Internet povezava-pomoč!
Živijo.
V petek je prišlo do problema z internet povezavo, in sicer po tem, ko sem očitno nekaj zbrisala, kar je našel Avast. Prosim, da mi vsaj namignete, če mi že pomagati ne morete, kaj bi lahko bil razlog, da povezave nikakor ne morem vzpostaviti.
Uporabljam OS: Microsoft Windows 98 SE in kabelski internet Telemach.
DNS ali karkoli v nastavitvah nisem nič spreminjala. Avast pa je našel nekaj,
kar sem zbrisala, ker se ni dalo shraniti v “chest”. Kasneje sem našla te zapise, ki pa sem jih že zbrisala:
Sign of »Win32:Dialer-572(Trj)« has been found in »c:\Program Files\webHancer\Programs\whSurvey.exe« file
Sign of »Win32:Dialer-567(Trj)« has been found in »c:\program files\webhancer\programs\whiehlpr.dll« file
Sign of »Win32:Adware-gen(Adw)« has been found in »c:\windows\webhdll.dll« file
Sign of »Win32:Lineage-197(Trj)« has been found in »C:\WINDOWS\ TEMP\p2psetup.exe\[UPX]« file
Sign of »Win32:Adware-gen(Adw)« has been found in »C\WINDOWS\webhdll.dll« file
Sign of »Win32:Dialer-570 (Trj)« has been found in »C:\Program Files\whInstall\whInstaller.exe« file
Sign of »Win32:Dialer-569 (Trj)« has been found in »C:\Program Files\webHancer\Programs\webhdll.dll« file
Sign of »Win32:Dialer-570 (Trj)« has been found in »C:\Program Files\webHancer\whinstaller.exe« file
Zanima me, ali je razlog, da ne morem vzpostaviti povezave, brisanje katerega od zgornjih dll ali exe????
Ko hočem odpreti katerokoli internet stran, se le-ta v naslovu zapiše, spodaj v browserju pa na brzino izpiše:
C:\WINDOWS\SYSTEM\SHDOCLC.DLL/DNSerror.htm in potem bela stran in ni povezave s strežnikom….
Kaj naj naredim? Sem že čisto obupala.
Hvala.
Lidija
Sem ga zagnala v varnem načinu in nič… še vedno je isto.
Kot da povezava je, strani pa se ne odpirajo in tudi e-mail ne.
Tole se izpiše:
C:\WINDOWS\SYSTEM\SHDOCLC.DLL/dnserror.htm
Sem že iskala na netu kako bi se odpravil ta problem in nič pametnega našla. Eni pišejo, da je vse kriv Kazaa, eni da je kriv firewall, eni da je treba zbrisati SHDOCLC in ga ponovno naložiti….
Aja, nastavitve sem pogledala (že stokrat :)) in je tko kot mora bit oz. tko kot piše na Telemachovi strani.
Kaj naj še naredim????
Naredila sem še Hijack in tukaj je rezultat. Lepo prosim, če lahko kdo pogleda in mi napiše ali je glavni krivec, da se mi IE ne odpre:
O10 – Hijacked Internet access by New.Net
O10 – Broken Internet access because of LSP provider ‘c:\windows\webhdll.dll’ missing.
In kaj lahko naredim, da bi zadeva delovala? Ali mi preostane le to, da škatlo odpeljem na servis?
Lp.
lidija
Logfile of HijackThis v1.99.1
Scan saved at 18:43:37, on 09. 05. 06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKJOBS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKTOPASS.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKSLAPI.EXE
C:\PROGRAM FILES\HIJACK THIS\HIJACKTHIS.EXE
R1 – HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.hotsearchbox.com/ie/
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hotsearchbox.com/ie/
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hotsearchbox.com/ie/
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.siol.net
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.hotsearchbox.com/ie/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hotsearchbox.com/ie/
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 – HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 – HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchalot.com
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchalot.com
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Povezave
R3 – URLSearchHook: ICQ Toolbar – {855F3B16-6D32-4fe6-8A56-BBB695989046} – C:\PROGRAM FILES\ICQ\ICQTOOLBAR\TOOLBAR.DLL
O2 – BHO: BrowserHelper Class – {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} – C:\WINDOWS\SYSTEM\NZDD.DLL
O2 – BHO: AcroIEHlprObj Class – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 – BHO: (no name) – {53707962-6F74-2D53-2644-206D7942484F} – blank (file missing)
O2 – BHO: YahooTaggedBM Class – {65D886A2-7CA7-479B-BB95-14D1EFB7946A} – C:\PROGRAM FILES\YAHOO!\COMMON\YIETAGBM.DLL
O2 – BHO: UberButton Class – {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} – C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
O2 – BHO: URLLink Class – {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} – C:\Program Files\NewDotNet\newdotnet3_88.dll
O3 – Toolbar: Updated.Toolbar – {9F6A22E6-1682-4F82-9B72-6314794CB253} – blank (file missing)
O3 – Toolbar: &Radio – {8E718888-423F-11D2-876E-00A0C9082467} – C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 – Toolbar: ICQ Toolbar – {855F3B16-6D32-4fe6-8A56-BBB695989046} – C:\PROGRAM FILES\ICQ\ICQTOOLBAR\TOOLBAR.DLL
O3 – Toolbar: &Google – {2318C2B1-4965-11d4-9B18-009027A5CD4F} – C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL
O4 – HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 – HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 – HKLM\..\Run: [SystemTray] SysTray.ExE
O4 – HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 – HKLM\..\Run: [internat.exe] internat.exe
O4 – HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 – HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSEcomR.EXE
O4 – HKLM\..\Run: [Vshwin32EXE] C:\Program Files\Network Associates\McAfee VirusScan\VSHWIN32.EXE
O4 – HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 – HKLM\..\Run: [LoadQM] loadqm.exe
O4 – HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 – HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 – HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 – HKLM\..\Run: [Shell API32] svcnet.exe
O4 – HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 – HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 – HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 – HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 – HKLM\..\RunServices: [Vshwin32EXE] C:\Program Files\Network Associates\McAfee VirusScan\VSHWIN32.EXE
O4 – HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 – HKCU\..\Run: [Felix] C:\Program Files\ScreenMates\FELIX21.EXE
O4 – HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 – HKCU\..\Run: [RocketPipe] C:\Program Files\RocketPipe\rpclient.exe -autorun
O4 – HKCU\..\Run: [MSGTAG] “C:\PROGRAM FILES\OUTLOOK EXPRESS\MSGTAG\MSGTAG.EXE” /startup
O4 – HKCU\..\Run: [Shell API32] svcnet.exe
O4 – Startup: InControl Desktop Manager.lnk = C:\Program Files\Encompass\Diamond\Diamond\InControl Tools 99\DMHKEY.EXE
O4 – Startup: PageKeeper Jobs.lnk = C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
O4 – Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 – User Startup: InControl Desktop Manager.lnk = C:\Program Files\Encompass\Diamond\Diamond\InControl Tools 99\DMHKEY.EXE
O4 – User Startup: PageKeeper Jobs.lnk = C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
O4 – User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 – Extra context menu item: Odpri okvir v novem okn&u – C:\WINDOWS\WEB\frm2new.htm
O8 – Extra context menu item: &Označi – C:\WINDOWS\WEB\highlight.htm
O8 – Extra context menu item: &Spletno iskanje – C:\WINDOWS\WEB\selsearch.htm
O8 – Extra context menu item: Seznam p&ovezav – C:\WINDOWS\WEB\urllist.htm
O8 – Extra context menu item: Po&večaj – C:\WINDOWS\WEB\zoomin.htm
O8 – Extra context menu item: Pomanj&šaj – C:\WINDOWS\WEB\zoomout.htm
O8 – Extra context menu item: S&eznam slik – C:\WINDOWS\Web\imglist.htm
O8 – Extra context menu item: &Add to IncrediMail Style Box – C:\PROGRA~1\INCRED~1\bin\WebMenuImg.htm
O8 – Extra context menu item: &Yahoo! Search – file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 – Extra context menu item: Yahoo! &Dictionary – file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 – Extra context menu item: Yahoo! &Maps – file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 – Extra context menu item: Yahoo! &SMS – file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O8 – Extra context menu item: &ICQ Toolbar Search – res://C:\PROGRAM FILES\ICQ\ICQTOOLBAR\TOOLBAR.DLL/SEARCH.HTML
O8 – Extra context menu item: &Google Search – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsearch.html
O8 – Extra context menu item: Cac&hed Snapshot of Page – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmcache.html
O8 – Extra context menu item: Si&milar Pages – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsimilar.html
O8 – Extra context menu item: Backward &Links – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmbacklinks.html
O9 – Extra button: (no name) – {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} – (no file)
O9 – Extra button: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQ\ICQLite\ICQLite.exe
O9 – Extra ‘Tools’ menuitem: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQ\ICQLite\ICQLite.exe
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 – Extra button: Yahoo! Services – {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} – C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
O10 – Hijacked Internet access by New.Net
O10 – Broken Internet access because of LSP provider ‘c:\windows\webhdll.dll’ missing
O12 – Plugin for .qt: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 – Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 – IERESET.INF: SEARCH_PAGE_URL=
O14 – IERESET.INF: START_PAGE_URL=
O16 – DPF: Dialpad US Java Applet – http://www.dialpad.com/applet/src/vscp.cab
O16 – DPF: Go2CallClient – http://www.go2call.com/maindialer/CallClient.cab
O16 – DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) – http://www.ipix-eu.com/viewers/ipixx.cab
O16 – DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} – http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.8.cab
O16 – DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) – http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 – DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) – C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 – DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) – https://ac.nlb.si/cda-docs/xenroll.cab
O16 – DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) – http://download.games.yahoo.com/games/web_games/tikgames/pandacraze/gpcontrol.cab
O16 – DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) – http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 – DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) – http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 – DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) – http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 – DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) – http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 – DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) – http://toolbar.google.com/data/sl/deleon/1.1.62-deleon/GoogleNav.cab
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKJOBS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKTOPASS.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKSLAPI.EXE
C:\PROGRAM FILES\HIJACK THIS\HIJACKTHIS.EXE
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.hotsearchbox.com/ie/
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hotsearchbox.com/ie/
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.hotsearchbox.com/ie/
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.siol.net
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.hotsearchbox.com/ie/
Odstrani
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
Odstrani
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/
Odstrani
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
Odstrani
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hotsearchbox.com/ie/
Odstrani
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/
Odstrani
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
Odstrani
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchalot.com
Odstrani
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchalot.com
Odstrani
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
Odstrani
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Povezave
R3 – URLSearchHook: ICQ Toolbar – {855F3B16-6D32-4fe6-8A56-BBB695989046} – C:\PROGRAM FILES\ICQ\ICQTOOLBAR\TOOLBAR.DLL
O2 – BHO: BrowserHelper Class – {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} – C:\WINDOWS\SYSTEM\NZDD.DLL
O2 – BHO: AcroIEHlprObj Class – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
Odstrani
O2 – BHO: (no name) – {53707962-6F74-2D53-2644-206D7942484F} – blank (file missing)
Odstrani
O2 – BHO: YahooTaggedBM Class – {65D886A2-7CA7-479B-BB95-14D1EFB7946A} – C:\PROGRAM FILES\YAHOO!\COMMON\YIETAGBM.DLL
Odstrani
O2 – BHO: UberButton Class – {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} – C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
Odstrani
O2 – BHO: URLLink Class – {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} – C:\Program Files\NewDotNet\newdotnet3_88.dll
Odstrani
O3 – Toolbar: Updated.Toolbar – {9F6A22E6-1682-4F82-9B72-6314794CB253} – blank (file missing)
Odstrani
O3 – Toolbar: &Radio – {8E718888-423F-11D2-876E-00A0C9082467} – C:\WINDOWS\SYSTEM\MSDXM.OCX
Odstrani
O3 – Toolbar: ICQ Toolbar – {855F3B16-6D32-4fe6-8A56-BBB695989046} – C:\PROGRAM FILES\ICQ\ICQTOOLBAR\TOOLBAR.DLL
Odstrani
O3 – Toolbar: &Google – {2318C2B1-4965-11d4-9B18-009027A5CD4F} – C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL
O4 – HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 – HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 – HKLM\..\Run: [SystemTray] SysTray.ExE
O4 – HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 – HKLM\..\Run: [internat.exe] internat.exe
O4 – HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 – HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSEcomR.EXE
O4 – HKLM\..\Run: [Vshwin32EXE] C:\Program Files\Network Associates\McAfee VirusScan\VSHWIN32.EXE
O4 – HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 – HKLM\..\Run: [LoadQM] loadqm.exe
O4 – HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 – HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 – HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 – HKLM\..\Run: [Shell API32] svcnet.exe
O4 – HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 – HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
Odstrani
O4 – HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 – HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 – HKLM\..\RunServices: [Vshwin32EXE] C:\Program Files\Network Associates\McAfee VirusScan\VSHWIN32.EXE
O4 – HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 – HKCU\..\Run: [Felix] C:\Program Files\ScreenMates\FELIX21.EXE
Odstrani
O4 – HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 – HKCU\..\Run: [RocketPipe] C:\Program Files\RocketPipe\rpclient.exe -autorun
O4 – HKCU\..\Run: [MSGTAG] “C:\PROGRAM FILES\OUTLOOK EXPRESS\MSGTAG\MSGTAG.EXE” /startup
O4 – HKCU\..\Run: [Shell API32] svcnet.exe
O4 – Startup: InControl Desktop Manager.lnk = C:\Program Files\Encompass\Diamond\Diamond\InControl Tools 99\DMHKEY.EXE
O4 – Startup: PageKeeper Jobs.lnk = C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
O4 – Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 – User Startup: InControl Desktop Manager.lnk = C:\Program Files\Encompass\Diamond\Diamond\InControl Tools 99\DMHKEY.EXE
O4 – User Startup: PageKeeper Jobs.lnk = C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
O4 – User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 – Extra context menu item: Odpri okvir v novem okn&u – C:\WINDOWS\WEB\frm2new.htm
O8 – Extra context menu item: &Označi – C:\WINDOWS\WEB\highlight.htm
O8 – Extra context menu item: &Spletno iskanje – C:\WINDOWS\WEB\selsearch.htm
O8 – Extra context menu item: Seznam p&ovezav – C:\WINDOWS\WEB\urllist.htm
O8 – Extra context menu item: Po&večaj – C:\WINDOWS\WEB\zoomin.htm
O8 – Extra context menu item: Pomanj&šaj – C:\WINDOWS\WEB\zoomout.htm
O8 – Extra context menu item: S&eznam slik – C:\WINDOWS\Web\imglist.htm
O8 – Extra context menu item: &Add to IncrediMail Style Box – C:\PROGRA~1\INCRED~1\bin\WebMenuImg.htm
Odstrani
O8 – Extra context menu item: &Yahoo! Search – file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
Odstrani
O8 – Extra context menu item: Yahoo! &Dictionary – file:///C:\Program Files\Yahoo!\Common/ycdict.htm
Odstrani
O8 – Extra context menu item: Yahoo! &Maps – file:///C:\Program Files\Yahoo!\Common/ycmap.htm
Odstrani
O8 – Extra context menu item: Yahoo! &SMS – file:///C:\Program Files\Yahoo!\Common/ycsms.htm
Odstrani
O8 – Extra context menu item: &ICQ Toolbar Search – res://C:\PROGRAM FILES\ICQ\ICQTOOLBAR\TOOLBAR.DLL/SEARCH.HTML
O8 – Extra context menu item: &Google Search – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsearch.html
O8 – Extra context menu item: Cac&hed Snapshot of Page – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmcache.html
O8 – Extra context menu item: Si&milar Pages – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsimilar.html
O8 – Extra context menu item: Backward &Links – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmbacklinks.html
O9 – Extra button: (no name) – {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} – (no file)
O9 – Extra button: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQ\ICQLite\ICQLite.exe
O9 – Extra ‘Tools’ menuitem: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQ\ICQLite\ICQLite.exe
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 – Extra button: Yahoo! Services – {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} – C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
Odstrani
O10 – Hijacked Internet access by New.Net
Odstrani
O10 – Broken Internet access because of LSP provider ‘c:\windows\webhdll.dll’ missing
O12 – Plugin for .qt: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 – Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 – IERESET.INF: SEARCH_PAGE_URL=
O14 – IERESET.INF: START_PAGE_URL=
O16 – DPF: Dialpad US Java Applet – http://www.dialpad.com/applet/src/vscp.cab
O16 – DPF: Go2CallClient – http://www.go2call.com/maindialer/CallClient.cab
O16 – DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) – http://www.ipix-eu.com/viewers/ipixx.cab
O16 – DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} – http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.8.cab
O16 – DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) – http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 – DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) – C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 – DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) – https://ac.nlb.si/cda-docs/xenroll.cab
O16 – DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) – http://download.games.yahoo.com/games/web_games/tikgames/pandacraze/gpcontrol.cab
O16 – DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) – http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 – DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) – http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 – DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) – http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 – DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) – http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 – DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) – http://toolbar.google.com/data/sl/deleon/1.1.62-deleon/GoogleNav.cab
potem pa še enkrat naredi hijack in prilepi vse skupaj gor.
Evo uspela sem se konektat. Mi pa s Hijackom ni uspelo odstraniti tistega Broken Internet accessa in webhdll… pa sem si na srečo že prej inštalirala
programček LPSFix.exe in je šlo. Ne vem, če sem vse odstranila, ker mi ponekod ni bilo jasno ali odstranim vse vrstice, ki sledijo ali le prvo vrstico.
Bi prosila, če še enkrat pogledaš (ali pa kdo drug) da zbrišem še ostalo nesnago.
HVALA!!!!
Logfile of HijackThis v1.99.1
Scan saved at 18:50:40, on 10. 05. 06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKJOBS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKSLAPI.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\CAERE\PAGEKEEPER30\SYSTEM\PKTOPASS.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\HIJACK THIS\HIJACKTHIS.EXE
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.siol.net
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R3 – URLSearchHook: ICQ Toolbar – {855F3B16-6D32-4fe6-8A56-BBB695989046} – C:\PROGRAM FILES\ICQ\ICQTOOLBAR\TOOLBAR.DLL
O2 – BHO: BrowserHelper Class – {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} – C:\WINDOWS\SYSTEM\NZDD.DLL
O2 – BHO: AcroIEHlprObj Class – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O4 – HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 – HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 – HKLM\..\Run: [SystemTray] SysTray.ExE
O4 – HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 – HKLM\..\Run: [internat.exe] internat.exe
O4 – HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 – HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSEcomR.EXE
O4 – HKLM\..\Run: [Vshwin32EXE] C:\Program Files\Network Associates\McAfee VirusScan\VSHWIN32.EXE
O4 – HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 – HKLM\..\Run: [LoadQM] loadqm.exe
O4 – HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 – HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 – HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 – HKLM\..\Run: [Shell API32] svcnet.exe
O4 – HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 – HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 – HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 – HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 – HKLM\..\RunServices: [Vshwin32EXE] C:\Program Files\Network Associates\McAfee VirusScan\VSHWIN32.EXE
O4 – HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 – HKCU\..\Run: [Felix] C:\Program Files\ScreenMates\FELIX21.EXE
O4 – HKCU\..\Run: [RocketPipe] C:\Program Files\RocketPipe\rpclient.exe -autorun
O4 – HKCU\..\Run: [MSGTAG] “C:\PROGRAM FILES\OUTLOOK EXPRESS\MSGTAG\MSGTAG.EXE” /startup
O4 – HKCU\..\Run: [Shell API32] svcnet.exe
O4 – Startup: InControl Desktop Manager.lnk = C:\Program Files\Encompass\Diamond\Diamond\InControl Tools 99\DMHKEY.EXE
O4 – Startup: PageKeeper Jobs.lnk = C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
O4 – Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 – User Startup: InControl Desktop Manager.lnk = C:\Program Files\Encompass\Diamond\Diamond\InControl Tools 99\DMHKEY.EXE
O4 – User Startup: PageKeeper Jobs.lnk = C:\Program Files\Caere\PageKeeper30\system\PKJobs.exe
O4 – User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 – Extra context menu item: Odpri okvir v novem okn&u – C:\WINDOWS\WEB\frm2new.htm
O8 – Extra context menu item: &Označi – C:\WINDOWS\WEB\highlight.htm
O8 – Extra context menu item: &Spletno iskanje – C:\WINDOWS\WEB\selsearch.htm
O8 – Extra context menu item: Seznam p&ovezav – C:\WINDOWS\WEB\urllist.htm
O8 – Extra context menu item: Po&večaj – C:\WINDOWS\WEB\zoomin.htm
O8 – Extra context menu item: Pomanj&šaj – C:\WINDOWS\WEB\zoomout.htm
O8 – Extra context menu item: S&eznam slik – C:\WINDOWS\Web\imglist.htm
O8 – Extra context menu item: &Add to IncrediMail Style Box – C:\PROGRA~1\INCRED~1\bin\WebMenuImg.htm
O8 – Extra context menu item: &Google Search – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsearch.html
O8 – Extra context menu item: Cac&hed Snapshot of Page – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmcache.html
O8 – Extra context menu item: Si&milar Pages – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmsimilar.html
O8 – Extra context menu item: Backward &Links – res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLENAV.DLL/cmbacklinks.html
O9 – Extra button: (no name) – {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} – (no file)
O9 – Extra button: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQ\ICQLite\ICQLite.exe
O9 – Extra ‘Tools’ menuitem: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQ\ICQLite\ICQLite.exe
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 – Extra button: Yahoo! Services – {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} – C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O12 – Plugin for .qt: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 – Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 – IERESET.INF: SEARCH_PAGE_URL=
O14 – IERESET.INF: START_PAGE_URL=
O16 – DPF: Dialpad US Java Applet – http://www.dialpad.com/applet/src/vscp.cab
O16 – DPF: Go2CallClient – http://www.go2call.com/maindialer/CallClient.cab
O16 – DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) – http://www.ipix-eu.com/viewers/ipixx.cab
O16 – DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} – http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.8.cab
O16 – DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) – http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 – DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) – C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 – DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) – https://ac.nlb.si/cda-docs/xenroll.cab
O16 – DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) – http://download.games.yahoo.com/games/web_games/tikgames/pandacraze/gpcontrol.cab
O16 – DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) – http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 – DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) – http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 – DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) – http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 – DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) – http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 – DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) – http://toolbar.google.com/data/sl/deleon/1.1.62-deleon/GoogleNav.cab
Briši:
O2 – BHO: BrowserHelper Class – {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} – C:\WINDOWS\SYSTEM\NZDD.DLL
O4 – HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 – HKLM\..\Run: [Shell API32] svcnet.exe
O4 – HKCU\..\Run: [Shell API32] svcnet.exe
O9 – Extra button: (no name) – {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} – (no file)
O14 – IERESET.INF: SEARCH_PAGE_URL=
O14 – IERESET.INF: START_PAGE_URL=
O16 – DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} – http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSe tup1.0.0.8.cab
Lp, Max
Forum je zaprt za komentiranje.