Home » Spyware Protection » Hijacked Browser Analysis » 

Re: HijackThisLog Analysis - Lime

Date: Wednesday, 13 October, 2004 5:19 AM

Remember DO NOT run hijackthis.exe inside the zip file.  Unzip (extract) it to your desktop then double click on "HijackThis.exe" icon in this way a backup for the removed key will be created on your desktop (useful if you remove them wrongly).

Here is what you should do.

Remove these search keys:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\vzazo.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\vzazo.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\vzazo.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\vzazo.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\vzazo.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\vzazo.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\vzazo.dll/sp.html#29126
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing

Remove these additional browser plug-in keys (O2...O4):

O4 - HKLM\..\RunServices: [D3JT.EXE] C:\WINDOWS\SYSTEM\D3JT.EXE
O4 - HKLM\..\RunServices: [CRJA32.EXE] C:\WINDOWS\SYSTEM\CRJA32.EXE
O4 - HKLM\..\RunServices: [JAVAUH32.EXE] C:\WINDOWS\SYSTEM\JAVAUH32.EXE
O4 - HKLM\..\RunServices: [IEVB.EXE] C:\WINDOWS\SYSTEM\IEVB.EXE
O4 - HKLM\..\RunServices: [IPVJ32.EXE] C:\WINDOWS\IPVJ32.EXE
O4 - HKLM\..\RunServices: [NETGQ32.EXE] C:\WINDOWS\NETGQ32.EXE
O4 - HKLM\..\RunServices: [ADDOA.EXE] C:\WINDOWS\ADDOA.EXE
O4 - HKLM\..\RunServices: [NETKL32.EXE] C:\WINDOWS\NETKL32.EXE
O4 - HKLM\..\RunServices: [SYSXV32.EXE] C:\WINDOWS\SYSTEM\SYSXV32.EXE
O4 - HKLM\..\RunServices: [CRHA.EXE] C:\WINDOWS\SYSTEM\CRHA.EXE
O4 - HKLM\..\RunServices: [SYSQB.EXE] C:\WINDOWS\SYSQB.EXE
O4 - HKLM\..\RunServices: [WINIS32.EXE] C:\WINDOWS\WINIS32.EXE
O4 - HKLM\..\RunServices: [MSOG32.EXE] C:\WINDOWS\MSOG32.EXE
O4 - HKLM\..\RunServices: [MSMP.EXE] C:\WINDOWS\SYSTEM\MSMP.EXE
O4 - HKLM\..\RunServices: [ADDSJ32.EXE] C:\WINDOWS\SYSTEM\ADDSJ32.EXE
O4 - HKLM\..\RunServices: [CREU32.EXE] C:\WINDOWS\CREU32.EXE
O4 - HKLM\..\RunServices: [ADDCP.EXE] C:\WINDOWS\SYSTEM\ADDCP.EXE
O4 - HKLM\..\RunServices: [IPFR.EXE] C:\WINDOWS\SYSTEM\IPFR.EXE
O4 - HKLM\..\RunServices: [APPXE.EXE] C:\WINDOWS\APPXE.EXE
O4 - HKLM\..\RunServices: [SYSPC.EXE] C:\WINDOWS\SYSTEM\SYSPC.EXE
O4 - HKLM\..\RunServices: [SYSFI.EXE] C:\WINDOWS\SYSTEM\SYSFI.EXE
O4 - HKLM\..\RunServices: [MSBF32.EXE] C:\WINDOWS\SYSTEM\MSBF32.EXE
O4 - HKLM\..\RunServices: [ATLMP.EXE] C:\WINDOWS\ATLMP.EXE
O4 - HKLM\..\RunServices: [NETDT.EXE] C:\WINDOWS\NETDT.EXE
O4 - HKLM\..\RunServices: [IEKW.EXE] C:\WINDOWS\SYSTEM\IEKW.EXE
O4 - HKLM\..\RunServices: [APIYZ32.EXE] C:\WINDOWS\APIYZ32.EXE
O4 - HKLM\..\RunServices: [MFCZZ.EXE] C:\WINDOWS\SYSTEM\MFCZZ.EXE
O4 - HKLM\..\RunServices: [WINON.EXE] C:\WINDOWS\WINON.EXE
O4 - HKLM\..\RunServices: [IEUI.EXE] C:\WINDOWS\SYSTEM\IEUI.EXE
O4 - HKLM\..\RunServices: [SDKND.EXE] C:\WINDOWS\SYSTEM\SDKND.EXE
O4 - HKLM\..\RunServices: [IPAW32.EXE] C:\WINDOWS\SYSTEM\IPAW32.EXE
O4 - HKLM\..\RunServices: [NETQN.EXE] C:\WINDOWS\SYSTEM\NETQN.EXE
O4 - HKLM\..\RunServices: [NTLE.EXE] C:\WINDOWS\SYSTEM\NTLE.EXE
O4 - HKLM\..\RunServices: [APIIR.EXE] C:\WINDOWS\SYSTEM\APIIR.EXE
O4 - HKLM\..\RunServices: [D3HJ32.EXE] C:\WINDOWS\SYSTEM\D3HJ32.EXE
O4 - HKLM\..\RunServices: [SDKJB.EXE] C:\WINDOWS\SYSTEM\SDKJB.EXE
O4 - HKLM\..\RunServices: [NTGZ32.EXE] C:\WINDOWS\NTGZ32.EXE
O4 - HKLM\..\RunServices: [SYSTS32.EXE] C:\WINDOWS\SYSTEM\SYSTS32.EXE
O4 - HKLM\..\RunServices: [JAVAAD.EXE] C:\WINDOWS\SYSTEM\JAVAAD.EXE
O4 - HKLM\..\RunServices: [MSFF32.EXE] C:\WINDOWS\MSFF32.EXE
O4 - HKLM\..\RunServices: [SDKKY32.EXE] C:\WINDOWS\SYSTEM\SDKKY32.EXE
O4 - HKLM\..\RunServices: [IPHD.EXE] C:\WINDOWS\SYSTEM\IPHD.EXE
O4 - HKLM\..\RunServices: [NTAR.EXE] C:\WINDOWS\NTAR.EXE
O4 - HKLM\..\RunServices: [NETCX.EXE] C:\WINDOWS\SYSTEM\NETCX.EXE
O4 - HKLM\..\RunServices: [D3US32.EXE] C:\WINDOWS\D3US32.EXE
O4 - HKLM\..\RunServices: [D3LG32.EXE] C:\WINDOWS\SYSTEM\D3LG32.EXE
O4 - HKLM\..\RunServices: [NETTL32.EXE] C:\WINDOWS\SYSTEM\NETTL32.EXE
O4 - HKLM\..\RunServices: [SDKLC.EXE] C:\WINDOWS\SDKLC.EXE
O4 - HKLM\..\RunServices: [MFCXD32.EXE] C:\WINDOWS\SYSTEM\MFCXD32.EXE
O4 - HKLM\..\RunServices: [SDKYI.EXE] C:\WINDOWS\SDKYI.EXE
O4 - HKLM\..\RunServices: [D3DJ.EXE] C:\WINDOWS\D3DJ.EXE
O4 - HKLM\..\RunServices: [JAVAWT.EXE] C:\WINDOWS\JAVAWT.EXE
O4 - HKLM\..\RunServices: [SDKFZ.EXE] C:\WINDOWS\SDKFZ.EXE
O4 - HKLM\..\RunServices: [JAVAKA.EXE] C:\WINDOWS\JAVAKA.EXE
O4 - HKLM\..\RunServices: [MFCMK.EXE] C:\WINDOWS\SYSTEM\MFCMK.EXE

Remove these ActiveX Objects (aka Downloaded Program Files) if you are not using them (O16):

O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - http://www.shizmoo.com/activex/web588.cab
O16 - DPF: {11111111-1111-1111-1111-111111111123} - file://c:\Recycled\1.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\explorer.cab
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\MSOPT.DLL (file missing)

Original log but with private information removed.


Logfile of HijackThis v1.98.2
Scan saved at 03:50:02, on 12.10.04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.51 SP2

Running processes:
C: \ WINDOWS \ SYSTEM \ KERNEL32.DLL
C: \ WINDOWS \ SYSTEM \ MSGSRV32.EXE
C: \ WINDOWS \ SYSTEM \ MPREXE.EXE
C: \ WINDOWS \ EXPLORER.EXE
C: \ WINDOWS \ SYSTEM \ DDHELP.EXE
C: \ WINDOWS \ SKRIVEBORD \ HIJACKTHIS.EXE
C: \ WINDOWS \ NOTEPAD.EXE

R1 - HKCU \ Software \ Microsoft \ Internet Explorer,SearchURL = about:blank
R1 - HKLM \ Software \ Microsoft \ Internet Explorer,SearchURL = about:blank
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Search Bar = res: / / C: \ WINDOWS \ system \ vzazo.dll / sp.html#29126
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Search Page = res: / / C: \ WINDOWS \ system \ vzazo.dll / sp.html#29126
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Default_Page_URL = about:blank
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Default_Search_URL = res: / / C: \ WINDOWS \ system \ vzazo.dll / sp.html#29126
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Search Bar = res: / / C: \ WINDOWS \ system \ vzazo.dll / sp.html#29126
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main,Search Page = res: / / C: \ WINDOWS \ system \ vzazo.dll / sp.html#29126
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Search,SearchAssistant = res: / / C: \ WINDOWS \ system \ vzazo.dll / sp.html#29126
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search,SearchAssistant = res: / / C: \ WINDOWS \ system \ vzazo.dll / sp.html#29126
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main,Local Page =
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
F1 - win.ini: run=C: \ MANDATUM \ MERKEDAG.EXE
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C: \ PROGRAMFILER \ ADOBE \ ACROBAT 5.0 \ READER \ ACTIVEX \ ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C: \ Programfiler \ Norton AntiVirus \ NavShExt.dll
O2 - BHO: Class - {51704C8A-007A-8362-32D7-C2EE36CE9214} - C: \ WINDOWS \ D3BL32.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1044,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C: \ WINDOWS \ SYSTEM \ MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C: \ Programfiler \ Norton AntiVirus \ NavShExt.dll
O4 - HKLM \ .. \ Run: [SystemTray] SysTray.Exe
O4 - HKLM \ .. \ Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM \ .. \ Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM \ .. \ Run: [CriticalUpdate] C: \ WINDOWS \ SYSTEM \ wucrtupd.exe -startup
O4 - HKLM \ .. \ Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM \ .. \ Run: [mdac_runonce] C: \ WINDOWS \ SYSTEM \ runonce.exe
O4 - HKLM \ .. \ Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM \ .. \ Run: [ccApp] "C: \ Programfiler \ Fellesfiler \ Symantec Shared \ ccApp.exe"
O4 - HKLM \ .. \ Run: [start_forbruksmåler] C: \ Programfiler \ Telenor Plus \ Forbruksmåler \ Forbruksmåler.exe C: \ Programfiler \ Telenor Plus \ Forbruksmåler
O4 - HKLM \ .. \ RunServices: [ATIPOLAB] ati2evae.exe
O4 - HKLM \ .. \ RunServices: [Machine Debug Manager] C: \ WINDOWS \ SYSTEM \ MDM.EXE
O4 - HKLM \ .. \ RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM \ .. \ RunServices: [SchedulingAgent] C: \ WINDOWS \ SYSTEM \ mstask.exe
O4 - HKLM \ .. \ RunServices: [ScriptBlocking] "C: \ Programfiler \ Fellesfiler \ Symantec Shared \ Script Blocking \ SBServ.exe" -reg
O4 - HKLM \ .. \ RunServices: [ccSetMgr] "C: \ Programfiler \ Fellesfiler \ Symantec Shared \ ccSetMgr.exe"
O4 - HKLM \ .. \ RunServices: [ccEvtMgr] "C: \ Programfiler \ Fellesfiler \ Symantec Shared \ ccEvtMgr.exe"
O4 - HKLM \ .. \ RunServices: [D3WD.EXE] C: \ WINDOWS \ D3WD.EXE
O4 - HKLM \ .. \ RunServices: [D3JT.EXE] C: \ WINDOWS \ SYSTEM \ D3JT.EXE
O4 - HKLM \ .. \ RunServices: [CRJA32.EXE] C: \ WINDOWS \ SYSTEM \ CRJA32.EXE
O4 - HKLM \ .. \ RunServices: [JAVAUH32.EXE] C: \ WINDOWS \ SYSTEM \ JAVAUH32.EXE
O4 - HKLM \ .. \ RunServices: [IEVB.EXE] C: \ WINDOWS \ SYSTEM \ IEVB.EXE
O4 - HKLM \ .. \ RunServices: [IPVJ32.EXE] C: \ WINDOWS \ IPVJ32.EXE
O4 - HKLM \ .. \ RunServices: [NETGQ32.EXE] C: \ WINDOWS \ NETGQ32.EXE
O4 - HKLM \ .. \ RunServices: [ADDOA.EXE] C: \ WINDOWS \ ADDOA.EXE
O4 - HKLM \ .. \ RunServices: [NETKL32.EXE] C: \ WINDOWS \ NETKL32.EXE
O4 - HKLM \ .. \ RunServices: [SYSXV32.EXE] C: \ WINDOWS \ SYSTEM \ SYSXV32.EXE
O4 - HKLM \ .. \ RunServices: [CRHA.EXE] C: \ WINDOWS \ SYSTEM \ CRHA.EXE
O4 - HKLM \ .. \ RunServices: [SYSQB.EXE] C: \ WINDOWS \ SYSQB.EXE
O4 - HKLM \ .. \ RunServices: [WINIS32.EXE] C: \ WINDOWS \ WINIS32.EXE
O4 - HKLM \ .. \ RunServices: [MSOG32.EXE] C: \ WINDOWS \ MSOG32.EXE
O4 - HKLM \ .. \ RunServices: [MSMP.EXE] C: \ WINDOWS \ SYSTEM \ MSMP.EXE
O4 - HKLM \ .. \ RunServices: [ADDSJ32.EXE] C: \ WINDOWS \ SYSTEM \ ADDSJ32.EXE
O4 - HKLM \ .. \ RunServices: [CREU32.EXE] C: \ WINDOWS \ CREU32.EXE
O4 - HKLM \ .. \ RunServices: [ADDCP.EXE] C: \ WINDOWS \ SYSTEM \ ADDCP.EXE
O4 - HKLM \ .. \ RunServices: [IPFR.EXE] C: \ WINDOWS \ SYSTEM \ IPFR.EXE
O4 - HKLM \ .. \ RunServices: [APPXE.EXE] C: \ WINDOWS \ APPXE.EXE
O4 - HKLM \ .. \ RunServices: [SYSPC.EXE] C: \ WINDOWS \ SYSTEM \ SYSPC.EXE
O4 - HKLM \ .. \ RunServices: [SYSFI.EXE] C: \ WINDOWS \ SYSTEM \ SYSFI.EXE
O4 - HKLM \ .. \ RunServices: [MSBF32.EXE] C: \ WINDOWS \ SYSTEM \ MSBF32.EXE
O4 - HKLM \ .. \ RunServices: [ATLMP.EXE] C: \ WINDOWS \ ATLMP.EXE
O4 - HKLM \ .. \ RunServices: [NETDT.EXE] C: \ WINDOWS \ NETDT.EXE
O4 - HKLM \ .. \ RunServices: [IEKW.EXE] C: \ WINDOWS \ SYSTEM \ IEKW.EXE
O4 - HKLM \ .. \ RunServices: [APIYZ32.EXE] C: \ WINDOWS \ APIYZ32.EXE
O4 - HKLM \ .. \ RunServices: [MFCZZ.EXE] C: \ WINDOWS \ SYSTEM \ MFCZZ.EXE
O4 - HKLM \ .. \ RunServices: [WINON.EXE] C: \ WINDOWS \ WINON.EXE
O4 - HKLM \ .. \ RunServices: [IEUI.EXE] C: \ WINDOWS \ SYSTEM \ IEUI.EXE
O4 - HKLM \ .. \ RunServices: [SDKND.EXE] C: \ WINDOWS \ SYSTEM \ SDKND.EXE
O4 - HKLM \ .. \ RunServices: [IPAW32.EXE] C: \ WINDOWS \ SYSTEM \ IPAW32.EXE
O4 - HKLM \ .. \ RunServices: [NETQN.EXE] C: \ WINDOWS \ SYSTEM \ NETQN.EXE
O4 - HKLM \ .. \ RunServices: [NTLE.EXE] C: \ WINDOWS \ SYSTEM \ NTLE.EXE
O4 - HKLM \ .. \ RunServices: [APIIR.EXE] C: \ WINDOWS \ SYSTEM \ APIIR.EXE
O4 - HKLM \ .. \ RunServices: [D3HJ32.EXE] C: \ WINDOWS \ SYSTEM \ D3HJ32.EXE
O4 - HKLM \ .. \ RunServices: [SDKJB.EXE] C: \ WINDOWS \ SYSTEM \ SDKJB.EXE
O4 - HKLM \ .. \ RunServices: [NTGZ32.EXE] C: \ WINDOWS \ NTGZ32.EXE
O4 - HKLM \ .. \ RunServices: [SYSTS32.EXE] C: \ WINDOWS \ SYSTEM \ SYSTS32.EXE
O4 - HKLM \ .. \ RunServices: [JAVAAD.EXE] C: \ WINDOWS \ SYSTEM \ JAVAAD.EXE
O4 - HKLM \ .. \ RunServices: [MSFF32.EXE] C: \ WINDOWS \ MSFF32.EXE
O4 - HKLM \ .. \ RunServices: [SDKKY32.EXE] C: \ WINDOWS \ SYSTEM \ SDKKY32.EXE
O4 - HKLM \ .. \ RunServices: [IPHD.EXE] C: \ WINDOWS \ SYSTEM \ IPHD.EXE
O4 - HKLM \ .. \ RunServices: [NTAR.EXE] C: \ WINDOWS \ NTAR.EXE
O4 - HKLM \ .. \ RunServices: [NETCX.EXE] C: \ WINDOWS \ SYSTEM \ NETCX.EXE
O4 - HKLM \ .. \ RunServices: [D3US32.EXE] C: \ WINDOWS \ D3US32.EXE
O4 - HKLM \ .. \ RunServices: [D3LG32.EXE] C: \ WINDOWS \ SYSTEM \ D3LG32.EXE
O4 - HKLM \ .. \ RunServices: [NETTL32.EXE] C: \ WINDOWS \ SYSTEM \ NETTL32.EXE
O4 - HKLM \ .. \ RunServices: [SDKLC.EXE] C: \ WINDOWS \ SDKLC.EXE
O4 - HKLM \ .. \ RunServices: [MFCXD32.EXE] C: \ WINDOWS \ SYSTEM \ MFCXD32.EXE
O4 - HKLM \ .. \ RunServices: [SDKYI.EXE] C: \ WINDOWS \ SDKYI.EXE
O4 - HKLM \ .. \ RunServices: [D3DJ.EXE] C: \ WINDOWS \ D3DJ.EXE
O4 - HKLM \ .. \ RunServices: [JAVAWT.EXE] C: \ WINDOWS \ JAVAWT.EXE
O4 - HKLM \ .. \ RunServices: [SDKFZ.EXE] C: \ WINDOWS \ SDKFZ.EXE
O4 - HKLM \ .. \ RunServices: [JAVAKA.EXE] C: \ WINDOWS \ JAVAKA.EXE
O4 - HKLM \ .. \ RunServices: [MFCMK.EXE] C: \ WINDOWS \ SYSTEM \ MFCMK.EXE
O4 - Startup: Microsoft Office.lnk = C: \ WINDOWS \ Application Data \ Microsoft \ Installer \ {00010414-78E1-11D2-B60F-006097C998E7} \ misc.exe
O4 - Startup: Configuration Utility.lnk = C: \ Programfiler \ Belkin \ 11Mbps Wireless Network \ Config.exe
O8 - Extra context menu item: Search Using Copernic - file: / / C: \ Programfiler \ Copernic 2000 \ Search Extension.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \ WINDOWS \ web \ related.htm
O9 - Extra ´Tools´ menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C: \ WINDOWS \ web \ related.htm
O9 - Extra button: (no name) - {2A465934-E5F0-11D2-91B5-00104B9C4765} - C: \ Programfiler \ Copernic 2000 \ Copernic.exe
O9 - Extra ´Tools´ menuitem: Launch Copernic - {2A465934-E5F0-11D2-91B5-00104B9C4765} - C: \ Programfiler \ Copernic 2000 \ Copernic.exe
O9 - Extra button: Copernic - {2A465936-E5F0-11D2-91B5-00104B9C4765} - C: \ Programfiler \ Copernic 2000 \ Copernic.exe
O9 - Extra button: Translate - {99EFB53C-C965-43CF-9F45-52242D134187} - file: / / C: \ Programfiler \ Copernic 2000 \ Translate.htm
O9 - Extra ´Tools´ menuitem: &Translate Using Gist-In-Time - {99EFB53C-C965-43CF-9F45-52242D134187} - file: / / C: \ Programfiler \ Copernic 2000 \ Translate.htm
O13 - WWW. Prefix: website:
O14 - IERESET.INF: START_PAGE_URL=website: online.no /
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - website: a1536.g.akamai.net / 7 / 1536 / 52 / 20011119 / qtinstall.info.apple.com / qt503 / no / win / QuickTimeInstaller.exe
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - website: shizmoo.com / activex / web588.cab
O16 - DPF: {11111111-1111-1111-1111-111111111123} - file: / / c: \ Recycled \ 1.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file: / / c: \ explorer.cab
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C: \ WINDOWS \ MSOPT.DLL (file missing)


Dimension.exe 18-Oct-2004


Mail this pageMail this page