Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - redryder

Pages: [1]
1
Tech Clinic / Firefox issues - HJT log attached
« on: August 13, 2006, 08:25:26 AM »
Thanks for the help... The yahoo page was taking forever to load using Firefox (I assumed I was being hijacked and consequently never kept the page open long enough to find out - all links button had stopped working on a previous surf session as well).  IE would load the page instantly.   Do most hijacking codes only affect a single browser or do they act globally across all?  Forgive my ignorance.

Red

2
Tech Clinic / Firefox issues - HJT log attached
« on: August 12, 2006, 03:40:37 AM »
Was surfing a few days ago using Firfox and all links stopped working...  Now when I start up Firefox, my homepage (Yahoo)t appears but at the bottom it says downloading from us1/ming or something along those lines.  I quickly exit out before it will finish as I believe a malacious deed is being performed...  I am able to use Window Explorer with no issue.. Could just be paranoid, but would you have a look please.  Your help is much appreciated.

Thanks,

Redryder


Logfile of HijackThis v1.99.1
Scan saved at 1:14:24 AM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
D:\Program Files\Scansoft\PaperPort\pptd40nt.exe
D:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
D:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
D:\CyberLink PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
D:\Program Files\DAEMON Tools\daemon.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Electronic Arts\EA Downloader\Core.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\patches and cracks\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [PathNvidiaTV] C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [PaperPort PTD] D:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] D:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] D:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [RemoteControl] "D:\CyberLink PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] D:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [DAEMON Tools] "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EA Downloader\Core.exe -silent
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

3
Tech Clinic / desktop/homepage hijacker + more - please help
« on: May 05, 2005, 12:49:31 PM »
hello Guestolo,

Heres the latest:

-Deleted the following files as requested:

C:\WINNT\system32\combo.ex_.exe
C:\WINNT\system32\spoolsrv32.exe <=notice the spelling
C:\WINNT\system32\txfdb32.dll
C:\WINNT\winsx.dll
C:\WINNT\fdrest.exe

-In safe mode I ran rkfiles.bat,  here are the results:

C:\rkfiles
 
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder............
------------------------
C:\WINNT\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
 
Files Found in all users startup Folder............
------------------------
Files Found in all users windows Folder............
------------------------
Finished
bye


-hijackthis file also ran... results follow:

Logfile of HijackThis v1.99.1
Scan saved at 10:02:40 AM, on 5/5/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus Xtreme G Configuration Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114014142184
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

------------------------------------------------------------------------

-Results from Jottis follows:
-----------------------------------------------------------------
cidaconf.exe
-------------------
Scanner results  
AntiVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found nothing
BitDefender  Found nothing
ClamAV  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found nothing
mks_vir  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
VBA32  Found nothing

---------------------------------
downf46.exe
-----------------
AntiVir  Found Worm/Bagz.J  
Avast  Found Win32:Bagz-F-UPX  
AVG Antivirus  Found I-Worm/Bagz.Q  
BitDefender  Found Win32.Bagz.H@mm  
ClamAV  Found nothing
Dr.Web  Found Trojan.Pigmail  
F-Prot Antivirus  Found nothing
Fortinet  Found W32/Mochi-tr  
Kaspersky Anti-Virus  Found Email-Worm.Win32.Bagz.h  
mks_vir  Found Worm.Bagz.H  
NOD32  Found Win32/Bagz.H  
Norman Virus Control  Found Bagz.H  
VBA32  Found Email-Worm.Win32.Bagz.h

------------------------------------
downf102.exe
---------------------
AntiVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found nothing
BitDefender  Found nothing
ClamAV  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found nothing
mks_vir  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
VBA32  Found nothing

--------------------------------------
mfunclo.exe
---------------------------
AntiVir  Found TR/Drop.Small.VN  
Avast  Found nothing
AVG Antivirus  Found Dropper.Small.17.A  
BitDefender  Found BehavesLike:Trojan.StartPage (probable variant)  
ClamAV  Found Trojan.Clicker.Agent-33  
Dr.Web  Found Trojan.MulDrop.1847  
F-Prot Antivirus  Found nothing
Fortinet  Found W32/Daodrop.B-tr  
Kaspersky Anti-Virus  Found Trojan-Dropper.Win32.Small.vn  
mks_vir  Found Win32 (probable variant)  
NOD32  Found probably unknown NewHeur_PE (probable variant)  
Norman Virus Control  Found W32/Smalldrp.BZX  
VBA32  Found Trojan-Dropper.Win32.Small.vn  

----------------------------------------
msmconret.dll
----------------------
AntiVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found nothing
BitDefender  Found nothing
ClamAV  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found rojanDownloader.Win32.Agent.fc  
mks_vir  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
VBA32  Found nothing

------------------------------------
sccfull.exe
----------------------
AntiVir  Found nothing
Avast  Found nothing
AVG Antivirus  Found nothing
BitDefender  Found nothing
ClamAV  Found nothing
Dr.Web  Found nothing
F-Prot Antivirus  Found nothing
Fortinet  Found nothing
Kaspersky Anti-Virus  Found nothing
mks_vir  Found nothing
NOD32  Found nothing
Norman Virus Control  Found nothing
VBA32  Found nothing
-----------------------------------------------------

Looks like some of these files are infected.. I'll wait for your reply on how to deal with them....

Thanks again,

Paul (redryder)

4
Tech Clinic / desktop/homepage hijacker + more - please help
« on: May 03, 2005, 08:46:18 AM »
Well, as far as I can tell, the computer is back to normal..  My desktop has been restored, my home page is no longer hijacked, pop-ups are gone, etc.

Thanks again for all the help.  I'll post one last Hijackthis log and the results from rkfiles.bat (with any luck, it will be the last one!!!).

Logfile of HijackThis v1.99.1
Scan saved at 5:13:01 AM, on 5/3/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link AirPlus Xtreme G\AirPlus.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINNT\System32\nvsvc32.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINNT\System32\wuauclt.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus Xtreme G Configuration Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114014142184
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

----------------------------------------------------------------------
C:\rkfiles
 
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder............
------------------------
C:\WINNT\system32\cidaconf.exe: UPX!
C:\WINNT\system32\combo.ex_.exe: UPX!
C:\WINNT\system32\downf102.exe: UPX!
C:\WINNT\system32\downf46.exe: UPX!
C:\WINNT\system32\sccfull.exe: UPX!
C:\WINNT\system32\spoolsrv32.exe: UPX!
C:\WINNT\system32\txfdb32.dll: UPX!
C:\WINNT\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
 
Files Found in all users startup Folder............
------------------------
Files Found in all users windows Folder............
------------------------
C:\WINNT\fdrest.exe: UPX!
C:\WINNT\MEMORY.DMP: UPX!
C:\WINNT\MEMORY.DMP: UPX!
C:\WINNT\MEMORY.DMP: UPX!
C:\WINNT\MEMORY.DMP: MSTVGS.ChannelLineupx!j6
C:\WINNT\msmconret.dll: UPX!
C:\WINNT\winsx.dll: UPX!
C:\WINNT\MEMORY.DMP: FSG!
C:\WINNT\mfunclo.exe: FSG!
Finished
bye
------------------------------------------------------------------------

Thanks again for all your efforts in helping me removing the malware.  I'd like to make a donation for your services.. The paypal link goes to someone named Tangea.  Is this the preferred account for making a donation?

Paul (redryder)

5
Tech Clinic / desktop/homepage hijacker + more - please help
« on: May 02, 2005, 10:30:38 PM »
I deleted C:\WINNT\system32\hdzjv.dll <-file  and did not have any of the other mentioned files/folders/programs.

The export and export2 files follow:
_________________________________________
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager]
"LoadedBefore"="1"
"ThemeActive"="1"
"LastUserLangID"="1033"
"DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,72,00,65,00,73,00,6f,00,75,00,72,00,63,00,65,00,73,00,5c,\
  00,54,00,68,00,65,00,6d,00,65,00,73,00,5c,00,6c,00,75,00,6e,00,61,00,5c,00,\
  6c,00,75,00,6e,00,61,00,2e,00,6d,00,73,00,73,00,74,00,79,00,6c,00,65,00,73,\
  00,00,00
"ColorName"="NormalColor"
"SizeName"="NormalSize"
_____________________________________________________________
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:00000091

__________________________________________________________
Thanks,

Paul

6
Tech Clinic / desktop/homepage hijacker + more - please help
« on: May 02, 2005, 08:09:44 AM »
I'm trapped at work for the next 12 hours..  Will try your last set of instructions when I get home.

Thanks again,

Paul

7
Tech Clinic / desktop/homepage hijacker + more - please help
« on: May 02, 2005, 12:41:07 AM »
Hello Guestolo,

I read your last post after performing the whole procedure.  I'm sure the version of REMV3 is the same.. I went ahead and downloaded the one from this thread and installed it - after the fact.  All the files were replaced with ones of equal size.  The reason I could not download it the 1st time was because I was not in the "full version" of the forum.. I guess attachments don't show up unless you're in the "full version".

Enough on that..  This time everything went fairly smooth.  A lot of the files in Hijack this were gone from yesterdays cleanup attempt.  I seem to have regained control of my Internet Explorer (no pop-ups, no redirects, homepage is once again yahoo, etc).  But my desktop is still hijacked..  A nasty black "Warning!! You're in danger!" message still  appears.  I right clicked on the desktop, went to properties and the address URL was //c:\\WINNT\\WEB\desktop.html.  I proceeded to delete this file and refresh the desktop and now I have a plain white desktop (with the same URL address).  I do not get the usual desktop configuration window when right clicking and going to properties (ie Wallpaper, screensaver, etc). However, I do see my original desktop picture for a short while when booting up... Dont know if this info helps out or not..  

Maybe the following logs will:

_____________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 10:28:22 PM, on 5/1/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link AirPlus Xtreme G\AirPlus.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINNT\System32\nvsvc32.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\System32\wuauclt.exe
C:\WINNT\System32\svchost.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [sysobj.exe] sysobj.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [sprmover.exe] sprmover.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus Xtreme G Configuration Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114014142184
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

_________________________________________

C:\log.txt states:

Files Found.................
----------------------------------------

Files Not deleted.................
----------------------------------------

Merging registry entries
-----------------------------------------------------------------
The Registry Entries Found...
-----------------------------------------------------------------
 
 
Other bad files to be Manually deleted.. Please note that this might also list legit Files, be careful while deleting
-----------------------------------------------------------------
 Volume in drive C has no label.
 Volume Serial Number is 9873-4FF9

 Directory of C:\WINNT\system32

04/30/2005  06:14 PM            19,456 hdzjv.dll
               1 File(s)         19,456 bytes
               0 Dir(s)  110,273,032,192 bytes free
msi.dll
Finished

_______________________________________________________
SpSeHjfix.txt states:



(4/30/05 7:57:07 PM) SPSeHjFix started v1.1.2
(4/30/05 7:57:07 PM) OS: WinXP  (5.1.2600)
(4/30/05 7:57:07 PM) Language: english
(4/30/05 7:57:07 PM) Win-Path: C:\WINNT
(4/30/05 7:57:07 PM) System-Path: C:\WINNT\System32
(4/30/05 7:57:07 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(4/30/05 7:57:17 PM) Disinfection started
(4/30/05 7:57:17 PM) Bad-Dll(IEP): (not found)
(4/30/05 7:57:17 PM) Bad-Dll(IEP) in BHO: (not found)
(4/30/05 7:57:17 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINNT\openwin.dll
(4/30/05 7:57:17 PM) Searchassistant Uninstaller - Keys Deleted
(4/30/05 7:57:17 PM) UBF: 5 - UBB: 0 - UBR: 12
(4/30/05 7:57:17 PM) UBF: 5 - UBB: 0 - UBR: 12
(4/30/05 7:57:17 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
(4/30/05 7:57:17 PM) Stealth-String not found
(4/30/05 7:57:17 PM) File added to delete: c:\winnt\openwin.dll
(4/30/05 7:57:17 PM) Reboot


(4/30/05 7:59:01 PM) SPSeHjFix started v1.1.2
(4/30/05 7:59:01 PM) OS: WinXP  (5.1.2600)
(4/30/05 7:59:01 PM) Language: english
(4/30/05 7:59:01 PM) Win-Path: C:\WINNT
(4/30/05 7:59:01 PM) System-Path: C:\WINNT\System32
(4/30/05 7:59:01 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(4/30/05 7:59:43 PM) Disinfection started
(4/30/05 7:59:43 PM) Bad-Dll(IEP): (not found)
(4/30/05 7:59:43 PM) Bad-Dll(IEP) in BHO: (not found)
(4/30/05 7:59:43 PM) UBF: 5 - UBB: 0 - UBR: 12
(4/30/05 7:59:43 PM) UBF: 5 - UBB: 0 - UBR: 12
(4/30/05 7:59:43 PM) Bad IE-pages: (none)
(4/30/05 7:59:43 PM) Stealth-String not found
(4/30/05 7:59:43 PM) Not infected->END


(5/1/05 9:37:07 PM) SPSeHjFix started v1.1.2
(5/1/05 9:37:07 PM) OS: WinXP  (5.1.2600)
(5/1/05 9:37:07 PM) Language: english
(5/1/05 9:37:07 PM) Win-Path: C:\WINNT
(5/1/05 9:37:07 PM) System-Path: C:\WINNT\System32
(5/1/05 9:37:07 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(5/1/05 9:37:08 PM) Disinfection started
(5/1/05 9:37:08 PM) Bad-Dll(IEP): (not found)
(5/1/05 9:37:08 PM) Bad-Dll(IEP) in BHO: (not found)
(5/1/05 9:37:08 PM) UBF: 5 - UBB: 0 - UBR: 11
(5/1/05 9:37:08 PM) UBF: 5 - UBB: 0 - UBR: 11
(5/1/05 9:37:08 PM) Bad IE-pages: (none)
(5/1/05 9:37:08 PM) Stealth-String not found
(5/1/05 9:37:08 PM) Not infected->END


(5/1/05 9:44:24 PM) SPSeHjFix started v1.1.2
(5/1/05 9:44:24 PM) OS: WinXP  (5.1.2600)
(5/1/05 9:44:24 PM) Language: english
(5/1/05 9:44:24 PM) Win-Path: C:\WINNT
(5/1/05 9:44:24 PM) System-Path: C:\WINNT\System32
(5/1/05 9:44:24 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(5/1/05 9:44:34 PM) Disinfection started
(5/1/05 9:44:34 PM) Bad-Dll(IEP): (not found)
(5/1/05 9:44:34 PM) Bad-Dll(IEP) in BHO: (not found)
(5/1/05 9:44:34 PM) UBF: 5 - UBB: 0 - UBR: 11
(5/1/05 9:44:34 PM) UBF: 5 - UBB: 0 - UBR: 11
(5/1/05 9:44:34 PM) Bad IE-pages: (none)
(5/1/05 9:44:34 PM) Stealth-String not found
(5/1/05 9:44:34 PM) Not infected->END
________________________________________________________________

I think I'm close... Any  ideas on the desktop?

Muchos Gracias,

Paul

8
Tech Clinic / desktop/homepage hijacker + more - please help
« on: May 01, 2005, 05:48:23 PM »
Hi Guestolo,

Thanks again for the quick reply...

Quote
Eg... I know you haven't download Remv3.zip and unzipped it yet

I actually did download and unzip the file... I don't know if I was in a view mode or what, but there was no hotlink to Remv3.zip when I originally looked (of course, it's plain as day now).  I did a search and found it attached to another post of yours...

Believe me, I followed your instructions to a "T" until running into the couple of snags mentioned in my previous post.  

I'll make sure I'm running SpSeHjfix112 on my next attempt...

Can't do anything till I get off from work!!!  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/dry.gif\' class=\'bbc_emoticon\' alt=\'<_<\' />

I'll post my results tonight or early tomorrow A.M.  

Thanks again for all the help..

Paul

9
Tech Clinic / desktop/homepage hijacker + more - please help
« on: May 01, 2005, 11:06:00 AM »
First off, thanks for the quick and thorough reply.  

I had a few issues with the recovery procedure..  

"Trace Network Connections" was stopped, yet I could not delete ACCRA and FreeBSD - said program was in use."  I checked them off in Hijackthis and deleted, then repeated the "Delete an NT Service" instructions.  Seemed to work.

WhenI ran SpSeHjfix109 the first time, it immediately restarted my computer (as it should).   After startup, I went to run SpSeHjfix109 again (as instructed) and it appeared to lock up..  My cursor would occasionally turn to an hour glass so I thought it was working..  After 5 minutes of this, I walked away and let it run.. An hour or so later it was still doing the same thing.  Aborted and rebooted to find my desktop still hijacked with black screen: "WARNING..."  

I decided to call it quits for the evening...  I will try the whole procedure again tonight after work....  Can you think of anything I may be doing wrong?

Thanks again,

Paul

10
Tech Clinic / desktop/homepage hijacker + more - please help
« on: April 30, 2005, 06:49:37 PM »
I have run SPYBOT, CWSHREDDER, and now HIJACK THIS.  I get rid of most mal ware, but can't seem to get 100% removal.. Please help.
Thanks

Logfile of HijackThis v1.99.1
Scan saved at 4:37:46 PM, on 4/30/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\mocih.exe
C:\WINNT\System32\dev32.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINNT\System32\combo.exe
C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINNT\System32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\winnt\nvsvwc.exe
C:\Program Files\D-Link AirPlus Xtreme G\AirPlus.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\System32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\sprmover.exe
C:\WINNT\System32\connmie.exe
C:\WINNT\System32\truettf.exe
C:\WINNT\System32\dxconf.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://clearsurfing.net/srch.php?qq=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Name - {53B6BC76-7DF8-4B44-ABCF-773DB7994ADF} - C:\WINNT\System32\msnxa.dll
O2 - BHO: Name - {5E26824E-3685-4B70-A914-7F2410B77C0B} - C:\WINNT\System32\msnxa.dll
O2 - BHO: (no name) - {D7F3D96A-26C7-4658-88C3-A72E18719246} - C:\WINNT\openwin.dll
O2 - BHO: Name - {E954B5DC-0CE3-4343-B1B6-FB1B069C5851} - C:\WINNT\System32\msnxa.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINNT\System32\iecustom32.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [combo.exe] combo.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winltmpv] c:\winnt\nvsvwc.exe
O4 - Global Startup: D-Link AirPlus Xtreme G Configuration Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://*.63.219.181.7
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114014142184
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B23A1B2-93B6-4D26-8A8D-5A920143ADD5}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE21173B-4981-4B8C-8B5C-2CE08D1D15A5}: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.184.84,195.225.176.37
O18 - Filter: text/html - {65FA9B6D-F028-4A58-9977-8321DA8D1F3A} - C:\WINNT\openwin.dll
O18 - Filter: text/plain - {65FA9B6D-F028-4A58-9977-8321DA8D1F3A} - C:\WINNT\openwin.dll
O23 - Service: Trace network connections (ACCRA) - Unknown owner - C:\WINNT\System32\mocih.exe
O23 - Service: Provides three management service (FreeBSD) - Unknown owner - C:\WINNT\System32\dev32.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

Pages: [1]