Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Support > WIN3 box....virus???

Reply
Thread Tools

WIN3 box....virus???

 
 
john
Guest
Posts: n/a
 
      12-15-2003
Help. When my desktop loads in Windows 2000, a little box appears in top
left corner saying "WIN3".
Sometimes this pops up when I'm on a website and then hangs it.
Anyone any idea what this is and how can I get rid of it?
Ta.


 
Reply With Quote
 
 
 
 
Harrison
Guest
Posts: n/a
 
      12-15-2003
Download, install, update, and run the following programs:
Adaware - http://www.lavasoftusa.com/
Spybot Search and Destroy - http://security.kolla.de/
Spyware Blaster - http://www.wilderssecurity.net/spywareblaster.html

The first two find and root out spyware, adware, hijackers, and
dialers.
The second one will protect your system from further infection by such
diseases.

Download and run hijackthis from http://mjc1.com/mirror/hjt/
and paste the results here for further review.


On Mon, 15 Dec 2003 17:41:35 -0000, "john" <(E-Mail Removed)>
wrote:

>Help. When my desktop loads in Windows 2000, a little box appears in top
>left corner saying "WIN3".
>Sometimes this pops up when I'm on a website and then hangs it.
>Anyone any idea what this is and how can I get rid of it?
>Ta.
>


 
Reply With Quote
 
 
 
 
john
Guest
Posts: n/a
 
      12-15-2003
Thanks Harrison, I'm working on it. Meanwhile, here is the the paste from
hijack! If you can understand it, please reply again.
Regards.

John


Logfile of HijackThis v1.97.7
Scan saved at 21:18:05, on 15/12/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\System32\Wt32exe.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\WINDOWS\system32\tblmouse.exe
C:\WINDOWS\MSMGT.exe
C:\PROGRA~1\Save\Save.exe
C:\Program Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe
C:\windows\system32\nscntrl.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\CConnect\CConnect.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Documents and Settings\john wood\Desktop\winzip\WZQKPICK.EXE
C:\PENSOFT\Quick95.exe
C:\PENSOFT\fquick32.exe
C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\DOCUME~1\JOHNWO~1\DESKTOP\WINZIP\winzip32.exe
C:\Documents and Settings\john wood\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://home.netscape.com/home/winsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.ntlworld.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://keyword.netscape.com/keyword/%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
C:\WINDOWS\SYSTEM\blank.htm
N1 - Netscape 4: user_pref("browser.startup.homepage",
"http://www.wazzupnet.com"); (C:\Program
Files\Netscape\Users\(E-Mail Removed)\prefs.js)
O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} -
C:\WINDOWS\host.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} -
C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM
FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common
Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif
O4 - HKLM\..\Run: [QuickTime Task]
"C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [tblfunc] tblmouse.exe
O4 - HKLM\..\Run: [Microsoft Debug Manager] C:\WINDOWS\System32\MDM.exe
O4 - HKLM\..\Run: [windows update] c:\winnt\web\printers\images\explorer.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe
O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe
O4 - HKLM\..\Run: [XXXmpeg] C:\Program
Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe /dontdial
O4 - HKLM\..\Run: [nscntrl] c:\windows\system32\nscntrl.exe /noconnect
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe"
/background
O4 - HKCU\..\Run: [Yahoo! Pager]
C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ypager.exe -quiet
O4 - Startup: Start.lnk = C:\PENSOFT\Quick95.exe
O4 - Startup: Quick StartUp.lnk = C:\PENSOFT\fquick32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: CorrectConnect.lnk = C:\Program
Files\CConnect\CConnect.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone
Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Documents and Settings\john
wood\Desktop\winzip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .mid: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 -
http://chat-a1.freeserve.com/Java/cfs31229.cab
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/game...ts/y/ct0_x.cab
O16 - DPF: Yahoo! Cribbage -
http://download.games.yahoo.com/game...ts/y/it0_x.cab
O16 - DPF: Yahoo! Freecell Solitaire -
http://yog55.games.scd.yahoo.com/yog/y/fs9_x.cab
O16 - DPF: Yahoo! Poker -
http://download.games.yahoo.com/game...ts/y/pt0_x.cab
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/game...s/y/potb_x.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio
Conferencing) - http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} -
http://download2.abetterinternet.com...8105/clean.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) -
https://webresponse.one.microsoft.co...veX/winrep.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) -
http://office.microsoft.com/productu...ntent/opuc.cab
O16 - DPF: {7183CF29-F63C-11D2-923F-00600854D3CE} (IEUpdateOSR2 Control) -
https://packageswitch.autoregister.n...UpdateOSR2.ocx
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} -
http://younghips.com/sexcam.cab
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
http://www1.getmapping.com/ecwplugins/ncs.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield
International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://webcam.citylink.co.nz//AxisCamControl.ocx
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.co...885.2894444444
O16 - DPF: {A0F0D762-D1DE-43AF-B70E-D87864743EB3} (NSLiteUpdateCtrl Class) -
http://217.145.76.16/nslite/nslite.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C} (NSUpdateLiteCtrl Class) -
http://204.177.92.201/quickdl/proclaim/NSupd9x.cab
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on
the Web Control) - http://dgl.microsoft.com/downloads/outc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/is...08/mcfscan.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) -
http://us.dl1.yimg.com/download.comp...bio5_1_6_0.cab


"john" <(E-Mail Removed)> wrote in message
news:GnmDb.1339$(E-Mail Removed)...
> Help. When my desktop loads in Windows 2000, a little box appears in top
> left corner saying "WIN3".
> Sometimes this pops up when I'm on a website and then hangs it.
> Anyone any idea what this is and how can I get rid of it?
> Ta.
>
>



 
Reply With Quote
 
Scrote
Guest
Posts: n/a
 
      12-15-2003
mmmmm nice file........run the suggested progs & stay away from the porn
sites! lol


"john" <(E-Mail Removed)> wrote in message
news:nFpDb.363$(E-Mail Removed)...
> Thanks Harrison, I'm working on it. Meanwhile, here is the the paste

from
> hijack! If you can understand it, please reply again.
> Regards.
>
> John
>
>
> Logfile of HijackThis v1.97.7
> Scan saved at 21:18:05, on 15/12/2003
> Platform: Windows 2000 SP4 (WinNT 5.00.2195)
> MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\system32\spoolsv.exe
> C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\System32\nvsvc32.exe
> C:\WINDOWS\system32\regsvc.exe
> C:\WINDOWS\system32\MSTask.exe
> C:\WINDOWS\System32\Wt32exe.exe
> C:\WINDOWS\System32\ZoneLabs\vsmon.exe
> C:\WINDOWS\System32\WBEM\WinMgmt.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\Explorer.EXE
> C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
> C:\Program Files\Common Files\Real\Update_OB\realsched.exe
> C:\WINDOWS\system32\qttask.exe
> C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
> C:\WINDOWS\system32\tblmouse.exe
> C:\WINDOWS\MSMGT.exe
> C:\PROGRA~1\Save\Save.exe
> C:\Program Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe
> C:\windows\system32\nscntrl.exe
> C:\WINDOWS\system32\internat.exe
> C:\Program Files\CConnect\CConnect.exe
> C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
> C:\Documents and Settings\john wood\Desktop\winzip\WZQKPICK.EXE
> C:\PENSOFT\Quick95.exe
> C:\PENSOFT\fquick32.exe
> C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ymsgr_tray.exe
> C:\Program Files\Internet Explorer\iexplore.exe
> C:\Program Files\Outlook Express\msimn.exe
> C:\DOCUME~1\JOHNWO~1\DESKTOP\WINZIP\winzip32.exe
> C:\Documents and Settings\john wood\Local Settings\Temp\HijackThis.exe
>
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
> http://home.netscape.com/home/winsearch.html
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
> http://www.ntlworld.com/
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
> http://home.netscape.com/home/winsearch200.html
> R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
> http://keyword.netscape.com/keyword/%s
> R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
> C:\WINDOWS\SYSTEM\blank.htm
> N1 - Netscape 4: user_pref("browser.startup.homepage",
> "http://www.wazzupnet.com"); (C:\Program
> Files\Netscape\Users\(E-Mail Removed)\prefs.js)
> O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} -
> C:\WINDOWS\host.dll
> O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} -
> C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
> O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\PROGRAM
> FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
> O3 - Toolbar: Yahoo! Companion -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
> C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
> O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
> C:\WINDOWS\system32\msdxm.ocx
> O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
> O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
> O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon

initialize
> O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe

/STARTUP
> O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common
> Files\Real\Update_OB\realsched.exe -osboot
> O4 - HKLM\..\Run: [System Tray] C:\Documents and Settings\john

wood\Local
> Settings\Temporary Internet

Files\Content.IE5\APCRM1SX\your_details.pif
> O4 - HKLM\..\Run: [QuickTime Task]
> "C:\WINDOWS\system32\qttask.exe" -atboottime
> O4 - HKLM\..\Run: [tblfunc] tblmouse.exe
> O4 - HKLM\..\Run: [Microsoft Debug Manager]

C:\WINDOWS\System32\MDM.exe
> O4 - HKLM\..\Run: [windows update]

c:\winnt\web\printers\images\explorer.exe
> O4 - HKLM\..\Run: [LoadQM] loadqm.exe
> O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
> O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe
> O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe
> O4 - HKLM\..\Run: [XXXmpeg] C:\Program
> Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe /dontdial
> O4 - HKLM\..\Run: [nscntrl] c:\windows\system32\nscntrl.exe /noconnect
> O4 - HKCU\..\Run: [internat.exe] internat.exe
> O4 - HKCU\..\Run: [System Tray] C:\Documents and Settings\john

wood\Local
> Settings\Temporary Internet

Files\Content.IE5\APCRM1SX\your_details.pif
> O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN

Messenger\MsnMsgr.Exe"
> /background
> O4 - HKCU\..\Run: [Yahoo! Pager]
> C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ypager.exe -quiet
> O4 - Startup: Start.lnk = C:\PENSOFT\Quick95.exe
> O4 - Startup: Quick StartUp.lnk = C:\PENSOFT\fquick32.exe
> O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
> Office\Office\OSA9.EXE
> O4 - Global Startup: CorrectConnect.lnk = C:\Program
> Files\CConnect\CConnect.exe
> O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone
> Labs\ZoneAlarm\zonealarm.exe
> O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
> Files\Adobe\Calibration\Adobe Gamma Loader.exe
> O4 - Global Startup: WinZip Quick Pick.lnk = C:\Documents and

Settings\john
> wood\Desktop\winzip\WZQKPICK.EXE
> O9 - Extra button: Related (HKLM)
> O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
> O9 - Extra button: Real.com (HKLM)
> O9 - Extra button: Yahoo! Messenger (HKLM)
> O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
> O12 - Plugin for .mid: C:\Program Files\Internet
> Explorer\PLUGINS\npqtplugin2.dll
> O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
> O16 - DPF: ChatSpace Full Java Client 3.1.0.229 -
> http://chat-a1.freeserve.com/Java/cfs31229.cab
> O16 - DPF: Yahoo! Chat -
> http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
> O16 - DPF: Yahoo! Chess -
> http://download.games.yahoo.com/game...ts/y/ct0_x.cab
> O16 - DPF: Yahoo! Cribbage -
> http://download.games.yahoo.com/game...ts/y/it0_x.cab
> O16 - DPF: Yahoo! Freecell Solitaire -
> http://yog55.games.scd.yahoo.com/yog/y/fs9_x.cab
> O16 - DPF: Yahoo! Poker -
> http://download.games.yahoo.com/game...ts/y/pt0_x.cab
> O16 - DPF: Yahoo! Pool 2 -
> http://download.games.yahoo.com/game...s/y/potb_x.cab
> O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
> Control) -

http://download.macromedia.com/pub/s...irector/sw.cab
> O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio
> Conferencing) - http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab
> O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} -
> http://download2.abetterinternet.com...8105/clean.cab
> O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
>

http://download.microsoft.com/downlo...22/wmv9VCM.CAB
> O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
>

http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
> O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) -
> https://webresponse.one.microsoft.co...veX/winrep.cab
> O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) -
> http://office.microsoft.com/productu...ntent/opuc.cab
> O16 - DPF: {7183CF29-F63C-11D2-923F-00600854D3CE} (IEUpdateOSR2

Control) -
> https://packageswitch.autoregister.n...UpdateOSR2.ocx
> O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
> http://chat.yahoo.com/cab/yacsui.cab
> O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} -
> http://younghips.com/sexcam.cab
> O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
> http://www1.getmapping.com/ecwplugins/ncs.cab
> O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield
> International Setup Player) -

http://www.installengine.com/engine/isetup.cab
> O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
> http://webcam.citylink.co.nz//AxisCamControl.ocx
> O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
>

http://v4.windowsupdate.microsoft.co...885.2894444444
> O16 - DPF: {A0F0D762-D1DE-43AF-B70E-D87864743EB3} (NSLiteUpdateCtrl

Class) -
> http://217.145.76.16/nslite/nslite.cab
> O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash

Object) -
> http://download.macromedia.com/pub/s...sh/swflash.cab
> O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C} (NSUpdateLiteCtrl

Class) -
> http://204.177.92.201/quickdl/proclaim/NSupd9x.cab
> O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office

Tools on
> the Web Control) - http://dgl.microsoft.com/downloads/outc.cab
> O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
>

http://download.mcafee.com/molbin/is...08/mcfscan.cab
> O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) -
>

http://us.dl1.yimg.com/download.comp...bio5_1_6_0.cab
>
>
> "john" <(E-Mail Removed)> wrote in message
> news:GnmDb.1339$(E-Mail Removed)...
> > Help. When my desktop loads in Windows 2000, a little box appears in

top
> > left corner saying "WIN3".
> > Sometimes this pops up when I'm on a website and then hangs it.
> > Anyone any idea what this is and how can I get rid of it?
> > Ta.
> >
> >

>
>



 
Reply With Quote
 
Harrison
Guest
Posts: n/a
 
      12-15-2003
Definitely remove these ones I've left below.
You may also want to spend some time on google groups on some of the
others if you're not sure about them.

On Mon, 15 Dec 2003 21:25:12 -0000, "john" <(E-Mail Removed)>
wrote:

>Thanks Harrison, I'm working on it. Meanwhile, here is the the paste from
>hijack! If you can understand it, please reply again.
>Regards.



>C:\PROGRA~1\Save\Save.exe


>C:\Program Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe


>O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} -
>C:\WINDOWS\host.dll



>O4 - HKLM\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
>Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif


>O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe


>O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe


>O4 - HKLM\..\Run: [XXXmpeg] C:\Program
>Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe /dontdial


>O4 - HKCU\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
>Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif



>O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} -
>http://download2.abetterinternet.com...8105/clean.cab



>O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} -
>http://younghips.com/sexcam.cab



>"john" <(E-Mail Removed)> wrote in message
>news:GnmDb.1339$(E-Mail Removed)...
>> Help. When my desktop loads in Windows 2000, a little box appears in top
>> left corner saying "WIN3".
>> Sometimes this pops up when I'm on a website and then hangs it.
>> Anyone any idea what this is and how can I get rid of it?
>> Ta.
>>
>>

>


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Help, Trying to install Win3.1 on a 72yr old mans computer Chill Factor Computer Support 41 02-21-2004 06:51 PM
The Final Word: Following Up On The Installing Win3.1 Thing Pete Holland Jr. Computer Support 1 02-21-2004 06:49 PM
Follow-up On Golden Oldie Question: Installing Win3.1 Pete Holland Jr. Computer Support 0 02-11-2004 06:49 PM
Golden Oldie Question: Installing Win3.1 Pete Holland Jr. Computer Support 9 02-11-2004 03:35 AM
Help ,Im Trying to install Win3.1 on a 72yr old mans computer Chill Factor Computer Support 4 01-10-2004 12:22 AM



Advertisments