Help - Search - Members - Calendar
Full Version: Browser Hijack?
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Crocker
I am running windows ME 2000 with IE 6.0
At present I am having problems with my homepage only displaying a blank page when I start browsing.
If I type a new url in then It changes to another varying url and I get a 404 message and the page remains blank.
If i do not use the modem to connect but just start IE then the Google URL is dispalyed as normal.

I have downloaded and run spybot.

Here is my highjackthis log

Hope you can help.

Logfile of HijackThis v1.98.2
Scan saved at 21:40:51, on 15/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\IPAP.EXE
C:\WINDOWS\SYSTEM\SYSMI32.EXE
C:\WINDOWS\SYSTEM\SDKPD32.EXE
C:\WINDOWS\MFCYU.EXE
C:\WINDOWS\IPUP32.EXE
C:\WINDOWS\SYSTEM\NTMO32.EXE
C:\WINDOWS\ATLTR.EXE
C:\WINDOWS\NTWJ.EXE
C:\WINDOWS\MSEY32.EXE
C:\WINDOWS\SYSTEM\NETAN.EXE
C:\WINDOWS\SYSTEM\JAVAFX.EXE
C:\WINDOWS\SYSTEM\D3ZM.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\SYSTEM\SISTRAY.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\NETUV32.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\START MENU\PROGRAMS\STARTUP\QBUTTON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\LOTUS\SMARTCTR\SMARTCTR.EXE
C:\LOTUS\SMARTCTR\SUITEST.EXE
C:\LOTUS\ORGANIZE\EASYCLIP.EXE
C:\WINDOWS\SYSTEM\D3ZM.EXE
C:\WINDOWS\SYSTEM\D3ZM.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\lqnho.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\lqnho.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\lqnho.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\lqnho.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\lqnho.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\lqnho.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {8A1767C4-2CF5-234A-F1BC-5C0E51691546} - C:\WINDOWS\ATLUE.DLL
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] irmon.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\SYSTEM\SISTRAY.EXE
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [NETUV32.EXE] C:\WINDOWS\SYSTEM\NETUV32.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRAM FILES\SPYBLOCS\SpyBlocs.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [IPAP.EXE] C:\WINDOWS\IPAP.EXE
O4 - HKLM\..\RunServices: [NTMO32.EXE] C:\WINDOWS\SYSTEM\NTMO32.EXE
O4 - HKLM\..\RunServices: [ATLTR.EXE] C:\WINDOWS\ATLTR.EXE
O4 - HKLM\..\RunServices: [NETAN.EXE] C:\WINDOWS\SYSTEM\NETAN.EXE
O4 - HKLM\..\RunServices: [SDKPD32.EXE] C:\WINDOWS\SYSTEM\SDKPD32.EXE
O4 - HKLM\..\RunServices: [IPUP32.EXE] C:\WINDOWS\IPUP32.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [NTWJ.EXE] C:\WINDOWS\NTWJ.EXE
O4 - HKLM\..\RunServices: [SYSMI32.EXE] C:\WINDOWS\SYSTEM\SYSMI32.EXE
O4 - HKLM\..\RunServices: [MSEY32.EXE] C:\WINDOWS\MSEY32.EXE
O4 - HKLM\..\RunServices: [MFCYU.EXE] C:\WINDOWS\MFCYU.EXE
O4 - HKLM\..\RunServices: [JAVAFX.EXE] C:\WINDOWS\SYSTEM\JAVAFX.EXE
O4 - HKLM\..\RunServices: [D3ZM.EXE] C:\WINDOWS\SYSTEM\D3ZM.EXE
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
O4 - Startup: QButton.exe
O4 - Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe
O4 - Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe
O4 - Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
O4 - Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
LoPhatPhuud
Your log is incomplete. PLease post the entire log!
Crocker
I have re-run hijackthis - here is the new log

Logfile of HijackThis v1.98.2
Scan saved at 19:31:17, on 16/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\IPAP.EXE
C:\WINDOWS\SYSTEM\NETAN.EXE
C:\WINDOWS\SYSTEM\NTMO32.EXE
C:\WINDOWS\ATLTR.EXE
C:\WINDOWS\SYSTEM\SYSMI32.EXE
C:\WINDOWS\NTWJ.EXE
C:\WINDOWS\SYSTEM\SDKPD32.EXE
C:\WINDOWS\SYSTEM\JAVAFX.EXE
C:\WINDOWS\MSEY32.EXE
C:\WINDOWS\IPUP32.EXE
C:\WINDOWS\MFCYU.EXE
C:\WINDOWS\SYSTEM\D3ZM.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\SYSTEM\SISTRAY.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\START MENU\PROGRAMS\STARTUP\QBUTTON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\LOTUS\SMARTCTR\SMARTCTR.EXE
C:\LOTUS\SMARTCTR\SUITEST.EXE
C:\LOTUS\ORGANIZE\EASYCLIP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ie.search.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {3F1E9371-EC2A-B621-2D74-27D9CAF4558A} - C:\WINDOWS\SYSTEM\JAVAVN32.DLL
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] irmon.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\SYSTEM\SISTRAY.EXE
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [NETUV32.EXE] C:\WINDOWS\SYSTEM\NETUV32.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRAM FILES\SPYBLOCS\SpyBlocs.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [IPAP.EXE] C:\WINDOWS\IPAP.EXE
O4 - HKLM\..\RunServices: [NTMO32.EXE] C:\WINDOWS\SYSTEM\NTMO32.EXE
O4 - HKLM\..\RunServices: [ATLTR.EXE] C:\WINDOWS\ATLTR.EXE
O4 - HKLM\..\RunServices: [NETAN.EXE] C:\WINDOWS\SYSTEM\NETAN.EXE
O4 - HKLM\..\RunServices: [SDKPD32.EXE] C:\WINDOWS\SYSTEM\SDKPD32.EXE
O4 - HKLM\..\RunServices: [IPUP32.EXE] C:\WINDOWS\IPUP32.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [NTWJ.EXE] C:\WINDOWS\NTWJ.EXE
O4 - HKLM\..\RunServices: [SYSMI32.EXE] C:\WINDOWS\SYSTEM\SYSMI32.EXE
O4 - HKLM\..\RunServices: [MSEY32.EXE] C:\WINDOWS\MSEY32.EXE
O4 - HKLM\..\RunServices: [MFCYU.EXE] C:\WINDOWS\MFCYU.EXE
O4 - HKLM\..\RunServices: [JAVAFX.EXE] C:\WINDOWS\SYSTEM\JAVAFX.EXE
O4 - HKLM\..\RunServices: [D3ZM.EXE] C:\WINDOWS\SYSTEM\D3ZM.EXE
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
O4 - Startup: QButton.exe
O4 - Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe
O4 - Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe
O4 - Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
O4 - Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
LoPhatPhuud
It still looks as if your log is not all posted. Normally logs go to O16 or even higher. When you psot the next log please confirm that last entry. HJT will normally open the log in Notepad. Please scroll to the bottom and double check the last entry against your post.

Here is something to work on, whiel you check that.

Before we begin, please be sure that HiJackThis is in its own folder. This will allow us to use backups to restore entries if necessary. Please do not put HiJackThis in a temporary folder, or on the Desktop. I suggest using 'c:\program files\hijackthis\' or C:\HiJackThis\, but any name you choose is fine.

Check the following items in HijackThis.
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ie.search.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {3F1E9371-EC2A-B621-2D74-27D9CAF4558A} - C:\WINDOWS\SYSTEM\JAVAVN32.DLL

O4 - HKLM\..\Run: [NETUV32.EXE] C:\WINDOWS\SYSTEM\NETUV32.EXE
O4 - HKLM\..\RunServices: [IPAP.EXE] C:\WINDOWS\IPAP.EXE
O4 - HKLM\..\RunServices: [NTMO32.EXE] C:\WINDOWS\SYSTEM\NTMO32.EXE
O4 - HKLM\..\RunServices: [ATLTR.EXE] C:\WINDOWS\ATLTR.EXE
O4 - HKLM\..\RunServices: [NETAN.EXE] C:\WINDOWS\SYSTEM\NETAN.EXE
O4 - HKLM\..\RunServices: [SDKPD32.EXE] C:\WINDOWS\SYSTEM\SDKPD32.EXE
O4 - HKLM\..\RunServices: [IPUP32.EXE] C:\WINDOWS\IPUP32.EXE
O4 - HKLM\..\RunServices: [NTWJ.EXE] C:\WINDOWS\NTWJ.EXE
O4 - HKLM\..\RunServices: [SYSMI32.EXE] C:\WINDOWS\SYSTEM\SYSMI32.EXE
O4 - HKLM\..\RunServices: [MSEY32.EXE] C:\WINDOWS\MSEY32.EXE
O4 - HKLM\..\RunServices: [MFCYU.EXE] C:\WINDOWS\MFCYU.EXE
O4 - HKLM\..\RunServices: [JAVAFX.EXE] C:\WINDOWS\SYSTEM\JAVAFX.EXE
O4 - HKLM\..\RunServices: [D3ZM.EXE] C:\WINDOWS\SYSTEM\D3ZM.EXE


Close all windows except HijackThis and click Fix checked.

Reboot in Safe Mode*, delete the following: (you may need to show hidden files**)
C:\WINDOWS\SYSTEM\NETUV32.EXE
C:\WINDOWS\IPAP.EXE
C:\WINDOWS\SYSTEM\NTMO32.EXE
C:\WINDOWS\ATLTR.EXE
C:\WINDOWS\SYSTEM\NETAN.EXE
C:\WINDOWS\SYSTEM\SDKPD32.EXE
C:\WINDOWS\IPUP32.EXE
C:\WINDOWS\NTWJ.EXE
C:\WINDOWS\SYSTEM\SYSMI32.EXE
C:\WINDOWS\MSEY32.EXE
C:\WINDOWS\MFCYU.EXE
C:\WINDOWS\SYSTEM\JAVAFX.EXE
C:\WINDOWS\SYSTEM\D3ZM.EXE

*How to Boot into Safe mode: http://service1.symantec.com/SUPPORT/tsgen...001052409420406
**Show Hidden and System files and folders
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Also, uncheck the boxes for hiding known file extensions and hiding protected operating system files. We want to see it all. When we finish here, it would be a good idea to rehide the protected operating system files but leave the rest to be shown.

Reboot in normal mode.


HiJackThis version 198.2 is now available.
If you do not already have it installed, download it from here:
http://www.computercops.biz/downloads-file-328.html
http://tomcoyote.org/hjt/

Then run HiJackThis again and post a new log in this thread.
Crocker
Hi There
I have followed your instructions as listed.
After selecting and fixing the hijackthis list as indicated I re-booted into safe mode and amended the options to allow all files to be seen.
When Itried to delete the .exe files I could not find any of them, I presume that the Hijackthis fox has removed them!
Here is the new log as requested, I have checked and this is all there is.
Logfile of HijackThis v1.98.2
Scan saved at 10:09:49, on 18/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\SYSTEM\SISTRAY.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\SPYBLOCS\SPYBLOCS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\START MENU\PROGRAMS\STARTUP\QBUTTON.EXE
C:\LOTUS\SMARTCTR\SMARTCTR.EXE
C:\LOTUS\SMARTCTR\SUITEST.EXE
C:\LOTUS\ORGANIZE\EASYCLIP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] irmon.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\SYSTEM\SISTRAY.EXE
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRAM FILES\SPYBLOCS\SpyBlocs.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
O4 - Startup: QButton.exe
O4 - Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe
O4 - Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe
O4 - Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
O4 - Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
LoPhatPhuud
THat last log i clean but are you sure that is all of it?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.