big trouble
|
|
Member
|
11. February 2007 @ 20:25 |
Link to this message
|
Okay my computer is really starting to screw itself over... alot.
I ran Spybot and Ad-Aware. and found a few problems, located them and used secure shredder (i dont trust Ad-Aware to get rid of malicious files) to really get rid of them. all but a few.
one of them lies in C:\System volume Information, according to Ad-Aware.
but no file is called that. its mind boggling.
another thing that those programs didnt pick up on that i thought was a problem was in C:\WINDOWS\system32 two files called "taskkill" and "tasklist". both of them are .exe
i didnt touch them incase they are important, but im thinking that those are whats keeping me from opening the task manager.
any help would be greatly appreciated
|
Advertisement
|
  |
|
kateman
Senior Member
|
11. February 2007 @ 20:52 |
Link to this message
|
taskkill = infected with a trojan known as 'abebot'
tasklist.exe should not be disabled, its required for essential applications to work properly
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
kateman
Senior Member
|
11. February 2007 @ 20:53 |
Link to this message
|
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
kateman
Senior Member
|
11. February 2007 @ 20:53 |
Link to this message
|
also, why not trust adaware?
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
Member
|
11. February 2007 @ 20:54 |
Link to this message
|
I was just about to edit that into my last post
Logfile of HijackThis v1.99.1
Scan saved at 2:49:56 AM, on 12/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\outlook\outlook.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\Tyler\LOCALS~1\Temp\exbaqt2718.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\mspaint.exe
C:\HJT\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\RunOnce: [SpybotDeletingA9639] command /c del "C:\Program Files\NewDotNet\newdotnet6_38.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5010] cmd /c del "C:\Program Files\NewDotNet\newdotnet6_38.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB5361] command /c del "C:\Program Files\NewDotNet\newdotnet6_38.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1891] cmd /c del "C:\Program Files\NewDotNet\newdotnet6_38.dll_tobedeleted_old"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
|
Member
|
11. February 2007 @ 20:56 |
Link to this message
|
Originally posted by kateman: also, why not trust adaware?
it has, in the past, told me that a mark selection was deleted, but showed up on the second and third scan.. but the shredder does the trick. takes more time, but i have alot of it to spare
|
kateman
Senior Member
|
11. February 2007 @ 20:57 |
Link to this message
|
never come across that before. old version or a glitch
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
Member
|
11. February 2007 @ 21:01 |
Link to this message
|
could be either, i havent updated it for a while, i should look into that
Edit: nope im running on the latest version, so i dont know what the dealio is
This message has been edited since posting. Last time this message was edited on 11. February 2007 @ 21:05
|
kateman
Senior Member
|
11. February 2007 @ 21:05 |
Link to this message
|
delete these:
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
04 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
i'd go into
C:\Program Files\NewDotNet\
and delete everything you see if i was you
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
Member
|
11. February 2007 @ 21:09 |
Link to this message
|
Quote: i'd go into
C:\Program Files\NewDotNet\
and delete everything you see if i was you
ive done that a couple times, all the things (including the folder) just keep re-appearing when i go up a folder then back into program files. so im gonna run Spybot next time i startup.. wich will be at the end of this post...
|
kateman
Senior Member
|
11. February 2007 @ 21:11 |
Link to this message
|
haha Spybot :P
it wont do any good
i can see that it has already tried 4 times before
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
kateman
Senior Member
|
11. February 2007 @ 21:19 |
Link to this message
|
How to I Remove SaveNow or NewDotNet?
Both of these programs can generally be removed through the Add/Remove Programs Control Panel under Normal Circumstances.
1) Click on Start, Control Panel, Add/Remove Programs
2) For SaveNow, search for Save!, SaveNow, or WhenUShop entries and click on Change/Remove to remove them
3) For NewDotNet, look for New.Net Domains and choose to Remove it.
4) Reboot your computer and SaveNow and NewdotNet should be removed.
What if These Steps Didnt Work?
For NewDotNet, sometimes the normal procedures do not work. If this is the case, follow the instructions below for more advanced removal of NewDotNet.
NewDotNet Removal PROCEDURE 2 (Uninstall from Hard Drive):
1. Double-click on My Computer.
2. Double-click on the C: drive.
3. Double-click on the Program Files folder.
4. Locate and double-click on the NewDotNet folder. If there is nofolder, please proceed to PROCEDURE 3.
5. Locate and double-click on the uninstall executable; it willbe labeled uninstallX_XX.exe. (?X? represents the version number of the uninstaller)
6. After removal of our software, you may be prompted to reboot.
Please reboot after removing our software.
7. If this does not fully remove our software, please proceed to PROCEDURE 3.
NewDotNet Removal PROCEDURE 3 (Locate Backup Copy of Uninstaller and Uninstall from Hard Drive):
1. Double-click on My Computer.
2. Double-click on the C: drive.
3. Double-click on the Windows or Winnt folder.
4. Locate and double-click on the uninstall executable; it will be labeled NDNuninstallX_XX.exe. (?X? represents the version number of the uninstaller)
5. After removal of our software, you may be prompted to reboot. Please reboot after removing our software.
6. If this does not fully remove our software, please proceed to PROCEDURE 4.
NewDotNet Removal PROCEDURE 4 (Download Uninstall from New.net):
1. From a computer that has Internet access, click on the following link:
http://www.new.net/support/uninstall7_22.exe
2. Download and save uninstall7_22.exe to a 3-½ floppy disk.
3. Insert the floppy disk into the floppy drive of the computer that needs to have our software uninstalled from.
4. Click on Start.
5. Click on Run.
6. In the Open window, type A:\uninstall7_22.exe.
7. Click on the OK button.
8. After removal of our software, you may be prompted to reboot. Please reboot after removing our software.
If the above 4 procedures do not fully remove our software, please contact New.net Customer Support at (626) 405-2000 or at
support@new.net.
Ok, I've Removed NewDotNet but now my browser does not work, What Now?
Because New.Net affects the Internet access on a computer, sometimes after removing it, you wont be able to go anywhere on the Internet. If this happens, follow these instructions.
1. From a computer that has Internet access, click on one of the following links and download the program:
LSPFix by Cexx.org
Winsock XP Fix
2. Download and save one of these programs to a 3-½ floppy disk.
3. Insert the floppy disk into the floppy drive of the computer that needs to have our software uninstalled from.
4. Open My Computer on the infected system.
5. Double-click on Drive A.
6. Run the WinsockXPFix file or the LSPfix file to fix broken Winsock connections
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
Member
|
11. February 2007 @ 21:42 |
Link to this message
|
okay procedure 1-3 doesnt work. the others wont be possible because i dont have a floppy drive. nor do i have a memory stick that'll work. i keep dropping them.. this is starting to get weird
|
Member
|
11. February 2007 @ 21:53 |
Link to this message
|
okay, check this one to see if its still there
Logfile of HijackThis v1.99.1
Scan saved at 3:52:13 AM, on 12/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\system32\HPZipm12.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
|
kateman
Senior Member
|
11. February 2007 @ 22:54 |
Link to this message
|
weird, its gone. perhaps post another one tommorow or after you restart it. if its gone then, its gone for now.
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|
Member
|
12. February 2007 @ 06:34 |
Link to this message
|
alright day 2.. heres the latest HijackThis log
Logfile of HijackThis v1.99.1
Scan saved at 12:31:23 PM, on 12/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
another thing,,, how should i get rid of the 'taskkill'?
This message has been edited since posting. Last time this message was edited on 12. February 2007 @ 06:45
|
Advertisement
|
  |
|
kateman
Senior Member
|
12. February 2007 @ 20:12 |
Link to this message
|
not sure, i'd delete it
nope clean :D
help the monkeys are attacking me! dont worry, i fed the monkeys a banana, so now their off fighting a cat. i like the snow but the rain burns my skin. i can build a fort but thefhsfhkfnkjdsfikdgkjnbgjk...
|