It is currently Tue Sep 01, 2026 4:09 pm


Hotxxx.exe dialer - Please help !!

Discuss security related topics in here (Hacking, Cracking, and Protecting)
Do not post HJT Logs here

Moderator: PCguy

Hotxxx.exe dialer - Please help !!

Postby Shakil » Wed Jul 28, 2004 8:00 pm

Hi,

I keep getting the HotXXX.exe dialer which starts up everytime I start the PC and dial into the net. I am appending HijackThis log. I use Win XP. I've got Mcafee antivirus with the latest defination data files plus Pest Patrol but these dont detect or remove this dialer.

Logfile of HijackThis v1.98.0
Scan saved at 08:49:30, on 2004/07/28
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINNT\System32\CTsvcCDA.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Creative\News\NewsUpd.EXE
C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\WINNT\outIook.exe
C:\WINNT\shman.exe
C:\WINNT\System32\ctfmon.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.65.3.68/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fastmetasearch.com/bar.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://216.65.3.68/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.65.3.68/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://approvedlinks.com/sp.htm
O1 - Hosts: 216.65.3.76 auto.search.msn.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NewsUpd] C:\Program Files\Creative\News\NewsUpd.EXE /q
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [HPCDTray] "C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe"
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KeyPatrol] C:\PROGRA~1\PESTPA~1\KeyPatrol.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccAppr] C:\WINNT\outIook.exe /i
O4 - HKLM\..\Run: [QTSvc] C:\WINNT\shman.exe /i
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [zzgshp] C:\WINNT\gshp.vbs
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\instant messenger\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-l ... cfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer = 163.38.34.11,163.38.30.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer = 163.38.34.11,163.38.30.9
O17 - HKLM\System\CS2\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer = 163.38.34.11,163.38.30.9
User avatar
Shakil
Newbie
Newbie
 
Posts: 6
Joined: Thu Jul 29, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Cactus » Thu Jul 29, 2004 12:13 am

Download CWShredder and save it to your desktop...
http://www.softpedia.com/public/cat/10/ ... -150.shtml

Next: with only CWShredder open, let it FIX all problems

RESTART your computer
Don't open a browser yet, instead access Internet Options via Control Panel
Under the Programs tab "Reset Web Settings"
Under the General tab---Delete files + offline content---Also Reset home page.

Now run HJT again,and post a fresh logfile...

Cactus
User avatar
Cactus
Geek Alumni
 
Posts: 1330
Joined: Sat Nov 30, 2002 1:00 am
Location: Somewhere...

Thanks given:0
Thanks received:0
Top

Postby Shakil » Thu Jul 29, 2004 1:25 am

Hi Cactus ! did as you instructed and the new HJT log is attached....

Logfile of HijackThis v1.98.0
Scan saved at 02:19:37, on 2004/07/29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINNT\System32\CTsvcCDA.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Creative\News\NewsUpd.EXE
C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\WINNT\outIook.exe
C:\WINNT\shman.exe
C:\WINNT\System32\ctfmon.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://fastmetasearch.com/bar.php
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NewsUpd] C:\Program Files\Creative\News\NewsUpd.EXE /q
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [HPCDTray] "C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe"
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KeyPatrol] C:\PROGRA~1\PESTPA~1\KeyPatrol.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccAppr] C:\WINNT\outIook.exe /i
O4 - HKLM\..\Run: [QTSvc] C:\WINNT\shman.exe /i
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [zzgshp] C:\WINNT\gshp.vbs
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft

Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program

Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} -

C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\instant

messenger\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -

http://download.mcafee.com/molbin/iss-l ... cfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer =

163.38.34.11,163.38.30.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer =

163.38.34.11,163.38.30.9
O17 - HKLM\System\CS2\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer =

163.38.34.11,163.38.30.9
User avatar
Shakil
Newbie
Newbie
 
Posts: 6
Joined: Thu Jul 29, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Cactus » Thu Jul 29, 2004 1:50 am

Please make a folder for hijackthis, It's not adviseable to leave it in your TEMP FOLDER, backups will be deleted :)
Right click an empty spot on the desktop----left click NEW---Folder
Name it HJT---copy and paste hijackthis to that new folder and delete the one in the TEMP FOLDER originally downloaded
Don't delete backups until everything is running ok...



Set Windows to show hidden files and folders

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

RESTART your Computer in SAFE MODE



Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

outIook.exe
shman.exe

Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =http://fastmetasearch.com/bar.php

O4 - HKLM\..\Run: [NewsUpd] C:\Program Files\Creative\News\NewsUpd.EXE /q
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccAppr] C:\WINNT\outIook.exe /i
O4 - HKLM\..\Run: [QTSvc] C:\WINNT\shman.exe /i
O4 - HKCU\..\Run: [zzgshp] C:\WINNT\gshp.vbs
O4 - Startup: PowerReg Scheduler.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer = 163.38.34.11,163.38.30.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer = 163.38.34.11,163.38.30.9
O17 - HKLM\System\CS2\Services\Tcpip\..\{04AE5CD3-EBB8-4FB1-974A-F351771E5286}: NameServer = 163.38.34.11,163.38.30.9



Go to Control Panel / Add/Remove Programs and remove the following if they are there:

NewsUpd
outIook
shman
PowerReg

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)

C:\Program Files\Creative\News\NewsUpd.EXE
C:\WINNT\outIook.exe /i
C:\WINNT\shman.exe /i



Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

Run HJT again and post a new logfile.

NOTE: Make sure you follow the instruction above and move HJT to a PERMANENT FOLDER before doing this fix.


Cactus
User avatar
Cactus
Geek Alumni
 
Posts: 1330
Joined: Sat Nov 30, 2002 1:00 am
Location: Somewhere...

Thanks given:0
Thanks received:0
Top

Postby brad » Thu Jul 29, 2004 11:03 am

Fix looks pretty good except for one thing:
Do you use CitiBank?
I believe the IP (163.38.34.11) in the 017's is for CitiBank Server...



Very Important!
After you've finished fixing this problem I strongly recommend that you visit the and download the Critical Updates.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby Shakil » Thu Jul 29, 2004 7:32 pm

Brad/Cactus thanks ! I am going to run the fix tonite and will post the HJT log after its done. I really should have updated the fixes on XP but atleast I've downloaded all the relevent ones and will install them also tonite. Wish me luck ! Not sure what I need to do about the Citibank IP, I dont use it for anything (the website I mean) so if its not there it wouldnt matter.
User avatar
Shakil
Newbie
Newbie
 
Posts: 6
Joined: Thu Jul 29, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Shakil » Thu Jul 29, 2004 9:48 pm

Hi Cactus/Brad.......... followed instructions everything was done except couldnt find NewsUpd, outIook, shman, and PowerReg in the Programs list so there was nothing to uninstall plus didnt find outIook and shman on the task list (process list) in safe mode so didnt have to kill these. Did everything else and the latest HJT is attached. After reboot from safe mode everything seems to be working except IE6 seems to hang while Outlook is fine and I have installed Mozilla which is working fine (hence this post !). Do I need to fix or reinstall IE6 ? Thnaks for all your help so far.

Logfile of HijackThis v1.98.0
Scan saved at 09:51:41, on 2004/07/29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINNT\System32\CTsvcCDA.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Webscanx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\WINNT\System32\ctfmon.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [HPCDTray] "C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe"
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KeyPatrol] C:\PROGRA~1\PESTPA~1\KeyPatrol.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\System32\ctfmon.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\instant messenger\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-l ... cfscan.cab
User avatar
Shakil
Newbie
Newbie
 
Posts: 6
Joined: Thu Jul 29, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Cactus » Thu Jul 29, 2004 11:21 pm

Logfile looks clean..... :)


Cactus
User avatar
Cactus
Geek Alumni
 
Posts: 1330
Joined: Sat Nov 30, 2002 1:00 am
Location: Somewhere...

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Fri Jul 30, 2004 5:02 am

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Fri Jul 30, 2004 8:59 am

I strongly recommend that you visit the and download the Critical Updates.
After that we'll address the OE issue.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby Shakil » Fri Jul 30, 2004 10:39 am

Brad tonite I'll install the missing MS fixes (got all the 2004 ones on a CD) and then lets see if the IE6 issue can be addressed tho I am quite impressed with Mozilla but it'll be nice to end it all on a good note by having everything work properly for a change ! thanks again for all your help.
User avatar
Shakil
Newbie
Newbie
 
Posts: 6
Joined: Thu Jul 29, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Shakil » Tue Aug 03, 2004 11:36 am

OK d/l all updates from Jan-Jul and IE6 also seems to be ok but I prefer Mozilla ! Thanks Brad and Cactus for your help and advise. javascript:emoticon(':P')
javascript:emoticon(':P')
User avatar
Shakil
Newbie
Newbie
 
Posts: 6
Joined: Thu Jul 29, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Security

Who is online

Users browsing this forum: No registered users and 1 guest

cron