This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Linklist.cc,about:blank

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, folks. This is my first post on this site and I'm not that knowledgeable about computers, but I was wondering if somebody might be able to help with a Cool Web Search issue.

I had linklist for a couple of weeks before I realized it was a CWS variant. While trying to fix it, it went away and was replaced by about:blank. I seem able to get rid of it for a day but then it comes back. Any ideas on how to fix it? S&D doesn't pick it up, AdAware picks up part of it but it comes back. Same with CWSshredder and even going into Hijack This and getting the obvious ones. Is there something I'm missing?

Here's a current HJT log:



Logfile of HijackThis v1.97.7
Scan saved at 1:00:16 AM, on 4/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Documents and Settings\ \Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP40\hta\station.sbrt
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)



I also tried to follow the advice on Merijn's site to download www.zerosrealm.com/downloads/pv.zip and then past the one with
61c00000 61440 into Killbox to delete on reboot. When I checked again, it was still there.

here's the pv log.

Module information for 'iexplore.exe'
MODULE BASE SIZE PATH
iexplore.exe 400000 102400 C:\Program Files\Internet Explorer\iexplore.exe
ntdll.dll 77f50000 684032 C:\WINDOWS\System32\ntdll.dll
kernel32.dll 77e60000 942080 C:\WINDOWS\system32\kernel32.dll
msvcrt.dll 77c10000 339968 C:\WINDOWS\system32\msvcrt.dll
USER32.dll 77d40000 573440 C:\WINDOWS\system32\USER32.dll
GDI32.dll 77c70000 262144 C:\WINDOWS\system32\GDI32.dll
ADVAPI32.dll 77dd0000 577536 C:\WINDOWS\system32\ADVAPI32.dll
RPCRT4.dll 78000000 548864 C:\WINDOWS\system32\RPCRT4.dll
SHLWAPI.dll 70a70000 409600 C:\WINDOWS\system32\SHLWAPI.dll
SHDOCVW.dll 769c0000 1351680 C:\WINDOWS\System32\SHDOCVW.dll
msodk.dll 61c00000 61440 c:\windows\system32\msodk.dll
comctl32.dll 71950000 933888 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
SHELL32.dll 773d0000 8351744 C:\WINDOWS\system32\SHELL32.dll
comctl32.dll 77340000 569344 C:\WINDOWS\system32\comctl32.dll
ole32.dll 771b0000 1183744 C:\WINDOWS\system32\ole32.dll
uxtheme.dll 5ad70000 212992 C:\WINDOWS\System32\uxtheme.dll
BROWSEUI.dll 75f80000 1032192 C:\WINDOWS\System32\BROWSEUI.dll
browselc.dll 72430000 73728 C:\WINDOWS\System32\browselc.dll
appHelp.dll 75f40000 126976 C:\WINDOWS\system32\appHelp.dll
CLBCATQ.DLL 76fd0000 491520 C:\WINDOWS\System32\CLBCATQ.DLL
OLEAUT32.dll 77120000 569344 C:\WINDOWS\system32\OLEAUT32.dll
COMRes.dll 77050000 806912 C:\WINDOWS\System32\COMRes.dll
VERSION.dll 77c00000 28672 C:\WINDOWS\system32\VERSION.dll
WININET.dll 76200000 622592 C:\WINDOWS\system32\WININET.dll
CRYPT32.dll 762c0000 569344 C:\WINDOWS\system32\CRYPT32.dll
MSASN1.dll 762a0000 61440 C:\WINDOWS\system32\MSASN1.dll
Secur32.dll 76f90000 65536 C:\WINDOWS\System32\Secur32.dll
cscui.dll 76620000 319488 C:\WINDOWS\System32\cscui.dll
CSCDLL.dll 76600000 110592 C:\WINDOWS\System32\CSCDLL.dll
SETUPAPI.dll 76670000 946176 C:\WINDOWS\System32\SETUPAPI.dll
urlmon.dll 760f0000 499712 C:\WINDOWS\system32\urlmon.dll
crtv2_32.dll 10000000 32768 C:\WINDOWS\crtv2_32.dll
shdoclc.dll 71800000 557056 C:\WINDOWS\System32\shdoclc.dll
MSRATING.dll 5ff20000 143360 C:\WINDOWS\System32\MSRATING.dll
WSOCK32.dll 71ad0000 32768 C:\WINDOWS\System32\WSOCK32.dll
WS2_32.dll 71ab0000 86016 C:\WINDOWS\System32\WS2_32.dll
WS2HELP.dll 71aa0000 32768 C:\WINDOWS\System32\WS2HELP.dll
msratelc.dll 5ff50000 69632 C:\WINDOWS\System32\msratelc.dll
mlang.dll 74770000 585728 C:\WINDOWS\System32\mlang.dll
RASAPI32.dll 76ee0000 225280 C:\WINDOWS\System32\RASAPI32.dll
rasman.dll 76e90000 69632 C:\WINDOWS\System32\rasman.dll
NETAPI32.dll 71c20000 319488 C:\WINDOWS\System32\NETAPI32.dll
TAPI32.dll 76eb0000 176128 C:\WINDOWS\System32\TAPI32.dll
rtutils.dll 76e80000 53248 C:\WINDOWS\System32\rtutils.dll
WINMM.dll 76b40000 180224 C:\WINDOWS\System32\WINMM.dll
serwvdrv.dll 5cd70000 28672 C:\WINDOWS\System32\serwvdrv.dll
umdmxfrm.dll 5b0a0000 28672 C:\WINDOWS\System32\umdmxfrm.dll
sensapi.dll 722b0000 20480 C:\WINDOWS\System32\sensapi.dll
USERENV.dll 75a70000 675840 C:\WINDOWS\system32\USERENV.dll
mswsock.dll 71a50000 241664 C:\WINDOWS\system32\mswsock.dll
wshtcpip.dll 71a90000 32768 C:\WINDOWS\System32\wshtcpip.dll
rasadhlp.dll 76fc0000 20480 C:\WINDOWS\System32\rasadhlp.dll
msi.dll 1410000 2101248 C:\WINDOWS\System32\msi.dll
SXS.DLL 75e90000 684032 C:\WINDOWS\System32\SXS.DLL
DNSAPI.dll 76f20000 151552 C:\WINDOWS\System32\DNSAPI.dll
winrnr.dll 76fb0000 28672 C:\WINDOWS\System32\winrnr.dll
WLDAP32.dll 76f60000 180224 C:\WINDOWS\system32\WLDAP32.dll
mshtml.dll 74810000 2846720 C:\WINDOWS\System32\mshtml.dll
msimtf.dll 746f0000 155648 C:\WINDOWS\System32\msimtf.dll
MSCTF.dll 74720000 278528 C:\WINDOWS\System32\MSCTF.dll
IMM32.DLL 76390000 114688 C:\WINDOWS\System32\IMM32.DLL
msohev.dll 32520000 73728 C:\Program Files\Microsoft Office\Office10\msohev.dll
jscript.dll 75c50000 593920 C:\WINDOWS\System32\jscript.dll
MSLS31.DLL 746c0000 159744 C:\WINDOWS\System32\MSLS31.DLL
iepeers.dll 66e50000 241664 C:\WINDOWS\System32\iepeers.dll
WINSPOOL.DRV 73000000 143360 C:\WINDOWS\System32\WINSPOOL.DRV
mshtmled.dll 74cb0000 454656 C:\WINDOWS\System32\mshtmled.dll

Somebody on another site though that the HJT log looked clean now (I hope that this is enough) but what's been happening is that I can get the nasties to go away for a few hours (up to 24) then they come back and I have to try to get rid of them again.
I'm wondering if this has something to do with that file I mentioned. It will not die, apparently. Any ideas? Anything else that needs to go?

Thanks in advance. By the way, I don't speak computerese well.

I'm grateful for any help you have to offer.

Thanks!

C. Ch.
I can show you the nasty deleted files too, if that will help. msodk.dll 61c00000 61440 c:\windows\system32\msodk.dll is the one I mentioned being concerned about in my last post. these were on the hijack this list before I deleted them. before that, I had the same basic pattern, but different letters for the dlls. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\ddbid.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\ddbid.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\ddbid.dll/sp.html (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\ddbid.dll/sp.html (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\ddbid.dll/sp.html (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\ddbid.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: (no name) - {8B38A515-3BEE-402E-A3D4-17429369DD8C} - C:\WINDOWS\System32\ddbid.dll They're gone for the moment, but I've gotten rid of them before and they just came back after a few hours (sometimes 2 or 3, but now up to 24). Thanks!
I'm not sure how you approached your fix, but try this. In the 'Paste Full Path of File to Delete' box, copy and paste this entry:

c:\windows\system32\msodk.dll

Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". On the next screen, click on the File menu and choose "Add File". The c:\windows\system32\msodk.dll listing should show up in the window. If that's successful, choose the Action menu and select "Process and Reboot". You'll be prompted to reboot, do so.

Let us know how you get on.
Hey, Daemon. Thanks for your response. That's the way I tried to do it. After pasting in, it did not come up automatically in the new window. I clicked on "add files" and got it in there, and then followed the rest of the instructions. One other note: I've also tried CWShredder and Hijack This in Safe Mode. When I do that, it removes CWS msconfig. If I use shredder again right then, it says it's clean. Next time I go in, though, it removes the same thing. Yesterday it removed SearchX and the day before it was removing 6 files, but then I'd run it again and it would get the same stuff. Your advice to do the remove at reboot was the same as Merijn's site. What happens if you try to do it with the buttons? Nothing? Something bad? Is there some other way to get rid of the dll?
By the way, Daemon, I sent you a message on the SWI forum about this. If it looks familiar, that's why. I'm Zarathustra over there. Would you rather talk about this here or there? Thank you SOOO much for your help. I'm really ready for this thing to go away. I've lost 4 days on it, so far. Just in the process of checking this, About:blank came back. I did this the same way you described before, but I just tried it again. This is the report after trying again and also after the recurrence. Module information for 'iexplore.exe' MODULE BASE SIZE PATH iexplore.exe 400000 102400 C:\Program Files\Internet Explorer\iexplore.exe ntdll.dll 77f50000 684032 C:\WINDOWS\System32\ntdll.dll kernel32.dll 77e60000 942080 C:\WINDOWS\system32\kernel32.dll msvcrt.dll 77c10000 339968 C:\WINDOWS\system32\msvcrt.dll USER32.dll 77d40000 573440 C:\WINDOWS\system32\USER32.dll GDI32.dll 77c70000 262144 C:\WINDOWS\system32\GDI32.dll ADVAPI32.dll 77dd0000 577536 C:\WINDOWS\system32\ADVAPI32.dll RPCRT4.dll 78000000 548864 C:\WINDOWS\system32\RPCRT4.dll SHLWAPI.dll 70a70000 409600 C:\WINDOWS\system32\SHLWAPI.dll SHDOCVW.dll 769c0000 1351680 C:\WINDOWS\System32\SHDOCVW.dll msodk.dll 61c00000 61440 c:\windows\system32\msodk.dll comctl32.dll 71950000 933888 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll SHELL32.dll 773d0000 8351744 C:\WINDOWS\system32\SHELL32.dll comctl32.dll 77340000 569344 C:\WINDOWS\system32\comctl32.dll ole32.dll 771b0000 1183744 C:\WINDOWS\system32\ole32.dll uxtheme.dll 5ad70000 212992 C:\WINDOWS\System32\uxtheme.dll BROWSEUI.dll 75f80000 1032192 C:\WINDOWS\System32\BROWSEUI.dll browselc.dll 72430000 73728 C:\WINDOWS\System32\browselc.dll appHelp.dll 75f40000 126976 C:\WINDOWS\system32\appHelp.dll CLBCATQ.DLL 76fd0000 491520 C:\WINDOWS\System32\CLBCATQ.DLL OLEAUT32.dll 77120000 569344 C:\WINDOWS\system32\OLEAUT32.dll COMRes.dll 77050000 806912 C:\WINDOWS\System32\COMRes.dll VERSION.dll 77c00000 28672 C:\WINDOWS\system32\VERSION.dll WININET.dll 76200000 622592 C:\WINDOWS\system32\WININET.dll CRYPT32.dll 762c0000 569344 C:\WINDOWS\system32\CRYPT32.dll MSASN1.dll 762a0000 61440 C:\WINDOWS\system32\MSASN1.dll Secur32.dll 76f90000 65536 C:\WINDOWS\System32\Secur32.dll cscui.dll 76620000 319488 C:\WINDOWS\System32\cscui.dll CSCDLL.dll 76600000 110592 C:\WINDOWS\System32\CSCDLL.dll SETUPAPI.dll 76670000 946176 C:\WINDOWS\System32\SETUPAPI.dll USERENV.dll 75a70000 675840 C:\WINDOWS\system32\USERENV.dll kedmbh.dll 10000000 53248 C:\WINDOWS\System32\kedmbh.dll urlmon.dll 760f0000 499712 C:\WINDOWS\system32\urlmon.dll mshtml.dll 74810000 2846720 C:\WINDOWS\System32\mshtml.dll crtv2_32.dll c80000 32768 C:\WINDOWS\crtv2_32.dll shdoclc.dll 71800000 557056 C:\WINDOWS\System32\shdoclc.dll MSRATING.dll 5ff20000 143360 C:\WINDOWS\System32\MSRATING.dll WSOCK32.dll 71ad0000 32768 C:\WINDOWS\System32\WSOCK32.dll WS2_32.dll 71ab0000 86016 C:\WINDOWS\System32\WS2_32.dll WS2HELP.dll 71aa0000 32768 C:\WINDOWS\System32\WS2HELP.dll msratelc.dll 5ff50000 69632 C:\WINDOWS\System32\msratelc.dll MLANG.dll 74770000 585728 C:\WINDOWS\System32\MLANG.dll msi.dll 1500000 2101248 C:\WINDOWS\System32\msi.dll SXS.DLL 75e90000 684032 C:\WINDOWS\System32\SXS.DLL msimtf.dll 746f0000 155648 C:\WINDOWS\System32\msimtf.dll MSCTF.dll 74720000 278528 C:\WINDOWS\System32\MSCTF.dll MSLS31.DLL 746c0000 159744 C:\WINDOWS\System32\MSLS31.DLL IMM32.DLL 76390000 114688 C:\WINDOWS\System32\IMM32.DLL msohev.dll 32520000 73728 C:\Program Files\Microsoft Office\Office10\msohev.dll jscript.dll 75c50000 593920 C:\WINDOWS\System32\jscript.dll here's a new log from HJT: Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\cisvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe C:\WINDOWS\NOTEPAD.EXE C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\\Local Settings\Temp\Temporary Directory 35 for hijackthis.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\kedmbh.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\kedmbh.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\kedmbh.dll/sp.html (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\kedmbh.dll/sp.html (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\kedmbh.dll/sp.html (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\kedmbh.dll/sp.html (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe O2 - BHO: (no name) - {92AA6119-7DE5-4282-9724-6556D1DA6BFE} - C:\WINDOWS\System32\kedmbh.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP40\hta\station.sbrt O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button: Real.com (HKLM) O9 - Extra button: MoneySide (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) By the way, Daemon, I sent you a message on the SWI forum about this. If it looks familiar, that's why. I'm Zarathustra over there. Would you rather talk about this here or there? Thank you SOOO much for your help. I'm really ready for this thing to go away. I've lost 4 days on it, so far.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI