Multiple Questions

Hi there. Here I am again :) .

1. I have Kazaa lite ressurrection here and sometimes I found "klaxtlock.dat". I always delete but it comes back. Do I need to worry about it?

2. I use an ibest dialer for connection. Than I've made a new skin download and ibest pop-ups start to pop, even throught SP2 pop-up blocker. I already remove and delete the skin but is still poping. Do I need to uninstall the dialer or it can be fixed?

3. In the hijackthis log, I saw something about DAP ( Idon't use this program anymore). Can I fix it?

I already scan the pc with Panda online, Spybot, adaware6.0, AVG and PestPatrol. And here is the hijackthis log:

Logfile of HijackThis v1.98.2
Scan saved at 15:17:59, on 7/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\ARQUIV~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\ARQUIV~1\PESTPA~1\PPControl.exe
C:\ARQUIV~1\PESTPA~1\PPMemCheck.exe
C:\ARQUIV~1\PESTPA~1\CookiePatrol.exe
C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe
C:\Arquivos de programas\Windows Media Player\wmplayer.exe
C:\Arquivos de programas\Discador iBest\discador.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\ARQUIV~1\Grisoft\AVG6\AVGCC32.EXE
C:\DOCUME~1\ADRIAN~1\CONFIG~1\Temp\Diretório temporário 4 para hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://login.yahoo.com/config/mail?.intl=br
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\ARQUIV~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\ARQUIV~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\ARQUIV~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [AVG_CC] C:\ARQUIV~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Arquivos de programas\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: Download &all with DAP - C:\ARQUIV~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F40B77A7-3805-470D-BCC1-9A6E8B2382D2}: NameServer = 200.225.64.1 200.225.64.2


Thank u very much again :thumbsup:
Adriano C.

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited December 2004
    Your log looks okay. You can uninstall DAP if you don't use it. Is ibestdialer your ISP (Internet Service Provider)? I've never heard of it, and it sounds like spyware (if it's not an ISP). If you don't essentially need it I would reccomend deleting it.
  • edited December 2004
    I don't have the Dap installed anymore, but the log shows one dap item so I can fix that right?
    The ibest is my ISP.
    what about the klaxtlock.dat?
  • SpywareShooterSpywareShooter 127.0.0.1
    edited December 2004
    Yes, fix the DAP entries. Don't do anything about ibest if it is your ISP, and you can delete klaxtlock.dat.
  • edited December 2004
    oK ;) Thanx again..see ya :thumbsup:
This discussion has been closed.