Periodic Popups and adding Favorites

D

Dave G

I recently had some sort of spyware get on my PC. I have
since run a couple tools to remove this, and I also
downloaded and ran the new Microsoft anti-spyware beta.
It found a few things and I removed them. But now I am
still getting a periodic pop-up from like
www.sexandpoker.net, and when this happens it also adds
like 10 new favorites to IE, like "Viagra", "Work at
Home", XXX Pictures", etc.

Any ideas how to prevent this or what is still affecting
my PC? The new Microsoft tool says things are clean.
Any info would be appreciated.

Thanks,

Dave
 
B

Bill Sanderson

You've definitely got spyware still active on the machine.

Here are my thoughts of things to try:
1) submit a Tools, suspected spyware report (if possible!)

Check that you are on current definitions. See Help, About. Current
definitions are 5682. If you are not there, go to File, Update.....

2) restart the machine in Safe mode, and do a Full system scan--not the
intelligent quick scan.

Another good idea is, while in safe mode to clear all Temporary Internet
Files, including Offline Content. You may even want to do this at a command
prompt if you know how to do that.

The thread below:

http://computercops.biz/postt96854.html

Shows another user removing a bug which also advertised this URL from his
machine via expert help and HijackThis logs.

This is another route to take--best done in a forum devoted to such things.
 
D

Dave

OK. Here is my log from HiJackThis.exe. Looks like
there may some issues, but I'm not sure what needs to go.

Logfile of HijackThis v1.97.7
Scan saved at 8:09:40 PM, on 1/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SSA\smc.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\MS\SMS\CORE\BIN\CLISVCL.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\gearsec.exe
C:\WINDOWS\System32\Hummingbird\Connectivity\7.00
\Inetd\inetd32.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\Hummingbird\Connectivity\7.00
\Jconfig\jconfigdNT.exe
C:\Program Files\Common Files\Microsoft
Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\CA\Unicenter Software
Delivery\BIN\SDSERV.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\MS\SMS\CLICOMP\RemCtrl\Wuser32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\mqsvc.exe
C:\Program Files\CA\Unicenter Software
Delivery\BIN\TRIGGAG.EXE
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\MS\SMS\clicomp\apa\Bin\smsapm32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\SxpInst\sxplog32.exe
C:\WINDOWS\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\MS\SMS\CLICOMP\SWDist32\bin\smsmon32.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCWizard.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vwipxspnt.exe
C:\Documents and Settings\geisberd\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
res://shdocpe.dll/asst.htm
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title = Microsoft Internet Explorer
provided by Timken Company v6sp1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,
(Default) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/s
bcydsl/*http://www.yahoo.com
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyServer = proxy:80
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = *.inside.tkr;<local>
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0
\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-
001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {A7CA6B45-5594-4E43-9CDF-
BA5055171516} - C:\WINDOWS\System32\msiip.dll
O2 - BHO: (no name) - {E967F5C4-36AB-4E37-83F3-
8A778736DF9D} - C:\WINDOWS\System32\mcicdb.dll (file
missing)
O3 - Toolbar: (no name) - {06ABAA2D-34AB-4902-A326-
409BD9B9A7A5} - C:\WINDOWS\System32\iecust.dll (file
missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1
\EzEjMnAp.Exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog
Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program
Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1
\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI
Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program
Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32
\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program
Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program
Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program
Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [SMS Application Launcher]
C:\WINDOWS\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1
\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - Global Startup: Logitech Desktop Messenger.lnk =
C:\Program Files\Logitech\Desktop Messenger\8876480
\Program\LDMConf.exe
O4 - Global Startup: Start Rapid Restore Services.lnk =
C:\Program Files\Xpoint\PE\Rapid Restore.bat
O6 - HKLM\Software\Policies\Microsoft\Internet
Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Research (HKLM)
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
(Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director
/sw.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Control
s/en/x86/client/wuweb_site.cab?1099950285693
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle
JInitiator 1.1.8.16) - http://tor-fbd-nca2/oa-
java/jinit11816.exe
O16 - DPF: {aa44da02-7f61-11d4-a3e1-00c04fa32518} -
http://tor-nca-prod/oa-java/jinit11732.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
https://download.macromedia.com/pub/shockwave/cabs/flash/s
wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
corp.timken.com
O17 - HKLM\Software\..\Telephony: DomainName =
corp.timken.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{44F666A9-85D5-
49F7-BCD1-077589722E65}: NameServer =
69.50.188.178,69.31.80.244
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
corp.timken.com


Thanks,

Dave
 
R

Ron Kinner

Wasn't sure this forum could take a whole log but it looks
like it can.

Boot into Safe Mode (F8) and run HijackThis again and then
check the following and hit Fix Checked:

R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
res://shdocpe.dll/asst.htm

O2 - BHO: (no name) - {A7CA6B45-5594-4E43-9CDF-
BA5055171516} - C:\WINDOWS\System32\msiip.dll
O2 - BHO: (no name) - {E967F5C4-36AB-4E37-83F3-
8A778736DF9D} - C:\WINDOWS\System32\mcicdb.dll (file
missing)
O3 - Toolbar: (no name) - {06ABAA2D-34AB-4902-A326-
409BD9B9A7A5} - C:\WINDOWS\System32\iecust.dll (file
missing)

Above may be enough but if not (or just to be sure) while
in Safe Mode see if you can find shdocpe.dll or msiip.dll
using Start | Search (Search for Hidden and System files
in C:\, C:\Windows, C:\Windows\System32 and
C:\Windows\System32\dllcache)

see:

http://support.microsoft.com/?kbid=302347

Right click on each and check their properties. See when
they were last modified and do another search for all
files again Hidden and System with the same modified
date. Delete all files with the same date and time
including the two target files. You may be able to use
the System Explorers in MS AntiSpy to find the dll files
too.

Reboot, do another scan and post it. Let's see if we got
it all.

Ron Kinner MVP Servers
 
A

ABC

Use Easy Cleaner (registry cleaner) to remove any useless
program, and clean up the registry, then run an antivirus
scan.

ABC
 
D

Dave

Thank you very much for the help! I think this has
knocked it out. I was suspicious of the msiip.dll, but
for some reason wasn't thinking to go into Safe Mode to
delete it. I wonder why none of the anti-spyware
packages picked this up as a threat?

Here is my new log if you want to verify that it now
looks safe:

Logfile of HijackThis v1.97.7
Scan saved at 6:18:19 PM, on 1/16/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SSA\smc.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\gearsec.exe
C:\WINDOWS\System32\Hummingbird\Connectivity\7.00
\Inetd\inetd32.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\Hummingbird\Connectivity\7.00
\Jconfig\jconfigdNT.exe
C:\Program Files\Common Files\Microsoft
Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\CA\Unicenter Software
Delivery\BIN\SDSERV.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\MS\SMS\CLICOMP\RemCtrl\Wuser32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\mqsvc.exe
C:\Program Files\CA\Unicenter Software
Delivery\BIN\TRIGGAG.EXE
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\SxpInst\sxplog32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\MS\SMS\clicomp\apa\Bin\smsapm32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\MS\SMS\CLICOMP\SWDist32\bin\smsmon32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCWizard.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and
Settings\geisberd\Desktop\Diagnostics\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title = Microsoft Internet Explorer
provided by Timken Company v6sp1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,
(Default) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/s
bcydsl/*http://www.yahoo.com
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyServer = proxy:80
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = *.inside.tkr;<local>
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0
\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-
206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-
001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1
\EzEjMnAp.Exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog
Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program
Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1
\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI
Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program
Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32
\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program
Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program
Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program
Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program
Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [SMS Application Launcher]
C:\WINDOWS\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1
\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - Global Startup: Logitech Desktop Messenger.lnk =
C:\Program Files\Logitech\Desktop Messenger\8876480
\Program\LDMConf.exe
O4 - Global Startup: Start Rapid Restore Services.lnk =
C:\Program Files\Xpoint\PE\Rapid Restore.bat
O6 - HKLM\Software\Policies\Microsoft\Internet
Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Research (HKLM)
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
(Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director
/sw.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Control
s/en/x86/client/wuweb_site.cab?1099950285693
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle
JInitiator 1.1.8.16) - http://tor-fbd-nca2/oa-
java/jinit11816.exe
O16 - DPF: {aa44da02-7f61-11d4-a3e1-00c04fa32518} -
http://tor-nca-prod/oa-java/jinit11732.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
https://download.macromedia.com/pub/shockwave/cabs/flash/s
wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
corp.timken.com
O17 - HKLM\Software\..\Telephony: DomainName =
corp.timken.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{44F666A9-85D5-
49F7-BCD1-077589722E65}: NameServer =
69.50.188.178,69.31.80.244
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
corp.timken.com

Thanks again,

Dave
 
R

Randall

Windows XP has a built in pop up blocker, if indeed you
are using that operating system.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top