Oni Posted November 2, 2004 Report Share Posted November 2, 2004 Ok first of all, I'll just begin with the problems that I have with my computer. I've been experimented with ProRat (Rat BackDoor Trojan Hacker.. Well actaully something administrative tool..) So that thing in my log is fine. But I've been missing my service.exe? It sometimes comes up on an error screen saying that I'm missing that in one of my important folder.. (Systems32 maybe...) I just newly noticed after I started my computer up have a IE Hijacker... Called Slotch I Googled it but I only found forums of people asking for help with no real answer... So my main problem is the missing service.exe AND Slotch...Help me please Here you all techies go!Look down.. I gotta new log. Link to post Share on other sites
Jaspossum Posted November 2, 2004 Report Share Posted November 2, 2004 There is a newer version of Hijack This. You can get it here, Hijack This v1.98.2EDIT: Correct Link Now. Link to post Share on other sites
Oni Posted November 2, 2004 Author Report Share Posted November 2, 2004 Downloading it THanksbtw I LOVE SQUIDWARD! Link to post Share on other sites
njustice Posted November 2, 2004 Report Share Posted November 2, 2004 Hello Oni, Before downloading the latest version could you please make a permanent folder off the desktop and put HijackThis.exe in that folder.How to make a permanent folder:Click My Computer, then C:\In the menu bar, File->New->Folder.That will create a folder named New Folder, which while highlighted you can rename to "HJT" or "HijackThis". Now you have C:\HJT\ folder. Please put your HijackThis.exe there......post a new log. Link to post Share on other sites
Oni Posted November 2, 2004 Author Report Share Posted November 2, 2004 Lol real precise intstuctions Look down again..Someone can erase all these posts except my newest log..Thanks. Link to post Share on other sites
njustice Posted November 2, 2004 Report Share Posted November 2, 2004 Download CWShredder http://www.downloads.subratam.org/CWShredder.exeRun it......press "Fix", follow its prompts & instructions.. press 'Next', and allow it to fix all it finds.reboot......post a new log. Link to post Share on other sites
Oni Posted November 2, 2004 Author Report Share Posted November 2, 2004 New one down there... Link to post Share on other sites
njustice Posted November 2, 2004 Report Share Posted November 2, 2004 Download Spybot fromhttp://www.safer-networking.org/index.php?page=downloadafter installing......hit.."Search for Updates".....get them all.......(Download Updates)........then "Check for Problems".......after the scan is complete..allow Spybot to remove everything listed in RED...reboot your computer.NOTE: Spybot will flag 5 DSO Exploit's...this is a bug in the program and will be fixed in the next version, you can ignore these.-------------------------------------------------------------------------Then Download Ad-aware SE from: http://www.majorgeeks.com/download506.htmlInstall the program and launch it.First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files.Next, we need to configure Ad-aware for a full scan.Click on the Gear icon (second from the left) to access the preferences/settings window1. In the General window make sure the following are selected:* Automatically save log-file* Automatically quarantine objects prior to removal* Safe Mode (always request confirmation)2. Click on the Scanning button on the left and select :* Scan Within Archives* Scan Active Processes* Scan Registry* Deep Scan Registry* Scan my IE favorites for banned URL’s* Scan my Hosts file* Under Click here to select drives + folders, choose:* All of your hard drivesClick on the Advanced button on the left and select:* Include additional process information* Include additional file information* Include environment informationClick the Tweak button and select:* Under the Scanning Engine:o Unload recognized processes & modules during scano Include additional Ad-aware settings in logfile* Under the Cleaning Engine:o Let Windows remove files in use at next rebootClick on Proceed to save the settings.Click Start and on the next screen choose Activate in-depth Scan at the bottom of the page and then choose:* Use Custom Scanning OptionsClick Next and Ad-aware will scan your hard drive(s) with the options you have selected.Save the log file when it asks and then click FinishWhen finished, mark everything for removal and get rid of it. (Right-click the window and choose Select All from the drop down menu and click Next).Reboot your computer.-------------------------------------------------------------------------Do an online virus scan HERE and HERE.....reboot after each scan, let us know what couldn't be cleaned(include file path).-------------------------------------------------------------------------Download latest version of 'Hijack This!'. HijackThis 1.98.2Post a new log.... Link to post Share on other sites
Oni Posted November 2, 2004 Author Report Share Posted November 2, 2004 Look DownNewer version... Link to post Share on other sites
njustice Posted November 3, 2004 Report Share Posted November 3, 2004 Hello Oni, sorry for the delay.Go to add/remove programs and uninstall if found: couponsandoffers, 180 Solutions(if present), WeatherBug, 2findm~1, 16HIDE~1 and SpeedHack(if not recognized).....reboot if prompted.Close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items if present:R3 - Default URLSearchHook is missingO2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dllO3 - Toolbar: GreyMore - {627DA590-A05C-ADAD-277A-A75F6CD7554C} - C:\PROGRA~1\16HIDE~1\acid sect.dll (file missing)O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"O4 - HKLM\..\Run: [synchronization Agent] C:\Documents and Settings\canf\Desktop\SpeedHack\Speed hack.exe<---what is this, if you don't know remove it.O4 - HKLM\..\Run: [saap] c:\progra~1\2findm~1\partner\saap.exeO4 - HKLM\..\Run: [OSS] c:\windows\system32\ossproxy.exe -bootO4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1O4 - Startup: PowerReg SchedulerV2.exeO8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htmO9 - Extra button: ÃøÖ·´óÈ« (HKLM)<---no info on this....removing won't hurt.O9 - Extra 'Tools' menuitem: ÃøÖ·´óÈ« (HKLM)<---no info on this....removing won't hurt.O9 - Extra button: WeatherBug (HKCU)O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri...Transporter.cab?Click "Fix Checked"...Reboot to SAFE mode (F8 on bootup)How to start the computer in Safe modeShow hidden files and folders-->Show hidden files & foldersand delete the following folders/files in red if found.....C:\PROGRAM FILES\16HIDE~1<---folder will start with 16HIDEC:\Documents and Settings\canf\Desktop\SpeedHack<---see note aboveO4 - HKLM\..\Run: [saap] c:\program files\2findm~1<---folder will start with 2findmO4 - HKLM\..\Run: [OSS] c:\windows\system32\ossproxy.exeC:\Program Files\couponsandoffersreboot.....download the latest version of HijackThis HERE....post new log. Link to post Share on other sites
Oni Posted November 4, 2004 Author Report Share Posted November 4, 2004 Here ya go!I think this is the newest version...I wasn't able to find everything that you said that was in the programs folder though...A BIG problem. Sometimes I can't close windows, for now it's gone I think its gone for good but Im not that sure.Another thing, this started happening after I rebooted after safe mode. I see my desktop background after I click the user account I which to login as. I don't see anything else, everything else is gone after I try to login. I wait... So I get this Xp version who has windows and toolbars which look like OS 95. I hate 95, 98. Even how they look. I love Xp though... Can you tell me how to make it look like REAL Xp? And That booting problem SOmetimes the 98 version never pops up. It just stays at my desktop backgorund Help me out again So far your good at it! Logfile of HijackThis v1.97.7Scan saved at 6:11:43 PM, on 11/5/2004Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\netdde.exeC:\Program Files\Apache Group\Apache\Apache.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\basfipm.exeC:\WINDOWS\system32\cisvc.exeC:\WINDOWS\system32\clipsrv.exeC:\Program Files\Apache Group\Apache\Apache.exeC:\WINDOWS\System32\dllhost.exeC:\Program Files\ewido\security suite\ewidoguard.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\tcpsvcs.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\System32\msiexec.exeC:\Program Files\Symantec\Ghost\ngctw32.exeC:\WINDOWS\Explorer.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\services.exeC:\WINDOWS\System32\dllhost.exeC:\WINDOWS\System32\tlntsvr.exeC:\WINDOWS\System32\vssvc.exeC:\WINDOWS\System32\WLTRYSVC.EXEC:\WINDOWS\System32\bcmwltry.exeC:\WINDOWS\System32\wbem\wmiapsrv.exeC:\WINDOWS\System32\dmadmin.exeC:\WINDOWS\system32\wuauclt.exeC:\WINDOWS\system32\carpserv.exeC:\Program Files\Apoint\Apoint.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\WINDOWS\System32\DSentry.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\Program Files\Network Associates\Common Framework\UpdaterUI.exeC:\Program Files\Apoint\Apntex.exeC:\Documents and Settings\canf\Desktop\SpeedHack\Speed hack.exeC:\Program Files\Java\j2re1.4.2_05\bin\jusched.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\RamBooster\Rambooster.exeC:\Program Files\Digital Line Detect\DLG.exeC:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exeC:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exeC:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exeC:\Program Files\Internet Explorer\iexplore.exeC:\HJT\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://education.dellnet.com/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://education.dellnet.com/F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\fservice.exeF2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\fservice.exeO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dllO4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exeO4 - HKLM\..\Run: [CARPService] carpserv.exeO4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [bascstray] BascsTray.exeO4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquietO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [NGClient] C:\Program Files\Symantec\Ghost\ngctw32.exeO4 - HKLM\..\Run: [AceGain LiveUpdate] C:\Program Files\AceGain\LiveUpdate\LiveUpdate.exeO4 - HKLM\..\Run: [synchronization Agent] C:\Documents and Settings\canf\Desktop\SpeedHack\Speed hack.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster\Rambooster.exeO4 - HKCU\..\Run: [warez] "C:\Documents and Settings\canf\Desktop\Alper\Warez P2P Client\warez.exe" -hO4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO8 - Extra context menu item: =>&Español - http:\\wordreference.com\es\j\iees69.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)O9 - Extra button: AIM (HKLM)O9 - Extra button: ICQ 4.0 (HKLM)O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...ector/swdir.cabO16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6...922/wmv9VCM.CABO16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/...7993.5388773148O16 - DPF: {AD08A333-609E-11D3-950C-008098601567} - http://wordreference.com/Install/English%20to%20Spanish.cabO16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{86227E37-D968-4D38-A943-438570D30533}: NameServer = 134.53.253.1 Link to post Share on other sites
Oni Posted November 6, 2004 Author Report Share Posted November 6, 2004 Sommore problems Logfile of HijackThis v1.98.2Scan saved at 10:04:45 PM, on 11/5/2004Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\netdde.exeC:\Program Files\Apache Group\Apache\Apache.exeC:\WINDOWS\System32\Ati2evxx.exeC:\WINDOWS\system32\basfipm.exeC:\WINDOWS\system32\cisvc.exeC:\Program Files\Apache Group\Apache\Apache.exeC:\WINDOWS\system32\clipsrv.exeC:\WINDOWS\System32\dllhost.exeC:\Program Files\ewido\security suite\ewidoguard.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\tcpsvcs.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\mcshield.exeC:\Program Files\Network Associates\VirusScan\vstskmgr.exeC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\WINDOWS\Explorer.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\dllhost.exeC:\WINDOWS\system32\carpserv.exeC:\Program Files\Apoint\Apoint.exeC:\WINDOWS\System32\tlntsvr.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\WINDOWS\System32\DSentry.exeC:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exeC:\WINDOWS\System32\vssvc.exeC:\Program Files\QuickTime\qttask.exeC:\WINDOWS\System32\WLTRYSVC.EXEC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\Program Files\Apoint\Apntex.exeC:\WINDOWS\System32\bcmwltry.exeC:\WINDOWS\System32\wbem\wmiapsrv.exeC:\Program Files\Network Associates\Common Framework\UpdaterUI.exeC:\Documents and Settings\canf\Desktop\SpeedHack\Speed hack.exeC:\Program Files\Java\j2re1.4.2_05\bin\jusched.exeC:\WINDOWS\System32\dmadmin.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\RamBooster\Rambooster.exeC:\Program Files\Digital Line Detect\DLG.exeC:\Documents and Settings\canf\My Documents\mIRC\mirc.exeC:\WINDOWS\system32\cidaemon.exeC:\WINDOWS\notepad.exeC:\Program Files\AIM\aim.exeC:\Program Files\Internet Explorer\iexplore.exeC:\HJT2\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://education.dellnet.com/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://education.dellnet.com/O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exeO4 - HKLM\..\Run: [CARPService] carpserv.exeO4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exeO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [bascstray] BascsTray.exeO4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exeO4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquietO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [NGClient] C:\Program Files\Symantec\Ghost\ngctw32.exeO4 - HKLM\..\Run: [AceGain LiveUpdate] C:\Program Files\AceGain\LiveUpdate\LiveUpdate.exeO4 - HKLM\..\Run: [synchronization Agent] C:\Documents and Settings\canf\Desktop\SpeedHack\Speed hack.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster\Rambooster.exeO4 - Global Startup: Digital Line Detect.lnk = ?O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO8 - Extra context menu item: =>&Español - http:\\wordreference.com\es\j\iees69.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: ICQ 4.0 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\Microsoft Games\ICQLite\ICQLite.exeO9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\Microsoft Games\ICQLite\ICQLite.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cabO16 - DPF: {AD08A333-609E-11D3-950C-008098601567} - http://wordreference.com/Install/English%20to%20Spanish.cabO16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{86227E37-D968-4D38-A943-438570D30533}: NameServer = 134.53.253.1O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll Link to post Share on other sites
Recommended Posts