![]() |
| ||
| trojan.cachecachewkit Hi, I am a beginner to this site and need some help! I can't get rid off the trojan.cachecachekit. Pleeeeaaasee help!!! : Here is my hijackthis report: Logfile of HijackThis v1.99.1 Scan saved at 14:08:05, on 11/13/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Skype\Phone\Skype.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Palm\HOTSYNC.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\MSN Apps\Updater\01.05.0000.1009\en-ca\msnappau.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Administrator\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.yoursearchspace.com/sp2.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts...&c=2C01&lc=1009 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yoursearchspace.com/sp2.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yoursearchspace.com/sp2.php R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yoursearchspace.com/sp2.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet O1 - Hosts: 127.0.2.5 www.symantec.com O1 - Hosts: 127.0.2.5 securityresponse.symantec.com O1 - Hosts: 127.0.2.5 sarc.com O1 - Hosts: 127.0.2.5 www.sarc.com O1 - Hosts: 127.0.2.5 www.sophos.com O1 - Hosts: 127.0.2.5 sophos.com O1 - Hosts: 127.0.2.5 www.mcafee.com O1 - Hosts: 127.0.2.5 mcafee.com O1 - Hosts: 127.0.2.5 liveupdate.symantecliveupdate.com O1 - Hosts: 127.0.2.5 www.viruslist.com O1 - Hosts: 127.0.2.5 viruslist.com O1 - Hosts: 127.0.2.5 f-secure.com O1 - Hosts: 127.0.2.5 www.f-secure.com O1 - Hosts: 127.0.2.5 f-prot.com O1 - Hosts: 127.0.2.5 www.f-prot.com O1 - Hosts: 127.0.2.5 kaspersky.com O1 - Hosts: 127.0.2.5 kaspersky-labs.com O1 - Hosts: 127.0.2.5 www.avp.com O1 - Hosts: 127.0.2.5 avp.com O1 - Hosts: 127.0.2.5 www.kaspersky.com O1 - Hosts: 127.0.2.5 www.networkassociates.com O1 - Hosts: 127.0.2.5 networkassociates.com O1 - Hosts: 127.0.2.5 www.ca.com O1 - Hosts: 127.0.2.5 ca.com O1 - Hosts: 127.0.2.5 mast.mcafee.com O1 - Hosts: 127.0.2.5 my-etrust.com O1 - Hosts: 127.0.2.5 www.my-etrust.com O1 - Hosts: 127.0.2.5 download.mcafee.com O1 - Hosts: 127.0.2.5 dispatch.mcafee.com O1 - Hosts: 127.0.2.5 secure.nai.com O1 - Hosts: 127.0.2.5 nai.com O1 - Hosts: 127.0.2.5 www.nai.com O1 - Hosts: 127.0.2.5 vil.nai.com O1 - Hosts: 127.0.2.5 update.symantec.com O1 - Hosts: 127.0.2.5 updates.symantec.com O1 - Hosts: 127.0.2.5 us.mcafee.com O1 - Hosts: 127.0.2.5 liveupdate.symantec.com O1 - Hosts: 127.0.2.5 customer.symantec.com O1 - Hosts: 127.0.2.5 rads.mcafee.com O1 - Hosts: 127.0.2.5 trendmicro.com O1 - Hosts: 127.0.2.5 www.trendmicro.com O1 - Hosts: 127.0.2.5 housecall.trendmicro.com O1 - Hosts: 127.0.2.5 pandasoftware.com O1 - Hosts: 127.0.2.5 www.pandasoftware.com O1 - Hosts: 127.0.2.5 www.trendmicro.com O1 - Hosts: 127.0.2.5 free.grisoft.com O1 - Hosts: 127.0.2.5 clamav.net O1 - Hosts: 127.0.2.5 www.clamav.net O1 - Hosts: 127.0.2.5 free-av.com O1 - Hosts: 127.0.2.5 www.free-av.com O1 - Hosts: 127.0.2.5 www.avast.com O1 - Hosts: 127.0.2.5 avast.com O1 - Hosts: 127.0.2.5 cert.org O1 - Hosts: 127.0.2.5 www.cert.org O1 - Hosts: 127.0.2.5 microsoft.com O1 - Hosts: 127.0.2.5 www.virustotal.com O1 - Hosts: 127.0.2.5 virustotal.com O1 - Hosts: 127.0.2.5 update.microsoft.com O1 - Hosts: 127.0.2.5 windowsupdate.microsoft.com O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\WINDOWS\System32\scpsssh2.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [msdev] msdev.exe O4 - HKLM\..\Run: [msconfig.exe] C:\WINDOWS\TEMP\mspaintx.exe O4 - HKLM\..\Run: [*windows update] wuacrlt.exe O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [SYSTRAY] C:\UNMT.EXE O4 - HKLM\..\Run: [WQZ0] C:\WINDOWS\jgxboia.exe O4 - HKLM\..\Run: [System service76] C:\WINDOWS\\\etb\\pokapoka76.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\RunServices: [msdev] msdev.exe O4 - HKLM\..\RunServices: [*windows update] wuacrlt.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [msdev] msdev.exe O4 - HKCU\..\Run: [*windows update] wuacrlt.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O16 - DPF: Dialpad US Java Applet - http://www.dialpad.com/applet/src/vscp.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab O16 - DPF: {0D62A517-E7C6-4E1F-A577-07D4AC549A48} (Progetto1.int_ver32) - http://advnt01.com/dialer/int_ver32b.CAB O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tec...rl/LSSupCtl.cab O16 - DPF: {217234FC-041F-4F27-84AB-8329440C4DED} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yah...ropper1_6ca.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab O16 - DPF: {2E3C3651-B19C-4DD9-A979-901EC3E930AF} (ssh2 Class) - https://wwwss.bradesco.com.br/ib2k1/scpsssh2.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19.hotmail.msn.com...es/MsnPUpld.cab O16 - DPF: {72D59B9C-1E59-4958-803A-ABDEE2D4CFA6} - http://download.divx.com/player/DivXPlayerInstaller.exe O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binar...StatsClient.cab O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab O16 - DPF: {B1B7606A-D7B9-42A8-AFA2-476308413211} (VacPro.canada_ver4) - http://advnt01.com/dialer/canada_ver4.CAB O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/M...pDownloader.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tec...rl/SymAData.cab O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://f1.pg.photos.yahoo.com/ocx/us/yexplorer1_9us.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub...ash/swflash.cab O16 - DPF: {F1835D04-7CCF-489E-8184-C08A1F682169} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.c...sharingctrl.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binar...ireShowdown.cab O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spys...rcabinstall.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: msdev (msdev.exe) - Unknown owner - C:\WINDOWS\System32\C:\WINDOWS\System32\msdev.exe" -netsvcs (file missing) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Windows 32 Bit (Windows 32 Bit Drivers) - Unknown owner - C:\WINDOWS\WinVid32.exe |
| ||
| Re: trojan.cachecachewkit Hi sorry about your trouble. I just looked at Symantec's removal instructions here: http://securityresponse.symantec.com...ecachekit.html It says that before removing this trojan, you must first remove the W32.Spybot.NLX worm responsible for dropping the trojan. Did your antivirus program already do that? It also recommends updating antivirus and running it in Safe Mode. So, that's where I would start. |
| ||
| Re: trojan.cachecachewkit I did all that, but it doesn't work.... |
| ||
| Re: trojan.cachecachewkit pleeeeaaaase help!!!! I had enough of this stupid trojan! |
| ||
| Re: trojan.cachecachewkit Well, let's see if this will help. Cross your fingers please. These are definitely bad. Place a check mark next to the following entries. O4 - HKLM\..\Run: [msdev] msdev.exe (Description: Added by an unknown WORM or TROJAN! ) O4 - HKLM\..\Run: [msconfig.exe] C:\WINDOWS\TEMP\mspaintx.exe (Description: Program running on startup from a temporary folder.) O4 - HKLM\..\Run: [*windows update] wuacrlt.exe (Description: WORM_RBOT.XZ VIRUS!) O4 - HKLM\..\Run: [SYSTRAY] C:\UNMT.EXE (Description: Added as result of a W32/Sdbot WORM! infection ) O4 - HKLM\..\RunServices: [msdev] msdev.exe (Description: Added by an unknown WORM or TROJAN! ) O4 - HKLM\..\RunServices: [*windows update] wuacrlt.exe (Description: WORM_RBOT.XZ VIRUS!) O4 - HKCU\..\Run: [msdev] msdev.exe (Description: Added by an unknown WORM or TROJAN! ) O4 - HKCU\..\Run: [*windows update] wuacrlt.exe (Description: WORM_RBOT.XZ VIRUS!) O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spys...rcabinstall.cab (Description: Rogue (False) Spyware remover) 1) Press the "Fix checked" button. Then close HijackThis. 2) Then reboot your computer into safe mode. (instructions) 3) Delete the file msdev.exe which resides in C:\WINDOWS\System32\ or C:\WINDOWS\System\ 4) Remove all files from your C:\WINDOWS\TEMP folder and your C:\DOCUMENTS AND SETTINGS\(your username)\LOCAL SETTINGS\Temp\ folder. (Do NOT delete the folders themselves). PLEASE NOTE: The local settings folder is a hidden folder. 5) Delete the file wuacrlt.exe which resides in C:\WINDOWS\System32\ or C:\WINDOWS\System\ 6) Delete the file C:\UNMT.EXE 7) Uninstall SpySpotter. 8) Empty your recycle bin. 9) Run Windows Update and install all critical updates. 10) Make sure your anti-virus program is up to date with the latest patches. If you do not have an anti-virus program, download and install AVG Personal Edition Anti-Virus, which is free. 11) Reboot one last time. 12) Some suspicious entries have been found in your log. The next step is to run HijackThis again and create another log file. |
| ||
| Re: trojan.cachecachewkit Hi, Download Ewido and install it. Then run it, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido. Download CleanUp and install it. Make Windows to show all files:- Go to Start > My Computer. Go to Tools menu, click Folder Options. Uncheck Hide protected operating system files. Then, click to select the option Show hidden files and folders. Click Apply and then click OK to exit. Reboot in Safe Mode:- Restart (or switch ON) the PC. Then, keep tapping the F8 Key. From the menu that will be displayed, out of which choose Safe Mode and press Enter. Go to Start > Run and type services.msc and press ENTER. Here, navigate to the service named msdev and right-click on it. Then click "Properties". Here, in the "Status" dialog box, select "Stop". Then, under "Startup type" dialog box, select "Disabled". Click "Apply" and then "OK". Do the same process (of stopping and disabling) for these Services too:- Windows 32 Bit Run HijackThis and click Do only a System scan. Then put a check mark infront of below listed entries:- R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.yoursearchspace.com/sp2.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts...&c=2C01&lc=1009 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yoursearchspace.com/sp2.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yoursearchspace.com/sp2.php R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yoursearchspace.com/sp2.php O1 - Hosts: 127.0.2.5 www.symantec.com O1 - Hosts: 127.0.2.5 securityresponse.symantec.com O1 - Hosts: 127.0.2.5 sarc.com O1 - Hosts: 127.0.2.5 www.sarc.com O1 - Hosts: 127.0.2.5 www.sophos.com O1 - Hosts: 127.0.2.5 sophos.com O1 - Hosts: 127.0.2.5 www.mcafee.com O1 - Hosts: 127.0.2.5 mcafee.com O1 - Hosts: 127.0.2.5 liveupdate.symantecliveupdate.com O1 - Hosts: 127.0.2.5 www.viruslist.com O1 - Hosts: 127.0.2.5 viruslist.com O1 - Hosts: 127.0.2.5 f-secure.com O1 - Hosts: 127.0.2.5 www.f-secure.com O1 - Hosts: 127.0.2.5 f-prot.com O1 - Hosts: 127.0.2.5 www.f-prot.com O1 - Hosts: 127.0.2.5 kaspersky.com O1 - Hosts: 127.0.2.5 kaspersky-labs.com O1 - Hosts: 127.0.2.5 www.avp.com O1 - Hosts: 127.0.2.5 avp.com O1 - Hosts: 127.0.2.5 www.kaspersky.com O1 - Hosts: 127.0.2.5 www.networkassociates.com O1 - Hosts: 127.0.2.5 networkassociates.com O1 - Hosts: 127.0.2.5 www.ca.com O1 - Hosts: 127.0.2.5 ca.com O1 - Hosts: 127.0.2.5 mast.mcafee.com O1 - Hosts: 127.0.2.5 my-etrust.com O1 - Hosts: 127.0.2.5 www.my-etrust.com O1 - Hosts: 127.0.2.5 download.mcafee.com O1 - Hosts: 127.0.2.5 dispatch.mcafee.com O1 - Hosts: 127.0.2.5 secure.nai.com O1 - Hosts: 127.0.2.5 nai.com O1 - Hosts: 127.0.2.5 www.nai.com O1 - Hosts: 127.0.2.5 vil.nai.com O1 - Hosts: 127.0.2.5 update.symantec.com O1 - Hosts: 127.0.2.5 updates.symantec.com O1 - Hosts: 127.0.2.5 us.mcafee.com O1 - Hosts: 127.0.2.5 liveupdate.symantec.com O1 - Hosts: 127.0.2.5 customer.symantec.com O1 - Hosts: 127.0.2.5 rads.mcafee.com O1 - Hosts: 127.0.2.5 trendmicro.com O1 - Hosts: 127.0.2.5 www.trendmicro.com O1 - Hosts: 127.0.2.5 housecall.trendmicro.com O1 - Hosts: 127.0.2.5 pandasoftware.com O1 - Hosts: 127.0.2.5 www.pandasoftware.com O1 - Hosts: 127.0.2.5 www.trendmicro.com O1 - Hosts: 127.0.2.5 free.grisoft.com O1 - Hosts: 127.0.2.5 clamav.net O1 - Hosts: 127.0.2.5 www.clamav.net O1 - Hosts: 127.0.2.5 free-av.com O1 - Hosts: 127.0.2.5 www.free-av.com O1 - Hosts: 127.0.2.5 www.avast.com O1 - Hosts: 127.0.2.5 avast.com O1 - Hosts: 127.0.2.5 cert.org O1 - Hosts: 127.0.2.5 www.cert.org O1 - Hosts: 127.0.2.5 microsoft.com O1 - Hosts: 127.0.2.5 www.virustotal.com O1 - Hosts: 127.0.2.5 virustotal.com O1 - Hosts: 127.0.2.5 update.microsoft.com O1 - Hosts: 127.0.2.5 windowsupdate.microsoft.com O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\WINDOWS\System32\scpsssh2.dll O4 - HKLM\..\Run: [msdev] msdev.exe O4 - HKLM\..\Run: [msconfig.exe] C:\WINDOWS\TEMP\mspaintx.exe O4 - HKLM\..\Run: [*windows update] wuacrlt.exe O4 - HKLM\..\Run: [SYSTRAY] C:\UNMT.EXE O4 - HKLM\..\Run: [WQZ0] C:\WINDOWS\jgxboia.exe O4 - HKLM\..\Run: [System service76] C:\WINDOWS\\\etb\\pokapoka76.exe O4 - HKLM\..\RunServices: [msdev] msdev.exe O4 - HKLM\..\RunServices: [*windows update] wuacrlt.exe O4 - HKCU\..\Run: [msdev] msdev.exe O4 - HKCU\..\Run: [*windows update] wuacrlt.exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O16 - DPF: {0D62A517-E7C6-4E1F-A577-07D4AC549A48} (Progetto1.int_ver32) - http://advnt01.com/dialer/int_ver32b.CAB O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c11.cab O16 - DPF: {B1B7606A-D7B9-42A8-AFA2-476308413211} (VacPro.canada_ver4) - http://advnt01.com/dialer/canada_ver4.CAB O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spys...rcabinstall.cab O23 - Service: msdev (msdev.exe) - Unknown owner - C:\WINDOWS\System32\C:\WINDOWS\System32\msdev.exe" -netsvcs (file missing) O23 - Service: Windows 32 Bit (Windows 32 Bit Drivers) - Unknown owner - C:\WINDOWS\WinVid32.exe Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis. Delete these files:- C:\WINDOWS\WinVid32.exe C:\UNMT.EXE C:\WINDOWS\jgxboia.exe Go to Start > Search. Here click "All files and folders" in the left pane. Next, click on "More advanced options". Here select the options "Search system folders", "Search hidden files and folders" and "Search subfolders". Next, type/copy the below mentioned filename and search for it, if you find it, right-click on it and click delete:- wuacrlt.exe msdev.exe Run CleanUp! and click "Options.." button. Here move the "Quick Setup" slider to "Thorough Cleanup" position. Uncheck the option "Delete Favorites Palces/Bookmarks", if you have any bookmarks. Click "OK" to return to main window, and click "CleanUp!" to start cleaning. After it completes, click "Close" and click "No" to avoid logging off. Run Ewido, click on the "Scanner" button in the left menu, then click on the "Complete System Scan" button. If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK. Reboot to Normal Mode. Perform an online virus scan at Panda ActiveScan with the "Disinfection" option enabled. Save the log it gives after the scan. Run HijackThis again, click Do a System scan and save log, and post the fresh log along with the Panda ActiveScan log. |
| ||
| Re: trojan.cachecachewkit Hi, thanks for helping!!! The following things I couldn't find: O23 - Service: msdev (msdev.exe) - Unknown owner - C:\WINDOWS\System32\C:\WINDOWS\System32\msdev.exe" -netsvcs (file missing) O23 - Service: Windows 32 Bit (Windows 32 Bit Drivers) - Unknown owner - C:\WINDOWS\WinVid32.exe[/b] C:\UNMT.EXE C:\WINDOWS\jgxboia.exe wuacrlt.exe msdev.exe Here are the log files: Incident Status Location Adware:adware/exact.bargainbuddyNo disinfected C:\WINDOWS\SYSTEM32\vx0.nls Adware:adware/mediatickets No disinfected C:\WINDOWS\re12.reg Adware:adware/wupd No disinfected C:\PROGRAM FILES\Windows TaskAd Adware:adware/elitebar No disinfected C:\WINDOWS\etb Adware:adware/surfaccuracy No disinfected Windows Registry Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\SYSTEM32\DRIVERS\etc\hosts.20051012-095319.backup Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\SYSTEM32\DRIVERS\etc\hosts.msn Adware:Adware/Exact.BargainBuddyNo disinfected C:\WINDOWS\etb\xml\images\dating.bmp Adware:Adware/Exact.BargainBuddyNo disinfected C:\WINDOWS\etb\xml\images\casino.bmp Adware:Adware/Exact.BargainBuddyNo disinfected C:\WINDOWS\etb\xml\images\virus.bmp Logfile of HijackThis v1.99.1 Scan saved at 12:42:20, on 11/19/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Skype\Phone\Skype.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Palm\HOTSYNC.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\cidaemon.exe C:\Documents and Settings\Administrator\Desktop\For Comp Clean\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O16 - DPF: Dialpad US Java Applet - http://www.dialpad.com/applet/src/vscp.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...l/LSSupCtl.cab O16 - DPF: {217234FC-041F-4F27-84AB-8329440C4DED} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yaho...opper1_6ca.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab O16 - DPF: {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - https://wwwss.bradesco.com.br/ib2k1/scpsssh2.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19.hotmail.msn.com/...s/MsnPUpld.cab O16 - DPF: {72D59B9C-1E59-4958-803A-ABDEE2D4CFA6} - http://download.divx.com/player/DivXPlayerInstaller.exe O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://f1.pg.photos.yahoo.com/ocx/us/yexplorer1_9us.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab O16 - DPF: {F1835D04-7CCF-489E-8184-C08A1F682169} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe Could you let me know what I can do, that this doesn't happen again. I have Norton Antivirus and use Sygate personal firewall. Should I use something else? Thank you for everything!!! |
| ||
| Re: trojan.cachecachewkit Hi, Forgot to say that the Trojan.cachecachekit doesn't appear anymore... Thanks!! |
| ||
| Re: trojan.cachecachewkit Hi, Theres one more thing to remove. Before we start fixing anything you may want to PRINT and keep all instructions handy. You may also want to save them to WordPad so that they will be accessible. DO NOT use notepad. Some steps will require you to disconnect from the Internet or boot into Safe Mode and you will not have access to this page. Download LQfix.exe subratam.org mirror geekstogo mirror 1. Save it to your desktop and double-click to install. 2. Leave the default settings. If you change them, the fix will fail. 3. Make sure 'Launch LQfix' is checked. After clicking finish in the install, the fix will start. 4. Follow the prompts on the screen. 5. Your system will reboot afterwards. 6. Please be patient after reboot, because there is a script running in the background that needs to complete. After this, post a fresh HijackThis log. --------------------------------------------- Note: When you run LQFix, IF you get this error:- Quote:
LQfirst.bfu LQsecond.bfu 1. After download, place them inside the LQfix folder (C:\WINDOWS\LQfix folder) 2. Open the folder and and double-click on the "ClickThis.bat" to run. |
| ||
| Re: trojan.cachecachewkit HI, Here is my new log file: Logfile of HijackThis v1.99.1 Scan saved at 12:51:23, on 11/20/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Palm\HOTSYNC.EXE C:\WINDOWS\system32\cisvc.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\ewido\security suite\ewidoguard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\cidaemon.exe C:\Documents and Settings\Administrator\Desktop\For Comp Clean\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O16 - DPF: Dialpad US Java Applet - http://www.dialpad.com/applet/src/vscp.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...l/LSSupCtl.cab O16 - DPF: {217234FC-041F-4F27-84AB-8329440C4DED} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yaho...opper1_6ca.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab O16 - DPF: {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - https://wwwss.bradesco.com.br/ib2k1/scpsssh2.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19.hotmail.msn.com/...s/MsnPUpld.cab O16 - DPF: {72D59B9C-1E59-4958-803A-ABDEE2D4CFA6} - http://download.divx.com/player/DivXPlayerInstaller.exe O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://f1.pg.photos.yahoo.com/ocx/us/yexplorer1_9us.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab O16 - DPF: {F1835D04-7CCF-489E-8184-C08A1F682169} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe |
| All times are GMT -4. The time now is 2:23 am. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC