0

Hi, this is my 1st post so please bear with me if I ramble or don't give all the relevent information.
Today AVG Anti-virus picked up a virus called 'hosts' in C:/windows/system32/drivers/etc which it did not 'heal.' I am guessing now that this was a file called 'hosts.msn'
I have deleted this file although, it is still in the recycle bin.

Later I ran Spybot search and destroy and it has picked up 'fakemsn8beta' which it has quarentined , but I am guessing has not fixed properly because I cannot get onto any proper antivirus sites.

I have been looking for help around the web and it seems that I will need to post some form of Hijack this log. I have downloaded Hijack this to create a log for this post but it will not run. It flashes on the screen but shuts down before I can do anything.

Can anyone give me any information as to what else this virus does, or better still a cure that does not force me to format my drive.

Thank you

3
Contributors
6
Replies
7
Views
10 Years
Discussion Span
Last Post by Whinger
0

Go to control panel if in classic veiw click System, if in category veiw click performance and maintenance then system.click Restore Tab turn off restore.

Download the trial version of Ewido Security Suite http://www.ewido.net/en/download/ (W2K/XP Only)
· Install ewido.
· During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
· Launch ewido
· It will prompt you to update click the OK button and it will go to the main screen
· On the left side of the main screen click update
· Click on Start and let it update.
· DO NOT run a scan yet. You will do that later in safe mode.

Restart your computer into safe mode now. Perform the following steps in safe mode:
(Start tapping F8 at the first black screen after power up)

Run Ewido:
· Click on scanner
· Click Complete System Scan and the scan will begin.
· During the scan it will prompt you to clean files, click OK
· When the scan is finished, This will take some time to run!Boot to normal mode

Run HJT and then post your log.

0

Thanks TT4Titan.
I have been investigating this problem all weekend whilst waiting for a reply from here and ComputerActive. In the last hour and before I read your post, I managed to download MSNVIRREM (I think thats what it was called.) ans I have managed to run it whilst in safe mode. The report was that this is now cured.
I can now run Hijackthis and I can visit anti-virus sites.
I have attached a HJT log to this post, so can anyone analyse it let me know if there is anything else wrong.
Thank you very much.
Whinger.


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 16:28:09, on 10/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Saitek\Saitek Gaming Extensions\saicnfig.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Xfire\Xfire.exe
C:\Documents and Settings\Dad\Desktop\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/firefox
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILEOi+UdWpSlz2q9Dzn13Emww/Yw33w+y0Mi3iABAHQDjNaGrPmPyBOZl2Cc2jPTQonzBB6OoKIBxsL4iZADMhgvHuV0uSN7h12RqT7gkuFnQe3+UtjZD5/z53DB
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SaitekAutoConfigure] "C:\Program Files\Saitek\Saitek Gaming Extensions\saicnfig.exe" /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 studios\Startup Delayer\Startup Launcher.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: services.lnk = ?
O4 - Global Startup: MsnVirRem.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O10 - Unknown file in Winsock LSP: xfire_lsp_10650.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.euro.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/UK/install.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.1.87.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A92E0798-BFA4-4FEE-BB48-8E2C69B2B0C5} (PageDive Control) - http://www.navigram.com/engine/v812/PageDive5.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game04.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.home.ntl.com/motive/files/MotivePreQual.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: (no name) - http://foxtrotters.tripod.com/firework14.gif
O24 - Desktop Component 1: (no name) - http://www.gifs.net/animate/eyeflash.gif
O24 - Desktop Component 10: (no name) - http://images.google.co.uk/images?q=tbn:jyi2TcsZ49oJ:daitian.tripod.com/transparent.gif
O24 - Desktop Component 11: (no name) - http://www.feebleminds-gifs.com/candle5.gif
O24 - Desktop Component 12: (no name) - http://www.mwp.50g.com/index_ani/pg07/santa02_ani.gif
O24 - Desktop Component 13: (no name) - http://www.mwp.50g.com/index_ani/pg07/santa01_ani.gif
O24 - Desktop Component 14: (no name) - http://www.feebleminds-gifs.com/santazx.gif
O24 - Desktop Component 15: (no name) - http://toons.artie.com/christmas/arg-christmas-newyear-bnr.gif
O24 - Desktop Component 16: (no name) - http://www.feebleminds-gifs.com/santa-sing.gif
O24 - Desktop Component 17: (no name) - http://www.feebleminds-gifs.com/santa-christmas.gif
O24 - Desktop Component 18: (no name) - http://www.feebleminds-gifs.com/tree-lights.gif
O24 - Desktop Component 19: (no name) - http://www.feebleminds-gifs.com/santa-waving.gif
O24 - Desktop Component 2: (no name) - http://www.gifs.net/animate/eye.gif
O24 - Desktop Component 20: (no name) - http://www.feebleminds-gifs.com/santaseesaw.gif
O24 - Desktop Component 21: (no name) - http://www.1001-votes.com/vote/4253sor/poisson/poisson_03.gif
O24 - Desktop Component 22: (no name) - http://www.1001-votes.com/vote/4253sor/animaux/pingouin1.gif
O24 - Desktop Component 23: (no name) - http://www.1001-votes.com/vote/4253sor/poisson/poisson_16.gif
O24 - Desktop Component 24: (no name) - http://www.gifanimations.com/Image/Animations/Animals/fish/~TS1142894590244/fish_011.gif
O24 - Desktop Component 25: (no name) - http://www.gifs.net/Animation11/Animals/Fish/Fast_fish.gif
O24 - Desktop Component 26: (no name) - http://www.feebleminds-gifs.com/aback006.gif
O24 - Desktop Component 27: (no name) - http://www.feebleminds-gifs.com/at012.gif
O24 - Desktop Component 28: (no name) - http://www.feebleminds-gifs.com/orb-background.gif
O24 - Desktop Component 29: (no name) - http://www.aaa-clipart.com/data/anim3/gears/an5.gif
O24 - Desktop Component 3: (no name) - http://toons.artie.com/christmas/arg-snowing-background-full.gif
O24 - Desktop Component 30: (no name) - http://www.animation-central.com/gear/gears8.gif
O24 - Desktop Component 31: (no name) - http://static-a.arttoday.com/d/animfactory/images/company/penguin_waiter_with_tray_sm_wht.gif
O24 - Desktop Component 32: (no name) - http://www.aaa-clipart.com/data/anim3/gears/an3.gif
O24 - Desktop Component 33: (no name) - http://www.animation-central.com/gear/gears2.gif
O24 - Desktop Component 34: (no name) - http://www.aaa-clipart.com/data/anim3/gears/an1.gif
O24 - Desktop Component 35: (no name) - http://www.aaa-clipart.com/data/anim3/gears/an4.gif
O24 - Desktop Component 36: (no name) - http://www.dewa.com/animated/new/1gear.gif
O24 - Desktop Component 37: (no name) - http://www.dewa.com/animated/new/1gear1.gif
O24 - Desktop Component 38: (no name) - http://www.dewa.com/animated/new/1gear2.gif
O24 - Desktop Component 39: (no name) - http://bestanimations.com/Holidays/Fireworks/Fireworks-05-june.gif
O24 - Desktop Component 4: (no name) - http://toons.artie.com/christmas/arg-christmas-holly-91x86-url.gif
O24 - Desktop Component 40: (no name) - http://bestanimations.com/Holidays/Fireworks/Fireworks-02-june.gif
O24 - Desktop Component 41: (no name) - http://sd-480.dedibox.fr/bestgraph/gifs/fetes/artifices/artifices-10.gif
O24 - Desktop Component 42: (no name) - http://sd-480.dedibox.fr/bestgraph/gifs/fetes/artifices/artifices-17.gif
O24 - Desktop Component 43: (no name) - http://foxtrotters.tripod.com/firewrk3.gif
O24 - Desktop Component 44: (no name) - http://sd-480.dedibox.fr/bestgraph/gifs/fetes/artifices/artifices-14.gif
O24 - Desktop Component 45: (no name) - http://sd-480.dedibox.fr/bestgraph/gifs/fetes/artifices/artifices-02.gif
O24 - Desktop Component 46: (no name) - http://foxtrotters.tripod.com/firework7.gif
O24 - Desktop Component 47: (no name) - http://bestanimations.com/Holidays/Fireworks/Fireworks-09-june.gif
O24 - Desktop Component 48: (no name) - http://bestanimations.com/Holidays/Fireworks/Fireworks-06-june.gif
O24 - Desktop Component 49: (no name) - http://bestanimations.com/Holidays/Fireworks/Fireworks-10-june.gif
O24 - Desktop Component 5: (no name) - http://toons.artie.com/christmas/arg-santa-ho-ho-url.gif
O24 - Desktop Component 50: (no name) - http://sd-480.dedibox.fr/bestgraph/gifs/fetes/artifices/artifices-13.gif
O24 - Desktop Component 51: (no name) - http://bestanimations.com/Holidays/Fireworks/Fireworks-08-june.gif
O24 - Desktop Component 52: (no name) - http://sd-480.dedibox.fr/bestgraph/gifs/fetes/artifices/artifices-15.gif
O24 - Desktop Component 53: (no name) - http://foxtrotters.tripod.com/firework13.gif
O24 - Desktop Component 54: (no name) - http://sd-480.dedibox.fr/bestgraph/gifs/fetes/artifices/artifices-16.gif
O24 - Desktop Component 55: (no name) - http://bestanimations.com/Holidays/Fireworks/Fireworks-07-june.gif
O24 - Desktop Component 56: (no name) - http://www.webdeveloper.com/animations/4th_July/gifs/firework1.gif
O24 - Desktop Component 6: (no name) - http://www.artie.com/20031215/arg-christmas-tree-trans-url.gif
O24 - Desktop Component 7: (no name) - http://akidsheart.com/pics3/rudyanism.gif
O24 - Desktop Component 8: (no name) - http://foxtrotters.tripod.com/snowman4.gif
O24 - Desktop Component 9: (no name) - http://www.feebleminds-gifs.com/skeleton-026.gif
--
End of file - 17189 bytes

0

Clean these:

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=w...3+UtjZD5/z53DB

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

0

Sorry if this is a daft question, But how do I clean them? Is it just a case of searching for the file and deleting it?
Thanks.

0

i think if you run HJT and check the boxes next to the ones TT said, then click fix it should work. but make sure they're the only ones checked.

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.