H
My internet explore dose not work properly. I used the HijackThis software and got the following log, would you help me out
Thank
A
Logfile of HijackThis v1.97.
Scan saved at 9:09:06 PM, on 4/22/200
Platform: Windows XP SP1 (WinNT 5.01.2600
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106
Running processes
C:\WINDOWS\System32\smss.ex
C:\WINDOWS\system32\winlogon.ex
C:\WINDOWS\system32\services.ex
C:\WINDOWS\system32\lsass.ex
C:\WINDOWS\system32\svchost.ex
C:\WINDOWS\System32\svchost.ex
C:\WINDOWS\system32\spoolsv.ex
C:\WINDOWS\System32\gearsec.ex
C:\MATLAB6p5\webserver\bin\win32\matlabserver.ex
C:\WINDOWS\System32\nvsvc32.ex
C:\WINDOWS\System32\svchost.ex
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EX
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SY
C:\Program Files\Sophos SWEEP for NT\SWUPDATE.EX
C:\WINDOWS\wanmpsvc.ex
C:\WINDOWS\Explorer.EX
C:\Program Files\Dell\AccessDirect\dadapp.ex
C:\WINDOWS\System32\carpserv.ex
C:\Program Files\Common files\updmgr\updmgr.ex
C:\Program Files\Common Files\Real\Update_OB\evntsvc.ex
C:\WINDOWS\System32\ctfmon.ex
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EX
C:\Program Files\Yahoo!\Messenger\ypager.ex
C:\WINDOWS\System32\RunDLL32.ex
C:\Program Files\Sophos SWEEP for NT\ICMON.EX
C:\Program Files\adware\SpywareGuard\sgmain.ex
C:\Program Files\OpenOffice.org1.1\program\soffice.ex
C:\Program Files\adware\SpywareGuard\sgbhp.ex
C:\Program Files\Common Files\Real\Update_OB\rndal.ex
C:\Program Files\Internet Explorer\iexplore.ex
C:\Program Files\adware\Hifackthis\HijackThis.ex
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bath.ac.uk
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dl
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\adware\SpywareGuard\dlprotect.dl
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dl
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dl
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.oc
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartu
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.ex
O4 - HKLM\..\Run: [CARPService] carpserv.ex
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.ex
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRu
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquie
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.ex
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.ex
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration3
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EX
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYN
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYN
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMENam
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboo
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.ex
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.ex
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quie
O4 - HKCU\..\Run: [OfotoNow USB Detection] C:\WINDOWS\System32\RunDLL32.exe C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL,WatchForConnection OfotoNo
O4 - Startup: OpenOffice.org 1.1.lnk = C:\Program Files\OpenOffice.org1.1\program\quickstart.ex
O4 - Startup: SpywareGuard.lnk = C:\Program Files\adware\SpywareGuard\sgmain.ex
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.ex
O4 - Global Startup: InterCheck Monitor.LNK =
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EX
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Sidesearch (HKLM)
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552f
c/msSecAdv.cab?1081977708481
O16 - DPF: {78A730D4-0DF3-4B65-8DD2-BFCD433CEE30} - http://www.surfsecret.com/inst/SDROP_Installer.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38095.1763657407
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} (DoomCln Object) - http://www.microsoft.com/security/controls/DoomCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Bob Barrows - 24 Apr 2004 15:39 GMT
> Hi
> My internet explore dose not work properly. I used the HijackThis
[quoted text clipped - 3 lines]
>
> Logfile of HijackThis v1.97.7
You're better off posting this to the forum recommended at the hijackthis
website:
http://www.spywareinfo.com/forums/index.php?s=04a72cef661e0480b8c7cc19c97cfeb0&a
ct=idx
This newsgroup is for help with programming dhtml and client-side scripting.

Signature
Microsoft MVP - ASP/ASP.NET
Please reply to the newsgroup. This email account is my spam trap so I
don't check it very often. If you must reply off-line, then remove the
"NO SPAM"