Annoyances.org
Home » Windows XP Discussion Forum » Message 1102317138 Search | Help | Home
  
Tip: Run a free scan for common Windows errors ad

re: Spyware & IE problems
Sunday, December 5, 2004 at 11:12 pm
Windows XP Annoyances Discussion Forum
Posted by Seth (50 messages posted)


I have done as requested with LSPfix. I will keep thread posted as to how this went. Here is copy of my HJT log. Logfile of HijackThis v1.98.2 Scan saved at 6:12:58 PM, on 6/12/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\system32\drivers\dcfssvc.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\System32\DkLog.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\ZONELABS\vsmon.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\System32\dkcktkn.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe C:\Program Files\TGTSoft\StyleXP\StyleXP.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\BPALogin\BPALogin.exe C:\Program Files\Palm\HOTSYNC.EXE C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Dr Gothic\Desktop\Downloads\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkAutoReg.exe O4 - HKLM\..\Run: [DkStartup] C:\Program Files\Rainbow Technologies\iKey 2000 Series Software\DkStartup.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [BigPondCable] "C:\Program Files\Telstra\Cable Login\bpcable.exe" /r O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE O4 - Global Startup: BPALogin.lnk = C:\Program Files\BPALogin\BPALogin.exe O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: ConferenceRoom Java Client - http://nsw-chat.telstra.com/java/cr.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093177363265 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab


On Sunday, December 5, 2004 at 2:19 am, Carol J wrote:
>
>You've had your Winsock settings hijacked, so that's what needs to be fixed yet.
>This is a Winsock hijacker: O10 - Unknown file in Winsock LSP.
>
>Download and run LSPFix. Remove this file only: gapsp.dll You'll need to answer
>YES you know what you're doing. Direct download: >color="CC00FF">
>LSPFIX.ZIP

>The download is from this page: >color="CC00FF">LSPFIX.ZIP >color="CC00FF">
>LSPFIX (Winsock2 repair utility) - Screenshot

>
>I'd fix these entries in HJT also:
>
>O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
>O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen)
>- http://ppupdates.ca.com/downloads/scanner/axscanner.cab
>O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab

>

>


> >color="CC00FF">
>Dealing with Unwanted Spyware and Parasites



Written in response to:
re: Spyware & IE problems (Ms. Eagle: Sunday, December 5, 2004 at 2:19 am)

There are presently no replies to this message.

All messages in this thread [show all]
-Spyware & IE problems (Seth: Mon, Nov 29, 2004, 4:11 am)
-re: Spyware & IE problems (Yap: Mon, Nov 29, 2004, 4:39 am)
*re: Spyware & IE problems (Seth: Mon, Nov 29, 2004, 4:59 am)
-re: Spyware & IE problems (joe: Mon, Nov 29, 2004, 6:07 am)
*re: Spyware & IE problems (Yap: Mon, Nov 29, 2004, 6:28 am)
*re: Spyware & IE problems (Tkwiget: Mon, Nov 29, 2004, 6:14 am)
*re: Spyware & IE problems (joe: Mon, Nov 29, 2004, 6:57 am)
-re: Spyware & IE problems (Deosyne: Mon, Nov 29, 2004, 12:39 pm)
*re: Spyware & IE problems (joe: Mon, Nov 29, 2004, 1:00 pm)
-re: Spyware & IE problems (Falcon: Mon, Nov 29, 2004, 1:30 pm)
-re: Spyware & IE problems (joe: Mon, Nov 29, 2004, 1:38 pm)
*re: Spyware & IE problems (Seth: Mon, Nov 29, 2004, 11:39 pm)
-re: Spyware & IE problems (Yap: Tue, Nov 30, 2004, 2:52 am)
-re: Spyware & IE problems (Seth: Thu, Dec 2, 2004, 5:06 pm)
-re: Spyware & IE problems (Yap: Thu, Dec 2, 2004, 7:38 pm)
-re: Spyware & IE problems (Seth: Thu, Dec 2, 2004, 11:42 pm)
-re: Spyware & IE problems (Yap: Fri, Dec 3, 2004, 12:21 am)
-re: Spyware & IE problems (Seth: Fri, Dec 3, 2004, 2:56 pm)
-re: Spyware & IE problems (Yap: Fri, Dec 3, 2004, 3:51 pm)
-re: Spyware & IE problems (Seth: Sat, Dec 4, 2004, 1:15 am)
-re: Spyware & IE problems (Yap: Sat, Dec 4, 2004, 1:20 am)
-re: Spyware & IE problems (Seth: Sat, Dec 4, 2004, 3:18 am)
-re: Spyware & IE problems (Yap: Sat, Dec 4, 2004, 3:27 am)
-re: Spyware & IE problems (Seth: Sat, Dec 4, 2004, 2:16 pm)
*re: Spyware & IE problems (Yap: Sat, Dec 4, 2004, 2:53 pm)
-re: Spyware & IE problems (Yap: Sat, Dec 4, 2004, 2:56 pm)
-re: Spyware & IE problems (Seth: Sat, Dec 4, 2004, 4:24 pm)
-re: Spyware & IE problems (Yap: Sat, Dec 4, 2004, 5:28 pm)
-re: Spyware & IE problems (Yap: Sat, Dec 4, 2004, 7:07 pm)
-re: Spyware & IE problems (Seth: Sat, Dec 4, 2004, 9:19 pm)
-re: Spyware & IE problems (Yap: Sat, Dec 4, 2004, 10:16 pm)
-re: Spyware & IE problems (Seth: Sat, Dec 4, 2004, 11:20 pm)
*re: Spyware & IE problems (Seth: Sun, Dec 5, 2004, 2:00 am)
-re: Spyware & IE problems (Yap: Sun, Dec 5, 2004, 2:03 am)
-re: Spyware & IE problems (Seth: Mon, Dec 6, 2004, 1:05 am)
*re: Spyware & IE problems (Yap: Mon, Dec 6, 2004, 3:12 am)
-re: Spyware & IE problems (Ms. Eagle: Sun, Dec 5, 2004, 2:19 am)
*re: Spyware & IE problems (Seth: Sun, Dec 5, 2004, 11:12 pm)
-re: Spyware & IE problems (Seth: Mon, Dec 6, 2004, 1:13 am)
*re: Spyware & IE problems (Ms. Eagle: Mon, Dec 6, 2004, 7:30 am)
Return to the Windows XP Discussion Forum


All content at Annoyances.org is Copyright © 1995-2009 Creative Elementtm All rights reserved.
Please do not plagiarize; redistributing these pages without permission is strictly prohibited.