Page 1 of 1

Posted: 2004-06-25 03:03am
by darthdavid

Code: Select all

O4 - HKLM\..\Run: [WebRebates0] "C:\PROGRAM FILES\WEB_REBATES\WebRebates0.exe" 
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM) 
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {92D30E04-B42C-4027-BDCE-97EF1FF02A53} - C:\WINDOWS\SYSTEM\JODBCTRAC.DLL
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\MXTARGET.DLL
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\BXXS5.DLL 

There's other stuff but i'm tired, oooh so tired. I'll post more later if no one else does.

Posted: 2004-06-25 07:52pm
by White Haven
Sweet jesus, that's hideous. Do them a favor, back up data and hose it with a thermonuclear...garden hose. From my experience at work (tech), once you hit a certain critical mass of crap on a system it's nearly impossible to put truly to rights again. Well, possible, but WAY more work than it's worth in many cases.

Posted: 2004-06-25 10:15pm
by EmperorMing
Start with spybot, ad-aware and CWshredder.

Posted: 2004-06-25 11:43pm
by Mad
EmperorMing wrote:Start with spybot, ad-aware and CWshredder.
Yeah, those should clear out most of the stuff. Then post Hijack This! logs to see if anything remaining should obviously be removed.

Posted: 2004-06-26 12:19pm
by phongn
Get VX2Finder as well -- that is a particularly nasty piece of spyware.