User Name Password Register
DaniWeb IT Discussion Community
All
What is DaniWeb IT Discussion Community?
You're currently browsing the Viruses, Spyware and other Nasties section within the Tech Talk category of DaniWeb, a massive community of 361,915 software developers, web developers, Internet marketers, and tech gurus who are all enthusiastic about making contacts, networking, and learning from each other. In fact, there are 2,587 IT professionals currently interacting right now! Registration is free, only takes a minute and lets you enjoy all of the interactive features of the site.
Please support our Viruses, Spyware and other Nasties advertiser:
Views: 7716 | Replies: 27
Reply
Join Date: Dec 2005
Location: Indiana
Posts: 22
Reputation: walton is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 0
walton walton is offline Offline
Newbie Poster

Help I've been Hijacked! Please help!

  #1  
Dec 24th, 2005
Hello, this is Walton and I need help! None of my shortcuts or programs on my desktop work anymore and I can't get into add/remove programs. I ran Mcafee Virus Scan, Spybot Search and Destroy, and Ad-Aware scan, and I'm still having trouble. I also restored my computer to an earlier point, but that did no good. I don't know if I have a virus or if I chose to block these applications. This problem began after I blocked something that popped up on my Ad-Watch monitor (Lavasoft). I have Windows Xp and the computer is a new Dell XPS 400. Please help me! Below is my Hijack This Report.

Logfile of HijackThis v1.99.1
Scan saved at 12:38:24 AM, on 12/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:///??
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1130266793890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1132318523125
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.co...x/HMAtchmt.ocx
O18 - Filter: text/html - (no CLSID) - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SVCLOAD - Unknown owner - c:\windows\system32\dllcache\sys32\winlogon.exe
O23 - Service: SVCMGR - Unknown owner - c:\windows\system32\dllcache\sys32\winlogon.exe
AddThis Social Bookmark Button
Reply With Quote  
Join Date: Nov 2005
Location: Out of this World..........
Posts: 273
Reputation: jaishankar is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 14
jaishankar's Avatar
jaishankar jaishankar is offline Offline
Posting Whiz in Training

Re: I've been Hijacked! Please help!

  #2  
Dec 24th, 2005
Download ewido from the link http://www.ewido.net/en/
install it and update it

Update ur McAfee Antivirus and Ad-Aware.

Disable ur computer from Lan.

Restart ur computer go to safe mode by hitting F8 key at boot up

Disable System Restore (MyComputer-Properties-System Restore Check Turn off System Restore on all Drives)
Perform a complete System scan with Mcafee, ewido, Ad-Aware, and also with Spybot Search and Destroy.

Delete all the temporary internet files, empty recycle bin and restart ur computer

And don't 4get to post a reply
6 rules to be happy:
Free your heart from hatred; Free your mind from worries; Live simply; Expect less; Give more & always have me as Ur Friend.
Reply With Quote  
Join Date: Dec 2005
Location: Indiana
Posts: 22
Reputation: walton is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 0
walton walton is offline Offline
Newbie Poster

I can't Open system restore

  #3  
Dec 25th, 2005
Thanks for you help, but I can't get into system restore to change the settings. The "My Computer" icon did not respond when I tried to get into its properties, and when I finally made my way to system restore settings, I had got a message saying that this function no longer exists and that I should contact my administrator. What does this mean. Help me please!
Reply With Quote  
Join Date: Nov 2005
Location: Out of this World..........
Posts: 273
Reputation: jaishankar is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 14
jaishankar's Avatar
jaishankar jaishankar is offline Offline
Posting Whiz in Training

Re: I can't Open system restore

  #4  
Dec 25th, 2005
Originally Posted by walton
Thanks for you help, but I can't get into system restore to change the settings. The "My Computer" icon did not respond when I tried to get into its properties, and when I finally made my way to system restore settings, I had got a message saying that this function no longer exists and that I should contact my administrator. What does this mean. Help me please!

When u enter into safe mode by default there will another account i.e., the Administrator account. Enter into it and try to disable system restore and scan
6 rules to be happy:
Free your heart from hatred; Free your mind from worries; Live simply; Expect less; Give more & always have me as Ur Friend.
Reply With Quote  
Join Date: Dec 2005
Location: Indiana
Posts: 22
Reputation: walton is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 0
walton walton is offline Offline
Newbie Poster

Is there another way?

  #5  
Dec 25th, 2005
I opened my computer in safe mode with the administrator and I still could not access system restore. However, I did run full systems scans with all of my scan programs including Ewido-Malware and I deleted all of my temporary internet files. Yet, my computer is still in a vegetative state, so I'm still in desperate need of help.
Reply With Quote  
Join Date: Nov 2005
Location: Out of this World..........
Posts: 273
Reputation: jaishankar is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 14
jaishankar's Avatar
jaishankar jaishankar is offline Offline
Posting Whiz in Training

Re: Is there another way?

  #6  
Dec 25th, 2005
Originally Posted by walton
I opened my computer in safe mode with the administrator and I still could not access system restore. However, I did run full systems scans with all of my scan programs including Ewido-Malware and I deleted all of my temporary internet files. Yet, my computer is still in a vegetative state, so I'm still in desperate need of help.

If the system is not infected with virus any more then try to repair it with the Window XP cd if u have one. As repairing sets the system to its default settings. You wont loose any of ur data or programs

Disable ur Antivirus, Boot from Windows XP CD, now press enter to continue setup and the F8 to accept the license agreement, now the setup will search for the previous versions of Operating System, select "Microsoft Windows XP Professional" from the list displayed and press 'r' to repair
6 rules to be happy:
Free your heart from hatred; Free your mind from worries; Live simply; Expect less; Give more & always have me as Ur Friend.
Reply With Quote  
Join Date: Dec 2005
Location: Indiana
Posts: 22
Reputation: walton is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 0
walton walton is offline Offline
Newbie Poster

Re: Is there another way?

  #7  
Dec 26th, 2005
What can I do if I don't have a Windows XP cd. My computer already had Windows XP installled on it, and no cd was provided. Can I get a cd from a website?
Reply With Quote  
Join Date: Nov 2005
Location: Out of this World..........
Posts: 273
Reputation: jaishankar is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 14
jaishankar's Avatar
jaishankar jaishankar is offline Offline
Posting Whiz in Training

Re: Is there another way?

  #8  
Dec 26th, 2005
Originally Posted by walton
What can I do if I don't have a Windows XP cd. My computer already had Windows XP installled on it, and no cd was provided. Can I get a cd from a website?

Either u have to purchase from u nearest computer store if u can afford it or have to borrow from ur friend
6 rules to be happy:
Free your heart from hatred; Free your mind from worries; Live simply; Expect less; Give more & always have me as Ur Friend.
Reply With Quote  
Join Date: Dec 2003
Location: Marin County, CA
Posts: 6,437
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Rep Power: 18
Solved Threads: 337
Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: I've been Hijacked! Please help!

  #9  
Dec 26th, 2005
Hi walton,

A couple of things, before you resort to an entire system restore or reformat:

1.
This problem began after I blocked something that popped up on my Ad-Watch monitor
Can you tell us anything more specific about that? "Something that popped up" doesn't give us very much to go on at all.


2. The list of running processes at the top of your HijackThis log looks rather "light on content" for a normal XP system. Did you run that HijackThis scan in Safe Mode? If so (and if possible), run HijackThis while booted into Windows normally and post the log from that scan. The log you posted definitely shows signs of infections, but I'd expect to see more information in a log than exists in yours.


3. If you can access your Administrative Tools control panel, open the Event Viewer utility in that control panel and look through your System and Application logs for entries flagged with "Error" or "Warning". Double-clicking on such an entry will open a window with more detailed information on the error; post that info here.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote  
Join Date: Dec 2005
Location: Indiana
Posts: 22
Reputation: walton is an unknown quantity at this point 
Rep Power: 3
Solved Threads: 0
walton walton is offline Offline
Newbie Poster

Re: I've been Hijacked! Please help!

  #10  
Dec 26th, 2005
This is a lengthy report. I used a Windows XP cd (Microsoft Windows XP Professional for OS 5.1.2600, which is compatible/identical with the original program on my PC) to reinstall Windows XP on my computer. However, when the startup wizard appeared which read "Welcome to Microsoft Windows XP, What do you want to do", I clicked "Install Windows XP", but nothing happened because my computer only responds to certain links now, which is all confusing to me. Since it responds to some links and not others, I've been having trouble connecting to shortcuts, programs, etc. and I definitely can't connect to my system restore settings option.

Here is a short story of how my computer came to be in the state that it's in: Before the Lavasoft Ad-watch pop-up encounter, I was trying to install my EA Sports MVP Baseball 2004 Demo (this is a demo of a baseball game for PC). However, One of the .exe files in the games folder read "MVP 2005", a newer edition so I decided to double click on it. It started to load the game's opening screen because a loading bar showed, but then it crashed (probably because it was trying to run all of the older version's applications since the games were in the same folder). This caused my computer to crash as well, so I rebooted my computer with a restart. I feared that this game cause a potential problem to my PC so I uninstalled it completely. Shortly after this incident (about 5-10 minutes later), "something" was detected on my Lavasoft Ad-watch monitor. I am unsure if there is any correlation between the two, but I'm just telling you the sequence of events of what happened.

As far as what happened with the Lavasoft Ad-watch pop-up, I can't really describe what happened. All I remember is that "something" was detected, which I don't have a name for, and the program asked me if I would like to block it or accept it. However, I was prompted to read more about this detection, before making a decision. I did not read because the report was somewhat lengthy like this one , and I chose to block whatever was detected to be on the safe side. Shortly after this, my computer started acting a fool, and it has remained in this vegetative state. I then ran a system restore at this time because this function was working propely at the time, but it did not change the functioning of my shortcuts, or programs back to normal.

You can see my HijackThis log below. I ran HijackThis again in Windows, normally (not Safe Mode) and my report probably is the exact same thing. Why it is short, I cannot explain.

As for the Administrative Tools control panel, I can get all the way to the Event Viewer, but it is a .LNK file like everything else is now. I have figured out a way to access other .LNK files/shortcuts by creating a shortcut for the file and then finding the program in a default list or its subfolder, by going through "My Computer". However, I can't get this procedure to work for the Event Viewer program, therefore I can't access any log info from it.

Thanks for the help thus far and I'm sorry for the lengthy detail, but I felt that this might be of some use, or not.

Logfile of HijackThis v1.99.1
Scan saved at 12:43:32 PM, on 12/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:///??
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1130266793890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1132318523125
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by108fd.bay108.hotmail.msn.co...x/HMAtchmt.ocx
O18 - Filter: text/html - (no CLSID) - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SVCLOAD - Unknown owner - c:\windows\system32\dllcache\sys32\winlogon.exe
O23 - Service: SVCMGR - Unknown owner - c:\windows\system32\dllcache\sys32\winlogon.exe
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

DaniWeb Viruses, Spyware and other Nasties Marketplace
Thread Tools Display Modes

Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum

All times are GMT -4. The time now is 9:57 pm.
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC