Home > General > Winlspak.dll.HELP!

Winlspak.dll.HELP!

Posts 14,022 Points 2335 Hi This could be the worst infection of this type I have seen ... Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Loading... Join over 733,556 other people just like you!

Total of file sizes: 5,457,206 bytes 5.20 M ------------------ Locate.com Results ------------------ C:\WINDOWS\SYSTEM\ swncui.dll Tue Mar 8 2005 3:59:58p ..S.R 227,104 221.78 K dxgsig.dll Tue Mar 8 2005 3:59:58p ..S.R 227,104 Also a lot of things in my favorites don't work....I suppose you understand why that is happening...lol Then I noticed some new programs running: CXbuycv--which I am unable to close Winupdt This utility will find legitimate files in addition to malware. Member Dec 2004 edited Dec 2004 Go here and download FindIt.zip to your Desktop, unzip it and open the FindIt folder and doubleclick on find.bat.

Username or email: I've forgotten my password Forum Password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Community Forum Member Dec 2004 edited Dec 2004 Download LSPfix from here On the opening screen, click the "I know what I'm doing" checkbox. Download VX2Finder9x(126).exe >> http://downloads.subratam.org/VX2Finder9x(126).exe (download it to your desktop) Find the VX2Finder9x(126).exe and double-click on it. If they do not, click once on the circle next to them to put a green checkmark in it.:"Automatically save logfile""Automatically quarantine objects prior to removal""Safe Mode (always request confirmation)""Prompt to

Select the View Tab. Follow the instructions on the screen. You may have to visit more then once Windows Update to install all updates.Not updating Internet Explorer will leave your computer vulnerable to malware and attacks.After the installation of the last Search by Components winlspak.dll- Process Information This component is part of ZestyFind Component Name: winlspak.dll Description of : ZestyFind is adware that sends pop-up warnings regarding Internet security and ads for

Uncheck the "Hide protected operating system files (recommended)" option. Logfile of HijackThis v1.98.2Scan saved at 3:09:24 PM, on 11/20/2004Platform: Windows ME (Win9x 4.90.3000)MSIE: Internet Explorer v5.50 (5.50.4134.0100)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\MPREXE.EXEC:\PROGRAM FILES\STOPZILLA!\SZNTSVC.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.EXEC:\WINDOWS\SYSTEM\DEVLDR16.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\RUNDLL32.EXEC:\PROGRAM FILES\STOPZILLA!\STOPZILLA.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\WINDOWS\TASKMON.EXEC:\PROGRAM FILES\SPYWAREGUARD\SPYWAREGUARDCP.EXEC:\WINDOWS\SYSTEM\RNAAPP.EXEC:\WINDOWS\SYSTEM\TAPISRV.EXEC:\WINDOWS\SYSTEM\STIMON.EXEC:\HJT\HIJACKTHIS.EXER0 - online checker at grc.com. Stay logged in Sign up now!

This is very important !: Update your outdated Internet Explorer browser. Flrman1, Nov 20, 2004 #2 rubaid Thread Starter Joined: Nov 20, 2004 Messages: 2 Hello! Have run Spybot & AdAware many times, but objects found are not deleted or just come back. Are you looking for the solution to your computer problem?

Then click Finish. http://icrontic.com/discussion/25808/need-help-with-persistent-annoying-pop-ups when I double clicked on "Findlt9ME" , "Hijackthis", or "My Computer"...nothing happened. Advertisement Recent Posts Having Problems That I Can Not Fix Michael56 replied Jan 17, 2017 at 4:49 PM Optical lead Triple6 replied Jan 17, 2017 at 4:46 PM What laptop should Post a new HJT log with a report on your condition. __________________ GO BIG BLUE!! 11-20-2004, 11:37 AM #3 ronlee67 Registered Member Join Date: Nov 2004 Posts: 3

If you need any further info, please dont hesitate to lemme know. It will display the files, and User Agent string. BTW, During Spybot's removal of, well, spybots...I came across these: CoolWWWSearch.Bootconf CoolWWWSearch.Loadbat CoolWWWSearch.Msconfd CoolWWWSearch.Oslogo CoolWWWSearch.Tapicfg CoolWWWSearch.Xmlmimefilter I could only get rid of them one at a time but they always showed It will ask you if you want to reboot each time you click it, answer "No" untill you have entered the last file, and then say "yes" Let it reboot Post

As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged I really appreciate your help. We need to get rid of it.Please download LSPFix from here.Run the LSPFix.exe that you have just finished downloading.Check the I know what I'm doing box.In the Keep box you should Using the site is easy and fun.

Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe O4 - HKCU\..\RunOnce: [Web Offer] C:\EZSTUB.EXE O4 - Startup: Internet Answering Machine.lnk = C:\Program Files\CallWave\IAM.EXE O4 - Startup: Microsoft Office.lnk = C:\Program please help - hijack log Started by patiquinn , Nov 20 2004 04:35 PM Please log in to reply 1 reply to this topic #1 patiquinn patiquinn Members 3 posts OFFLINE Western Australia.

flavallee replied Jan 17, 2017 at 4:26 PM Windows Update slowed down laptop?

To help prevent future spyware installations/infections, please read the Anti-Spyware Section and use the tools provided. __________________ GO BIG BLUE!! 11-20-2004, 05:06 PM #5 ronlee67 Registered Member Join Ron Lee \ Remove Advertisements Sponsored Links TechSupportForum.com Advertisement 11-20-2004, 06:35 AM #2 CTSNKY TSF Team Emeritus, Security Team Join Date: Aug 2004 Posts: 10,821 OS: Here is my log from vxfinder: Log for VX2.BetterInternet File Finder (ver126) Files Found--- C:\WINDOWS\SYSTEM\DeCNDI.DLL C:\WINDOWS\SYSTEM\DfCNDI.DLL C:\WINDOWS\SYSTEM\DlNDI.DLL C:\WINDOWS\SYSTEM\WnOCK32.DLL User Agent String--- {2233A721-38CA-11D9-BD4E-0008A1466678} Awaiting further instructions sir! Copy and paste the contents of that log here, IMPORTANT >> do not reboot until you have used Killbox to delete all the files which I will list for you steam

Total of file sizes: 38,392,734 bytes 36.61 M ------------ Strings.exe Qoologic Results ------------ C:\WINDOWS\knncth.dll: excl_urls=photobucket.com,c1.zedo.com,media.deskwizz.com,stats.eblocs.com,passportimages.com,banners.searchingbooth.com,ads234.com,click2.containsitall.com,media.fastclick.net,sandboxer.com,a.websponsors.com,ads.clickagents.com,trk.bestmagsdirect.com,toprebates.com,ad.doubleclick.net,as.casalemedia.com,m3.doubleclick.net,dw.dailywinner.net,img2.mailpostdirect.com,bv.channel.aol.com,adlog2.lzio.com,host239.ipowerweb.com,popups.ad-logics.com,clickserve.cc-dt.com,hits.clickandtrack.net,ads.mydailyhoroscope.net,c5.zedo.com,affiliates.4lowrates.com,couponage.com,ekmas.com,creativeby.viewpoint.com,mydailyhoroscope.net,images.trafficmp.com,actualdeals.com,download.websearch.com,aim-charts.pf.aol.com,aol.com,target.com,yahoo.com,microsoft.com,anrdoezrs.net,isg05.casalemedia.com,jbigpops.cjt1.net,whenusearch.com,trk.pcsecurityshield.com,license.hotbar.com,web.icq.com,sc.musicmatch.com,comcast.net,filter.belkin.com,clickit.go2net.com,adverts.lzio.com,windowsupdate.microsoft.com,v4.windowsupdate.microsoft.com,odysseusmarketing.com,join1.winhundred.com,advert.runescape.com,top-banners.com,sr.websearch.com,messenger.msn.com,download.abetterinternet.com,adserv.internetfuel.com,pops.browseraid.com,banners.pennyweb.com,tv.180solutions.com,s.clkoptimizer.com,adserv1.gruvmedia.com,cdn.icq.com,messenger.zango.com,smileycentral.com,wwp.icq.com,web.tickle.com,isapi60.weatherbug.com,websearch.com,hop.clickbank.net,media76.fastclick.net,mmm.media-motor.net,rightmedia.net,bannerserver.gator.com,www4.yesadvertising.com,ww2.weatherbug.com,servedby.advertising.com,adsrv.qoologic.com,games.yahoo.com,weatherbug.com,jicmedia.cjt1.net,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,ar.atwola.com,ads.addynamix.com,wisapidata.weatherbug.com,popuppers.com,as.adwave.com,look2me.com,jbns2.cydoor.com,bannerfarm.ace.advertising.com,delfinproject.com,view.atdmt.com,mm.delfinproject.com,download.smileycentral.com,xadso.offeroptimizer.com,webpdp.gator.com,ayb.lop.com,stopzilla.com,pgq.yahoo.com,jmnad1.com,topicks.com,e.rn11.com,focusin.ads.targetnet.com,insider.msg.yahoo.com,m2.doubleclick.net,mail.yahoo.com,jcontent.bns1.net,ctl.twain-tech.com,master.mx-targeting.com,hotmail.com,searcheffect.com,ads.delfinproject.com,cfg.mywebsearch.com,akapp.whenu.com,newupdates.lzio.com,allaboutsearching.com,amch.questionmarket.com,adfarm.mediaplex.com,hotmail.msn.com,by.optimost.com,cdn-cf.aol.com,paypopup.com,popuptraffic.com,xadsq.offeroptimizer.com,jnictech.cjt1.net,xanga.com,count.exitexchange.com,servedby.adscpm.com,search200.com,cdn-aimtoday.aol.com,kill-pop-ups.com,us.update.companion.yahoo.com,qksrv.net,clickspring.net,xlime.offeroptimizer.com,sr.adwave.com,zone.msn.com,radio.launch.yahoo.com,ads.bidclix.com,counters.honesty.com,oz.valueclick.com,i.emarketresearchgroup.com,ads2.revenue.net,popup.msn.com,adsv2.delfinproject.com,u.clkoptimizer.com,ezula.com,server.iad.liveperson.net,loadingwebsite.com,pan-advert.com,t.trafficmp.com,clicktrk.com,aaabesthomepage.com,ads.exitexchange.com,us.a1.yimg.com,trafficmp.com,yimg.com,a.as-us.falkag.net,a1.yimg.com,z1.adserver.com,falkag.net,as-us.falkag.net,loginnet.passport.com,ads.inet1.com,pagead2.googlesyndication.com,login.passport.net,v8.alwaysupdatednews.com,adv.eblocs.com,alwaysupdatednews.com,fxfeeds.mozilla.org,cdn.aim.com,ar.atwola.com,c4.maxserving.com,maxserving.com,mediaplex.com,altfarm.mediaplex.com,topmoxie.com,global.msads.net,msads.net,banner.goldenpalace.com,goldenpalace.com,us.i1.yimg.com,cdn.comcast.net,us.yimg.com,us.js1.yimg.com,js1.yimg.com,switch.atdmt.com,atdmt.com,update32.searchmiracle.com,onemoresearch.net, C:\WINDOWS\VPTNFILE.418: TROJ_QOOLOGIC.C C:\WINDOWS\VPTNFILE.418: TROJ_QOOLOGIC.B C:\WINDOWS\VPTNFILE.418: TROJ_QOOLOGIC.A C:\WINDOWS\siipue.dll: updates.qoologic.com C:\WINDOWS\xllumh.exe: updates.qoologic.com C:\WINDOWS\illuzc.dll: updates.qoologic.com C:\WINDOWS\SYSTEM\pav.sig: Qoologic C:\WINDOWS\SYSTEM\pav.sig: Qoologic Click OK.Boot into Safe Mode:Restart your computer and immediately begin tapping the F8 key on your keyboard. This site is completely free -- paid for by advertisers and donations. Select the Safe Mode option and press Enter.To return to normal mode just restart your computer as you normally would.Please remove these entries from Add/Remove Programs in the Control Panel(if present):WinToolsPlease

If not, you should be set to go. Variants/Versions: Release Date: 2004 Spyware-Net features: ZeroSpyware v3.4 Spyware-Net home Vulnerability Scanning Automated Discovery Intrusion Detection Real-Time Protection 24/7 Remote Restore Remove PC History Permanently get rid of temporary Back to top #5 pandh pandh Member Full Member 10 posts Posted 22 December 2004 - 05:40 PM Some of the things you had me remove appear to still be on Tech Support Guy is completely free -- paid for by advertisers and donations.

This utility will find legitimate files in addition to malware. Home Spyware Trends Submit Spyware Watch List Vulnerabilty Advisory Request Removal Information Search the database threats, dlls, file, etc. If they do not, click once on the circle next to them to put a green checkmark in it.:"Move deleted files to Recycle Bin""Include additional object information""Include negligible objects information""Include environment Categories 45951 All Categories6598 Gaming 16745 Hardware 19273 Science & Tech 1855 Internet & Media 849 Lifestyle 28053 Community Edit Need help with persistent, annoying POP-UPs!

Please start a New Thread if you're having a similar issue.View our Welcome Guide to learn how to use this site. Are you sure you just don't want to send me a sledgehammer or baseball bat? :wink: Ty for your patience & help! Therefore I have posted my HJT Log in the hopes that someone could assist me in killing these $#^*&^# Pop-Ups. Uncheck the "Hide file extensions for known file types" option.Click Yes to confirm.

I think I may have half killed it using one of...Ad-awareTrend Micro onlineMicrosoft Anti - Spyware.None of these are getting rid of it.The log looks like this....Logfile of HijackThis v1.99.1Scan saved Toolbar) - http://us.dl1.yimg.com/download.yaho...bio5_1_2_0.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/...6/mcinsctl.cab O16 - DPF: Yahoo! Western Australia. Click the red button with the X after each.

MessengeriTunesWindows Media PlayerSkypeWinRARWinAMPMicrosoft WordMozillaAdobe PhotoshopMozilla FirefoxMusic MatchMicrosoft OutlookGoogle ToolbarMacromedia FlashZone AlarmRoxio's GoBackCanon S450WeatherEyeComodo AntivirusAcronis Privacy Expert SuiteNotePager 32WinFaxTClockExNaviscopePC Suite for NokiaMacromedia Extension ManagerControle ParentalGuardIE-Adware AgentiMarkupUlead Photo ExplorerSlySoft CloneCDIBM Mouse SuiteWinUtilitiesMicrosoft Foundation