Options
how to remove home search spyware. please suggest me any uninstaller for window98.
hi.
i am having so much problems with this home search. i tried the uninstall download exe for home search but it was for window xp. please help me its bothering me so much. home page is always home search and computer is hanging again and again. i triad spybot and adware se but it not going. the log file is this.
Logfile of HijackThis v1.98.2
Scan saved at 7:23:15 PM, on 9/18/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\APPLJ32.EXE
C:\WINDOWS\NTBW.EXE
C:\WINDOWS\IEKH32.EXE
C:\WINDOWS\APPTM32.EXE
C:\WINDOWS\SYSTEM\ATLLL.EXE
C:\WINDOWS\JAVAYV32.EXE
C:\WINDOWS\SYSTEM\IPRT.EXE
C:\WINDOWS\SYSTEM\WINAD.EXE
C:\WINDOWS\SYSTEM\IPAF32.EXE
C:\WINDOWS\SYSTEM\IEWC.EXE
C:\WINDOWS\WINCX.EXE
C:\WINDOWS\SDKFZ32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\SIS630_V1.04.54\UTILITY\SISTRAY.EXE
C:\PROGRAM FILES\SIS630_V1.04.54\UTILITY\3D\KHOOKER.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\WINDOWS\SM56HLPR.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\CYBERLINK\CDWIZARD'98\CDWIZARD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\WINAD CLIENT\WINAD.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\SYSTEM\WINAD.EXE
C:\WINDOWS\SYSTEM\MSNB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\JAVAYV32.EXE
C:\WINDOWS\SYSTEM\APPVY32.EXE
C:\WINDOWS\JAVAYV32.EXE
C:\WINDOWS\WINNO32.EXE
C:\WINDOWS\NTBW.EXE
C:\WINDOWS\JAVANA32.EXE
C:\WINDOWS\SYSTEM\ATLLL.EXE
C:\WINDOWS\SYSTEM\ATLLE.EXE
C:\WINDOWS\APPTM32.EXE
C:\WINDOWS\SYSTEM\MSCG.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\JAVANA32.EXE
C:\WINDOWS\SYSTEM\ADDEA.EXE
C:\WINDOWS\SYSTEM\IPRT.EXE
C:\WINDOWS\IPUT.EXE
C:\WINDOWS\SYSTEM\APPLJ32.EXE
C:\WINDOWS\SYSTEM\NTBY32.EXE
C:\WINDOWS\SYSTEM\WINAD.EXE
C:\WINDOWS\SYSTEM\IPAF32.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {E433A46E-2FD1-792D-709B-F788A00AC431} - C:\WINDOWS\MFCIJ32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SiS Tray] C:\PROGRAM FILES\SIS630_V1.04.54\UTILITY\SISTRAY.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\Program Files\SiS630_V1.04.54\utility\3d\khooker.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [CDWizard] C:\Program Files\CyberLink\CDWizard'98\CDwizard.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Winad Client] C:\PROGRAM FILES\WINAD CLIENT\WINAD.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [JAVAWR.EXE] C:\WINDOWS\SYSTEM\JAVAWR.EXE
O4 - HKLM\..\RunServices: [APPWJ32.EXE] C:\WINDOWS\SYSTEM\APPWJ32.EXE
O4 - HKLM\..\RunServices: [NTHD.EXE] C:\WINDOWS\SYSTEM\NTHD.EXE
O4 - HKLM\..\RunServices: [WINEO32.EXE] C:\WINDOWS\WINEO32.EXE
O4 - HKLM\..\RunServices: [ATLCN.EXE] C:\WINDOWS\ATLCN.EXE
O4 - HKLM\..\RunServices: [D3SH32.EXE] C:\WINDOWS\SYSTEM\D3SH32.EXE
O4 - HKLM\..\RunServices: [SDKQY32.EXE] C:\WINDOWS\SDKQY32.EXE
O4 - HKLM\..\RunServices: [APPLJ32.EXE] C:\WINDOWS\SYSTEM\APPLJ32.EXE
O4 - HKLM\..\RunServices: [NTBW.EXE] C:\WINDOWS\NTBW.EXE
O4 - HKLM\..\RunServices: [APPTM32.EXE] C:\WINDOWS\APPTM32.EXE
O4 - HKLM\..\RunServices: [IPRT.EXE] C:\WINDOWS\SYSTEM\IPRT.EXE
O4 - HKLM\..\RunServices: [IEKH32.EXE] C:\WINDOWS\IEKH32.EXE
O4 - HKLM\..\RunServices: [JAVAYV32.EXE] C:\WINDOWS\JAVAYV32.EXE
O4 - HKLM\..\RunServices: [ATLLL.EXE] C:\WINDOWS\SYSTEM\ATLLL.EXE
O4 - HKLM\..\RunServices: [IEWC.EXE] C:\WINDOWS\SYSTEM\IEWC.EXE
O4 - HKLM\..\RunServices: [WINAD.EXE] C:\WINDOWS\SYSTEM\WINAD.EXE
O4 - HKLM\..\RunServices: [SDKFZ32.EXE] C:\WINDOWS\SDKFZ32.EXE
O4 - HKLM\..\RunServices: [IPAF32.EXE] C:\WINDOWS\SYSTEM\IPAF32.EXE
O4 - HKLM\..\RunServices: [WINCX.EXE] C:\WINDOWS\WINCX.EXE
O4 - HKLM\..\RunServices: [MSNB.EXE] C:\WINDOWS\SYSTEM\MSNB.EXE
O4 - HKLM\..\RunServices: [APPVY32.EXE] C:\WINDOWS\SYSTEM\APPVY32.EXE
O4 - HKLM\..\RunServices: [WINNO32.EXE] C:\WINDOWS\WINNO32.EXE
O4 - HKLM\..\RunServices: [JAVANA32.EXE] C:\WINDOWS\JAVANA32.EXE
O4 - HKLM\..\RunServices: [ATLLE.EXE] C:\WINDOWS\SYSTEM\ATLLE.EXE
O4 - HKLM\..\RunServices: [MSCG.EXE] C:\WINDOWS\SYSTEM\MSCG.EXE
O4 - HKLM\..\RunServices: [ADDEA.EXE] C:\WINDOWS\SYSTEM\ADDEA.EXE
O4 - HKLM\..\RunServices: [IPUT.EXE] C:\WINDOWS\IPUT.EXE
O4 - HKLM\..\RunServices: [NTBY32.EXE] C:\WINDOWS\SYSTEM\NTBY32.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: ubisoft register.lnk = C:\Program Files\Ubi Soft\Register\schedule.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=9eafaeb2a8e2a9518112bc6e0cedee1552dd4ecb1dd748bcf1cf4d42ced1394245b14c137e17952f3a6abadc3d36297b2b37:b70ac5aa8ec48e2e58a29296baabe1d6
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 202.144.115.4,202.144.66.6
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)
please help me
i am having so much problems with this home search. i tried the uninstall download exe for home search but it was for window xp. please help me its bothering me so much. home page is always home search and computer is hanging again and again. i triad spybot and adware se but it not going. the log file is this.
Logfile of HijackThis v1.98.2
Scan saved at 7:23:15 PM, on 9/18/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\APPLJ32.EXE
C:\WINDOWS\NTBW.EXE
C:\WINDOWS\IEKH32.EXE
C:\WINDOWS\APPTM32.EXE
C:\WINDOWS\SYSTEM\ATLLL.EXE
C:\WINDOWS\JAVAYV32.EXE
C:\WINDOWS\SYSTEM\IPRT.EXE
C:\WINDOWS\SYSTEM\WINAD.EXE
C:\WINDOWS\SYSTEM\IPAF32.EXE
C:\WINDOWS\SYSTEM\IEWC.EXE
C:\WINDOWS\WINCX.EXE
C:\WINDOWS\SDKFZ32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\SIS630_V1.04.54\UTILITY\SISTRAY.EXE
C:\PROGRAM FILES\SIS630_V1.04.54\UTILITY\3D\KHOOKER.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\WINDOWS\SM56HLPR.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\CYBERLINK\CDWIZARD'98\CDWIZARD.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\WINAD CLIENT\WINAD.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\SYSTEM\WINAD.EXE
C:\WINDOWS\SYSTEM\MSNB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\JAVAYV32.EXE
C:\WINDOWS\SYSTEM\APPVY32.EXE
C:\WINDOWS\JAVAYV32.EXE
C:\WINDOWS\WINNO32.EXE
C:\WINDOWS\NTBW.EXE
C:\WINDOWS\JAVANA32.EXE
C:\WINDOWS\SYSTEM\ATLLL.EXE
C:\WINDOWS\SYSTEM\ATLLE.EXE
C:\WINDOWS\APPTM32.EXE
C:\WINDOWS\SYSTEM\MSCG.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\JAVANA32.EXE
C:\WINDOWS\SYSTEM\ADDEA.EXE
C:\WINDOWS\SYSTEM\IPRT.EXE
C:\WINDOWS\IPUT.EXE
C:\WINDOWS\SYSTEM\APPLJ32.EXE
C:\WINDOWS\SYSTEM\NTBY32.EXE
C:\WINDOWS\SYSTEM\WINAD.EXE
C:\WINDOWS\SYSTEM\IPAF32.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {E433A46E-2FD1-792D-709B-F788A00AC431} - C:\WINDOWS\MFCIJ32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SiS Tray] C:\PROGRAM FILES\SIS630_V1.04.54\UTILITY\SISTRAY.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\Program Files\SiS630_V1.04.54\utility\3d\khooker.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [CDWizard] C:\Program Files\CyberLink\CDWizard'98\CDwizard.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Winad Client] C:\PROGRAM FILES\WINAD CLIENT\WINAD.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [JAVAWR.EXE] C:\WINDOWS\SYSTEM\JAVAWR.EXE
O4 - HKLM\..\RunServices: [APPWJ32.EXE] C:\WINDOWS\SYSTEM\APPWJ32.EXE
O4 - HKLM\..\RunServices: [NTHD.EXE] C:\WINDOWS\SYSTEM\NTHD.EXE
O4 - HKLM\..\RunServices: [WINEO32.EXE] C:\WINDOWS\WINEO32.EXE
O4 - HKLM\..\RunServices: [ATLCN.EXE] C:\WINDOWS\ATLCN.EXE
O4 - HKLM\..\RunServices: [D3SH32.EXE] C:\WINDOWS\SYSTEM\D3SH32.EXE
O4 - HKLM\..\RunServices: [SDKQY32.EXE] C:\WINDOWS\SDKQY32.EXE
O4 - HKLM\..\RunServices: [APPLJ32.EXE] C:\WINDOWS\SYSTEM\APPLJ32.EXE
O4 - HKLM\..\RunServices: [NTBW.EXE] C:\WINDOWS\NTBW.EXE
O4 - HKLM\..\RunServices: [APPTM32.EXE] C:\WINDOWS\APPTM32.EXE
O4 - HKLM\..\RunServices: [IPRT.EXE] C:\WINDOWS\SYSTEM\IPRT.EXE
O4 - HKLM\..\RunServices: [IEKH32.EXE] C:\WINDOWS\IEKH32.EXE
O4 - HKLM\..\RunServices: [JAVAYV32.EXE] C:\WINDOWS\JAVAYV32.EXE
O4 - HKLM\..\RunServices: [ATLLL.EXE] C:\WINDOWS\SYSTEM\ATLLL.EXE
O4 - HKLM\..\RunServices: [IEWC.EXE] C:\WINDOWS\SYSTEM\IEWC.EXE
O4 - HKLM\..\RunServices: [WINAD.EXE] C:\WINDOWS\SYSTEM\WINAD.EXE
O4 - HKLM\..\RunServices: [SDKFZ32.EXE] C:\WINDOWS\SDKFZ32.EXE
O4 - HKLM\..\RunServices: [IPAF32.EXE] C:\WINDOWS\SYSTEM\IPAF32.EXE
O4 - HKLM\..\RunServices: [WINCX.EXE] C:\WINDOWS\WINCX.EXE
O4 - HKLM\..\RunServices: [MSNB.EXE] C:\WINDOWS\SYSTEM\MSNB.EXE
O4 - HKLM\..\RunServices: [APPVY32.EXE] C:\WINDOWS\SYSTEM\APPVY32.EXE
O4 - HKLM\..\RunServices: [WINNO32.EXE] C:\WINDOWS\WINNO32.EXE
O4 - HKLM\..\RunServices: [JAVANA32.EXE] C:\WINDOWS\JAVANA32.EXE
O4 - HKLM\..\RunServices: [ATLLE.EXE] C:\WINDOWS\SYSTEM\ATLLE.EXE
O4 - HKLM\..\RunServices: [MSCG.EXE] C:\WINDOWS\SYSTEM\MSCG.EXE
O4 - HKLM\..\RunServices: [ADDEA.EXE] C:\WINDOWS\SYSTEM\ADDEA.EXE
O4 - HKLM\..\RunServices: [IPUT.EXE] C:\WINDOWS\IPUT.EXE
O4 - HKLM\..\RunServices: [NTBY32.EXE] C:\WINDOWS\SYSTEM\NTBY32.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: ubisoft register.lnk = C:\Program Files\Ubi Soft\Register\schedule.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=9eafaeb2a8e2a9518112bc6e0cedee1552dd4ecb1dd748bcf1cf4d42ced1394245b14c137e17952f3a6abadc3d36297b2b37:b70ac5aa8ec48e2e58a29296baabe1d6
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 202.144.115.4,202.144.66.6
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)
please help me
0
Comments
You can try our alternative removal method, with a few exceptions. Instead of "END PROCESS TREE", which is not available on windows 98, you'll have to just end the task.
Here is a list of files that need to be deleted from your system. If you know basic dos commands (such as DEL and CD), then you can easily boot into DOS mode and delete the files you need to get rid of. Otherwise, try my removal method.
The list:
C:\WINDOWS\system\txmzp.dll
C:\WINDOWS\MFCIJ32.DLL
C:\PROGRAM FILES\WINAD CLIENT\WINAD.EXE
C:\WINDOWS\SYSTEM\JAVAWR.EXE
C:\WINDOWS\SYSTEM\APPWJ32.EXE
C:\WINDOWS\SYSTEM\NTHD.EXE
C:\WINDOWS\WINEO32.EXE
C:\WINDOWS\ATLCN.EXE
C:\WINDOWS\SYSTEM\D3SH32.EXE
C:\WINDOWS\SDKQY32.EXE
C:\WINDOWS\SYSTEM\APPLJ32.EXE
C:\WINDOWS\NTBW.EXE
C:\WINDOWS\APPTM32.EXE
C:\WINDOWS\SYSTEM\IPRT.EXE
C:\WINDOWS\IEKH32.EXE
C:\WINDOWS\JAVAYV32.EXE
C:\WINDOWS\SYSTEM\ATLLL.EXE
C:\WINDOWS\SYSTEM\IEWC.EXE
C:\WINDOWS\SYSTEM\WINAD.EXE
C:\WINDOWS\SDKFZ32.EXE
C:\WINDOWS\SYSTEM\IPAF32.EXE
C:\WINDOWS\WINCX.EXE
C:\WINDOWS\SYSTEM\MSNB.EXE
C:\WINDOWS\SYSTEM\APPVY32.EXE
C:\WINDOWS\WINNO32.EXE
C:\WINDOWS\JAVANA32.EXE
C:\WINDOWS\SYSTEM\ATLLE.EXE
C:\WINDOWS\SYSTEM\MSCG.EXE
C:\WINDOWS\SYSTEM\ADDEA.EXE
C:\WINDOWS\IPUT.EXE
C:\WINDOWS\SYSTEM\NTBY32.EXE
You'll also want to get rid of the following HJT entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\txmzp.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {E433A46E-2FD1-792D-709B-F788A00AC431} - C:\WINDOWS\MFCIJ32.DLL
O4 - HKLM\..\Run: [Winad Client] C:\PROGRAM FILES\WINAD CLIENT\WINAD.EXE
O4 - HKLM\..\RunServices: [JAVAWR.EXE] C:\WINDOWS\SYSTEM\JAVAWR.EXE
O4 - HKLM\..\RunServices: [APPWJ32.EXE] C:\WINDOWS\SYSTEM\APPWJ32.EXE
O4 - HKLM\..\RunServices: [NTHD.EXE] C:\WINDOWS\SYSTEM\NTHD.EXE
O4 - HKLM\..\RunServices: [WINEO32.EXE] C:\WINDOWS\WINEO32.EXE
O4 - HKLM\..\RunServices: [ATLCN.EXE] C:\WINDOWS\ATLCN.EXE
O4 - HKLM\..\RunServices: [D3SH32.EXE] C:\WINDOWS\SYSTEM\D3SH32.EXE
O4 - HKLM\..\RunServices: [SDKQY32.EXE] C:\WINDOWS\SDKQY32.EXE
O4 - HKLM\..\RunServices: [APPLJ32.EXE] C:\WINDOWS\SYSTEM\APPLJ32.EXE
O4 - HKLM\..\RunServices: [NTBW.EXE] C:\WINDOWS\NTBW.EXE
O4 - HKLM\..\RunServices: [APPTM32.EXE] C:\WINDOWS\APPTM32.EXE
O4 - HKLM\..\RunServices: [IPRT.EXE] C:\WINDOWS\SYSTEM\IPRT.EXE
O4 - HKLM\..\RunServices: [IEKH32.EXE] C:\WINDOWS\IEKH32.EXE
O4 - HKLM\..\RunServices: [JAVAYV32.EXE] C:\WINDOWS\JAVAYV32.EXE
O4 - HKLM\..\RunServices: [ATLLL.EXE] C:\WINDOWS\SYSTEM\ATLLL.EXE
O4 - HKLM\..\RunServices: [IEWC.EXE] C:\WINDOWS\SYSTEM\IEWC.EXE
O4 - HKLM\..\RunServices: [WINAD.EXE] C:\WINDOWS\SYSTEM\WINAD.EXE
O4 - HKLM\..\RunServices: [SDKFZ32.EXE] C:\WINDOWS\SDKFZ32.EXE
O4 - HKLM\..\RunServices: [IPAF32.EXE] C:\WINDOWS\SYSTEM\IPAF32.EXE
O4 - HKLM\..\RunServices: [WINCX.EXE] C:\WINDOWS\WINCX.EXE
O4 - HKLM\..\RunServices: [MSNB.EXE] C:\WINDOWS\SYSTEM\MSNB.EXE
O4 - HKLM\..\RunServices: [APPVY32.EXE] C:\WINDOWS\SYSTEM\APPVY32.EXE
O4 - HKLM\..\RunServices: [WINNO32.EXE] C:\WINDOWS\WINNO32.EXE
O4 - HKLM\..\RunServices: [JAVANA32.EXE] C:\WINDOWS\JAVANA32.EXE
O4 - HKLM\..\RunServices: [ATLLE.EXE] C:\WINDOWS\SYSTEM\ATLLE.EXE
O4 - HKLM\..\RunServices: [MSCG.EXE] C:\WINDOWS\SYSTEM\MSCG.EXE
O4 - HKLM\..\RunServices: [ADDEA.EXE] C:\WINDOWS\SYSTEM\ADDEA.EXE
O4 - HKLM\..\RunServices: [IPUT.EXE] C:\WINDOWS\IPUT.EXE
O4 - HKLM\..\RunServices: [NTBY32.EXE] C:\WINDOWS\SYSTEM\NTBY32.EXE
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_f...8a29296baabe1d6
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - (no file)
After you delete those files and remove those entries with HJT, PULL THE PLUG on your computer - DON'T shut it down properly. After you turn it back on, post a new log for us.