WIN3 box....virus???

Discussion in 'Computer Support' started by john, Dec 15, 2003.

  1. john

    john Guest

    Help. When my desktop loads in Windows 2000, a little box appears in top
    left corner saying "WIN3".
    Sometimes this pops up when I'm on a website and then hangs it.
    Anyone any idea what this is and how can I get rid of it?
    Ta.
    john, Dec 15, 2003
    #1
    1. Advertising

  2. john

    Harrison Guest

    Download, install, update, and run the following programs:
    Adaware - http://www.lavasoftusa.com/
    Spybot Search and Destroy - http://security.kolla.de/
    Spyware Blaster - http://www.wilderssecurity.net/spywareblaster.html

    The first two find and root out spyware, adware, hijackers, and
    dialers.
    The second one will protect your system from further infection by such
    diseases.

    Download and run hijackthis from http://mjc1.com/mirror/hjt/
    and paste the results here for further review.


    On Mon, 15 Dec 2003 17:41:35 -0000, "john" <>
    wrote:

    >Help. When my desktop loads in Windows 2000, a little box appears in top
    >left corner saying "WIN3".
    >Sometimes this pops up when I'm on a website and then hangs it.
    >Anyone any idea what this is and how can I get rid of it?
    >Ta.
    >
    Harrison, Dec 15, 2003
    #2
    1. Advertising

  3. john

    john Guest

    Thanks Harrison, I'm working on it. Meanwhile, here is the the paste from
    hijack! If you can understand it, please reply again.
    Regards.

    John


    Logfile of HijackThis v1.97.7
    Scan saved at 21:18:05, on 15/12/2003
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\regsvc.exe
    C:\WINDOWS\system32\MSTask.exe
    C:\WINDOWS\System32\Wt32exe.exe
    C:\WINDOWS\System32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\WBEM\WinMgmt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    C:\WINDOWS\system32\tblmouse.exe
    C:\WINDOWS\MSMGT.exe
    C:\PROGRA~1\Save\Save.exe
    C:\Program Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe
    C:\windows\system32\nscntrl.exe
    C:\WINDOWS\system32\internat.exe
    C:\Program Files\CConnect\CConnect.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
    C:\Documents and Settings\john wood\Desktop\winzip\WZQKPICK.EXE
    C:\PENSOFT\Quick95.exe
    C:\PENSOFT\fquick32.exe
    C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ymsgr_tray.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\DOCUME~1\JOHNWO~1\DESKTOP\WINZIP\winzip32.exe
    C:\Documents and Settings\john wood\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    http://home.netscape.com/home/winsearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.ntlworld.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    http://home.netscape.com/home/winsearch200.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
    http://keyword.netscape.com/keyword/%s
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    C:\WINDOWS\SYSTEM\blank.htm
    N1 - Netscape 4: user_pref("browser.startup.homepage",
    "http://www.wazzupnet.com"); (C:\Program
    Files\Netscape\Users\\prefs.js)
    O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} -
    C:\WINDOWS\host.dll
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} -
    C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM
    FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
    C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
    C:\WINDOWS\system32\msdxm.ocx
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common
    Files\Real\Update_OB\realsched.exe -osboot
    O4 - HKLM\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
    Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif
    O4 - HKLM\..\Run: [QuickTime Task]
    "C:\WINDOWS\system32\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [tblfunc] tblmouse.exe
    O4 - HKLM\..\Run: [Microsoft Debug Manager] C:\WINDOWS\System32\MDM.exe
    O4 - HKLM\..\Run: [windows update] c:\winnt\web\printers\images\explorer.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
    O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe
    O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe
    O4 - HKLM\..\Run: [XXXmpeg] C:\Program
    Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe /dontdial
    O4 - HKLM\..\Run: [nscntrl] c:\windows\system32\nscntrl.exe /noconnect
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKCU\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
    Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe"
    /background
    O4 - HKCU\..\Run: [Yahoo! Pager]
    C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ypager.exe -quiet
    O4 - Startup: Start.lnk = C:\PENSOFT\Quick95.exe
    O4 - Startup: Quick StartUp.lnk = C:\PENSOFT\fquick32.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
    Office\Office\OSA9.EXE
    O4 - Global Startup: CorrectConnect.lnk = C:\Program
    Files\CConnect\CConnect.exe
    O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone
    Labs\ZoneAlarm\zonealarm.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
    Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Documents and Settings\john
    wood\Desktop\winzip\WZQKPICK.EXE
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Yahoo! Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O12 - Plugin for .mid: C:\Program Files\Internet
    Explorer\PLUGINS\npqtplugin2.dll
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: ChatSpace Full Java Client 3.1.0.229 -
    http://chat-a1.freeserve.com/Java/cfs31229.cab
    O16 - DPF: Yahoo! Chat -
    http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    O16 - DPF: Yahoo! Chess -
    http://download.games.yahoo.com/games/clients/y/ct0_x.cab
    O16 - DPF: Yahoo! Cribbage -
    http://download.games.yahoo.com/games/clients/y/it0_x.cab
    O16 - DPF: Yahoo! Freecell Solitaire -
    http://yog55.games.scd.yahoo.com/yog/y/fs9_x.cab
    O16 - DPF: Yahoo! Poker -
    http://download.games.yahoo.com/games/clients/y/pt0_x.cab
    O16 - DPF: Yahoo! Pool 2 -
    http://download.games.yahoo.com/games/clients/y/potb_x.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
    Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio
    Conferencing) - http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab
    O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} -
    http://download2.abetterinternet.com/download/cabs/CGA18105/clean.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
    http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
    http://a1540.g.akamai.net/7/1540/52...pple.com/borris/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) -
    https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) -
    http://office.microsoft.com/productupdates/content/opuc.cab
    O16 - DPF: {7183CF29-F63C-11D2-923F-00600854D3CE} (IEUpdateOSR2 Control) -
    https://packageswitch.autoregister.net/objects/IEUpdateOSR2.ocx
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
    http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} -
    http://younghips.com/sexcam.cab
    O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
    http://www1.getmapping.com/ecwplugins/ncs.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield
    International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
    http://webcam.citylink.co.nz//AxisCamControl.ocx
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
    http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37885.2894444444
    O16 - DPF: {A0F0D762-D1DE-43AF-B70E-D87864743EB3} (NSLiteUpdateCtrl Class) -
    http://217.145.76.16/nslite/nslite.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
    http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C} (NSUpdateLiteCtrl Class) -
    http://204.177.92.201/quickdl/proclaim/NSupd9x.cab
    O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on
    the Web Control) - http://dgl.microsoft.com/downloads/outc.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
    http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4308/mcfscan.cab
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) -
    http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab


    "john" <> wrote in message
    news:GnmDb.1339$...
    > Help. When my desktop loads in Windows 2000, a little box appears in top
    > left corner saying "WIN3".
    > Sometimes this pops up when I'm on a website and then hangs it.
    > Anyone any idea what this is and how can I get rid of it?
    > Ta.
    >
    >
    john, Dec 15, 2003
    #3
  4. john

    Scrote Guest

    mmmmm nice file........run the suggested progs & stay away from the porn
    sites! lol


    "john" <> wrote in message
    news:nFpDb.363$...
    > Thanks Harrison, I'm working on it. Meanwhile, here is the the paste

    from
    > hijack! If you can understand it, please reply again.
    > Regards.
    >
    > John
    >
    >
    > Logfile of HijackThis v1.97.7
    > Scan saved at 21:18:05, on 15/12/2003
    > Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    > MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    >
    > Running processes:
    > C:\WINDOWS\System32\smss.exe
    > C:\WINDOWS\system32\winlogon.exe
    > C:\WINDOWS\system32\services.exe
    > C:\WINDOWS\system32\lsass.exe
    > C:\WINDOWS\system32\svchost.exe
    > C:\WINDOWS\system32\spoolsv.exe
    > C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    > C:\WINDOWS\System32\svchost.exe
    > C:\WINDOWS\System32\nvsvc32.exe
    > C:\WINDOWS\system32\regsvc.exe
    > C:\WINDOWS\system32\MSTask.exe
    > C:\WINDOWS\System32\Wt32exe.exe
    > C:\WINDOWS\System32\ZoneLabs\vsmon.exe
    > C:\WINDOWS\System32\WBEM\WinMgmt.exe
    > C:\WINDOWS\system32\svchost.exe
    > C:\WINDOWS\Explorer.EXE
    > C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    > C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    > C:\WINDOWS\system32\qttask.exe
    > C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
    > C:\WINDOWS\system32\tblmouse.exe
    > C:\WINDOWS\MSMGT.exe
    > C:\PROGRA~1\Save\Save.exe
    > C:\Program Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe
    > C:\windows\system32\nscntrl.exe
    > C:\WINDOWS\system32\internat.exe
    > C:\Program Files\CConnect\CConnect.exe
    > C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
    > C:\Documents and Settings\john wood\Desktop\winzip\WZQKPICK.EXE
    > C:\PENSOFT\Quick95.exe
    > C:\PENSOFT\fquick32.exe
    > C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ymsgr_tray.exe
    > C:\Program Files\Internet Explorer\iexplore.exe
    > C:\Program Files\Outlook Express\msimn.exe
    > C:\DOCUME~1\JOHNWO~1\DESKTOP\WINZIP\winzip32.exe
    > C:\Documents and Settings\john wood\Local Settings\Temp\HijackThis.exe
    >
    > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    > http://home.netscape.com/home/winsearch.html
    > R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    > http://www.ntlworld.com/
    > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    > http://home.netscape.com/home/winsearch200.html
    > R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
    > http://keyword.netscape.com/keyword/%s
    > R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    > C:\WINDOWS\SYSTEM\blank.htm
    > N1 - Netscape 4: user_pref("browser.startup.homepage",
    > "http://www.wazzupnet.com"); (C:\Program
    > Files\Netscape\Users\\prefs.js)
    > O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} -
    > C:\WINDOWS\host.dll
    > O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} -
    > C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
    > O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

    C:\PROGRAM
    > FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    > O3 - Toolbar: Yahoo! Companion -

    {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
    > C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll
    > O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
    > C:\WINDOWS\system32\msdxm.ocx
    > O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    > O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    > O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon

    initialize
    > O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe

    /STARTUP
    > O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common
    > Files\Real\Update_OB\realsched.exe -osboot
    > O4 - HKLM\..\Run: [System Tray] C:\Documents and Settings\john

    wood\Local
    > Settings\Temporary Internet

    Files\Content.IE5\APCRM1SX\your_details.pif
    > O4 - HKLM\..\Run: [QuickTime Task]
    > "C:\WINDOWS\system32\qttask.exe" -atboottime
    > O4 - HKLM\..\Run: [tblfunc] tblmouse.exe
    > O4 - HKLM\..\Run: [Microsoft Debug Manager]

    C:\WINDOWS\System32\MDM.exe
    > O4 - HKLM\..\Run: [windows update]

    c:\winnt\web\printers\images\explorer.exe
    > O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    > O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
    > O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe
    > O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe
    > O4 - HKLM\..\Run: [XXXmpeg] C:\Program
    > Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe /dontdial
    > O4 - HKLM\..\Run: [nscntrl] c:\windows\system32\nscntrl.exe /noconnect
    > O4 - HKCU\..\Run: [internat.exe] internat.exe
    > O4 - HKCU\..\Run: [System Tray] C:\Documents and Settings\john

    wood\Local
    > Settings\Temporary Internet

    Files\Content.IE5\APCRM1SX\your_details.pif
    > O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN

    Messenger\MsnMsgr.Exe"
    > /background
    > O4 - HKCU\..\Run: [Yahoo! Pager]
    > C:\MYDOCU~1\ONEVAL~1\MESSEN~1\ypager.exe -quiet
    > O4 - Startup: Start.lnk = C:\PENSOFT\Quick95.exe
    > O4 - Startup: Quick StartUp.lnk = C:\PENSOFT\fquick32.exe
    > O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
    > Office\Office\OSA9.EXE
    > O4 - Global Startup: CorrectConnect.lnk = C:\Program
    > Files\CConnect\CConnect.exe
    > O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone
    > Labs\ZoneAlarm\zonealarm.exe
    > O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
    > Files\Adobe\Calibration\Adobe Gamma Loader.exe
    > O4 - Global Startup: WinZip Quick Pick.lnk = C:\Documents and

    Settings\john
    > wood\Desktop\winzip\WZQKPICK.EXE
    > O9 - Extra button: Related (HKLM)
    > O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    > O9 - Extra button: Real.com (HKLM)
    > O9 - Extra button: Yahoo! Messenger (HKLM)
    > O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    > O12 - Plugin for .mid: C:\Program Files\Internet
    > Explorer\PLUGINS\npqtplugin2.dll
    > O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    > O16 - DPF: ChatSpace Full Java Client 3.1.0.229 -
    > http://chat-a1.freeserve.com/Java/cfs31229.cab
    > O16 - DPF: Yahoo! Chat -
    > http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
    > O16 - DPF: Yahoo! Chess -
    > http://download.games.yahoo.com/games/clients/y/ct0_x.cab
    > O16 - DPF: Yahoo! Cribbage -
    > http://download.games.yahoo.com/games/clients/y/it0_x.cab
    > O16 - DPF: Yahoo! Freecell Solitaire -
    > http://yog55.games.scd.yahoo.com/yog/y/fs9_x.cab
    > O16 - DPF: Yahoo! Poker -
    > http://download.games.yahoo.com/games/clients/y/pt0_x.cab
    > O16 - DPF: Yahoo! Pool 2 -
    > http://download.games.yahoo.com/games/clients/y/potb_x.cab
    > O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
    > Control) -

    http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    > O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio
    > Conferencing) - http://cs7.chat.sc5.yahoo.com/v43/yacscom.cab
    > O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} -
    > http://download2.abetterinternet.com/download/cabs/CGA18105/clean.cab
    > O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
    >

    http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    > O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
    >

    http://a1540.g.akamai.net/7/1540/52...pple.com/borris/us/win/QuickTimeInstaller.exe
    > O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) -
    > https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    > O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) -
    > http://office.microsoft.com/productupdates/content/opuc.cab
    > O16 - DPF: {7183CF29-F63C-11D2-923F-00600854D3CE} (IEUpdateOSR2

    Control) -
    > https://packageswitch.autoregister.net/objects/IEUpdateOSR2.ocx
    > O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
    > http://chat.yahoo.com/cab/yacsui.cab
    > O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} -
    > http://younghips.com/sexcam.cab
    > O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
    > http://www1.getmapping.com/ecwplugins/ncs.cab
    > O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield
    > International Setup Player) -

    http://www.installengine.com/engine/isetup.cab
    > O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
    > http://webcam.citylink.co.nz//AxisCamControl.ocx
    > O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
    >

    http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37885.2894444444
    > O16 - DPF: {A0F0D762-D1DE-43AF-B70E-D87864743EB3} (NSLiteUpdateCtrl

    Class) -
    > http://217.145.76.16/nslite/nslite.cab
    > O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash

    Object) -
    > http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    > O16 - DPF: {DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C} (NSUpdateLiteCtrl

    Class) -
    > http://204.177.92.201/quickdl/proclaim/NSupd9x.cab
    > O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office

    Tools on
    > the Web Control) - http://dgl.microsoft.com/downloads/outc.cab
    > O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
    >

    http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4308/mcfscan.cab
    > O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) -
    >

    http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
    >
    >
    > "john" <> wrote in message
    > news:GnmDb.1339$...
    > > Help. When my desktop loads in Windows 2000, a little box appears in

    top
    > > left corner saying "WIN3".
    > > Sometimes this pops up when I'm on a website and then hangs it.
    > > Anyone any idea what this is and how can I get rid of it?
    > > Ta.
    > >
    > >

    >
    >
    Scrote, Dec 15, 2003
    #4
  5. john

    Harrison Guest

    Definitely remove these ones I've left below.
    You may also want to spend some time on google groups on some of the
    others if you're not sure about them.

    On Mon, 15 Dec 2003 21:25:12 -0000, "john" <>
    wrote:

    >Thanks Harrison, I'm working on it. Meanwhile, here is the the paste from
    >hijack! If you can understand it, please reply again.
    >Regards.



    >C:\PROGRA~1\Save\Save.exe


    >C:\Program Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe


    >O2 - BHO: (no name) - {00000273-8230-4DD4-BE4F-6889D1E74167} -
    >C:\WINDOWS\host.dll



    >O4 - HKLM\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
    >Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif


    >O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe


    >O4 - HKLM\..\Run: [susp] C:\WINDOWS\susp.exe


    >O4 - HKLM\..\Run: [XXXmpeg] C:\Program
    >Files\SCom\Dialers\XXXmpeg\XXXmpeg.exe /dontdial


    >O4 - HKCU\..\Run: [System Tray] C:\Documents and Settings\john wood\Local
    >Settings\Temporary Internet Files\Content.IE5\APCRM1SX\your_details.pif



    >O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} -
    >http://download2.abetterinternet.com/download/cabs/CGA18105/clean.cab



    >O16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} -
    >http://younghips.com/sexcam.cab



    >"john" <> wrote in message
    >news:GnmDb.1339$...
    >> Help. When my desktop loads in Windows 2000, a little box appears in top
    >> left corner saying "WIN3".
    >> Sometimes this pops up when I'm on a website and then hangs it.
    >> Anyone any idea what this is and how can I get rid of it?
    >> Ta.
    >>
    >>

    >
    Harrison, Dec 15, 2003
    #5
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. Chill Factor
    Replies:
    4
    Views:
    496
    philo
    Jan 10, 2004
  2. Chill Factor
    Replies:
    41
    Views:
    2,137
    Misa Mirkovic
    Feb 21, 2004
  3. Pete Holland Jr.

    Golden Oldie Question: Installing Win3.1

    Pete Holland Jr., Feb 10, 2004, in forum: Computer Support
    Replies:
    9
    Views:
    624
    Patrick
    Feb 11, 2004
  4. Pete Holland Jr.

    Follow-up On Golden Oldie Question: Installing Win3.1

    Pete Holland Jr., Feb 11, 2004, in forum: Computer Support
    Replies:
    0
    Views:
    363
    Pete Holland Jr.
    Feb 11, 2004
  5. Pete Holland Jr.

    The Final Word: Following Up On The Installing Win3.1 Thing

    Pete Holland Jr., Feb 21, 2004, in forum: Computer Support
    Replies:
    1
    Views:
    393
    Misa Mirkovic
    Feb 21, 2004
Loading...

Share This Page