i restarted my computer and the winoldap is back so is dxsetu.exe this is my hijack this Entry Kind
(Safe, Nasty, Unknown) Description Tip
Logfile of HijackThis v1.98.2
Safe. Shows the version of HijackThis an. The newest version is: v1.98.2! This should be the newest version. (v1.98.2)
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Possibly out of date Shows the version of your Internet Explorer. Newest Version is: 6.00.2800.1106! The version (6.00.2600.0000) is out of date. Check Windows Update to update the Internet Explorer.
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
Safe. running process. (MSGSRV32.EXE)
Systemprozess - Windows Message Server
C:\WINDOWS\SYSTEM\SPOOL32.EXE
Safe. running process. (SPOOL32.EXE)
Systemprozess - Application that handles the spooling of print jobs transparently. It works only when the user configures the printer to spool print jobs.
C:\WINDOWS\SYSTEM\MPREXE.EXE
Safe. running process. (MPREXE.EXE)
Systemprozess - Erlaubt mehr als einen Netzwerkclienten und 95, 98 oder ME einzurichten.
C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
Safe. running process. (SMC.EXE)
C:\WINDOWS\SYSTEM\RPCSS.EXE
Safe. running process. (RPCSS.EXE)
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
Safe. running process. (AVGCC32.EXE)
Grisoft AVG6
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
Safe. running process. (REALSCHED.EXE)
C:\WINDOWS\SYSTEM\STIMON.EXE
Safe. running process. (STIMON.EXE)
Systemprozess - Application that provides one-touch scanning for a scanner. The application is automatically started through registry settings.
C:\WINDOWS\SYSTEM\DDHELP.EXE
Safe. running process. (DDHELP.EXE)
Direct Draw Helper, DirectX
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
Safe. running process. (SGMAIN.EXE)
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
Safe. running process. (SGBHP.EXE)
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Safe. running process. (IEXPLORE.EXE)
Internet Explorer - Wir empfehlen einen sichereren alternativen Browser zu verwenden. (z.B. Firefox)
C:\WINDOWS\EXPLORER.EXE
Safe. running process. (EXPLORER.EXE)
Systemprozess für Desktop und Taskleiste.
C:\WINDOWS\SYSTEM\RNAAPP.EXE
Safe. running process. (RNAAPP.EXE)
Systemprozess - Windows Dial-Up Networking application that handles dial-up modem connections.
C:\WINDOWS\SYSTEM\TAPISRV.EXE
Safe. running process. (TAPISRV.EXE)
Systemprozess - Background service that provides Windows Telephony (TAPI) Support in Windows 98 and Windows NT 4.
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
Safe. running process. (IEXPLORE.EXE)
Internet Explorer - Wir empfehlen einen sichereren alternativen Browser zu verwenden. (z.B. Firefox)
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
Safe. running process. (HIJACKTHIS.EXE)
Tool, mit dem sie dieses Logfile erzeugt haben. Remember that Hijackthis must be run in an own folder. Only if Hijackthis run in an own folder it will create backups!
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
Safe. This page has been identified as safe.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.ntlworld.com/
Possibly nasty This page could possibly be nasty. If you do not know the entry 'http://www.ntlworld.com/', delete it.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
Possibly nasty This page could possibly be nasty. If you do not know the entry '127.0.0.1', delete it.
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
Safe. Entries found in this registry zone are potentially nasty. This application ([06849E9F-C8D7-4D59-B87D-784B7D6BE0B3] - Result: 06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) has been checked. Hit rate: 99 %
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
Safe. Entries found in this registry zone are potentially nasty. This application ([4A368E80-174F-4872-96B5-0B27DDD11DB2] - Result: 4A368E80-174F-4872-96B5-0B27DDD11DB2) has been checked. Hit rate: 99 %
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
Safe. Entries found in this registry zone are potentially nasty. This application ([53707962-6F74-2D53-2644-206D7942484F] - Result: 53707962-6F74-2D53-2644-206D7942484F) has been checked. Hit rate: 99 %
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
Safe. Entries found in this registry zone are potentially nasty. This application ([8E718888-423F-11D2-876E-00A0C9082467] - Result: 8E718888-423F-11D2-876E-00A0C9082467) has been checked. If the name is made up of random letters, found in the folder 'Application Data' and the kind is 'Unknown' , it should be fixed. Hit rate: 99 %
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
Safe. The entered application PCHealth was identified: PCHealth. Hit rate: 78 % (result) Not dangerous, but unnecessary.
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
Safe. The entered application AVG_CC was identified: AVG_CC. Hit rate: 99 % (result)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
Safe. The entered application ScanRegistry was identified: ScanRegistry. Hit rate: 94 % (result)
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
Nasty The entered application LoadPowerProfile was identified: LoadPowerProfile. Hit rate: 95 % (result) Must be fixed!
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\SYGATE\SPF\SMC.EXE -startgui
Safe. The entered application SmcService was identified: SmcService. Hit rate: 63 % (result)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
Safe. The entered application TkBellExe was identified: TkBellExe or TkBell.Exe. Hit rate: 53 % (result) Not dangerous, but unnecessary.
O4 - HKLM\..\Run: [dxset.exe] C:\WINDOWS\dxsetu.exe
Unknown The entered application dxset.exe was identified: None. Hit rate: 6 % (result) Unknown application.
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
Nasty The entered application LoadPowerProfile was identified: LoadPowerProfile. Hit rate: 95 % (result) Must be fixed!
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
Safe. The entered application Avgserv9.exe was identified: Avgserv9.exe. Hit rate: 95 % (result)
O4 - HKLM\..\RunServices: [SmcService] C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
Safe. The entered application SmcService was identified: SmcService. Hit rate: 63 % (result)
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Safe. The entered application MsnMsgr was identified: MsnMsgr. Hit rate: 99 % (result)
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
Safe. The entered application 'SpywareGuard.lnk (sgmain.exe)' was identified: 'SpywareGuard (sgmain.exe )'. Hit rate: 87 % (result)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE10\EXCEL.EXE/3000
Safe. The entry E&xport to Microsoft Excel has been identified as safe. If the entry 'E&xport to Microsoft Excel ' is not needed anymore, it should be fixed.
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
Unnecessarily The entry has been identified as safe. If the entry '' is not needed anymore, it should be fixed.
Unnecessary (deactivated) entry that can be fixed.
O14 - IERESET.INF: START_PAGE_URL=http://www.ntlworld.com/
Possibly nasty This entry should be fixed if this address does not belong to your PC-manufacturer or your 'Internet-Service-Provider (ISP)'. This entry should be fixed if 'http://www.ntlworld.com/' is not your PC-manufacturer or your 'Internet-Service-Provider (ISP)'.
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) -
http://www.gigex.com/tv/igor/gigexagent.dll
Possibly nasty Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! Check if you know this site and fix it if you do not.
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com...43/yacscom.cab
Safe. This entry has been identified as safe.
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
http://pv0fd.pav0.hotmail.msn.com/activex/HMAtchmt.ocx
Safe. This entry has been identified as safe.
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
Safe. This entry has been identified as safe.
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) -
http://www.pcpitstop.com/internet/pcpConnCheck.cab
Safe. This entry has been identified as safe.
O16 - DPF: {F8F88D0D-E455-11D6-B547-00400555C7FB} (DiskHealth2 Class) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
Safe. This entry has been identified as safe.
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/SSC/Sha.../bin/cabsa.cab
Safe. This entry has been identified as safe.
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/SSC/Sha...in/AvSniff.cab
Safe. This entry has been identified as safe.
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://fdl.msn.com/public/chat/msnchat45.cab
Safe. This entry has been identified as safe.
O16 - DPF: {FC9C7D52-C99A-494A-AA79-4A25098F659C} -
http://www.casinotreasure.com/dload/gvdload.cab
Possibly nasty Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! Check if you know this site and fix it if you do not.
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...tatsClient.cab
Safe. This entry has been identified as safe.
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab
Safe. This entry has been identified as safe.
O16 - DPF: {AE609930-A6EB-4A78-B7DA-B3200705FEBD} (Mophun Control) -
http://www.sonyericsson.com/t310/mophun.cab
Possibly nasty Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed. If the name of the ActiveX-Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed! Check if you know this site and fix it if you do not.
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/...com/mickey/us/ win/QuickTimeInstaller.exe
Safe. This entry has been identified as safe.
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
Safe. This entry has been identified as safe.
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
Safe. This entry has been identified as safe.
This log has been checked automatically.
Check your log file automatically at
www.hijackthis.de.
i downloaded everything that you said above and scanned my computer and found loads of stuff i got rid of them. but this problem is still here
these is the ctrl+alt+del window and the message i get whenever i try to end task winoldap