Gimpi Posted December 24, 2004 Report Share Posted December 24, 2004 I really need your help here guys. Please, read this log and tell me what to do. I won't be here all night, so, the sooner the better. Thanks.Logfile of HijackThis v1.99.0Scan saved at 7:29:11 PM, on 12/23/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\cisvc.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\system32\cidaemon.exeC:\WINDOWS\system32\cidaemon.exeC:\Program Files\Real\RealPlayer\RealPlay.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exeC:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exeC:\docume~1\chrisk~1\locals~1\temp\yWY.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\WINDOWS\System32\d3detobj.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\AIM95\aim.exeC:\PROGRA~1\COMMON~1\tsa\tsm2.exeC:\Program Files\Digital Line Detect\DLG.exeC:\PROGRA~1\COMMON~1\tsa\ts2.exeC:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeC:\WINDOWS\system\diskweb.exeC:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exec:\windows\8ScUs5OP.exeC:\WINDOWS\Tasks\pcav.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exec:\windows\x.exeC:\Program Files\CxtPls\CxtPls.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\WINDOWS\explorer.exeC:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exeC:\WINDOWS\system\svrwin.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.aspR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/saR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)O1 - Hosts: comO1 - Hosts: nu.comO1 - Hosts: nu.comO1 - Hosts: enu.comO1 - Hosts: enu.comO1 - Hosts: henu.comO1 - Hosts: henu.comO1 - Hosts: .whenu.comO1 - Hosts: .whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: nc.whenu.comO1 - Hosts: nc.whenu.comO2 - BHO: (no name) - SOFTWARE - (no file)O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dllO2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\98Z6LTm.dllO2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exeO4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exeO4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exeO4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeO4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exeO4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exeO4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exeO4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exeO4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exeO4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exeO4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exeO4 - HKLM\..\Run: [*faxcr] C:\WINDOWS\assembly\temp\faxcr.exeO4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exeO4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exeO4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exeO4 - HKLM\..\Run: [vs9k3EO] d3detobj.exeO4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exeO4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exeO4 - HKLM\..\Run: [8ScUs5OP] c:\windows\8ScUs5OP.exeO4 - HKLM\..\Run: [x] c:\windows\x.exeO4 - HKLM\..\RunOnce: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe rerunO4 - HKLM\..\RunOnce: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe rerunO4 - HKLM\..\RunOnce: [*binole] C:\WINDOWS\Registration\binole.exe rerunO4 - HKLM\..\RunOnce: [*adcom] C:\WINDOWS\addins\adcom.exe rerunO4 - HKLM\..\RunOnce: [*libexp] C:\WINDOWS\Cursors\libexp.exe rerunO4 - HKLM\..\RunOnce: [*wmsinet] C:\WINDOWS\Config\wmsinet.exe rerunO4 - HKLM\..\RunOnce: [*faxlog] C:\WINDOWS\assembly\temp\faxlog.exe rerunO4 - HKLM\..\RunOnce: [*faxcr] C:\WINDOWS\assembly\temp\faxcr.exe rerunO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /qO4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exeO4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\svrwin.exe ren time:1103658999O4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exeO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocxO16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cabO23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exeO23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exeO23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe-gimp Link to post Share on other sites
Gimpi Posted December 24, 2004 Author Report Share Posted December 24, 2004 Alright heres another, note: the longnet stuff is ok, it's for long reality where she works. Thanks again.Logfile of HijackThis v1.99.0Scan saved at 7:59:33 PM, on 12/23/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\cisvc.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\system32\cidaemon.exeC:\WINDOWS\system32\cidaemon.exeC:\Program Files\Real\RealPlayer\RealPlay.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exeC:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exeC:\docume~1\chrisk~1\locals~1\temp\yWY.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\WINDOWS\System32\d3detobj.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\AIM95\aim.exeC:\PROGRA~1\COMMON~1\tsa\tsm2.exeC:\Program Files\Digital Line Detect\DLG.exeC:\PROGRA~1\COMMON~1\tsa\ts2.exeC:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeC:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exec:\windows\8ScUs5OP.exeC:\WINDOWS\Tasks\pcav.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exec:\windows\x.exeC:\Program Files\CxtPls\CxtPls.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\WINDOWS\explorer.exeC:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exeC:\WINDOWS\system\svrwin.exeF:\Programs\Misc\TinyIRC\TinyIRC.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.aspR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/saR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)O1 - Hosts: comO1 - Hosts: nu.comO1 - Hosts: nu.comO1 - Hosts: enu.comO1 - Hosts: enu.comO1 - Hosts: henu.comO1 - Hosts: henu.comO1 - Hosts: .whenu.comO1 - Hosts: .whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: nc.whenu.comO1 - Hosts: nc.whenu.comO2 - BHO: (no name) - SOFTWARE - (no file)O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dllO2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\98Z6LTm.dllO2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exeO4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exeO4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exeO4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeO4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exeO4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exeO4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exeO4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exeO4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exeO4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exeO4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exeO4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exeO4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exeO4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exeO4 - HKLM\..\Run: [vs9k3EO] d3detobj.exeO4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exeO4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exeO4 - HKLM\..\Run: [8ScUs5OP] c:\windows\8ScUs5OP.exeO4 - HKLM\..\Run: [x] c:\windows\x.exeO4 - HKLM\..\RunOnce: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe rerunO4 - HKLM\..\RunOnce: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe rerunO4 - HKLM\..\RunOnce: [*binole] C:\WINDOWS\Registration\binole.exe rerunO4 - HKLM\..\RunOnce: [*adcom] C:\WINDOWS\addins\adcom.exe rerunO4 - HKLM\..\RunOnce: [*libexp] C:\WINDOWS\Cursors\libexp.exe rerunO4 - HKLM\..\RunOnce: [*wmsinet] C:\WINDOWS\Config\wmsinet.exe rerunO4 - HKLM\..\RunOnce: [*faxlog] C:\WINDOWS\assembly\temp\faxlog.exe rerunO4 - HKLM\..\RunOnce: [*vgakb] C:\WINDOWS\Microsoft.NET\vgakb.exe rerunO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /qO4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exeO4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\svrwin.exe ren time:1103658999O4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exeO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocxO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cabO23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exeO23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exeO23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe Link to post Share on other sites
Gimpi Posted December 24, 2004 Author Report Share Posted December 24, 2004 Alright, ran housecall, it killed 37 trojans. :-x Here's the log.Logfile of HijackThis v1.99.0Scan saved at 8:36:31 PM, on 12/23/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\cisvc.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\system32\cidaemon.exeC:\WINDOWS\system32\cidaemon.exeC:\Program Files\Real\RealPlayer\RealPlay.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exeC:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exeC:\docume~1\chrisk~1\locals~1\temp\yWY.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\WINDOWS\System32\d3detobj.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\AIM95\aim.exeC:\Program Files\Digital Line Detect\DLG.exeC:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeC:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exec:\windows\8ScUs5OP.exeC:\WINDOWS\Tasks\pcav.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exec:\windows\x.exeC:\Program Files\CxtPls\CxtPls.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\WINDOWS\explorer.exeC:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exeC:\WINDOWS\system\svrwin.exeF:\Programs\Misc\TinyIRC\TinyIRC.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.aspR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/saR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)O1 - Hosts: comO1 - Hosts: nu.comO1 - Hosts: nu.comO1 - Hosts: enu.comO1 - Hosts: enu.comO1 - Hosts: henu.comO1 - Hosts: henu.comO1 - Hosts: .whenu.comO1 - Hosts: .whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: nc.whenu.comO1 - Hosts: nc.whenu.comO2 - BHO: (no name) - SOFTWARE - (no file)O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dllO2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\98Z6LTm.dllO2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exeO4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exeO4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exeO4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeO4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exeO4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exeO4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exeO4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exeO4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exeO4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exeO4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exeO4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exeO4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exeO4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exeO4 - HKLM\..\Run: [vs9k3EO] d3detobj.exeO4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exeO4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exeO4 - HKLM\..\Run: [8ScUs5OP] c:\windows\8ScUs5OP.exeO4 - HKLM\..\Run: [x] c:\windows\x.exeO4 - HKLM\..\RunOnce: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe rerunO4 - HKLM\..\RunOnce: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe rerunO4 - HKLM\..\RunOnce: [*binole] C:\WINDOWS\Registration\binole.exe rerunO4 - HKLM\..\RunOnce: [*adcom] C:\WINDOWS\addins\adcom.exe rerunO4 - HKLM\..\RunOnce: [*libexp] C:\WINDOWS\Cursors\libexp.exe rerunO4 - HKLM\..\RunOnce: [*wmsinet] C:\WINDOWS\Config\wmsinet.exe rerunO4 - HKLM\..\RunOnce: [*faxlog] C:\WINDOWS\assembly\temp\faxlog.exe rerunO4 - HKLM\..\RunOnce: [*vgakb] C:\WINDOWS\Microsoft.NET\vgakb.exe rerunO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /qO4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exeO4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\svrwin.exe ren time:1103658999O4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exeO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocxO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cabO23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exeO23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exeO23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe-gimp Link to post Share on other sites
Gimpi Posted December 24, 2004 Author Report Share Posted December 24, 2004 One more time...I hope...Logfile of HijackThis v1.99.0Scan saved at 8:46:27 PM, on 12/23/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\cisvc.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\System32\wuauclt.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Real\RealPlayer\RealPlay.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exeC:\WINDOWS\System32\wuauclt.exeC:\docume~1\chrisk~1\locals~1\temp\yWY.exeC:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\WINDOWS\System32\d3detobj.exeC:\windows\8ScUs5OP.exeC:\windows\x.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\AIM95\aim.exeC:\Program Files\Digital Line Detect\DLG.exeC:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeC:\WINDOWS\Tasks\vbexp.exeC:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exeC:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.aspR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/saR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)O1 - Hosts: comO1 - Hosts: nu.comO1 - Hosts: nu.comO1 - Hosts: enu.comO1 - Hosts: enu.comO1 - Hosts: henu.comO1 - Hosts: henu.comO1 - Hosts: .whenu.comO1 - Hosts: .whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: c.whenu.comO1 - Hosts: nc.whenu.comO1 - Hosts: nc.whenu.comO2 - BHO: (no name) - SOFTWARE - (no file)O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dllO2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\HcpUW6Kh.dllO2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exeO4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exeO4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exeO4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeO4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exeO4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exeO4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exeO4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exeO4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exeO4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exeO4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exeO4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exeO4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exeO4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exeO4 - HKLM\..\Run: [vs9k3EO] d3detobj.exeO4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exeO4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exeO4 - HKLM\..\Run: [8ScUs5OP] C:\windows\8ScUs5OP.exeO4 - HKLM\..\Run: [x] C:\windows\x.exeO4 - HKLM\..\RunOnce: [*ftpcr] C:\WINDOWS\ServicePackFiles\ftpcr.exe rerunO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /qO4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exeO4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\Tasks\vbexp.exe ren time:1103658999O4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exeO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocxO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cabO23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exeO23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exeO23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe-gimp Link to post Share on other sites
Besttechie Posted December 24, 2004 Report Share Posted December 24, 2004 Hi Gimpi,Note: I am helping him via chat so I have some steps done already. Which is why I am starting at the point I will be starting at.Please boot to Safe Mode and delete the following files/folders.Make sure you unhide hidden files and folders. http://www.xtra.co.nz/help/0,,4155-1916458,00.htmlC:\docume~1\chrisk~1\locals~1\temp\yWY.exe <-- the fileC:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exe <-- the fileC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe <-- the Viewpoint folderC:\WINDOWS\AppPatch\cabole.exe <-- the fileC:\WINDOWS\system\wmsac.exe <-- the fileC:\WINDOWS\Microsoft.NET\catwms.exe <-- the fileC:\WINDOWS\msagent\CHARS\antidoc.exe <-- the fileC:\WINDOWS\Registration\dllc.exe <-- the fileC:\WINDOWS\ipabr.exe <-- the fileC:\WINDOWS\system\svcinet.exe <-- the fileC:\WINDOWS\assembly\temp\pcwave.exe <-- the fileC:\WINDOWS\Cursors\libexp.exe <-- the fileC:\WINDOWS\addins\adcom.exe <-- the fileC:\d3detobj.exe <-- the file If it's not at that location check C:\Windows\d3detobj.exeC:\WINDOWS\system32\CatRoot2\mfcftp.exe <-- the fileC:\WINDOWS\Registration\binole.exe <-- the fileC:\windows\8ScUs5OP.exe <-- the fileC:\windows\x.exe <-- the fileThen from Safe Mode run Ad-aware and Spybot have them clean what they find. After you do that reboot into normal mode, and post a new logfile.Good Luck! B Link to post Share on other sites
Gimpi Posted December 24, 2004 Author Report Share Posted December 24, 2004 Last one I hope.Logfile of HijackThis v1.99.0Scan saved at 10:18:11 PM, on 12/23/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\cisvc.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Real\RealPlayer\RealPlay.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exeC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\AIM95\aim.exeC:\Program Files\Digital Line Detect\DLG.exeC:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeC:\WINDOWS\system32\ICSXML\inetmp3.exeC:\WINDOWS\System32\wuauclt.exeC:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exeC:\WINDOWS\System32\hpoipm07.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exeC:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.aspR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.datO2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dllO2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\yBV.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\RunOnce: [*olecat] C:\WINDOWS\security\Database\olecat.exe rerunO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /qO4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exeO4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system32\ICSXML\inetmp3.exe ren time:1103658999O4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exeO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocxO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cabO23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exeO23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exeO23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe Link to post Share on other sites
Gimpi Posted December 24, 2004 Author Report Share Posted December 24, 2004 Logfile of HijackThis v1.99.0Scan saved at 10:41:59 PM, on 12/23/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\cisvc.exec:\PROGRA~1\mcafee.com\vso\mcvsrte.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Real\RealPlayer\RealPlay.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\mcafee.com\vso\mcvsshld.exeC:\Program Files\Common Files\Dell\EUSW\Support.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exeC:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\AIM95\aim.exeC:\Program Files\Digital Line Detect\DLG.exeC:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeC:\WINDOWS\System32\wuauclt.exeC:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exeC:\WINDOWS\System32\hpoipm07.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exeC:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exeC:\Program Files\HJT\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.aspR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exeO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /qO4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exeO4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exeO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocxO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cabO23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exeO23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exeO23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe Link to post Share on other sites
Besttechie Posted December 24, 2004 Report Share Posted December 24, 2004 Hi Gimpi,Please fix this too.O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exeThen reboot into Safe Mode like before, and delete this folder.C:\Program Files\Common Files\tsa\tsm2.exe <-- the tsa folder. Good Luck!B Link to post Share on other sites
Besttechie Posted December 24, 2004 Report Share Posted December 24, 2004 Hi,This is being worked on. The rest will be taken care of via chat. B Link to post Share on other sites
Recommended Posts