| | |
Bridge.dll
![]() |
•
•
Join Date: May 2004
Posts: 6
Reputation:
Solved Threads: 0
HI THERE
I also when I boot up my computer, a RUNDLL window pops up stating "error loading "C:\WINDOWS\SYSTEM\BRIDGE.DLL" the system cannot find the file specified.
THIS IS MY LOG, please help meeeeeeeeeeeeeeeee!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Symantec_Client_Security\Symantec AntiVirus2\DefWatch.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Symantec_Client_Security\Symantec AntiVirus2\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
C:\ARCHIV~1\SYMANT~1\SYMANT~1\vptray.exe
C:\winnt\msbb.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\ARCHIV~1\Grisoft\AVG6\AVGCC32.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgw.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\ARCHIV~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos
F0 - system.ini: Shell=
F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [vptray] C:\ARCHIV~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [wzmhuryf] C:\WINNT\wzmhuryf.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.c...8111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/...ash/swflash.cab
THANK YOUUUUUUUUUUUUUUUUUUUUUUUUUU
:cry:
I also when I boot up my computer, a RUNDLL window pops up stating "error loading "C:\WINDOWS\SYSTEM\BRIDGE.DLL" the system cannot find the file specified.
THIS IS MY LOG, please help meeeeeeeeeeeeeeeee!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Symantec_Client_Security\Symantec AntiVirus2\DefWatch.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Symantec_Client_Security\Symantec AntiVirus2\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
C:\ARCHIV~1\SYMANT~1\SYMANT~1\vptray.exe
C:\winnt\msbb.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\ARCHIV~1\Grisoft\AVG6\AVGCC32.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgw.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\ARCHIV~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos
F0 - system.ini: Shell=
F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [vptray] C:\ARCHIV~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [wzmhuryf] C:\WINNT\wzmhuryf.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.c...8111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/...ash/swflash.cab
THANK YOUUUUUUUUUUUUUUUUUUUUUUUUUU
:cry:
guata,
You've now posted this question in no less that 3 different threads as far as I can tell. Please read the "Forum rules when posting" Announcement at the top of each forum to familiarize yourself them, especially these:
"Do not flood the forum
Do not flood the forum posting the same question in multiple forums, or multiple ways. All that happens is it gets confusing. It's a lot easier for everyone to get the answers they need if everything is kept in one place."
and:
"Post in the correct place
There are more than enough forums here for everyone to find somewhere suitable to post their computer support related questions. Please take the extra minute to make sure you are correctly posting in the correct place. Every question or new thought should have its own thread. Replies to a previous post should be thread replies to that particular thread. Do not piggyback threads by posting your question as a reply to another question. Any threads in an unsuitable forum will be moved to another at the administrator's/moderator's discretion."
Please keep this question in this thread form now on; I'm deleting your duplicate posts in the other threads.
Thanks for understanding.
You've now posted this question in no less that 3 different threads as far as I can tell. Please read the "Forum rules when posting" Announcement at the top of each forum to familiarize yourself them, especially these:
"Do not flood the forum
Do not flood the forum posting the same question in multiple forums, or multiple ways. All that happens is it gets confusing. It's a lot easier for everyone to get the answers they need if everything is kept in one place."
and:
"Post in the correct place
There are more than enough forums here for everyone to find somewhere suitable to post their computer support related questions. Please take the extra minute to make sure you are correctly posting in the correct place. Every question or new thought should have its own thread. Replies to a previous post should be thread replies to that particular thread. Do not piggyback threads by posting your question as a reply to another question. Any threads in an unsuitable forum will be moved to another at the administrator's/moderator's discretion."
Please keep this question in this thread form now on; I'm deleting your duplicate posts in the other threads.
Thanks for understanding.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
- Ancient Aborigine blessing
Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.
However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos
F0 - system.ini: Shell=
F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [wzmhuryf] C:\WINNT\wzmhuryf.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe
Reboot into safe mode following the instructions here & navigate to & delete
C:\WINNT\wzmhuryf.exe< file
C:\WINNT\alchem.exe< file
C:\winnt\msbb.exe< file
Reboot normally after doing the above then post a fresh log plz.
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3....rchPageHome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vênculos
F0 - system.ini: Shell=
F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINNT\Downloaded Program Files\bridge.dll",Load
O4 - HKLM\..\Run: [wzmhuryf] C:\WINNT\wzmhuryf.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe
Reboot into safe mode following the instructions here & navigate to & delete
C:\WINNT\wzmhuryf.exe< file
C:\WINNT\alchem.exe< file
C:\winnt\msbb.exe< file
Reboot normally after doing the above then post a fresh log plz.
•
•
Join Date: May 2004
Posts: 6
Reputation:
Solved Threads: 0
HEY! THANKKKKKKKKKKKKKKK YOUUUUUUUUUUUUUUUUUUUUUUU
I DONT GET THE ERROR ANYMORE
Anyway...I wasn´t able to check this (on the HIJACK box)
04 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe ....because when I scanned that box wasn't there!!!!!
Same thing when I did a reboot in safe mode I wasn´t able to delete this files C:\WINNT\wzmhuryf.exe< file
C:\WINNT\alchem.exe< file
C:\winnt\msbb.exe< file .... due they weren't there
Anyway here is my log, please tell me if i need to do something extra
AND THANKS AGAIN! LOVE YA
Logfile of HijackThis v1.97.7
Scan saved at 0:03:25, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/dialer...ecomendada.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/es/SysWebTelecom.cab
I DONT GET THE ERROR ANYMORE
Anyway...I wasn´t able to check this (on the HIJACK box)
04 - HKLM\..\Run: [msbb] C:\winnt\msbb.exe ....because when I scanned that box wasn't there!!!!!
Same thing when I did a reboot in safe mode I wasn´t able to delete this files C:\WINNT\wzmhuryf.exe< file
C:\WINNT\alchem.exe< file
C:\winnt\msbb.exe< file .... due they weren't there
Anyway here is my log, please tell me if i need to do something extra
AND THANKS AGAIN! LOVE YA
Logfile of HijackThis v1.97.7
Scan saved at 0:03:25, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/dialer...ecomendada.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/es/SysWebTelecom.cab
You got two more already. Have hijackthis fix these:
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/diale...Recomendada.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/es/SysWebTelecom.cab
Download & install spywareblaster from www.javacoolsoftware.com to prevent these installs. Keep it updated regularly.
Also, it looks like you have two anti virus programs running. You should take one off the start up menu as they may conflict. Use one as an on-demand scanner.
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/diale...Recomendada.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/es/SysWebTelecom.cab
Download & install spywareblaster from www.javacoolsoftware.com to prevent these installs. Keep it updated regularly.
Also, it looks like you have two anti virus programs running. You should take one off the start up menu as they may conflict. Use one as an on-demand scanner.
•
•
Join Date: May 2004
Posts: 6
Reputation:
Solved Threads: 0
OK
I downloaded the file you mention, I will keep it uploaded
This is my new log
Am I on now? :eek:
Logfile of HijackThis v1.97.7
Scan saved at 3:09:00, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\Yahoo!\Messenger\YPager.exe
C:\Archivos de programa\Soulseek\slsk.exe
C:\Archivos de programa\WinMX\WinMX.exe
C:\WINNT\explorer.exe
C:\Archivos de programa\Winamp\Winamp.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\SpywareBlaster\spywareblaster.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
THANKS AGAIN, you are the best!
I downloaded the file you mention, I will keep it uploaded
This is my new log
Am I on now? :eek:
Logfile of HijackThis v1.97.7
Scan saved at 3:09:00, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\Yahoo!\Messenger\YPager.exe
C:\Archivos de programa\Soulseek\slsk.exe
C:\Archivos de programa\WinMX\WinMX.exe
C:\WINNT\explorer.exe
C:\Archivos de programa\Winamp\Winamp.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\SpywareBlaster\spywareblaster.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
THANKS AGAIN, you are the best!
Looks ok now.
From answers that work:
These two background programs implement the OCR Aware feature of OmniPage in the later versions of OmniPage (this is called OmniPage/OCR Aware in other versions of OmniPage). This feature inserts the Acquire Text option in the File menu of Office Suites (Microsoft Office, Lotus SmartSuite, Corel WordPerfect). By clicking on "Acquire Text" you can scan a page of text and have it OCR’ed by OmniPage straight into your wordprocessor, spreadsheet, or presentation, all in one operation. When it works it is a great feature and a much simpler operation than opening OmniPage, scanning, converting, and saving into a file.
Recommendation :
Unfortunately there are many documented conflicts between these background programs and other applications such as applications using your modem (!!), or other applications which need to use the scanner. Our recommendation, therefore, is that, unless you do a lot of conversion-to-text scanning (OCR) and you are not experiencing general PC problems or problems with other programs, then you should disable this feature and get used to manually opening OmniPage to scan text. You can disable the feature as follows :
(1) Open OmniPage.
(2) Choose the "Tools \ OCR Aware" menu option.
(3) Remove the check mark against the "Enable OCR Aware" option.
From answers that work:
These two background programs implement the OCR Aware feature of OmniPage in the later versions of OmniPage (this is called OmniPage/OCR Aware in other versions of OmniPage). This feature inserts the Acquire Text option in the File menu of Office Suites (Microsoft Office, Lotus SmartSuite, Corel WordPerfect). By clicking on "Acquire Text" you can scan a page of text and have it OCR’ed by OmniPage straight into your wordprocessor, spreadsheet, or presentation, all in one operation. When it works it is a great feature and a much simpler operation than opening OmniPage, scanning, converting, and saving into a file.
Recommendation :
Unfortunately there are many documented conflicts between these background programs and other applications such as applications using your modem (!!), or other applications which need to use the scanner. Our recommendation, therefore, is that, unless you do a lot of conversion-to-text scanning (OCR) and you are not experiencing general PC problems or problems with other programs, then you should disable this feature and get used to manually opening OmniPage to scan text. You can disable the feature as follows :
(1) Open OmniPage.
(2) Choose the "Tools \ OCR Aware" menu option.
(3) Remove the check mark against the "Enable OCR Aware" option.
•
•
Join Date: May 2004
Posts: 6
Reputation:
Solved Threads: 0
THANK YOU THANK YOU THANK YOUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
LOVE U!!!!!
One question: I should be let the SPYWAREBLASTER running (open) when I use the computer or just I must update it!???
THANKS AGAIN , HUGS FROM SANTIAGO; CHILE
this is my new log
Logfile of HijackThis v1.97.7
Scan saved at 14:05:48, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\Soulseek\slsk.exe
C:\Archivos de programa\WinMX\WinMX.exe
C:\WINNT\explorer.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\Yahoo!\Messenger\YPager.exe
C:\Archivos de programa\ZMatrix\matrix.exe
C:\ARCHIV~1\Grisoft\AVG6\AVGCC32.EXE
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Winamp\Winamp.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Startup: ZMatrix.lnk = C:\Archivos de programa\ZMatrix\matrix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: Bajar web con LeechGet - file://C:\Archivos de programa\LeechGet 2004\\Parser.html
O8 - Extra context menu item: Descargar usando el Asistente de Descargas - file://C:\Archivos de programa\LeechGet 2004\\Wizard.html
O8 - Extra context menu item: Descargar usando LeechGet - file://C:\Archivos de programa\LeechGet 2004\\AddUrl.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
LOVE U!!!!!
One question: I should be let the SPYWAREBLASTER running (open) when I use the computer or just I must update it!???
THANKS AGAIN , HUGS FROM SANTIAGO; CHILE
this is my new log
Logfile of HijackThis v1.97.7
Scan saved at 14:05:48, on 12-05-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVG6\avgserv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\VetMsgNT.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\keyhook.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\WINNT\PowerS.exe
C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe
C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\WINNT\system32\ctfmon.exe
C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
C:\WINNT\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Archivos de programa\Soulseek\slsk.exe
C:\Archivos de programa\WinMX\WinMX.exe
C:\WINNT\explorer.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\Yahoo!\Messenger\YPager.exe
C:\Archivos de programa\ZMatrix\matrix.exe
C:\ARCHIV~1\Grisoft\AVG6\AVGCC32.EXE
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Winamp\Winamp.exe
C:\unzipped\hijackthis1977\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\System32\keyhook.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [PowerS] C:\WINNT\PowerS.exe
O4 - HKLM\..\Run: [Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\Agent.exe"
O4 - HKLM\..\Run: [Remote_Agent] "C:\Archivos de programa\CyberLink\PowerVCRII\RemoteAgent.exe"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P23 "EPSON Stylus C43 Series" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [EPSON Stylus C43 Series (Copia 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S08IC1.EXE /P33 "EPSON Stylus C43 Series (Copia 2)" /O6 "USB001" /M "Stylus C43"
O4 - HKLM\..\Run: [Ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARCHIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Startup: ZMatrix.lnk = C:\Archivos de programa\ZMatrix\matrix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Remote.lnk = C:\Archivos de programa\Prolink\PlayTV MPEG2\TVRMVCR.EXE
O8 - Extra context menu item: Bajar web con LeechGet - file://C:\Archivos de programa\LeechGet 2004\\Parser.html
O8 - Extra context menu item: Descargar usando el Asistente de Descargas - file://C:\Archivos de programa\LeechGet 2004\\Wizard.html
O8 - Extra context menu item: Descargar usando LeechGet - file://C:\Archivos de programa\LeechGet 2004\\AddUrl.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...111.6574768519
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
![]() |
Similar Threads
- Removing Bridge.dll (Web Browsers)
- What is BRIDGE.DLL (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Please Help... Hijack log attached
- Next Thread: Another "bridge.dll"-problem
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus apple attack avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial conficker connect control cyber cybercrime cyberwarfare ddos education email europe exam exploit facebook fake fancheckvirus gaming gtaiv halloween hijack hosting internet iphone kaspersky legal logfiles mail malware mcafee messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista war warning windows worm yahoo zeroday






