This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pop-up, Even After Spyware & Ad-aware

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am trying to help my brother with his computer.

He is getting major pop-ups.

I have run, spybot S&D and Ad-Aware & Norton Anti-Virus.

After running each program twice and coming boack OK, next time I try IE, I get slammed with pop-ups, changes my home page.

I ran hijackthis and started to remove what I suspected were culprits, but I then realized I may be causing more trouble for myself.

Any help would be appreciated.

Thanks,

Chris

below is my hijackthis log:

Logfile of HijackThis v1.97.7
Scan saved at 1:14:51 AM, on 06/11/2004
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\PROGRAM FILES\SYGATE\SGSERV95.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WTOOLSA.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WSUP.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\TEMP\W.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\ODSMM.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\WINDOWS\PLAXO\1.4.2.25\INSTALLSTUB.EXE
C:\WINDOWS\WINLOGON.EXE
C:\HIJACK\HIJACKTHIS.EXE
C:\WINDOWS\DESKTOP\CS4P028.EXE
C:\WINDOWS\SYSTEM\OOLC.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50093
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50093
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50093
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [VoodooBanshee] rundll32.exe 3DBBps.dll,BansheeLoadSettings
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [vptray] c:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ODEMM] C:\WINDOWS\SYSTEM\ODEMM.exe
O4 - HKLM\..\Run: [QDKT] C:\WINDOWS\QDKT.exe
O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [W] C:\WINDOWS\TEMP\W.EXE
O4 - HKLM\..\Run: [TB_setup] C:\WINDOWS\TEMP\TB_SETUP.EXE /dcheck
O4 - HKLM\..\Run: [COMSMDEXE] comsmd.exe -off
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [mkdkj] C:\WINDOWS\odsmm.exe
O4 - HKLM\..\Run: [netcfgi] C:\WINDOWS\SYSTEM\netcfgi.exe
O4 - HKLM\..\Run: [ClrSchLoader] \Progra~1\Lycos\IEagent\Loader.exe
O4 - HKLM\..\Run: [systray] C:\WINDOWS\SYSTEM\A.EXE
O4 - HKLM\..\Run: [OOLC] C:\WINDOWS\SYSTEM\OOLC.exe
O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [SyGateService] C:\Program Files\SyGate\sgserv95.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [rtvscn95] c:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] c:\Program Files\Norton AntiVirus\defwatch.exe
O4 - HKLM\..\RunServices: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINDOWS\Plaxo\1.4.2.25\InstallStub.exe -a
O4 - HKCU\..\Run: [winlogon] c:\windows\winlogon.exe
O4 - HKCU\..\Run: [Uninstal] regsvr32 /u /s image.dll
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O9 - Extra button: Real.com (HKLM)
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: Sidesearch (HKLM)
O12 - Plugin for .mov: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPQTW32.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.travelers.com
O15 - Trusted Zone: http://*.travelerspc.com
O15 - Trusted Zone: *.greg-search.com
O16 - DPF: WebConnect Pro 5.1.7 - https://connect.travelers.com/WebConnectDU.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {9A428531-7CBF-11D3-A0E7-0060979D7EAD} (PLINQWebFunctions.PLINQHllapi) - https://plagt.travelers.com/CDE/download/Cleanup.cab
O16 - DPF: {CC3276A9-0D47-11D3-A08B-0060979D7EAD} (PLINQWebFunctions.PLINQWord) - https://plagt.travelers.com/CDE/download/PL…ebFunctions.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 199.45.32.37,151.198.0.38
Welcome to the forum.

Please look in your add/remove programs for WinTools, if found uninstall it. If you have a problem, try it in safe mode and/or bring up your task manager and end task on it, then delete it.


With only HJT running fix these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = <http://www.websearch.com/ie.aspx?tb_id=50093>

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <http://www.websearch.com/ie.aspx?tb_id=50093>

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = <http://www.websearch.com/ie.aspx?tb_id=50093>

R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL


O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL

O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

O4 - HKLM\..\Run: [TV Media] C:\TV MEDIA\TVM.EXE

O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"

O4 - HKLM\..\Run: [TB_setup] C:\WINDOWS\TEMP\TB_SETUP.EXE /dcheck

O4 - HKLM\..\Run: [ClrSchLoader] \Progra~1\Lycos\IEagent\Loader.exe

O4 - HKCU\..\Run: [winlogon] c:\windows\winlogon.exe

O4 - HKCU\..\Run: [winlogon] c:\windows\winlogon.exe

O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q

O4 - HKLM\..\Run: [systray] C:\WINDOWS\SYSTEM\A.EXE

O4 - HKLM\..\Run: [ODEMM] C:\WINDOWS\SYSTEM\ODEMM.exe

O4 - HKLM\..\Run: [QDKT] C:\WINDOWS\QDKT.exe

O4 - HKLM\..\Run: [W] C:\WINDOWS\TEMP\W.EXE

O4 - HKLM\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE

O4 - HKLM\..\Run: [mkdkj] C:\WINDOWS\odsmm.exe

O4 - HKLM\..\Run: [netcfgi] C:\WINDOWS\SYSTEM\netcfgi.exe

O4 - HKLM\..\Run: [OOLC] C:\WINDOWS\SYSTEM\OOLC.exe

O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe

O4 - HKLM\..\RunServices: [WinTools] C:\Program Files\Common files\WinTools\WToolsA.exe

O4 - HKCU\..\Run: [Uninstal] regsvr32 /u /s image.dll

Reboot into SafeMode and delete these files:
HowToShowHiddenFiles - if needed
Use ctrl, alt and delete to bring up your task manager and end task on any of these files if they are listed before you delete them.


C:\TV MEDIA <—Folder

C:\Program Files\Common files\WinTools <—Folder if it's there

c:\windows\winlogon.exe

C:\WINDOWS\QDKT.exe

C:\WINDOWS\odsmm.exe

C:\WINDOWS\SYSTEM\netcfgi.exe

C:\WINDOWS\SYSTEM\A.EXE

C:\WINDOWS\SYSTEM\ODEMM.exe

C:\WINDOWS\SYSTEM\SYSSTARTUP.EXE

C:\WINDOWS\SYSTEM\OOLC.exe

C:\Program Files\webHancer\Programs\whSurvey.exe

C:\WINDOWS\TEMP\TB_SETUP.EXE

C:\WINDOWS\TEMP\W.EXE

Progra~1\Lycos\IEagent\Loader.exe

C:\PROGRA~1\CLOCKS~1\Sync.exe

Reboot and post a frsh HJT look back here and we'll get the rest of it. MrC
Mr. C I show a program called Wintools for Internet Explorer (v2). When attempting to remove, i get the error Other ad-powered software installed. Please remove it first. I have tried this in normal and safe mode with no luck. Should I continue on or do we need to figure out how to remove it first before going to hijack. Thanks for your quick response. Chris
Mr. C,

Thanks, some of the files I could not find to delete, I am assuming HJT did it.

THANKS AGAIN FOR YOU QUICK RESPONSE AND SUPPORT!

Here is the new HJT Log:

Logfile of HijackThis v1.97.7
Scan saved at 6:20:44 PM, on 06/11/2004
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\PROGRAM FILES\SYGATE\SGSERV95.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\WINDOWS\PLAXO\1.4.2.25\INSTALLSTUB.EXE
C:\HIJACK\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [VoodooBanshee] rundll32.exe 3DBBps.dll,BansheeLoadSettings
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [vptray] c:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [COMSMDEXE] comsmd.exe -off
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [SyGateService] C:\Program Files\SyGate\sgserv95.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [rtvscn95] c:\Program Files\Norton AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] c:\Program Files\Norton AntiVirus\defwatch.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINDOWS\Plaxo\1.4.2.25\InstallStub.exe -a
O9 - Extra button: Real.com (HKLM)
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O12 - Plugin for .mov: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPQTW32.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.travelers.com
O15 - Trusted Zone: http://*.travelerspc.com
O15 - Trusted Zone: *.greg-search.com
O16 - DPF: WebConnect Pro 5.1.7 - https://connect.travelers.com/WebConnectDU.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {9A428531-7CBF-11D3-A0E7-0060979D7EAD} (PLINQWebFunctions.PLINQHllapi) - https://plagt.travelers.com/CDE/download/Cleanup.cab
O16 - DPF: {CC3276A9-0D47-11D3-A08B-0060979D7EAD} (PLINQWebFunctions.PLINQWord) - https://plagt.travelers.com/CDE/download/PL…ebFunctions.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 199.45.32.37,151.198.0.38
My friend, you're ready to rock & roll - Good Job!! ;) :thumbup:


Some preventive maintenance:

Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked. Check for updates weekly.

SpywareBlaster

SpywareGuard

Need a free anti virus?
AVG*free
(check for updates - daily)

How about a firewall?
ZoneAlarm*free
DirectDownload ZA 4.5.594.000 <—use this version for now

Free spyware removal programs:

SpyBot

AD-Aware


Good luck and thanks for using the forum - MrC
THANK YOU! THANK YOU! THANK YOU! You were able to do in one day what I in 3 weeks could not do. I made a donation at the start in good faith and I will follow up with a second donation. Keep up the good work, we need more like you! Chris
O15 - Trusted Zone: http://*.travelers.com O15 - Trusted Zone: http://*.travelerspc.com O15 - Trusted Zone: *.greg-search.com Do you recognize the above three entries in your log file. If not they need to be removed as these websites have full access to your computer. Please Scan again with HJT and post a new log file here in this thread using Add Reply and include the information about the above entries
My brother is an insurance agent so I am assuming travelers is part of the travelers insurance company which he is an agent for. So I think that is part of software he has for getting quotes. The Greg one I do not recognize. i need to look into that. Monday I am going to his office and check a few others in the office to see if that is on all of them. Thanks for noticing it, I will post back Monday afternoon. I will say, I have been running my brothers computer now for 2 days, and not one POP-UP, :thumbup:
OF these three O15 - Trusted Zone: http://*.travelers.com O15 - Trusted Zone: http://*.travelerspc.com O15 - Trusted Zone: *.greg-search.com I checked 3 other computers in the office and none had the O15 - Trusted Zone: *.greg-search.com, but all had the travelers.com one which their office is an agent for. I removed O15 - Trusted Zone: *.greg-search.com I forgot to make a hijackthis log, but it has been 5 days or so and not one pop-up. If you need me to post one more log, please advise, otherwise I would say this could be closed. Thanks again, you guys are awesome
It would probably be a good idea to make sure that the O15 is gone with a HijackThis log as it is a security breach. It is also possible that you still have some other bad files left that haven't reared their ugly heads yet so if you want us to look at the log and make sure it is clean, then post another one. We do appreciate knowing that the logs are clean Glad we could help!
Here is the Hijackthis Log from this afternoon.

Thanks, Chris

Logfile of HijackThis v1.97.7
Scan saved at 10:32:26 AM, on 06/18/2004
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\PROGRAM FILES\SYGATE\SGSERV95.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\WINDOWS\PLAXO\1.4.2.25\INSTALLSTUB.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HIJACK\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
O2 - BHO: SpywareGuard Download Protection -
{4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM
FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [VoodooBanshee] rundll32.exe
3DBBps.dll,BansheeLoadSettings
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [vptray] c:\Program Files\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe
SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [COMSMDEXE] comsmd.exe -off
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [SyGateService] C:\Program
Files\SyGate\sgserv95.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [rtvscn95] c:\Program Files\Norton
AntiVirus\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] c:\Program Files\Norton
AntiVirus\defwatch.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL
deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft
Money\System\reminder.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINDOWS\Plaxo\1.4.2.25\InstallStub.exe -a
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Real.com (HKLM)
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mov: C:\Program
Files\Netscape\Communicator\Program\PLUGINS\NPQTW32.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.travelers.com
O15 - Trusted Zone: http://*.travelerspc.com
O16 - DPF: WebConnect Pro 5.1.7 -
https://connect.travelers.com/WebConnectDU.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} -
http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {9A428531-7CBF-11D3-A0E7-0060979D7EAD}
(PLINQWebFunctions.PLINQHllapi) -
https://plagt.travelers.com/CDE/download/Cleanup.cab
O16 - DPF: {CC3276A9-0D47-11D3-A08B-0060979D7EAD}
(PLINQWebFunctions.PLINQWord) -
https://plagt.travelers.com/CDE/download/PL…ebFunctions.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/…8149.7362268519
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
199.45.32.37,151.198.0.38

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI