PDA

View Full Version : CoolSearch log won't get removed-log posted



Tudds
2006-02-06, 21:05
Not sure if the end part matters but spybot can't remove this....
It tells me to reboot and I did it 3 times so far but it never removes it :(
--- Search result list ---
CoolWWWSearch.HomeSearch: Data (File, fixing failed)
C:\WINDOWS\lbdyo.log


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-06-28 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-03 Includes\Cookies.sbi (*)
2006-02-03 Includes\Dialer.sbi (*)
2006-02-03 Includes\Hijackers.sbi (*)
2006-02-03 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-02-03 Includes\Malware.sbi (*)
2006-02-03 Includes\PUPS.sbi (*)
2006-02-03 Includes\Revision.sbi (*)
2006-02-03 Includes\Security.sbi (*)
2006-02-03 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-02-03 Includes\Trojans.sbi (*)



--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB886906)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Service Pack 3 (KB867461)
/ Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB898458)
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB867282
/ Windows XP / SP3: Windows XP Hotfix - KB873333
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Security Update for Windows XP (KB883939)
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB885884
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890047
/ Windows XP / SP3: Windows XP Hotfix - KB890175
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB890923
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Windows XP Hotfix - KB893086
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Security Update for Windows XP (KB896688)
/ Windows XP / SP3: Update for Windows XP (KB896727)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899588)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB903235)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Security Update for Windows XP (KB912919)


--- Startup entries list ---
Located: HK_LM:Run, {0228e555-4f9c-4e35-a3ec-b109a192b4c2}
command: C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
file: C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
size: 479232
MD5: 3df7ac30a381c57d0c70eaefee3c4ef2

Located: HK_LM:Run, addoa32.exe
command: C:\WINDOWS\system32\addoa32.exe
file: C:\WINDOWS\system32\addoa32.exe
size: 35959
MD5: 0b2e6ad2fc0900d0686b966f4a0ac89b

Located: HK_LM:Run, apidi32.exe
command: C:\WINDOWS\system32\apidi32.exe
file:

Located: HK_LM:Run, apiet32.exe
command: C:\WINDOWS\system32\apiet32.exe
file:

Located: HK_LM:Run, apiif.exe
command: C:\WINDOWS\apiif.exe
file:

Located: HK_LM:Run, apivc32.exe
command: C:\WINDOWS\system32\apivc32.exe
file:

Located: HK_LM:Run, appws.exe
command: C:\WINDOWS\system32\appws.exe
file:

Located: HK_LM:Run, atlgm32.exe
command: C:\WINDOWS\atlgm32.exe
file:

Located: HK_LM:Run, atlkn.exe
command: C:\WINDOWS\atlkn.exe
file:

Located: HK_LM:Run, ccApp
command: "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: c:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 54296
MD5: ace91f1db4e08fa62c758adf2390c07e

Located: HK_LM:Run, ccRegVfy
command: "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
file: c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
size: 58392
MD5: 8ab27947c7c2b3388f15ce7c3d595050

Located: HK_LM:Run, d3td.exe
command: C:\WINDOWS\system32\d3td.exe
file:

Located: HK_LM:Run, d3us.exe
command: C:\WINDOWS\d3us.exe
file:

Located: HK_LM:Run, EPSON Stylus CX6400
command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
size: 99840
MD5: 043a77336c3092a1fe30a85342149269

Located: HK_LM:Run, HotKeysCmds
command: C:\WINDOWS\System32\hkcmd.exe
file: C:\WINDOWS\System32\hkcmd.exe
size: 114688
MD5: 4ec9b66aa45683b89d58c3b2c3e64e49

Located: HK_LM:Run, hpsysdrv
command: c:\windows\system\hpsysdrv.exe
file: c:\windows\system\hpsysdrv.exe
size: 52736
MD5: 06a1ecb63df139ec639e084d4ab3c9d7

Located: HK_LM:Run, ieya32.exe
command: C:\WINDOWS\ieya32.exe
file:

Located: HK_LM:Run, ipdf.exe
command: C:\WINDOWS\ipdf.exe
file:

Located: HK_LM:Run, ipkz.exe
command: C:\WINDOWS\system32\ipkz.exe
file:

Located: HK_LM:Run, ipnx32.exe
command: C:\WINDOWS\system32\ipnx32.exe
file:

Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 274432
MD5: 1c2b9fcd48112b0297b83e7fc43d1b42

Located: HK_LM:Run, javarc.exe
command: C:\WINDOWS\javarc.exe
file:

Located: HK_LM:Run, mfccb32.exe
command: C:\WINDOWS\system32\mfccb32.exe
file:

Located: HK_LM:Run, mfcgo.exe
command: C:\WINDOWS\mfcgo.exe
file:

Located: HK_LM:Run, mseg.exe
command: C:\WINDOWS\mseg.exe
file:

Located: HK_LM:Run, msum32.exe
command: C:\WINDOWS\msum32.exe
file:

Located: HK_LM:Run, NeroFilterCheck
command: C:\WINDOWS\system32\NeroCheck.exe
file: C:\WINDOWS\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90

Located: HK_LM:Run, nthv32.exe
command: C:\WINDOWS\nthv32.exe
file:

Located: HK_LM:Run, ntkq32.exe
command: C:\WINDOWS\ntkq32.exe
file:

Located: HK_LM:Run, ntpk32.exe
command: C:\WINDOWS\system32\ntpk32.exe
file:

Located: HK_LM:Run, ntpu.exe
command: C:\WINDOWS\system32\ntpu.exe
file:

Located: HK_LM:Run, ntpw32.exe
command: C:\WINDOWS\system32\ntpw32.exe
file:

Located: HK_LM:Run, ntxg32.exe
command: C:\WINDOWS\system32\ntxg32.exe
file:

Located: HK_LM:Run, ntxr32.exe
command: C:\WINDOWS\ntxr32.exe
file:

Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, NvMediaCenter
command: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, NWEReboot
command:
file:

Located: HK_LM:Run, nwiz
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1519616
MD5: 2c598564c621436a8bdc1d2912c2e3dd

Located: HK_LM:Run, PS2
command: C:\WINDOWS\system32\ps2.exe
file: C:\WINDOWS\system32\ps2.exe
size: 81920
MD5: c4c523e78774e05d06efe3e10017cf6d

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: 3e7d91f24d28c968b92c85c7e2882eed

Located: HK_LM:Run, Recguard
command: C:\WINDOWS\SMINST\RECGUARD.EXE
file: C:\WINDOWS\SMINST\RECGUARD.EXE
size: 212992
MD5: d3cc7a3813123e955b3a497c04b404e2

Located: HK_LM:Run, sdkly.exe
command: C:\WINDOWS\sdkly.exe
file:

Located: HK_LM:Run, sdkrj.exe
command: C:\WINDOWS\system32\sdkrj.exe
file:

Located: HK_LM:Run, sdkyj.exe
command: C:\WINDOWS\system32\sdkyj.exe
file:

LonnyRJones
2006-02-08, 00:53
Tudds Hi
Please go here and follow instructions.
"Before you post a log"
http://forums.spybot.info/showthread.php?t=288
Post the hjt log here in this thread.
Someone will then take a look at the system and advise you.

Tudds
2006-02-08, 02:43
Logfile of HijackThis v1.99.1
Scan saved at 8:43:53 PM, on 2/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\apidm.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winkn.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Tonio\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {072E058D-3046-1956-68F1-D9BA95C696E9} - (no file)
O2 - BHO: (no name) - {0A9850AB-BEFF-800A-BCCF-27897A9AC53A} - (no file)
O2 - BHO: (no name) - {0CDCC695-26E8-8B05-0DE0-344FBFCD407F} - (no file)
O2 - BHO: (no name) - {0DCB855C-7AF4-46FC-F0C0-27DCB8195678} - (no file)
O2 - BHO: (no name) - {0FBD6D56-852E-81B0-D541-08A7403661DC} - (no file)
O2 - BHO: (no name) - {179408EE-D094-77D5-2292-789A736D6E90} - (no file)
O2 - BHO: Class - {1A2FCB78-BCDE-411A-2F9F-AE7FEB55F327} - C:\WINDOWS\sysxr.dll
O2 - BHO: (no name) - {1B7868F3-747F-F324-23F0-1A3EC3D2C170} - (no file)
O2 - BHO: Class - {1BB06227-02D6-8AE4-475A-58D02CC66F9A} - C:\WINDOWS\crsd.dll
O2 - BHO: (no name) - {26292D92-C47D-8978-68F1-EADFBF80E5DD} - (no file)
O2 - BHO: (no name) - {28A5C3A0-8EDD-4FB2-1F3A-10A98544D413} - (no file)
O2 - BHO: (no name) - {2C14596F-F821-7151-8E15-D6C625BA9326} - (no file)
O2 - BHO: Class - {2CEDF703-7B1D-11EA-9346-27AA2F77086D} - C:\WINDOWS\system32\netft32.dll
O2 - BHO: (no name) - {3A1BDA7E-F499-48DE-E72D-92C016F9B8A9} - (no file)
O2 - BHO: (no name) - {3F1BB4CB-FD6D-A0D8-C38F-183CE033C2DA} - (no file)
O2 - BHO: (no name) - {41D02906-F44B-CF32-3373-65367914AB05} - (no file)
O2 - BHO: (no name) - {4249913F-B87B-5BCB-BDAC-0E589CD03682} - (no file)
O2 - BHO: (no name) - {4AC62F9C-2025-CE87-7120-9845408A0B63} - (no file)
O2 - BHO: (no name) - {4D9FC428-C242-144C-B27B-F27F0CC116BE} - (no file)
O2 - BHO: (no name) - {5207D81A-0909-7BF3-CDC4-ABE426C5E934} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54D0E15D-04E1-F4B0-9D57-9A826010E6AA} - (no file)
O2 - BHO: (no name) - {5B791DC9-4315-DB99-ED8F-D81BA733A257} - (no file)
O2 - BHO: (no name) - {60315168-4625-9371-95C8-1DF81A38AF24} - (no file)
O2 - BHO: (no name) - {63093676-2125-8F3C-BA68-4915122AC394} - (no file)
O2 - BHO: (no name) - {6F8EC736-6522-74CB-8763-5B86830D7656} - (no file)
O2 - BHO: (no name) - {7133F302-4755-78D3-A8F2-7D74FEF0E4FB} - (no file)
O2 - BHO: (no name) - {79100B7A-EC6C-7C6A-7BDA-CDBF78C70B60} - (no file)
O2 - BHO: (no name) - {7A00499E-BCBB-B127-9B94-C5DF5086E096} - (no file)
O2 - BHO: (no name) - {7AF33B82-8818-7906-C899-C50B34622AF6} - (no file)
O2 - BHO: Class - {7FF0C18F-DEC1-F4E3-8B04-146F5F290713} - C:\WINDOWS\mfchg32.dll
O2 - BHO: (no name) - {852FA20A-9E12-6825-3E86-D9C0B1C1184B} - (no file)
O2 - BHO: (no name) - {89C52F8E-6421-B53A-EBC0-9EFEAF3E7FCD} - (no file)
O2 - BHO: (no name) - {8A680A8F-C9AB-CE2A-A1BA-7072064D7B92} - (no file)
O2 - BHO: (no name) - {8B01EAC7-A0C9-5910-0FD2-A47C18F4C174} - (no file)
O2 - BHO: (no name) - {8B10E5C2-6029-0876-04F6-786D53DF4AD3} - (no file)
O2 - BHO: (no name) - {8B39AA17-3978-F260-9FEA-931168F79497} - (no file)
O2 - BHO: (no name) - {8C8960FA-A206-CA3C-2AA1-E1179654EDFA} - (no file)
O2 - BHO: (no name) - {91EAAEAE-3F55-F506-EB9F-47DFCAB8E7D6} - (no file)
O2 - BHO: (no name) - {9341B059-25B9-C093-AEB4-FF0CB478B147} - (no file)
O2 - BHO: (no name) - {95AF0ED6-C5F7-060D-D454-9070ABC0FF5F} - (no file)
O2 - BHO: (no name) - {98D79E08-A8D3-7C16-C8D1-316A15F195A3} - (no file)
O2 - BHO: (no name) - {99CD36FC-5A1C-A22E-3D74-2B4A9C0E897C} - (no file)
O2 - BHO: (no name) - {9E51B05C-3A1D-6175-2F9B-368F3DF431A5} - (no file)
O2 - BHO: (no name) - {A67AC66F-E66D-B230-07D8-8163A013AE40} - (no file)
O2 - BHO: (no name) - {A8A6D469-369F-3458-9CB6-13F81431144C} - (no file)
O2 - BHO: (no name) - {A963E875-BD23-4A38-7CEC-B5840D7C5CF0} - (no file)
O2 - BHO: (no name) - {AC2E519E-930B-3F24-8456-0D52BEB257CF} - (no file)
O2 - BHO: (no name) - {B263F539-8F16-AA18-E6C0-55D9E74037F7} - (no file)
O2 - BHO: (no name) - {B7899CB8-DD7C-2910-E570-6C8A6A72D509} - (no file)
O2 - BHO: (no name) - {B7B83230-6E91-B3C1-619A-54550AB911E0} - (no file)
O2 - BHO: (no name) - {BA94C7FC-6F23-61AD-837C-91262653369E} - (no file)
O2 - BHO: (no name) - {BB5A0FC4-FCAF-FA07-2E59-B4F763DA2F07} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C0FE83BD-31A5-72B3-58A3-123E5B3E66F7} - (no file)
O2 - BHO: (no name) - {C17402BF-BD26-10E5-0CDD-D64A6C70BA8B} - (no file)
O2 - BHO: (no name) - {C2EF3E65-B610-3BA5-4D34-6D00744A449C} - (no file)
O2 - BHO: (no name) - {C3B7AF3E-092D-AC15-1A46-F27B9FA50A1C} - (no file)
O2 - BHO: (no name) - {CAD07FE9-6CBE-706E-AD3F-ABD30C3C2C92} - (no file)
O2 - BHO: (no name) - {CB798A46-957D-1AE4-8F9E-F766D6E85F00} - (no file)
O2 - BHO: (no name) - {CE5A87FA-D18B-3151-897D-CFBA65E341E0} - (no file)
O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - (no file)
O2 - BHO: (no name) - {D8249B4E-958A-B03F-2C17-480C0BABA6A6} - (no file)
O2 - BHO: (no name) - {E2CF3F20-7B47-7FDF-0B4B-317598789569} - (no file)
O2 - BHO: (no name) - {E60D7284-3090-534F-5C3A-08BCBA772F9C} - (no file)
O2 - BHO: (no name) - {EE055B7A-58F8-B9E1-4CDD-84A44E1735F0} - (no file)
O2 - BHO: (no name) - {F0369D81-D189-AC88-E454-02C0B2632F5E} - (no file)
O2 - BHO: (no name) - {FBE3BC88-D27A-10A7-E44D-9FD607FA2D90} - (no file)
O2 - BHO: (no name) - {FEB6E8AA-FE92-E2C2-E455-A3DF3DEA94CC} - (no file)
O2 - BHO: (no name) - {FEF289B2-6015-9A71-D02D-8394ED825678} - (no file)
O2 - BHO: (no name) - {FF82035F-0086-8DD2-C7FF-4F5E2A38F671} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [apivc32.exe] C:\WINDOWS\system32\apivc32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [sysbg.exe] C:\WINDOWS\system32\sysbg.exe
O4 - HKLM\..\Run: [ntxg32.exe] C:\WINDOWS\system32\ntxg32.exe
O4 - HKLM\..\Run: [nthv32.exe] C:\WINDOWS\nthv32.exe
O4 - HKLM\..\Run: [atlkn.exe] C:\WINDOWS\atlkn.exe
O4 - HKLM\..\Run: [msum32.exe] C:\WINDOWS\msum32.exe
O4 - HKLM\..\Run: [mfcgo.exe] C:\WINDOWS\mfcgo.exe
O4 - HKLM\..\Run: [apiif.exe] C:\WINDOWS\apiif.exe
O4 - HKLM\..\Run: [sdkly.exe] C:\WINDOWS\sdkly.exe
O4 - HKLM\..\Run: [sdkrj.exe] C:\WINDOWS\system32\sdkrj.exe
O4 - HKLM\..\Run: [ipnx32.exe] C:\WINDOWS\system32\ipnx32.exe
O4 - HKLM\..\Run: [apiet32.exe] C:\WINDOWS\system32\apiet32.exe
O4 - HKLM\..\Run: [ipkz.exe] C:\WINDOWS\system32\ipkz.exe
O4 - HKLM\..\Run: [ipdf.exe] C:\WINDOWS\ipdf.exe
O4 - HKLM\..\Run: [ntkq32.exe] C:\WINDOWS\ntkq32.exe
O4 - HKLM\..\Run: [ieya32.exe] C:\WINDOWS\ieya32.exe
O4 - HKLM\..\Run: [ntpk32.exe] C:\WINDOWS\system32\ntpk32.exe
O4 - HKLM\..\Run: [apidi32.exe] C:\WINDOWS\system32\apidi32.exe
O4 - HKLM\..\Run: [atlgm32.exe] C:\WINDOWS\atlgm32.exe
O4 - HKLM\..\Run: [javarc.exe] C:\WINDOWS\javarc.exe
O4 - HKLM\..\Run: [ntpu.exe] C:\WINDOWS\system32\ntpu.exe
O4 - HKLM\..\Run: [mseg.exe] C:\WINDOWS\mseg.exe
O4 - HKLM\..\Run: [mfccb32.exe] C:\WINDOWS\system32\mfccb32.exe
O4 - HKLM\..\Run: [ntpw32.exe] C:\WINDOWS\system32\ntpw32.exe
O4 - HKLM\..\Run: [ntxr32.exe] C:\WINDOWS\ntxr32.exe
O4 - HKLM\..\Run: [d3td.exe] C:\WINDOWS\system32\d3td.exe
O4 - HKLM\..\Run: [sdkyj.exe] C:\WINDOWS\system32\sdkyj.exe
O4 - HKLM\..\Run: [appws.exe] C:\WINDOWS\system32\appws.exe
O4 - HKLM\..\Run: [d3us.exe] C:\WINDOWS\d3us.exe
O4 - HKLM\..\Run: [addoa32.exe] C:\WINDOWS\system32\addoa32.exe
O4 - HKLM\..\Run: [winkn.exe] C:\WINDOWS\system32\winkn.exe
O4 - HKLM\..\Run: [mfcyu.exe] C:\WINDOWS\mfcyu.exe
O4 - HKLM\..\Run: [iece.exe] C:\WINDOWS\system32\iece.exe
O4 - HKLM\..\RunOnce: [apian32.exe] C:\WINDOWS\apian32.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccess/ie/bridge-c5.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

LonnyRJones
2006-02-08, 02:53
Download extract then run aboutbuster
http://www.downloads.subratam.org/AboutBuster.zip

Then Restart your PC
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Start Hijackthis and place a check next to these items If there.
Close all browser windows and shut down all other programs that show in the taskbar.(even Folders)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\yoycg.dll/sp.html#10001%resultposition.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {072E058D-3046-1956-68F1-D9BA95C696E9} - (no file)
O2 - BHO: (no name) - {0A9850AB-BEFF-800A-BCCF-27897A9AC53A} - (no file)
O2 - BHO: (no name) - {0CDCC695-26E8-8B05-0DE0-344FBFCD407F} - (no file)
O2 - BHO: (no name) - {0DCB855C-7AF4-46FC-F0C0-27DCB8195678} - (no file)
O2 - BHO: (no name) - {0FBD6D56-852E-81B0-D541-08A7403661DC} - (no file)
O2 - BHO: (no name) - {179408EE-D094-77D5-2292-789A736D6E90} - (no file)
O2 - BHO: Class - {1A2FCB78-BCDE-411A-2F9F-AE7FEB55F327} - C:\WINDOWS\sysxr.dll
O2 - BHO: (no name) - {1B7868F3-747F-F324-23F0-1A3EC3D2C170} - (no file)
O2 - BHO: Class - {1BB06227-02D6-8AE4-475A-58D02CC66F9A} - C:\WINDOWS\crsd.dll
O2 - BHO: (no name) - {26292D92-C47D-8978-68F1-EADFBF80E5DD} - (no file)
O2 - BHO: (no name) - {28A5C3A0-8EDD-4FB2-1F3A-10A98544D413} - (no file)
O2 - BHO: (no name) - {2C14596F-F821-7151-8E15-D6C625BA9326} - (no file)
O2 - BHO: Class - {2CEDF703-7B1D-11EA-9346-27AA2F77086D} - C:\WINDOWS\system32\netft32.dll
O2 - BHO: (no name) - {3A1BDA7E-F499-48DE-E72D-92C016F9B8A9} - (no file)
O2 - BHO: (no name) - {3F1BB4CB-FD6D-A0D8-C38F-183CE033C2DA} - (no file)
O2 - BHO: (no name) - {41D02906-F44B-CF32-3373-65367914AB05} - (no file)
O2 - BHO: (no name) - {4249913F-B87B-5BCB-BDAC-0E589CD03682} - (no file)
O2 - BHO: (no name) - {4AC62F9C-2025-CE87-7120-9845408A0B63} - (no file)
O2 - BHO: (no name) - {4D9FC428-C242-144C-B27B-F27F0CC116BE} - (no file)
O2 - BHO: (no name) - {5207D81A-0909-7BF3-CDC4-ABE426C5E934} - (no file)
O2 - BHO: (no name) - {54D0E15D-04E1-F4B0-9D57-9A826010E6AA} - (no file)
O2 - BHO: (no name) - {5B791DC9-4315-DB99-ED8F-D81BA733A257} - (no file)
O2 - BHO: (no name) - {60315168-4625-9371-95C8-1DF81A38AF24} - (no file)
O2 - BHO: (no name) - {63093676-2125-8F3C-BA68-4915122AC394} - (no file)
O2 - BHO: (no name) - {6F8EC736-6522-74CB-8763-5B86830D7656} - (no file)
O2 - BHO: (no name) - {7133F302-4755-78D3-A8F2-7D74FEF0E4FB} - (no file)
O2 - BHO: (no name) - {79100B7A-EC6C-7C6A-7BDA-CDBF78C70B60} - (no file)
O2 - BHO: (no name) - {7A00499E-BCBB-B127-9B94-C5DF5086E096} - (no file)
O2 - BHO: (no name) - {7AF33B82-8818-7906-C899-C50B34622AF6} - (no file)
O2 - BHO: Class - {7FF0C18F-DEC1-F4E3-8B04-146F5F290713} - C:\WINDOWS\mfchg32.dll
O2 - BHO: (no name) - {852FA20A-9E12-6825-3E86-D9C0B1C1184B} - (no file)
O2 - BHO: (no name) - {89C52F8E-6421-B53A-EBC0-9EFEAF3E7FCD} - (no file)
O2 - BHO: (no name) - {8A680A8F-C9AB-CE2A-A1BA-7072064D7B92} - (no file)
O2 - BHO: (no name) - {8B01EAC7-A0C9-5910-0FD2-A47C18F4C174} - (no file)
O2 - BHO: (no name) - {8B10E5C2-6029-0876-04F6-786D53DF4AD3} - (no file)
O2 - BHO: (no name) - {8B39AA17-3978-F260-9FEA-931168F79497} - (no file)
O2 - BHO: (no name) - {8C8960FA-A206-CA3C-2AA1-E1179654EDFA} - (no file)
O2 - BHO: (no name) - {91EAAEAE-3F55-F506-EB9F-47DFCAB8E7D6} - (no file)
O2 - BHO: (no name) - {9341B059-25B9-C093-AEB4-FF0CB478B147} - (no file)
O2 - BHO: (no name) - {95AF0ED6-C5F7-060D-D454-9070ABC0FF5F} - (no file)
O2 - BHO: (no name) - {98D79E08-A8D3-7C16-C8D1-316A15F195A3} - (no file)
O2 - BHO: (no name) - {99CD36FC-5A1C-A22E-3D74-2B4A9C0E897C} - (no file)
O2 - BHO: (no name) - {9E51B05C-3A1D-6175-2F9B-368F3DF431A5} - (no file)
O2 - BHO: (no name) - {A67AC66F-E66D-B230-07D8-8163A013AE40} - (no file)
O2 - BHO: (no name) - {A8A6D469-369F-3458-9CB6-13F81431144C} - (no file)
O2 - BHO: (no name) - {A963E875-BD23-4A38-7CEC-B5840D7C5CF0} - (no file)
O2 - BHO: (no name) - {AC2E519E-930B-3F24-8456-0D52BEB257CF} - (no file)
O2 - BHO: (no name) - {B263F539-8F16-AA18-E6C0-55D9E74037F7} - (no file)
O2 - BHO: (no name) - {B7899CB8-DD7C-2910-E570-6C8A6A72D509} - (no file)
O2 - BHO: (no name) - {B7B83230-6E91-B3C1-619A-54550AB911E0} - (no file)
O2 - BHO: (no name) - {BA94C7FC-6F23-61AD-837C-91262653369E} - (no file)
O2 - BHO: (no name) - {BB5A0FC4-FCAF-FA07-2E59-B4F763DA2F07} - (no file)
O2 - BHO: (no name) - {C0FE83BD-31A5-72B3-58A3-123E5B3E66F7} - (no file)
O2 - BHO: (no name) - {C17402BF-BD26-10E5-0CDD-D64A6C70BA8B} - (no file)
O2 - BHO: (no name) - {C2EF3E65-B610-3BA5-4D34-6D00744A449C} - (no file)
O2 - BHO: (no name) - {C3B7AF3E-092D-AC15-1A46-F27B9FA50A1C} - (no file)
O2 - BHO: (no name) - {CAD07FE9-6CBE-706E-AD3F-ABD30C3C2C92} - (no file)
O2 - BHO: (no name) - {CB798A46-957D-1AE4-8F9E-F766D6E85F00} - (no file)
O2 - BHO: (no name) - {CE5A87FA-D18B-3151-897D-CFBA65E341E0} - (no file)
O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - (no file)
O2 - BHO: (no name) - {D8249B4E-958A-B03F-2C17-480C0BABA6A6} - (no file)
O2 - BHO: (no name) - {E2CF3F20-7B47-7FDF-0B4B-317598789569} - (no file)
O2 - BHO: (no name) - {E60D7284-3090-534F-5C3A-08BCBA772F9C} - (no file)
O2 - BHO: (no name) - {EE055B7A-58F8-B9E1-4CDD-84A44E1735F0} - (no file)
O2 - BHO: (no name) - {F0369D81-D189-AC88-E454-02C0B2632F5E} - (no file)
O2 - BHO: (no name) - {FBE3BC88-D27A-10A7-E44D-9FD607FA2D90} - (no file)
O2 - BHO: (no name) - {FEB6E8AA-FE92-E2C2-E455-A3DF3DEA94CC} - (no file)
O2 - BHO: (no name) - {FEF289B2-6015-9A71-D02D-8394ED825678} - (no file)
O2 - BHO: (no name) - {FF82035F-0086-8DD2-C7FF-4F5E2A38F671} - (no file)
O4 - HKLM\..\Run: [apivc32.exe] C:\WINDOWS\system32\apivc32.exe
O4 - HKLM\..\Run: [sysbg.exe] C:\WINDOWS\system32\sysbg.exe
O4 - HKLM\..\Run: [ntxg32.exe] C:\WINDOWS\system32\ntxg32.exe
O4 - HKLM\..\Run: [nthv32.exe] C:\WINDOWS\nthv32.exe
O4 - HKLM\..\Run: [atlkn.exe] C:\WINDOWS\atlkn.exe
O4 - HKLM\..\Run: [msum32.exe] C:\WINDOWS\msum32.exe
O4 - HKLM\..\Run: [mfcgo.exe] C:\WINDOWS\mfcgo.exe
O4 - HKLM\..\Run: [apiif.exe] C:\WINDOWS\apiif.exe
O4 - HKLM\..\Run: [sdkly.exe] C:\WINDOWS\sdkly.exe
O4 - HKLM\..\Run: [sdkrj.exe] C:\WINDOWS\system32\sdkrj.exe
O4 - HKLM\..\Run: [ipnx32.exe] C:\WINDOWS\system32\ipnx32.exe
O4 - HKLM\..\Run: [apiet32.exe] C:\WINDOWS\system32\apiet32.exe
O4 - HKLM\..\Run: [ipkz.exe] C:\WINDOWS\system32\ipkz.exe
O4 - HKLM\..\Run: [ipdf.exe] C:\WINDOWS\ipdf.exe
O4 - HKLM\..\Run: [ntkq32.exe] C:\WINDOWS\ntkq32.exe
O4 - HKLM\..\Run: [ieya32.exe] C:\WINDOWS\ieya32.exe
O4 - HKLM\..\Run: [ntpk32.exe] C:\WINDOWS\system32\ntpk32.exe
O4 - HKLM\..\Run: [apidi32.exe] C:\WINDOWS\system32\apidi32.exe
O4 - HKLM\..\Run: [atlgm32.exe] C:\WINDOWS\atlgm32.exe
O4 - HKLM\..\Run: [javarc.exe] C:\WINDOWS\javarc.exe
O4 - HKLM\..\Run: [ntpu.exe] C:\WINDOWS\system32\ntpu.exe
O4 - HKLM\..\Run: [mseg.exe] C:\WINDOWS\mseg.exe
O4 - HKLM\..\Run: [mfccb32.exe] C:\WINDOWS\system32\mfccb32.exe
O4 - HKLM\..\Run: [ntpw32.exe] C:\WINDOWS\system32\ntpw32.exe
O4 - HKLM\..\Run: [ntxr32.exe] C:\WINDOWS\ntxr32.exe
O4 - HKLM\..\Run: [d3td.exe] C:\WINDOWS\system32\d3td.exe
O4 - HKLM\..\Run: [sdkyj.exe] C:\WINDOWS\system32\sdkyj.exe
O4 - HKLM\..\Run: [appws.exe] C:\WINDOWS\system32\appws.exe
O4 - HKLM\..\Run: [d3us.exe] C:\WINDOWS\d3us.exe
O4 - HKLM\..\Run: [addoa32.exe] C:\WINDOWS\system32\addoa32.exe
O4 - HKLM\..\Run: [winkn.exe] C:\WINDOWS\system32\winkn.exe
O4 - HKLM\..\Run: [mfcyu.exe] C:\WINDOWS\mfcyu.exe
O4 - HKLM\..\Run: [iece.exe] C:\WINDOWS\system32\iece.exe
O4 - HKLM\..\RunOnce: [apian32.exe] C:\WINDOWS\apian32.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Me.../bridge-c5.cab
====================================
Hit fix checked and close Hijackthis.
Restart the PC again
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Once back make and post a new hiajckthis log please.

Tudds
2006-02-08, 02:55
I just realized, someone used the computer after the log was created. I did another scan and found these some that were removed.
Logfile of HijackThis v1.99.1
Scan saved at 8:53:35 PM, on 2/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\apidm.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\WINDOWS\nethb.exe
C:\Documents and Settings\Tonio\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {072E058D-3046-1956-68F1-D9BA95C696E9} - (no file)
O2 - BHO: (no name) - {0A9850AB-BEFF-800A-BCCF-27897A9AC53A} - (no file)
O2 - BHO: (no name) - {0CDCC695-26E8-8B05-0DE0-344FBFCD407F} - (no file)
O2 - BHO: (no name) - {0DCB855C-7AF4-46FC-F0C0-27DCB8195678} - (no file)
O2 - BHO: (no name) - {0FBD6D56-852E-81B0-D541-08A7403661DC} - (no file)
O2 - BHO: (no name) - {179408EE-D094-77D5-2292-789A736D6E90} - (no file)
O2 - BHO: Class - {1A2FCB78-BCDE-411A-2F9F-AE7FEB55F327} - C:\WINDOWS\sysxr.dll
O2 - BHO: (no name) - {1B7868F3-747F-F324-23F0-1A3EC3D2C170} - (no file)
O2 - BHO: Class - {1BB06227-02D6-8AE4-475A-58D02CC66F9A} - C:\WINDOWS\crsd.dll
O2 - BHO: (no name) - {26292D92-C47D-8978-68F1-EADFBF80E5DD} - (no file)
O2 - BHO: (no name) - {28A5C3A0-8EDD-4FB2-1F3A-10A98544D413} - (no file)
O2 - BHO: (no name) - {2C14596F-F821-7151-8E15-D6C625BA9326} - (no file)
O2 - BHO: Class - {2CEDF703-7B1D-11EA-9346-27AA2F77086D} - C:\WINDOWS\system32\netft32.dll
O2 - BHO: (no name) - {3A1BDA7E-F499-48DE-E72D-92C016F9B8A9} - (no file)
O2 - BHO: (no name) - {3F1BB4CB-FD6D-A0D8-C38F-183CE033C2DA} - (no file)
O2 - BHO: (no name) - {41D02906-F44B-CF32-3373-65367914AB05} - (no file)
O2 - BHO: (no name) - {4249913F-B87B-5BCB-BDAC-0E589CD03682} - (no file)
O2 - BHO: (no name) - {4AC62F9C-2025-CE87-7120-9845408A0B63} - (no file)
O2 - BHO: (no name) - {4D9FC428-C242-144C-B27B-F27F0CC116BE} - (no file)
O2 - BHO: (no name) - {5207D81A-0909-7BF3-CDC4-ABE426C5E934} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54D0E15D-04E1-F4B0-9D57-9A826010E6AA} - (no file)
O2 - BHO: (no name) - {5B791DC9-4315-DB99-ED8F-D81BA733A257} - (no file)
O2 - BHO: (no name) - {60315168-4625-9371-95C8-1DF81A38AF24} - (no file)
O2 - BHO: (no name) - {63093676-2125-8F3C-BA68-4915122AC394} - (no file)
O2 - BHO: (no name) - {6F8EC736-6522-74CB-8763-5B86830D7656} - (no file)
O2 - BHO: (no name) - {7133F302-4755-78D3-A8F2-7D74FEF0E4FB} - (no file)
O2 - BHO: (no name) - {79100B7A-EC6C-7C6A-7BDA-CDBF78C70B60} - (no file)
O2 - BHO: (no name) - {7A00499E-BCBB-B127-9B94-C5DF5086E096} - (no file)
O2 - BHO: (no name) - {7AF33B82-8818-7906-C899-C50B34622AF6} - (no file)
O2 - BHO: Class - {7FF0C18F-DEC1-F4E3-8B04-146F5F290713} - C:\WINDOWS\mfchg32.dll
O2 - BHO: (no name) - {852FA20A-9E12-6825-3E86-D9C0B1C1184B} - (no file)
O2 - BHO: (no name) - {89C52F8E-6421-B53A-EBC0-9EFEAF3E7FCD} - (no file)
O2 - BHO: (no name) - {8A680A8F-C9AB-CE2A-A1BA-7072064D7B92} - (no file)
O2 - BHO: (no name) - {8B01EAC7-A0C9-5910-0FD2-A47C18F4C174} - (no file)
O2 - BHO: (no name) - {8B10E5C2-6029-0876-04F6-786D53DF4AD3} - (no file)
O2 - BHO: (no name) - {8B39AA17-3978-F260-9FEA-931168F79497} - (no file)
O2 - BHO: (no name) - {8C8960FA-A206-CA3C-2AA1-E1179654EDFA} - (no file)
O2 - BHO: (no name) - {91EAAEAE-3F55-F506-EB9F-47DFCAB8E7D6} - (no file)
O2 - BHO: (no name) - {9341B059-25B9-C093-AEB4-FF0CB478B147} - (no file)
O2 - BHO: (no name) - {95AF0ED6-C5F7-060D-D454-9070ABC0FF5F} - (no file)
O2 - BHO: (no name) - {98D79E08-A8D3-7C16-C8D1-316A15F195A3} - (no file)
O2 - BHO: (no name) - {99CD36FC-5A1C-A22E-3D74-2B4A9C0E897C} - (no file)
O2 - BHO: (no name) - {9E51B05C-3A1D-6175-2F9B-368F3DF431A5} - (no file)
O2 - BHO: (no name) - {A67AC66F-E66D-B230-07D8-8163A013AE40} - (no file)
O2 - BHO: (no name) - {A8A6D469-369F-3458-9CB6-13F81431144C} - (no file)
O2 - BHO: (no name) - {A963E875-BD23-4A38-7CEC-B5840D7C5CF0} - (no file)
O2 - BHO: (no name) - {AC2E519E-930B-3F24-8456-0D52BEB257CF} - (no file)
O2 - BHO: (no name) - {B263F539-8F16-AA18-E6C0-55D9E74037F7} - (no file)
O2 - BHO: (no name) - {B7899CB8-DD7C-2910-E570-6C8A6A72D509} - (no file)
O2 - BHO: (no name) - {B7B83230-6E91-B3C1-619A-54550AB911E0} - (no file)
O2 - BHO: (no name) - {BA94C7FC-6F23-61AD-837C-91262653369E} - (no file)
O2 - BHO: (no name) - {BB5A0FC4-FCAF-FA07-2E59-B4F763DA2F07} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C0FE83BD-31A5-72B3-58A3-123E5B3E66F7} - (no file)
O2 - BHO: (no name) - {C17402BF-BD26-10E5-0CDD-D64A6C70BA8B} - (no file)
O2 - BHO: (no name) - {C2EF3E65-B610-3BA5-4D34-6D00744A449C} - (no file)
O2 - BHO: (no name) - {C3B7AF3E-092D-AC15-1A46-F27B9FA50A1C} - (no file)
O2 - BHO: (no name) - {CAD07FE9-6CBE-706E-AD3F-ABD30C3C2C92} - (no file)
O2 - BHO: (no name) - {CB798A46-957D-1AE4-8F9E-F766D6E85F00} - (no file)
O2 - BHO: (no name) - {CE5A87FA-D18B-3151-897D-CFBA65E341E0} - (no file)
O2 - BHO: (no name) - {D3176F21-DA2F-61E8-97B6-26C992DA4F51} - (no file)
O2 - BHO: (no name) - {D8249B4E-958A-B03F-2C17-480C0BABA6A6} - (no file)
O2 - BHO: (no name) - {E2CF3F20-7B47-7FDF-0B4B-317598789569} - (no file)
O2 - BHO: (no name) - {E60D7284-3090-534F-5C3A-08BCBA772F9C} - (no file)
O2 - BHO: (no name) - {EE055B7A-58F8-B9E1-4CDD-84A44E1735F0} - (no file)
O2 - BHO: (no name) - {F0369D81-D189-AC88-E454-02C0B2632F5E} - (no file)
O2 - BHO: (no name) - {FBE3BC88-D27A-10A7-E44D-9FD607FA2D90} - (no file)
O2 - BHO: (no name) - {FEB6E8AA-FE92-E2C2-E455-A3DF3DEA94CC} - (no file)
O2 - BHO: (no name) - {FEF289B2-6015-9A71-D02D-8394ED825678} - (no file)
O2 - BHO: (no name) - {FF82035F-0086-8DD2-C7FF-4F5E2A38F671} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [apivc32.exe] C:\WINDOWS\system32\apivc32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [sysbg.exe] C:\WINDOWS\system32\sysbg.exe
O4 - HKLM\..\Run: [ntxg32.exe] C:\WINDOWS\system32\ntxg32.exe
O4 - HKLM\..\Run: [nthv32.exe] C:\WINDOWS\nthv32.exe
O4 - HKLM\..\Run: [atlkn.exe] C:\WINDOWS\atlkn.exe
O4 - HKLM\..\Run: [msum32.exe] C:\WINDOWS\msum32.exe
O4 - HKLM\..\Run: [mfcgo.exe] C:\WINDOWS\mfcgo.exe
O4 - HKLM\..\Run: [apiif.exe] C:\WINDOWS\apiif.exe
O4 - HKLM\..\Run: [sdkly.exe] C:\WINDOWS\sdkly.exe
O4 - HKLM\..\Run: [sdkrj.exe] C:\WINDOWS\system32\sdkrj.exe
O4 - HKLM\..\Run: [ipnx32.exe] C:\WINDOWS\system32\ipnx32.exe
O4 - HKLM\..\Run: [apiet32.exe] C:\WINDOWS\system32\apiet32.exe
O4 - HKLM\..\Run: [ipkz.exe] C:\WINDOWS\system32\ipkz.exe
O4 - HKLM\..\Run: [ipdf.exe] C:\WINDOWS\ipdf.exe
O4 - HKLM\..\Run: [ntkq32.exe] C:\WINDOWS\ntkq32.exe
O4 - HKLM\..\Run: [ieya32.exe] C:\WINDOWS\ieya32.exe
O4 - HKLM\..\Run: [ntpk32.exe] C:\WINDOWS\system32\ntpk32.exe
O4 - HKLM\..\Run: [apidi32.exe] C:\WINDOWS\system32\apidi32.exe
O4 - HKLM\..\Run: [atlgm32.exe] C:\WINDOWS\atlgm32.exe
O4 - HKLM\..\Run: [javarc.exe] C:\WINDOWS\javarc.exe
O4 - HKLM\..\Run: [ntpu.exe] C:\WINDOWS\system32\ntpu.exe
O4 - HKLM\..\Run: [mseg.exe] C:\WINDOWS\mseg.exe
O4 - HKLM\..\Run: [mfccb32.exe] C:\WINDOWS\system32\mfccb32.exe
O4 - HKLM\..\Run: [ntpw32.exe] C:\WINDOWS\system32\ntpw32.exe
O4 - HKLM\..\Run: [ntxr32.exe] C:\WINDOWS\ntxr32.exe
O4 - HKLM\..\Run: [d3td.exe] C:\WINDOWS\system32\d3td.exe
O4 - HKLM\..\Run: [sdkyj.exe] C:\WINDOWS\system32\sdkyj.exe
O4 - HKLM\..\Run: [appws.exe] C:\WINDOWS\system32\appws.exe
O4 - HKLM\..\Run: [d3us.exe] C:\WINDOWS\d3us.exe
O4 - HKLM\..\Run: [addoa32.exe] C:\WINDOWS\system32\addoa32.exe
O4 - HKLM\..\Run: [winkn.exe] C:\WINDOWS\system32\winkn.exe
O4 - HKLM\..\Run: [mfcyu.exe] C:\WINDOWS\mfcyu.exe
O4 - HKLM\..\Run: [iece.exe] C:\WINDOWS\system32\iece.exe
O4 - HKLM\..\Run: [nethb.exe] C:\WINDOWS\nethb.exe
O4 - HKLM\..\RunOnce: [apian32.exe] C:\WINDOWS\apian32.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAccess/ie/bridge-c5.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Tudds
2006-02-08, 14:58
That AboutBuster completely raped my computer, I hope you don't tell any more people to use it. AB deleted a lot of required system files. I had to reformat and since my computer uses the OS from another HD I am missing registry files. I wish I had just dealed with the spyware

LonnyRJones
2006-02-08, 16:46
Perhaps it was one of the virus/hiajcker that coused the problems ,
aboutbuster certainly did not, Million's have use it

tashi
2006-02-08, 17:02
Hello.
Please explain:

I just realized, someone used the computer after the log was created. I did another scan and found these some that were removed.

Tudds
2006-02-08, 17:07
I did the hijack this list, ran spybot and then redid the hijack this
I had the Coolsearch crap for days.... I ran the AB and rebooted as it said.. it was a no go

tashi
2006-02-08, 17:25
Thank you. :)

I was referring to this:

I just realized, someone used the computer after the log was created

At any rate, sorry to hear about the reformat.

Best wishes.

Tudds
2006-02-08, 21:11
It was probably for the best, I found my locked files and will transfer them to a 2nd hard drive and completely erase everything. I was really angry before but have figured it out and am calm :) Maybe put a warning with AB though

tashi
2006-02-08, 21:51
Hi there.

You could post at the developer's site with a link back to your topic.

http://www.malwarebytes.org/forums/index.php?

As lonny said, this tool has been used by many people and I personally have never heard of a problem after using it.

But thanks for letting us know what you did with the system and have a great week. :)

tashi
2006-02-13, 03:51
This topic will now be archived.