts: 66.250.171.136 auto.search.msn.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0
\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-
82F2F98635CB} - C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-
170DE4475CCA} - C:\PROGRAM
FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-
072E-44cf-8957-5838F569A31D} - C:\PROGRAM
FILES\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-
170DE4475CCA} - C:\PROGRAM
FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL
O4 - HKLM\..\Run: [ScanRegistry]
C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6
\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [StillImageMonitor]
C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1
\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM
FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -
cnetwait.odl
O4 - Startup: Office Startup.lnk = C:\Program
Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program
Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program
Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Get It With Kontiki -
res://C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL/201
O8 - Extra context menu item: &Add animation to
IncrediMail Style Box - C:\PROGRA~1\INCRED~1
\bin\WebMenuImg.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Net2Phone (HKLM)
O9 - Extra 'Tools' menuitem: Net2Phone (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Dictionary (HKLM)
O9 - Extra 'Tools' menuitem: Dictionary (HKLM)
O9 - Extra button: Netnews (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1
\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet
Explorer\Plugins\NPUPano.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swf
lash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE}
(Microsoft Office Tools on the Web Control) -
http://officeupdate.microsoft.com/TemplateGallery/downloads
/outc.cab
O16 - DPF: {0D6451B3-FDDA-11D3-BFEC-00D0B725EB0B} (Yahoo!
Vision) - http://download.yahoo.com/dl/fv/yv.cab
O16 - DPF: {53A1630A-DB38-4316-B18F-911719E1F66E} (MSN
Money Ticker) -
http://fdl.msn.com/public/investor/v11/ticker.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68}
(InstallShield International Setup Player) -
http://www.installengine.com/engine/isetup.cab
O16 - DPF: {7160FB1B-3DE0-4C42-81F0-41B4269990B0} (MSN
Money Ticker) -
http://fdl.msn.com/public/investor/v12/ticker.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
(PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC
Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV
Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CA
B?37898.742025463
O16 - DPF: PlaceWare Console: PWS-CC2K-4-2-0-0-A-m7t8o4 -
http://www27.placeware.com/etc/pwf/test/lib/cc-full.cab
O16 - DPF: {1000026A-8230-4DD4-BE4F-6889D1E74167} -
http://207.246.124.105/cabs/ROOSTTD3001/TPS108.cab
O16 - DPF: {11111111-1111-1111-1111-111111111111} -
http://207.246.124.105/cabs/ROOSTER3001/TPS108.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE}
(Symantec RuFSI Registry Information Class) -
http://security.symantec.com/SSC/SharedContent/common/bin/c
absa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/SSC/SharedContent/vc/bin/AvSni
ff.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web
Products Installer Start) -
http://imgfarm.com/images/nocache/funwebproducts/SmileyCent
ralInitialSetup1.0.0.5.cab

End of log file
============================================
PS-I know what most of this is, but there appears to be
some things like super-spider.com---have no idea.  Let me
know what you think.
=============================================

>-----Original Message-----
>-----Original Message-----
>Re-enable anything you have un-checked in Msconfig>Startup tab, and click OK, reboot, prior to
running Hijack This, so that all items will be visible to
the scan..

>Download and run Hijack This, but do not remove anything with it yet:
>http://www.spywareinfo.com/downloads.php
[quoted text clipped - 115 lines]
>
>.
glee - 30 Oct 2003 04:24 GMT
Uh-oh!  super-spider.com AND MyWebSearch.....not good!
Search page hijack/ trojan, CWS, is related to coolwebsearch.
Also, 'Fun Web Products Easy Installer' is part of MyWebSearch.
Follow the removal instructions for MyWebSearch and Fun Web Products here:
http://www.doxdesk.com/parasite/MySearch.html

Then read here, and download CWShredder, the removal tool, and run it, post haste!

http://www.spywareinfo.com/articles/cws/

http://doxdesk.com/parasite/CoolWebSearch.html

http://www.spywareinfo.com/~merijn/cwschronicles.html

Use CWShredder, the removal tool:
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
or
http://216.180.252.218/~spywareinfo.com/downloads/tools/cwshredder.zip

After you have run CWShredder, and rebooted, run Hijack This again, and post the log files here again.

I suggest you also post them at the Spywareinfo forum also, where the experts on these baddies hang out:

Go to: http://www.spywareinfo.com/forums/

Sign in, go to the "Spyware and Hijackware Removal" section.
Press "New Topic", copy and paste hijackthis.log into your new message.

(from http://mvps.org/winhelp2002/unwanted.htm)

Signature

Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm

> Glen- Log contents for your review below:
> =================================================>
[quoted text clipped - 311 lines]
> >
> >.
Leta - 30 Oct 2003 21:01 GMT
Glen- lost my cable connection and lost everything.  Ran
Hijackthis and CWShredder.  Looked on forum and it didnt
post.  Let me know what you think.  Also, will send this
to Spywareinfo forum.

I am resending the new logfile from Hijackthis:

Logfile of HijackThis v1.97.3
Scan saved at 11:20:08 AM, on 10/30/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE
EDITION\PSFREE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINZIP81\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Bar = +s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window
Title = Microsoft Internet Explorer provided by AT&T
WorldNet Service
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0
\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-
82F2F98635CB} - C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry]
C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6
\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM
FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -
cnetwait.odl
O4 - Startup: Office Startup.lnk = C:\Program
Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program
Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Event Reminder.lnk = C:\pmw\PMREMIND.EXE
O8 - Extra context menu item: Get It With Kontiki -
res://C:\PROGRAM FILES\KONTIKI\BIN\BH304181.DLL/201
O8 - Extra context menu item: &Add animation to
IncrediMail Style Box - C:\PROGRA~1\INCRED~1
\bin\WebMenuImg.htm
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Net2Phone (HKLM)
O9 - Extra 'Tools' menuitem: Net2Phone (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Dictionary (HKLM)
O9 - Extra 'Tools' menuitem: Dictionary (HKLM)
O9 - Extra button: Netnews (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1
\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet
Explorer\Plugins\NPUPano.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swf
lash.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE}
(Microsoft Office Tools on the Web Control) -
http://officeupdate.microsoft.com/TemplateGallery/downloads
/outc.cab
O16 - DPF: {0D6451B3-FDDA-11D3-BFEC-00D0B725EB0B} (Yahoo!
Vision) - http://download.yahoo.com/dl/fv/yv.cab
O16 - DPF: {53A1630A-DB38-4316-B18F-911719E1F66E} (MSN
Money Ticker) -
http://fdl.msn.com/public/investor/v11/ticker.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68}
(InstallShield International Setup Player) -
http://www.installengine.com/engine/isetup.cab
O16 - DPF: {7160FB1B-3DE0-4C42-81F0-41B4269990B0} (MSN
Money Ticker) -
http://fdl.msn.com/public/investor/v12/ticker.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
(PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC
Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV
Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CA
B?37898.742025463
O16 - DPF: PlaceWare Console: PWS-CC2K-4-2-0-0-A-m7t8o4 -
http://www27.placeware.com/etc/pwf/test/lib/cc-full.cab
O16 - DPF: {1000026A-8230-4DD4-BE4F-6889D1E74167} -
http://207.246.124.105/cabs/ROOSTTD3001/TPS108.cab
O16 - DPF: {11111111-1111-1111-1111-111111111111} -
http://207.246.124.105/cabs/ROOSTER3001/TPS108.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE}
(Symantec RuFSI Registry Information Class) -
http://security.symantec.com/SSC/SharedContent/common/bin/c
absa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/SSC/SharedContent/vc/bin/AvSni
ff.cab

-----------------end of file

>-----Original Message-----
>Uh-oh!  super-spider.com AND MyWebSearch.....not good!
[quoted text clipped - 57 lines]
>> http://super-spider.com/main/sp.php
>> R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search
>> Bar = http://super-spider.com/main/sp.php
>> R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search
>> Page = http://super-spider.com/main/sp.php
>> R1 - HKCU\Software\Microsoft\Internet
[quoted text clipped - 7 lines]
>> Explorer\Search,SearchAssistant = +s
>> R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window
>> Title = Microsoft Internet Explorer provided by AT&T
>> WorldNet Service
[quoted text clipped - 60 lines]
>> O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
>> (Shockwave Flash Object) -

http://download.macromedia.com/pub/shockwave/cabs/flash/swf
>> lash.cab
>> O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE}
>> (Microsoft Office Tools on the Web Control) -

http://officeupdate.microsoft.com/TemplateGallery/downloads
>> /outc.cab
>> O16 - DPF: {0D6451B3-FDDA-11D3-BFEC-00D0B725EB0B} (Yahoo!
[quoted text clipped - 17 lines]
>> O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
>> Class) -

http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CA
>> B?37898.742025463
>> O16 - DPF: PlaceWare Console: PWS-CC2K-4-2-0-0-A-m7t8o4 -
[quoted text clipped - 5 lines]
>> O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE}
>> (Symantec RuFSI Registry Information Class) -

http://security.symantec.com/SSC/SharedContent/common/bin/c
>> absa.cab
>> O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
>> (Symantec AntiVirus scanner) -

http://security.symantec.com/SSC/SharedContent/vc/bin/AvSni
>> ff.cab
>> O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web
>> Products Installer Start) -

http://imgfarm.com/images/nocache/funwebproducts/SmileyCent
>> ralInitialSetup1.0.0.5.cab
>>
[quoted text clipped - 164 lines]
>
>.
glee - 31 Oct 2003 05:03 GMT
More spyware....Transponder:
> O16 - DPF: {1000026A-8230-4DD4-BE4F-6889D1E74167} -
> http://207.246.124.105/cabs/ROOSTTD3001/TPS108.cab
> O16 - DPF: {11111111-1111-1111-1111-111111111111} -
> http://207.246.124.105/cabs/ROOSTER3001/TPS108.cab

Read here:
http://www.doxdesk.com/parasite/Transponder.html
and
http://www.cexx.org/vx2.htm

Install Ad-Aware 6 free edition:
http://www.lavasoftusa.com/support/download/
Then start Ad-Aware, click the 'Check for updates' link in the progranm and install updates.
Scan the system with Ad-Aware, and remove what it finds.
Reboot.

Post back with another Hijack This log after the reboot, and report whether the system is operating correctly.
Signature

Glen Ventura, MS MVP W95/98 Systems
http://dts-l.org/goodpost.htm

> Glen- lost my cable connection and lost everything.  Ran
> Hijackthis and CWShredder.  Looked on forum and it didnt
[quoted text clipped - 527 lines]
> >
> >.
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.